| Time & API |
Arguments |
Status |
Return |
Repeated |
1619685967.59325
NtAllocateVirtualMemory
|
process_identifier:
2468
region_size:
2293760
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00a00000
|
success
|
0 |
0
|
1619685967.59325
NtAllocateVirtualMemory
|
process_identifier:
2468
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00bf0000
|
success
|
0 |
0
|
1619685967.98425
NtProtectVirtualMemory
|
process_identifier:
2468
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73c51000
|
success
|
0 |
0
|
1619685967.99925
NtAllocateVirtualMemory
|
process_identifier:
2468
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0034a000
|
success
|
0 |
0
|
1619685967.99925
NtProtectVirtualMemory
|
process_identifier:
2468
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73c52000
|
success
|
0 |
0
|
1619685967.99925
NtAllocateVirtualMemory
|
process_identifier:
2468
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00342000
|
success
|
0 |
0
|
1619685968.84325
NtAllocateVirtualMemory
|
process_identifier:
2468
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00452000
|
success
|
0 |
0
|
1619685969.12425
NtAllocateVirtualMemory
|
process_identifier:
2468
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00453000
|
success
|
0 |
0
|
1619685969.14025
NtAllocateVirtualMemory
|
process_identifier:
2468
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0048b000
|
success
|
0 |
0
|
1619685969.14025
NtAllocateVirtualMemory
|
process_identifier:
2468
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00487000
|
success
|
0 |
0
|
1619685969.17125
NtAllocateVirtualMemory
|
process_identifier:
2468
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0045c000
|
success
|
0 |
0
|
1619685969.21825
NtAllocateVirtualMemory
|
process_identifier:
2468
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00790000
|
success
|
0 |
0
|
1619685969.45325
NtAllocateVirtualMemory
|
process_identifier:
2468
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00454000
|
success
|
0 |
0
|
1619685969.45325
NtAllocateVirtualMemory
|
process_identifier:
2468
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00791000
|
success
|
0 |
0
|
1619685969.46825
NtAllocateVirtualMemory
|
process_identifier:
2468
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0045a000
|
success
|
0 |
0
|
1619685969.49925
NtProtectVirtualMemory
|
process_identifier:
2468
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
389120
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00972000
|
success
|
0 |
0
|
1619685976.06225
NtAllocateVirtualMemory
|
process_identifier:
2468
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00792000
|
success
|
0 |
0
|
1619685976.09325
NtAllocateVirtualMemory
|
process_identifier:
2468
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00793000
|
success
|
0 |
0
|
1619685976.09325
NtAllocateVirtualMemory
|
process_identifier:
2468
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00794000
|
success
|
0 |
0
|
1619685976.12425
NtAllocateVirtualMemory
|
process_identifier:
2468
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00795000
|
success
|
0 |
0
|
1619685976.12425
NtAllocateVirtualMemory
|
process_identifier:
2468
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00796000
|
success
|
0 |
0
|
1619685976.29625
NtAllocateVirtualMemory
|
process_identifier:
2468
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00455000
|
success
|
0 |
0
|
1619685976.32825
NtAllocateVirtualMemory
|
process_identifier:
2468
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00797000
|
success
|
0 |
0
|
1619685976.32825
NtAllocateVirtualMemory
|
process_identifier:
2468
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00799000
|
success
|
0 |
0
|
1619685976.32825
NtProtectVirtualMemory
|
process_identifier:
2468
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x009d2000
|
success
|
0 |
0
|
1619685976.32825
NtProtectVirtualMemory
|
process_identifier:
2468
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x009d2000
|
success
|
0 |
0
|
1619685976.32825
NtProtectVirtualMemory
|
process_identifier:
2468
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00970000
|
success
|
0 |
0
|
1619685976.32825
NtProtectVirtualMemory
|
process_identifier:
2468
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00970000
|
success
|
0 |
0
|
1619685976.32825
NtProtectVirtualMemory
|
process_identifier:
2468
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00970000
|
success
|
0 |
0
|
1619685976.32825
NtProtectVirtualMemory
|
process_identifier:
2468
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00970000
|
success
|
0 |
0
|
1619685976.32825
NtProtectVirtualMemory
|
process_identifier:
2468
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00970000
|
success
|
0 |
0
|
1619685976.32825
NtProtectVirtualMemory
|
process_identifier:
2468
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x009d2000
|
success
|
0 |
0
|
1619685976.32825
NtProtectVirtualMemory
|
process_identifier:
2468
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x009d2000
|
success
|
0 |
0
|
1619685976.32825
NtProtectVirtualMemory
|
process_identifier:
2468
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x009d2000
|
success
|
0 |
0
|
1619685976.32825
NtProtectVirtualMemory
|
process_identifier:
2468
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x009d2000
|
success
|
0 |
0
|
1619685976.32825
NtProtectVirtualMemory
|
process_identifier:
2468
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x009d2000
|
success
|
0 |
0
|
1619685976.32825
NtProtectVirtualMemory
|
process_identifier:
2468
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x009d2000
|
success
|
0 |
0
|
1619685976.32825
NtProtectVirtualMemory
|
process_identifier:
2468
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x009d2000
|
success
|
0 |
0
|
1619685976.32825
NtProtectVirtualMemory
|
process_identifier:
2468
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x009d2000
|
success
|
0 |
0
|
1619685976.32825
NtProtectVirtualMemory
|
process_identifier:
2468
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x009d2000
|
success
|
0 |
0
|
1619685976.32825
NtProtectVirtualMemory
|
process_identifier:
2468
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x009d2000
|
success
|
0 |
0
|
1619685976.32825
NtProtectVirtualMemory
|
process_identifier:
2468
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x009d2000
|
success
|
0 |
0
|
1619685976.32825
NtProtectVirtualMemory
|
process_identifier:
2468
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x009d2000
|
success
|
0 |
0
|
1619685976.32825
NtProtectVirtualMemory
|
process_identifier:
2468
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x009d2000
|
success
|
0 |
0
|
1619685976.32825
NtProtectVirtualMemory
|
process_identifier:
2468
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x009d2000
|
success
|
0 |
0
|
1619685976.32825
NtProtectVirtualMemory
|
process_identifier:
2468
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x009d2000
|
success
|
0 |
0
|
1619685976.32825
NtProtectVirtualMemory
|
process_identifier:
2468
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x009d2000
|
success
|
0 |
0
|
1619685976.32825
NtProtectVirtualMemory
|
process_identifier:
2468
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x009d2000
|
success
|
0 |
0
|
1619685976.32825
NtProtectVirtualMemory
|
process_identifier:
2468
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x009d2000
|
success
|
0 |
0
|
1619685976.32825
NtProtectVirtualMemory
|
process_identifier:
2468
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x009d2000
|
success
|
0 |
0
|