| Time & API |
Arguments |
Status |
Return |
Repeated |
1620755174.151625
NtAllocateVirtualMemory
|
process_identifier:
2436
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x01e20000
|
success
|
0 |
0
|
1620755188.729625
NtAllocateVirtualMemory
|
process_identifier:
2436
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x01e50000
|
success
|
0 |
0
|
1620755188.729625
NtAllocateVirtualMemory
|
process_identifier:
2436
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x01e70000
|
success
|
0 |
0
|
1620755189.995374
NtAllocateVirtualMemory
|
process_identifier:
2344
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00360000
|
success
|
0 |
0
|
1620755203.917374
NtAllocateVirtualMemory
|
process_identifier:
2344
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00390000
|
success
|
0 |
0
|
1620755203.917374
NtAllocateVirtualMemory
|
process_identifier:
2344
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x003b0000
|
success
|
0 |
0
|
1620755205.66775
NtProtectVirtualMemory
|
process_identifier:
1752
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00400000
|
success
|
0 |
0
|
1620755205.91775
NtAllocateVirtualMemory
|
process_identifier:
1752
region_size:
2228224
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x01fe0000
|
success
|
0 |
0
|
1620755205.91775
NtAllocateVirtualMemory
|
process_identifier:
1752
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x021c0000
|
success
|
0 |
0
|
1620755205.93275
NtAllocateVirtualMemory
|
process_identifier:
1752
region_size:
589824
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x01e50000
|
success
|
0 |
0
|
1620755205.93275
NtProtectVirtualMemory
|
process_identifier:
1752
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
565248
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01e52000
|
success
|
0 |
0
|
1620755207.13675
NtAllocateVirtualMemory
|
process_identifier:
1752
region_size:
327680
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x01f30000
|
success
|
0 |
0
|
1620755207.13675
NtAllocateVirtualMemory
|
process_identifier:
1752
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x01f40000
|
success
|
0 |
0
|
1620755209.05775
NtProtectVirtualMemory
|
process_identifier:
1752
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x005e2000
|
success
|
0 |
0
|
1620755209.05775
NtProtectVirtualMemory
|
process_identifier:
1752
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76351000
|
success
|
0 |
0
|
1620755209.05775
NtProtectVirtualMemory
|
process_identifier:
1752
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x005e2000
|
success
|
0 |
0
|
1620755209.05775
NtProtectVirtualMemory
|
process_identifier:
1752
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76353000
|
success
|
0 |
0
|
1620755209.05775
NtProtectVirtualMemory
|
process_identifier:
1752
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x005e2000
|
success
|
0 |
0
|
1620755209.07375
NtProtectVirtualMemory
|
process_identifier:
1752
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76354000
|
success
|
0 |
0
|
1620755209.07375
NtProtectVirtualMemory
|
process_identifier:
1752
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x005e2000
|
success
|
0 |
0
|
1620755209.07375
NtProtectVirtualMemory
|
process_identifier:
1752
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76351000
|
success
|
0 |
0
|
1620755209.07375
NtProtectVirtualMemory
|
process_identifier:
1752
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x005e2000
|
success
|
0 |
0
|
1620755209.07375
NtProtectVirtualMemory
|
process_identifier:
1752
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x77d4f000
|
success
|
0 |
0
|
1620755209.07375
NtProtectVirtualMemory
|
process_identifier:
1752
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x005e2000
|
success
|
0 |
0
|
1620755209.07375
NtProtectVirtualMemory
|
process_identifier:
1752
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76353000
|
success
|
0 |
0
|
1620755209.07375
NtProtectVirtualMemory
|
process_identifier:
1752
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x005e2000
|
success
|
0 |
0
|
1620755209.07375
NtProtectVirtualMemory
|
process_identifier:
1752
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76351000
|
success
|
0 |
0
|
1620755209.07375
NtProtectVirtualMemory
|
process_identifier:
1752
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x005e2000
|
success
|
0 |
0
|
1620755209.07375
NtProtectVirtualMemory
|
process_identifier:
1752
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76351000
|
success
|
0 |
0
|
1620755209.07375
NtProtectVirtualMemory
|
process_identifier:
1752
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x005e2000
|
success
|
0 |
0
|
1620755209.07375
NtProtectVirtualMemory
|
process_identifier:
1752
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76354000
|
success
|
0 |
0
|
1620755209.07375
NtProtectVirtualMemory
|
process_identifier:
1752
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x005e2000
|
success
|
0 |
0
|
1620755209.07375
NtProtectVirtualMemory
|
process_identifier:
1752
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76351000
|
success
|
0 |
0
|