| Time & API |
Arguments |
Status |
Return |
Repeated |
1619345033.91311
NtAllocateVirtualMemory
|
process_identifier:
2292
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003f0000
|
success
|
0 |
0
|
1619345034.03811
NtProtectVirtualMemory
|
process_identifier:
2292
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
73728
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00476000
|
success
|
0 |
0
|
1619345034.03811
NtAllocateVirtualMemory
|
process_identifier:
2292
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x01f80000
|
success
|
0 |
0
|
1619361323.017875
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005e0000
|
success
|
0 |
0
|
1619361323.048875
NtProtectVirtualMemory
|
process_identifier:
2104
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
73728
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00476000
|
success
|
0 |
0
|
1619361323.048875
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00620000
|
success
|
0 |
0
|
1619361324.22125
NtProtectVirtualMemory
|
process_identifier:
1068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00400000
|
success
|
0 |
0
|
1619361324.28425
NtAllocateVirtualMemory
|
process_identifier:
1068
region_size:
2228224
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x020b0000
|
success
|
0 |
0
|
1619361324.28425
NtAllocateVirtualMemory
|
process_identifier:
1068
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02290000
|
success
|
0 |
0
|
1619361324.28425
NtAllocateVirtualMemory
|
process_identifier:
1068
region_size:
630784
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x01ff0000
|
success
|
0 |
0
|
1619361324.28425
NtProtectVirtualMemory
|
process_identifier:
1068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
602112
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01ff2000
|
success
|
0 |
0
|
1619361324.98725
NtProtectVirtualMemory
|
process_identifier:
1068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00372000
|
success
|
0 |
0
|
1619361324.98725
NtProtectVirtualMemory
|
process_identifier:
1068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76351000
|
success
|
0 |
0
|
1619361324.98725
NtProtectVirtualMemory
|
process_identifier:
1068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00372000
|
success
|
0 |
0
|
1619361324.98725
NtProtectVirtualMemory
|
process_identifier:
1068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76353000
|
success
|
0 |
0
|
1619361324.98725
NtProtectVirtualMemory
|
process_identifier:
1068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00372000
|
success
|
0 |
0
|
1619361324.98725
NtProtectVirtualMemory
|
process_identifier:
1068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76354000
|
success
|
0 |
0
|
1619361324.98725
NtProtectVirtualMemory
|
process_identifier:
1068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00372000
|
success
|
0 |
0
|
1619361324.98725
NtProtectVirtualMemory
|
process_identifier:
1068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76351000
|
success
|
0 |
0
|
1619361325.00225
NtProtectVirtualMemory
|
process_identifier:
1068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00372000
|
success
|
0 |
0
|
1619361325.00225
NtProtectVirtualMemory
|
process_identifier:
1068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x77d4f000
|
success
|
0 |
0
|
1619361325.00225
NtProtectVirtualMemory
|
process_identifier:
1068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00372000
|
success
|
0 |
0
|
1619361325.00225
NtProtectVirtualMemory
|
process_identifier:
1068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76353000
|
success
|
0 |
0
|
1619361325.00225
NtProtectVirtualMemory
|
process_identifier:
1068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00372000
|
success
|
0 |
0
|
1619361325.00225
NtProtectVirtualMemory
|
process_identifier:
1068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76351000
|
success
|
0 |
0
|
1619361325.00225
NtProtectVirtualMemory
|
process_identifier:
1068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00372000
|
success
|
0 |
0
|
1619361325.00225
NtProtectVirtualMemory
|
process_identifier:
1068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76351000
|
success
|
0 |
0
|
1619361325.00225
NtProtectVirtualMemory
|
process_identifier:
1068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00372000
|
success
|
0 |
0
|
1619361325.00225
NtProtectVirtualMemory
|
process_identifier:
1068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76354000
|
success
|
0 |
0
|
1619361325.00225
NtProtectVirtualMemory
|
process_identifier:
1068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00372000
|
success
|
0 |
0
|
1619361325.00225
NtProtectVirtualMemory
|
process_identifier:
1068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76351000
|
success
|
0 |
0
|
1619361324.5015
NtAllocateVirtualMemory
|
process_identifier:
3136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00800000
|
success
|
0 |
0
|
1619361324.5335
NtProtectVirtualMemory
|
process_identifier:
3136
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
73728
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00476000
|
success
|
0 |
0
|
1619361324.5335
NtAllocateVirtualMemory
|
process_identifier:
3136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00840000
|
success
|
0 |
0
|
1619361331.11175
NtAllocateVirtualMemory
|
process_identifier:
3268
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003f0000
|
success
|
0 |
0
|
1619361331.48675
NtProtectVirtualMemory
|
process_identifier:
3268
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
73728
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00476000
|
success
|
0 |
0
|
1619361331.48675
NtAllocateVirtualMemory
|
process_identifier:
3268
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x01ea0000
|
success
|
0 |
0
|
1619361332.704502
NtProtectVirtualMemory
|
process_identifier:
3336
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00400000
|
success
|
0 |
0
|
1619361332.736502
NtAllocateVirtualMemory
|
process_identifier:
3336
region_size:
1703936
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x01f70000
|
success
|
0 |
0
|
1619361332.736502
NtAllocateVirtualMemory
|
process_identifier:
3336
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x020d0000
|
success
|
0 |
0
|
1619361332.736502
NtAllocateVirtualMemory
|
process_identifier:
3336
region_size:
630784
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x01f70000
|
success
|
0 |
0
|
1619361332.736502
NtProtectVirtualMemory
|
process_identifier:
3336
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
602112
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01f72000
|
success
|
0 |
0
|
1619361332.814502
NtProtectVirtualMemory
|
process_identifier:
3336
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01f62000
|
success
|
0 |
0
|
1619361332.814502
NtProtectVirtualMemory
|
process_identifier:
3336
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76351000
|
success
|
0 |
0
|
1619361332.814502
NtProtectVirtualMemory
|
process_identifier:
3336
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01f62000
|
success
|
0 |
0
|
1619361332.814502
NtProtectVirtualMemory
|
process_identifier:
3336
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76353000
|
success
|
0 |
0
|
1619361332.814502
NtProtectVirtualMemory
|
process_identifier:
3336
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01f62000
|
success
|
0 |
0
|
1619361332.814502
NtProtectVirtualMemory
|
process_identifier:
3336
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76354000
|
success
|
0 |
0
|
1619361332.814502
NtProtectVirtualMemory
|
process_identifier:
3336
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01f62000
|
success
|
0 |
0
|
1619361332.814502
NtProtectVirtualMemory
|
process_identifier:
3336
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76351000
|
success
|
0 |
0
|