| Time & API |
Arguments |
Status |
Return |
Repeated |
1619272284.931125
CreateProcessInternalW
|
thread_identifier:
2116
thread_handle:
0x000001a8
process_identifier:
2080
current_directory:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp
filepath:
C:\Program Files\Google\Chrome\Application\chrome.exe
track:
1
command_line:
"C:\Program Files\Google\Chrome\Application\chrome.exe" --single-argument C:\Users\ADMINI~1.OSK\AppData\Local\Temp\SWIFTMT103.pdf
filepath_r:
C:\Program Files\Google\Chrome\Application\chrome.exe
stack_pivoted:
0
creation_flags:
67634192
(CREATE_DEFAULT_ERROR_MODE|CREATE_NEW_CONSOLE|CREATE_UNICODE_ENVIRONMENT|EXTENDED_STARTUPINFO_PRESENT)
process_handle:
0x000001b0
inherit_handles:
0
|
success
|
1 |
0
|
1619272285.041125
CreateProcessInternalW
|
thread_identifier:
2272
thread_handle:
0x00000110
process_identifier:
1704
current_directory:
filepath:
track:
1
command_line:
"C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\2013298bbd1a4bf0bd41d04ad192be62.exe"
filepath_r:
stack_pivoted:
0
creation_flags:
4
(CREATE_SUSPENDED)
process_handle:
0x00000108
inherit_handles:
0
|
success
|
1 |
0
|
1619272285.041125
NtUnmapViewOfSection
|
process_identifier:
1704
region_size:
4096
process_handle:
0x00000108
base_address:
0x00400000
|
success
|
0 |
0
|
1619272285.041125
NtMapViewOfSection
|
section_handle:
0x00000130
process_identifier:
1704
commit_size:
2306048
win32_protect:
64
(PAGE_EXECUTE_READWRITE)
buffer:
process_handle:
0x00000108
allocation_type:
0
()
section_offset:
0
view_size:
2306048
base_address:
0x00400000
|
success
|
0 |
0
|
1619272285.103125
NtGetContextThread
|
thread_handle:
0x00000110
|
success
|
0 |
0
|
1619272285.103125
NtSetContextThread
|
thread_handle:
0x00000110
registers.eip:
0
registers.esp:
0
registers.edi:
0
registers.eax:
6291591
registers.ebp:
0
registers.edx:
0
registers.ebx:
2130567168
registers.esi:
0
registers.ecx:
0
process_identifier:
1704
|
success
|
0 |
0
|
1619272285.447125
NtResumeThread
|
thread_handle:
0x00000110
suspend_count:
1
process_identifier:
1704
|
success
|
0 |
0
|
1619272285.588125
CreateProcessInternalW
|
thread_identifier:
1176
thread_handle:
0x00000100
process_identifier:
324
current_directory:
filepath:
track:
1
command_line:
"C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\2013298bbd1a4bf0bd41d04ad192be62.exe" 2 1704 1289437
filepath_r:
stack_pivoted:
0
creation_flags:
32
(NORMAL_PRIORITY_CLASS)
process_handle:
0x0000013c
inherit_handles:
0
|
success
|
1 |
0
|
1619271855.965646
NtResumeThread
|
thread_handle:
0x0000000000000078
suspend_count:
1
process_identifier:
2080
|
success
|
0 |
0
|
1619271856.137646
CreateProcessInternalW
|
thread_identifier:
2636
thread_handle:
0x00000000000000c0
process_identifier:
2764
current_directory:
filepath:
C:\Program Files\Google\Chrome\Application\chrome.exe
track:
1
command_line:
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=89.0.4389.114 --initial-client-data=0xb0,0xb4,0xb8,0x84,0xbc,0x7fef2494f50,0x7fef2494f60,0x7fef2494f70
filepath_r:
C:\Program Files\Google\Chrome\Application\chrome.exe
stack_pivoted:
0
creation_flags:
524288
(EXTENDED_STARTUPINFO_PRESENT)
process_handle:
0x00000000000000c4
inherit_handles:
1
|
success
|
1 |
0
|
1619271919.183646
CreateProcessInternalW
|
thread_identifier:
3592
thread_handle:
0x0000000000000584
process_identifier:
3588
current_directory:
filepath:
C:\Program Files\Google\Chrome\Application\chrome.exe
track:
1
command_line:
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=1060,15031422247710088254,7379468732611753755,131072 --gpu-preferences=SAAAAAAAAADgAAAwAAAAAAAAAAAAAAAAAABgAAAAAAAoAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAB4AAAAAAAAAHgAAAAAAAAAKAAAAAQAAAAgAAAAAAAAACgAAAAAAAAAMAAAAAAAAAA4AAAAAAAAABAAAAAAAAAAAAAAAAUAAAAQAAAAAAAAAAAAAAAGAAAAEAAAAAAAAAABAAAABQAAABAAAAAAAAAAAQAAAAYAAAAIAAAAAAAAAAgAAAAAAAAA --mojo-platform-channel-handle=1068 /prefetch:2
filepath_r:
C:\Program Files\Google\Chrome\Application\chrome.exe
stack_pivoted:
0
creation_flags:
17302540
(CREATE_BREAKAWAY_FROM_JOB|CREATE_SUSPENDED|CREATE_UNICODE_ENVIRONMENT|DETACHED_PROCESS|EXTENDED_STARTUPINFO_PRESENT)
process_handle:
0x000000000000058c
inherit_handles:
1
|
success
|
1 |
0
|
1619271857.371769
NtResumeThread
|
thread_handle:
0x0000000000000120
suspend_count:
1
process_identifier:
2764
|
success
|
0 |
0
|
1619271919.840769
NtGetContextThread
|
thread_handle:
0x0000000000000144
|
success
|
0 |
0
|
1619271921.887769
NtResumeThread
|
thread_handle:
0x0000000000000144
suspend_count:
2
process_identifier:
2080
|
success
|
0 |
0
|
1619271921.902769
NtGetContextThread
|
thread_handle:
0x0000000000000144
|
success
|
0 |
0
|
1619271923.418769
NtResumeThread
|
thread_handle:
0x0000000000000144
suspend_count:
2
process_identifier:
2080
|
success
|
0 |
0
|
1619271923.418769
NtGetContextThread
|
thread_handle:
0x0000000000000144
|
success
|
0 |
0
|