Technical Information
- <SYSTEM32>\cmd.exe
- %WINDIR%\fonts\roboto-medium.ttf
- 'wo###.cheat.guru':80
- http://wo###.cheat.guru/loader/new/.loader-version.txt
- http://wo###.cheat.guru/loader/Roboto-Medium.ttf
- http://wo###.cheat.guru/loader/new/.loader.exe
- '35.##1.9.150':443
- '34.##0.144.191':443
- DNS ASK ch###.cheat.guru
- DNS ASK wo###.cheat.guru
- '<SYSTEM32>\cmd.exe' /c cls
- '<SYSTEM32>\cmd.exe' "<Full path to file>"