NtGetContextThread
|
thread_handle:
0x00000184
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000184
suspend_count:
1
process_identifier:
1800
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x00000184
|
1
|
0 |
0
|
NtSetContextThread
|
registers.eip:
4571616
registers.esp:
310868764
registers.edi:
0
registers.eax:
0
registers.ebp:
6
registers.edx:
0
registers.ebx:
0
registers.esi:
0
registers.ecx:
0
thread_handle:
0x00000184
process_identifier:
1800
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000184
suspend_count:
1
process_identifier:
1800
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x0000018c
|
1
|
0 |
0
|
NtSetContextThread
|
registers.eip:
4571616
registers.esp:
310868712
registers.edi:
0
registers.eax:
0
registers.ebp:
310649984
registers.edx:
0
registers.ebx:
0
registers.esi:
0
registers.ecx:
0
thread_handle:
0x0000018c
process_identifier:
1800
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000018c
suspend_count:
1
process_identifier:
1800
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x0000018c
|
1
|
0 |
0
|
NtSetContextThread
|
registers.eip:
4571616
registers.esp:
310868876
registers.edi:
0
registers.eax:
0
registers.ebp:
311700609
registers.edx:
0
registers.ebx:
0
registers.esi:
0
registers.ecx:
0
thread_handle:
0x0000018c
process_identifier:
1800
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000018c
suspend_count:
1
process_identifier:
1800
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x0000018c
|
1
|
0 |
0
|
NtSetContextThread
|
registers.eip:
4571616
registers.esp:
310868876
registers.edi:
0
registers.eax:
0
registers.ebp:
3
registers.edx:
0
registers.ebx:
0
registers.esi:
0
registers.ecx:
0
thread_handle:
0x0000018c
process_identifier:
1800
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000018c
suspend_count:
1
process_identifier:
1800
|
1
|
0 |
0
|
CreateProcessInternalW
|
thread_identifier:
2140
thread_handle:
0x00000284
process_identifier:
3068
current_directory:
filepath:
C:\Windows\System32\cmd.exe
track:
1
command_line:
cmd.exe /c "netsh wlan show networks mode=bssid"
filepath_r:
C:\Windows\system32\cmd.exe
stack_pivoted:
0
creation_flags:
1024
(CREATE_UNICODE_ENVIRONMENT)
inherit_handles:
1
process_handle:
0x00000288
|
1
|
1 |
0
|
CreateProcessInternalW
|
thread_identifier:
1108
thread_handle:
0x000002a0
process_identifier:
1312
current_directory:
filepath:
C:\Windows\System32\cmd.exe
track:
1
command_line:
cmd.exe /c "arp -a"
filepath_r:
C:\Windows\system32\cmd.exe
stack_pivoted:
0
creation_flags:
1024
(CREATE_UNICODE_ENVIRONMENT)
inherit_handles:
1
process_handle:
0x000002a4
|
1
|
1 |
0
|
CreateProcessInternalW
|
thread_identifier:
276
thread_handle:
0x0000029c
process_identifier:
508
current_directory:
filepath:
C:\Windows\System32\cmd.exe
track:
1
command_line:
cmd.exe /c "netstat -ano -p TCP"
filepath_r:
C:\Windows\system32\cmd.exe
stack_pivoted:
0
creation_flags:
1024
(CREATE_UNICODE_ENVIRONMENT)
inherit_handles:
1
process_handle:
0x000002a0
|
1
|
1 |
0
|
NtGetContextThread
|
thread_handle:
0x0000028c
|
1
|
0 |
0
|
NtSetContextThread
|
registers.eip:
4571616
registers.esp:
318274096
registers.edi:
0
registers.eax:
0
registers.ebp:
2
registers.edx:
0
registers.ebx:
0
registers.esi:
0
registers.ecx:
0
thread_handle:
0x0000028c
process_identifier:
1800
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000028c
suspend_count:
1
process_identifier:
1800
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x0000028c
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000028c
suspend_count:
1
process_identifier:
1800
|
1
|
0 |
0
|
CreateProcessInternalW
|
thread_identifier:
1644
thread_handle:
0x00000084
process_identifier:
684
current_directory:
C:\Users\test22\AppData\Local\Temp
filepath:
C:\Windows\System32\netsh.exe
track:
1
command_line:
netsh wlan show networks mode=bssid
filepath_r:
C:\Windows\system32\netsh.exe
stack_pivoted:
0
creation_flags:
524288
(EXTENDED_STARTUPINFO_PRESENT)
inherit_handles:
1
process_handle:
0x00000088
|
1
|
1 |
0
|
NtResumeThread
|
thread_handle:
0x00000230
suspend_count:
1
process_identifier:
684
|
1
|
0 |
0
|
CreateProcessInternalW
|
thread_identifier:
2168
thread_handle:
0x00000084
process_identifier:
2252
current_directory:
C:\Users\test22\AppData\Local\Temp
filepath:
C:\Windows\System32\ARP.EXE
track:
1
command_line:
arp -a
filepath_r:
C:\Windows\system32\ARP.EXE
stack_pivoted:
0
creation_flags:
524288
(EXTENDED_STARTUPINFO_PRESENT)
inherit_handles:
1
process_handle:
0x00000088
|
1
|
1 |
0
|
NtResumeThread
|
thread_handle:
0x00000158
suspend_count:
1
process_identifier:
2252
|
1
|
0 |
0
|
CreateProcessInternalW
|
thread_identifier:
1776
thread_handle:
0x00000084
process_identifier:
2212
current_directory:
C:\Users\test22\AppData\Local\Temp
filepath:
C:\Windows\System32\NETSTAT.EXE
track:
1
command_line:
netstat -ano -p TCP
filepath_r:
C:\Windows\system32\NETSTAT.EXE
stack_pivoted:
0
creation_flags:
524288
(EXTENDED_STARTUPINFO_PRESENT)
inherit_handles:
1
process_handle:
0x00000088
|
1
|
1 |
0
|