| Time & API |
Arguments |
Status |
Return |
Repeated |
1619517557.96125
NtAllocateVirtualMemory
|
process_identifier:
2544
region_size:
745472
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x02450000
|
success
|
0 |
0
|
1619517558.46125
NtAllocateVirtualMemory
|
process_identifier:
2056
region_size:
405504
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00610000
|
success
|
0 |
0
|
1619517558.99225
NtAllocateVirtualMemory
|
process_identifier:
2056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x01f30000
|
success
|
0 |
0
|
1619517558.99225
NtProtectVirtualMemory
|
process_identifier:
2056
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01f30000
|
success
|
0 |
0
|
1619517558.99225
NtProtectVirtualMemory
|
process_identifier:
2056
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x775e9000
|
success
|
0 |
0
|
1619517558.99225
NtProtectVirtualMemory
|
process_identifier:
2056
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01f30000
|
success
|
0 |
0
|
1619517558.99225
NtAllocateVirtualMemory
|
process_identifier:
2056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x01f40000
|
success
|
0 |
0
|
1619517558.99225
NtProtectVirtualMemory
|
process_identifier:
2056
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01f40000
|
success
|
0 |
0
|
1619517558.99225
NtProtectVirtualMemory
|
process_identifier:
2056
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01f40000
|
success
|
0 |
0
|
1619517558.99225
NtProtectVirtualMemory
|
process_identifier:
2056
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01f30000
|
success
|
0 |
0
|
1619517558.99225
NtProtectVirtualMemory
|
process_identifier:
2056
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x775e9000
|
success
|
0 |
0
|
1619517558.99225
NtAllocateVirtualMemory
|
process_identifier:
2056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x01f50000
|
success
|
0 |
0
|
1619517558.99225
NtProtectVirtualMemory
|
process_identifier:
2056
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01f50000
|
success
|
0 |
0
|
1619517558.99225
NtProtectVirtualMemory
|
process_identifier:
2056
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01f50000
|
success
|
0 |
0
|
1619517558.99225
NtAllocateVirtualMemory
|
process_identifier:
2056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x01fb0000
|
success
|
0 |
0
|
1619517558.99225
NtProtectVirtualMemory
|
process_identifier:
2056
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01fb0000
|
success
|
0 |
0
|
1619517558.99225
NtProtectVirtualMemory
|
process_identifier:
2056
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x775a7000
|
success
|
0 |
0
|
1619517558.99225
NtProtectVirtualMemory
|
process_identifier:
2056
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01fb0000
|
success
|
0 |
0
|
1619517558.99225
NtAllocateVirtualMemory
|
process_identifier:
2056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x01fc0000
|
success
|
0 |
0
|
1619517558.99225
NtProtectVirtualMemory
|
process_identifier:
2056
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01fc0000
|
success
|
0 |
0
|
1619517558.99225
NtProtectVirtualMemory
|
process_identifier:
2056
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01fc0000
|
success
|
0 |
0
|
1619517558.99225
NtProtectVirtualMemory
|
process_identifier:
2056
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01fb0000
|
success
|
0 |
0
|
1619517558.99225
NtProtectVirtualMemory
|
process_identifier:
2056
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x775a7000
|
success
|
0 |
0
|
1619517558.99225
NtAllocateVirtualMemory
|
process_identifier:
2056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x01fd0000
|
success
|
0 |
0
|
1619517558.99225
NtProtectVirtualMemory
|
process_identifier:
2056
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01fd0000
|
success
|
0 |
0
|
1619517558.99225
NtProtectVirtualMemory
|
process_identifier:
2056
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01fd0000
|
success
|
0 |
0
|
1619517558.99225
NtProtectVirtualMemory
|
process_identifier:
2056
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x775a7000
|
success
|
0 |
0
|
1619517558.99225
NtAllocateVirtualMemory
|
process_identifier:
2056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x01fe0000
|
success
|
0 |
0
|
1619517558.99225
NtProtectVirtualMemory
|
process_identifier:
2056
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01fe0000
|
success
|
0 |
0
|
1619517558.99225
NtProtectVirtualMemory
|
process_identifier:
2056
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x775a7000
|
success
|
0 |
0
|
1619517558.99225
NtProtectVirtualMemory
|
process_identifier:
2056
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01fe0000
|
success
|
0 |
0
|
1619517558.99225
NtAllocateVirtualMemory
|
process_identifier:
2056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x01ff0000
|
success
|
0 |
0
|
1619517558.99225
NtProtectVirtualMemory
|
process_identifier:
2056
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01ff0000
|
success
|
0 |
0
|
1619517558.99225
NtProtectVirtualMemory
|
process_identifier:
2056
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01ff0000
|
success
|
0 |
0
|
1619517558.99225
NtProtectVirtualMemory
|
process_identifier:
2056
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01fe0000
|
success
|
0 |
0
|
1619517558.99225
NtProtectVirtualMemory
|
process_identifier:
2056
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x775a7000
|
success
|
0 |
0
|
1619517558.99225
NtAllocateVirtualMemory
|
process_identifier:
2056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x02000000
|
success
|
0 |
0
|
1619517558.99225
NtProtectVirtualMemory
|
process_identifier:
2056
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x02000000
|
success
|
0 |
0
|
1619517558.99225
NtProtectVirtualMemory
|
process_identifier:
2056
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x02000000
|
success
|
0 |
0
|
1619517558.99225
NtProtectVirtualMemory
|
process_identifier:
2056
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x775a7000
|
success
|
0 |
0
|
1619517558.99225
NtAllocateVirtualMemory
|
process_identifier:
2056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x02010000
|
success
|
0 |
0
|
1619517558.99225
NtProtectVirtualMemory
|
process_identifier:
2056
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x02010000
|
success
|
0 |
0
|
1619517558.99225
NtProtectVirtualMemory
|
process_identifier:
2056
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x775a7000
|
success
|
0 |
0
|
1619517558.99225
NtProtectVirtualMemory
|
process_identifier:
2056
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x02010000
|
success
|
0 |
0
|
1619517558.99225
NtAllocateVirtualMemory
|
process_identifier:
2056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x02020000
|
success
|
0 |
0
|
1619517558.99225
NtProtectVirtualMemory
|
process_identifier:
2056
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x02020000
|
success
|
0 |
0
|
1619517558.99225
NtProtectVirtualMemory
|
process_identifier:
2056
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x02020000
|
success
|
0 |
0
|
1619517558.99225
NtProtectVirtualMemory
|
process_identifier:
2056
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x02010000
|
success
|
0 |
0
|
1619517558.99225
NtProtectVirtualMemory
|
process_identifier:
2056
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x775a7000
|
success
|
0 |
0
|
1619517558.99225
NtAllocateVirtualMemory
|
process_identifier:
2056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x02030000
|
success
|
0 |
0
|