| Time & API |
Arguments |
Status |
Return |
Repeated |
1619345031.07685
NtAllocateVirtualMemory
|
process_identifier:
3060
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00360000
|
success
|
0 |
0
|
1619345031.26385
NtProtectVirtualMemory
|
process_identifier:
3060
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
40960
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00454000
|
success
|
0 |
0
|
1619345031.26385
NtAllocateVirtualMemory
|
process_identifier:
3060
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x02e20000
|
success
|
0 |
0
|
1619350314.242498
NtProtectVirtualMemory
|
process_identifier:
884
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00400000
|
success
|
0 |
0
|
1619350314.305498
NtAllocateVirtualMemory
|
process_identifier:
884
region_size:
1179648
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x006c0000
|
success
|
0 |
0
|
1619350314.305498
NtAllocateVirtualMemory
|
process_identifier:
884
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x007a0000
|
success
|
0 |
0
|
1619350314.305498
NtAllocateVirtualMemory
|
process_identifier:
884
region_size:
335872
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00510000
|
success
|
0 |
0
|
1619350314.320498
NtProtectVirtualMemory
|
process_identifier:
884
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
307200
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00512000
|
success
|
0 |
0
|
1619350314.977498
NtProtectVirtualMemory
|
process_identifier:
884
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00592000
|
success
|
0 |
0
|
1619350314.977498
NtProtectVirtualMemory
|
process_identifier:
884
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76351000
|
success
|
0 |
0
|
1619350314.977498
NtProtectVirtualMemory
|
process_identifier:
884
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00592000
|
success
|
0 |
0
|
1619350314.977498
NtProtectVirtualMemory
|
process_identifier:
884
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76353000
|
success
|
0 |
0
|
1619350314.977498
NtProtectVirtualMemory
|
process_identifier:
884
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00592000
|
success
|
0 |
0
|
1619350314.977498
NtProtectVirtualMemory
|
process_identifier:
884
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76354000
|
success
|
0 |
0
|
1619350314.977498
NtProtectVirtualMemory
|
process_identifier:
884
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00592000
|
success
|
0 |
0
|
1619350314.977498
NtProtectVirtualMemory
|
process_identifier:
884
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76351000
|
success
|
0 |
0
|
1619350314.977498
NtProtectVirtualMemory
|
process_identifier:
884
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00592000
|
success
|
0 |
0
|
1619350314.977498
NtProtectVirtualMemory
|
process_identifier:
884
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x77d4f000
|
success
|
0 |
0
|
1619350314.977498
NtProtectVirtualMemory
|
process_identifier:
884
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00592000
|
success
|
0 |
0
|
1619350314.977498
NtProtectVirtualMemory
|
process_identifier:
884
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76353000
|
success
|
0 |
0
|
1619350314.977498
NtProtectVirtualMemory
|
process_identifier:
884
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00592000
|
success
|
0 |
0
|
1619350314.977498
NtProtectVirtualMemory
|
process_identifier:
884
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76351000
|
success
|
0 |
0
|
1619350314.977498
NtProtectVirtualMemory
|
process_identifier:
884
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00592000
|
success
|
0 |
0
|
1619350314.977498
NtProtectVirtualMemory
|
process_identifier:
884
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76351000
|
success
|
0 |
0
|
1619350314.977498
NtProtectVirtualMemory
|
process_identifier:
884
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00592000
|
success
|
0 |
0
|
1619350314.977498
NtProtectVirtualMemory
|
process_identifier:
884
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76354000
|
success
|
0 |
0
|
1619350314.977498
NtProtectVirtualMemory
|
process_identifier:
884
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00592000
|
success
|
0 |
0
|
1619350314.977498
NtProtectVirtualMemory
|
process_identifier:
884
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76351000
|
success
|
0 |
0
|
1619350314.320375
NtAllocateVirtualMemory
|
process_identifier:
2860
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003e0000
|
success
|
0 |
0
|
1619350314.383375
NtProtectVirtualMemory
|
process_identifier:
2860
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
40960
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00454000
|
success
|
0 |
0
|
1619350314.399375
NtAllocateVirtualMemory
|
process_identifier:
2860
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x01e80000
|
success
|
0 |
0
|
1619350320.28975
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003e0000
|
success
|
0 |
0
|
1619350320.43075
NtProtectVirtualMemory
|
process_identifier:
2764
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
40960
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00454000
|
success
|
0 |
0
|
1619350320.44575
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x01f70000
|
success
|
0 |
0
|
1619350322.75825
NtProtectVirtualMemory
|
process_identifier:
2196
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00400000
|
success
|
0 |
0
|
1619350322.78925
NtAllocateVirtualMemory
|
process_identifier:
2196
region_size:
917504
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x01e30000
|
success
|
0 |
0
|
1619350322.78925
NtAllocateVirtualMemory
|
process_identifier:
2196
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x01ed0000
|
success
|
0 |
0
|
1619350322.78925
NtAllocateVirtualMemory
|
process_identifier:
2196
region_size:
335872
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00560000
|
success
|
0 |
0
|
1619350322.78925
NtProtectVirtualMemory
|
process_identifier:
2196
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
307200
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00562000
|
success
|
0 |
0
|
1619350322.96125
NtProtectVirtualMemory
|
process_identifier:
2196
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x003d2000
|
success
|
0 |
0
|
1619350322.96125
NtProtectVirtualMemory
|
process_identifier:
2196
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76351000
|
success
|
0 |
0
|
1619350322.96125
NtProtectVirtualMemory
|
process_identifier:
2196
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x003d2000
|
success
|
0 |
0
|
1619350322.96125
NtProtectVirtualMemory
|
process_identifier:
2196
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76353000
|
success
|
0 |
0
|
1619350322.96125
NtProtectVirtualMemory
|
process_identifier:
2196
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x003d2000
|
success
|
0 |
0
|
1619350322.96125
NtProtectVirtualMemory
|
process_identifier:
2196
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76354000
|
success
|
0 |
0
|
1619350322.96125
NtProtectVirtualMemory
|
process_identifier:
2196
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x003d2000
|
success
|
0 |
0
|
1619350322.96125
NtProtectVirtualMemory
|
process_identifier:
2196
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76351000
|
success
|
0 |
0
|
1619350322.96125
NtProtectVirtualMemory
|
process_identifier:
2196
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x003d2000
|
success
|
0 |
0
|
1619350322.96125
NtProtectVirtualMemory
|
process_identifier:
2196
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x77d4f000
|
success
|
0 |
0
|
1619350322.96125
NtProtectVirtualMemory
|
process_identifier:
2196
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x003d2000
|
success
|
0 |
0
|