

Reconstructed Crackonosh Inno Setup installer script If it finds it’s “safe” to run malware, then installs the Crackonosh malware to %SystemRoot%\system32\ and one configuration file to %localappdata%\Programs\Common and creates in the Windows Task scheduler the tasks InstallWinSAT to start maintenance.vbs and StartupCheckLibrary to start StartupcheckLibrary.vbs. The installer Inno Setup executes the following script. This shows us that Crackonosh was packed in a password protected archive and unpacked in the process of installation.


