NtResumeThread
|
thread_handle:
0x000000dc
suspend_count:
1
process_identifier:
2428
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000150
suspend_count:
1
process_identifier:
2428
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000018c
suspend_count:
1
process_identifier:
2428
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000254
suspend_count:
1
process_identifier:
2428
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x000000e0
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x000000e0
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x000000e0
suspend_count:
1
process_identifier:
2428
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x000000e0
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x000000e0
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x000000e0
suspend_count:
1
process_identifier:
2428
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x000000e0
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x000000e0
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x000000e0
suspend_count:
1
process_identifier:
2428
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x000000e0
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x000000e0
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x000000e0
|
1
|
0 |
0
|
NtSetContextThread
|
registers.eip:
1947216772
registers.esp:
6022624
registers.edi:
128913232
registers.eax:
4259905
registers.ebp:
6022628
registers.edx:
128999232
registers.ebx:
49237
registers.esi:
6237
registers.ecx:
129097720
thread_handle:
0x000000e0
process_identifier:
2428
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x000000e0
suspend_count:
1
process_identifier:
2428
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x000000e0
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x000000e0
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x000000e0
suspend_count:
1
process_identifier:
2428
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x000000e0
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x000000e0
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x000000e0
suspend_count:
1
process_identifier:
2428
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x000000e0
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x000000e0
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x000000e0
|
1
|
0 |
0
|
NtSetContextThread
|
registers.eip:
1947216772
registers.esp:
6022624
registers.edi:
133871232
registers.eax:
3407972
registers.ebp:
6022628
registers.edx:
133882688
registers.ebx:
61016
registers.esi:
55288
registers.ecx:
134004736
thread_handle:
0x000000e0
process_identifier:
2428
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x000000e0
suspend_count:
1
process_identifier:
2428
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x000000e0
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x000000e0
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x000000e0
suspend_count:
1
process_identifier:
2428
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000025c
suspend_count:
1
process_identifier:
2428
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x000000e0
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x000000e0
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x000000e0
suspend_count:
1
process_identifier:
2428
|
1
|
0 |
0
|
CreateProcessInternalW
|
thread_identifier:
2920
thread_handle:
0x00000268
process_identifier:
2916
current_directory:
filepath:
C:\Users\test22\AppData\Local\Temp\aa.exe
track:
1
command_line:
filepath_r:
C:\Users\test22\AppData\Local\Temp\aa.exe
stack_pivoted:
0
creation_flags:
134217732
(CREATE_NO_WINDOW|CREATE_SUSPENDED)
inherit_handles:
0
process_handle:
0x0000026c
|
1
|
1 |
0
|
NtGetContextThread
|
thread_handle:
0x00000268
|
1
|
0 |
0
|
NtAllocateVirtualMemory
|
process_identifier:
2916
region_size:
245760
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00400000
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
process_handle:
0x0000026c
|
|
3221225496 |
0
|
CreateProcessInternalW
|
thread_identifier:
2956
thread_handle:
0x0000027c
process_identifier:
2952
current_directory:
filepath:
C:\Users\test22\AppData\Local\Temp\aa.exe
track:
1
command_line:
filepath_r:
C:\Users\test22\AppData\Local\Temp\aa.exe
stack_pivoted:
0
creation_flags:
134217732
(CREATE_NO_WINDOW|CREATE_SUSPENDED)
inherit_handles:
0
process_handle:
0x00000280
|
1
|
1 |
0
|
NtGetContextThread
|
thread_handle:
0x0000027c
|
1
|
0 |
0
|
NtAllocateVirtualMemory
|
process_identifier:
2952
region_size:
245760
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00400000
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
process_handle:
0x00000280
|
|
3221225496 |
0
|
CreateProcessInternalW
|
thread_identifier:
2992
thread_handle:
0x00000288
process_identifier:
2988
current_directory:
filepath:
C:\Users\test22\AppData\Local\Temp\aa.exe
track:
1
command_line:
filepath_r:
C:\Users\test22\AppData\Local\Temp\aa.exe
stack_pivoted:
0
creation_flags:
134217732
(CREATE_NO_WINDOW|CREATE_SUSPENDED)
inherit_handles:
0
process_handle:
0x00000284
|
1
|
1 |
0
|
NtGetContextThread
|
thread_handle:
0x00000288
|
1
|
0 |
0
|
NtAllocateVirtualMemory
|
process_identifier:
2988
region_size:
245760
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00400000
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
process_handle:
0x00000284
|
|
3221225496 |
0
|
CreateProcessInternalW
|
thread_identifier:
3028
thread_handle:
0x00000290
process_identifier:
3024
current_directory:
filepath:
C:\Users\test22\AppData\Local\Temp\aa.exe
track:
1
command_line:
filepath_r:
C:\Users\test22\AppData\Local\Temp\aa.exe
stack_pivoted:
0
creation_flags:
134217732
(CREATE_NO_WINDOW|CREATE_SUSPENDED)
inherit_handles:
0
process_handle:
0x0000028c
|
1
|
1 |
0
|
NtGetContextThread
|
thread_handle:
0x00000290
|
1
|
0 |
0
|
NtAllocateVirtualMemory
|
process_identifier:
3024
region_size:
245760
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00400000
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
process_handle:
0x0000028c
|
|
3221225496 |
0
|
CreateProcessInternalW
|
thread_identifier:
3064
thread_handle:
0x00000298
process_identifier:
3060
current_directory:
filepath:
C:\Users\test22\AppData\Local\Temp\aa.exe
track:
1
command_line:
filepath_r:
C:\Users\test22\AppData\Local\Temp\aa.exe
stack_pivoted:
0
creation_flags:
134217732
(CREATE_NO_WINDOW|CREATE_SUSPENDED)
inherit_handles:
0
process_handle:
0x00000294
|
1
|
1 |
0
|
NtGetContextThread
|
thread_handle:
0x00000298
|
1
|
0 |
0
|