Техническая информация
- %APPDATA%\nighty selfbot\auth.json
- %TEMP%\esgwsegewsrg.dll
- %TEMP%\cert.pem
- %TEMP%\key.pem
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -inputformat none -outputformat none -NonInteractive -Command "Import-Certificate -FilePath '%TEMP%\cert.pem' -CertStoreLocation Cert:\LocalMachine\Root"
- '<SYSTEM32>\cmd.exe' "powershell -inputformat none -outputformat none -NonInteractive -Command "Import-Certificate -FilePath '%TEMP%\cert.pem' -CertStoreLocation Cert:\LocalMachine\Root""' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' "powershell -inputformat none -outputformat none -NonInteractive -Command "Import-Certificate -FilePath '%TEMP%\cert.pem' -CertStoreLocation Cert:\LocalMachine\Root""
- '<SYSTEM32>\cmd.exe' /c start Nighty.exe