Time & API |
Arguments |
Status |
Return |
Repeated |
1727545269.81275
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x6fc91000
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1612
|
success
|
0 |
0
|
1727545269.81275
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x002fa000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1612
|
success
|
0 |
0
|
1727545269.81275
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x6fc92000
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1612
|
success
|
0 |
0
|
1727545269.81275
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x002f2000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1612
|
success
|
0 |
0
|
1727545269.84375
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x00402000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1612
|
success
|
0 |
0
|
1727545269.84375
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x00403000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1612
|
success
|
0 |
0
|
1727545269.84375
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x0043b000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1612
|
success
|
0 |
0
|
1727545269.84375
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x00437000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1612
|
success
|
0 |
0
|
1727545269.84375
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x0040c000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1612
|
success
|
0 |
0
|
1727545269.87475
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x006a0000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1612
|
success
|
0 |
0
|
1727545269.89075
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x00404000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1612
|
success
|
0 |
0
|
1727545269.89075
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x00416000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1612
|
success
|
0 |
0
|
1727545269.89075
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x0040a000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1612
|
success
|
0 |
0
|
1727545269.90675
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x0042a000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1612
|
success
|
0 |
0
|
1727545269.90675
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x00422000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1612
|
success
|
0 |
0
|
1727545269.92175
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x00435000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1612
|
success
|
0 |
0
|
1727545269.95375
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x002fb000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1612
|
success
|
0 |
0
|
1727545269.95375
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x0041a000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1612
|
success
|
0 |
0
|
1727545269.95375
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x00417000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1612
|
success
|
0 |
0
|
1727545270.749875
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x6f6e1000
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1384
|
success
|
0 |
0
|
1727545270.765875
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x002aa000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1384
|
success
|
0 |
0
|
1727545270.765875
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x6f6e2000
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1384
|
success
|
0 |
0
|
1727545270.765875
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x002a2000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1384
|
success
|
0 |
0
|
1727545270.765875
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x002b2000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1384
|
success
|
0 |
0
|
1727545270.781875
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x002b3000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1384
|
success
|
0 |
0
|
1727545270.781875
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x002eb000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1384
|
success
|
0 |
0
|
1727545270.781875
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x002e7000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1384
|
success
|
0 |
0
|
1727545270.781875
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x002bc000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1384
|
success
|
0 |
0
|
1727545270.796875
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x00970000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1384
|
success
|
0 |
0
|
1727545270.796875
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x002da000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1384
|
success
|
0 |
0
|
1727545270.796875
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x002d2000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1384
|
success
|
0 |
0
|
1727545270.796875
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x002b4000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1384
|
success
|
0 |
0
|
1727545270.796875
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x002e5000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1384
|
success
|
0 |
0
|
1727545270.828875
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x002b5000
region_size:
8192
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1384
|
success
|
0 |
0
|
1727545270.828875
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x002b7000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1384
|
success
|
0 |
0
|
1727545270.828875
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x002ca000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1384
|
success
|
0 |
0
|
1727545270.828875
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x002c7000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1384
|
success
|
0 |
0
|
1727545270.843875
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x002ab000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1384
|
success
|
0 |
0
|
1727545271.484875
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x04680000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1384
|
success
|
0 |
0
|
1727545271.484875
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x002c6000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1384
|
success
|
0 |
0
|
1727545275.499875
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x002ba000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1384
|
success
|
0 |
0
|
1727545275.515875
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x002b8000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1384
|
success
|
0 |
0
|
1727545275.546875
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x04681000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1384
|
success
|
0 |
0
|
1727545275.593875
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x002a3000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1384
|
success
|
0 |
0
|
1727545275.593875
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x04682000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1384
|
success
|
0 |
0
|
1727545278.249875
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x002cb000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1384
|
success
|
0 |
0
|
1727545278.656875
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x04683000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1384
|
success
|
0 |
0
|
1727545279.171875
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x00971000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1384
|
success
|
0 |
0
|
1727545279.171875
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x7ef20000
region_size:
327680
allocation_type:
1056768
(MEM_RESERVE|MEM_TOP_DOWN)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1384
|
success
|
0 |
0
|
1727545279.171875
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x7ef20000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
1384
|
success
|
0 |
0
|