CreateProcessInternalW
|
thread_identifier:
2720
thread_handle:
0x000001b0
process_identifier:
2716
current_directory:
filepath:
track:
1
command_line:
C:\Users\test22\AppData\Local\Temp\RNOLL.txt.exe /stext "C:\Users\test22\AppData\Local\Temp\vxqfthlyepaiilrbgazioeyntvwujbi"
filepath_r:
stack_pivoted:
0
creation_flags:
4
(CREATE_SUSPENDED)
inherit_handles:
0
process_handle:
0x000002d0
|
1
|
1 |
0
|
NtGetContextThread
|
thread_handle:
0x000001b0
|
1
|
0 |
0
|
NtUnmapViewOfSection
|
base_address:
0x00400000
region_size:
4096
process_identifier:
2716
process_handle:
0x000002d0
|
1
|
0 |
0
|
NtMapViewOfSection
|
section_handle:
0x00000338
process_identifier:
2716
commit_size:
0
win32_protect:
64
(PAGE_EXECUTE_READWRITE)
buffer:
base_address:
0x00400000
allocation_type:
0
()
section_offset:
0
view_size:
491520
process_handle:
0x000002d0
|
1
|
0 |
0
|
NtSetContextThread
|
registers.eip:
1995571652
registers.esp:
1638384
registers.edi:
0
registers.eax:
4678260
registers.ebp:
0
registers.edx:
0
registers.ebx:
2130567168
registers.esi:
0
registers.ecx:
0
thread_handle:
0x000001b0
process_identifier:
2716
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x000001b0
suspend_count:
1
process_identifier:
2716
|
1
|
0 |
0
|
CreateProcessInternalW
|
thread_identifier:
2784
thread_handle:
0x000001b0
process_identifier:
2780
current_directory:
filepath:
track:
1
command_line:
C:\Users\test22\AppData\Local\Temp\RNOLL.txt.exe /stext "C:\Users\test22\AppData\Local\Temp\xzvxuzeasxsnsrnfxkmkqrtetcgdkmhwcc"
filepath_r:
stack_pivoted:
0
creation_flags:
4
(CREATE_SUSPENDED)
inherit_handles:
0
process_handle:
0x000002d0
|
1
|
1 |
0
|
NtGetContextThread
|
thread_handle:
0x000001b0
|
1
|
0 |
0
|
NtUnmapViewOfSection
|
base_address:
0x00400000
region_size:
4096
process_identifier:
2780
process_handle:
0x000002d0
|
1
|
0 |
0
|
NtMapViewOfSection
|
section_handle:
0x0000033c
process_identifier:
2780
commit_size:
0
win32_protect:
64
(PAGE_EXECUTE_READWRITE)
buffer:
base_address:
0x00400000
allocation_type:
0
()
section_offset:
0
view_size:
401408
process_handle:
0x000002d0
|
1
|
0 |
0
|
NtSetContextThread
|
registers.eip:
1995571652
registers.esp:
1638384
registers.edi:
0
registers.eax:
4583992
registers.ebp:
0
registers.edx:
0
registers.ebx:
2130567168
registers.esi:
0
registers.ecx:
0
thread_handle:
0x000001b0
process_identifier:
2780
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x000001b0
suspend_count:
1
process_identifier:
2780
|
1
|
0 |
0
|
CreateProcessInternalW
|
thread_identifier:
2852
thread_handle:
0x000001b0
process_identifier:
2848
current_directory:
filepath:
track:
1
command_line:
C:\Users\test22\AppData\Local\Temp\RNOLL.txt.exe /stext "C:\Users\test22\AppData\Local\Temp\iuaivsp"
filepath_r:
stack_pivoted:
0
creation_flags:
4
(CREATE_SUSPENDED)
inherit_handles:
0
process_handle:
0x000002d0
|
1
|
1 |
0
|
NtGetContextThread
|
thread_handle:
0x000001b0
|
1
|
0 |
0
|
NtUnmapViewOfSection
|
base_address:
0x00400000
region_size:
4096
process_identifier:
2848
process_handle:
0x000002d0
|
1
|
0 |
0
|
NtMapViewOfSection
|
section_handle:
0x00000340
process_identifier:
2848
commit_size:
0
win32_protect:
64
(PAGE_EXECUTE_READWRITE)
buffer:
base_address:
0x00400000
allocation_type:
0
()
section_offset:
0
view_size:
147456
process_handle:
0x000002d0
|
1
|
0 |
0
|
NtSetContextThread
|
registers.eip:
1995571652
registers.esp:
1638384
registers.edi:
0
registers.eax:
4334086
registers.ebp:
0
registers.edx:
0
registers.ebx:
2130567168
registers.esi:
0
registers.ecx:
0
thread_handle:
0x000001b0
process_identifier:
2848
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x000001b0
suspend_count:
1
process_identifier:
2848
|
1
|
0 |
0
|
CreateProcessInternalW
|
thread_identifier:
2976
thread_handle:
0x000001b0
process_identifier:
2972
current_directory:
filepath:
track:
1
command_line:
C:\Users\test22\AppData\Local\Temp\RNOLL.txt.exe /stext "C:\Users\test22\AppData\Local\Temp\cjwhrqbfckotgygpizmerfrnnt"
filepath_r:
stack_pivoted:
0
creation_flags:
4
(CREATE_SUSPENDED)
inherit_handles:
0
process_handle:
0x000002d0
|
1
|
1 |
0
|
NtGetContextThread
|
thread_handle:
0x000001b0
|
1
|
0 |
0
|
NtUnmapViewOfSection
|
base_address:
0x00400000
region_size:
4096
process_identifier:
2972
process_handle:
0x000002d0
|
1
|
0 |
0
|
NtMapViewOfSection
|
section_handle:
0x00000344
process_identifier:
2972
commit_size:
0
win32_protect:
64
(PAGE_EXECUTE_READWRITE)
buffer:
base_address:
0x00400000
allocation_type:
0
()
section_offset:
0
view_size:
491520
process_handle:
0x000002d0
|
1
|
0 |
0
|
NtSetContextThread
|
registers.eip:
1995571652
registers.esp:
1638384
registers.edi:
0
registers.eax:
4678260
registers.ebp:
0
registers.edx:
0
registers.ebx:
2130567168
registers.esi:
0
registers.ecx:
0
thread_handle:
0x000001b0
process_identifier:
2972
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x000001b0
suspend_count:
1
process_identifier:
2972
|
1
|
0 |
0
|
CreateProcessInternalW
|
thread_identifier:
3036
thread_handle:
0x000001b0
process_identifier:
3032
current_directory:
filepath:
track:
1
command_line:
C:\Users\test22\AppData\Local\Temp\RNOLL.txt.exe /stext "C:\Users\test22\AppData\Local\Temp\ndcssjmgqsgyrfcbrkhyujmewalzfo"
filepath_r:
stack_pivoted:
0
creation_flags:
4
(CREATE_SUSPENDED)
inherit_handles:
0
process_handle:
0x000002d0
|
1
|
1 |
0
|
NtGetContextThread
|
thread_handle:
0x000001b0
|
1
|
0 |
0
|
NtUnmapViewOfSection
|
base_address:
0x00400000
region_size:
4096
process_identifier:
3032
process_handle:
0x000002d0
|
1
|
0 |
0
|
NtMapViewOfSection
|
section_handle:
0x00000348
process_identifier:
3032
commit_size:
0
win32_protect:
64
(PAGE_EXECUTE_READWRITE)
buffer:
base_address:
0x00400000
allocation_type:
0
()
section_offset:
0
view_size:
401408
process_handle:
0x000002d0
|
1
|
0 |
0
|
NtSetContextThread
|
registers.eip:
1995571652
registers.esp:
1638384
registers.edi:
0
registers.eax:
4583992
registers.ebp:
0
registers.edx:
0
registers.ebx:
2130567168
registers.esi:
0
registers.ecx:
0
thread_handle:
0x000001b0
process_identifier:
3032
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x000001b0
suspend_count:
1
process_identifier:
3032
|
1
|
0 |
0
|
CreateProcessInternalW
|
thread_identifier:
1152
thread_handle:
0x000001b0
process_identifier:
2056
current_directory:
filepath:
track:
1
command_line:
C:\Users\test22\AppData\Local\Temp\RNOLL.txt.exe /stext "C:\Users\test22\AppData\Local\Temp\pfhltbxadaydttqfivuzfwguwodiyzzxs"
filepath_r:
stack_pivoted:
0
creation_flags:
4
(CREATE_SUSPENDED)
inherit_handles:
0
process_handle:
0x000002d0
|
1
|
1 |
0
|
NtGetContextThread
|
thread_handle:
0x000001b0
|
1
|
0 |
0
|
NtUnmapViewOfSection
|
base_address:
0x00400000
region_size:
4096
process_identifier:
2056
process_handle:
0x000002d0
|
1
|
0 |
0
|
NtMapViewOfSection
|
section_handle:
0x0000034c
process_identifier:
2056
commit_size:
0
win32_protect:
64
(PAGE_EXECUTE_READWRITE)
buffer:
base_address:
0x00400000
allocation_type:
0
()
section_offset:
0
view_size:
147456
process_handle:
0x000002d0
|
1
|
0 |
0
|
NtSetContextThread
|
registers.eip:
1995571652
registers.esp:
1638384
registers.edi:
0
registers.eax:
4334086
registers.ebp:
0
registers.edx:
0
registers.ebx:
2130567168
registers.esi:
0
registers.ecx:
0
thread_handle:
0x000001b0
process_identifier:
2056
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x000001b0
suspend_count:
1
process_identifier:
2056
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000108
suspend_count:
1
process_identifier:
2716
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x000000fc
suspend_count:
1
process_identifier:
2780
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000108
suspend_count:
1
process_identifier:
2972
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x000000fc
suspend_count:
1
process_identifier:
3032
|
1
|
0 |
0
|