Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '%APPDATA%\csrss.exe' = '%APPDATA%\csrss.exe:*:Enabled:csrss.exe'
- '<SYSTEM32>\schtasks.exe' /create /sc minute /mo 9 /tn Google-Updater-0xGIU4WXA /tr %APPDATA%\csrss.exe
- '<SYSTEM32>\cmd.exe' /k ping google.com & del "%APPDATA%\csrss.exe" & exit
- '<SYSTEM32>\ping.exe' google.com
- '%APPDATA%\csrss.exe'
- '<SYSTEM32>\reg.exe' ADD HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /v ms-csrss.exe /t REG_SZ /d %APPDATA%\csrss.exe
- '<SYSTEM32>\netsh.exe' firewall add allowedprogram "%APPDATA%\csrss.exe" "csrss.exe" ENABLE
- %APPDATA%\csrss.exe
- %APPDATA%\csrss.exe
- 'ko###.mooo.com':1142
- DNS ASK google.com
- DNS ASK ko###.mooo.com
