|
Action call | System path | Extracted behavior |
|
NtCreateFile | “c:\windows\...\sfile1.exe,” malware.exe ⟶ 1 | CreateFile (1) |
NtCreateFile | “c:\programfiles\...\,” malware.exe ⟶ 2 | none |
NtQueryDirectory | 2, “c:\programfiles\...\,” malware.exe ⟶ 3 | SearchDirectory (2) |
NtReadFile | 3, “c:\...\tfile1.txt,” malware.exe ⟶ 4 | ReadFile (3) |
NtReadFile | 3, “c:\...\tfile2.exe,” malware.exe ⟶ 5 | ReadFile (3) |
NtCloseFile | 4, “tfile1.txt,” malware.exe ⟶ 6 | none |
NtWriteFile | 1, “sfile1.exe,” malware.exe ⟶ 7 | WriteFile (1) |
NtReadFile | 7, “sfile1.exe,” malware.exe ⟶ 8 | ReadFile (7) |
NtWriteFile | 5, “tfile2.exe,” sfile1.exe ⟶ 9 | WriteFile (5) |
NtCreateKey | “hklm\software\...\, key1,” tfile2.exe ⟶ 10 | none |
NtSetValue | 10, “key1,” tfile2.exe ⟶ 11 | SetValue (10) |
NtRegCloseKey | 11, “key1,” tfile2.exe ⟶ 12 | none |
NtCreateFile | “c:\windows\...\stfile1.dll,” tfile2.exe ⟶ 13 | none |
NtCreateFile | “c:\windows\...\stfile2.dll,” tfile2.exe ⟶ 14 | none |
NtCloseFile | 8, “sfile1.exe,” malware.exe ⟶ 15 | none |
NtReadFile | 13, “stfile1.dll,” tfile2.exe ⟶ 16 | ReadFile (13) |
NtReadFile | 13, “stfile1.dll,” tfile2.exe ⟶ 17 | ReadFile (13) |
NtReadFile | 14, “stfile2.dll,” tfile2.exe ⟶ 18 | ReadFile (14) |
NtCloseFile | 17, “stfile1.dll,” tfile2.exe ⟶ 19 | none |
NtCloseFile | 18, “stfile2.dll,” tfile2.exe ⟶ 20 | none |
NtCloseFile | 9, “tfile2.exe,” tfile2.exe ⟶ 21 | none |
|