| Process injection |
Process 2236 manipulating memory of non-child process 2196 |
| Process injection |
Process 2236 manipulating memory of non-child process 300 |
| Process injection |
Process 2236 manipulating memory of non-child process 580 |
| Process injection |
Process 2236 manipulating memory of non-child process 284 |
| Process injection |
Process 2236 manipulating memory of non-child process 1272 |
| Process injection |
Process 2236 manipulating memory of non-child process 2852 |
| Process injection |
Process 2236 manipulating memory of non-child process 3040 |
| Process injection |
Process 2236 manipulating memory of non-child process 1880 |
| Process injection |
Process 2236 manipulating memory of non-child process 3100 |
| Process injection |
Process 2236 manipulating memory of non-child process 3136 |
| Process injection |
Process 2236 manipulating memory of non-child process 3172 |
| Process injection |
Process 2236 manipulating memory of non-child process 3208 |
| Process injection |
Process 2236 manipulating memory of non-child process 3244 |
| Process injection |
Process 2236 manipulating memory of non-child process 3280 |
| Process injection |
Process 2236 manipulating memory of non-child process 3316 |
| Process injection |
Process 2236 manipulating memory of non-child process 3352 |
| Process injection |
Process 2236 manipulating memory of non-child process 3388 |
| Process injection |
Process 2236 manipulating memory of non-child process 3424 |
| Process injection |
Process 2236 manipulating memory of non-child process 3460 |
| Process injection |
Process 2236 manipulating memory of non-child process 3496 |
| Process injection |
Process 2236 manipulating memory of non-child process 3532 |
| Process injection |
Process 2236 manipulating memory of non-child process 3568 |
| Process injection |
Process 2236 manipulating memory of non-child process 3604 |
| Process injection |
Process 2236 manipulating memory of non-child process 3640 |
| Process injection |
Process 2236 manipulating memory of non-child process 3676 |
| Time & API |
Arguments |
Status |
Return |
Repeated |
1619404698.013875
NtAllocateVirtualMemory
|
process_identifier:
2196
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x0000013c
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000a0000
|
success
|
0 |
0
|
1619404698.013875
NtAllocateVirtualMemory
|
process_identifier:
300
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x00000150
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000a0000
|
success
|
0 |
0
|
1619404698.044875
NtAllocateVirtualMemory
|
process_identifier:
580
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x0000015c
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000a0000
|
success
|
0 |
0
|
1619404698.044875
NtAllocateVirtualMemory
|
process_identifier:
284
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x00000168
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000a0000
|
success
|
0 |
0
|
1619404698.060875
NtAllocateVirtualMemory
|
process_identifier:
1272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x00000174
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000a0000
|
success
|
0 |
0
|
1619404698.075875
NtAllocateVirtualMemory
|
process_identifier:
2852
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x00000180
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000a0000
|
success
|
0 |
0
|
1619404698.091875
NtAllocateVirtualMemory
|
process_identifier:
3040
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x0000018c
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000a0000
|
success
|
0 |
0
|
1619404698.091875
NtAllocateVirtualMemory
|
process_identifier:
1880
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x00000198
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000a0000
|
success
|
0 |
0
|
1619404698.106875
NtAllocateVirtualMemory
|
process_identifier:
3100
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x000001a4
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000a0000
|
success
|
0 |
0
|
1619404698.138875
NtAllocateVirtualMemory
|
process_identifier:
3136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x000001b0
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000e0000
|
success
|
0 |
0
|
1619404698.153875
NtAllocateVirtualMemory
|
process_identifier:
3172
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x000001bc
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000a0000
|
success
|
0 |
0
|
1619404698.153875
NtAllocateVirtualMemory
|
process_identifier:
3208
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x000001c8
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000e0000
|
success
|
0 |
0
|
1619404698.169875
NtAllocateVirtualMemory
|
process_identifier:
3244
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x000001d4
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000a0000
|
success
|
0 |
0
|
1619404698.185875
NtAllocateVirtualMemory
|
process_identifier:
3280
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x000001e0
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000a0000
|
success
|
0 |
0
|
1619404698.200875
NtAllocateVirtualMemory
|
process_identifier:
3316
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x000001ec
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000a0000
|
success
|
0 |
0
|
1619404698.200875
NtAllocateVirtualMemory
|
process_identifier:
3352
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x000001f8
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000a0000
|
success
|
0 |
0
|
1619404698.216875
NtAllocateVirtualMemory
|
process_identifier:
3388
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x00000204
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000a0000
|
success
|
0 |
0
|
1619404698.231875
NtAllocateVirtualMemory
|
process_identifier:
3424
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x00000210
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000a0000
|
success
|
0 |
0
|
1619404698.247875
NtAllocateVirtualMemory
|
process_identifier:
3460
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x0000021c
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000a0000
|
success
|
0 |
0
|
1619404698.263875
NtAllocateVirtualMemory
|
process_identifier:
3496
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x00000228
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000a0000
|
success
|
0 |
0
|
1619404698.263875
NtAllocateVirtualMemory
|
process_identifier:
3532
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x00000234
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000a0000
|
success
|
0 |
0
|
1619404698.278875
NtAllocateVirtualMemory
|
process_identifier:
3568
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x00000240
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000e0000
|
success
|
0 |
0
|
1619404698.294875
NtAllocateVirtualMemory
|
process_identifier:
3604
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x0000024c
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000a0000
|
success
|
0 |
0
|
1619404698.310875
NtAllocateVirtualMemory
|
process_identifier:
3640
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x00000258
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000a0000
|
success
|
0 |
0
|
1619404698.325875
NtAllocateVirtualMemory
|
process_identifier:
3676
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x00000264
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000e0000
|
success
|
0 |
0
|