| Time & API |
Arguments |
Status |
Return |
Repeated |
1619652149.915
NtAllocateVirtualMemory
|
process_identifier:
2316
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00350000
|
success
|
0 |
0
|
1619652150.04
NtProtectVirtualMemory
|
process_identifier:
2316
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
49152
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00459000
|
success
|
0 |
0
|
1619652150.04
NtAllocateVirtualMemory
|
process_identifier:
2316
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x01e80000
|
success
|
0 |
0
|
1619652151.165125
NtProtectVirtualMemory
|
process_identifier:
376
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00400000
|
success
|
0 |
0
|
1619652151.274125
NtAllocateVirtualMemory
|
process_identifier:
376
region_size:
1769472
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x01f60000
|
success
|
0 |
0
|
1619652151.274125
NtAllocateVirtualMemory
|
process_identifier:
376
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x020d0000
|
success
|
0 |
0
|
1619652151.274125
NtAllocateVirtualMemory
|
process_identifier:
376
region_size:
229376
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x01ce0000
|
success
|
0 |
0
|
1619652151.274125
NtProtectVirtualMemory
|
process_identifier:
376
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
118784
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01ce2000
|
success
|
0 |
0
|
1619652151.665125
NtAllocateVirtualMemory
|
process_identifier:
376
region_size:
262144
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x01d50000
|
success
|
0 |
0
|
1619652151.665125
NtAllocateVirtualMemory
|
process_identifier:
376
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x01d50000
|
success
|
0 |
0
|
1619652152.290125
NtProtectVirtualMemory
|
process_identifier:
376
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01e02000
|
success
|
0 |
0
|
1619652152.290125
NtProtectVirtualMemory
|
process_identifier:
376
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76351000
|
success
|
0 |
0
|
1619652152.290125
NtProtectVirtualMemory
|
process_identifier:
376
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01e02000
|
success
|
0 |
0
|
1619652152.290125
NtProtectVirtualMemory
|
process_identifier:
376
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76353000
|
success
|
0 |
0
|
1619652152.290125
NtProtectVirtualMemory
|
process_identifier:
376
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01e02000
|
success
|
0 |
0
|
1619652152.290125
NtProtectVirtualMemory
|
process_identifier:
376
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76354000
|
success
|
0 |
0
|
1619652152.290125
NtProtectVirtualMemory
|
process_identifier:
376
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01e02000
|
success
|
0 |
0
|
1619652152.290125
NtProtectVirtualMemory
|
process_identifier:
376
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76351000
|
success
|
0 |
0
|
1619652152.290125
NtProtectVirtualMemory
|
process_identifier:
376
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01e02000
|
success
|
0 |
0
|
1619652152.290125
NtProtectVirtualMemory
|
process_identifier:
376
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x77d4f000
|
success
|
0 |
0
|
1619652152.290125
NtProtectVirtualMemory
|
process_identifier:
376
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01e02000
|
success
|
0 |
0
|
1619652152.290125
NtProtectVirtualMemory
|
process_identifier:
376
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76353000
|
success
|
0 |
0
|
1619652152.290125
NtProtectVirtualMemory
|
process_identifier:
376
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01e02000
|
success
|
0 |
0
|
1619652152.290125
NtProtectVirtualMemory
|
process_identifier:
376
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76351000
|
success
|
0 |
0
|
1619652152.290125
NtProtectVirtualMemory
|
process_identifier:
376
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01e02000
|
success
|
0 |
0
|
1619652152.290125
NtProtectVirtualMemory
|
process_identifier:
376
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76351000
|
success
|
0 |
0
|
1619652152.290125
NtProtectVirtualMemory
|
process_identifier:
376
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01e02000
|
success
|
0 |
0
|
1619652152.290125
NtProtectVirtualMemory
|
process_identifier:
376
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76354000
|
success
|
0 |
0
|
1619652152.290125
NtProtectVirtualMemory
|
process_identifier:
376
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01e02000
|
success
|
0 |
0
|
1619652152.290125
NtProtectVirtualMemory
|
process_identifier:
376
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76351000
|
success
|
0 |
0
|
1619652151.39925
NtAllocateVirtualMemory
|
process_identifier:
2228
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003f0000
|
success
|
0 |
0
|
1619652151.43125
NtProtectVirtualMemory
|
process_identifier:
2228
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
49152
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00459000
|
success
|
0 |
0
|
1619652151.44625
NtAllocateVirtualMemory
|
process_identifier:
2228
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x01fa0000
|
success
|
0 |
0
|
1619652158.602375
NtAllocateVirtualMemory
|
process_identifier:
2536
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x007b0000
|
success
|
0 |
0
|
1619652158.680375
NtProtectVirtualMemory
|
process_identifier:
2536
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
49152
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00459000
|
success
|
0 |
0
|
1619652158.680375
NtAllocateVirtualMemory
|
process_identifier:
2536
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00880000
|
success
|
0 |
0
|
1619652160.508875
NtProtectVirtualMemory
|
process_identifier:
1320
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00400000
|
success
|
0 |
0
|
1619652160.508875
NtAllocateVirtualMemory
|
process_identifier:
1320
region_size:
1507328
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x01f50000
|
success
|
0 |
0
|
1619652160.508875
NtAllocateVirtualMemory
|
process_identifier:
1320
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02080000
|
success
|
0 |
0
|
1619652160.508875
NtAllocateVirtualMemory
|
process_identifier:
1320
region_size:
229376
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x004c0000
|
success
|
0 |
0
|
1619652160.508875
NtProtectVirtualMemory
|
process_identifier:
1320
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
118784
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x004c2000
|
success
|
0 |
0
|
1619652160.555875
NtAllocateVirtualMemory
|
process_identifier:
1320
region_size:
1245184
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x006d0000
|
success
|
0 |
0
|
1619652160.555875
NtAllocateVirtualMemory
|
process_identifier:
1320
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x007c0000
|
success
|
0 |
0
|
1619652161.133875
NtProtectVirtualMemory
|
process_identifier:
1320
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x005b2000
|
success
|
0 |
0
|
1619652161.148875
NtProtectVirtualMemory
|
process_identifier:
1320
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76351000
|
success
|
0 |
0
|
1619652161.148875
NtProtectVirtualMemory
|
process_identifier:
1320
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x005b2000
|
success
|
0 |
0
|
1619652161.148875
NtProtectVirtualMemory
|
process_identifier:
1320
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76353000
|
success
|
0 |
0
|
1619652161.148875
NtProtectVirtualMemory
|
process_identifier:
1320
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x005b2000
|
success
|
0 |
0
|
1619652161.148875
NtProtectVirtualMemory
|
process_identifier:
1320
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76354000
|
success
|
0 |
0
|
1619652161.148875
NtProtectVirtualMemory
|
process_identifier:
1320
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x005b2000
|
success
|
0 |
0
|