| Time & API |
Arguments |
Status |
Return |
Repeated |
1619686132.224119
NtResumeThread
|
thread_handle:
0x00000174
suspend_count:
1
process_identifier:
1436
|
success
|
0 |
0
|
1619686132.692119
CreateProcessInternalW
|
thread_identifier:
2216
thread_handle:
0x000001a0
process_identifier:
2468
current_directory:
filepath:
track:
1
command_line:
notepad
filepath_r:
stack_pivoted:
0
creation_flags:
134217728
(CREATE_NO_WINDOW)
process_handle:
0x000001a4
inherit_handles:
0
|
success
|
1 |
0
|
1619686132.692119
NtAllocateVirtualMemory
|
process_identifier:
2468
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000001a4
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x000f0000
|
success
|
0 |
0
|
1619686132.692119
WriteProcessMemory
|
process_identifier:
2468
buffer:
kernel32.dll
process_handle:
0x000001a4
base_address:
0x000f0000
|
success
|
1 |
0
|
1619686132.692119
NtAllocateVirtualMemory
|
process_identifier:
2468
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000001a4
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00010000
|
success
|
0 |
0
|
1619686132.692119
WriteProcessMemory
|
process_identifier:
2468
buffer:
user32.dll
process_handle:
0x000001a4
base_address:
0x00010000
|
success
|
1 |
0
|
1619686132.692119
NtAllocateVirtualMemory
|
process_identifier:
2468
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000001a4
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00020000
|
success
|
0 |
0
|
1619686132.692119
WriteProcessMemory
|
process_identifier:
2468
buffer:
Sleep
process_handle:
0x000001a4
base_address:
0x00020000
|
success
|
1 |
0
|
1619686132.692119
NtAllocateVirtualMemory
|
process_identifier:
2468
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000001a4
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00100000
|
success
|
0 |
0
|
1619686132.692119
WriteProcessMemory
|
process_identifier:
2468
buffer:
MessageBoxA
process_handle:
0x000001a4
base_address:
0x00100000
|
success
|
1 |
0
|
1619686132.692119
NtAllocateVirtualMemory
|
process_identifier:
2468
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000001a4
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00110000
|
success
|
0 |
0
|
1619686132.692119
WriteProcessMemory
|
process_identifier:
2468
buffer:
CreateProcessA
process_handle:
0x000001a4
base_address:
0x00110000
|
success
|
1 |
0
|
1619686132.692119
NtAllocateVirtualMemory
|
process_identifier:
2468
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000001a4
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00120000
|
success
|
0 |
0
|
1619686132.692119
WriteProcessMemory
|
process_identifier:
2468
buffer:
GetLastError
process_handle:
0x000001a4
base_address:
0x00120000
|
success
|
1 |
0
|
1619686132.692119
NtAllocateVirtualMemory
|
process_identifier:
2468
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000001a4
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00130000
|
success
|
0 |
0
|
1619686132.692119
WriteProcessMemory
|
process_identifier:
2468
buffer:
SetLastError
process_handle:
0x000001a4
base_address:
0x00130000
|
success
|
1 |
0
|
1619686132.692119
NtAllocateVirtualMemory
|
process_identifier:
2468
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000001a4
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00140000
|
success
|
0 |
0
|
1619686132.692119
WriteProcessMemory
|
process_identifier:
2468
buffer:
CreateMutexA
process_handle:
0x000001a4
base_address:
0x00140000
|
success
|
1 |
0
|
1619686132.692119
NtAllocateVirtualMemory
|
process_identifier:
2468
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000001a4
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00150000
|
success
|
0 |
0
|
1619686132.692119
WriteProcessMemory
|
process_identifier:
2468
buffer:
CloseHandle
process_handle:
0x000001a4
base_address:
0x00150000
|
success
|
1 |
0
|
1619686132.692119
NtAllocateVirtualMemory
|
process_identifier:
2468
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000001a4
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00160000
|
success
|
0 |
0
|
1619686132.692119
WriteProcessMemory
|
process_identifier:
2468
buffer:
ExitThread
process_handle:
0x000001a4
base_address:
0x00160000
|
success
|
1 |
0
|
1619686132.692119
NtAllocateVirtualMemory
|
process_identifier:
2468
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000001a4
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00170000
|
success
|
0 |
0
|
1619686132.692119
WriteProcessMemory
|
process_identifier:
2468
buffer:
OpenProcess
process_handle:
0x000001a4
base_address:
0x00170000
|
success
|
1 |
0
|
1619686132.692119
NtAllocateVirtualMemory
|
process_identifier:
2468
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000001a4
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00180000
|
success
|
0 |
0
|
1619686132.692119
WriteProcessMemory
|
process_identifier:
2468
buffer:
DCPERSFWBP
process_handle:
0x000001a4
base_address:
0x00180000
|
success
|
1 |
0
|
1619686132.692119
NtAllocateVirtualMemory
|
process_identifier:
2468
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000001a4
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00190000
|
success
|
0 |
0
|
1619686132.692119
WriteProcessMemory
|
process_identifier:
2468
buffer:
TerminateProcess
process_handle:
0x000001a4
base_address:
0x00190000
|
success
|
1 |
0
|
1619686132.692119
NtAllocateVirtualMemory
|
process_identifier:
2468
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000001a4
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00030000
|
success
|
0 |
0
|
1619686132.692119
WriteProcessMemory
|
process_identifier:
2468
buffer:
GetExitCodeProcess
process_handle:
0x000001a4
base_address:
0x00030000
|
success
|
1 |
0
|
1619686132.692119
NtAllocateVirtualMemory
|
process_identifier:
2468
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000001a4
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x001a0000
|
success
|
0 |
0
|
1619686132.692119
WriteProcessMemory
|
process_identifier:
2468
buffer:
DC_MUTEX-P4MPQBE
process_handle:
0x000001a4
base_address:
0x001a0000
|
success
|
1 |
0
|
1619686132.692119
NtAllocateVirtualMemory
|
process_identifier:
2468
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000001a4
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x001b0000
|
success
|
0 |
0
|
1619686132.692119
WriteProcessMemory
|
process_identifier:
2468
buffer:
WaitForSingleObject
process_handle:
0x000001a4
base_address:
0x001b0000
|
success
|
1 |
0
|
1619686132.692119
NtAllocateVirtualMemory
|
process_identifier:
2468
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000001a4
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x001c0000
|
success
|
0 |
0
|
1619686132.692119
WriteProcessMemory
|
process_identifier:
2468
buffer:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\8be33a14d056b3fa353ef25d992b6055.exe
process_handle:
0x000001a4
base_address:
0x001c0000
|
success
|
1 |
0
|
1619686132.692119
NtAllocateVirtualMemory
|
process_identifier:
2468
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000001a4
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00220000
|
success
|
0 |
0
|
1619686132.692119
WriteProcessMemory
|
process_identifier:
2468
buffer:
×I5v"5vý_wÿ5vÀ5vr5v65v©5vÕØw5vØ6v5vM6vkL5v ¤
process_handle:
0x000001a4
base_address:
0x00220000
|
success
|
1 |
0
|
1619686132.692119
NtAllocateVirtualMemory
|
process_identifier:
2468
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000001a4
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00230000
|
success
|
0 |
0
|
1619686132.692119
WriteProcessMemory
|
process_identifier:
2468
buffer:
UìĬSVW]C@PC8PÿPÿSCCDPC<PÿPÿSCCTPC8PÿPÿSCCXPC8PÿPÿSCCHPC8PÿPÿSCCLPC8PÿPÿSCCPPC8PÿPÿSC4C`PC8PÿPÿSC,ClPC8PÿPÿSC(ChPC8PÿPÿSC0CdPC8PÿPÿSC CpPC8PÿPÿSC$j ÿSCxPj j ÿS4ÿS=· u$C|Pj jÿS$ø
ÿtVWÿS0VWÿS(WÿS,j ÿS j ÿSC\Pj j ÿS4øÿS=· tRWÿS,ÇE¼D E¬PE¼Pj j j j j j CtPj ÿS
Àt3öhÈ E¬PÿSèsÎÿ
ötèë¼hÐ ÿSë²WÿS,hô ÿSë_^[å] UìÄ ÿÿÿSVWMôUøEüEüèëùÿEøèãùÿEôèÛùÿµtÿÿÿ3ÀUh)XG dÿ0d
0ÿÿÿ3ɺD èÝåøÿÇ
0ÿÿÿD Ç
\ÿÿÿ fÇ
`ÿÿÿ Eüè0MùÿÀu
Eüº@XG è{ ùÿEøèMùÿÀu
Uø3ÀèÑùÿ¿HXG
ÿÿÿP
0ÿÿÿPj j h j j j EüèOùÿPj è$ùÿ ÿÿÿºTXG Ãè±÷ÿÿF8ºdXG Ãè¢÷ÿÿF<ºpXG Ãè÷ÿÿF@ºxXG Ãè÷ÿÿFDºXG Ãèu÷ÿÿFTºXG Ãèf÷ÿÿFHº¤XG ÃèW÷ÿÿFLº´XG ÃèH÷ÿÿFPºÄXG Ãè9÷ÿÿF`ºÐXG Ãè*÷ÿÿFdºÜXG Ãè÷ÿÿFp×Ãè÷ÿÿFxºèXG Ãè ÷ÿÿFlºüXG ÃèñöÿÿFhEôèjùÿÐÃèÝöÿÿF\ºYG ÃèÎöÿÿFXEøèGùÿÐÃèºöÿÿFt
(ÿÿÿF|h$YG h4YG èO$ùÿPèQ$ùÿh@YG h4YG è8$ùÿPè:$ùÿFhpXG h4YG è $ùÿPè"$ùÿFhxXG hPYG è$ùÿPè
$ùÿFhÄXG h4YG èð#ùÿPèò#ùÿF,hXG h4YG èØ#ùÿPèÚ#ùÿFhXG h4YG èÀ#ùÿPèÂ#ùÿFh¤XG h4YG è¨#ùÿPèª#ùÿFh´XG h4YG è#ùÿPè#ùÿF4hüXG h4YG èx#ùÿPèz#ùÿF0hÐXG h4YG è`#ùÿPèb#ùÿF hèXG h4YG èH#ùÿPèJ#ùÿF(hYG h4YG è0#ùÿPè2#ùÿFhÜXG h4YG è#ùÿPè#ùÿF$h j κ(SG Ãèöÿÿ3ÀZYYdh0XG Eôº è,ýøÿÃ
process_handle:
0x000001a4
base_address:
0x00230000
|
success
|
1 |
0
|
1619686132.692119
NtResumeThread
|
thread_handle:
0x000001b4
suspend_count:
1
process_identifier:
1436
|
success
|
0 |
0
|