Summary | ZeroBOX

MegVlau.exe

PE32 PE File .NET EXE
Category Machine Started Completed
FILE s1_win7_x6401 Feb. 26, 2025, 9:42 a.m. Feb. 26, 2025, 9:45 a.m.
Size 349.0KB
Type PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 936f4b47e08ca09483ca85f7b901eb0f
SHA256 fad4e974cc163c386e77091efb9bbffab7f5ea4559c111baaee9954f8b3e3ce1
CRC32 82F7DD20
ssdeep 6144:3HYaosINWXFGYJabd0UyB8kOKWAKo1Ze7OwEK/MNt8lEdgxbuZm/uPEtCfwoZIEO:3HH9INsFF4R0UyBSKW0lK/MNWqdgJuY5
Yara
  • PE_Header_Zero - PE File Signature
  • Is_DotNET_EXE - (no description)
  • IsPE32 - (no description)

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
No hosts contacted.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Time & API Arguments Status Return Repeated

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0
Time & API Arguments Status Return Repeated

GlobalMemoryStatusEx

1 1 0
section .css
Time & API Arguments Status Return Repeated

NtAllocateVirtualMemory

process_identifier: 2556
region_size: 1179648
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00290000
allocation_type: 8192 (MEM_RESERVE)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2556
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00370000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2556
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x727a1000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2556
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x727a2000
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2556
region_size: 1769472
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02000000
allocation_type: 8192 (MEM_RESERVE)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2556
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02170000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2556
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x002a2000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2556
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x002d5000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2556
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x002db000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2556
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x002d7000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2556
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x002bc000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2556
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x005f0000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2556
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x002c6000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2556
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x002ca000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2556
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x002c7000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2556
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x002aa000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2556
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 8192
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x023c1000
process_handle: 0xffffffff
1 0 0
section {u'size_of_data': u'0x00052400', u'virtual_address': u'0x00008000', u'entropy': 7.999542099646437, u'name': u'.css', u'virtual_size': u'0x00052400'} entropy 7.99954209965 description A section with a high entropy has been found
entropy 0.971935007386 description Overall entropy of this PE file is high
Time & API Arguments Status Return Repeated

NtTerminateProcess

status_code: 0x00000000
process_identifier: 2644
process_handle: 0x000001fc
0 0

NtTerminateProcess

status_code: 0x00000000
process_identifier: 2644
process_handle: 0x000001fc
1 0 0

NtTerminateProcess

status_code: 0x00000000
process_identifier: 2680
process_handle: 0x00000200
0 0

NtTerminateProcess

status_code: 0x00000000
process_identifier: 2680
process_handle: 0x00000200
1 0 0

NtTerminateProcess

status_code: 0x00000000
process_identifier: 2716
process_handle: 0x00000208
0 0

NtTerminateProcess

status_code: 0x00000000
process_identifier: 2716
process_handle: 0x00000208
1 0 0

NtTerminateProcess

status_code: 0x00000000
process_identifier: 2752
process_handle: 0x00000210
0 0

NtTerminateProcess

status_code: 0x00000000
process_identifier: 2752
process_handle: 0x00000210
1 0 0

NtTerminateProcess

status_code: 0x00000000
process_identifier: 2788
process_handle: 0x00000218
0 0

NtTerminateProcess

status_code: 0x00000000
process_identifier: 2788
process_handle: 0x00000218
1 0 0

NtTerminateProcess

status_code: 0x00000000
process_identifier: 2824
process_handle: 0x00000220
0 0

NtTerminateProcess

status_code: 0x00000000
process_identifier: 2824
process_handle: 0x00000220
1 0 0

NtTerminateProcess

status_code: 0x00000000
process_identifier: 2860
process_handle: 0x00000228
0 0

NtTerminateProcess

status_code: 0x00000000
process_identifier: 2860
process_handle: 0x00000228
1 0 0

NtTerminateProcess

status_code: 0x00000000
process_identifier: 2904
process_handle: 0x00000230
0 0

NtTerminateProcess

status_code: 0x00000000
process_identifier: 2904
process_handle: 0x00000230
1 0 0

NtTerminateProcess

status_code: 0x00000000
process_identifier: 2940
process_handle: 0x00000238
0 0

NtTerminateProcess

status_code: 0x00000000
process_identifier: 2940
process_handle: 0x00000238
1 0 0

NtTerminateProcess

status_code: 0x00000000
process_identifier: 2976
process_handle: 0x00000240
0 0

NtTerminateProcess

status_code: 0x00000000
process_identifier: 2976
process_handle: 0x00000240
1 0 0

NtTerminateProcess

status_code: 0x00000000
process_identifier: 3012
process_handle: 0x00000248
0 0

NtTerminateProcess

status_code: 0x00000000
process_identifier: 3012
process_handle: 0x00000248
1 0 0

NtTerminateProcess

status_code: 0x00000000
process_identifier: 3048
process_handle: 0x00000250
0 0

NtTerminateProcess

status_code: 0x00000000
process_identifier: 3048
process_handle: 0x00000250
1 0 0

NtTerminateProcess

status_code: 0x00000000
process_identifier: 1120
process_handle: 0x00000258
0 0

NtTerminateProcess

status_code: 0x00000000
process_identifier: 1120
process_handle: 0x00000258
1 0 0

NtTerminateProcess

status_code: 0x00000000
process_identifier: 2076
process_handle: 0x00000260
0 0

NtTerminateProcess

status_code: 0x00000000
process_identifier: 2076
process_handle: 0x00000260
1 0 0

NtTerminateProcess

status_code: 0x00000000
process_identifier: 2124
process_handle: 0x00000268
0 0

NtTerminateProcess

status_code: 0x00000000
process_identifier: 2124
process_handle: 0x00000268
1 0 0

NtTerminateProcess

status_code: 0x00000000
process_identifier: 1336
process_handle: 0x00000270
0 0

NtTerminateProcess

status_code: 0x00000000
process_identifier: 1336
process_handle: 0x00000270
1 0 0

NtTerminateProcess

status_code: 0x00000000
process_identifier: 1400
process_handle: 0x00000278
0 0

NtTerminateProcess

status_code: 0x00000000
process_identifier: 1400
process_handle: 0x00000278
1 0 0

NtTerminateProcess

status_code: 0x00000000
process_identifier: 2220
process_handle: 0x00000280
0 0

NtTerminateProcess

status_code: 0x00000000
process_identifier: 2220
process_handle: 0x00000280
1 0 0

NtTerminateProcess

status_code: 0x00000000
process_identifier: 2228
process_handle: 0x00000288
0 0

NtTerminateProcess

status_code: 0x00000000
process_identifier: 2228
process_handle: 0x00000288
1 0 0

NtTerminateProcess

status_code: 0x00000000
process_identifier: 2412
process_handle: 0x00000290
0 0

NtTerminateProcess

status_code: 0x00000000
process_identifier: 2412
process_handle: 0x00000290
1 0 0

NtTerminateProcess

status_code: 0x00000000
process_identifier: 2500
process_handle: 0x00000298
0 0

NtTerminateProcess

status_code: 0x00000000
process_identifier: 2500
process_handle: 0x00000298
1 0 0

NtTerminateProcess

status_code: 0x00000000
process_identifier: 2544
process_handle: 0x000002a0
0 0

NtTerminateProcess

status_code: 0x00000000
process_identifier: 2544
process_handle: 0x000002a0
1 0 0

NtTerminateProcess

status_code: 0x00000000
process_identifier: 2588
process_handle: 0x000002a8
0 0

NtTerminateProcess

status_code: 0x00000000
process_identifier: 2588
process_handle: 0x000002a8
1 0 0

NtTerminateProcess

status_code: 0x00000000
process_identifier: 2696
process_handle: 0x000002b0
0 0

NtTerminateProcess

status_code: 0x00000000
process_identifier: 2696
process_handle: 0x000002b0
1 0 0

NtTerminateProcess

status_code: 0x00000000
process_identifier: 2772
process_handle: 0x000002b8
0 0

NtTerminateProcess

status_code: 0x00000000
process_identifier: 2772
process_handle: 0x000002b8
1 0 0
Time & API Arguments Status Return Repeated

NtAllocateVirtualMemory

process_identifier: 2644
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x000001fc
3221225496 0

NtAllocateVirtualMemory

process_identifier: 2680
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x00000200
3221225496 0

NtAllocateVirtualMemory

process_identifier: 2716
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x00000208
3221225496 0

NtAllocateVirtualMemory

process_identifier: 2752
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x00000210
3221225496 0

NtAllocateVirtualMemory

process_identifier: 2788
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x00000218
3221225496 0

NtAllocateVirtualMemory

process_identifier: 2824
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x00000220
3221225496 0

NtAllocateVirtualMemory

process_identifier: 2860
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x00000228
3221225496 0

NtAllocateVirtualMemory

process_identifier: 2904
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x00000230
3221225496 0

NtAllocateVirtualMemory

process_identifier: 2940
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x00000238
3221225496 0

NtAllocateVirtualMemory

process_identifier: 2976
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x00000240
3221225496 0

NtAllocateVirtualMemory

process_identifier: 3012
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x00000248
3221225496 0

NtAllocateVirtualMemory

process_identifier: 3048
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x00000250
3221225496 0

NtAllocateVirtualMemory

process_identifier: 1120
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x00000258
3221225496 0

NtAllocateVirtualMemory

process_identifier: 2076
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x00000260
3221225496 0

NtAllocateVirtualMemory

process_identifier: 2124
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x00000268
3221225496 0

NtAllocateVirtualMemory

process_identifier: 1336
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x00000270
3221225496 0

NtAllocateVirtualMemory

process_identifier: 1400
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x00000278
3221225496 0

NtAllocateVirtualMemory

process_identifier: 2220
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x00000280
3221225496 0

NtAllocateVirtualMemory

process_identifier: 2228
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x00000288
3221225496 0

NtAllocateVirtualMemory

process_identifier: 2412
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x00000290
3221225496 0

NtAllocateVirtualMemory

process_identifier: 2500
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x00000298
3221225496 0

NtAllocateVirtualMemory

process_identifier: 2544
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x000002a0
3221225496 0

NtAllocateVirtualMemory

process_identifier: 2588
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x000002a8
3221225496 0

NtAllocateVirtualMemory

process_identifier: 2696
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x000002b0
3221225496 0

NtAllocateVirtualMemory

process_identifier: 2772
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x000002b8
3221225496 0

NtAllocateVirtualMemory

process_identifier: 2816
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x000002c0
3221225496 0

NtAllocateVirtualMemory

process_identifier: 2900
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x000002c8
3221225496 0

NtAllocateVirtualMemory

process_identifier: 2952
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x000002d0
3221225496 0

NtAllocateVirtualMemory

process_identifier: 3032
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x000002d8
3221225496 0

NtAllocateVirtualMemory

process_identifier: 1152
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x000002e0
3221225496 0

NtAllocateVirtualMemory

process_identifier: 1728
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x000002e8
3221225496 0

NtAllocateVirtualMemory

process_identifier: 2168
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x000002f0
3221225496 0

NtAllocateVirtualMemory

process_identifier: 2208
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x000002f8
3221225496 0

NtAllocateVirtualMemory

process_identifier: 2468
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x00000300
3221225496 0

NtAllocateVirtualMemory

process_identifier: 2572
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x00000308
3221225496 0

NtAllocateVirtualMemory

process_identifier: 2672
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x00000310
3221225496 0

NtAllocateVirtualMemory

process_identifier: 2820
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x00000318
3221225496 0

NtAllocateVirtualMemory

process_identifier: 2924
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x00000320
3221225496 0

NtAllocateVirtualMemory

process_identifier: 3068
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x00000328
3221225496 0

NtAllocateVirtualMemory

process_identifier: 2068
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x00000330
3221225496 0

NtAllocateVirtualMemory

process_identifier: 2264
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x00000338
3221225496 0

NtAllocateVirtualMemory

process_identifier: 2596
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x00000340
3221225496 0

NtAllocateVirtualMemory

process_identifier: 2836
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x00000348
3221225496 0

NtAllocateVirtualMemory

process_identifier: 3004
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x00000350
3221225496 0

NtAllocateVirtualMemory

process_identifier: 2620
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x00000358
3221225496 0

NtAllocateVirtualMemory

process_identifier: 2312
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x00000360
3221225496 0

NtAllocateVirtualMemory

process_identifier: 2808
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x00000368
3221225496 0

NtAllocateVirtualMemory

process_identifier: 1404
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x00000370
3221225496 0

NtAllocateVirtualMemory

process_identifier: 2552
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x00000378
3221225496 0

NtAllocateVirtualMemory

process_identifier: 2116
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x00000380
3221225496 0
Process injection Process 2556 manipulating memory of non-child process 2644
Process injection Process 2556 manipulating memory of non-child process 2680
Process injection Process 2556 manipulating memory of non-child process 2716
Process injection Process 2556 manipulating memory of non-child process 2752
Process injection Process 2556 manipulating memory of non-child process 2788
Process injection Process 2556 manipulating memory of non-child process 2824
Process injection Process 2556 manipulating memory of non-child process 2860
Process injection Process 2556 manipulating memory of non-child process 2904
Process injection Process 2556 manipulating memory of non-child process 2940
Process injection Process 2556 manipulating memory of non-child process 2976
Process injection Process 2556 manipulating memory of non-child process 3012
Process injection Process 2556 manipulating memory of non-child process 3048
Process injection Process 2556 manipulating memory of non-child process 1120
Process injection Process 2556 manipulating memory of non-child process 2076
Process injection Process 2556 manipulating memory of non-child process 2124
Process injection Process 2556 manipulating memory of non-child process 1336
Process injection Process 2556 manipulating memory of non-child process 1400
Process injection Process 2556 manipulating memory of non-child process 2220
Process injection Process 2556 manipulating memory of non-child process 2228
Process injection Process 2556 manipulating memory of non-child process 2412
Process injection Process 2556 manipulating memory of non-child process 2500
Process injection Process 2556 manipulating memory of non-child process 2544
Process injection Process 2556 manipulating memory of non-child process 2588
Process injection Process 2556 manipulating memory of non-child process 2696
Process injection Process 2556 manipulating memory of non-child process 2772
Time & API Arguments Status Return Repeated

NtAllocateVirtualMemory

process_identifier: 2644
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x000001fc
3221225496 0

NtAllocateVirtualMemory

process_identifier: 2680
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x00000200
3221225496 0

NtAllocateVirtualMemory

process_identifier: 2716
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x00000208
3221225496 0

NtAllocateVirtualMemory

process_identifier: 2752
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x00000210
3221225496 0

NtAllocateVirtualMemory

process_identifier: 2788
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x00000218
3221225496 0

NtAllocateVirtualMemory

process_identifier: 2824
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x00000220
3221225496 0

NtAllocateVirtualMemory

process_identifier: 2860
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x00000228
3221225496 0

NtAllocateVirtualMemory

process_identifier: 2904
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x00000230
3221225496 0

NtAllocateVirtualMemory

process_identifier: 2940
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x00000238
3221225496 0

NtAllocateVirtualMemory

process_identifier: 2976
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x00000240
3221225496 0

NtAllocateVirtualMemory

process_identifier: 3012
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x00000248
3221225496 0

NtAllocateVirtualMemory

process_identifier: 3048
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x00000250
3221225496 0

NtAllocateVirtualMemory

process_identifier: 1120
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x00000258
3221225496 0

NtAllocateVirtualMemory

process_identifier: 2076
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x00000260
3221225496 0

NtAllocateVirtualMemory

process_identifier: 2124
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x00000268
3221225496 0

NtAllocateVirtualMemory

process_identifier: 1336
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x00000270
3221225496 0

NtAllocateVirtualMemory

process_identifier: 1400
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x00000278
3221225496 0

NtAllocateVirtualMemory

process_identifier: 2220
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x00000280
3221225496 0

NtAllocateVirtualMemory

process_identifier: 2228
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x00000288
3221225496 0

NtAllocateVirtualMemory

process_identifier: 2412
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x00000290
3221225496 0

NtAllocateVirtualMemory

process_identifier: 2500
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x00000298
3221225496 0

NtAllocateVirtualMemory

process_identifier: 2544
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x000002a0
3221225496 0

NtAllocateVirtualMemory

process_identifier: 2588
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x000002a8
3221225496 0

NtAllocateVirtualMemory

process_identifier: 2696
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x000002b0
3221225496 0

NtAllocateVirtualMemory

process_identifier: 2772
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x000002b8
3221225496 0
Time & API Arguments Status Return Repeated

NtResumeThread

thread_handle: 0x000000dc
suspend_count: 1
process_identifier: 2556
1 0 0

NtResumeThread

thread_handle: 0x00000154
suspend_count: 1
process_identifier: 2556
1 0 0

NtResumeThread

thread_handle: 0x00000194
suspend_count: 1
process_identifier: 2556
1 0 0

CreateProcessInternalW

thread_identifier: 2648
thread_handle: 0x000001f8
process_identifier: 2644
current_directory:
filepath: C:\Users\test22\AppData\Local\Temp\MegVlau.exe
track: 1
command_line:
filepath_r: C:\Users\test22\AppData\Local\Temp\MegVlau.exe
stack_pivoted: 0
creation_flags: 4 (CREATE_SUSPENDED)
inherit_handles: 0
process_handle: 0x000001fc
1 1 0

NtGetContextThread

thread_handle: 0x000001f8
1 0 0

NtAllocateVirtualMemory

process_identifier: 2644
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x000001fc
3221225496 0

CreateProcessInternalW

thread_identifier: 2684
thread_handle: 0x00000204
process_identifier: 2680
current_directory:
filepath: C:\Users\test22\AppData\Local\Temp\MegVlau.exe
track: 1
command_line:
filepath_r: C:\Users\test22\AppData\Local\Temp\MegVlau.exe
stack_pivoted: 0
creation_flags: 4 (CREATE_SUSPENDED)
inherit_handles: 0
process_handle: 0x00000200
1 1 0

NtGetContextThread

thread_handle: 0x00000204
1 0 0

NtAllocateVirtualMemory

process_identifier: 2680
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x00000200
3221225496 0

CreateProcessInternalW

thread_identifier: 2720
thread_handle: 0x0000020c
process_identifier: 2716
current_directory:
filepath: C:\Users\test22\AppData\Local\Temp\MegVlau.exe
track: 1
command_line:
filepath_r: C:\Users\test22\AppData\Local\Temp\MegVlau.exe
stack_pivoted: 0
creation_flags: 4 (CREATE_SUSPENDED)
inherit_handles: 0
process_handle: 0x00000208
1 1 0

NtGetContextThread

thread_handle: 0x0000020c
1 0 0

NtAllocateVirtualMemory

process_identifier: 2716
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x00000208
3221225496 0

CreateProcessInternalW

thread_identifier: 2756
thread_handle: 0x00000214
process_identifier: 2752
current_directory:
filepath: C:\Users\test22\AppData\Local\Temp\MegVlau.exe
track: 1
command_line:
filepath_r: C:\Users\test22\AppData\Local\Temp\MegVlau.exe
stack_pivoted: 0
creation_flags: 4 (CREATE_SUSPENDED)
inherit_handles: 0
process_handle: 0x00000210
1 1 0

NtGetContextThread

thread_handle: 0x00000214
1 0 0

NtAllocateVirtualMemory

process_identifier: 2752
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x00000210
3221225496 0

CreateProcessInternalW

thread_identifier: 2792
thread_handle: 0x0000021c
process_identifier: 2788
current_directory:
filepath: C:\Users\test22\AppData\Local\Temp\MegVlau.exe
track: 1
command_line:
filepath_r: C:\Users\test22\AppData\Local\Temp\MegVlau.exe
stack_pivoted: 0
creation_flags: 4 (CREATE_SUSPENDED)
inherit_handles: 0
process_handle: 0x00000218
1 1 0

NtGetContextThread

thread_handle: 0x0000021c
1 0 0

NtAllocateVirtualMemory

process_identifier: 2788
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x00000218
3221225496 0

CreateProcessInternalW

thread_identifier: 2828
thread_handle: 0x00000224
process_identifier: 2824
current_directory:
filepath: C:\Users\test22\AppData\Local\Temp\MegVlau.exe
track: 1
command_line:
filepath_r: C:\Users\test22\AppData\Local\Temp\MegVlau.exe
stack_pivoted: 0
creation_flags: 4 (CREATE_SUSPENDED)
inherit_handles: 0
process_handle: 0x00000220
1 1 0

NtGetContextThread

thread_handle: 0x00000224
1 0 0

NtAllocateVirtualMemory

process_identifier: 2824
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x00000220
3221225496 0

CreateProcessInternalW

thread_identifier: 2864
thread_handle: 0x0000022c
process_identifier: 2860
current_directory:
filepath: C:\Users\test22\AppData\Local\Temp\MegVlau.exe
track: 1
command_line:
filepath_r: C:\Users\test22\AppData\Local\Temp\MegVlau.exe
stack_pivoted: 0
creation_flags: 4 (CREATE_SUSPENDED)
inherit_handles: 0
process_handle: 0x00000228
1 1 0

NtGetContextThread

thread_handle: 0x0000022c
1 0 0

NtAllocateVirtualMemory

process_identifier: 2860
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x00000228
3221225496 0

CreateProcessInternalW

thread_identifier: 2908
thread_handle: 0x00000234
process_identifier: 2904
current_directory:
filepath: C:\Users\test22\AppData\Local\Temp\MegVlau.exe
track: 1
command_line:
filepath_r: C:\Users\test22\AppData\Local\Temp\MegVlau.exe
stack_pivoted: 0
creation_flags: 4 (CREATE_SUSPENDED)
inherit_handles: 0
process_handle: 0x00000230
1 1 0

NtGetContextThread

thread_handle: 0x00000234
1 0 0

NtAllocateVirtualMemory

process_identifier: 2904
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x00000230
3221225496 0

CreateProcessInternalW

thread_identifier: 2944
thread_handle: 0x0000023c
process_identifier: 2940
current_directory:
filepath: C:\Users\test22\AppData\Local\Temp\MegVlau.exe
track: 1
command_line:
filepath_r: C:\Users\test22\AppData\Local\Temp\MegVlau.exe
stack_pivoted: 0
creation_flags: 4 (CREATE_SUSPENDED)
inherit_handles: 0
process_handle: 0x00000238
1 1 0

NtGetContextThread

thread_handle: 0x0000023c
1 0 0

NtAllocateVirtualMemory

process_identifier: 2940
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x00000238
3221225496 0

CreateProcessInternalW

thread_identifier: 2980
thread_handle: 0x00000244
process_identifier: 2976
current_directory:
filepath: C:\Users\test22\AppData\Local\Temp\MegVlau.exe
track: 1
command_line:
filepath_r: C:\Users\test22\AppData\Local\Temp\MegVlau.exe
stack_pivoted: 0
creation_flags: 4 (CREATE_SUSPENDED)
inherit_handles: 0
process_handle: 0x00000240
1 1 0

NtGetContextThread

thread_handle: 0x00000244
1 0 0

NtAllocateVirtualMemory

process_identifier: 2976
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x00000240
3221225496 0

CreateProcessInternalW

thread_identifier: 3016
thread_handle: 0x0000024c
process_identifier: 3012
current_directory:
filepath: C:\Users\test22\AppData\Local\Temp\MegVlau.exe
track: 1
command_line:
filepath_r: C:\Users\test22\AppData\Local\Temp\MegVlau.exe
stack_pivoted: 0
creation_flags: 4 (CREATE_SUSPENDED)
inherit_handles: 0
process_handle: 0x00000248
1 1 0

NtGetContextThread

thread_handle: 0x0000024c
1 0 0

NtAllocateVirtualMemory

process_identifier: 3012
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x00000248
3221225496 0

CreateProcessInternalW

thread_identifier: 3052
thread_handle: 0x00000254
process_identifier: 3048
current_directory:
filepath: C:\Users\test22\AppData\Local\Temp\MegVlau.exe
track: 1
command_line:
filepath_r: C:\Users\test22\AppData\Local\Temp\MegVlau.exe
stack_pivoted: 0
creation_flags: 4 (CREATE_SUSPENDED)
inherit_handles: 0
process_handle: 0x00000250
1 1 0

NtGetContextThread

thread_handle: 0x00000254
1 0 0

NtAllocateVirtualMemory

process_identifier: 3048
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x00000250
3221225496 0

CreateProcessInternalW

thread_identifier: 604
thread_handle: 0x0000025c
process_identifier: 1120
current_directory:
filepath: C:\Users\test22\AppData\Local\Temp\MegVlau.exe
track: 1
command_line:
filepath_r: C:\Users\test22\AppData\Local\Temp\MegVlau.exe
stack_pivoted: 0
creation_flags: 4 (CREATE_SUSPENDED)
inherit_handles: 0
process_handle: 0x00000258
1 1 0

NtGetContextThread

thread_handle: 0x0000025c
1 0 0

NtAllocateVirtualMemory

process_identifier: 1120
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x00000258
3221225496 0

CreateProcessInternalW

thread_identifier: 2080
thread_handle: 0x00000264
process_identifier: 2076
current_directory:
filepath: C:\Users\test22\AppData\Local\Temp\MegVlau.exe
track: 1
command_line:
filepath_r: C:\Users\test22\AppData\Local\Temp\MegVlau.exe
stack_pivoted: 0
creation_flags: 4 (CREATE_SUSPENDED)
inherit_handles: 0
process_handle: 0x00000260
1 1 0

NtGetContextThread

thread_handle: 0x00000264
1 0 0

NtAllocateVirtualMemory

process_identifier: 2076
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x00000260
3221225496 0

CreateProcessInternalW

thread_identifier: 2104
thread_handle: 0x0000026c
process_identifier: 2124
current_directory:
filepath: C:\Users\test22\AppData\Local\Temp\MegVlau.exe
track: 1
command_line:
filepath_r: C:\Users\test22\AppData\Local\Temp\MegVlau.exe
stack_pivoted: 0
creation_flags: 4 (CREATE_SUSPENDED)
inherit_handles: 0
process_handle: 0x00000268
1 1 0

NtGetContextThread

thread_handle: 0x0000026c
1 0 0

NtAllocateVirtualMemory

process_identifier: 2124
region_size: 385024
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x00000268
3221225496 0

CreateProcessInternalW

thread_identifier: 2136
thread_handle: 0x00000274
process_identifier: 1336
current_directory:
filepath: C:\Users\test22\AppData\Local\Temp\MegVlau.exe
track: 1
command_line:
filepath_r: C:\Users\test22\AppData\Local\Temp\MegVlau.exe
stack_pivoted: 0
creation_flags: 4 (CREATE_SUSPENDED)
inherit_handles: 0
process_handle: 0x00000270
1 1 0

NtGetContextThread

thread_handle: 0x00000274
1 0 0
Bkav W32.AIDetectMalware.CS
Lionic Trojan.Win32.Stelpak.4!c
MicroWorld-eScan Gen:Variant.MSILHeracles.179021
ALYac Gen:Variant.MSILHeracles.179021
Cylance Unsafe
VIPRE Gen:Variant.MSILHeracles.179021
CrowdStrike win/malicious_confidence_100% (W)
BitDefender Gen:Variant.MSILHeracles.179021
VirIT Trojan.Win32.MSIL_Heur.A
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of MSIL/GenKryptik.HGSD
APEX Malicious
Avast Win32:PWSX-gen [Trj]
Kaspersky HEUR:Trojan.MSIL.Stelpak.gen
Rising Malware.Obfus/MSIL@AI.86 (RDM.MSIL2:ajG9bOr4a0giQjH12GC91w)
Emsisoft Gen:Variant.MSILHeracles.179021 (B)
F-Secure Trojan.TR/AD.Nekark.jcdze
McAfeeD ti!FAD4E974CC16
CTX exe.trojan.msil
Sophos Mal/Generic-S
SentinelOne Static AI - Malicious PE
FireEye Generic.mg.936f4b47e08ca094
Google Detected
Avira TR/AD.Nekark.jcdze
Kingsoft MSIL.Trojan.Stelpak.gen
Gridinsoft Trojan.Heur!.000120B1
Arcabit Trojan.MSILHeracles.D2BB4D
Microsoft Trojan:Win32/Wacatac.B!ml
Varist W32/MSIL_Kryptik.MAV.gen!Eldorado
AhnLab-V3 Trojan/Win.Generic.C5731599
DeepInstinct MALICIOUS
Ikarus Trojan.MSIL.Krypt
Panda Trj/Chgt.AD
Tencent Win32.Trojan.FalseSign.Xfow
huorong Trojan/MSIL.Agent.vl
Fortinet MSIL/Kryptik.ANCY!tr
AVG Win32:PWSX-gen [Trj]
Paloalto generic.ml