NtResumeThread
|
thread_handle:
0x00000284
suspend_count:
1
process_identifier:
1648
|
1
|
0 |
0
|
CreateProcessInternalW
|
thread_identifier:
2120
thread_handle:
0x000002a4
process_identifier:
2116
current_directory:
C:\Users\test22\AppData\Local\Temp
filepath:
C:\Program Files\Mozilla Firefox\firefox.exe
track:
1
command_line:
"C:\Program Files\Mozilla Firefox\firefox.exe" https://www.youtube.com/account
filepath_r:
C:\Program Files\Mozilla Firefox\firefox.exe
stack_pivoted:
0
creation_flags:
67634196
(CREATE_DEFAULT_ERROR_MODE|CREATE_NEW_CONSOLE|CREATE_SUSPENDED|CREATE_UNICODE_ENVIRONMENT|EXTENDED_STARTUPINFO_PRESENT)
inherit_handles:
0
process_handle:
0x000002ac
|
1
|
1 |
0
|
NtResumeThread
|
thread_handle:
0x000002a4
suspend_count:
1
process_identifier:
2116
|
1
|
0 |
0
|
CreateProcessInternalW
|
thread_identifier:
2192
thread_handle:
0x0000000000000044
process_identifier:
2188
current_directory:
filepath:
C:\Program Files\Mozilla Firefox\firefox.exe
track:
1
command_line:
"C:\Program Files\Mozilla Firefox\firefox.exe" https://www.youtube.com/account
filepath_r:
C:\Program Files\Mozilla Firefox\firefox.exe
stack_pivoted:
0
creation_flags:
1028
(CREATE_SUSPENDED|CREATE_UNICODE_ENVIRONMENT)
inherit_handles:
0
process_handle:
0x000000000000004c
|
1
|
1 |
0
|
WriteProcessMemory
|
buffer:
base_address:
0x000000013f8922b0
process_identifier:
2188
process_handle:
0x000000000000004c
|
1
|
1 |
0
|
WriteProcessMemory
|
buffer:
base_address:
0x000000013f8a0d88
process_identifier:
2188
process_handle:
0x000000000000004c
|
1
|
1 |
0
|
NtMapViewOfSection
|
section_handle:
0x0000000000000060
process_identifier:
2188
commit_size:
0
win32_protect:
32
(PAGE_EXECUTE_READ)
buffer:
base_address:
0x0000000075660000
allocation_type:
0
()
section_offset:
0
view_size:
65536
process_handle:
0x0000000000000050
|
1
|
0 |
0
|
NtAllocateVirtualMemory
|
process_identifier:
2188
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
32
(PAGE_EXECUTE_READ)
base_address:
0x0000000075660000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0x0000000000000050
|
1
|
0 |
0
|
WriteProcessMemory
|
buffer:
I»`#? Aÿã
base_address:
0x0000000077711590
process_identifier:
2188
process_handle:
0x0000000000000050
|
1
|
1 |
0
|
WriteProcessMemory
|
buffer:
fu
base_address:
0x000000013f8a0d78
process_identifier:
2188
process_handle:
0x000000000000004c
|
1
|
1 |
0
|
WriteProcessMemory
|
buffer:
I» ? Aÿã
base_address:
0x00000000776e7a90
process_identifier:
2188
process_handle:
0x0000000000000050
|
1
|
1 |
0
|
WriteProcessMemory
|
buffer:
fu
base_address:
0x000000013f8a0d70
process_identifier:
2188
process_handle:
0x000000000000004c
|
1
|
1 |
0
|
WriteProcessMemory
|
buffer:
Ï T
base_address:
0x000000013f840108
process_identifier:
2188
process_handle:
0x000000000000004c
|
1
|
1 |
0
|
WriteProcessMemory
|
buffer:
qw @qw qw @qw qw °qw nw àTnw 3qw qw À´lw `,qw Àow ömw Yqw 2qw Vqw °ww nw Rqw nw Qqw Ânw ?ow Pnw °Tnw àtnw ðow Ð1qw mw ÐOmw `êpw Ðæpw Ðæpw Ð.qw
base_address:
0x000000013f89aae8
process_identifier:
2188
process_handle:
0x000000000000004c
|
1
|
1 |
0
|
WriteProcessMemory
|
buffer:
base_address:
0x000000013f8a0c78
process_identifier:
2188
process_handle:
0x000000000000004c
|
1
|
1 |
0
|
NtResumeThread
|
thread_handle:
0x0000000000000044
suspend_count:
1
process_identifier:
2188
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x000000000000016c
suspend_count:
1
process_identifier:
2188
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x0000000000000230
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x0000000000000238
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x000000000000023c
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x0000000000000240
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x0000000000000244
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x0000000000000248
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x000000000000024c
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x0000000000000250
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000000000000230
suspend_count:
1
process_identifier:
2188
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000000000000238
suspend_count:
1
process_identifier:
2188
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x000000000000023c
suspend_count:
1
process_identifier:
2188
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000000000000240
suspend_count:
1
process_identifier:
2188
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000000000000248
suspend_count:
1
process_identifier:
2188
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x000000000000024c
suspend_count:
1
process_identifier:
2188
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000000000000250
suspend_count:
1
process_identifier:
2188
|
1
|
0 |
0
|
CreateProcessInternalW
|
thread_identifier:
2668
thread_handle:
0x00000000000001f8
process_identifier:
2664
current_directory:
filepath:
track:
1
command_line:
"C:\Program Files\Mozilla Firefox\crashreporter.exe" "C:\Users\test22\AppData\Roaming\Mozilla\Firefox\Profiles\1pfa5s83.default-release\minidumps\8262ecc5-5978-42cb-89b5-8d0c80d5ab36.dmp"
filepath_r:
stack_pivoted:
0
creation_flags:
150994976
(CREATE_BREAKAWAY_FROM_JOB|CREATE_NO_WINDOW|NORMAL_PRIORITY_CLASS)
inherit_handles:
0
process_handle:
0x000000000000021c
|
1
|
1 |
0
|
CreateProcessInternalW
|
thread_identifier:
2716
thread_handle:
0x00000000000000a0
process_identifier:
2712
current_directory:
filepath:
track:
1
command_line:
"C:\Program Files\Mozilla Firefox\minidump-analyzer.exe" "C:\Users\test22\AppData\Roaming\Mozilla\Firefox\Profiles\1pfa5s83.default-release\minidumps\8262ecc5-5978-42cb-89b5-8d0c80d5ab36.dmp"
filepath_r:
stack_pivoted:
0
creation_flags:
134217760
(CREATE_NO_WINDOW|NORMAL_PRIORITY_CLASS)
inherit_handles:
0
process_handle:
0x00000000000000a4
|
1
|
1 |
0
|
NtResumeThread
|
thread_handle:
0x0000000000000150
suspend_count:
1
process_identifier:
2664
|
1
|
0 |
0
|
CreateProcessInternalW
|
thread_identifier:
2820
thread_handle:
0x0000000000000164
process_identifier:
2816
current_directory:
filepath:
track:
1
command_line:
"C:\Program Files\Mozilla Firefox\firefox.exe" "https://www.youtube.com/account"
filepath_r:
stack_pivoted:
0
creation_flags:
0
()
inherit_handles:
0
process_handle:
0x0000000000000168
|
1
|
1 |
0
|
CreateProcessInternalW
|
thread_identifier:
2960
thread_handle:
0x0000000000000304
process_identifier:
2956
current_directory:
filepath:
track:
1
command_line:
"C:\Program Files\Mozilla Firefox\firefox.exe" "https://www.youtube.com/account"
filepath_r:
stack_pivoted:
0
creation_flags:
0
()
inherit_handles:
0
process_handle:
0x0000000000000170
|
1
|
1 |
0
|
NtResumeThread
|
thread_handle:
0x00000000000000c0
suspend_count:
1
process_identifier:
2712
|
1
|
0 |
0
|
CreateProcessInternalW
|
thread_identifier:
2868
thread_handle:
0x0000000000000044
process_identifier:
2864
current_directory:
filepath:
C:\Program Files\Mozilla Firefox\firefox.exe
track:
1
command_line:
"C:\Program Files\Mozilla Firefox\firefox.exe" https://www.youtube.com/account
filepath_r:
C:\Program Files\Mozilla Firefox\firefox.exe
stack_pivoted:
0
creation_flags:
1028
(CREATE_SUSPENDED|CREATE_UNICODE_ENVIRONMENT)
inherit_handles:
0
process_handle:
0x0000000000000048
|
1
|
1 |
0
|
WriteProcessMemory
|
buffer:
base_address:
0x000000013f3022b0
process_identifier:
2864
process_handle:
0x0000000000000048
|
1
|
1 |
0
|
WriteProcessMemory
|
buffer:
base_address:
0x000000013f310d88
process_identifier:
2864
process_handle:
0x0000000000000048
|
1
|
1 |
0
|
NtMapViewOfSection
|
section_handle:
0x000000000000005c
process_identifier:
2864
commit_size:
0
win32_protect:
32
(PAGE_EXECUTE_READ)
buffer:
base_address:
0x0000000000900000
allocation_type:
0
()
section_offset:
0
view_size:
65536
process_handle:
0x000000000000004c
|
1
|
0 |
0
|
NtAllocateVirtualMemory
|
process_identifier:
2864
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
32
(PAGE_EXECUTE_READ)
base_address:
0x0000000000900000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0x000000000000004c
|
1
|
0 |
0
|
WriteProcessMemory
|
buffer:
I»`#-? Aÿã
base_address:
0x0000000077711590
process_identifier:
2864
process_handle:
0x000000000000004c
|
1
|
1 |
0
|
WriteProcessMemory
|
buffer:
base_address:
0x000000013f310d78
process_identifier:
2864
process_handle:
0x0000000000000048
|
1
|
1 |
0
|
WriteProcessMemory
|
buffer:
I» -? Aÿã
base_address:
0x00000000776e7a90
process_identifier:
2864
process_handle:
0x000000000000004c
|
1
|
1 |
0
|
WriteProcessMemory
|
buffer:
base_address:
0x000000013f310d70
process_identifier:
2864
process_handle:
0x0000000000000048
|
1
|
1 |
0
|
WriteProcessMemory
|
buffer:
Ï T
base_address:
0x000000013f2b0108
process_identifier:
2864
process_handle:
0x0000000000000048
|
1
|
1 |
0
|
WriteProcessMemory
|
buffer:
qw @qw qw @qw qw °qw nw àTnw 3qw qw À´lw `,qw Àow ömw Yqw 2qw Vqw °ww nw Rqw nw Qqw Ânw ?ow Pnw °Tnw àtnw ðow Ð1qw mw ÐOmw `êpw Ðæpw Ðæpw Ð.qw
base_address:
0x000000013f30aae8
process_identifier:
2864
process_handle:
0x0000000000000048
|
1
|
1 |
0
|
WriteProcessMemory
|
buffer:
base_address:
0x000000013f310c78
process_identifier:
2864
process_handle:
0x0000000000000048
|
1
|
1 |
0
|