| Time & API |
Arguments |
Status |
Return |
Repeated |
1727110794.75025
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x6fc91000
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2284
|
success
|
0 |
0
|
1727110794.76625
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x003aa000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2284
|
success
|
0 |
0
|
1727110794.76625
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x6fc92000
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2284
|
success
|
0 |
0
|
1727110794.76625
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x003a2000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2284
|
success
|
0 |
0
|
1727110794.78125
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x003b2000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2284
|
success
|
0 |
0
|
1727110794.79725
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x003b3000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2284
|
success
|
0 |
0
|
1727110794.79725
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x003eb000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2284
|
success
|
0 |
0
|
1727110794.79725
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x003e7000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2284
|
success
|
0 |
0
|
1727110794.79725
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x003bc000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2284
|
success
|
0 |
0
|
1727110794.84425
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x005e0000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2284
|
success
|
0 |
0
|
1727110794.85925
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x003b4000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2284
|
success
|
0 |
0
|
1727110794.85925
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x003c6000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2284
|
success
|
0 |
0
|
1727110794.85925
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x003ba000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2284
|
success
|
0 |
0
|
1727110794.87525
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x003da000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2284
|
success
|
0 |
0
|
1727110794.87525
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x003d2000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2284
|
success
|
0 |
0
|
1727110794.87525
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x003e5000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2284
|
success
|
0 |
0
|
1727110794.92225
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x003ab000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2284
|
success
|
0 |
0
|
1727110794.92225
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x003ca000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2284
|
success
|
0 |
0
|
1727110794.92225
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x003c7000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2284
|
success
|
0 |
0
|
1727110795.67175
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x6f6e1000
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1428
|
success
|
0 |
0
|
1727110795.67175
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x0039a000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1428
|
success
|
0 |
0
|
1727110795.67175
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x6f6e2000
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1428
|
success
|
0 |
0
|
1727110795.67175
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x00392000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1428
|
success
|
0 |
0
|
1727110795.68775
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x003a2000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1428
|
success
|
0 |
0
|
1727110795.68775
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x003a3000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1428
|
success
|
0 |
0
|
1727110795.68775
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x003db000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1428
|
success
|
0 |
0
|
1727110795.68775
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x003d7000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1428
|
success
|
0 |
0
|
1727110795.68775
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x003ac000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1428
|
success
|
0 |
0
|
1727110795.70275
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x00b80000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1428
|
success
|
0 |
0
|
1727110795.70275
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x003ca000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1428
|
success
|
0 |
0
|
1727110795.70275
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x003c2000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1428
|
success
|
0 |
0
|
1727110795.71875
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x003a4000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1428
|
success
|
0 |
0
|
1727110795.71875
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x003d5000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1428
|
success
|
0 |
0
|
1727110795.73375
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x003a5000
region_size:
8192
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1428
|
success
|
0 |
0
|
1727110795.73375
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x003a7000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1428
|
success
|
0 |
0
|
1727110795.73375
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x003ba000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1428
|
success
|
0 |
0
|
1727110795.73375
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x003b7000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1428
|
success
|
0 |
0
|
1727110795.74975
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x0039b000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1428
|
success
|
0 |
0
|
1727110796.31275
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x01220000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1428
|
success
|
0 |
0
|
1727110796.31275
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x003b6000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1428
|
success
|
0 |
0
|
1727110800.32775
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x003aa000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1428
|
success
|
0 |
0
|
1727110800.34375
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x003a8000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1428
|
success
|
0 |
0
|
1727110800.35875
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x01221000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1428
|
success
|
0 |
0
|
1727110800.39075
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x00393000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1428
|
success
|
0 |
0
|
1727110800.39075
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x01222000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1428
|
success
|
0 |
0
|
1727110803.01575
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x003bb000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1428
|
success
|
0 |
0
|
1727110804.24975
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x01223000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1428
|
success
|
0 |
0
|
1727110804.73375
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x00b81000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1428
|
success
|
0 |
0
|
1727110804.73375
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x7ef20000
region_size:
327680
allocation_type:
1056768
(MEM_RESERVE|MEM_TOP_DOWN)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1428
|
success
|
0 |
0
|
1727110804.73375
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x7ef20000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1428
|
success
|
0 |
0
|