| Time & API |
Arguments |
Status |
Return |
Repeated |
1727545321.890875
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x6fc91000
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1856
|
success
|
0 |
0
|
1727545321.921875
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x003aa000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1856
|
success
|
0 |
0
|
1727545321.921875
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x6fc92000
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1856
|
success
|
0 |
0
|
1727545321.921875
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x003a2000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1856
|
success
|
0 |
0
|
1727545322.000875
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x003b2000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1856
|
success
|
0 |
0
|
1727545322.031875
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x003b3000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1856
|
success
|
0 |
0
|
1727545322.031875
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x003eb000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1856
|
success
|
0 |
0
|
1727545322.031875
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x003e7000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1856
|
success
|
0 |
0
|
1727545322.046875
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x003bc000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1856
|
success
|
0 |
0
|
1727545322.125875
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x00610000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1856
|
success
|
0 |
0
|
1727545322.140875
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x003b4000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1856
|
success
|
0 |
0
|
1727545322.140875
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x003c6000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1856
|
success
|
0 |
0
|
1727545322.156875
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x003ba000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1856
|
success
|
0 |
0
|
1727545322.171875
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x003da000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1856
|
success
|
0 |
0
|
1727545322.171875
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x003d2000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1856
|
success
|
0 |
0
|
1727545322.187875
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x003e5000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1856
|
success
|
0 |
0
|
1727545322.265875
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x003ab000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1856
|
success
|
0 |
0
|
1727545322.281875
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x003ca000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1856
|
success
|
0 |
0
|
1727545322.281875
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x003c7000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1856
|
success
|
0 |
0
|
1727545324.2185
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x6f6e1000
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1600
|
success
|
0 |
0
|
1727545324.2345
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x0047a000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1600
|
success
|
0 |
0
|
1727545324.2345
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x6f6e2000
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1600
|
success
|
0 |
0
|
1727545324.2505
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x00472000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1600
|
success
|
0 |
0
|
1727545324.2655
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x00482000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1600
|
success
|
0 |
0
|
1727545324.2965
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x00483000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1600
|
success
|
0 |
0
|
1727545324.2965
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x004bb000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1600
|
success
|
0 |
0
|
1727545324.2965
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x004b7000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1600
|
success
|
0 |
0
|
1727545324.2965
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x0048c000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1600
|
success
|
0 |
0
|
1727545324.3435
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x005d0000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1600
|
success
|
0 |
0
|
1727545324.3595
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x004aa000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1600
|
success
|
0 |
0
|
1727545324.3595
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x004a2000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1600
|
success
|
0 |
0
|
1727545324.3595
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x00484000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1600
|
success
|
0 |
0
|
1727545324.3595
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x004b5000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1600
|
success
|
0 |
0
|
1727545324.4375
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x00485000
region_size:
8192
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1600
|
success
|
0 |
0
|
1727545324.4375
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x00487000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1600
|
success
|
0 |
0
|
1727545324.4535
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x0049a000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1600
|
success
|
0 |
0
|
1727545324.4535
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x00497000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1600
|
success
|
0 |
0
|
1727545324.4685
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x0047b000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1600
|
success
|
0 |
0
|
1727545325.9535
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x04640000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1600
|
success
|
0 |
0
|
1727545325.9535
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x00496000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1600
|
success
|
0 |
0
|
1727545330.0005
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x0048a000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1600
|
success
|
0 |
0
|
1727545330.0625
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x00488000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1600
|
success
|
0 |
0
|
1727545330.1255
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x04641000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1600
|
success
|
0 |
0
|
1727545330.1875
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x00473000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1600
|
success
|
0 |
0
|
1727545330.2035
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x04642000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1600
|
success
|
0 |
0
|
1727545332.9845
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x0049b000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1600
|
success
|
0 |
0
|
1727545333.3905
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x04643000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1600
|
success
|
0 |
0
|
1727545333.9375
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x005d1000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1600
|
success
|
0 |
0
|
1727545333.9535
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x7ef20000
region_size:
327680
allocation_type:
1056768
(MEM_RESERVE|MEM_TOP_DOWN)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1600
|
success
|
0 |
0
|
1727545333.9535
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x7ef20000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1600
|
success
|
0 |
0
|