| Time & API |
Arguments |
Status |
Return |
Repeated |
1620759747.267125
NtResumeThread
|
thread_handle:
0x00000174
suspend_count:
1
process_identifier:
2284
|
success
|
0 |
0
|
1620759748.799125
CreateProcessInternalW
|
thread_identifier:
2260
thread_handle:
0x00000290
process_identifier:
2456
current_directory:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp
filepath:
C:\Windows\System32\cmd.exe
track:
1
command_line:
"C:\Windows\System32\cmd.exe" /k attrib "C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\32307c24db9052003547acd8c7814a09.exe" +s +h
filepath_r:
C:\Windows\System32\cmd.exe
stack_pivoted:
0
creation_flags:
67634192
(CREATE_DEFAULT_ERROR_MODE|CREATE_NEW_CONSOLE|CREATE_UNICODE_ENVIRONMENT|EXTENDED_STARTUPINFO_PRESENT)
process_handle:
0x000002cc
inherit_handles:
0
|
success
|
1 |
0
|
1620759748.955125
CreateProcessInternalW
|
thread_identifier:
2344
thread_handle:
0x00000290
process_identifier:
2452
current_directory:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp
filepath:
C:\Windows\System32\cmd.exe
track:
1
command_line:
"C:\Windows\System32\cmd.exe" /k attrib "C:\Users\Administrator.Oskar-PC\AppData\Local\Temp" +s +h
filepath_r:
C:\Windows\System32\cmd.exe
stack_pivoted:
0
creation_flags:
67634192
(CREATE_DEFAULT_ERROR_MODE|CREATE_NEW_CONSOLE|CREATE_UNICODE_ENVIRONMENT|EXTENDED_STARTUPINFO_PRESENT)
process_handle:
0x000002a4
inherit_handles:
0
|
success
|
1 |
0
|
1620759749.220125
CreateProcessInternalW
|
thread_identifier:
2860
thread_handle:
0x00000278
process_identifier:
2636
current_directory:
filepath:
track:
1
command_line:
notepad
filepath_r:
stack_pivoted:
0
creation_flags:
134217728
(CREATE_NO_WINDOW)
process_handle:
0x00000288
inherit_handles:
0
|
success
|
1 |
0
|
1620759749.220125
NtAllocateVirtualMemory
|
process_identifier:
2636
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000288
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x000b0000
|
success
|
0 |
0
|
1620759749.220125
WriteProcessMemory
|
process_identifier:
2636
buffer:
kernel32.dll
process_handle:
0x00000288
base_address:
0x000b0000
|
success
|
1 |
0
|
1620759749.220125
NtAllocateVirtualMemory
|
process_identifier:
2636
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000288
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00100000
|
success
|
0 |
0
|
1620759749.220125
WriteProcessMemory
|
process_identifier:
2636
buffer:
user32.dll
process_handle:
0x00000288
base_address:
0x00100000
|
success
|
1 |
0
|
1620759749.220125
NtAllocateVirtualMemory
|
process_identifier:
2636
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000288
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00110000
|
success
|
0 |
0
|
1620759749.220125
WriteProcessMemory
|
process_identifier:
2636
buffer:
Sleep
process_handle:
0x00000288
base_address:
0x00110000
|
success
|
1 |
0
|
1620759749.220125
NtAllocateVirtualMemory
|
process_identifier:
2636
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000288
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00120000
|
success
|
0 |
0
|
1620759749.220125
WriteProcessMemory
|
process_identifier:
2636
buffer:
MessageBoxA
process_handle:
0x00000288
base_address:
0x00120000
|
success
|
1 |
0
|
1620759749.220125
NtAllocateVirtualMemory
|
process_identifier:
2636
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000288
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00130000
|
success
|
0 |
0
|
1620759749.220125
WriteProcessMemory
|
process_identifier:
2636
buffer:
ExitThread
process_handle:
0x00000288
base_address:
0x00130000
|
success
|
1 |
0
|
1620759749.220125
NtAllocateVirtualMemory
|
process_identifier:
2636
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000288
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00140000
|
success
|
0 |
0
|
1620759749.220125
WriteProcessMemory
|
process_identifier:
2636
buffer:
DeleteFileA
process_handle:
0x00000288
base_address:
0x00140000
|
success
|
1 |
0
|
1620759749.220125
NtAllocateVirtualMemory
|
process_identifier:
2636
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000288
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00150000
|
success
|
0 |
0
|
1620759749.220125
WriteProcessMemory
|
process_identifier:
2636
buffer:
GetLastError
process_handle:
0x00000288
base_address:
0x00150000
|
success
|
1 |
0
|
1620759749.220125
NtAllocateVirtualMemory
|
process_identifier:
2636
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000288
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00160000
|
success
|
0 |
0
|
1620759749.220125
WriteProcessMemory
|
process_identifier:
2636
buffer:
TerminateProcess
process_handle:
0x00000288
base_address:
0x00160000
|
success
|
1 |
0
|
1620759749.220125
NtAllocateVirtualMemory
|
process_identifier:
2636
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000288
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00170000
|
success
|
0 |
0
|
1620759749.220125
WriteProcessMemory
|
process_identifier:
2636
buffer:
CloseHandle
process_handle:
0x00000288
base_address:
0x00170000
|
success
|
1 |
0
|
1620759749.220125
NtAllocateVirtualMemory
|
process_identifier:
2636
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000288
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00180000
|
success
|
0 |
0
|
1620759749.220125
WriteProcessMemory
|
process_identifier:
2636
buffer:
OpenProcess
process_handle:
0x00000288
base_address:
0x00180000
|
success
|
1 |
0
|
1620759749.220125
NtAllocateVirtualMemory
|
process_identifier:
2636
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000288
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00190000
|
success
|
0 |
0
|
1620759749.220125
WriteProcessMemory
|
process_identifier:
2636
buffer:
GetExitCodeProcess
process_handle:
0x00000288
base_address:
0x00190000
|
success
|
1 |
0
|
1620759749.220125
NtAllocateVirtualMemory
|
process_identifier:
2636
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000288
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x001a0000
|
success
|
0 |
0
|
1620759749.220125
WriteProcessMemory
|
process_identifier:
2636
buffer:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\32307c24db9052003547acd8c7814a09.exe
process_handle:
0x00000288
base_address:
0x001a0000
|
success
|
1 |
0
|
1620759749.220125
NtAllocateVirtualMemory
|
process_identifier:
2636
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000288
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x001b0000
|
success
|
0 |
0
|
1620759749.220125
WriteProcessMemory
|
process_identifier:
2636
buffer:
×I5v"5vF@ ÕØwDT5vÀ5vØ6v5v5vM6v L
process_handle:
0x00000288
base_address:
0x001b0000
|
success
|
1 |
0
|
1620759749.220125
NtAllocateVirtualMemory
|
process_identifier:
2636
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000288
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x001c0000
|
success
|
0 |
0
|
1620759749.220125
WriteProcessMemory
|
process_identifier:
2636
buffer:
UìSVW]C4PC,PÿPÿSCC8PC0PÿPÿSCC<PC,PÿPÿSCC@PC,PÿPÿSCCDPC,PÿPÿSCCHPC,PÿPÿSCCTPC,PÿPÿSC CLPC,PÿPÿSC$CPPC,PÿPÿSC(ëÿSøthô ÿSC\PÿSÀtåCXPj jÿS$ð
ötWVÿS(WVÿSVÿS j ÿS_^[] ÀUìÄ@ÿÿÿSV3ÉMôUøEüEüè.
ùÿEøè&
ùÿu3ÀUhFRG dÿ0d
Pÿÿÿ3ɺD è+ëøÿÇ
PÿÿÿD Ç
|ÿÿÿ fÇE
@ÿÿÿP
PÿÿÿPj j h j j j EüèÔ ùÿPj è)ùÿ@ÿÿÿEüèNRùÿÀu
Eüº\RG èùÿEøè5RùÿÀu
Uø3Àèï¡ùÿEôUøèxùÿºdRG ÃèüüÿÿF,ºtRG ÃèíüÿÿF0ºRG ÃèÞüÿÿF4ºRG ÃèÏüÿÿF8ºRG ÃèÀüÿÿF<º RG Ãè±üÿÿF@º¬RG Ãè¢üÿÿFDº¼RG ÃèüÿÿFHºÐRG ÃèüÿÿFTºÜRG ÃèuüÿÿFLºèRG ÃèfüÿÿFPEôèßùÿÐÃèRüÿÿF\
HÿÿÿFXhüRG hSG èç)ùÿPèé)ùÿhSG hSG èÐ)ùÿPèÒ)ùÿFhRG hSG è¸)ùÿPèº)ùÿFhRG hSG è )ùÿPè¢)ùÿFhRG hSG è)ùÿPè)ùÿFh RG hSG èp)ùÿPèr)ùÿFh¬RG hSG èX)ùÿPèZ)ùÿFh¼RG hSG è@)ùÿPèB)ùÿFhÐRG hSG è()ùÿPè*)ùÿF hÜRG hSG è)ùÿPè)ùÿF$hèRG hSG èø(ùÿPèú(ùÿF(j`j κNG Ãèõûÿÿ3ÀZYYdhMRG Eôº èùÿÃ
process_handle:
0x00000288
base_address:
0x001c0000
|
success
|
1 |
0
|
1620759751.674125
CreateProcessInternalW
|
thread_identifier:
3212
thread_handle:
0x00000434
process_identifier:
3208
current_directory:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp
filepath:
C:\Users\Administrator.Oskar-PC\Documents\MSDCSC\msdcsc.exe
track:
1
command_line:
"C:\Users\Administrator.Oskar-PC\Documents\MSDCSC\msdcsc.exe"
filepath_r:
C:\Users\Administrator.Oskar-PC\Documents\MSDCSC\msdcsc.exe
stack_pivoted:
0
creation_flags:
67634192
(CREATE_DEFAULT_ERROR_MODE|CREATE_NEW_CONSOLE|CREATE_UNICODE_ENVIRONMENT|EXTENDED_STARTUPINFO_PRESENT)
process_handle:
0x00000440
inherit_handles:
0
|
success
|
1 |
0
|
1620759749.283125
CreateProcessInternalW
|
thread_identifier:
2740
thread_handle:
0x00000080
process_identifier:
2256
current_directory:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp
filepath:
C:\Windows\System32\attrib.exe
track:
1
command_line:
attrib "C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\32307c24db9052003547acd8c7814a09.exe" +s +h
filepath_r:
C:\Windows\system32\attrib.exe
stack_pivoted:
0
creation_flags:
524288
(EXTENDED_STARTUPINFO_PRESENT)
process_handle:
0x00000084
inherit_handles:
1
|
success
|
1 |
0
|
1620759749.830375
CreateProcessInternalW
|
thread_identifier:
3092
thread_handle:
0x00000080
process_identifier:
3088
current_directory:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp
filepath:
C:\Windows\System32\attrib.exe
track:
1
command_line:
attrib "C:\Users\Administrator.Oskar-PC\AppData\Local\Temp" +s +h
filepath_r:
C:\Windows\system32\attrib.exe
stack_pivoted:
0
creation_flags:
524288
(EXTENDED_STARTUPINFO_PRESENT)
process_handle:
0x00000084
inherit_handles:
1
|
success
|
1 |
0
|
1620759752.283625
NtResumeThread
|
thread_handle:
0x00000174
suspend_count:
1
process_identifier:
3208
|
success
|
0 |
0
|
1620759753.127625
CreateProcessInternalW
|
thread_identifier:
3288
thread_handle:
0x00000244
process_identifier:
3284
current_directory:
filepath:
C:\Program Files (x86)\Internet Explorer\iexplore.exe
track:
1
command_line:
filepath_r:
C:\Program Files (x86)\Internet Explorer\iexplore.exe
stack_pivoted:
0
creation_flags:
4
(CREATE_SUSPENDED)
process_handle:
0x00000248
inherit_handles:
0
|
success
|
1 |
0
|
1620759753.127625
NtGetContextThread
|
thread_handle:
0x00000244
|
success
|
0 |
0
|
1620759753.127625
NtAllocateVirtualMemory
|
process_identifier:
3284
region_size:
749568
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000248
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00400000
|
failed
|
3221225496 |
0
|
1620759754.158625
CreateProcessInternalW
|
thread_identifier:
3376
thread_handle:
0x0000025c
process_identifier:
3372
current_directory:
filepath:
C:\Windows\explorer.exe
track:
1
command_line:
filepath_r:
C:\Windows\explorer.exe
stack_pivoted:
0
creation_flags:
4
(CREATE_SUSPENDED)
process_handle:
0x0000024c
inherit_handles:
0
|
success
|
1 |
0
|
1620759754.158625
NtGetContextThread
|
thread_handle:
0x0000025c
|
failed
|
3221225485 |
0
|
1620759755.783625
CreateProcessInternalW
|
thread_identifier:
3436
thread_handle:
0x00000260
process_identifier:
3432
current_directory:
filepath:
track:
1
command_line:
notepad
filepath_r:
stack_pivoted:
0
creation_flags:
134217728
(CREATE_NO_WINDOW)
process_handle:
0x00000268
inherit_handles:
0
|
success
|
1 |
0
|
1620759755.783625
NtAllocateVirtualMemory
|
process_identifier:
3432
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000268
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x000b0000
|
success
|
0 |
0
|
1620759755.783625
WriteProcessMemory
|
process_identifier:
3432
buffer:
kernel32.dll
process_handle:
0x00000268
base_address:
0x000b0000
|
success
|
1 |
0
|
1620759755.783625
NtAllocateVirtualMemory
|
process_identifier:
3432
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000268
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x000c0000
|
success
|
0 |
0
|
1620759755.783625
WriteProcessMemory
|
process_identifier:
3432
buffer:
user32.dll
process_handle:
0x00000268
base_address:
0x000c0000
|
success
|
1 |
0
|
1620759755.783625
NtAllocateVirtualMemory
|
process_identifier:
3432
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000268
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x000d0000
|
success
|
0 |
0
|
1620759755.783625
WriteProcessMemory
|
process_identifier:
3432
buffer:
Sleep
process_handle:
0x00000268
base_address:
0x000d0000
|
success
|
1 |
0
|
1620759755.783625
NtAllocateVirtualMemory
|
process_identifier:
3432
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000268
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x000e0000
|
success
|
0 |
0
|
1620759755.783625
WriteProcessMemory
|
process_identifier:
3432
buffer:
MessageBoxA
process_handle:
0x00000268
base_address:
0x000e0000
|
success
|
1 |
0
|