| Time & API |
Arguments |
Status |
Return |
Repeated |
1620762783.719625
NtAllocateVirtualMemory
|
process_identifier:
1912
region_size:
1441792
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00530000
|
success
|
0 |
0
|
1620762783.719625
NtAllocateVirtualMemory
|
process_identifier:
1912
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00650000
|
success
|
0 |
0
|
1620762785.156625
NtAllocateVirtualMemory
|
process_identifier:
1912
region_size:
1835008
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x02280000
|
success
|
0 |
0
|
1620762785.156625
NtAllocateVirtualMemory
|
process_identifier:
1912
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02400000
|
success
|
0 |
0
|
1620762785.219625
NtProtectVirtualMemory
|
process_identifier:
1912
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73b91000
|
success
|
0 |
0
|
1620762785.250625
NtAllocateVirtualMemory
|
process_identifier:
1912
region_size:
589824
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x005c0000
|
success
|
0 |
0
|
1620762785.250625
NtAllocateVirtualMemory
|
process_identifier:
1912
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00610000
|
success
|
0 |
0
|
1620762785.250625
NtAllocateVirtualMemory
|
process_identifier:
1912
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0056a000
|
success
|
0 |
0
|
1620762785.250625
NtProtectVirtualMemory
|
process_identifier:
1912
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73b92000
|
success
|
0 |
0
|
1620762785.250625
NtAllocateVirtualMemory
|
process_identifier:
1912
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00562000
|
success
|
0 |
0
|
1620762785.687625
NtAllocateVirtualMemory
|
process_identifier:
1912
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00572000
|
success
|
0 |
0
|
1620762785.859625
NtAllocateVirtualMemory
|
process_identifier:
1912
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00595000
|
success
|
0 |
0
|
1620762785.859625
NtAllocateVirtualMemory
|
process_identifier:
1912
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0059b000
|
success
|
0 |
0
|
1620762785.859625
NtAllocateVirtualMemory
|
process_identifier:
1912
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00597000
|
success
|
0 |
0
|
1620762786.078625
NtAllocateVirtualMemory
|
process_identifier:
1912
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00573000
|
success
|
0 |
0
|
1620762786.187625
NtAllocateVirtualMemory
|
process_identifier:
1912
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0057c000
|
success
|
0 |
0
|
1620762786.187625
NtAllocateVirtualMemory
|
process_identifier:
1912
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00574000
|
success
|
0 |
0
|
1620762786.250625
NtAllocateVirtualMemory
|
process_identifier:
1912
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x007e0000
|
success
|
0 |
0
|
1620762786.859625
NtAllocateVirtualMemory
|
process_identifier:
1912
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x007e1000
|
success
|
0 |
0
|
1620762787.031625
NtProtectVirtualMemory
|
process_identifier:
1912
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
204800
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00df2000
|
success
|
0 |
0
|
1620762791.672625
NtAllocateVirtualMemory
|
process_identifier:
1912
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x007e2000
|
success
|
0 |
0
|
1620762791.687625
NtAllocateVirtualMemory
|
process_identifier:
1912
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00575000
|
success
|
0 |
0
|
1620762791.750625
NtAllocateVirtualMemory
|
process_identifier:
1912
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x007e3000
|
success
|
0 |
0
|
1620762791.812625
NtAllocateVirtualMemory
|
process_identifier:
1912
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x007e4000
|
success
|
0 |
0
|
1620762791.844625
NtAllocateVirtualMemory
|
process_identifier:
1912
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x007e5000
|
success
|
0 |
0
|
1620762791.859625
NtAllocateVirtualMemory
|
process_identifier:
1912
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x007e6000
|
success
|
0 |
0
|
1620762792.000625
NtAllocateVirtualMemory
|
process_identifier:
1912
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00576000
|
success
|
0 |
0
|
1620762792.015625
NtAllocateVirtualMemory
|
process_identifier:
1912
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x007e7000
|
success
|
0 |
0
|
1620762792.078625
NtAllocateVirtualMemory
|
process_identifier:
1912
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x007e8000
|
success
|
0 |
0
|
1620762792.078625
NtProtectVirtualMemory
|
process_identifier:
1912
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00e24000
|
success
|
0 |
0
|
1620762792.078625
NtProtectVirtualMemory
|
process_identifier:
1912
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00e24000
|
success
|
0 |
0
|
1620762792.078625
NtProtectVirtualMemory
|
process_identifier:
1912
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00df0000
|
success
|
0 |
0
|
1620762792.328625
NtProtectVirtualMemory
|
process_identifier:
1912
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00df0000
|
success
|
0 |
0
|
1620762792.328625
NtProtectVirtualMemory
|
process_identifier:
1912
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00df0000
|
success
|
0 |
0
|
1620762792.328625
NtProtectVirtualMemory
|
process_identifier:
1912
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00df0000
|
success
|
0 |
0
|
1620762792.328625
NtProtectVirtualMemory
|
process_identifier:
1912
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00df0000
|
success
|
0 |
0
|
1620762792.328625
NtProtectVirtualMemory
|
process_identifier:
1912
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00e24000
|
success
|
0 |
0
|
1620762792.328625
NtProtectVirtualMemory
|
process_identifier:
1912
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00e24000
|
success
|
0 |
0
|
1620762792.328625
NtProtectVirtualMemory
|
process_identifier:
1912
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00e24000
|
success
|
0 |
0
|
1620762792.328625
NtProtectVirtualMemory
|
process_identifier:
1912
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00e24000
|
success
|
0 |
0
|
1620762792.328625
NtProtectVirtualMemory
|
process_identifier:
1912
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00e24000
|
success
|
0 |
0
|
1620762792.328625
NtProtectVirtualMemory
|
process_identifier:
1912
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00e24000
|
success
|
0 |
0
|
1620762792.328625
NtProtectVirtualMemory
|
process_identifier:
1912
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00e24000
|
success
|
0 |
0
|
1620762792.328625
NtProtectVirtualMemory
|
process_identifier:
1912
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00e24000
|
success
|
0 |
0
|
1620762792.328625
NtProtectVirtualMemory
|
process_identifier:
1912
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00e24000
|
success
|
0 |
0
|
1620762792.328625
NtProtectVirtualMemory
|
process_identifier:
1912
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00e24000
|
success
|
0 |
0
|
1620762792.328625
NtProtectVirtualMemory
|
process_identifier:
1912
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00e24000
|
success
|
0 |
0
|
1620762792.328625
NtProtectVirtualMemory
|
process_identifier:
1912
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00e24000
|
success
|
0 |
0
|
1620762792.328625
NtProtectVirtualMemory
|
process_identifier:
1912
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00e24000
|
success
|
0 |
0
|
1620762792.328625
NtProtectVirtualMemory
|
process_identifier:
1912
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00e24000
|
success
|
0 |
0
|