| Time & API |
Arguments |
Status |
Return |
Repeated |
1619286912.92425
NtAllocateVirtualMemory
|
process_identifier:
2060
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006e0000
|
success
|
0 |
0
|
1619286556.05252
NtAllocateVirtualMemory
|
process_identifier:
1424
region_size:
65536
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0000000004610000
|
success
|
0 |
0
|
1619286935.72125
NtAllocateVirtualMemory
|
process_identifier:
1176
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00690000
|
success
|
0 |
0
|
1619286935.72125
NtProtectVirtualMemory
|
process_identifier:
1176
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x755d1000
|
success
|
0 |
0
|
1619286935.72125
NtProtectVirtualMemory
|
process_identifier:
1176
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x75011000
|
success
|
0 |
0
|
1619286935.73725
NtProtectVirtualMemory
|
process_identifier:
1176
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x75051000
|
success
|
0 |
0
|
1619286936.04925
NtProtectVirtualMemory
|
process_identifier:
1176
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x74ff1000
|
success
|
0 |
0
|
1619286936.33025
NtProtectVirtualMemory
|
process_identifier:
1176
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x77711000
|
success
|
0 |
0
|
1619286936.33025
NtProtectVirtualMemory
|
process_identifier:
1176
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76241000
|
success
|
0 |
0
|
1619286936.33025
NtProtectVirtualMemory
|
process_identifier:
1176
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76121000
|
success
|
0 |
0
|
1619286936.47125
NtProtectVirtualMemory
|
process_identifier:
1176
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x75a11000
|
success
|
0 |
0
|
1619286936.47125
NtProtectVirtualMemory
|
process_identifier:
1176
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x766c1000
|
success
|
0 |
0
|
1619286936.47125
NtProtectVirtualMemory
|
process_identifier:
1176
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x77691000
|
success
|
0 |
0
|
1619286937.76825
NtProtectVirtualMemory
|
process_identifier:
1176
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x75021000
|
success
|
0 |
0
|
1619286937.76825
NtProtectVirtualMemory
|
process_identifier:
1176
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76881000
|
success
|
0 |
0
|
1619286939.97125
NtProtectVirtualMemory
|
process_identifier:
1176
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x746e1000
|
success
|
0 |
0
|
1619286940.01825
NtProtectVirtualMemory
|
process_identifier:
1176
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x74811000
|
success
|
0 |
0
|
1619286940.14325
NtProtectVirtualMemory
|
process_identifier:
1176
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x74641000
|
success
|
0 |
0
|