| Time & API |
Arguments |
Status |
Return |
Repeated |
1619686131.641567
NtAllocateVirtualMemory
|
process_identifier:
428
region_size:
851968
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00460000
|
success
|
0 |
0
|
1619686131.641567
NtAllocateVirtualMemory
|
process_identifier:
428
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004f0000
|
success
|
0 |
0
|
1619686132.391567
NtProtectVirtualMemory
|
process_identifier:
428
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73f31000
|
success
|
0 |
0
|
1619686132.610567
NtAllocateVirtualMemory
|
process_identifier:
428
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003ba000
|
success
|
0 |
0
|
1619686132.610567
NtProtectVirtualMemory
|
process_identifier:
428
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73f32000
|
success
|
0 |
0
|
1619686132.610567
NtAllocateVirtualMemory
|
process_identifier:
428
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003b2000
|
success
|
0 |
0
|
1619686132.860567
NtAllocateVirtualMemory
|
process_identifier:
428
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003c2000
|
success
|
0 |
0
|
1619686132.953567
NtAllocateVirtualMemory
|
process_identifier:
428
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003c3000
|
success
|
0 |
0
|
1619686132.969567
NtAllocateVirtualMemory
|
process_identifier:
428
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0047b000
|
success
|
0 |
0
|
1619686132.969567
NtAllocateVirtualMemory
|
process_identifier:
428
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00477000
|
success
|
0 |
0
|
1619686132.985567
NtAllocateVirtualMemory
|
process_identifier:
428
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003cc000
|
success
|
0 |
0
|
1619686133.063567
NtAllocateVirtualMemory
|
process_identifier:
428
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00780000
|
success
|
0 |
0
|
1619686133.203567
NtAllocateVirtualMemory
|
process_identifier:
428
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003c4000
|
success
|
0 |
0
|
1619686133.219567
NtAllocateVirtualMemory
|
process_identifier:
428
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00781000
|
success
|
0 |
0
|
1619686133.250567
NtAllocateVirtualMemory
|
process_identifier:
428
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003ca000
|
success
|
0 |
0
|
1619686133.297567
NtProtectVirtualMemory
|
process_identifier:
428
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
413696
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00cb2000
|
success
|
0 |
0
|
1619686139.860567
NtAllocateVirtualMemory
|
process_identifier:
428
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00782000
|
success
|
0 |
0
|
1619686139.875567
NtAllocateVirtualMemory
|
process_identifier:
428
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003c5000
|
success
|
0 |
0
|
1619686139.875567
NtAllocateVirtualMemory
|
process_identifier:
428
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00783000
|
success
|
0 |
0
|
1619686139.875567
NtAllocateVirtualMemory
|
process_identifier:
428
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00784000
|
success
|
0 |
0
|
1619686140.016567
NtAllocateVirtualMemory
|
process_identifier:
428
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00785000
|
success
|
0 |
0
|
1619686140.032567
NtAllocateVirtualMemory
|
process_identifier:
428
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00786000
|
success
|
0 |
0
|
1619686140.594567
NtAllocateVirtualMemory
|
process_identifier:
428
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00787000
|
success
|
0 |
0
|
1619686140.594567
NtAllocateVirtualMemory
|
process_identifier:
428
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00789000
|
success
|
0 |
0
|
1619686140.594567
NtProtectVirtualMemory
|
process_identifier:
428
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00d18000
|
success
|
0 |
0
|
1619686140.594567
NtProtectVirtualMemory
|
process_identifier:
428
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00d18000
|
success
|
0 |
0
|
1619686140.594567
NtProtectVirtualMemory
|
process_identifier:
428
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00cb0000
|
success
|
0 |
0
|
1619686140.610567
NtProtectVirtualMemory
|
process_identifier:
428
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00cb0000
|
success
|
0 |
0
|
1619686140.610567
NtProtectVirtualMemory
|
process_identifier:
428
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00cb0000
|
success
|
0 |
0
|
1619686140.610567
NtProtectVirtualMemory
|
process_identifier:
428
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00cb0000
|
success
|
0 |
0
|
1619686140.610567
NtProtectVirtualMemory
|
process_identifier:
428
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00cb0000
|
success
|
0 |
0
|
1619686140.610567
NtProtectVirtualMemory
|
process_identifier:
428
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00d18000
|
success
|
0 |
0
|
1619686140.610567
NtProtectVirtualMemory
|
process_identifier:
428
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00d18000
|
success
|
0 |
0
|
1619686140.610567
NtProtectVirtualMemory
|
process_identifier:
428
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00d18000
|
success
|
0 |
0
|
1619686140.610567
NtProtectVirtualMemory
|
process_identifier:
428
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00d18000
|
success
|
0 |
0
|
1619686140.610567
NtProtectVirtualMemory
|
process_identifier:
428
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00d18000
|
success
|
0 |
0
|
1619686140.610567
NtProtectVirtualMemory
|
process_identifier:
428
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00d18000
|
success
|
0 |
0
|
1619686140.610567
NtProtectVirtualMemory
|
process_identifier:
428
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00d18000
|
success
|
0 |
0
|
1619686140.610567
NtProtectVirtualMemory
|
process_identifier:
428
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00d18000
|
success
|
0 |
0
|
1619686140.610567
NtProtectVirtualMemory
|
process_identifier:
428
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00d18000
|
success
|
0 |
0
|
1619686140.610567
NtProtectVirtualMemory
|
process_identifier:
428
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00d18000
|
success
|
0 |
0
|
1619686140.610567
NtProtectVirtualMemory
|
process_identifier:
428
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00d18000
|
success
|
0 |
0
|
1619686140.610567
NtProtectVirtualMemory
|
process_identifier:
428
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00d18000
|
success
|
0 |
0
|
1619686140.610567
NtProtectVirtualMemory
|
process_identifier:
428
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00d18000
|
success
|
0 |
0
|
1619686140.610567
NtProtectVirtualMemory
|
process_identifier:
428
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00d18000
|
success
|
0 |
0
|
1619686140.610567
NtProtectVirtualMemory
|
process_identifier:
428
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00d18000
|
success
|
0 |
0
|
1619686140.610567
NtProtectVirtualMemory
|
process_identifier:
428
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00d18000
|
success
|
0 |
0
|
1619686140.610567
NtProtectVirtualMemory
|
process_identifier:
428
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00d18000
|
success
|
0 |
0
|
1619686140.610567
NtProtectVirtualMemory
|
process_identifier:
428
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00d18000
|
success
|
0 |
0
|
1619686140.610567
NtProtectVirtualMemory
|
process_identifier:
428
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00d18000
|
success
|
0 |
0
|