| Time & API |
Arguments |
Status |
Return |
Repeated |
1619464046.85975
NtAllocateVirtualMemory
|
process_identifier:
2996
region_size:
1376256
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x007b0000
|
success
|
0 |
0
|
1619464046.85975
NtAllocateVirtualMemory
|
process_identifier:
2996
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x008c0000
|
success
|
0 |
0
|
1619464047.82875
NtProtectVirtualMemory
|
process_identifier:
2996
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73c51000
|
success
|
0 |
0
|
1619464048.15675
NtAllocateVirtualMemory
|
process_identifier:
2996
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0043a000
|
success
|
0 |
0
|
1619464048.15675
NtProtectVirtualMemory
|
process_identifier:
2996
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73c52000
|
success
|
0 |
0
|
1619464048.15675
NtAllocateVirtualMemory
|
process_identifier:
2996
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00432000
|
success
|
0 |
0
|
1619464048.48475
NtAllocateVirtualMemory
|
process_identifier:
2996
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00442000
|
success
|
0 |
0
|
1619464048.54675
NtAllocateVirtualMemory
|
process_identifier:
2996
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00443000
|
success
|
0 |
0
|
1619464048.56275
NtAllocateVirtualMemory
|
process_identifier:
2996
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0047b000
|
success
|
0 |
0
|
1619464048.56275
NtAllocateVirtualMemory
|
process_identifier:
2996
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00477000
|
success
|
0 |
0
|
1619464048.59375
NtAllocateVirtualMemory
|
process_identifier:
2996
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0044c000
|
success
|
0 |
0
|
1619464048.62475
NtAllocateVirtualMemory
|
process_identifier:
2996
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00750000
|
success
|
0 |
0
|
1619464048.95375
NtAllocateVirtualMemory
|
process_identifier:
2996
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00444000
|
success
|
0 |
0
|
1619464048.96875
NtAllocateVirtualMemory
|
process_identifier:
2996
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00751000
|
success
|
0 |
0
|
1619464048.96875
NtAllocateVirtualMemory
|
process_identifier:
2996
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0044a000
|
success
|
0 |
0
|
1619464049.01575
NtProtectVirtualMemory
|
process_identifier:
2996
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
491520
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00db2000
|
success
|
0 |
0
|
1619464057.82875
NtAllocateVirtualMemory
|
process_identifier:
2996
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00752000
|
success
|
0 |
0
|
1619464057.85975
NtAllocateVirtualMemory
|
process_identifier:
2996
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00753000
|
success
|
0 |
0
|
1619464057.85975
NtAllocateVirtualMemory
|
process_identifier:
2996
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00754000
|
success
|
0 |
0
|
1619464057.95375
NtAllocateVirtualMemory
|
process_identifier:
2996
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00755000
|
success
|
0 |
0
|
1619464058.18775
NtAllocateVirtualMemory
|
process_identifier:
2996
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00445000
|
success
|
0 |
0
|
1619464058.18775
NtAllocateVirtualMemory
|
process_identifier:
2996
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00756000
|
success
|
0 |
0
|
1619464058.21875
NtAllocateVirtualMemory
|
process_identifier:
2996
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00757000
|
success
|
0 |
0
|
1619464058.21875
NtAllocateVirtualMemory
|
process_identifier:
2996
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00759000
|
success
|
0 |
0
|
1619464058.21875
NtProtectVirtualMemory
|
process_identifier:
2996
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00e2a000
|
success
|
0 |
0
|
1619464058.21875
NtProtectVirtualMemory
|
process_identifier:
2996
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00e2a000
|
success
|
0 |
0
|
1619464058.21875
NtProtectVirtualMemory
|
process_identifier:
2996
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00db0000
|
success
|
0 |
0
|
1619464058.21875
NtProtectVirtualMemory
|
process_identifier:
2996
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00db0000
|
success
|
0 |
0
|
1619464058.21875
NtProtectVirtualMemory
|
process_identifier:
2996
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00db0000
|
success
|
0 |
0
|
1619464058.21875
NtProtectVirtualMemory
|
process_identifier:
2996
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00db0000
|
success
|
0 |
0
|
1619464058.21875
NtProtectVirtualMemory
|
process_identifier:
2996
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00db0000
|
success
|
0 |
0
|
1619464058.21875
NtProtectVirtualMemory
|
process_identifier:
2996
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00e2a000
|
success
|
0 |
0
|
1619464058.21875
NtProtectVirtualMemory
|
process_identifier:
2996
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00e2a000
|
success
|
0 |
0
|
1619464058.21875
NtProtectVirtualMemory
|
process_identifier:
2996
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00e2a000
|
success
|
0 |
0
|
1619464058.21875
NtProtectVirtualMemory
|
process_identifier:
2996
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00e2a000
|
success
|
0 |
0
|
1619464058.21875
NtProtectVirtualMemory
|
process_identifier:
2996
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00e2a000
|
success
|
0 |
0
|
1619464058.21875
NtProtectVirtualMemory
|
process_identifier:
2996
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00e2a000
|
success
|
0 |
0
|
1619464058.21875
NtProtectVirtualMemory
|
process_identifier:
2996
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00e2a000
|
success
|
0 |
0
|
1619464058.21875
NtProtectVirtualMemory
|
process_identifier:
2996
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00e2a000
|
success
|
0 |
0
|
1619464058.21875
NtProtectVirtualMemory
|
process_identifier:
2996
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00e2a000
|
success
|
0 |
0
|
1619464058.21875
NtProtectVirtualMemory
|
process_identifier:
2996
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00e2a000
|
success
|
0 |
0
|
1619464058.21875
NtProtectVirtualMemory
|
process_identifier:
2996
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00e2a000
|
success
|
0 |
0
|
1619464058.21875
NtProtectVirtualMemory
|
process_identifier:
2996
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00e2a000
|
success
|
0 |
0
|
1619464058.21875
NtProtectVirtualMemory
|
process_identifier:
2996
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00e2a000
|
success
|
0 |
0
|
1619464058.21875
NtProtectVirtualMemory
|
process_identifier:
2996
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00e2a000
|
success
|
0 |
0
|
1619464058.21875
NtProtectVirtualMemory
|
process_identifier:
2996
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00e2a000
|
success
|
0 |
0
|
1619464058.21875
NtProtectVirtualMemory
|
process_identifier:
2996
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00e2a000
|
success
|
0 |
0
|
1619464058.21875
NtProtectVirtualMemory
|
process_identifier:
2996
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00e2a000
|
success
|
0 |
0
|
1619464058.21875
NtProtectVirtualMemory
|
process_identifier:
2996
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00e2a000
|
success
|
0 |
0
|
1619464058.21875
NtProtectVirtualMemory
|
process_identifier:
2996
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00e2a000
|
success
|
0 |
0
|