| Time & API |
Arguments |
Status |
Return |
Repeated |
1619685976.781375
NtAllocateVirtualMemory
|
process_identifier:
2712
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003d0000
|
success
|
0 |
0
|
1619685977.077375
NtProtectVirtualMemory
|
process_identifier:
2712
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
69632
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x0045c000
|
success
|
0 |
0
|
1619685977.093375
NtAllocateVirtualMemory
|
process_identifier:
2712
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x01f30000
|
success
|
0 |
0
|
1619713222.049751
NtAllocateVirtualMemory
|
process_identifier:
1804
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003e0000
|
success
|
0 |
0
|
1619713222.081751
NtProtectVirtualMemory
|
process_identifier:
1804
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
69632
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x0045c000
|
success
|
0 |
0
|
1619713222.081751
NtAllocateVirtualMemory
|
process_identifier:
1804
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00530000
|
success
|
0 |
0
|
1619713223.768751
NtProtectVirtualMemory
|
process_identifier:
2080
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00400000
|
success
|
0 |
0
|
1619713224.018751
NtAllocateVirtualMemory
|
process_identifier:
2080
region_size:
393216
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00840000
|
success
|
0 |
0
|
1619713224.018751
NtAllocateVirtualMemory
|
process_identifier:
2080
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00860000
|
success
|
0 |
0
|
1619713224.018751
NtAllocateVirtualMemory
|
process_identifier:
2080
region_size:
630784
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x02030000
|
success
|
0 |
0
|
1619713224.018751
NtProtectVirtualMemory
|
process_identifier:
2080
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
602112
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x02032000
|
success
|
0 |
0
|
1619713229.127751
NtProtectVirtualMemory
|
process_identifier:
2080
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x005a2000
|
success
|
0 |
0
|
1619713229.127751
NtProtectVirtualMemory
|
process_identifier:
2080
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76351000
|
success
|
0 |
0
|
1619713229.143751
NtProtectVirtualMemory
|
process_identifier:
2080
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x005a2000
|
success
|
0 |
0
|
1619713229.143751
NtProtectVirtualMemory
|
process_identifier:
2080
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76353000
|
success
|
0 |
0
|
1619713229.143751
NtProtectVirtualMemory
|
process_identifier:
2080
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x005a2000
|
success
|
0 |
0
|
1619713229.143751
NtProtectVirtualMemory
|
process_identifier:
2080
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76354000
|
success
|
0 |
0
|
1619713229.143751
NtProtectVirtualMemory
|
process_identifier:
2080
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x005a2000
|
success
|
0 |
0
|
1619713229.143751
NtProtectVirtualMemory
|
process_identifier:
2080
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76351000
|
success
|
0 |
0
|
1619713229.143751
NtProtectVirtualMemory
|
process_identifier:
2080
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x005a2000
|
success
|
0 |
0
|
1619713229.143751
NtProtectVirtualMemory
|
process_identifier:
2080
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x77d4f000
|
success
|
0 |
0
|
1619713229.143751
NtProtectVirtualMemory
|
process_identifier:
2080
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x005a2000
|
success
|
0 |
0
|
1619713229.143751
NtProtectVirtualMemory
|
process_identifier:
2080
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76353000
|
success
|
0 |
0
|
1619713229.143751
NtProtectVirtualMemory
|
process_identifier:
2080
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x005a2000
|
success
|
0 |
0
|
1619713229.143751
NtProtectVirtualMemory
|
process_identifier:
2080
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76351000
|
success
|
0 |
0
|
1619713229.143751
NtProtectVirtualMemory
|
process_identifier:
2080
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x005a2000
|
success
|
0 |
0
|
1619713229.143751
NtProtectVirtualMemory
|
process_identifier:
2080
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76351000
|
success
|
0 |
0
|
1619713229.143751
NtProtectVirtualMemory
|
process_identifier:
2080
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x005a2000
|
success
|
0 |
0
|
1619713229.143751
NtProtectVirtualMemory
|
process_identifier:
2080
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76354000
|
success
|
0 |
0
|
1619713229.143751
NtProtectVirtualMemory
|
process_identifier:
2080
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x005a2000
|
success
|
0 |
0
|
1619713229.143751
NtProtectVirtualMemory
|
process_identifier:
2080
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76351000
|
success
|
0 |
0
|
1619713223.658999
NtAllocateVirtualMemory
|
process_identifier:
2040
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x01e00000
|
success
|
0 |
0
|
1619713223.705999
NtProtectVirtualMemory
|
process_identifier:
2040
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
69632
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x0045c000
|
success
|
0 |
0
|
1619713223.720999
NtAllocateVirtualMemory
|
process_identifier:
2040
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x01f80000
|
success
|
0 |
0
|
1619713249.737751
NtAllocateVirtualMemory
|
process_identifier:
3208
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003e0000
|
success
|
0 |
0
|
1619713249.752751
NtProtectVirtualMemory
|
process_identifier:
3208
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
69632
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x0045c000
|
success
|
0 |
0
|
1619713249.752751
NtAllocateVirtualMemory
|
process_identifier:
3208
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00530000
|
success
|
0 |
0
|
1619713249.940874
NtProtectVirtualMemory
|
process_identifier:
3276
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00400000
|
success
|
0 |
0
|
1619713249.940874
NtAllocateVirtualMemory
|
process_identifier:
3276
region_size:
2097152
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x01ff0000
|
success
|
0 |
0
|
1619713249.940874
NtAllocateVirtualMemory
|
process_identifier:
3276
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x021b0000
|
success
|
0 |
0
|
1619713249.956874
NtAllocateVirtualMemory
|
process_identifier:
3276
region_size:
630784
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x01f00000
|
success
|
0 |
0
|
1619713249.956874
NtProtectVirtualMemory
|
process_identifier:
3276
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
602112
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01f02000
|
success
|
0 |
0
|
1619713249.956874
NtProtectVirtualMemory
|
process_identifier:
3276
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01db2000
|
success
|
0 |
0
|
1619713249.956874
NtProtectVirtualMemory
|
process_identifier:
3276
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76351000
|
success
|
0 |
0
|
1619713249.956874
NtProtectVirtualMemory
|
process_identifier:
3276
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01db2000
|
success
|
0 |
0
|
1619713249.956874
NtProtectVirtualMemory
|
process_identifier:
3276
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76353000
|
success
|
0 |
0
|
1619713249.956874
NtProtectVirtualMemory
|
process_identifier:
3276
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01db2000
|
success
|
0 |
0
|
1619713249.956874
NtProtectVirtualMemory
|
process_identifier:
3276
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76354000
|
success
|
0 |
0
|
1619713249.956874
NtProtectVirtualMemory
|
process_identifier:
3276
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01db2000
|
success
|
0 |
0
|
1619713249.956874
NtProtectVirtualMemory
|
process_identifier:
3276
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76351000
|
success
|
0 |
0
|