| Time & API |
Arguments |
Status |
Return |
Repeated |
1619695917.741999
CreateProcessInternalW
|
thread_identifier:
1436
thread_handle:
0x00000100
process_identifier:
1432
current_directory:
filepath:
track:
1
command_line:
"C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\8208efff87339c95a7c0780dcb9f6533.exe"
filepath_r:
stack_pivoted:
0
creation_flags:
4
(CREATE_SUSPENDED)
process_handle:
0x00000104
inherit_handles:
0
|
success
|
1 |
0
|
1619695917.741999
NtUnmapViewOfSection
|
process_identifier:
1432
region_size:
4096
process_handle:
0x00000104
base_address:
0x00400000
|
success
|
0 |
0
|
1619695917.741999
NtMapViewOfSection
|
section_handle:
0x0000010c
process_identifier:
1432
commit_size:
208896
win32_protect:
64
(PAGE_EXECUTE_READWRITE)
buffer:
process_handle:
0x00000104
allocation_type:
0
()
section_offset:
0
view_size:
208896
base_address:
0x00400000
|
success
|
0 |
0
|
1619695917.741999
NtGetContextThread
|
thread_handle:
0x00000100
|
success
|
0 |
0
|
1619695917.741999
NtSetContextThread
|
thread_handle:
0x00000100
registers.eip:
0
registers.esp:
0
registers.edi:
0
registers.eax:
4203565
registers.ebp:
0
registers.edx:
0
registers.ebx:
2130567168
registers.esi:
0
registers.ecx:
0
process_identifier:
1432
|
success
|
0 |
0
|
1619695917.788999
NtResumeThread
|
thread_handle:
0x00000100
suspend_count:
1
process_identifier:
1432
|
success
|
0 |
0
|
1619695917.804999
CreateProcessInternalW
|
thread_identifier:
708
thread_handle:
0x00000108
process_identifier:
1632
current_directory:
filepath:
track:
1
command_line:
"C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\8208efff87339c95a7c0780dcb9f6533.exe" 2 1432 28896312
filepath_r:
stack_pivoted:
0
creation_flags:
32
(NORMAL_PRIORITY_CLASS)
process_handle:
0x00000118
inherit_handles:
0
|
success
|
1 |
0
|
1619695924.352626
CreateProcessInternalW
|
thread_identifier:
2008
thread_handle:
0x00000220
process_identifier:
616
current_directory:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Install\Host.exe
track:
1
command_line:
"C:\Users\Administrator.Oskar-PC\AppData\Roaming\Install\Host.exe" -m "C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\8208efff87339c95a7c0780dcb9f6533.exe"
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Install\Host.exe
stack_pivoted:
0
creation_flags:
67634192
(CREATE_DEFAULT_ERROR_MODE|CREATE_NEW_CONSOLE|CREATE_UNICODE_ENVIRONMENT|EXTENDED_STARTUPINFO_PRESENT)
process_handle:
0x000002a0
inherit_handles:
0
|
success
|
1 |
0
|
1619695950.211249
CreateProcessInternalW
|
thread_identifier:
3464
thread_handle:
0x000005a0
process_identifier:
3460
current_directory:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\8208efff87339c95a7c0780dcb9f6533.exe
track:
1
command_line:
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\8208efff87339c95a7c0780dcb9f6533.exe
stack_pivoted:
0
creation_flags:
32
(NORMAL_PRIORITY_CLASS)
process_handle:
0x000005a4
inherit_handles:
0
|
success
|
1 |
0
|
1619695924.664499
CreateProcessInternalW
|
thread_identifier:
1208
thread_handle:
0x00000100
process_identifier:
1380
current_directory:
filepath:
track:
1
command_line:
"C:\Users\Administrator.Oskar-PC\AppData\Roaming\Install\Host.exe" -m "C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\8208efff87339c95a7c0780dcb9f6533.exe"
filepath_r:
stack_pivoted:
0
creation_flags:
4
(CREATE_SUSPENDED)
process_handle:
0x00000104
inherit_handles:
0
|
success
|
1 |
0
|
1619695924.664499
NtUnmapViewOfSection
|
process_identifier:
1380
region_size:
4096
process_handle:
0x00000104
base_address:
0x00400000
|
success
|
0 |
0
|
1619695924.664499
NtMapViewOfSection
|
section_handle:
0x0000010c
process_identifier:
1380
commit_size:
208896
win32_protect:
64
(PAGE_EXECUTE_READWRITE)
buffer:
process_handle:
0x00000104
allocation_type:
0
()
section_offset:
0
view_size:
208896
base_address:
0x00400000
|
success
|
0 |
0
|
1619695924.680499
NtGetContextThread
|
thread_handle:
0x00000100
|
success
|
0 |
0
|
1619695924.680499
NtSetContextThread
|
thread_handle:
0x00000100
registers.eip:
0
registers.esp:
0
registers.edi:
0
registers.eax:
4203565
registers.ebp:
0
registers.edx:
0
registers.ebx:
2130567168
registers.esi:
0
registers.ecx:
0
process_identifier:
1380
|
success
|
0 |
0
|
1619695924.711499
NtResumeThread
|
thread_handle:
0x00000100
suspend_count:
1
process_identifier:
1380
|
success
|
0 |
0
|
1619695924.727499
CreateProcessInternalW
|
thread_identifier:
1816
thread_handle:
0x00000108
process_identifier:
2424
current_directory:
filepath:
track:
1
command_line:
"C:\Users\Administrator.Oskar-PC\AppData\Roaming\Install\Host.exe" 2 1380 28903234
filepath_r:
stack_pivoted:
0
creation_flags:
32
(NORMAL_PRIORITY_CLASS)
process_handle:
0x00000118
inherit_handles:
0
|
success
|
1 |
0
|
1619695950.430501
CreateProcessInternalW
|
thread_identifier:
3544
thread_handle:
0x00000100
process_identifier:
3540
current_directory:
filepath:
track:
1
command_line:
"C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\8208efff87339c95a7c0780dcb9f6533.exe"
filepath_r:
stack_pivoted:
0
creation_flags:
4
(CREATE_SUSPENDED)
process_handle:
0x00000104
inherit_handles:
0
|
success
|
1 |
0
|
1619695950.430501
NtUnmapViewOfSection
|
process_identifier:
3540
region_size:
4096
process_handle:
0x00000104
base_address:
0x00400000
|
success
|
0 |
0
|
1619695950.430501
NtMapViewOfSection
|
section_handle:
0x0000010c
process_identifier:
3540
commit_size:
208896
win32_protect:
64
(PAGE_EXECUTE_READWRITE)
buffer:
process_handle:
0x00000104
allocation_type:
0
()
section_offset:
0
view_size:
208896
base_address:
0x00400000
|
success
|
0 |
0
|
1619695950.430501
NtGetContextThread
|
thread_handle:
0x00000100
|
success
|
0 |
0
|
1619695950.430501
NtSetContextThread
|
thread_handle:
0x00000100
registers.eip:
0
registers.esp:
0
registers.edi:
0
registers.eax:
4203565
registers.ebp:
0
registers.edx:
0
registers.ebx:
2130567168
registers.esi:
0
registers.ecx:
0
process_identifier:
3540
|
success
|
0 |
0
|
1619695950.445501
NtResumeThread
|
thread_handle:
0x00000100
suspend_count:
1
process_identifier:
3540
|
success
|
0 |
0
|
1619695950.461501
CreateProcessInternalW
|
thread_identifier:
3604
thread_handle:
0x00000108
process_identifier:
3600
current_directory:
filepath:
track:
1
command_line:
"C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\8208efff87339c95a7c0780dcb9f6533.exe" 2 3540 28928968
filepath_r:
stack_pivoted:
0
creation_flags:
32
(NORMAL_PRIORITY_CLASS)
process_handle:
0x00000118
inherit_handles:
0
|
success
|
1 |
0
|
1619695959.617874
CreateProcessInternalW
|
thread_identifier:
3740
thread_handle:
0x0000024c
process_identifier:
3736
current_directory:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\8208efff87339c95a7c0780dcb9f6533.exe
track:
1
command_line:
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\8208efff87339c95a7c0780dcb9f6533.exe
stack_pivoted:
0
creation_flags:
32
(NORMAL_PRIORITY_CLASS)
process_handle:
0x00000250
inherit_handles:
0
|
success
|
1 |
0
|
1619695959.805751
CreateProcessInternalW
|
thread_identifier:
3812
thread_handle:
0x00000100
process_identifier:
3808
current_directory:
filepath:
track:
1
command_line:
"C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\8208efff87339c95a7c0780dcb9f6533.exe"
filepath_r:
stack_pivoted:
0
creation_flags:
4
(CREATE_SUSPENDED)
process_handle:
0x00000104
inherit_handles:
0
|
success
|
1 |
0
|
1619695959.805751
NtUnmapViewOfSection
|
process_identifier:
3808
region_size:
4096
process_handle:
0x00000104
base_address:
0x00400000
|
success
|
0 |
0
|
1619695959.805751
NtMapViewOfSection
|
section_handle:
0x0000010c
process_identifier:
3808
commit_size:
208896
win32_protect:
64
(PAGE_EXECUTE_READWRITE)
buffer:
process_handle:
0x00000104
allocation_type:
0
()
section_offset:
0
view_size:
208896
base_address:
0x00400000
|
success
|
0 |
0
|
1619695959.805751
NtGetContextThread
|
thread_handle:
0x00000100
|
success
|
0 |
0
|
1619695959.805751
NtSetContextThread
|
thread_handle:
0x00000100
registers.eip:
0
registers.esp:
0
registers.edi:
0
registers.eax:
4203565
registers.ebp:
0
registers.edx:
0
registers.ebx:
2130567168
registers.esi:
0
registers.ecx:
0
process_identifier:
3808
|
success
|
0 |
0
|
1619695959.836751
NtResumeThread
|
thread_handle:
0x00000100
suspend_count:
1
process_identifier:
3808
|
success
|
0 |
0
|
1619695959.852751
CreateProcessInternalW
|
thread_identifier:
3876
thread_handle:
0x00000108
process_identifier:
3872
current_directory:
filepath:
track:
1
command_line:
"C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\8208efff87339c95a7c0780dcb9f6533.exe" 2 3808 28938359
filepath_r:
stack_pivoted:
0
creation_flags:
32
(NORMAL_PRIORITY_CLASS)
process_handle:
0x00000118
inherit_handles:
0
|
success
|
1 |
0
|
1619695968.352499
CreateProcessInternalW
|
thread_identifier:
3988
thread_handle:
0x00000238
process_identifier:
3984
current_directory:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\8208efff87339c95a7c0780dcb9f6533.exe
track:
1
command_line:
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\8208efff87339c95a7c0780dcb9f6533.exe
stack_pivoted:
0
creation_flags:
32
(NORMAL_PRIORITY_CLASS)
process_handle:
0x0000023c
inherit_handles:
0
|
success
|
1 |
0
|
1619695968.539499
CreateProcessInternalW
|
thread_identifier:
4060
thread_handle:
0x00000100
process_identifier:
4056
current_directory:
filepath:
track:
1
command_line:
"C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\8208efff87339c95a7c0780dcb9f6533.exe"
filepath_r:
stack_pivoted:
0
creation_flags:
4
(CREATE_SUSPENDED)
process_handle:
0x00000104
inherit_handles:
0
|
success
|
1 |
0
|
1619695968.539499
NtUnmapViewOfSection
|
process_identifier:
4056
region_size:
4096
process_handle:
0x00000104
base_address:
0x00400000
|
success
|
0 |
0
|
1619695968.539499
NtMapViewOfSection
|
section_handle:
0x0000010c
process_identifier:
4056
commit_size:
208896
win32_protect:
64
(PAGE_EXECUTE_READWRITE)
buffer:
process_handle:
0x00000104
allocation_type:
0
()
section_offset:
0
view_size:
208896
base_address:
0x00400000
|
success
|
0 |
0
|
1619695968.539499
NtGetContextThread
|
thread_handle:
0x00000100
|
success
|
0 |
0
|
1619695968.539499
NtSetContextThread
|
thread_handle:
0x00000100
registers.eip:
0
registers.esp:
0
registers.edi:
0
registers.eax:
4203565
registers.ebp:
0
registers.edx:
0
registers.ebx:
2130567168
registers.esi:
0
registers.ecx:
0
process_identifier:
4056
|
success
|
0 |
0
|
1619695968.570499
NtResumeThread
|
thread_handle:
0x00000100
suspend_count:
1
process_identifier:
4056
|
success
|
0 |
0
|
1619695968.586499
CreateProcessInternalW
|
thread_identifier:
3108
thread_handle:
0x00000108
process_identifier:
2008
current_directory:
filepath:
track:
1
command_line:
"C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\8208efff87339c95a7c0780dcb9f6533.exe" 2 4056 28947093
filepath_r:
stack_pivoted:
0
creation_flags:
32
(NORMAL_PRIORITY_CLASS)
process_handle:
0x00000118
inherit_handles:
0
|
success
|
1 |
0
|
1619695977.320874
CreateProcessInternalW
|
thread_identifier:
2080
thread_handle:
0x0000023c
process_identifier:
3228
current_directory:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\8208efff87339c95a7c0780dcb9f6533.exe
track:
1
command_line:
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\8208efff87339c95a7c0780dcb9f6533.exe
stack_pivoted:
0
creation_flags:
32
(NORMAL_PRIORITY_CLASS)
process_handle:
0x00000240
inherit_handles:
0
|
success
|
1 |
0
|