CreateProcessA
Read documentation
Through official Microsoft Developer Network (MSDN).
Featured in Techniques
| Technique Name | Technique ID's | Categories | Snippet(s) | Rules(s) |
|---|---|---|---|---|
| Process Hollowing, RunPE | U1225 E1055.012 |
|
||
| APC injection | U1221 E1055.004 |
|
||
| File Melt | U1007 |
|
||
| Access Token Manipulation: Parent PID Spoofing | U1234 T1134.004 |
|
Matching Samples 10 most recent
| Sample Name | Matching Techniques | First Seen | Last Seen |
|---|---|---|---|
| KincoBuilderV85En.exe | 4 | 2026-06-24 | 1 day, 13 hours ago |
| nopggplus.dll | 5 | 2026-06-12 | 1 week, 6 days ago |
| presenter_lib.dll | 5 | 2025-08-16 | 1 month ago |
| merged.exe | 6 | 2026-04-24 | 2 months ago |
| rlm1611_http.dll | 6 | 2025-11-22 | 3 months ago |
| loader_complete.exe | 10 | 2026-01-27 | 4 months, 4 weeks ago |
| eState-2026-ZM4RXTVD.exe | 3 | 2026-01-20 | 5 months ago |
| NVTArk_Free_Setup.exe | 3 | 2026-01-18 | 5 months, 1 week ago |
| steamcmd.exe | 5 | 2025-11-02 | 7 months, 3 weeks ago |
| program.exe | 6 | 2025-10-01 | 8 months, 3 weeks ago |