| Time & API |
Arguments |
Status |
Return |
Repeated |
1619345031.637857
NtAllocateVirtualMemory
|
process_identifier:
2308
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00360000
|
success
|
0 |
0
|
1619345031.809857
NtProtectVirtualMemory
|
process_identifier:
2308
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
28672
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00495000
|
success
|
0 |
0
|
1619345031.825857
NtAllocateVirtualMemory
|
process_identifier:
2308
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x006b0000
|
success
|
0 |
0
|
1619353254.162874
NtProtectVirtualMemory
|
process_identifier:
1464
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00400000
|
success
|
0 |
0
|
1619353254.193874
NtAllocateVirtualMemory
|
process_identifier:
1464
region_size:
1835008
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x01fb0000
|
success
|
0 |
0
|
1619353254.193874
NtAllocateVirtualMemory
|
process_identifier:
1464
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02130000
|
success
|
0 |
0
|
1619353254.193874
NtAllocateVirtualMemory
|
process_identifier:
1464
region_size:
311296
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00510000
|
success
|
0 |
0
|
1619353254.193874
NtProtectVirtualMemory
|
process_identifier:
1464
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
282624
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00512000
|
success
|
0 |
0
|
1619353254.506874
NtAllocateVirtualMemory
|
process_identifier:
1464
region_size:
2228224
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x02170000
|
success
|
0 |
0
|
1619353254.506874
NtAllocateVirtualMemory
|
process_identifier:
1464
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02350000
|
success
|
0 |
0
|
1619353254.959874
NtProtectVirtualMemory
|
process_identifier:
1464
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01fa2000
|
success
|
0 |
0
|
1619353254.959874
NtProtectVirtualMemory
|
process_identifier:
1464
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76351000
|
success
|
0 |
0
|
1619353254.959874
NtProtectVirtualMemory
|
process_identifier:
1464
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01fa2000
|
success
|
0 |
0
|
1619353254.959874
NtProtectVirtualMemory
|
process_identifier:
1464
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76353000
|
success
|
0 |
0
|
1619353254.959874
NtProtectVirtualMemory
|
process_identifier:
1464
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01fa2000
|
success
|
0 |
0
|
1619353254.959874
NtProtectVirtualMemory
|
process_identifier:
1464
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76354000
|
success
|
0 |
0
|
1619353254.959874
NtProtectVirtualMemory
|
process_identifier:
1464
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01fa2000
|
success
|
0 |
0
|
1619353254.959874
NtProtectVirtualMemory
|
process_identifier:
1464
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76351000
|
success
|
0 |
0
|
1619353254.959874
NtProtectVirtualMemory
|
process_identifier:
1464
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01fa2000
|
success
|
0 |
0
|
1619353254.959874
NtProtectVirtualMemory
|
process_identifier:
1464
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x77d4f000
|
success
|
0 |
0
|
1619353254.959874
NtProtectVirtualMemory
|
process_identifier:
1464
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01fa2000
|
success
|
0 |
0
|
1619353254.959874
NtProtectVirtualMemory
|
process_identifier:
1464
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76353000
|
success
|
0 |
0
|
1619353254.959874
NtProtectVirtualMemory
|
process_identifier:
1464
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01fa2000
|
success
|
0 |
0
|
1619353254.959874
NtProtectVirtualMemory
|
process_identifier:
1464
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76351000
|
success
|
0 |
0
|
1619353254.974874
NtProtectVirtualMemory
|
process_identifier:
1464
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01fa2000
|
success
|
0 |
0
|
1619353254.974874
NtProtectVirtualMemory
|
process_identifier:
1464
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76351000
|
success
|
0 |
0
|
1619353254.974874
NtProtectVirtualMemory
|
process_identifier:
1464
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01fa2000
|
success
|
0 |
0
|
1619353254.974874
NtProtectVirtualMemory
|
process_identifier:
1464
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76354000
|
success
|
0 |
0
|
1619353254.974874
NtProtectVirtualMemory
|
process_identifier:
1464
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01fa2000
|
success
|
0 |
0
|
1619353254.974874
NtProtectVirtualMemory
|
process_identifier:
1464
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76351000
|
success
|
0 |
0
|