| Time & API |
Arguments |
Status |
Return |
Repeated |
1620762839.172375
NtResumeThread
|
thread_handle:
0x00000208
suspend_count:
1
process_identifier:
2632
|
success
|
0 |
0
|
1620762839.531375
CreateProcessInternalW
|
thread_identifier:
1760
thread_handle:
0x00000198
process_identifier:
2732
current_directory:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp
filepath:
C:\Windows\System32\wscript.exe
track:
1
command_line:
"C:\Windows\System32\WScript.exe" "C:\Users\ADMINI~1.OSK\AppData\Local\Temp\z6NePsMNYPKFwFZAnp3Jk1b1XqKTVW5bWUz.vbs"
filepath_r:
C:\Windows\System32\WScript.exe
stack_pivoted:
0
creation_flags:
67634192
(CREATE_DEFAULT_ERROR_MODE|CREATE_NEW_CONSOLE|CREATE_UNICODE_ENVIRONMENT|EXTENDED_STARTUPINFO_PRESENT)
process_handle:
0x000001b0
inherit_handles:
0
|
success
|
1 |
0
|
1620762839.563375
CreateProcessInternalW
|
thread_identifier:
420
thread_handle:
0x0000010c
process_identifier:
1108
current_directory:
filepath:
track:
1
command_line:
"C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\59eb031f2da8ee9d5499c9147c2253fb.exe"
filepath_r:
stack_pivoted:
0
creation_flags:
4
(CREATE_SUSPENDED)
process_handle:
0x000001dc
inherit_handles:
0
|
success
|
1 |
0
|
1620762839.563375
NtGetContextThread
|
thread_handle:
0x0000010c
|
success
|
0 |
0
|
1620762839.563375
NtUnmapViewOfSection
|
process_identifier:
1108
region_size:
4096
process_handle:
0x000001dc
base_address:
0x00400000
|
success
|
0 |
0
|
1620762839.563375
NtMapViewOfSection
|
section_handle:
0x00000104
process_identifier:
1108
commit_size:
131072
win32_protect:
64
(PAGE_EXECUTE_READWRITE)
buffer:
process_handle:
0x000001dc
allocation_type:
0
()
section_offset:
0
view_size:
131072
base_address:
0x00400000
|
success
|
0 |
0
|
1620762839.563375
NtMapViewOfSection
|
section_handle:
0x000001e0
process_identifier:
1108
commit_size:
4096
win32_protect:
64
(PAGE_EXECUTE_READWRITE)
buffer:
process_handle:
0x000001dc
allocation_type:
0
()
section_offset:
0
view_size:
4096
base_address:
0x001e0000
|
success
|
0 |
0
|
1620762839.563375
NtSetContextThread
|
thread_handle:
0x0000010c
registers.eip:
2010382788
registers.esp:
1638384
registers.edi:
0
registers.eax:
4302468
registers.ebp:
0
registers.edx:
0
registers.ebx:
2130567168
registers.esi:
0
registers.ecx:
0
process_identifier:
1108
|
success
|
0 |
0
|
1620762839.594375
NtResumeThread
|
thread_handle:
0x0000010c
suspend_count:
1
process_identifier:
1108
|
success
|
0 |
0
|
1620801159.972249
NtResumeThread
|
thread_handle:
0x00000420
suspend_count:
1
process_identifier:
2732
|
success
|
0 |
0
|
1620801150.909124
NtResumeThread
|
thread_handle:
0x000000e8
suspend_count:
1
process_identifier:
1108
|
success
|
0 |
0
|