NtResumeThread
|
thread_handle:
0x000001d8
suspend_count:
1
process_identifier:
2436
|
1
|
0 |
0
|
CreateProcessInternalW
|
thread_identifier:
2604
thread_handle:
0x00000218
process_identifier:
2600
current_directory:
C:\Users\test22\AppData\Local\Temp\
filepath:
C:\Windows\sysnative\cmd.exe
track:
1
command_line:
"C:\Windows\sysnative\cmd.exe" /c "C:\Users\test22\AppData\Local\Temp\F112.tmp\F122.tmp\F123.bat C:\Users\test22\AppData\Local\Temp\random.exe"
filepath_r:
C:\Windows\sysnative\cmd.exe
stack_pivoted:
0
creation_flags:
67634196
(CREATE_DEFAULT_ERROR_MODE|CREATE_NEW_CONSOLE|CREATE_SUSPENDED|CREATE_UNICODE_ENVIRONMENT|EXTENDED_STARTUPINFO_PRESENT)
inherit_handles:
0
process_handle:
0x0000021c
|
1
|
1 |
0
|
NtResumeThread
|
thread_handle:
0x00000218
suspend_count:
1
process_identifier:
2600
|
1
|
0 |
0
|
CreateProcessInternalW
|
thread_identifier:
2700
thread_handle:
0x000000000000006c
process_identifier:
2696
current_directory:
filepath:
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
track:
1
command_line:
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" "https://accounts.google.com/ServiceLogin?service=accountsettings&continue=https://accounts.google.com/v3/signin/challenge/pwd"
filepath_r:
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
stack_pivoted:
0
creation_flags:
525328
(CREATE_NEW_CONSOLE|CREATE_UNICODE_ENVIRONMENT|EXTENDED_STARTUPINFO_PRESENT)
inherit_handles:
1
process_handle:
0x0000000000000068
|
1
|
1 |
0
|
NtResumeThread
|
thread_handle:
0x000000000000006c
suspend_count:
0
process_identifier:
2696
|
1
|
0 |
0
|
CreateProcessInternalW
|
thread_identifier:
2780
thread_handle:
0x0000000000000068
process_identifier:
2776
current_directory:
filepath:
C:\Program Files\Mozilla Firefox\firefox.exe
track:
1
command_line:
"C:\Program Files\Mozilla Firefox\firefox.exe" "https://accounts.google.com/ServiceLogin?service=accountsettings&continue=https://accounts.google.com/v3/signin/challenge/pwd"
filepath_r:
C:\Program Files\Mozilla Firefox\firefox.exe
stack_pivoted:
0
creation_flags:
525328
(CREATE_NEW_CONSOLE|CREATE_UNICODE_ENVIRONMENT|EXTENDED_STARTUPINFO_PRESENT)
inherit_handles:
1
process_handle:
0x000000000000006c
|
1
|
1 |
0
|
NtResumeThread
|
thread_handle:
0x0000000000000068
suspend_count:
0
process_identifier:
2776
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000000000000078
suspend_count:
1
process_identifier:
2696
|
1
|
0 |
0
|
CreateProcessInternalW
|
thread_identifier:
2852
thread_handle:
0x00000000000000c0
process_identifier:
2848
current_directory:
filepath:
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
track:
1
command_line:
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\test22\AppData\Local\Google\Chrome\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\test22\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\test22\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=86.0.4240.111 --initial-client-data=0xb0,0xb4,0xb8,0x84,0xbc,0x7fef2f46e00,0x7fef2f46e10,0x7fef2f46e20
filepath_r:
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
stack_pivoted:
0
creation_flags:
524288
(EXTENDED_STARTUPINFO_PRESENT)
inherit_handles:
1
process_handle:
0x00000000000000c4
|
1
|
1 |
0
|
CreateProcessInternalW
|
thread_identifier:
2280
thread_handle:
0x000000000000054c
process_identifier:
2136
current_directory:
filepath:
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
track:
1
command_line:
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=1032,5541684671558472443,12650463613368348251,131072 --gpu-preferences=MAAAAAAAAADgAAAwAAAAAAAAAAAAAAAAAABgAAAAAAAQAAAAAAAAAAAAAAAAAAAAKAAAAAQAAAAgAAAAAAAAACgAAAAAAAAAMAAAAAAAAAA4AAAAAAAAABAAAAAAAAAAAAAAAAUAAAAQAAAAAAAAAAAAAAAGAAAAEAAAAAAAAAABAAAABQAAABAAAAAAAAAAAQAAAAYAAAA= --use-gl=swiftshader-webgl --mojo-platform-channel-handle=1020 /prefetch:2
filepath_r:
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
stack_pivoted:
0
creation_flags:
17302540
(CREATE_BREAKAWAY_FROM_JOB|CREATE_SUSPENDED|CREATE_UNICODE_ENVIRONMENT|DETACHED_PROCESS|EXTENDED_STARTUPINFO_PRESENT)
inherit_handles:
1
process_handle:
0x0000000000000550
|
1
|
1 |
0
|
CreateProcessInternalW
|
thread_identifier:
2896
thread_handle:
0x000000000000004c
process_identifier:
2892
current_directory:
filepath:
C:\Program Files\Mozilla Firefox\firefox.exe
track:
1
command_line:
"C:\Program Files\Mozilla Firefox\firefox.exe" https://accounts.google.com/ServiceLogin?service=accountsettings&continue=https://accounts.google.com/v3/signin/challenge/pwd
filepath_r:
C:\Program Files\Mozilla Firefox\firefox.exe
stack_pivoted:
0
creation_flags:
1028
(CREATE_SUSPENDED|CREATE_UNICODE_ENVIRONMENT)
inherit_handles:
0
process_handle:
0x0000000000000054
|
1
|
1 |
0
|
WriteProcessMemory
|
buffer:
base_address:
0x000000013fc122b0
process_identifier:
2892
process_handle:
0x0000000000000054
|
1
|
1 |
0
|
WriteProcessMemory
|
buffer:
base_address:
0x000000013fc20d88
process_identifier:
2892
process_handle:
0x0000000000000054
|
1
|
1 |
0
|
NtMapViewOfSection
|
section_handle:
0x0000000000000068
process_identifier:
2892
commit_size:
0
win32_protect:
32
(PAGE_EXECUTE_READ)
buffer:
base_address:
0x0000000077010000
allocation_type:
0
()
section_offset:
0
view_size:
65536
process_handle:
0x0000000000000058
|
1
|
0 |
0
|
NtAllocateVirtualMemory
|
process_identifier:
2892
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
32
(PAGE_EXECUTE_READ)
base_address:
0x0000000077010000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0x0000000000000058
|
1
|
0 |
0
|
WriteProcessMemory
|
buffer:
I»`#¾? Aÿã
base_address:
0x0000000077711590
process_identifier:
2892
process_handle:
0x0000000000000058
|
1
|
1 |
0
|
WriteProcessMemory
|
buffer:
w
base_address:
0x000000013fc20d78
process_identifier:
2892
process_handle:
0x0000000000000054
|
1
|
1 |
0
|
WriteProcessMemory
|
buffer:
I» ¾? Aÿã
base_address:
0x00000000776e7a90
process_identifier:
2892
process_handle:
0x0000000000000058
|
1
|
1 |
0
|
WriteProcessMemory
|
buffer:
w
base_address:
0x000000013fc20d70
process_identifier:
2892
process_handle:
0x0000000000000054
|
1
|
1 |
0
|
WriteProcessMemory
|
buffer:
Ï T
base_address:
0x000000013fbc0108
process_identifier:
2892
process_handle:
0x0000000000000054
|
1
|
1 |
0
|
WriteProcessMemory
|
buffer:
qw @qw qw @qw qw °qw nw àTnw 3qw qw À´lw `,qw Àow ömw Yqw 2qw Vqw °ww nw Rqw nw Qqw Ânw ?ow Pnw °Tnw àtnw ðow Ð1qw mw ÐOmw `êpw Ðæpw Ðæpw Ð.qw
base_address:
0x000000013fc1aae8
process_identifier:
2892
process_handle:
0x0000000000000054
|
1
|
1 |
0
|
WriteProcessMemory
|
buffer:
base_address:
0x000000013fc20c78
process_identifier:
2892
process_handle:
0x0000000000000054
|
1
|
1 |
0
|
NtResumeThread
|
thread_handle:
0x000000000000004c
suspend_count:
1
process_identifier:
2892
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000000000000f0
suspend_count:
1
process_identifier:
2848
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x0000000000000118
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000000000000118
suspend_count:
2
process_identifier:
2696
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x0000000000000118
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000000000000118
suspend_count:
2
process_identifier:
2696
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x0000000000000118
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000000000000118
suspend_count:
2
process_identifier:
2696
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x0000000000000118
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000000000000118
suspend_count:
2
process_identifier:
2696
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x0000000000000118
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000000000000118
suspend_count:
2
process_identifier:
2696
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x0000000000000118
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000000000000118
suspend_count:
2
process_identifier:
2696
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x0000000000000118
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000000000000118
suspend_count:
2
process_identifier:
2696
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x0000000000000118
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000000000000118
suspend_count:
2
process_identifier:
2696
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x0000000000000118
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000000000000118
suspend_count:
2
process_identifier:
2696
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x0000000000000118
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000000000000118
suspend_count:
2
process_identifier:
2696
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x0000000000000118
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000000000000118
suspend_count:
2
process_identifier:
2696
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x0000000000000118
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000000000000118
suspend_count:
2
process_identifier:
2696
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x0000000000000118
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000000000000118
suspend_count:
2
process_identifier:
2696
|
1
|
0 |
0
|