| Time & API |
Arguments |
Status |
Return |
Repeated |
1619373865.958625
NtAllocateVirtualMemory
|
process_identifier:
1632
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005d0000
|
success
|
0 |
0
|
1619373866.005625
NtProtectVirtualMemory
|
process_identifier:
1632
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
61440
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x0047f000
|
success
|
0 |
0
|
1619373866.021625
NtAllocateVirtualMemory
|
process_identifier:
1632
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00610000
|
success
|
0 |
0
|
1619373866.239
NtProtectVirtualMemory
|
process_identifier:
2452
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00400000
|
success
|
0 |
0
|
1619373866.271
NtAllocateVirtualMemory
|
process_identifier:
2452
region_size:
327680
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00500000
|
success
|
0 |
0
|
1619373866.271
NtAllocateVirtualMemory
|
process_identifier:
2452
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00510000
|
success
|
0 |
0
|
1619373866.271
NtAllocateVirtualMemory
|
process_identifier:
2452
region_size:
311296
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x01dd0000
|
success
|
0 |
0
|
1619373866.271
NtProtectVirtualMemory
|
process_identifier:
2452
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
282624
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01dd2000
|
success
|
0 |
0
|
1619373866.739
NtProtectVirtualMemory
|
process_identifier:
2452
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01f22000
|
success
|
0 |
0
|
1619373866.739
NtProtectVirtualMemory
|
process_identifier:
2452
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76351000
|
success
|
0 |
0
|
1619373866.755
NtProtectVirtualMemory
|
process_identifier:
2452
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01f22000
|
success
|
0 |
0
|
1619373866.755
NtProtectVirtualMemory
|
process_identifier:
2452
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76353000
|
success
|
0 |
0
|
1619373866.755
NtProtectVirtualMemory
|
process_identifier:
2452
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01f22000
|
success
|
0 |
0
|
1619373866.755
NtProtectVirtualMemory
|
process_identifier:
2452
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76354000
|
success
|
0 |
0
|
1619373866.755
NtProtectVirtualMemory
|
process_identifier:
2452
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01f22000
|
success
|
0 |
0
|
1619373866.755
NtProtectVirtualMemory
|
process_identifier:
2452
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76351000
|
success
|
0 |
0
|
1619373866.755
NtProtectVirtualMemory
|
process_identifier:
2452
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01f22000
|
success
|
0 |
0
|
1619373866.755
NtProtectVirtualMemory
|
process_identifier:
2452
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x77d4f000
|
success
|
0 |
0
|
1619373866.755
NtProtectVirtualMemory
|
process_identifier:
2452
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01f22000
|
success
|
0 |
0
|
1619373866.755
NtProtectVirtualMemory
|
process_identifier:
2452
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76353000
|
success
|
0 |
0
|
1619373866.755
NtProtectVirtualMemory
|
process_identifier:
2452
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01f22000
|
success
|
0 |
0
|
1619373866.755
NtProtectVirtualMemory
|
process_identifier:
2452
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76351000
|
success
|
0 |
0
|
1619373866.755
NtProtectVirtualMemory
|
process_identifier:
2452
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01f22000
|
success
|
0 |
0
|
1619373866.755
NtProtectVirtualMemory
|
process_identifier:
2452
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76351000
|
success
|
0 |
0
|
1619373866.755
NtProtectVirtualMemory
|
process_identifier:
2452
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01f22000
|
success
|
0 |
0
|
1619373866.755
NtProtectVirtualMemory
|
process_identifier:
2452
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76354000
|
success
|
0 |
0
|
1619373866.755
NtProtectVirtualMemory
|
process_identifier:
2452
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01f22000
|
success
|
0 |
0
|
1619373866.755
NtProtectVirtualMemory
|
process_identifier:
2452
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76351000
|
success
|
0 |
0
|
1619373866.30225
NtAllocateVirtualMemory
|
process_identifier:
1396
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00380000
|
success
|
0 |
0
|
1619373866.31725
NtProtectVirtualMemory
|
process_identifier:
1396
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
61440
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x0047f000
|
success
|
0 |
0
|
1619373866.31725
NtAllocateVirtualMemory
|
process_identifier:
1396
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x003c0000
|
success
|
0 |
0
|
1619373881.364625
NtAllocateVirtualMemory
|
process_identifier:
1124
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004e0000
|
success
|
0 |
0
|
1619373881.364625
NtProtectVirtualMemory
|
process_identifier:
1124
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
61440
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x0047f000
|
success
|
0 |
0
|
1619373881.364625
NtAllocateVirtualMemory
|
process_identifier:
1124
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00520000
|
success
|
0 |
0
|
1619373882.052125
NtProtectVirtualMemory
|
process_identifier:
1168
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00400000
|
success
|
0 |
0
|
1619373882.052125
NtAllocateVirtualMemory
|
process_identifier:
1168
region_size:
327680
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x01d90000
|
success
|
0 |
0
|
1619373882.052125
NtAllocateVirtualMemory
|
process_identifier:
1168
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x01da0000
|
success
|
0 |
0
|
1619373882.052125
NtAllocateVirtualMemory
|
process_identifier:
1168
region_size:
311296
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x01de0000
|
success
|
0 |
0
|
1619373882.052125
NtProtectVirtualMemory
|
process_identifier:
1168
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
282624
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01de2000
|
success
|
0 |
0
|
1619373882.130125
NtProtectVirtualMemory
|
process_identifier:
1168
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00392000
|
success
|
0 |
0
|
1619373882.130125
NtProtectVirtualMemory
|
process_identifier:
1168
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76351000
|
success
|
0 |
0
|
1619373882.130125
NtProtectVirtualMemory
|
process_identifier:
1168
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00392000
|
success
|
0 |
0
|
1619373882.130125
NtProtectVirtualMemory
|
process_identifier:
1168
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76353000
|
success
|
0 |
0
|
1619373882.130125
NtProtectVirtualMemory
|
process_identifier:
1168
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00392000
|
success
|
0 |
0
|
1619373882.130125
NtProtectVirtualMemory
|
process_identifier:
1168
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76354000
|
success
|
0 |
0
|
1619373882.130125
NtProtectVirtualMemory
|
process_identifier:
1168
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00392000
|
success
|
0 |
0
|
1619373882.130125
NtProtectVirtualMemory
|
process_identifier:
1168
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76351000
|
success
|
0 |
0
|
1619373882.130125
NtProtectVirtualMemory
|
process_identifier:
1168
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00392000
|
success
|
0 |
0
|
1619373882.130125
NtProtectVirtualMemory
|
process_identifier:
1168
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x77d4f000
|
success
|
0 |
0
|
1619373882.130125
NtProtectVirtualMemory
|
process_identifier:
1168
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00392000
|
success
|
0 |
0
|