NtResumeThread
|
thread_handle:
0x00000260
suspend_count:
1
process_identifier:
3036
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x000002c0
suspend_count:
1
process_identifier:
3036
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x000002c4
suspend_count:
1
process_identifier:
3036
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x000002c8
suspend_count:
1
process_identifier:
3036
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x000002cc
suspend_count:
1
process_identifier:
3036
|
1
|
0 |
0
|
CreateProcessInternalW
|
thread_identifier:
2276
thread_handle:
0x00000324
process_identifier:
2292
current_directory:
filepath:
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe
track:
1
command_line:
"C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe" --locale=ko-kr --backgroundcolor=16514043
filepath_r:
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe
stack_pivoted:
0
creation_flags:
1040
(CREATE_NEW_CONSOLE|CREATE_UNICODE_ENVIRONMENT)
inherit_handles:
1
process_handle:
0x0000032c
|
1
|
1 |
0
|
NtResumeThread
|
thread_handle:
0x00000330
suspend_count:
1
process_identifier:
3036
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000340
suspend_count:
1
process_identifier:
3036
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000038c
suspend_count:
1
process_identifier:
3036
|
1
|
0 |
0
|
CreateProcessInternalW
|
thread_identifier:
1608
thread_handle:
0x00000340
process_identifier:
1620
current_directory:
filepath:
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe
track:
1
command_line:
"C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe" --locale=ko-kr --backgroundcolor=16514043
filepath_r:
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe
stack_pivoted:
0
creation_flags:
1040
(CREATE_NEW_CONSOLE|CREATE_UNICODE_ENVIRONMENT)
inherit_handles:
1
process_handle:
0x00000348
|
1
|
1 |
0
|
NtResumeThread
|
thread_handle:
0x00000340
suspend_count:
1
process_identifier:
3036
|
1
|
0 |
0
|
CreateProcessInternalW
|
thread_identifier:
1604
thread_handle:
0x0000053c
process_identifier:
1652
current_directory:
filepath:
track:
1
command_line:
"C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome "http://krishikannada.com/blo/hf98fh92.zip"
filepath_r:
stack_pivoted:
0
creation_flags:
0
()
inherit_handles:
0
process_handle:
0x00000528
|
1
|
1 |
0
|
CreateProcessInternalW
|
thread_identifier:
2692
thread_handle:
0x00000340
process_identifier:
2520
current_directory:
filepath:
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe
track:
1
command_line:
"C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe" --locale=ko-kr --backgroundcolor=16514043
filepath_r:
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe
stack_pivoted:
0
creation_flags:
1040
(CREATE_NEW_CONSOLE|CREATE_UNICODE_ENVIRONMENT)
inherit_handles:
1
process_handle:
0x00000348
|
1
|
1 |
0
|
NtResumeThread
|
thread_handle:
0x00000340
suspend_count:
1
process_identifier:
3036
|
1
|
0 |
0
|
CreateProcessInternalW
|
thread_identifier:
2828
thread_handle:
0x0000051c
process_identifier:
2852
current_directory:
filepath:
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe
track:
1
command_line:
"C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe" --locale=ko-kr --backgroundcolor=16514043
filepath_r:
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe
stack_pivoted:
0
creation_flags:
1040
(CREATE_NEW_CONSOLE|CREATE_UNICODE_ENVIRONMENT)
inherit_handles:
1
process_handle:
0x00000534
|
1
|
1 |
0
|
NtResumeThread
|
thread_handle:
0x0000051c
suspend_count:
1
process_identifier:
3036
|
1
|
0 |
0
|
CreateProcessInternalW
|
thread_identifier:
2980
thread_handle:
0x00000350
process_identifier:
2984
current_directory:
filepath:
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe
track:
1
command_line:
"C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe" --locale=ko-kr --backgroundcolor=16514043
filepath_r:
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe
stack_pivoted:
0
creation_flags:
1040
(CREATE_NEW_CONSOLE|CREATE_UNICODE_ENVIRONMENT)
inherit_handles:
1
process_handle:
0x00000534
|
1
|
1 |
0
|
NtResumeThread
|
thread_handle:
0x00000350
suspend_count:
1
process_identifier:
3036
|
1
|
0 |
0
|
CreateProcessInternalW
|
thread_identifier:
964
thread_handle:
0x00000350
process_identifier:
792
current_directory:
filepath:
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe
track:
1
command_line:
"C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe" --locale=ko-kr --backgroundcolor=16514043
filepath_r:
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe
stack_pivoted:
0
creation_flags:
1040
(CREATE_NEW_CONSOLE|CREATE_UNICODE_ENVIRONMENT)
inherit_handles:
1
process_handle:
0x00000534
|
1
|
1 |
0
|
NtResumeThread
|
thread_handle:
0x00000350
suspend_count:
1
process_identifier:
3036
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000051c
suspend_count:
1
process_identifier:
3036
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000548
suspend_count:
1
process_identifier:
3036
|
1
|
0 |
0
|
CreateProcessInternalW
|
thread_identifier:
1880
thread_handle:
0x00000360
process_identifier:
1844
current_directory:
filepath:
track:
1
command_line:
"C:\Program Files (x86)\Internet Explorer\iexplore.exe" SCODEF:1652 CREDAT:145409
filepath_r:
stack_pivoted:
0
creation_flags:
4
(CREATE_SUSPENDED)
inherit_handles:
0
process_handle:
0x00000364
|
1
|
1 |
0
|
NtResumeThread
|
thread_handle:
0x00000360
suspend_count:
1
process_identifier:
1844
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000438
suspend_count:
1
process_identifier:
1652
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000294
suspend_count:
1
process_identifier:
1652
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x000001f8
suspend_count:
1
process_identifier:
1844
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000022c
suspend_count:
1
process_identifier:
1844
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000238
suspend_count:
1
process_identifier:
1844
|
1
|
0 |
0
|
CreateProcessInternalW
|
thread_identifier:
3044
thread_handle:
0x0000000000000b8c
process_identifier:
3004
current_directory:
C:\Program Files (x86)\Google\Chrome\Application
filepath:
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
track:
1
command_line:
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
filepath_r:
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
stack_pivoted:
0
creation_flags:
67634196
(CREATE_DEFAULT_ERROR_MODE|CREATE_NEW_CONSOLE|CREATE_SUSPENDED|CREATE_UNICODE_ENVIRONMENT|EXTENDED_STARTUPINFO_PRESENT)
inherit_handles:
0
process_handle:
0x0000000000000b20
|
1
|
1 |
0
|
NtResumeThread
|
thread_handle:
0x0000000000000b8c
suspend_count:
1
process_identifier:
3004
|
1
|
0 |
0
|
CreateProcessInternalW
|
thread_identifier:
2456
thread_handle:
0x0000000000000b94
process_identifier:
2476
current_directory:
C:\Program Files (x86)\Google\Chrome\Application
filepath:
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
track:
1
command_line:
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
filepath_r:
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
stack_pivoted:
0
creation_flags:
67634196
(CREATE_DEFAULT_ERROR_MODE|CREATE_NEW_CONSOLE|CREATE_SUSPENDED|CREATE_UNICODE_ENVIRONMENT|EXTENDED_STARTUPINFO_PRESENT)
inherit_handles:
0
process_handle:
0x00000000000006ac
|
1
|
1 |
0
|
NtResumeThread
|
thread_handle:
0x0000000000000b94
suspend_count:
1
process_identifier:
2476
|
1
|
0 |
0
|
CreateProcessInternalW
|
thread_identifier:
1044
thread_handle:
0x0000000000000b20
process_identifier:
2120
current_directory:
C:\Program Files (x86)\Google\Chrome\Application
filepath:
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
track:
1
command_line:
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
filepath_r:
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
stack_pivoted:
0
creation_flags:
67634196
(CREATE_DEFAULT_ERROR_MODE|CREATE_NEW_CONSOLE|CREATE_SUSPENDED|CREATE_UNICODE_ENVIRONMENT|EXTENDED_STARTUPINFO_PRESENT)
inherit_handles:
0
process_handle:
0x00000000000003a0
|
1
|
1 |
0
|
NtResumeThread
|
thread_handle:
0x0000000000000b20
suspend_count:
1
process_identifier:
2120
|
1
|
0 |
0
|
CreateProcessInternalW
|
thread_identifier:
3236
thread_handle:
0x0000000000000564
process_identifier:
3232
current_directory:
C:\Program Files (x86)\Google\Chrome\Application
filepath:
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
track:
1
command_line:
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
filepath_r:
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
stack_pivoted:
0
creation_flags:
67634196
(CREATE_DEFAULT_ERROR_MODE|CREATE_NEW_CONSOLE|CREATE_SUSPENDED|CREATE_UNICODE_ENVIRONMENT|EXTENDED_STARTUPINFO_PRESENT)
inherit_handles:
0
process_handle:
0x0000000000000598
|
1
|
1 |
0
|
NtResumeThread
|
thread_handle:
0x0000000000000564
suspend_count:
1
process_identifier:
3232
|
1
|
0 |
0
|
CreateProcessInternalW
|
thread_identifier:
3536
thread_handle:
0x00000000000005c4
process_identifier:
3532
current_directory:
C:\Program Files\Mozilla Firefox
filepath:
C:\Program Files\Mozilla Firefox\firefox.exe
track:
1
command_line:
"C:\Program Files\Mozilla Firefox\firefox.exe"
filepath_r:
C:\Program Files\Mozilla Firefox\firefox.exe
stack_pivoted:
0
creation_flags:
67634196
(CREATE_DEFAULT_ERROR_MODE|CREATE_NEW_CONSOLE|CREATE_SUSPENDED|CREATE_UNICODE_ENVIRONMENT|EXTENDED_STARTUPINFO_PRESENT)
inherit_handles:
0
process_handle:
0x00000000000005c0
|
1
|
1 |
0
|
NtResumeThread
|
thread_handle:
0x00000000000005c4
suspend_count:
1
process_identifier:
3532
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000000000000078
suspend_count:
1
process_identifier:
3004
|
1
|
0 |
0
|
CreateProcessInternalW
|
thread_identifier:
1020
thread_handle:
0x00000000000000c0
process_identifier:
1968
current_directory:
filepath:
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
track:
1
command_line:
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\test22\AppData\Local\Google\Chrome\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\test22\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\test22\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=86.0.4240.111 --initial-client-data=0xb0,0xb4,0xb8,0x84,0xbc,0x7fef33c6e00,0x7fef33c6e10,0x7fef33c6e20
filepath_r:
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
stack_pivoted:
0
creation_flags:
524288
(EXTENDED_STARTUPINFO_PRESENT)
inherit_handles:
1
process_handle:
0x00000000000000c4
|
1
|
1 |
0
|
NtResumeThread
|
thread_handle:
0x00000000000000f0
suspend_count:
1
process_identifier:
1968
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000000000000078
suspend_count:
1
process_identifier:
2476
|
1
|
0 |
0
|
CreateProcessInternalW
|
thread_identifier:
3020
thread_handle:
0x00000000000000c0
process_identifier:
3024
current_directory:
filepath:
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
track:
1
command_line:
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\test22\AppData\Local\Google\Chrome\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\test22\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\test22\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=86.0.4240.111 --initial-client-data=0xb0,0xb4,0xb8,0x84,0xbc,0x7fef33c6e00,0x7fef33c6e10,0x7fef33c6e20
filepath_r:
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
stack_pivoted:
0
creation_flags:
524288
(EXTENDED_STARTUPINFO_PRESENT)
inherit_handles:
1
process_handle:
0x00000000000000c4
|
1
|
1 |
0
|
NtResumeThread
|
thread_handle:
0x00000000000000dc
suspend_count:
1
process_identifier:
3024
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000000000000078
suspend_count:
1
process_identifier:
2120
|
1
|
0 |
0
|
CreateProcessInternalW
|
thread_identifier:
2276
thread_handle:
0x00000000000000c0
process_identifier:
1596
current_directory:
filepath:
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
track:
1
command_line:
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\test22\AppData\Local\Google\Chrome\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\test22\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\test22\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=86.0.4240.111 --initial-client-data=0xb0,0xb4,0xb8,0x84,0xbc,0x7fef33c6e00,0x7fef33c6e10,0x7fef33c6e20
filepath_r:
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
stack_pivoted:
0
creation_flags:
524288
(EXTENDED_STARTUPINFO_PRESENT)
inherit_handles:
1
process_handle:
0x00000000000000c4
|
1
|
1 |
0
|
NtResumeThread
|
thread_handle:
0x00000000000000d4
suspend_count:
1
process_identifier:
1596
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000000000000078
suspend_count:
1
process_identifier:
3232
|
1
|
0 |
0
|
CreateProcessInternalW
|
thread_identifier:
3380
thread_handle:
0x00000000000000c0
process_identifier:
3376
current_directory:
filepath:
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
track:
1
command_line:
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\test22\AppData\Local\Google\Chrome\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\test22\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\test22\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=86.0.4240.111 --initial-client-data=0xb0,0xb4,0xb8,0x84,0xbc,0x7fef33c6e00,0x7fef33c6e10,0x7fef33c6e20
filepath_r:
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
stack_pivoted:
0
creation_flags:
524288
(EXTENDED_STARTUPINFO_PRESENT)
inherit_handles:
1
process_handle:
0x00000000000000c4
|
1
|
1 |
0
|