| Time & API |
Arguments |
Status |
Return |
Repeated |
1619999685.114436
CreateProcessInternalW
|
thread_identifier:
2368
thread_handle:
0x000001a8
process_identifier:
2228
current_directory:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp
filepath:
C:\Program Files\Google\Chrome\Application\chrome.exe
track:
1
command_line:
"C:\Program Files\Google\Chrome\Application\chrome.exe" --single-argument C:\Users\ADMINI~1.OSK\AppData\Local\Temp\Caixa.pdf
filepath_r:
C:\Program Files\Google\Chrome\Application\chrome.exe
stack_pivoted:
0
creation_flags:
67634192
(CREATE_DEFAULT_ERROR_MODE|CREATE_NEW_CONSOLE|CREATE_UNICODE_ENVIRONMENT|EXTENDED_STARTUPINFO_PRESENT)
process_handle:
0x000001b0
inherit_handles:
0
|
success
|
1 |
0
|
1619999685.145436
CreateProcessInternalW
|
thread_identifier:
392
thread_handle:
0x000000fc
process_identifier:
428
current_directory:
filepath:
track:
1
command_line:
"C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\f13aa37174903d14951c141da29ec4bc.exe"
filepath_r:
stack_pivoted:
0
creation_flags:
4
(CREATE_SUSPENDED)
process_handle:
0x00000104
inherit_handles:
0
|
success
|
1 |
0
|
1619999685.145436
NtUnmapViewOfSection
|
process_identifier:
428
region_size:
4096
process_handle:
0x00000104
base_address:
0x00400000
|
success
|
0 |
0
|
1619999685.160436
NtMapViewOfSection
|
section_handle:
0x0000018c
process_identifier:
428
commit_size:
208896
win32_protect:
64
(PAGE_EXECUTE_READWRITE)
buffer:
process_handle:
0x00000104
allocation_type:
0
()
section_offset:
0
view_size:
208896
base_address:
0x00400000
|
success
|
0 |
0
|
1619999685.160436
NtGetContextThread
|
thread_handle:
0x000000fc
|
success
|
0 |
0
|
1619999685.160436
NtSetContextThread
|
thread_handle:
0x000000fc
registers.eip:
0
registers.esp:
0
registers.edi:
0
registers.eax:
4203565
registers.ebp:
0
registers.edx:
0
registers.ebx:
2130567168
registers.esi:
0
registers.ecx:
0
process_identifier:
428
|
success
|
0 |
0
|
1619999685.426436
NtResumeThread
|
thread_handle:
0x000000fc
suspend_count:
1
process_identifier:
428
|
success
|
0 |
0
|
1619999685.582436
CreateProcessInternalW
|
thread_identifier:
1380
thread_handle:
0x00000190
process_identifier:
192
current_directory:
filepath:
track:
1
command_line:
"C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\f13aa37174903d14951c141da29ec4bc.exe" 2 428 7288312
filepath_r:
stack_pivoted:
0
creation_flags:
32
(NORMAL_PRIORITY_CLASS)
process_handle:
0x00000110
inherit_handles:
0
|
success
|
1 |
0
|
1620016689.694125
NtResumeThread
|
thread_handle:
0x0000000000000078
suspend_count:
1
process_identifier:
2228
|
success
|
0 |
0
|
1620016690.053125
CreateProcessInternalW
|
thread_identifier:
3084
thread_handle:
0x00000000000000c0
process_identifier:
3080
current_directory:
filepath:
C:\Program Files\Google\Chrome\Application\chrome.exe
track:
1
command_line:
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=89.0.4389.114 --initial-client-data=0xb0,0xb4,0xb8,0x84,0xbc,0x7fef23c4f50,0x7fef23c4f60,0x7fef23c4f70
filepath_r:
C:\Program Files\Google\Chrome\Application\chrome.exe
stack_pivoted:
0
creation_flags:
524288
(EXTENDED_STARTUPINFO_PRESENT)
process_handle:
0x00000000000000c4
inherit_handles:
1
|
success
|
1 |
0
|
1620016749.288125
CreateProcessInternalW
|
thread_identifier:
1760
thread_handle:
0x0000000000000578
process_identifier:
1752
current_directory:
filepath:
C:\Program Files\Google\Chrome\Application\chrome.exe
track:
1
command_line:
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=1052,15413193236887919189,2803694855300359941,131072 --gpu-preferences=SAAAAAAAAADgAAAwAAAAAAAAAAAAAAAAAABgAAAAAAAoAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAB4AAAAAAAAAHgAAAAAAAAAKAAAAAQAAAAgAAAAAAAAACgAAAAAAAAAMAAAAAAAAAA4AAAAAAAAABAAAAAAAAAAAAAAAAUAAAAQAAAAAAAAAAAAAAAGAAAAEAAAAAAAAAABAAAABQAAABAAAAAAAAAAAQAAAAYAAAAIAAAAAAAAAAgAAAAAAAAA --mojo-platform-channel-handle=1072 /prefetch:2
filepath_r:
C:\Program Files\Google\Chrome\Application\chrome.exe
stack_pivoted:
0
creation_flags:
17302540
(CREATE_BREAKAWAY_FROM_JOB|CREATE_SUSPENDED|CREATE_UNICODE_ENVIRONMENT|DETACHED_PROCESS|EXTENDED_STARTUPINFO_PRESENT)
process_handle:
0x0000000000000574
inherit_handles:
1
|
success
|
1 |
0
|
1620016690.694875
CreateProcessInternalW
|
thread_identifier:
3168
thread_handle:
0x0000021c
process_identifier:
3164
current_directory:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Install\Host.exe
track:
1
command_line:
"C:\Users\Administrator.Oskar-PC\AppData\Roaming\Install\Host.exe"
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Install\Host.exe
stack_pivoted:
0
creation_flags:
67634192
(CREATE_DEFAULT_ERROR_MODE|CREATE_NEW_CONSOLE|CREATE_UNICODE_ENVIRONMENT|EXTENDED_STARTUPINFO_PRESENT)
process_handle:
0x0000029c
inherit_handles:
0
|
success
|
1 |
0
|
1620016728.2885
CreateProcessInternalW
|
thread_identifier:
4000
thread_handle:
0x0000044c
process_identifier:
3996
current_directory:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\f13aa37174903d14951c141da29ec4bc.exe
track:
1
command_line:
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\f13aa37174903d14951c141da29ec4bc.exe
stack_pivoted:
0
creation_flags:
32
(NORMAL_PRIORITY_CLASS)
process_handle:
0x00000450
inherit_handles:
0
|
success
|
1 |
0
|
1620016690.97525
NtResumeThread
|
thread_handle:
0x000000000000011c
suspend_count:
1
process_identifier:
3080
|
success
|
0 |
0
|
1620016750.94425
NtGetContextThread
|
thread_handle:
0x0000000000000140
|
success
|
0 |
0
|
1620016757.38225
NtResumeThread
|
thread_handle:
0x0000000000000140
suspend_count:
2
process_identifier:
2228
|
success
|
0 |
0
|
1620016757.38225
NtGetContextThread
|
thread_handle:
0x0000000000000140
|
success
|
0 |
0
|
1620016759.28825
NtResumeThread
|
thread_handle:
0x0000000000000140
suspend_count:
2
process_identifier:
2228
|
success
|
0 |
0
|
1620016759.28825
NtGetContextThread
|
thread_handle:
0x0000000000000140
|
success
|
0 |
0
|
1620016691.272125
CreateProcessInternalW
|
thread_identifier:
3284
thread_handle:
0x000001ac
process_identifier:
3280
current_directory:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp
filepath:
C:\Program Files\Google\Chrome\Application\chrome.exe
track:
1
command_line:
"C:\Program Files\Google\Chrome\Application\chrome.exe" --single-argument C:\Users\ADMINI~1.OSK\AppData\Local\Temp\Caixa.pdf
filepath_r:
C:\Program Files\Google\Chrome\Application\chrome.exe
stack_pivoted:
0
creation_flags:
67634192
(CREATE_DEFAULT_ERROR_MODE|CREATE_NEW_CONSOLE|CREATE_UNICODE_ENVIRONMENT|EXTENDED_STARTUPINFO_PRESENT)
process_handle:
0x000001a8
inherit_handles:
0
|
success
|
1 |
0
|
1620016691.428125
CreateProcessInternalW
|
thread_identifier:
3324
thread_handle:
0x00000114
process_identifier:
3320
current_directory:
filepath:
track:
1
command_line:
"C:\Users\Administrator.Oskar-PC\AppData\Roaming\Install\Host.exe"
filepath_r:
stack_pivoted:
0
creation_flags:
4
(CREATE_SUSPENDED)
process_handle:
0x0000010c
inherit_handles:
0
|
success
|
1 |
0
|
1620016691.428125
NtUnmapViewOfSection
|
process_identifier:
3320
region_size:
4096
process_handle:
0x0000010c
base_address:
0x00400000
|
success
|
0 |
0
|
1620016691.428125
NtMapViewOfSection
|
section_handle:
0x00000100
process_identifier:
3320
commit_size:
208896
win32_protect:
64
(PAGE_EXECUTE_READWRITE)
buffer:
process_handle:
0x0000010c
allocation_type:
0
()
section_offset:
0
view_size:
208896
base_address:
0x00400000
|
success
|
0 |
0
|
1620016691.428125
NtGetContextThread
|
thread_handle:
0x00000114
|
success
|
0 |
0
|
1620016691.428125
NtSetContextThread
|
thread_handle:
0x00000114
registers.eip:
0
registers.esp:
0
registers.edi:
0
registers.eax:
4203565
registers.ebp:
0
registers.edx:
0
registers.ebx:
2130567168
registers.esi:
0
registers.ecx:
0
process_identifier:
3320
|
success
|
0 |
0
|
1620016693.350125
NtResumeThread
|
thread_handle:
0x00000114
suspend_count:
1
process_identifier:
3320
|
success
|
0 |
0
|
1620016694.522125
CreateProcessInternalW
|
thread_identifier:
3424
thread_handle:
0x00000108
process_identifier:
3420
current_directory:
filepath:
track:
1
command_line:
"C:\Users\Administrator.Oskar-PC\AppData\Roaming\Install\Host.exe" 2 3320 7292093
filepath_r:
stack_pivoted:
0
creation_flags:
32
(NORMAL_PRIORITY_CLASS)
process_handle:
0x0000013c
inherit_handles:
0
|
success
|
1 |
0
|
1620016692.428625
NtResumeThread
|
thread_handle:
0x0000000000000078
suspend_count:
1
process_identifier:
3280
|
success
|
0 |
0
|
1620016694.507625
CreateProcessInternalW
|
thread_identifier:
3396
thread_handle:
0x00000000000000c0
process_identifier:
3392
current_directory:
filepath:
C:\Program Files\Google\Chrome\Application\chrome.exe
track:
1
command_line:
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=89.0.4389.114 --initial-client-data=0xb0,0xb4,0xb8,0x84,0xbc,0x7fef23c4f50,0x7fef23c4f60,0x7fef23c4f70
filepath_r:
C:\Program Files\Google\Chrome\Application\chrome.exe
stack_pivoted:
0
creation_flags:
524288
(EXTENDED_STARTUPINFO_PRESENT)
process_handle:
0x00000000000000c4
inherit_handles:
1
|
success
|
1 |
0
|
1620016752.944625
CreateProcessInternalW
|
thread_identifier:
2952
thread_handle:
0x0000000000000518
process_identifier:
2956
current_directory:
filepath:
C:\Program Files\Google\Chrome\Application\chrome.exe
track:
1
command_line:
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=1044,2818024349387557598,6441002237860518477,131072 --gpu-preferences=SAAAAAAAAADgAAAwAAAAAAAAAAAAAAAAAABgAAAAAAAoAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAB4AAAAAAAAAHgAAAAAAAAAKAAAAAQAAAAgAAAAAAAAACgAAAAAAAAAMAAAAAAAAAA4AAAAAAAAABAAAAAAAAAAAAAAAAUAAAAQAAAAAAAAAAAAAAAGAAAAEAAAAAAAAAABAAAABQAAABAAAAAAAAAAAQAAAAYAAAAIAAAAAAAAAAgAAAAAAAAA --mojo-platform-channel-handle=1048 /prefetch:2
filepath_r:
C:\Program Files\Google\Chrome\Application\chrome.exe
stack_pivoted:
0
creation_flags:
17302540
(CREATE_BREAKAWAY_FROM_JOB|CREATE_SUSPENDED|CREATE_UNICODE_ENVIRONMENT|DETACHED_PROCESS|EXTENDED_STARTUPINFO_PRESENT)
process_handle:
0x000000000000051c
inherit_handles:
1
|
success
|
1 |
0
|
1620016695.27275
NtResumeThread
|
thread_handle:
0x00000000000000dc
suspend_count:
1
process_identifier:
3392
|
success
|
0 |
0
|
1620016753.78875
NtGetContextThread
|
thread_handle:
0x000000000000010c
|
success
|
0 |
0
|
1620016757.21075
NtResumeThread
|
thread_handle:
0x000000000000010c
suspend_count:
2
process_identifier:
3280
|
success
|
0 |
0
|
1620016757.21075
NtGetContextThread
|
thread_handle:
0x000000000000010c
|
success
|
0 |
0
|
1620016758.88275
NtResumeThread
|
thread_handle:
0x000000000000010c
suspend_count:
2
process_identifier:
3280
|
success
|
0 |
0
|
1620016758.88275
NtGetContextThread
|
thread_handle:
0x000000000000010c
|
success
|
0 |
0
|
1620016759.89775
NtResumeThread
|
thread_handle:
0x000000000000010c
suspend_count:
2
process_identifier:
3280
|
success
|
0 |
0
|
1620016759.91375
NtGetContextThread
|
thread_handle:
0x000000000000010c
|
success
|
0 |
0
|
1620016732.53797
CreateProcessInternalW
|
thread_identifier:
4084
thread_handle:
0x000001ac
process_identifier:
4080
current_directory:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp
filepath:
C:\Program Files\Google\Chrome\Application\chrome.exe
track:
1
command_line:
"C:\Program Files\Google\Chrome\Application\chrome.exe" --single-argument C:\Users\ADMINI~1.OSK\AppData\Local\Temp\Caixa.pdf
filepath_r:
C:\Program Files\Google\Chrome\Application\chrome.exe
stack_pivoted:
0
creation_flags:
67634192
(CREATE_DEFAULT_ERROR_MODE|CREATE_NEW_CONSOLE|CREATE_UNICODE_ENVIRONMENT|EXTENDED_STARTUPINFO_PRESENT)
process_handle:
0x000001a8
inherit_handles:
0
|
success
|
1 |
0
|
1620016734.83497
CreateProcessInternalW
|
thread_identifier:
2128
thread_handle:
0x000000fc
process_identifier:
2764
current_directory:
filepath:
track:
1
command_line:
"C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\f13aa37174903d14951c141da29ec4bc.exe"
filepath_r:
stack_pivoted:
0
creation_flags:
4
(CREATE_SUSPENDED)
process_handle:
0x00000104
inherit_handles:
0
|
success
|
1 |
0
|
1620016734.83497
NtUnmapViewOfSection
|
process_identifier:
2764
region_size:
4096
process_handle:
0x00000104
base_address:
0x00400000
|
success
|
0 |
0
|
1620016734.84997
NtMapViewOfSection
|
section_handle:
0x00000108
process_identifier:
2764
commit_size:
208896
win32_protect:
64
(PAGE_EXECUTE_READWRITE)
buffer:
process_handle:
0x00000104
allocation_type:
0
()
section_offset:
0
view_size:
208896
base_address:
0x00400000
|
success
|
0 |
0
|
1620016734.86597
NtGetContextThread
|
thread_handle:
0x000000fc
|
success
|
0 |
0
|
1620016734.86597
NtSetContextThread
|
thread_handle:
0x000000fc
registers.eip:
0
registers.esp:
0
registers.edi:
0
registers.eax:
4203565
registers.ebp:
0
registers.edx:
0
registers.ebx:
2130567168
registers.esi:
0
registers.ecx:
0
process_identifier:
2764
|
success
|
0 |
0
|
1620016736.61597
NtResumeThread
|
thread_handle:
0x000000fc
suspend_count:
1
process_identifier:
2764
|
success
|
0 |
0
|
1620016737.59997
CreateProcessInternalW
|
thread_identifier:
3484
thread_handle:
0x00000110
process_identifier:
3480
current_directory:
filepath:
track:
1
command_line:
"C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\f13aa37174903d14951c141da29ec4bc.exe" 2 2764 7334437
filepath_r:
stack_pivoted:
0
creation_flags:
32
(NORMAL_PRIORITY_CLASS)
process_handle:
0x00000100
inherit_handles:
0
|
success
|
1 |
0
|
1620016733.94372
NtResumeThread
|
thread_handle:
0x0000000000000078
suspend_count:
1
process_identifier:
4080
|
success
|
0 |
0
|
1620016734.63172
CreateProcessInternalW
|
thread_identifier:
3224
thread_handle:
0x00000000000000c0
process_identifier:
3228
current_directory:
filepath:
C:\Program Files\Google\Chrome\Application\chrome.exe
track:
1
command_line:
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=89.0.4389.114 --initial-client-data=0xb0,0xb4,0xb8,0x84,0xbc,0x7fef23c4f50,0x7fef23c4f60,0x7fef23c4f70
filepath_r:
C:\Program Files\Google\Chrome\Application\chrome.exe
stack_pivoted:
0
creation_flags:
524288
(EXTENDED_STARTUPINFO_PRESENT)
process_handle:
0x00000000000000c4
inherit_handles:
1
|
success
|
1 |
0
|
1620016735.756845
NtResumeThread
|
thread_handle:
0x00000000000000d8
suspend_count:
1
process_identifier:
3228
|
success
|
0 |
0
|