| Time & API |
Arguments |
Status |
Return |
Repeated |
1619596029.687125
NtAllocateVirtualMemory
|
process_identifier:
2616
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003d0000
|
success
|
0 |
0
|
1619596029.844125
NtProtectVirtualMemory
|
process_identifier:
2616
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
81920
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00466000
|
success
|
0 |
0
|
1619596029.859125
NtAllocateVirtualMemory
|
process_identifier:
2616
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00a70000
|
success
|
0 |
0
|
1619596031.797375
NtAllocateVirtualMemory
|
process_identifier:
2364
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00360000
|
success
|
0 |
0
|
1619596031.828375
NtProtectVirtualMemory
|
process_identifier:
2364
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
36864
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00491000
|
success
|
0 |
0
|
1619596031.844375
NtAllocateVirtualMemory
|
process_identifier:
2364
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00840000
|
success
|
0 |
0
|
1619603457.569875
NtAllocateVirtualMemory
|
process_identifier:
2240
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00360000
|
success
|
0 |
0
|
1619603457.725875
NtProtectVirtualMemory
|
process_identifier:
2240
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
36864
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00465000
|
success
|
0 |
0
|
1619603457.803875
NtAllocateVirtualMemory
|
process_identifier:
2240
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x021b0000
|
success
|
0 |
0
|
1619603461.803
NtAllocateVirtualMemory
|
process_identifier:
3040
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003e0000
|
success
|
0 |
0
|
1619603477.616
NtAllocateVirtualMemory
|
process_identifier:
3040
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x01f40000
|
success
|
0 |
0
|
1619603480.069625
NtProtectVirtualMemory
|
process_identifier:
1824
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00400000
|
success
|
0 |
0
|
1619603480.132625
NtAllocateVirtualMemory
|
process_identifier:
1824
region_size:
851968
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x01da0000
|
success
|
0 |
0
|
1619603480.132625
NtAllocateVirtualMemory
|
process_identifier:
1824
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x01e30000
|
success
|
0 |
0
|
1619603480.132625
NtAllocateVirtualMemory
|
process_identifier:
1824
region_size:
368640
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x01da0000
|
success
|
0 |
0
|
1619603480.132625
NtProtectVirtualMemory
|
process_identifier:
1824
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
339968
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01da2000
|
success
|
0 |
0
|
1619603481.569625
NtAllocateVirtualMemory
|
process_identifier:
1824
region_size:
1769472
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x01f20000
|
success
|
0 |
0
|
1619603481.569625
NtAllocateVirtualMemory
|
process_identifier:
1824
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02090000
|
success
|
0 |
0
|
1619603482.757625
NtProtectVirtualMemory
|
process_identifier:
1824
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01cd2000
|
success
|
0 |
0
|
1619603482.757625
NtProtectVirtualMemory
|
process_identifier:
1824
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76351000
|
success
|
0 |
0
|
1619603482.757625
NtProtectVirtualMemory
|
process_identifier:
1824
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01cd2000
|
success
|
0 |
0
|
1619603482.757625
NtProtectVirtualMemory
|
process_identifier:
1824
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76353000
|
success
|
0 |
0
|
1619603482.757625
NtProtectVirtualMemory
|
process_identifier:
1824
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01cd2000
|
success
|
0 |
0
|
1619603482.757625
NtProtectVirtualMemory
|
process_identifier:
1824
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76354000
|
success
|
0 |
0
|
1619603482.757625
NtProtectVirtualMemory
|
process_identifier:
1824
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01cd2000
|
success
|
0 |
0
|
1619603482.757625
NtProtectVirtualMemory
|
process_identifier:
1824
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76351000
|
success
|
0 |
0
|
1619603482.757625
NtProtectVirtualMemory
|
process_identifier:
1824
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01cd2000
|
success
|
0 |
0
|
1619603482.757625
NtProtectVirtualMemory
|
process_identifier:
1824
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x77d4f000
|
success
|
0 |
0
|
1619603482.757625
NtProtectVirtualMemory
|
process_identifier:
1824
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01cd2000
|
success
|
0 |
0
|
1619603482.757625
NtProtectVirtualMemory
|
process_identifier:
1824
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76353000
|
success
|
0 |
0
|
1619603482.757625
NtProtectVirtualMemory
|
process_identifier:
1824
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01cd2000
|
success
|
0 |
0
|
1619603482.757625
NtProtectVirtualMemory
|
process_identifier:
1824
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76351000
|
success
|
0 |
0
|
1619603482.757625
NtProtectVirtualMemory
|
process_identifier:
1824
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01cd2000
|
success
|
0 |
0
|
1619603482.757625
NtProtectVirtualMemory
|
process_identifier:
1824
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76351000
|
success
|
0 |
0
|
1619603482.757625
NtProtectVirtualMemory
|
process_identifier:
1824
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01cd2000
|
success
|
0 |
0
|
1619603482.757625
NtProtectVirtualMemory
|
process_identifier:
1824
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76354000
|
success
|
0 |
0
|
1619603482.757625
NtProtectVirtualMemory
|
process_identifier:
1824
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01cd2000
|
success
|
0 |
0
|
1619603482.757625
NtProtectVirtualMemory
|
process_identifier:
1824
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76351000
|
success
|
0 |
0
|