| Time & API |
Arguments |
Status |
Return |
Repeated |
1620762725.771186
NtProtectVirtualMemory
|
process_identifier:
1108
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x10001000
|
failed
|
3221225713 |
0
|
1620762725.771186
NtProtectVirtualMemory
|
process_identifier:
1108
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
86016
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x10028000
|
success
|
0 |
0
|
1620762725.786186
NtProtectVirtualMemory
|
process_identifier:
1108
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x10009000
|
success
|
0 |
0
|
1620762725.786186
NtProtectVirtualMemory
|
process_identifier:
1108
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x7786d000
|
success
|
0 |
0
|
1620762725.786186
NtProtectVirtualMemory
|
process_identifier:
1108
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x10009000
|
success
|
0 |
0
|
1620762725.786186
NtProtectVirtualMemory
|
process_identifier:
1108
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x10009000
|
success
|
0 |
0
|
1620762725.786186
NtProtectVirtualMemory
|
process_identifier:
1108
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x77868000
|
success
|
0 |
0
|
1620762725.786186
NtProtectVirtualMemory
|
process_identifier:
1108
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x10009000
|
success
|
0 |
0
|
1620762725.786186
NtProtectVirtualMemory
|
process_identifier:
1108
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x10009000
|
success
|
0 |
0
|
1620762725.786186
NtProtectVirtualMemory
|
process_identifier:
1108
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x775ad000
|
success
|
0 |
0
|
1620762725.786186
NtProtectVirtualMemory
|
process_identifier:
1108
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x10009000
|
success
|
0 |
0
|
1620762725.786186
NtProtectVirtualMemory
|
process_identifier:
1108
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x10009000
|
success
|
0 |
0
|
1620762725.786186
NtProtectVirtualMemory
|
process_identifier:
1108
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x775b6000
|
success
|
0 |
0
|
1620762725.786186
NtProtectVirtualMemory
|
process_identifier:
1108
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x10009000
|
success
|
0 |
0
|
1620762725.786186
NtProtectVirtualMemory
|
process_identifier:
1108
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x10009000
|
success
|
0 |
0
|
1620762725.786186
NtProtectVirtualMemory
|
process_identifier:
1108
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x775a8000
|
success
|
0 |
0
|
1620762725.786186
NtProtectVirtualMemory
|
process_identifier:
1108
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x10009000
|
success
|
0 |
0
|
1620762725.786186
NtProtectVirtualMemory
|
process_identifier:
1108
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x10009000
|
success
|
0 |
0
|
1620762725.786186
NtProtectVirtualMemory
|
process_identifier:
1108
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x775a6000
|
success
|
0 |
0
|
1620762725.786186
NtProtectVirtualMemory
|
process_identifier:
1108
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x10009000
|
success
|
0 |
0
|
1620762725.786186
NtProtectVirtualMemory
|
process_identifier:
1108
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x10009000
|
success
|
0 |
0
|
1620762725.786186
NtProtectVirtualMemory
|
process_identifier:
1108
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x775b1000
|
success
|
0 |
0
|
1620762725.786186
NtProtectVirtualMemory
|
process_identifier:
1108
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x10009000
|
success
|
0 |
0
|
1620762725.786186
NtProtectVirtualMemory
|
process_identifier:
1108
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x10009000
|
success
|
0 |
0
|
1620762725.786186
NtProtectVirtualMemory
|
process_identifier:
1108
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x775b1000
|
success
|
0 |
0
|
1620762725.786186
NtProtectVirtualMemory
|
process_identifier:
1108
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x10009000
|
success
|
0 |
0
|
1620762725.786186
NtProtectVirtualMemory
|
process_identifier:
1108
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x10009000
|
success
|
0 |
0
|
1620762725.786186
NtProtectVirtualMemory
|
process_identifier:
1108
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x775a7000
|
success
|
0 |
0
|
1620762725.786186
NtProtectVirtualMemory
|
process_identifier:
1108
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x10009000
|
success
|
0 |
0
|
1620762725.786186
NtProtectVirtualMemory
|
process_identifier:
1108
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x10009000
|
success
|
0 |
0
|
1620762725.786186
NtProtectVirtualMemory
|
process_identifier:
1108
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x775a8000
|
success
|
0 |
0
|
1620762725.786186
NtProtectVirtualMemory
|
process_identifier:
1108
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x10009000
|
success
|
0 |
0
|
1620762725.786186
NtProtectVirtualMemory
|
process_identifier:
1108
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x10009000
|
success
|
0 |
0
|
1620762725.786186
NtProtectVirtualMemory
|
process_identifier:
1108
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x775a7000
|
success
|
0 |
0
|
1620762725.786186
NtProtectVirtualMemory
|
process_identifier:
1108
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x10009000
|
success
|
0 |
0
|
1620762725.786186
NtProtectVirtualMemory
|
process_identifier:
1108
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x10009000
|
success
|
0 |
0
|
1620762725.786186
NtProtectVirtualMemory
|
process_identifier:
1108
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x775b1000
|
success
|
0 |
0
|
1620762725.786186
NtProtectVirtualMemory
|
process_identifier:
1108
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x10009000
|
success
|
0 |
0
|
1620762725.786186
NtProtectVirtualMemory
|
process_identifier:
1108
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x10009000
|
success
|
0 |
0
|
1620762725.786186
NtProtectVirtualMemory
|
process_identifier:
1108
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x775b4000
|
success
|
0 |
0
|
1620762725.786186
NtProtectVirtualMemory
|
process_identifier:
1108
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x10009000
|
success
|
0 |
0
|
1620762725.786186
NtProtectVirtualMemory
|
process_identifier:
1108
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x10009000
|
success
|
0 |
0
|
1620762725.786186
NtProtectVirtualMemory
|
process_identifier:
1108
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x775b4000
|
success
|
0 |
0
|
1620762725.786186
NtProtectVirtualMemory
|
process_identifier:
1108
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x10009000
|
success
|
0 |
0
|
1620762725.786186
NtProtectVirtualMemory
|
process_identifier:
1108
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x10009000
|
success
|
0 |
0
|
1620762725.786186
NtProtectVirtualMemory
|
process_identifier:
1108
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x775b9000
|
success
|
0 |
0
|
1620762725.786186
NtProtectVirtualMemory
|
process_identifier:
1108
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x10009000
|
success
|
0 |
0
|
1620762725.786186
NtProtectVirtualMemory
|
process_identifier:
1108
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x10009000
|
success
|
0 |
0
|
1620762725.786186
NtProtectVirtualMemory
|
process_identifier:
1108
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x775b3000
|
success
|
0 |
0
|
1620762725.786186
NtProtectVirtualMemory
|
process_identifier:
1108
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x10009000
|
success
|
0 |
0
|