Time & API |
Arguments |
Status |
Return |
Repeated |
1727545298.078125
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x02450000
region_size:
745472
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2228
|
success
|
0 |
0
|
1727545396.984125
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x03670000
region_size:
405504
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545397.094125
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x035b0000
region_size:
4096
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545397.094125
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x035b0000
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545397.094125
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x76789000
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545397.094125
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x035b0000
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545397.094125
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x03600000
region_size:
4096
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545397.094125
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x03600000
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545397.094125
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x03600000
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545397.094125
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x035b0000
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545397.094125
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x76789000
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545397.094125
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x03610000
region_size:
4096
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545397.094125
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x03610000
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545397.094125
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x03610000
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545397.094125
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x03620000
region_size:
4096
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545397.094125
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x03620000
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545397.094125
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x76747000
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545397.094125
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x03620000
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545397.094125
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x03630000
region_size:
4096
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545397.094125
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x03630000
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545397.094125
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x03630000
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545397.094125
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x03620000
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545397.094125
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x76747000
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545397.094125
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x03640000
region_size:
4096
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545397.094125
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x03640000
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545397.094125
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x03640000
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545397.094125
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x76747000
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545397.094125
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x03650000
region_size:
4096
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545397.094125
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x03650000
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545397.094125
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x76747000
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545397.094125
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x03650000
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545397.094125
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x03660000
region_size:
4096
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545397.094125
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x03660000
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545397.094125
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x03660000
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545397.094125
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x03650000
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545397.094125
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x76747000
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545397.094125
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x036e0000
region_size:
4096
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545397.094125
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x036e0000
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545397.094125
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x036e0000
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545397.094125
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x76747000
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545397.094125
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x036f0000
region_size:
4096
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545397.094125
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x036f0000
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545397.094125
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x76747000
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545397.094125
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x036f0000
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545397.094125
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x03700000
region_size:
4096
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545397.094125
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x03700000
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545397.094125
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x03700000
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545397.094125
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x036f0000
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545397.094125
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x76747000
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545397.094125
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x03810000
region_size:
4096
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|