Summary:
NtAdjustPrivilegesToken(>) | 1 | NtOpenDirectoryObject(>) | 2 | NtFsControlFile(>) | 11 | NtCreateSection(>) | 71 |
NtCallbackReturn(>) | 1 | NtOpenProcessTokenEx(>) | 2 | NtQuerySection(>) | 11 | NtTestAlert(>) | 91 |
NtDelayExecution(>) | 1 | NtOpenThreadTokenEx(>) | 2 | NtSetInformationThread(>) | 11 | NtRegisterThreadTerminatePort(>) | 94 |
NtGdiCreateBitmap(>) | 1 | NtQueryDefaultLocale(>) | 2 | NtOpenThreadToken(>) | 12 | NtOpenKey(>) | 96 |
NtGdiInit(>) | 1 | NtSetInformationObject(>) | 2 | NtSetInformationFile(>) | 13 | NtMapViewOfSection(>) | 98 |
NtGdiQueryFontAssocInfo(>) | 1 | NtGdiCreateCompatibleDC(>) | 3 | NtQueryDirectoryFile(>) | 14 | NtDuplicateObject(>) | 101 |
NtGdiSelectBitmap(>) | 1 | NtOpenProcessToken(>) | 3 | NtUserRegisterClassExWOW(>) | 14 | NtQuerySystemInformation(>) | 116 |
NtOpenKeyedEvent(>) | 1 | NtSecureConnectPort(>) | 3 | NtCreateFile(>) | 16 | NtWriteVirtualMemory(>) | 116 |
NtOpenSymbolicLinkObject(>) | 1 | NtFreeVirtualMemory(>) | 4 | NtSetValueKey(>) | 16 | NtSetEventBoostPriority(>) | 178 |
NtQueryObject(>) | 1 | NtReadFile(>) | 4 | NtCreateKey(>) | 18 | NtQueryValueKey(>) | 221 |
NtQuerySymbolicLinkObject(>) | 1 | NtWriteFile(>) | 4 | NtOpenFile(>) | 25 | NtResumeThread(>) | 270 |
NtQuerySystemTime(>) | 1 | NtConnectPort(>) | 5 | NtOpenProcess(>) | 29 | NtCreateThread(>) | 277 |
NtSetInformationProcess(>) | 1 | NtGdiGetStockObject(>) | 5 | NtDeviceIoControlFile(>) | 34 | NtQueryInformationThread(>) | 277 |
NtUserCallNoParam(>) | 1 | NtQueryInformationToken(>) | 5 | NtFlushInstructionCache(>) | 42 | NtRequestWaitReplyPort(>) | 305 |
NtUserGetThreadDesktop(>) | 1 | NtQueryVirtualMemory(>) | 5 | NtUnmapViewOfSection(>) | 44 | NtClose(>) | 354 |
NtCreateIoCompletion(>) | 2 | NtQueryVolumeInformationFile(>) | 5 | NtContinue(>) | 50 | NtProtectVirtualMemory(>) | 485 |
NtCreateMutant(>) | 2 | NtQueryInformationProcess(>) | 6 | NtOpenSection(>) | 50 | NtWaitForSingleObject(>) | 520 |
NtGdiCreateSolidBrush(>) | 2 | NtQueryInformationFile(>) | 8 | NtQueryAttributesFile(>) | 52 | NtAllocateVirtualMemory(>) | 705 |
NtNotifyChangeKey(>) | 2 | NtUserFindExistingCursorIcon(>) | 9 | NtCreateEvent(>) | 61 |
\271"HY{b\343U\224\260R\35*\271\377\27\375,\266\15\261\357!\347\245\364\347\10\262\361\223r]\257S\220\353\310R\322"\213\263\21\320\242\271>\242\375\375T\317\325\245\275\265\21a?V/89dY\244\353`\354w\320\302\10\241\370", ) HY{b\343U\224\260R\35*\271\377\27\375,\266\15\261\357!\347\245\364\347\10\262\361\223r]\257S\220\353\310R\322 ... {status=0x0, info=256}, "\32\316Da-4zp\231t\220\3260]t\22\6\347\376(\2622\365\347\343\216\351\21\371\221\207\230u\320\254\13\5\252S(\355\365\212KDd\211\240\230\2620Q\201\351X\2753N\347D\277\347\217\331\207\242\260;(C\11\240\262\321\324\35\213\3019m\276d\327>\26\357\253\213^Q2\243M}\324\325\304\25O\224\3034\21\21\362\307\33\21\350rl}e\37;\34\2503\265\37d\217\223U[\202L\365\16\266EG\250\366\16\360Z`\224\366\3778m\300\32\3114\251\300\345\360\271\22
\271"HY{b\343U\224\260R\35*\271\377\27\375,\266\15\261\357!\347\245\364\347\10\262\361\223r]\257S\220\353\310R\322"\213\263\21\320\242\271>\242\375\375T\317\325\245\275\265\21a?V/89dY\244\353`\354w\320\302\10\241\370", ) , ) == 0x0 02068 484 NtWaitForSingleObject ... ) == 0x102 02071 1296 NtCreateFile (0xc0100000, {24, 0, 0x42, 0, 0, (0xc0100000, {24, 0, 0x42, 0, 0, "\Device\Afd\Endpoint"}, 0x0, 0, 3, 3, 0, 11599488, 67, ... }, 0x0, 0, 3, 3, 0, 11599488, 67, ... 02072 1756 NtContinue (43056432, 1, ... 02070 896 NtAllocateVirtualMemory ... 43057152, 1048576, ) == 0x0 02073 1588 NtCreateEvent (0x1f0003, 0x0, 1, 0, ... 02074 484 NtWaitForSingleObject (176, 0, 0x0, ... 02071 1296 NtCreateFile ... 348, {status=0x0, info=0}, ) == 0x0 02075 1756 NtRegisterThreadTerminatePort (24, ... 02076 896 NtAllocateVirtualMemory (-1, 44097536, 0, 8192, 4096, 4, ... 02073 1588 NtCreateEvent ... 404, ) == 0x0 02077 1296 NtDeviceIoControlFile (348, 148, 0x0, 0x0, 0x1207b, (348, 148, 0x0, 0x0, 0x1207b, "\7\0\0\0\250q\250q%\0\0\0\216\326\220|", 16, 16, ... , 16, 16, ... 02075 1756 NtRegisterThreadTerminatePort ... ) == 0x0 02076 896 NtAllocateVirtualMemory ... 44097536, 8192, ) == 0x0 02078 1588 NtConnectPort ( ("\RPC Control\DNSResolver", {12, 2, 1, 0}, 0x0, 0x0, 12643844, 188, ... , {12, 2, 1, 0}, 0x0, 0x0, 12643844, 188, ... 02077 1296 NtDeviceIoControlFile ... {status=0x0, info=16}, ... {status=0x0, info=16}, "\7\0\0\00\207\273\201\0 \0\0\200=\242\201", ) , ) == 0x0 02069 1656 NtDuplicateObject ... 408, ) == 0x0 02079 896 NtProtectVirtualMemory (-1, (0x2a0e000), 4096, 260, ... 02080 1756 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 02081 1656 NtWaitForSingleObject (104, 0, {0, 0}, ... 02079 896 NtProtectVirtualMemory ... (0x2a0e000), 4096, 4, ) == 0x0 02080 1756 NtDuplicateObject ... 412, ) == 0x0 02081 1656 NtWaitForSingleObject ... ) == 0x102 02082 1296 NtDeviceIoControlFile (348, 148, 0x0, 0x0, 0x1207b, (348, 148, 0x0, 0x0, 0x1207b, "\6\0\0\00\207\273\201\0 \0\0\200=\242\201", 16, 16, ... , 16, 16, ... 02078 1588 NtConnectPort ... 416, 0x0, 0x0, 0x0, 188, ) == 0x0 02083 1756 NtWaitForSingleObject (104, 0, {0, 0}, ... 02084 1656 NtWaitForSingleObject (176, 0, 0x0, ... 02082 1296 NtDeviceIoControlFile ... {status=0x0, info=16}, ... {status=0x0, info=16}, "\6\0\0\00\207\273\201\0 \0\0\200=\242\201", ) , ) == 0x0 02085 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 02083 1756 NtWaitForSingleObject ... ) == 0x102 02086 1296 NtDeviceIoControlFile (348, 148, 0x0, 0x0, 0x12047, (348, 148, 0x0, 0x0, 0x12047, "\0\0\0\0\2\0\0\0\1\0\0\0\6\0\0\0\20\0\0\0\20\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0 \0\0\0 \0\0\0\0\0\0\1\0\0\0\351\3\0\0f\0\2\0\10\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0h\0\0\0\224\375\260\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0\1\0\0\0\6\0\0\0\0 \0\0\1\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\1\0\0\0\1\0\0\1\0\0\0 \0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 248, 16, ... , 248, 16, ... 02085 896 NtCreateThread ... 420, {1252, 540}, ) == 0x0 02087 1756 NtWaitForSingleObject (176, 0, 0x0, ... 02086 1296 NtDeviceIoControlFile ... {status=0x0, info=0}, "", ) == 0x0 02088 896 NtQueryInformationThread (420, Basic, 28, ... 02089 1588 NtRequestWaitReplyPort (416, {200, 224, new_msg, 0, 1330592, 12, 2, 1} (416, {200, 224, new_msg, 0, 1330592, 12, 2, 1} "\0\0\0\0\274\0\0\0x\1\24\0\1kwEVY\205D\237\200\364(\367\326\1)\2\0\0\0\1\0\0\0x*\25\0\4\0\0\0\320+\25\0\10\0\0\0\5\0\0\0x\1\24\0\0\0\0\0\0\0\25\0\1\0\0\0\233\263>Z\302\3768\5\370+\25\0h\1\24\0\12\0\0\0\0\0\0\0\0\0\0\0(\0\0\0\320+\25\0D"a\244x\1\24\0\360+\25\0h\1\24\0\0\0\0\0\0\0\0\0\360+\25\0P\0\0\0\370+\25\0\360\6\221|x\1\24\0P\0\0\0\346\31\0\0\0\0\24\0\204\354\300\0\372\31\221|\30\364\300\0\30\356\220|\360\6\221|\0\0\0\0\0\0\0\0\0\0\0\0\6\0\0\0" ... a\244x\1\24\0\360+\25\0h\1\24\0\0\0\0\0\0\0\0\0\360+\25\0P\0\0\0\370+\25\0\360\6\221|x\1\24\0P\0\0\0\346\31\0\0\0\0\24\0\204\354\300\0\372\31\221|\30\364\300\0\30\356\220|\360\6\221|\0\0\0\0\0\0\0\0\0\0\0\0\6\0\0\0" ... 02090 1296 NtWaitForSingleObject (96, 0, {0, 0}, ... 02088 896 NtQueryInformationThread ... {ExitStatus=0x103,TebBaseAddress=0x7ff93000,Pid=1252,Tid=540,}, 0x0, ) == 0x0 02091 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81913, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81913, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\244\1\0\0\344\4\0\0\34\2\0\0" ... ... 02089 1588 NtRequestWaitReplyPort ... {200, 224, reply, 0, 1252, 1588, 81915, 0} ... {200, 224, reply, 0, 1252, 1588, 81915, 0} "\7\0\0\0\274\0\0\0x\1\24\0\1kwEVY\205D\237\200\364(\367\326\1)\2\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\320+\25\0\377\377\377\377\5\0\0\0x\1\24\0\0\0\0\0\0\0\25\0\1\0\0\0\233\263>Z\302\3768\5\370+\25\0h\1\24\0\12\0\0\0\0\0\0\0\0\0\0\0(\0\0\0\320+\25\0D"a\244x\1\24\0\360+\25\0h\1\24\0\0\0\0\0\0\0\0\0\360+\25\0P\0\0\0\370+\25\0\360\6\221|x\1\24\0P\0\0\0\346\31\0\0\0\0\24\0\204\354\300\0\372\31\221|\30\364\300\0\30\356\220|\360\6\221|\0\0\0\0\0\0\0\0\0\0\0\0\6\0\0\0" ) a\244x\1\24\0\360+\25\0h\1\24\0\0\0\0\0\0\0\0\0\360+\25\0P\0\0\0\370+\25\0\360\6\221|x\1\24\0P\0\0\0\346\31\0\0\0\0\24\0\204\354\300\0\372\31\221|\30\364\300\0\30\356\220|\360\6\221|\0\0\0\0\0\0\0\0\0\0\0\0\6\0\0\0" ) == 0x0 02092 1588 NtAllocateVirtualMemory (-1, 1388544, 0, 4096, 4096, 4, ... 1388544, 4096, ) == 0x0 02093 1588 NtRequestWaitReplyPort (416, {64, 88, new_msg, 0, 0, 0, 0, 0} (416, {64, 88, new_msg, 0, 0, 0, 0, 0} "\1\0\0\0A\2\10\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\377\377\377\377\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ... {52, 76, reply, 0, 1252, 1588, 81917, 0} "\2\356Q\200\1\0\0\0\30b\202\201\0\300\375\177\220\273\270\367\370\37`\300l\273\270\367X\353Q\200\360\317\12\0\1\0\0\0\1\0\0\0\300\250|\207\377\377\377\0" ) ... {52, 76, reply, 0, 1252, 1588, 81917, 0} (416, {64, 88, new_msg, 0, 0, 0, 0, 0} "\1\0\0\0A\2\10\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\377\377\377\377\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ... {52, 76, reply, 0, 1252, 1588, 81917, 0} "\2\356Q\200\1\0\0\0\30b\202\201\0\300\375\177\220\273\270\367\370\37`\300l\273\270\367X\353Q\200\360\317\12\0\1\0\0\0\1\0\0\0\300\250|\207\377\377\377\0" ) ) == 0x0 02094 1588 NtClose (404, ... ) == 0x0 02095 1588 NtClose (416, ... ) == 0x0 02090 1296 NtWaitForSingleObject ... ) == 0x102 02091 896 NtRequestWaitReplyPort ... {28, 56, reply, 0, 1252, 896, 81916, 0} ... {28, 56, reply, 0, 1252, 896, 81916, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\244\1\0\0\344\4\0\0\34\2\0\0" ) ) == 0x0 02096 1296 NtDeviceIoControlFile (348, 148, 0x0, 0x0, 0x12003, (348, 148, 0x0, 0x0, 0x12003, "\0\0\0\0\1\0\0\0\16\0\2\0\25\262\0\0\0\0\0\0\0\0\0\0\0\0", 26, 26, ... , 26, 26, ... 02097 896 NtResumeThread (420, ... 02096 1296 NtDeviceIoControlFile ... {status=0x0, info=416}, ... {status=0x0, info=416}, "\1\0\0\0\1\0\0\0\16\0\2\0\25\262\0\0\0\0\0\0\0\0\0\0\0\0", ) , ) == 0x0 02097 896 NtResumeThread ... 1, ) == 0x0 02098 1296 NtDeviceIoControlFile (348, 148, 0x0, 0x0, 0x12047, (348, 148, 0x0, 0x0, 0x12047, "\1\0\0\0\2\0\0\0\1\0\0\0\6\0\0\0\20\0\0\0\20\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0 \0\0\0 \0\0\0\0\0\0\1\0\0\0\351\3\0\0f\0\2\0\10\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0h\0\0\0(\0*\0\2\0\25\262\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0\1\0\0\0\6\0\0\0\0 \0\0\1\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\1\0\0\0\1\0\0\1\0\0\0 \0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 248, 0, ... , 248, 0, ... 02099 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02098 1296 NtDeviceIoControlFile ... {status=0x0, info=0}, 0x0, ) == 0x0 02099 896 NtAllocateVirtualMemory ... 44105728, 1048576, ) == 0x0 02100 1588 NtCreateKey (0x20019, {24, 36, 0x40, 0, 0, (0x20019, {24, 36, 0x40, 0, 0, "System\CurrentControlSet\Services\Tcpip\Parameters"}, 0, "Class", 0, ... }, 0, (0x20019, {24, 36, 0x40, 0, 0, "System\CurrentControlSet\Services\Tcpip\Parameters"}, 0, "Class", 0, ... , 0, ... 02101 540 NtTestAlert (... 02102 896 NtAllocateVirtualMemory (-1, 45146112, 0, 8192, 4096, 4, ... 02100 1588 NtCreateKey ... 404, 2, ) == 0x0 02101 540 NtTestAlert ... ) == 0x0 02103 1296 NtDeviceIoControlFile (348, 148, 0x0, 0x0, 0x12037, (348, 148, 0x0, 0x0, 0x12037, "\2\0\0\0", 4, 8, ... , 4, 8, ... 02104 1588 NtOpenKey (0x20019, {24, 36, 0x40, 0, 0, (0x20019, {24, 36, 0x40, 0, 0, "System\CurrentControlSet\Services\DnsCache\Parameters"}, ... }, ... 02105 540 NtContinue (44105008, 1, ... 02103 1296 NtDeviceIoControlFile ... {status=0x0, info=8}, ... {status=0x0, info=8}, "\0\0\0\0\0\0\0\0", ) , ) == 0x0 02104 1588 NtOpenKey ... 424, ) == 0x0 02106 540 NtRegisterThreadTerminatePort (24, ... 02107 1296 NtDeviceIoControlFile (348, 148, 0x0, 0x0, 0x1200b, (348, 148, 0x0, 0x0, 0x1200b, "\0\376\260\0\5\0\0\0\0\320\24\0", 12, 0, ... , 12, 0, ... 02108 1588 NtOpenKey (0x20019, {24, 36, 0x40, 0, 0, (0x20019, {24, 36, 0x40, 0, 0, "Software\Policies\Microsoft\Windows NT\DnsClient"}, ... }, ... 02106 540 NtRegisterThreadTerminatePort ... ) == 0x0 02107 1296 NtDeviceIoControlFile ... {status=0x0, info=0}, 0x0, ) == 0x0 02108 1588 NtOpenKey ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02102 896 NtAllocateVirtualMemory ... 45146112, 8192, ) == 0x0 02109 1296 NtDeviceIoControlFile (348, 148, 0x0, 0x0, 0x12047, (348, 148, 0x0, 0x0, 0x12047, "\1\0\0\0\2\0\0\0\1\0\0\0\6\0\0\0\20\0\0\0\20\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0 \0\0\0 \0\0\1\0\0\0\1\0\0\0\351\3\0\0f\0\2\0\10\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0h\0\0\0\310\376\260\0\2\0\25\262\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0\1\0\0\0\6\0\0\0\0 \0\0\1\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\1\0\0\0\1\0\0\1\0\0\0 \0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 248, 0, ... , 248, 0, ... 02110 540 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 02111 896 NtProtectVirtualMemory (-1, (0x2b0e000), 4096, 260, ... 02109 1296 NtDeviceIoControlFile ... {status=0x0, info=0}, 0x0, ) == 0x0 02110 540 NtDuplicateObject ... 428, ) == 0x0 02111 896 NtProtectVirtualMemory ... (0x2b0e000), 4096, 4, ) == 0x0 02112 1588 NtQueryValueKey (404, (404, "Hostname", Partial, 144, ... , Partial, 144, ... 02113 540 NtWaitForSingleObject (104, 0, {0, 0}, ... 02114 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 02112 1588 NtQueryValueKey ... TitleIdx=0, Type=1, Data= ... TitleIdx=0, Type=1, Data="v\0i\0r\0t\0u\0a\0l\0\0\0"}, 28, ) }, 28, ) == 0x0 02113 540 NtWaitForSingleObject ... ) == 0x102 02114 896 NtCreateThread ... 432, {1252, 1556}, ) == 0x0 02115 1588 NtQueryValueKey (404, (404, "Hostname", Partial, 144, ... , Partial, 144, ... 02116 540 NtWaitForSingleObject (176, 0, 0x0, ... 02117 896 NtQueryInformationThread (432, Basic, 28, ... 02115 1588 NtQueryValueKey ... TitleIdx=0, Type=1, Data= ... TitleIdx=0, Type=1, Data="v\0i\0r\0t\0u\0a\0l\0\0\0"}, 28, ) }, 28, ) == 0x0 02118 1296 NtDeviceIoControlFile (348, 148, 0x0, 0x0, 0x1202f, 0x0, 0, 26, ... 02119 1588 NtClose (404, ... 02118 1296 NtDeviceIoControlFile ... {status=0x0, info=26}, ... {status=0x0, info=26}, "\1\0\0\0\1\0\0\0\16\0\2\0\25\262\0\0\0\0\0\0\0\0\0\0\0\0", ) , ) == 0x0 02119 1588 NtClose ... ) == 0x0 02120 1296 NtAllocateVirtualMemory (-1, 1392640, 0, 4096, 4096, 4, ... 02117 896 NtQueryInformationThread ... {ExitStatus=0x103,TebBaseAddress=0x7ff92000,Pid=1252,Tid=1556,}, 0x0, ) == 0x0 02120 1296 NtAllocateVirtualMemory ... 1392640, 4096, ) == 0x0 02121 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81916, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81916, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\260\1\0\0\344\4\0\0\24\6\0\0" ... ... 02122 1296 NtDeviceIoControlFile (388, 0, 0x0, 0x0, 0x390008, (388, 0, 0x0, 0x0, 0x390008, ",Me\245\330\254\243\302lA\360\372\247A\350\17\350U@\344V\311s\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 256, 256, ... , 256, 256, ... 02121 896 NtRequestWaitReplyPort ... {28, 56, reply, 0, 1252, 896, 81919, 0} ... {28, 56, reply, 0, 1252, 896, 81919, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\260\1\0\0\344\4\0\0\24\6\0\0" ) ) == 0x0 02123 1296 NtQuerySystemInformation (TimeOfDay, 48, ... 02124 896 NtResumeThread (432, ... 02125 1588 NtClose (424, ... 02124 896 NtResumeThread ... 1, ) == 0x0 02125 1588 NtClose ... ) == 0x0 02123 1296 NtQuerySystemInformation ... {system info, class 3, size 48}, 48, ) == 0x0 02126 1556 NtTestAlert (... 02127 1588 NtCreateEvent (0x100003, 0x0, 1, 0, ... 02128 1296 NtQuerySystemInformation (ProcessorTimes, 48, ... 02126 1556 NtTestAlert ... ) == 0x0 02127 1588 NtCreateEvent ... 424, ) == 0x0 02128 1296 NtQuerySystemInformation ... {system info, class 8, size 48}, 48, ) == 0x0 02129 1556 NtContinue (45153584, 1, ... 02130 1588 NtWaitForSingleObject (424, 0, 0x0, ... 02131 1296 NtQuerySystemInformation (Performance, 312, ... 02132 1556 NtRegisterThreadTerminatePort (24, ... 02131 1296 NtQuerySystemInformation ... {system info, class 2, size 312}, 312, ) == 0x0 02132 1556 NtRegisterThreadTerminatePort ... ) == 0x0 02133 1296 NtQuerySystemInformation (Exception, 16, ... 02134 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02135 1556 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 02134 896 NtAllocateVirtualMemory ... 45154304, 1048576, ) == 0x0 02135 1556 NtDuplicateObject ... 404, ) == 0x0 02136 896 NtAllocateVirtualMemory (-1, 46194688, 0, 8192, 4096, 4, ... 02137 1556 NtWaitForSingleObject (104, 0, {0, 0}, ... 02136 896 NtAllocateVirtualMemory ... 46194688, 8192, ) == 0x0 02137 1556 NtWaitForSingleObject ... ) == 0x102 02138 896 NtProtectVirtualMemory (-1, (0x2c0e000), 4096, 260, ... 02139 1556 NtWaitForSingleObject (176, 0, 0x0, ... 02138 896 NtProtectVirtualMemory ... (0x2c0e000), 4096, 4, ) == 0x0 02133 1296 NtQuerySystemInformation ... {system info, class 33, size 16}, 16, ) == 0x0 02140 1296 NtQuerySystemInformation (Lookaside, 32, ... {system info, class 45, size 32}, 32, ) == 0x0 02141 1296 NtQuerySystemInformation (ProcessorStatistics, 3016, ... {system info, class 23, size 0}, 0, ) == 0x0 02142 1296 NtQuerySystemInformation (ProcessesAndThreads, 3008, ... ) == STATUS_INFO_LENGTH_MISMATCH 02143 1296 NtCreateKey (0x2, {24, 0, 0x240, 0, 0, (0x2, {24, 0, 0x240, 0, 0, "\Registry\Machine\SOFTWARE\Microsoft\Cryptography\RNG"}, 0, 0x0, 0, ... -2147481484, 2, ) }, 0, 0x0, 0, ... -2147481484, 2, ) == 0x0 02144 1296 NtSetValueKey (-2147481484, (-2147481484, "Seed", 0, 3, "\351h\360\260\5gP\\323\215\345s`\30\310P\332\235\35u\211O\237\237\255\365\15\221\310\327JKN}\343Z\262Qr\215W\3536\313p\273\363\250[5\332\353]|R\14=:\305\206X\3466\24\203\275\\5\364\200i\304+s,V\336\342"\377", 80, ... ) , 0, 3, (-2147481484, "Seed", 0, 3, "\351h\360\260\5gP\\323\215\345s`\30\310P\332\235\35u\211O\237\237\255\365\15\221\310\327JKN}\343Z\262Qr\215W\3536\313p\273\363\250[5\332\353]|R\14=:\305\206X\3466\24\203\275\\5\364\200i\304+s,V\336\342"\377", 80, ... ) \377", 80, ... ) == 0x0 02145 1296 NtClose (-2147481484, ... 02146 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 436, {1252, 460}, ) == 0x0 02147 896 NtQueryInformationThread (436, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff91000,Pid=1252,Tid=460,}, 0x0, ) == 0x0 02148 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81919, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81919, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\264\1\0\0\344\4\0\0\314\1\0\0" ... {28, 56, reply, 0, 1252, 896, 81920, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\264\1\0\0\344\4\0\0\314\1\0\0" ) ... {28, 56, reply, 0, 1252, 896, 81920, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81919, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\264\1\0\0\344\4\0\0\314\1\0\0" ... {28, 56, reply, 0, 1252, 896, 81920, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\264\1\0\0\344\4\0\0\314\1\0\0" ) ) == 0x0 02149 896 NtResumeThread (436, ... 1, ) == 0x0 02150 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 46202880, 1048576, ) == 0x0 02151 896 NtAllocateVirtualMemory (-1, 47243264, 0, 8192, 4096, 4, ... 02145 1296 NtClose ... ) == 0x0 02152 460 NtTestAlert (... 02122 1296 NtDeviceIoControlFile ... {status=0x0, info=256}, ... {status=0x0, info=256}, "\27\373\2\3666\261s'\210\301\214u\302\207@\3158\345$\7\177_\356\3149\371\307\3379\23;\341\365Y\21,\370\253\354I\226b\4\2670\35k\22[\374td\374ut%\315\7\3f\232\300\251?\2557\233\1\33T \275?\331\251)\302b \25\324Z\354%\212w\247cq\3127:v\311D\177M]/PL\364e\365N\241\217\270\212\256\32_\245\375\360[\340\230\372k\33q\3\303>\232j\325FY#\2070\336\226\203\17\207\247\315'S$\22\232%\320\267\270\20\304\325Q\16\37RL\237\221\267\257\241\357\354yO\245\314\234\235\305\305\204\253\21\337\222\2521Y\253\344\363&PR\366\301g\235|\301R5\354\1\1\231\210\350\365\356\302P\220\344\35\210J\363E<5P#\31p\322\343Ls\322cB\220\325K\362\372\355\26]o\20&\2064h\16\316\246\321=\264m\0\227\375:c\246\322\365\373\362\211", ) , ) == 0x0 02152 460 NtTestAlert ... ) == 0x0 02153 1296 NtDeviceIoControlFile (388, 0, 0x0, 0x0, 0x390008, (388, 0, 0x0, 0x0, 0x390008, ",Me\245\330\254\243\302lA\360\372\247AA\333\2472e\345\372\274a\350U@\344V\311s\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 256, 256, ... , 256, 256, ... 02154 460 NtContinue (46202160, 1, ... 02155 1296 NtQuerySystemInformation (TimeOfDay, 48, ... 02156 460 NtRegisterThreadTerminatePort (24, ... 02155 1296 NtQuerySystemInformation ... {system info, class 3, size 48}, 48, ) == 0x0 02156 460 NtRegisterThreadTerminatePort ... ) == 0x0 02157 1296 NtQuerySystemInformation (ProcessorTimes, 48, ... 02151 896 NtAllocateVirtualMemory ... 47243264, 8192, ) == 0x0 02158 460 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 02159 896 NtProtectVirtualMemory (-1, (0x2d0e000), 4096, 260, ... 02158 460 NtDuplicateObject ... 440, ) == 0x0 02159 896 NtProtectVirtualMemory ... (0x2d0e000), 4096, 4, ) == 0x0 02160 460 NtWaitForSingleObject (104, 0, {0, 0}, ... 02161 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 02160 460 NtWaitForSingleObject ... ) == 0x102 02161 896 NtCreateThread ... 444, {1252, 1856}, ) == 0x0 02162 460 NtWaitForSingleObject (176, 0, 0x0, ... 02163 896 NtQueryInformationThread (444, Basic, 28, ... 02157 1296 NtQuerySystemInformation ... {system info, class 8, size 48}, 48, ) == 0x0 02164 1296 NtQuerySystemInformation (Performance, 312, ... {system info, class 2, size 312}, 312, ) == 0x0 02165 1296 NtQuerySystemInformation (Exception, 16, ... {system info, class 33, size 16}, 16, ) == 0x0 02166 1296 NtQuerySystemInformation (Lookaside, 32, ... {system info, class 45, size 32}, 32, ) == 0x0 02167 1296 NtQuerySystemInformation (ProcessorStatistics, 3016, ... {system info, class 23, size 0}, 0, ) == 0x0 02168 1296 NtQuerySystemInformation (ProcessesAndThreads, 3008, ... ) == STATUS_INFO_LENGTH_MISMATCH 02169 1296 NtCreateKey (0x2, {24, 0, 0x240, 0, 0, (0x2, {24, 0, 0x240, 0, 0, "\Registry\Machine\SOFTWARE\Microsoft\Cryptography\RNG"}, 0, 0x0, 0, ... }, 0, 0x0, 0, ... 02163 896 NtQueryInformationThread ... {ExitStatus=0x103,TebBaseAddress=0x7ff90000,Pid=1252,Tid=1856,}, 0x0, ) == 0x0 02170 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81920, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81920, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\274\1\0\0\344\4\0\0@\7\0\0" ... {28, 56, reply, 0, 1252, 896, 81921, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\274\1\0\0\344\4\0\0@\7\0\0" ) ... {28, 56, reply, 0, 1252, 896, 81921, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81920, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\274\1\0\0\344\4\0\0@\7\0\0" ... {28, 56, reply, 0, 1252, 896, 81921, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\274\1\0\0\344\4\0\0@\7\0\0" ) ) == 0x0 02171 896 NtResumeThread (444, ... 1, ) == 0x0 02172 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 47251456, 1048576, ) == 0x0 02173 896 NtAllocateVirtualMemory (-1, 48291840, 0, 8192, 4096, 4, ... 48291840, 8192, ) == 0x0 02174 896 NtProtectVirtualMemory (-1, (0x2e0e000), 4096, 260, ... (0x2e0e000), 4096, 4, ) == 0x0 02169 1296 NtCreateKey ... -2147481484, 2, ) == 0x0 02175 1856 NtTestAlert (... 02176 1296 NtSetValueKey (-2147481484, (-2147481484, "Seed", 0, 3, "\2609\231\375\262\353i\255+/\301\331\255\256\231H(_\303E\37\26381\333G?\300\266\305\313s\2772\3176`6\31\2770\24\343e\373\14\272GyX\334gOQ\247p\0\231\361z0\305O\17\313\374\244\254\4\354\212\0\331\257\3j\205bPp", 80, ... , 0, 3, (-2147481484, "Seed", 0, 3, "\2609\231\375\262\353i\255+/\301\331\255\256\231H(_\303E\37\26381\333G?\300\266\305\313s\2772\3176`6\31\2770\24\343e\373\14\272GyX\334gOQ\247p\0\231\361z0\305O\17\313\374\244\254\4\354\212\0\331\257\3j\205bPp", 80, ... , 80, ... 02175 1856 NtTestAlert ... ) == 0x0 02176 1296 NtSetValueKey ... ) == 0x0 02177 1856 NtContinue (47250736, 1, ... 02178 1296 NtClose (-2147481484, ... 02179 1856 NtRegisterThreadTerminatePort (24, ... 02178 1296 NtClose ... ) == 0x0 02179 1856 NtRegisterThreadTerminatePort ... ) == 0x0 02153 1296 NtDeviceIoControlFile ... {status=0x0, info=256}, ... {status=0x0, info=256}, "$*oB|\201\315\364(\205\16\361\25N\350\350am\214\3441{}\200\376i\225\252\354\11\244\26I\215\33X\315,\255\335y2#\0=y\22\302\351U\6\34\365$\200{k\277\205