| Size | 2.3MB |
|---|---|
| Type | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5 | fea68d40d8be54ede189a6ee32ed6c0d |
| SHA1 | 55f1aea853cd45217a310041f6ca9319d2672038 |
| SHA256 | 51d44fd2988585ff21cd1d6fde99a29a1901fea6bd7d58572a16816723da96b4 |
| SHA512 |
29ffbd567284f2662461d40bf45d556fd11b21fbb50518e8c2b201898ff5a1f77852cb84fc1a250b1429b2bdeb19780616d40322f92de8a77640dbb4d23cd716
|
| CRC32 | 1A235EDB |
| ssdeep | None |
| Yara |
|
This file is very suspicious, with a score of 10 out of 10!
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
| Category | Started | Completed | Duration | Routing | Logs |
|---|---|---|---|---|---|
| FILE | Dec. 22, 2025, 8:28 a.m. | Dec. 22, 2025, 8:37 a.m. | 551 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2025-12-21 16:46:06,078 [analyzer] DEBUG: Starting analyzer from: C:\tmp1xmcit 2025-12-21 16:46:06,092 [analyzer] DEBUG: Pipe server name: \??\PIPE\coJFodDNqTXZkBcpKCgwjixQuvqgDfG 2025-12-21 16:46:06,092 [analyzer] DEBUG: Log pipe server name: \??\PIPE\ocRWTltxLeUfSMEOqFO 2025-12-21 16:46:06,092 [analyzer] DEBUG: No analysis package specified, trying to detect it automagically. 2025-12-21 16:46:06,108 [analyzer] INFO: Automatically selected analysis package "exe" 2025-12-21 16:46:06,717 [analyzer] DEBUG: Started auxiliary module Curtain 2025-12-21 16:46:06,717 [analyzer] DEBUG: Started auxiliary module DbgView 2025-12-21 16:46:07,358 [analyzer] DEBUG: Started auxiliary module Disguise 2025-12-21 16:46:07,578 [analyzer] DEBUG: Loaded monitor into process with pid 508 2025-12-21 16:46:07,578 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2025-12-21 16:46:07,578 [analyzer] DEBUG: Started auxiliary module Human 2025-12-21 16:46:07,578 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2025-12-21 16:46:07,578 [analyzer] DEBUG: Started auxiliary module Reboot 2025-12-21 16:46:07,687 [analyzer] DEBUG: Started auxiliary module RecentFiles 2025-12-21 16:46:07,687 [analyzer] DEBUG: Started auxiliary module Screenshots 2025-12-21 16:46:07,687 [analyzer] DEBUG: Started auxiliary module Sysmon 2025-12-21 16:46:07,687 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2025-12-21 16:46:07,921 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\51d44fd2988585ff_svchost.exe' with arguments '' and pid 1432 2025-12-21 16:46:08,187 [analyzer] DEBUG: Loaded monitor into process with pid 1432 2025-12-21 16:46:09,108 [analyzer] INFO: Added new file to list with pid 1432 and path C:\Windows\AppPatch\svchost.exe 2025-12-21 16:46:09,233 [analyzer] INFO: Injected into process with pid 892 and name u'svchost.exe' 2025-12-21 16:46:09,453 [analyzer] DEBUG: Loaded monitor into process with pid 892 2025-12-21 16:46:09,921 [analyzer] INFO: Process with pid 1432 has terminated 2025-12-21 16:46:10,312 [analyzer] WARNING: Received request to inject Cuckoo processes, skipping it. 2025-12-21 16:46:11,390 [analyzer] INFO: Added new file to list with pid 892 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\14232B434CF29D4C4FB335A86D7FFFE3 2025-12-21 16:46:11,390 [analyzer] INFO: Added new file to list with pid 892 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\14232B434CF29D4C4FB335A86D7FFFE3 2025-12-21 16:46:11,421 [analyzer] INFO: Added new file to list with pid 892 and path C:\Users\Administrator\AppData\Local\Temp\TarC5D4.tmp 2025-12-21 16:46:11,530 [analyzer] INFO: Added new file to list with pid 892 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015 2025-12-21 16:46:11,530 [analyzer] INFO: Added new file to list with pid 892 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\94308059B57B3142E455B38A6EB92015 2025-12-21 16:46:11,546 [analyzer] INFO: Added new file to list with pid 892 and path C:\Users\Administrator\AppData\Local\Temp\TarC653.tmp 2025-12-21 16:46:11,717 [analyzer] INFO: Added new file to list with pid 892 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8B2B9A00839EED1DFDCCC3BFC2F5DF12 2025-12-21 16:46:11,717 [analyzer] INFO: Added new file to list with pid 892 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8B2B9A00839EED1DFDCCC3BFC2F5DF12 2025-12-21 16:46:11,780 [analyzer] INFO: Added new file to list with pid 892 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B46811C17859FFB409CF0E904A4AA8F8 2025-12-21 16:46:11,780 [analyzer] INFO: Added new file to list with pid 892 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B46811C17859FFB409CF0E904A4AA8F8 2025-12-22 07:32:51,055 [analyzer] INFO: Added new file to list with pid 892 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\F0ACCF77CDCBFF39F6191887F6D2D357 2025-12-22 07:32:51,072 [analyzer] INFO: Added new file to list with pid 892 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\F0ACCF77CDCBFF39F6191887F6D2D357 2025-12-22 07:32:51,697 [analyzer] INFO: Added new file to list with pid 892 and path C:\Users\Administrator\AppData\Local\Temp\6896.tmp 2025-12-22 07:33:13,868 [analyzer] WARNING: Received request to inject Cuckoo processes, skipping it. 2025-12-22 07:35:24,713 [analyzer] INFO: Analysis timeout hit, terminating analysis. 2025-12-22 07:35:25,697 [analyzer] INFO: Terminating remaining processes before shutdown. 2025-12-22 07:35:25,697 [lib.api.process] INFO: Successfully terminated process with pid 892. 2025-12-22 07:35:25,743 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tarc653.tmp' does not exist, skip. 2025-12-22 07:35:25,759 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tarc5d4.tmp' does not exist, skip. 2025-12-22 07:35:25,805 [analyzer] INFO: Analysis completed.
2025-12-22 08:28:32,210 [cuckoo.core.scheduler] DEBUG: Task #7253259: no machine available yet 2025-12-22 08:28:33,232 [cuckoo.core.scheduler] DEBUG: Task #7253259: no machine available yet 2025-12-22 08:28:34,252 [cuckoo.core.scheduler] DEBUG: Task #7253259: no machine available yet 2025-12-22 08:28:35,276 [cuckoo.core.scheduler] DEBUG: Task #7253259: no machine available yet 2025-12-22 08:28:36,427 [cuckoo.core.scheduler] DEBUG: Task #7253259: no machine available yet 2025-12-22 08:28:37,466 [cuckoo.core.scheduler] DEBUG: Task #7253259: no machine available yet 2025-12-22 08:28:38,498 [cuckoo.core.scheduler] DEBUG: Task #7253259: no machine available yet 2025-12-22 08:28:39,521 [cuckoo.core.scheduler] DEBUG: Task #7253259: no machine available yet 2025-12-22 08:28:40,548 [cuckoo.core.scheduler] DEBUG: Task #7253259: no machine available yet 2025-12-22 08:28:41,702 [cuckoo.core.scheduler] DEBUG: Task #7253259: no machine available yet 2025-12-22 08:28:42,727 [cuckoo.core.scheduler] DEBUG: Task #7253259: no machine available yet 2025-12-22 08:28:43,748 [cuckoo.core.scheduler] DEBUG: Task #7253259: no machine available yet 2025-12-22 08:28:44,767 [cuckoo.core.scheduler] DEBUG: Task #7253259: no machine available yet 2025-12-22 08:28:45,830 [cuckoo.core.scheduler] DEBUG: Task #7253259: no machine available yet 2025-12-22 08:28:46,849 [cuckoo.core.scheduler] DEBUG: Task #7253259: no machine available yet 2025-12-22 08:28:47,873 [cuckoo.core.scheduler] DEBUG: Task #7253259: no machine available yet 2025-12-22 08:28:48,893 [cuckoo.core.scheduler] DEBUG: Task #7253259: no machine available yet 2025-12-22 08:28:49,917 [cuckoo.core.scheduler] DEBUG: Task #7253259: no machine available yet 2025-12-22 08:28:50,939 [cuckoo.core.scheduler] DEBUG: Task #7253259: no machine available yet 2025-12-22 08:28:51,960 [cuckoo.core.scheduler] DEBUG: Task #7253259: no machine available yet 2025-12-22 08:28:52,982 [cuckoo.core.scheduler] DEBUG: Task #7253259: no machine available yet 2025-12-22 08:28:54,015 [cuckoo.core.scheduler] DEBUG: Task #7253259: no machine available yet 2025-12-22 08:28:55,043 [cuckoo.core.scheduler] DEBUG: Task #7253259: no machine available yet 2025-12-22 08:28:56,352 [cuckoo.core.scheduler] DEBUG: Task #7253259: no machine available yet 2025-12-22 08:28:57,374 [cuckoo.core.scheduler] DEBUG: Task #7253259: no machine available yet 2025-12-22 08:28:58,406 [cuckoo.core.scheduler] DEBUG: Task #7253259: no machine available yet 2025-12-22 08:28:59,567 [cuckoo.core.scheduler] DEBUG: Task #7253259: no machine available yet 2025-12-22 08:29:00,732 [cuckoo.core.scheduler] DEBUG: Task #7253259: no machine available yet 2025-12-22 08:29:01,764 [cuckoo.core.scheduler] DEBUG: Task #7253259: no machine available yet 2025-12-22 08:29:02,814 [cuckoo.core.scheduler] DEBUG: Task #7253259: no machine available yet 2025-12-22 08:29:03,857 [cuckoo.core.scheduler] DEBUG: Task #7253259: no machine available yet 2025-12-22 08:29:04,880 [cuckoo.core.scheduler] DEBUG: Task #7253259: no machine available yet 2025-12-22 08:29:05,906 [cuckoo.core.scheduler] DEBUG: Task #7253259: no machine available yet 2025-12-22 08:29:06,931 [cuckoo.core.scheduler] DEBUG: Task #7253259: no machine available yet 2025-12-22 08:29:07,958 [cuckoo.core.scheduler] DEBUG: Task #7253259: no machine available yet 2025-12-22 08:29:08,979 [cuckoo.core.scheduler] DEBUG: Task #7253259: no machine available yet 2025-12-22 08:29:10,000 [cuckoo.core.scheduler] DEBUG: Task #7253259: no machine available yet 2025-12-22 08:29:11,110 [cuckoo.core.scheduler] DEBUG: Task #7253259: no machine available yet 2025-12-22 08:29:12,129 [cuckoo.core.scheduler] DEBUG: Task #7253259: no machine available yet 2025-12-22 08:29:13,154 [cuckoo.core.scheduler] DEBUG: Task #7253259: no machine available yet 2025-12-22 08:29:14,185 [cuckoo.core.scheduler] DEBUG: Task #7253259: no machine available yet 2025-12-22 08:29:15,396 [cuckoo.core.scheduler] INFO: Task #7253259: acquired machine win7x6414 (label=win7x6414) 2025-12-22 08:29:15,399 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.214 for task #7253259 2025-12-22 08:29:15,807 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 3657478 (interface=vboxnet0, host=192.168.168.214) 2025-12-22 08:29:18,261 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6414 2025-12-22 08:29:19,090 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6414 to vmcloak 2025-12-22 08:31:55,455 [cuckoo.core.guest] INFO: Starting analysis #7253259 on guest (id=win7x6414, ip=192.168.168.214) 2025-12-22 08:31:56,461 [cuckoo.core.guest] DEBUG: win7x6414: not ready yet 2025-12-22 08:32:01,504 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6414, ip=192.168.168.214) 2025-12-22 08:32:01,636 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6414, ip=192.168.168.214, monitor=latest, size=6660546) 2025-12-22 08:32:03,982 [cuckoo.core.resultserver] DEBUG: Task #7253259: live log analysis.log initialized. 2025-12-22 08:32:05,389 [cuckoo.core.resultserver] DEBUG: Task #7253259 is sending a BSON stream 2025-12-22 08:32:05,885 [cuckoo.core.resultserver] DEBUG: Task #7253259 is sending a BSON stream 2025-12-22 08:32:06,686 [cuckoo.core.resultserver] DEBUG: Task #7253259: File upload for 'shots/0001.jpg' 2025-12-22 08:32:06,879 [cuckoo.core.resultserver] DEBUG: Task #7253259 uploaded file length: 133499 2025-12-22 08:32:07,093 [cuckoo.core.resultserver] DEBUG: Task #7253259: File upload for 'files/51d44fd2988585ff_BD4E.tmp' 2025-12-22 08:32:07,511 [cuckoo.core.resultserver] DEBUG: Task #7253259 uploaded file length: 2400946 2025-12-22 08:32:07,522 [cuckoo.core.resultserver] DEBUG: Task #7253259 is sending a BSON stream 2025-12-22 08:32:09,044 [cuckoo.core.resultserver] DEBUG: Task #7253259: File upload for 'files/e3b0c44298fc1c14_C2E1.tmp' 2025-12-22 08:32:09,052 [cuckoo.core.resultserver] DEBUG: Task #7253259 uploaded file length: 0 2025-12-22 08:32:18,358 [cuckoo.core.guest] DEBUG: win7x6414: analysis #7253259 still processing 2025-12-22 08:32:33,470 [cuckoo.core.guest] DEBUG: win7x6414: analysis #7253259 still processing 2025-12-22 08:32:48,740 [cuckoo.core.guest] DEBUG: win7x6414: analysis #7253259 still processing 2025-12-22 08:32:51,862 [cuckoo.core.resultserver] DEBUG: Task #7253259: File upload for 'files/d6a9bd30c6a1cd05_6896.tmp' 2025-12-22 08:32:51,865 [cuckoo.core.resultserver] DEBUG: Task #7253259 uploaded file length: 1230 2025-12-22 08:33:03,900 [cuckoo.core.guest] DEBUG: win7x6414: analysis #7253259 still processing 2025-12-22 08:33:19,181 [cuckoo.core.guest] DEBUG: win7x6414: analysis #7253259 still processing 2025-12-22 08:33:34,317 [cuckoo.core.guest] DEBUG: win7x6414: analysis #7253259 still processing 2025-12-22 08:33:49,433 [cuckoo.core.guest] DEBUG: win7x6414: analysis #7253259 still processing 2025-12-22 08:34:04,609 [cuckoo.core.guest] DEBUG: win7x6414: analysis #7253259 still processing 2025-12-22 08:34:19,733 [cuckoo.core.guest] DEBUG: win7x6414: analysis #7253259 still processing 2025-12-22 08:34:34,867 [cuckoo.core.guest] DEBUG: win7x6414: analysis #7253259 still processing 2025-12-22 08:34:49,942 [cuckoo.core.guest] DEBUG: win7x6414: analysis #7253259 still processing 2025-12-22 08:35:05,022 [cuckoo.core.guest] DEBUG: win7x6414: analysis #7253259 still processing 2025-12-22 08:35:20,246 [cuckoo.core.guest] DEBUG: win7x6414: analysis #7253259 still processing 2025-12-22 08:35:25,058 [cuckoo.core.resultserver] DEBUG: Task #7253259: File upload for 'curtain/1766385324.92.curtain.log' 2025-12-22 08:35:25,061 [cuckoo.core.resultserver] DEBUG: Task #7253259 uploaded file length: 36 2025-12-22 08:35:25,758 [cuckoo.core.resultserver] DEBUG: Task #7253259: File upload for 'sysmon/1766385325.6.sysmon.xml' 2025-12-22 08:35:25,848 [cuckoo.core.resultserver] DEBUG: Task #7253259 uploaded file length: 8807488 2025-12-22 08:35:25,869 [cuckoo.core.resultserver] DEBUG: Task #7253259: File upload for 'files/aa3f745baa0067fb_svchost.exe' 2025-12-22 08:35:25,888 [cuckoo.core.resultserver] DEBUG: Task #7253259 uploaded file length: 2400946 2025-12-22 08:35:25,896 [cuckoo.core.resultserver] DEBUG: Task #7253259: File upload for 'files/33ba8221ff3f5211_94308059b57b3142e455b38a6eb92015' 2025-12-22 08:35:25,898 [cuckoo.core.resultserver] DEBUG: Task #7253259 uploaded file length: 73211 2025-12-22 08:35:25,900 [cuckoo.core.resultserver] DEBUG: Task #7253259: File upload for 'files/2661247d753fc638_8b2b9a00839eed1dfdccc3bfc2f5df12' 2025-12-22 08:35:25,902 [cuckoo.core.resultserver] DEBUG: Task #7253259 uploaded file length: 174 2025-12-22 08:35:25,905 [cuckoo.core.resultserver] DEBUG: Task #7253259: File upload for 'files/6fb1b8e593cb0388_b46811c17859ffb409cf0e904a4aa8f8' 2025-12-22 08:35:25,908 [cuckoo.core.resultserver] DEBUG: Task #7253259 uploaded file length: 530 2025-12-22 08:35:25,912 [cuckoo.core.resultserver] DEBUG: Task #7253259: File upload for 'files/ebd41040e4bb3ec7_14232b434cf29d4c4fb335a86d7fffe3' 2025-12-22 08:35:25,914 [cuckoo.core.resultserver] DEBUG: Task #7253259 uploaded file length: 889 2025-12-22 08:35:25,918 [cuckoo.core.resultserver] DEBUG: Task #7253259: File upload for 'files/e28476175c1c43f2_94308059b57b3142e455b38a6eb92015' 2025-12-22 08:35:25,922 [cuckoo.core.resultserver] DEBUG: Task #7253259 uploaded file length: 344 2025-12-22 08:35:25,924 [cuckoo.core.resultserver] DEBUG: Task #7253259: File upload for 'files/0f71708dbfee304a_8b2b9a00839eed1dfdccc3bfc2f5df12' 2025-12-22 08:35:25,929 [cuckoo.core.resultserver] DEBUG: Task #7253259 uploaded file length: 1739 2025-12-22 08:35:25,931 [cuckoo.core.resultserver] DEBUG: Task #7253259: File upload for 'files/43f20d0103c6616c_f0accf77cdcbff39f6191887f6d2d357' 2025-12-22 08:35:25,937 [cuckoo.core.resultserver] DEBUG: Task #7253259 uploaded file length: 242 2025-12-22 08:35:25,939 [cuckoo.core.resultserver] DEBUG: Task #7253259: File upload for 'files/df545bf919a2439c_f0accf77cdcbff39f6191887f6d2d357' 2025-12-22 08:35:25,941 [cuckoo.core.resultserver] DEBUG: Task #7253259 uploaded file length: 1521 2025-12-22 08:35:25,942 [cuckoo.core.resultserver] DEBUG: Task #7253259: File upload for 'files/d49efe255e51f8be_14232b434cf29d4c4fb335a86d7fffe3' 2025-12-22 08:35:25,944 [cuckoo.core.resultserver] DEBUG: Task #7253259 uploaded file length: 170 2025-12-22 08:35:25,945 [cuckoo.core.resultserver] DEBUG: Task #7253259: File upload for 'files/12cd4c75a59e34cc_b46811c17859ffb409cf0e904a4aa8f8' 2025-12-22 08:35:25,948 [cuckoo.core.resultserver] DEBUG: Task #7253259 uploaded file length: 170 2025-12-22 08:35:25,969 [cuckoo.core.resultserver] DEBUG: Task #7253259 had connection reset for <Context for LOG> 2025-12-22 08:35:26,276 [cuckoo.core.guest] INFO: win7x6414: analysis completed successfully 2025-12-22 08:35:26,294 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2025-12-22 08:35:26,321 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2025-12-22 08:35:29,013 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6414 to path /srv/cuckoo/cwd/storage/analyses/7253259/memory.dmp 2025-12-22 08:35:30,628 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6414 2025-12-22 08:37:41,606 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.214 for task #7253259 2025-12-22 08:37:43,553 [cuckoo.core.scheduler] DEBUG: Released database task #7253259 2025-12-22 08:37:43,632 [cuckoo.core.scheduler] INFO: Task #7253259: analysis procedure completed
| description | Communications use DNS | rule | network_dns | ||||||
| description | Take screenshot | rule | screenshot | ||||||
| description | Affect system registries | rule | win_registry | ||||||
| registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\InstallDate |
| section | .vjNlbf |
| section | .kudd |
| section | .FeE |
| section | .kbVKK |
| section | .WKQ |
| section | .J |
| section | .UXAdns |
| section | .jFpzOB |
| section | .cmF |
| description | svchost.exe tried to sleep 240 seconds, actually delayed analysis time by 240 seconds | |||
| file | C:\Windows\AppPatch\svchost.exe |
| cmdline | C:\Windows\AppPatch\svchost.exe |
| file | C:\Windows\AppPatch\svchost.exe |
| section | {u'size_of_data': u'0x0001485c', u'virtual_address': u'0x00235000', u'entropy': 7.9111750686050515, u'name': u'.rsrc', u'virtual_size': u'0x0001485c'} | entropy | 7.91117506861 | description | A section with a high entropy has been found | |||||||||
| buffer | Buffer with sha1: 501b45da2f14fb66a5098cfaa2e35fcd0070956c |
| snort | ET POLICY Unsupported/Fake Windows NT Version 5.0 |
| snort | ET POLICY Unsupported/Fake Internet Explorer Version MSIE 2. |
| snort | ET INFO Namecheap URL Forward |
| file | C:\Program Files (x86)\AVG\AVG9\dfncfg.dat |
| registry | HKEY_LOCAL_MACHINE\SystemBiosVersion |
| reg_key | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\userinit | reg_value | C:\Windows\system32\userinit.exe,C:\Windows\apppatch\svchost.exe, | ||||||
| Process injection | Process 892 created a remote thread in non-child process 2352 |
| Process injection | Process 892 created a remote thread in non-child process 1796 |
| Process injection | Process 892 manipulating memory of non-child process 892 |
| Process injection | Process 892 manipulating memory of non-child process 2352 |
| Process injection | Process 892 manipulating memory of non-child process 1796 |