| Time & API |
Arguments |
Status |
Return |
Repeated |
1620828828.801146
NtAllocateVirtualMemory
|
process_identifier:
1424
region_size:
65536
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0000000006d90000
|
success
|
0 |
0
|
1620829241.343375
NtProtectVirtualMemory
|
process_identifier:
1564
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x74631000
|
success
|
0 |
0
|
1620829241.625375
NtProtectVirtualMemory
|
process_identifier:
1564
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x74621000
|
success
|
0 |
0
|
1620829241.625375
NtProtectVirtualMemory
|
process_identifier:
1564
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x74611000
|
success
|
0 |
0
|
1620829241.625375
NtProtectVirtualMemory
|
process_identifier:
1564
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x745f1000
|
success
|
0 |
0
|
1620829241.625375
NtProtectVirtualMemory
|
process_identifier:
1564
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x750c1000
|
success
|
0 |
0
|
1620829241.625375
NtProtectVirtualMemory
|
process_identifier:
1564
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x74fc1000
|
success
|
0 |
0
|
1620829241.625375
NtProtectVirtualMemory
|
process_identifier:
1564
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x745e1000
|
success
|
0 |
0
|
1620829241.656375
NtProtectVirtualMemory
|
process_identifier:
1564
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x75641000
|
success
|
0 |
0
|
1620829241.953375
NtProtectVirtualMemory
|
process_identifier:
1564
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x75331000
|
success
|
0 |
0
|
1620829241.953375
NtProtectVirtualMemory
|
process_identifier:
1564
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76881000
|
success
|
0 |
0
|
1620829244.531375
NtProtectVirtualMemory
|
process_identifier:
1564
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73951000
|
success
|
0 |
0
|
1620829246.093375
NtProtectVirtualMemory
|
process_identifier:
1564
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x74591000
|
success
|
0 |
0
|