| Time & API |
Arguments |
Status |
Return |
Repeated |
1619269232.136495
CreateProcessInternalW
|
thread_identifier:
880
thread_handle:
0x000001b4
process_identifier:
420
current_directory:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp
filepath:
C:\Program Files\Google\Chrome\Application\chrome.exe
track:
1
command_line:
"C:\Program Files\Google\Chrome\Application\chrome.exe" --single-argument C:\Users\ADMINI~1.OSK\AppData\Local\Temp\CARTASCONF.pdf
filepath_r:
C:\Program Files\Google\Chrome\Application\chrome.exe
stack_pivoted:
0
creation_flags:
67634192
(CREATE_DEFAULT_ERROR_MODE|CREATE_NEW_CONSOLE|CREATE_UNICODE_ENVIRONMENT|EXTENDED_STARTUPINFO_PRESENT)
process_handle:
0x000001b0
inherit_handles:
0
|
success
|
1 |
0
|
1619269232.245495
CreateProcessInternalW
|
thread_identifier:
1108
thread_handle:
0x00000118
process_identifier:
2864
current_directory:
filepath:
track:
1
command_line:
"C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\2427073d233ffe91b0457305371d237d.exe"
filepath_r:
stack_pivoted:
0
creation_flags:
4
(CREATE_SUSPENDED)
process_handle:
0x00000110
inherit_handles:
0
|
success
|
1 |
0
|
1619269232.245495
NtUnmapViewOfSection
|
process_identifier:
2864
region_size:
4096
process_handle:
0x00000110
base_address:
0x00400000
|
success
|
0 |
0
|
1619269232.261495
NtMapViewOfSection
|
section_handle:
0x00000138
process_identifier:
2864
commit_size:
2306048
win32_protect:
64
(PAGE_EXECUTE_READWRITE)
buffer:
process_handle:
0x00000110
allocation_type:
0
()
section_offset:
0
view_size:
2306048
base_address:
0x00400000
|
success
|
0 |
0
|
1619269232.355495
NtGetContextThread
|
thread_handle:
0x00000118
|
success
|
0 |
0
|
1619269232.355495
NtSetContextThread
|
thread_handle:
0x00000118
registers.eip:
0
registers.esp:
0
registers.edi:
0
registers.eax:
6291591
registers.ebp:
0
registers.edx:
0
registers.ebx:
2130567168
registers.esi:
0
registers.ecx:
0
process_identifier:
2864
|
success
|
0 |
0
|
1619269232.855495
NtResumeThread
|
thread_handle:
0x00000118
suspend_count:
1
process_identifier:
2864
|
success
|
0 |
0
|
1619269233.042495
CreateProcessInternalW
|
thread_identifier:
2520
thread_handle:
0x00000108
process_identifier:
1912
current_directory:
filepath:
track:
1
command_line:
"C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\2427073d233ffe91b0457305371d237d.exe" 2 2864 24088156
filepath_r:
stack_pivoted:
0
creation_flags:
32
(NORMAL_PRIORITY_CLASS)
process_handle:
0x00000144
inherit_handles:
0
|
success
|
1 |
0
|
1619302928.008625
NtResumeThread
|
thread_handle:
0x0000000000000078
suspend_count:
1
process_identifier:
420
|
success
|
0 |
0
|
1619302928.149625
CreateProcessInternalW
|
thread_identifier:
2260
thread_handle:
0x00000000000000c0
process_identifier:
2536
current_directory:
filepath:
C:\Program Files\Google\Chrome\Application\chrome.exe
track:
1
command_line:
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=89.0.4389.114 --initial-client-data=0xb0,0xb4,0xb8,0x84,0xbc,0x7fef24e4f50,0x7fef24e4f60,0x7fef24e4f70
filepath_r:
C:\Program Files\Google\Chrome\Application\chrome.exe
stack_pivoted:
0
creation_flags:
524288
(EXTENDED_STARTUPINFO_PRESENT)
process_handle:
0x00000000000000c4
inherit_handles:
1
|
success
|
1 |
0
|
1619302929.853125
NtResumeThread
|
thread_handle:
0x0000000000000124
suspend_count:
1
process_identifier:
2536
|
success
|
0 |
0
|