CreateProcessInternalW
|
thread_identifier:
2712
thread_handle:
0x000001b0
process_identifier:
2708
current_directory:
filepath:
track:
1
command_line:
C:\Users\test22\AppData\Local\Temp\WERFFG.txt.exe /stext "C:\Users\test22\AppData\Local\Temp\eqtqnfiklijwbogvkspkjzpdekiubz"
filepath_r:
stack_pivoted:
0
creation_flags:
4
(CREATE_SUSPENDED)
inherit_handles:
0
process_handle:
0x000002d4
|
1
|
1 |
0
|
NtGetContextThread
|
thread_handle:
0x000001b0
|
1
|
0 |
0
|
NtUnmapViewOfSection
|
base_address:
0x00400000
region_size:
4096
process_identifier:
2708
process_handle:
0x000002d4
|
1
|
0 |
0
|
NtMapViewOfSection
|
section_handle:
0x00000334
process_identifier:
2708
commit_size:
0
win32_protect:
64
(PAGE_EXECUTE_READWRITE)
buffer:
base_address:
0x00400000
allocation_type:
0
()
section_offset:
0
view_size:
491520
process_handle:
0x000002d4
|
1
|
0 |
0
|
NtSetContextThread
|
registers.eip:
1995571652
registers.esp:
1638384
registers.edi:
0
registers.eax:
4678260
registers.ebp:
0
registers.edx:
0
registers.ebx:
2130567168
registers.esi:
0
registers.ecx:
0
thread_handle:
0x000001b0
process_identifier:
2708
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x000001b0
suspend_count:
1
process_identifier:
2708
|
1
|
0 |
0
|
CreateProcessInternalW
|
thread_identifier:
2772
thread_handle:
0x000001b0
process_identifier:
2768
current_directory:
filepath:
track:
1
command_line:
C:\Users\test22\AppData\Local\Temp\WERFFG.txt.exe /stext "C:\Users\test22\AppData\Local\Temp\psyaoyslzqbblcczuuketdkumqsvckpadf"
filepath_r:
stack_pivoted:
0
creation_flags:
4
(CREATE_SUSPENDED)
inherit_handles:
0
process_handle:
0x000002d4
|
1
|
1 |
0
|
NtGetContextThread
|
thread_handle:
0x000001b0
|
1
|
0 |
0
|
NtUnmapViewOfSection
|
base_address:
0x00400000
region_size:
4096
process_identifier:
2768
process_handle:
0x000002d4
|
1
|
0 |
0
|
NtMapViewOfSection
|
section_handle:
0x00000338
process_identifier:
2768
commit_size:
0
win32_protect:
64
(PAGE_EXECUTE_READWRITE)
buffer:
base_address:
0x00400000
allocation_type:
0
()
section_offset:
0
view_size:
401408
process_handle:
0x000002d4
|
1
|
0 |
0
|
NtSetContextThread
|
registers.eip:
1995571652
registers.esp:
1638384
registers.edi:
0
registers.eax:
4583992
registers.ebp:
0
registers.edx:
0
registers.ebx:
2130567168
registers.esi:
0
registers.ecx:
0
thread_handle:
0x000001b0
process_identifier:
2768
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x000001b0
suspend_count:
1
process_identifier:
2768
|
1
|
0 |
0
|
CreateProcessInternalW
|
thread_identifier:
2836
thread_handle:
0x000001b0
process_identifier:
2832
current_directory:
filepath:
track:
1
command_line:
C:\Users\test22\AppData\Local\Temp\WERFFG.txt.exe /stext "C:\Users\test22\AppData\Local\Temp\zmetoq"
filepath_r:
stack_pivoted:
0
creation_flags:
4
(CREATE_SUSPENDED)
inherit_handles:
0
process_handle:
0x000002d4
|
1
|
1 |
0
|
NtGetContextThread
|
thread_handle:
0x000001b0
|
1
|
0 |
0
|
NtUnmapViewOfSection
|
base_address:
0x00400000
region_size:
4096
process_identifier:
2832
process_handle:
0x000002d4
|
1
|
0 |
0
|
NtMapViewOfSection
|
section_handle:
0x0000033c
process_identifier:
2832
commit_size:
0
win32_protect:
64
(PAGE_EXECUTE_READWRITE)
buffer:
base_address:
0x00400000
allocation_type:
0
()
section_offset:
0
view_size:
147456
process_handle:
0x000002d4
|
1
|
0 |
0
|
NtSetContextThread
|
registers.eip:
1995571652
registers.esp:
1638384
registers.edi:
0
registers.eax:
4334086
registers.ebp:
0
registers.edx:
0
registers.ebx:
2130567168
registers.esi:
0
registers.ecx:
0
thread_handle:
0x000001b0
process_identifier:
2832
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x000001b0
suspend_count:
1
process_identifier:
2832
|
1
|
0 |
0
|
CreateProcessInternalW
|
thread_identifier:
2960
thread_handle:
0x000001b0
process_identifier:
2956
current_directory:
filepath:
track:
1
command_line:
C:\Users\test22\AppData\Local\Temp\WERFFG.txt.exe /stext "C:\Users\test22\AppData\Local\Temp\tbzktppqidxzzjvjerkymrily"
filepath_r:
stack_pivoted:
0
creation_flags:
4
(CREATE_SUSPENDED)
inherit_handles:
0
process_handle:
0x000002d4
|
1
|
1 |
0
|
NtGetContextThread
|
thread_handle:
0x000001b0
|
1
|
0 |
0
|
NtUnmapViewOfSection
|
base_address:
0x00400000
region_size:
4096
process_identifier:
2956
process_handle:
0x000002d4
|
1
|
0 |
0
|
NtMapViewOfSection
|
section_handle:
0x00000340
process_identifier:
2956
commit_size:
0
win32_protect:
64
(PAGE_EXECUTE_READWRITE)
buffer:
base_address:
0x00400000
allocation_type:
0
()
section_offset:
0
view_size:
491520
process_handle:
0x000002d4
|
1
|
0 |
0
|
NtSetContextThread
|
registers.eip:
1995571652
registers.esp:
1638384
registers.edi:
0
registers.eax:
4678260
registers.ebp:
0
registers.edx:
0
registers.ebx:
2130567168
registers.esi:
0
registers.ecx:
0
thread_handle:
0x000001b0
process_identifier:
2956
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x000001b0
suspend_count:
1
process_identifier:
2956
|
1
|
0 |
0
|
CreateProcessInternalW
|
thread_identifier:
3020
thread_handle:
0x000001b0
process_identifier:
3016
current_directory:
filepath:
track:
1
command_line:
C:\Users\test22\AppData\Local\Temp\WERFFG.txt.exe /stext "C:\Users\test22\AppData\Local\Temp\wvfdlhaswlpmkpjnvcxaxeduhpxzx"
filepath_r:
stack_pivoted:
0
creation_flags:
4
(CREATE_SUSPENDED)
inherit_handles:
0
process_handle:
0x000002d4
|
1
|
1 |
0
|
NtGetContextThread
|
thread_handle:
0x000001b0
|
1
|
0 |
0
|
NtUnmapViewOfSection
|
base_address:
0x00400000
region_size:
4096
process_identifier:
3016
process_handle:
0x000002d4
|
1
|
0 |
0
|
NtMapViewOfSection
|
section_handle:
0x00000344
process_identifier:
3016
commit_size:
0
win32_protect:
64
(PAGE_EXECUTE_READWRITE)
buffer:
base_address:
0x00400000
allocation_type:
0
()
section_offset:
0
view_size:
401408
process_handle:
0x000002d4
|
1
|
0 |
0
|
NtSetContextThread
|
registers.eip:
1995571652
registers.esp:
1638384
registers.edi:
0
registers.eax:
4583992
registers.ebp:
0
registers.edx:
0
registers.ebx:
2130567168
registers.esi:
0
registers.ecx:
0
thread_handle:
0x000001b0
process_identifier:
3016
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x000001b0
suspend_count:
1
process_identifier:
3016
|
1
|
0 |
0
|
CreateProcessInternalW
|
thread_identifier:
1120
thread_handle:
0x000001b0
process_identifier:
1216
current_directory:
filepath:
track:
1
command_line:
C:\Users\test22\AppData\Local\Temp\WERFFG.txt.exe /stext "C:\Users\test22\AppData\Local\Temp\gxkvmallkthrmdfrfnktajxlpvpiqwib"
filepath_r:
stack_pivoted:
0
creation_flags:
4
(CREATE_SUSPENDED)
inherit_handles:
0
process_handle:
0x000002d4
|
1
|
1 |
0
|
NtGetContextThread
|
thread_handle:
0x000001b0
|
1
|
0 |
0
|
NtUnmapViewOfSection
|
base_address:
0x00400000
region_size:
4096
process_identifier:
1216
process_handle:
0x000002d4
|
1
|
0 |
0
|
NtMapViewOfSection
|
section_handle:
0x00000348
process_identifier:
1216
commit_size:
0
win32_protect:
64
(PAGE_EXECUTE_READWRITE)
buffer:
base_address:
0x00400000
allocation_type:
0
()
section_offset:
0
view_size:
147456
process_handle:
0x000002d4
|
1
|
0 |
0
|
NtSetContextThread
|
registers.eip:
1995571652
registers.esp:
1638384
registers.edi:
0
registers.eax:
4334086
registers.ebp:
0
registers.edx:
0
registers.ebx:
2130567168
registers.esi:
0
registers.ecx:
0
thread_handle:
0x000001b0
process_identifier:
1216
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x000001b0
suspend_count:
1
process_identifier:
1216
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000108
suspend_count:
1
process_identifier:
2708
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x000000fc
suspend_count:
1
process_identifier:
2768
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000108
suspend_count:
1
process_identifier:
2956
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x000000fc
suspend_count:
1
process_identifier:
3016
|
1
|
0 |
0
|