| Time & API |
Arguments |
Status |
Return |
Repeated |
1619781067.765886
NtAllocateVirtualMemory
|
process_identifier:
732
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005e0000
|
success
|
0 |
0
|
1619781067.937886
NtProtectVirtualMemory
|
process_identifier:
732
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
73728
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00476000
|
success
|
0 |
0
|
1619781067.937886
NtAllocateVirtualMemory
|
process_identifier:
732
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x01e50000
|
success
|
0 |
0
|
1619796562.0155
NtAllocateVirtualMemory
|
process_identifier:
944
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003e0000
|
success
|
0 |
0
|
1619796562.0465
NtProtectVirtualMemory
|
process_identifier:
944
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
73728
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00476000
|
success
|
0 |
0
|
1619796562.0465
NtAllocateVirtualMemory
|
process_identifier:
944
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00530000
|
success
|
0 |
0
|
1619796563.5775
NtProtectVirtualMemory
|
process_identifier:
520
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00400000
|
success
|
0 |
0
|
1619796563.7185
NtAllocateVirtualMemory
|
process_identifier:
520
region_size:
393216
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00650000
|
success
|
0 |
0
|
1619796563.7185
NtAllocateVirtualMemory
|
process_identifier:
520
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00670000
|
success
|
0 |
0
|
1619796563.7185
NtAllocateVirtualMemory
|
process_identifier:
520
region_size:
630784
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x01f70000
|
success
|
0 |
0
|
1619796563.7185
NtProtectVirtualMemory
|
process_identifier:
520
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
602112
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01f72000
|
success
|
0 |
0
|
1619796564.3435
NtProtectVirtualMemory
|
process_identifier:
520
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x003e2000
|
success
|
0 |
0
|
1619796564.3435
NtProtectVirtualMemory
|
process_identifier:
520
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76351000
|
success
|
0 |
0
|
1619796564.3435
NtProtectVirtualMemory
|
process_identifier:
520
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x003e2000
|
success
|
0 |
0
|
1619796564.3435
NtProtectVirtualMemory
|
process_identifier:
520
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76353000
|
success
|
0 |
0
|
1619796564.3435
NtProtectVirtualMemory
|
process_identifier:
520
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x003e2000
|
success
|
0 |
0
|
1619796564.3435
NtProtectVirtualMemory
|
process_identifier:
520
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76354000
|
success
|
0 |
0
|
1619796564.3435
NtProtectVirtualMemory
|
process_identifier:
520
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x003e2000
|
success
|
0 |
0
|
1619796564.3435
NtProtectVirtualMemory
|
process_identifier:
520
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76351000
|
success
|
0 |
0
|
1619796564.3435
NtProtectVirtualMemory
|
process_identifier:
520
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x003e2000
|
success
|
0 |
0
|
1619796564.3435
NtProtectVirtualMemory
|
process_identifier:
520
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x77d4f000
|
success
|
0 |
0
|
1619796564.3435
NtProtectVirtualMemory
|
process_identifier:
520
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x003e2000
|
success
|
0 |
0
|
1619796564.3435
NtProtectVirtualMemory
|
process_identifier:
520
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76353000
|
success
|
0 |
0
|
1619796564.3435
NtProtectVirtualMemory
|
process_identifier:
520
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x003e2000
|
success
|
0 |
0
|
1619796564.3435
NtProtectVirtualMemory
|
process_identifier:
520
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76351000
|
success
|
0 |
0
|
1619796564.3435
NtProtectVirtualMemory
|
process_identifier:
520
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x003e2000
|
success
|
0 |
0
|
1619796564.3435
NtProtectVirtualMemory
|
process_identifier:
520
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76351000
|
success
|
0 |
0
|
1619796564.3435
NtProtectVirtualMemory
|
process_identifier:
520
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x003e2000
|
success
|
0 |
0
|
1619796564.3435
NtProtectVirtualMemory
|
process_identifier:
520
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76354000
|
success
|
0 |
0
|
1619796564.3435
NtProtectVirtualMemory
|
process_identifier:
520
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x003e2000
|
success
|
0 |
0
|
1619796564.3435
NtProtectVirtualMemory
|
process_identifier:
520
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76351000
|
success
|
0 |
0
|
1619796564.45275
NtAllocateVirtualMemory
|
process_identifier:
1380
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003e0000
|
success
|
0 |
0
|
1619796564.46875
NtProtectVirtualMemory
|
process_identifier:
1380
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
73728
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00476000
|
success
|
0 |
0
|
1619796564.46875
NtAllocateVirtualMemory
|
process_identifier:
1380
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00630000
|
success
|
0 |
0
|
1619796572.1085
NtAllocateVirtualMemory
|
process_identifier:
3188
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00360000
|
success
|
0 |
0
|
1619796572.3115
NtProtectVirtualMemory
|
process_identifier:
3188
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
73728
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00476000
|
success
|
0 |
0
|
1619796572.3585
NtAllocateVirtualMemory
|
process_identifier:
3188
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x01ea0000
|
success
|
0 |
0
|
1619796574.562125
NtProtectVirtualMemory
|
process_identifier:
3264
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00400000
|
success
|
0 |
0
|
1619796574.641125
NtAllocateVirtualMemory
|
process_identifier:
3264
region_size:
2031616
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x02190000
|
success
|
0 |
0
|
1619796574.641125
NtAllocateVirtualMemory
|
process_identifier:
3264
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02340000
|
success
|
0 |
0
|
1619796574.656125
NtAllocateVirtualMemory
|
process_identifier:
3264
region_size:
630784
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x007d0000
|
success
|
0 |
0
|
1619796574.672125
NtProtectVirtualMemory
|
process_identifier:
3264
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
602112
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x007d2000
|
success
|
0 |
0
|
1619796574.875125
NtProtectVirtualMemory
|
process_identifier:
3264
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x02182000
|
success
|
0 |
0
|
1619796574.875125
NtProtectVirtualMemory
|
process_identifier:
3264
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76351000
|
success
|
0 |
0
|
1619796574.875125
NtProtectVirtualMemory
|
process_identifier:
3264
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x02182000
|
success
|
0 |
0
|
1619796574.875125
NtProtectVirtualMemory
|
process_identifier:
3264
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76353000
|
success
|
0 |
0
|
1619796574.875125
NtProtectVirtualMemory
|
process_identifier:
3264
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x02182000
|
success
|
0 |
0
|
1619796574.875125
NtProtectVirtualMemory
|
process_identifier:
3264
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76354000
|
success
|
0 |
0
|
1619796574.875125
NtProtectVirtualMemory
|
process_identifier:
3264
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x02182000
|
success
|
0 |
0
|
1619796574.875125
NtProtectVirtualMemory
|
process_identifier:
3264
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76351000
|
success
|
0 |
0
|