NtResumeThread
|
thread_handle:
0x000001d8
suspend_count:
1
process_identifier:
1932
|
1
|
0 |
0
|
CreateProcessInternalW
|
thread_identifier:
2064
thread_handle:
0x00000208
process_identifier:
2060
current_directory:
C:\Users\test22\AppData\Local\Temp\
filepath:
C:\Windows\sysnative\cmd.exe
track:
1
command_line:
"C:\Windows\sysnative\cmd.exe" /c "C:\Users\test22\AppData\Local\Temp\BFEF.tmp\BFF0.tmp\C001.bat C:\Users\test22\AppData\Local\Temp\random.exe"
filepath_r:
C:\Windows\sysnative\cmd.exe
stack_pivoted:
0
creation_flags:
67634196
(CREATE_DEFAULT_ERROR_MODE|CREATE_NEW_CONSOLE|CREATE_SUSPENDED|CREATE_UNICODE_ENVIRONMENT|EXTENDED_STARTUPINFO_PRESENT)
inherit_handles:
0
process_handle:
0x00000210
|
1
|
1 |
0
|
NtResumeThread
|
thread_handle:
0x00000208
suspend_count:
1
process_identifier:
2060
|
1
|
0 |
0
|
CreateProcessInternalW
|
thread_identifier:
2160
thread_handle:
0x000000000000006c
process_identifier:
2156
current_directory:
filepath:
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
track:
1
command_line:
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" "https://accounts.google.com/ServiceLogin?service=accountsettings&continue=https://accounts.google.com/v3/signin/challenge/pwd"
filepath_r:
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
stack_pivoted:
0
creation_flags:
525328
(CREATE_NEW_CONSOLE|CREATE_UNICODE_ENVIRONMENT|EXTENDED_STARTUPINFO_PRESENT)
inherit_handles:
1
process_handle:
0x0000000000000068
|
1
|
1 |
0
|
NtResumeThread
|
thread_handle:
0x000000000000006c
suspend_count:
0
process_identifier:
2156
|
1
|
0 |
0
|
CreateProcessInternalW
|
thread_identifier:
2244
thread_handle:
0x0000000000000068
process_identifier:
2240
current_directory:
filepath:
C:\Program Files\Mozilla Firefox\firefox.exe
track:
1
command_line:
"C:\Program Files\Mozilla Firefox\firefox.exe" "https://accounts.google.com/ServiceLogin?service=accountsettings&continue=https://accounts.google.com/v3/signin/challenge/pwd"
filepath_r:
C:\Program Files\Mozilla Firefox\firefox.exe
stack_pivoted:
0
creation_flags:
525328
(CREATE_NEW_CONSOLE|CREATE_UNICODE_ENVIRONMENT|EXTENDED_STARTUPINFO_PRESENT)
inherit_handles:
1
process_handle:
0x000000000000006c
|
1
|
1 |
0
|
NtResumeThread
|
thread_handle:
0x0000000000000068
suspend_count:
0
process_identifier:
2240
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000000000000078
suspend_count:
1
process_identifier:
2156
|
1
|
0 |
0
|
CreateProcessInternalW
|
thread_identifier:
2304
thread_handle:
0x00000000000000c0
process_identifier:
2300
current_directory:
filepath:
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
track:
1
command_line:
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\test22\AppData\Local\Google\Chrome\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\test22\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\test22\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=86.0.4240.111 --initial-client-data=0xb0,0xb4,0xb8,0x84,0xbc,0x7fef3e36e00,0x7fef3e36e10,0x7fef3e36e20
filepath_r:
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
stack_pivoted:
0
creation_flags:
524288
(EXTENDED_STARTUPINFO_PRESENT)
inherit_handles:
1
process_handle:
0x00000000000000c4
|
1
|
1 |
0
|
CreateProcessInternalW
|
thread_identifier:
2256
thread_handle:
0x0000000000000508
process_identifier:
2252
current_directory:
filepath:
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
track:
1
command_line:
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=1064,405328435193604317,3726656886444491162,131072 --gpu-preferences=MAAAAAAAAADgAAAwAAAAAAAAAAAAAAAAAABgAAAAAAAQAAAAAAAAAAAAAAAAAAAAKAAAAAQAAAAgAAAAAAAAACgAAAAAAAAAMAAAAAAAAAA4AAAAAAAAABAAAAAAAAAAAAAAAAUAAAAQAAAAAAAAAAAAAAAGAAAAEAAAAAAAAAABAAAABQAAABAAAAAAAAAAAQAAAAYAAAA= --use-gl=swiftshader-webgl --mojo-platform-channel-handle=1032 /prefetch:2
filepath_r:
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
stack_pivoted:
0
creation_flags:
17302540
(CREATE_BREAKAWAY_FROM_JOB|CREATE_SUSPENDED|CREATE_UNICODE_ENVIRONMENT|DETACHED_PROCESS|EXTENDED_STARTUPINFO_PRESENT)
inherit_handles:
1
process_handle:
0x0000000000000510
|
1
|
1 |
0
|
NtResumeThread
|
thread_handle:
0x00000000000000e0
suspend_count:
1
process_identifier:
2300
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x0000000000000114
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000000000000114
suspend_count:
2
process_identifier:
2156
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x0000000000000114
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000000000000114
suspend_count:
2
process_identifier:
2156
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x0000000000000114
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000000000000114
suspend_count:
2
process_identifier:
2156
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x0000000000000114
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000000000000114
suspend_count:
2
process_identifier:
2156
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x0000000000000114
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000000000000114
suspend_count:
2
process_identifier:
2156
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x0000000000000114
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000000000000114
suspend_count:
2
process_identifier:
2156
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x0000000000000114
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000000000000114
suspend_count:
2
process_identifier:
2156
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x0000000000000114
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000000000000114
suspend_count:
2
process_identifier:
2156
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x0000000000000114
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000000000000114
suspend_count:
2
process_identifier:
2156
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x0000000000000114
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000000000000114
suspend_count:
2
process_identifier:
2156
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x0000000000000114
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000000000000114
suspend_count:
2
process_identifier:
2156
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x0000000000000114
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000000000000114
suspend_count:
2
process_identifier:
2156
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x0000000000000114
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000000000000114
suspend_count:
2
process_identifier:
2156
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x0000000000000114
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000000000000114
suspend_count:
2
process_identifier:
2156
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x0000000000000114
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000000000000114
suspend_count:
2
process_identifier:
2156
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x0000000000000114
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000000000000114
suspend_count:
2
process_identifier:
2156
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x0000000000000114
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000000000000114
suspend_count:
2
process_identifier:
2156
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x0000000000000114
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000000000000114
suspend_count:
2
process_identifier:
2156
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x0000000000000114
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000000000000114
suspend_count:
2
process_identifier:
2156
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x0000000000000114
|
1
|
0 |
0
|