| Time & API |
Arguments |
Status |
Return |
Repeated |
1727110790.797125
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x6fc91000
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2264
|
success
|
0 |
0
|
1727110790.812125
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x0043a000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2264
|
success
|
0 |
0
|
1727110790.812125
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x6fc92000
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2264
|
success
|
0 |
0
|
1727110790.812125
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x00432000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2264
|
success
|
0 |
0
|
1727110790.828125
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x00442000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2264
|
success
|
0 |
0
|
1727110790.844125
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x00443000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2264
|
success
|
0 |
0
|
1727110790.844125
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x0047b000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2264
|
success
|
0 |
0
|
1727110790.844125
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x00477000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2264
|
success
|
0 |
0
|
1727110790.844125
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x0044c000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2264
|
success
|
0 |
0
|
1727110790.875125
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x00680000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2264
|
success
|
0 |
0
|
1727110790.875125
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x00444000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2264
|
success
|
0 |
0
|
1727110790.891125
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x00456000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2264
|
success
|
0 |
0
|
1727110790.891125
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x0044a000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2264
|
success
|
0 |
0
|
1727110790.906125
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x0046a000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2264
|
success
|
0 |
0
|
1727110790.906125
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x00462000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2264
|
success
|
0 |
0
|
1727110790.906125
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x00475000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2264
|
success
|
0 |
0
|
1727110790.937125
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x0043b000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2264
|
success
|
0 |
0
|
1727110790.937125
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x0045a000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2264
|
success
|
0 |
0
|
1727110790.937125
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x00457000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2264
|
success
|
0 |
0
|
1727110791.73425
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x6f6e1000
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2004
|
success
|
0 |
0
|
1727110791.73425
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x002ba000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2004
|
success
|
0 |
0
|
1727110791.73425
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x6f6e2000
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2004
|
success
|
0 |
0
|
1727110791.73425
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x002b2000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2004
|
success
|
0 |
0
|
1727110791.75025
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x002c2000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2004
|
success
|
0 |
0
|
1727110791.76625
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x002c3000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2004
|
success
|
0 |
0
|
1727110791.76625
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x002fb000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2004
|
success
|
0 |
0
|
1727110791.76625
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x002f7000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2004
|
success
|
0 |
0
|
1727110791.76625
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x002cc000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2004
|
success
|
0 |
0
|
1727110791.78125
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x00850000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2004
|
success
|
0 |
0
|
1727110791.78125
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x002ea000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2004
|
success
|
0 |
0
|
1727110791.78125
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x002e2000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2004
|
success
|
0 |
0
|
1727110791.78125
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x002c4000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2004
|
success
|
0 |
0
|
1727110791.78125
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x002f5000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2004
|
success
|
0 |
0
|
1727110791.81225
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x002c5000
region_size:
8192
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2004
|
success
|
0 |
0
|
1727110791.81225
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x002c7000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2004
|
success
|
0 |
0
|
1727110791.81225
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x002da000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2004
|
success
|
0 |
0
|
1727110791.81225
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x002d7000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2004
|
success
|
0 |
0
|
1727110791.81225
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x002bb000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2004
|
success
|
0 |
0
|
1727110792.43725
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x04580000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2004
|
success
|
0 |
0
|
1727110792.43725
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x002d6000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2004
|
success
|
0 |
0
|
1727110796.45325
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x002ca000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2004
|
success
|
0 |
0
|
1727110796.46925
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x002c8000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2004
|
success
|
0 |
0
|
1727110796.48425
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x04581000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2004
|
success
|
0 |
0
|
1727110796.51625
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x002b3000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2004
|
success
|
0 |
0
|
1727110796.51625
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x04582000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2004
|
success
|
0 |
0
|
1727110799.15625
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x002db000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2004
|
success
|
0 |
0
|
1727110799.53125
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x04583000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2004
|
success
|
0 |
0
|
1727110803.04725
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x00851000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2004
|
success
|
0 |
0
|
1727110803.04725
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x7ef20000
region_size:
327680
allocation_type:
1056768
(MEM_RESERVE|MEM_TOP_DOWN)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2004
|
success
|
0 |
0
|
1727110803.04725
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x7ef20000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2004
|
success
|
0 |
0
|