| Time & API |
Arguments |
Status |
Return |
Repeated |
1727545335.327625
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x6fc91000
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1064
|
success
|
0 |
0
|
1727545335.359625
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x003aa000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1064
|
success
|
0 |
0
|
1727545335.359625
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x6fc92000
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1064
|
success
|
0 |
0
|
1727545335.359625
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x003a2000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1064
|
success
|
0 |
0
|
1727545335.421625
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x003b2000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1064
|
success
|
0 |
0
|
1727545335.452625
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x003b3000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1064
|
success
|
0 |
0
|
1727545335.452625
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x003eb000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1064
|
success
|
0 |
0
|
1727545335.452625
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x003e7000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1064
|
success
|
0 |
0
|
1727545335.468625
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x003bc000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1064
|
success
|
0 |
0
|
1727545335.546625
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x006d0000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1064
|
success
|
0 |
0
|
1727545335.562625
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x003b4000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1064
|
success
|
0 |
0
|
1727545335.577625
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x003c6000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1064
|
success
|
0 |
0
|
1727545335.593625
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x003ba000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1064
|
success
|
0 |
0
|
1727545335.609625
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x003da000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1064
|
success
|
0 |
0
|
1727545335.624625
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x003d2000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1064
|
success
|
0 |
0
|
1727545335.640625
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x003e5000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1064
|
success
|
0 |
0
|
1727545335.749625
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x003ab000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1064
|
success
|
0 |
0
|
1727545335.749625
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x003ca000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1064
|
success
|
0 |
0
|
1727545335.749625
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x003c7000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1064
|
success
|
0 |
0
|
1727545337.43725
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x6f6e1000
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2492
|
success
|
0 |
0
|
1727545337.45225
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x0044a000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2492
|
success
|
0 |
0
|
1727545337.45225
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x6f6e2000
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2492
|
success
|
0 |
0
|
1727545337.45225
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x00442000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2492
|
success
|
0 |
0
|
1727545337.49925
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x00452000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2492
|
success
|
0 |
0
|
1727545337.51525
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x00453000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2492
|
success
|
0 |
0
|
1727545337.51525
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x0048b000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2492
|
success
|
0 |
0
|
1727545337.51525
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x00487000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2492
|
success
|
0 |
0
|
1727545337.51525
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x0045c000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2492
|
success
|
0 |
0
|
1727545337.56225
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x00700000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2492
|
success
|
0 |
0
|
1727545337.57725
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x0047a000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2492
|
success
|
0 |
0
|
1727545337.57725
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x00472000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2492
|
success
|
0 |
0
|
1727545337.57725
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x00454000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2492
|
success
|
0 |
0
|
1727545337.57725
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x00485000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2492
|
success
|
0 |
0
|
1727545337.64025
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x00455000
region_size:
8192
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2492
|
success
|
0 |
0
|
1727545337.64025
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x00457000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2492
|
success
|
0 |
0
|
1727545337.64025
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x0046a000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2492
|
success
|
0 |
0
|
1727545337.64025
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x00467000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2492
|
success
|
0 |
0
|
1727545337.65625
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x0044b000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2492
|
success
|
0 |
0
|
1727545338.81225
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x02050000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2492
|
success
|
0 |
0
|
1727545338.81225
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x00466000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2492
|
success
|
0 |
0
|
1727545342.84325
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x0045a000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2492
|
success
|
0 |
0
|
1727545342.90625
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x00458000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2492
|
success
|
0 |
0
|
1727545342.96825
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x02051000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2492
|
success
|
0 |
0
|
1727545343.04625
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x00443000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2492
|
success
|
0 |
0
|
1727545343.06225
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x02052000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2492
|
success
|
0 |
0
|
1727545345.84325
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x0046b000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2492
|
success
|
0 |
0
|
1727545346.23425
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x02053000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2492
|
success
|
0 |
0
|
1727545346.78125
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x00701000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2492
|
success
|
0 |
0
|
1727545346.78125
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x7ef20000
region_size:
327680
allocation_type:
1056768
(MEM_RESERVE|MEM_TOP_DOWN)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2492
|
success
|
0 |
0
|
1727545346.78125
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x7ef20000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2492
|
success
|
0 |
0
|