This repo has the decoded Schneiken dropper files. ALL content on this repo is for research and learning use ONLY. Use this content at your own risk.
Here's the flow:
Schneiken > stage2
Stage2 > vCNkCxcKEd > Dunihi RAT AND Stage3
Stage3 > Ratty (JRAT) + Watcher.vbs + Master.vbs
VBS dropper: MD5 47f21544a7479cae3e20488731ba6aa6 https://www.virustotal.com/#/file/d5f56058608f8dabb9d19c432c751f99f994edd056b2846ac51915258494598a/detection