Time & API |
Arguments |
Status |
Return |
Repeated |
1620962181.093499
NtProtectVirtualMemory
|
process_identifier:
2216
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00400000
|
success
|
0 |
0
|
1620962181.093499
NtProtectVirtualMemory
|
process_identifier:
2216
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
69632
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00401000
|
success
|
0 |
0
|
1620962181.093499
NtProtectVirtualMemory
|
process_identifier:
2216
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
69632
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x0041b000
|
success
|
0 |
0
|
1620962182.329001
NtAllocateVirtualMemory
|
process_identifier:
1176
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00620000
|
success
|
0 |
0
|
1620962253.734499
NtAllocateVirtualMemory
|
process_identifier:
1424
region_size:
65536
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00000000042a0000
|
success
|
0 |
0
|
1620962207.171876
NtProtectVirtualMemory
|
process_identifier:
2288
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x1005d000
|
success
|
0 |
0
|
1620962207.171876
NtProtectVirtualMemory
|
process_identifier:
2288
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x741e1000
|
success
|
0 |
0
|
1620962207.171876
NtProtectVirtualMemory
|
process_identifier:
2288
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x741d1000
|
success
|
0 |
0
|
1620962207.171876
NtProtectVirtualMemory
|
process_identifier:
2288
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x741b1000
|
success
|
0 |
0
|
1620962207.171876
NtProtectVirtualMemory
|
process_identifier:
2288
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x741a1000
|
success
|
0 |
0
|
1620962207.171876
NtProtectVirtualMemory
|
process_identifier:
2288
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x744c1000
|
success
|
0 |
0
|
1620962207.171876
NtProtectVirtualMemory
|
process_identifier:
2288
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x74181000
|
success
|
0 |
0
|
1620962207.171876
NtProtectVirtualMemory
|
process_identifier:
2288
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x74141000
|
success
|
0 |
0
|
1620962207.171876
NtProtectVirtualMemory
|
process_identifier:
2288
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x74101000
|
success
|
0 |
0
|
1620962207.171876
NtProtectVirtualMemory
|
process_identifier:
2288
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76881000
|
success
|
0 |
0
|
1620962207.171876
NtProtectVirtualMemory
|
process_identifier:
2288
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x740e1000
|
success
|
0 |
0
|
1620962207.171876
NtProtectVirtualMemory
|
process_identifier:
2288
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x74081000
|
success
|
0 |
0
|
1620962207.171876
NtProtectVirtualMemory
|
process_identifier:
2288
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x77531000
|
success
|
0 |
0
|
1620962207.171876
NtProtectVirtualMemory
|
process_identifier:
2288
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x75a01000
|
success
|
0 |
0
|
1620961787.91002
NtProtectVirtualMemory
|
process_identifier:
1476
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x0000000010059000
|
success
|
0 |
0
|
1620961787.91002
NtProtectVirtualMemory
|
process_identifier:
1476
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fefd8b4000
|
success
|
0 |
0
|
1620961787.91002
NtProtectVirtualMemory
|
process_identifier:
1476
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fefcd66000
|
success
|
0 |
0
|
1620961787.91002
NtProtectVirtualMemory
|
process_identifier:
1476
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fefbaaa000
|
success
|
0 |
0
|
1620961787.91002
NtProtectVirtualMemory
|
process_identifier:
1476
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fefb97c000
|
success
|
0 |
0
|
1620961787.91002
NtProtectVirtualMemory
|
process_identifier:
1476
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fefb94b000
|
success
|
0 |
0
|
1620961787.91002
NtProtectVirtualMemory
|
process_identifier:
1476
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fefd69d000
|
success
|
0 |
0
|
1620961787.91002
NtProtectVirtualMemory
|
process_identifier:
1476
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fefb92d000
|
success
|
0 |
0
|
1620961787.92502
NtProtectVirtualMemory
|
process_identifier:
1476
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fefb465000
|
success
|
0 |
0
|
1620961787.92502
NtProtectVirtualMemory
|
process_identifier:
1476
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef3c1e000
|
success
|
0 |
0
|
1620961787.94102
NtProtectVirtualMemory
|
process_identifier:
1476
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef318e000
|
success
|
0 |
0
|
1620961787.94102
NtProtectVirtualMemory
|
process_identifier:
1476
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feffc2a000
|
success
|
0 |
0
|
1620961787.94102
NtProtectVirtualMemory
|
process_identifier:
1476
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fefb48f000
|
success
|
0 |
0
|
1620961787.95702
NtProtectVirtualMemory
|
process_identifier:
1476
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feff9bb000
|
success
|
0 |
0
|
1620961787.95702
NtProtectVirtualMemory
|
process_identifier:
1476
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fefdce1000
|
success
|
0 |
0
|
1620961787.95702
NtProtectVirtualMemory
|
process_identifier:
1476
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feff53d000
|
success
|
0 |
0
|
1620961787.95702
NtProtectVirtualMemory
|
process_identifier:
1476
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fefdb61000
|
success
|
0 |
0
|
1620961787.95702
NtProtectVirtualMemory
|
process_identifier:
1476
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fefddcf000
|
success
|
0 |
0
|
1620961787.95702
NtProtectVirtualMemory
|
process_identifier:
1476
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fefdb49000
|
success
|
0 |
0
|
1620961787.95702
NtProtectVirtualMemory
|
process_identifier:
1476
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef96f1000
|
success
|
0 |
0
|
1620961787.97202
NtProtectVirtualMemory
|
process_identifier:
1476
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feff3c1000
|
success
|
0 |
0
|
1620961787.97202
NtProtectVirtualMemory
|
process_identifier:
1476
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fefde73000
|
success
|
0 |
0
|