| Time & API |
Arguments |
Status |
Return |
Repeated |
1619360977.078001
NtAllocateVirtualMemory
|
process_identifier:
392
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003d0000
|
success
|
0 |
0
|
1619360977.156001
NtProtectVirtualMemory
|
process_identifier:
392
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
77824
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00472000
|
success
|
0 |
0
|
1619360977.156001
NtAllocateVirtualMemory
|
process_identifier:
392
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00520000
|
success
|
0 |
0
|
1619360978.610249
NtProtectVirtualMemory
|
process_identifier:
2616
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00400000
|
success
|
0 |
0
|
1619360978.656249
NtAllocateVirtualMemory
|
process_identifier:
2616
region_size:
983040
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x01dd0000
|
success
|
0 |
0
|
1619360978.656249
NtAllocateVirtualMemory
|
process_identifier:
2616
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x01e80000
|
success
|
0 |
0
|
1619360978.656249
NtAllocateVirtualMemory
|
process_identifier:
2616
region_size:
368640
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x01dd0000
|
success
|
0 |
0
|
1619360978.656249
NtProtectVirtualMemory
|
process_identifier:
2616
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
339968
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01dd2000
|
success
|
0 |
0
|
1619360979.141249
NtAllocateVirtualMemory
|
process_identifier:
2616
region_size:
1703936
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x02150000
|
success
|
0 |
0
|
1619360979.141249
NtAllocateVirtualMemory
|
process_identifier:
2616
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x022b0000
|
success
|
0 |
0
|
1619360980.110249
NtProtectVirtualMemory
|
process_identifier:
2616
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01fb2000
|
success
|
0 |
0
|
1619360980.110249
NtProtectVirtualMemory
|
process_identifier:
2616
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76351000
|
success
|
0 |
0
|
1619360980.110249
NtProtectVirtualMemory
|
process_identifier:
2616
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01fb2000
|
success
|
0 |
0
|
1619360980.125249
NtProtectVirtualMemory
|
process_identifier:
2616
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76353000
|
success
|
0 |
0
|
1619360980.125249
NtProtectVirtualMemory
|
process_identifier:
2616
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01fb2000
|
success
|
0 |
0
|
1619360980.125249
NtProtectVirtualMemory
|
process_identifier:
2616
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76354000
|
success
|
0 |
0
|
1619360980.125249
NtProtectVirtualMemory
|
process_identifier:
2616
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01fb2000
|
success
|
0 |
0
|
1619360980.125249
NtProtectVirtualMemory
|
process_identifier:
2616
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76351000
|
success
|
0 |
0
|
1619360980.125249
NtProtectVirtualMemory
|
process_identifier:
2616
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01fb2000
|
success
|
0 |
0
|
1619360980.125249
NtProtectVirtualMemory
|
process_identifier:
2616
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x77d4f000
|
success
|
0 |
0
|
1619360980.125249
NtProtectVirtualMemory
|
process_identifier:
2616
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01fb2000
|
success
|
0 |
0
|
1619360980.125249
NtProtectVirtualMemory
|
process_identifier:
2616
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76353000
|
success
|
0 |
0
|
1619360980.125249
NtProtectVirtualMemory
|
process_identifier:
2616
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01fb2000
|
success
|
0 |
0
|
1619360980.125249
NtProtectVirtualMemory
|
process_identifier:
2616
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76351000
|
success
|
0 |
0
|
1619360980.125249
NtProtectVirtualMemory
|
process_identifier:
2616
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01fb2000
|
success
|
0 |
0
|
1619360980.125249
NtProtectVirtualMemory
|
process_identifier:
2616
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76351000
|
success
|
0 |
0
|
1619360980.125249
NtProtectVirtualMemory
|
process_identifier:
2616
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01fb2000
|
success
|
0 |
0
|
1619360980.125249
NtProtectVirtualMemory
|
process_identifier:
2616
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76354000
|
success
|
0 |
0
|
1619360980.125249
NtProtectVirtualMemory
|
process_identifier:
2616
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01fb2000
|
success
|
0 |
0
|
1619360980.125249
NtProtectVirtualMemory
|
process_identifier:
2616
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76351000
|
success
|
0 |
0
|
1619360979.016499
NtAllocateVirtualMemory
|
process_identifier:
428
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003d0000
|
success
|
0 |
0
|
1619360979.078499
NtProtectVirtualMemory
|
process_identifier:
428
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
77824
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00472000
|
success
|
0 |
0
|
1619360979.078499
NtAllocateVirtualMemory
|
process_identifier:
428
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00800000
|
success
|
0 |
0
|
1619360989.656249
NtAllocateVirtualMemory
|
process_identifier:
3124
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x01f40000
|
success
|
0 |
0
|
1619360990.047249
NtProtectVirtualMemory
|
process_identifier:
3124
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
77824
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00472000
|
success
|
0 |
0
|
1619360990.063249
NtAllocateVirtualMemory
|
process_identifier:
3124
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x02cf0000
|
success
|
0 |
0
|
1619360992.031876
NtProtectVirtualMemory
|
process_identifier:
3192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00400000
|
success
|
0 |
0
|
1619360992.047876
NtAllocateVirtualMemory
|
process_identifier:
3192
region_size:
589824
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x01e50000
|
success
|
0 |
0
|
1619360992.047876
NtAllocateVirtualMemory
|
process_identifier:
3192
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x01ea0000
|
success
|
0 |
0
|
1619360992.047876
NtAllocateVirtualMemory
|
process_identifier:
3192
region_size:
368640
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x01ee0000
|
success
|
0 |
0
|
1619360992.047876
NtProtectVirtualMemory
|
process_identifier:
3192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
339968
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01ee2000
|
success
|
0 |
0
|
1619360992.078876
NtAllocateVirtualMemory
|
process_identifier:
3192
region_size:
2162688
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x02110000
|
success
|
0 |
0
|
1619360992.078876
NtAllocateVirtualMemory
|
process_identifier:
3192
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x022e0000
|
success
|
0 |
0
|
1619360992.281876
NtProtectVirtualMemory
|
process_identifier:
3192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00532000
|
success
|
0 |
0
|
1619360992.281876
NtProtectVirtualMemory
|
process_identifier:
3192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76351000
|
success
|
0 |
0
|
1619360992.281876
NtProtectVirtualMemory
|
process_identifier:
3192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00532000
|
success
|
0 |
0
|
1619360992.281876
NtProtectVirtualMemory
|
process_identifier:
3192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76353000
|
success
|
0 |
0
|
1619360992.281876
NtProtectVirtualMemory
|
process_identifier:
3192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00532000
|
success
|
0 |
0
|
1619360992.281876
NtProtectVirtualMemory
|
process_identifier:
3192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76354000
|
success
|
0 |
0
|
1619360992.281876
NtProtectVirtualMemory
|
process_identifier:
3192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00532000
|
success
|
0 |
0
|