CreateProcessA
Read documentation
Through official Microsoft Developer Network (MSDN).
Featured in Techniques
| Technique Name | Technique ID's | Snippet(s) | Rules(s) | OS |
|---|---|---|---|---|
| Process Hollowing, RunPE | U1225 E1055.012 | |||
| APC injection | U1221 E1055.004 | |||
| File Melt | U1007 | |||
| Access Token Manipulation: Parent PID Spoofing | U1234 T1134.004 |
Matching Samples 10 most recent
| Sample Name | Matching Techniques | First Seen | Last Seen |
|---|---|---|---|
| eState-2026-ZM4RXTVD.exe | 3 | 2026-01-20 | 5 days, 1 hour ago |
| NVTArk_Free_Setup.exe | 3 | 2026-01-18 | 6 days, 12 hours ago |
| rlm1611_http.dll | 6 | 2025-11-22 | 2 months ago |
| steamcmd.exe | 5 | 2025-11-02 | 2 months, 3 weeks ago |
| program.exe | 6 | 2025-10-01 | 3 months, 3 weeks ago |
| DNS-C2.exe84-rednefed-swodniw-8snoci.exe | 6 | 2025-09-23 | 4 months ago |
| rlm1611_http.dll | 6 | 2025-09-22 | 4 months ago |
| test.exe | 8 | 2025-09-20 | 4 months ago |
| presenter_lib.dll | 5 | 2025-08-16 | 5 months, 1 week ago |
| hemlockwin.exe | 8 | 2025-08-06 | 5 months, 2 weeks ago |