| Time & API |
Arguments |
Status |
Return |
Repeated |
1619426981.613755
NtAllocateVirtualMemory
|
process_identifier:
1068
region_size:
176128
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x0000000001f80000
|
success
|
0 |
0
|
1619426981.738755
NtProtectVirtualMemory
|
process_identifier:
1068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feff1e6000
|
success
|
0 |
0
|
1619426981.738755
NtProtectVirtualMemory
|
process_identifier:
1068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feff1e7000
|
success
|
0 |
0
|
1619426981.769755
NtProtectVirtualMemory
|
process_identifier:
1068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feff183000
|
success
|
0 |
0
|
1619426981.769755
NtProtectVirtualMemory
|
process_identifier:
1068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feff183000
|
success
|
0 |
0
|
1619426981.769755
NtProtectVirtualMemory
|
process_identifier:
1068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feff165000
|
success
|
0 |
0
|
1619426981.769755
NtProtectVirtualMemory
|
process_identifier:
1068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feff1cf000
|
success
|
0 |
0
|
1619426981.769755
NtProtectVirtualMemory
|
process_identifier:
1068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feff173000
|
success
|
0 |
0
|
1619426981.769755
NtProtectVirtualMemory
|
process_identifier:
1068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feff165000
|
success
|
0 |
0
|
1619426981.769755
NtProtectVirtualMemory
|
process_identifier:
1068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feff183000
|
success
|
0 |
0
|
1619426981.769755
NtProtectVirtualMemory
|
process_identifier:
1068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feff183000
|
success
|
0 |
0
|
1619426981.769755
NtProtectVirtualMemory
|
process_identifier:
1068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feff1b0000
|
success
|
0 |
0
|
1619426981.769755
NtProtectVirtualMemory
|
process_identifier:
1068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feff15c000
|
success
|
0 |
0
|
1619426981.769755
NtProtectVirtualMemory
|
process_identifier:
1068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feff15f000
|
success
|
0 |
0
|
1619426981.769755
NtProtectVirtualMemory
|
process_identifier:
1068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feff1aa000
|
success
|
0 |
0
|
1619426981.769755
NtProtectVirtualMemory
|
process_identifier:
1068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feff15f000
|
success
|
0 |
0
|
1619426981.785755
NtProtectVirtualMemory
|
process_identifier:
1068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feff169000
|
success
|
0 |
0
|
1619426981.785755
NtProtectVirtualMemory
|
process_identifier:
1068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feff16b000
|
success
|
0 |
0
|
1619426981.785755
NtProtectVirtualMemory
|
process_identifier:
1068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feff1b2000
|
success
|
0 |
0
|
1619426981.785755
NtProtectVirtualMemory
|
process_identifier:
1068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feff181000
|
success
|
0 |
0
|
1619426981.785755
NtProtectVirtualMemory
|
process_identifier:
1068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feff15e000
|
success
|
0 |
0
|
1619426981.785755
NtProtectVirtualMemory
|
process_identifier:
1068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feff163000
|
success
|
0 |
0
|
1619426981.785755
NtProtectVirtualMemory
|
process_identifier:
1068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feff15f000
|
success
|
0 |
0
|
1619426981.785755
NtProtectVirtualMemory
|
process_identifier:
1068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feff182000
|
success
|
0 |
0
|
1619426981.785755
NtProtectVirtualMemory
|
process_identifier:
1068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feff185000
|
success
|
0 |
0
|
1619426981.910755
NtProtectVirtualMemory
|
process_identifier:
1068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feffb1b000
|
success
|
0 |
0
|
1619426981.910755
NtProtectVirtualMemory
|
process_identifier:
1068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feffb03000
|
success
|
0 |
0
|
1619426981.926755
NtProtectVirtualMemory
|
process_identifier:
1068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feffae8000
|
success
|
0 |
0
|
1619426981.926755
NtProtectVirtualMemory
|
process_identifier:
1068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feffaed000
|
success
|
0 |
0
|
1619426981.926755
NtProtectVirtualMemory
|
process_identifier:
1068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feffaed000
|
success
|
0 |
0
|
1619426981.926755
NtProtectVirtualMemory
|
process_identifier:
1068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feffb1b000
|
success
|
0 |
0
|
1619426981.941755
NtProtectVirtualMemory
|
process_identifier:
1068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feffb1b000
|
success
|
0 |
0
|
1619426981.941755
NtProtectVirtualMemory
|
process_identifier:
1068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feffae8000
|
success
|
0 |
0
|
1619426981.972755
NtProtectVirtualMemory
|
process_identifier:
1068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feffb2d000
|
success
|
0 |
0
|
1619426981.972755
NtProtectVirtualMemory
|
process_identifier:
1068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feffb2d000
|
success
|
0 |
0
|
1619426982.004755
NtProtectVirtualMemory
|
process_identifier:
1068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feffaed000
|
success
|
0 |
0
|
1619426982.004755
NtProtectVirtualMemory
|
process_identifier:
1068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feffaf1000
|
success
|
0 |
0
|
1619426982.019755
NtProtectVirtualMemory
|
process_identifier:
1068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feffafb000
|
success
|
0 |
0
|
1619426982.019755
NtProtectVirtualMemory
|
process_identifier:
1068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feffafb000
|
success
|
0 |
0
|
1619426982.035755
NtProtectVirtualMemory
|
process_identifier:
1068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feffae3000
|
success
|
0 |
0
|
1619426982.051755
NtProtectVirtualMemory
|
process_identifier:
1068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feffb00000
|
success
|
0 |
0
|
1619426982.051755
NtProtectVirtualMemory
|
process_identifier:
1068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feffaf1000
|
success
|
0 |
0
|
1619426982.051755
NtProtectVirtualMemory
|
process_identifier:
1068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feffafb000
|
success
|
0 |
0
|
1619426982.051755
NtProtectVirtualMemory
|
process_identifier:
1068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feffb06000
|
success
|
0 |
0
|
1619426982.066755
NtProtectVirtualMemory
|
process_identifier:
1068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feffaf1000
|
success
|
0 |
0
|
1619426982.082755
NtProtectVirtualMemory
|
process_identifier:
1068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feffaf1000
|
success
|
0 |
0
|
1619426982.082755
NtProtectVirtualMemory
|
process_identifier:
1068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feffafc000
|
success
|
0 |
0
|
1619426982.082755
NtProtectVirtualMemory
|
process_identifier:
1068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feffafb000
|
success
|
0 |
0
|
1619426982.082755
NtProtectVirtualMemory
|
process_identifier:
1068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feffaed000
|
success
|
0 |
0
|
1619426982.082755
NtProtectVirtualMemory
|
process_identifier:
1068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feffafc000
|
success
|
0 |
0
|