启动一个进程并注入代码,该程序可能正在脱壳
Time & API
Arguments
Status
Return
2018-04-20 23:59:00
CreateProcessInternalW
thread_identifier :2524
thread_handle :0x00000070
process_identifier :2520
current_directory :
filepath :
track :1
command_line :"C:\Users\vbccsb\AppData\Local\Temp\1.exe"
filepath_r :
stack_pivoted :0
creation_flags :4
inherit_handles :0
process_handle :0x00000074
11
2018-04-20 23:59:00
NtGetContextThread
thread_handle :0x00000070
10
2018-04-20 23:59:00
NtUnmapViewOfSection
base_address :0x00400000
region_size :4096
process_identifier :2520
process_handle :0x00000074
10
2018-04-20 23:59:00
NtAllocateVirtualMemory
process_identifier :2520
region_size :155648
stack_dep_bypass :0
stack_pivoted :0
heap_dep_bypass :0
protection :64
base_address :0x00400000
allocation_type :12288
process_handle :0x00000074
10
2018-04-20 23:59:00
WriteProcessMemory
buffer :
base_address :0x00400000
process_identifier :2520
process_handle :0x00000074
11
2018-04-20 23:59:00
WriteProcessMemory
buffer :@
base_address :0x7ffd7008
process_identifier :2520
process_handle :0x00000074
11
2018-04-20 23:59:00
NtSetContextThread
registers :{"eip":0,"esp":0,"edi":0,"eax":4198400,"ebp":0,"edx":0,"ebx":2147315712,"esi":0,"ecx":0}
thread_handle :0x00000070
process_identifier :2520
10
2018-04-20 23:59:02
NtResumeThread
thread_handle :0x00000070
suspend_count :1
process_identifier :2520
10
2018-04-20 23:59:04
CreateProcessInternalW
thread_identifier :2624
thread_handle :0x00000094
process_identifier :2620
current_directory :C:\Users\vbccsb\AppData\Roaming\DiskMonitor
filepath :
track :1
command_line :C:\Users\vbccsb\AppData\Roaming\DiskMonitor\1.exe
filepath_r :
stack_pivoted :0
creation_flags :0
inherit_handles :0
process_handle :0x00000098
11
2018-04-20 23:59:20
CreateProcessInternalW
thread_identifier :2676
thread_handle :0x00000070
process_identifier :2672
current_directory :
filepath :
track :1
command_line :C:\Users\vbccsb\AppData\Roaming\DiskMonitor\1.exe
filepath_r :
stack_pivoted :0
creation_flags :4
inherit_handles :0
process_handle :0x00000074
11
2018-04-20 23:59:20
NtGetContextThread
thread_handle :0x00000070
10
2018-04-20 23:59:20
NtUnmapViewOfSection
base_address :0x00400000
region_size :4096
process_identifier :2672
process_handle :0x00000074
10
2018-04-20 23:59:20
NtAllocateVirtualMemory
process_identifier :2672
region_size :155648
stack_dep_bypass :0
stack_pivoted :0
heap_dep_bypass :0
protection :64
base_address :0x00400000
allocation_type :12288
process_handle :0x00000074
10
2018-04-20 23:59:20
WriteProcessMemory
buffer :
base_address :0x00400000
process_identifier :2672
process_handle :0x00000074
11
2018-04-20 23:59:20
WriteProcessMemory
buffer :@
base_address :0x7ffdf008
process_identifier :2672
process_handle :0x00000074
11
2018-04-20 23:59:20
NtSetContextThread
registers :{"eip":0,"esp":0,"edi":0,"eax":4198400,"ebp":0,"edx":0,"ebx":2147348480,"esi":0,"ecx":0}
thread_handle :0x00000070
process_identifier :2672
10
2018-04-20 23:59:21
NtResumeThread
thread_handle :0x00000070
suspend_count :1
process_identifier :2672
10