| Time & API |
Arguments |
Status |
Return |
Repeated |
1619781072.530531
NtAllocateVirtualMemory
|
process_identifier:
1912
region_size:
176128
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00000000025a0000
|
success
|
0 |
0
|
1619781072.842531
NtProtectVirtualMemory
|
process_identifier:
1912
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feff1e6000
|
success
|
0 |
0
|
1619781072.842531
NtProtectVirtualMemory
|
process_identifier:
1912
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feff1e7000
|
success
|
0 |
0
|
1619781072.920531
NtProtectVirtualMemory
|
process_identifier:
1912
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feff183000
|
success
|
0 |
0
|
1619781072.920531
NtProtectVirtualMemory
|
process_identifier:
1912
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feff183000
|
success
|
0 |
0
|
1619781072.920531
NtProtectVirtualMemory
|
process_identifier:
1912
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feff165000
|
success
|
0 |
0
|
1619781072.920531
NtProtectVirtualMemory
|
process_identifier:
1912
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feff1cf000
|
success
|
0 |
0
|
1619781072.936531
NtProtectVirtualMemory
|
process_identifier:
1912
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feff173000
|
success
|
0 |
0
|
1619781072.936531
NtProtectVirtualMemory
|
process_identifier:
1912
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feff165000
|
success
|
0 |
0
|
1619781072.952531
NtProtectVirtualMemory
|
process_identifier:
1912
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feff183000
|
success
|
0 |
0
|
1619781072.952531
NtProtectVirtualMemory
|
process_identifier:
1912
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feff183000
|
success
|
0 |
0
|
1619781072.952531
NtProtectVirtualMemory
|
process_identifier:
1912
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feff1b0000
|
success
|
0 |
0
|
1619781072.952531
NtProtectVirtualMemory
|
process_identifier:
1912
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feff15c000
|
success
|
0 |
0
|
1619781072.952531
NtProtectVirtualMemory
|
process_identifier:
1912
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feff15f000
|
success
|
0 |
0
|
1619781072.952531
NtProtectVirtualMemory
|
process_identifier:
1912
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feff1aa000
|
success
|
0 |
0
|
1619781072.952531
NtProtectVirtualMemory
|
process_identifier:
1912
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feff15f000
|
success
|
0 |
0
|
1619781072.967531
NtProtectVirtualMemory
|
process_identifier:
1912
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feff169000
|
success
|
0 |
0
|
1619781072.967531
NtProtectVirtualMemory
|
process_identifier:
1912
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feff16b000
|
success
|
0 |
0
|
1619781072.967531
NtProtectVirtualMemory
|
process_identifier:
1912
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feff1b2000
|
success
|
0 |
0
|
1619781072.967531
NtProtectVirtualMemory
|
process_identifier:
1912
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feff181000
|
success
|
0 |
0
|
1619781072.967531
NtProtectVirtualMemory
|
process_identifier:
1912
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feff15e000
|
success
|
0 |
0
|
1619781072.967531
NtProtectVirtualMemory
|
process_identifier:
1912
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feff163000
|
success
|
0 |
0
|
1619781072.967531
NtProtectVirtualMemory
|
process_identifier:
1912
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feff15f000
|
success
|
0 |
0
|
1619781072.983531
NtProtectVirtualMemory
|
process_identifier:
1912
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feff182000
|
success
|
0 |
0
|
1619781072.983531
NtProtectVirtualMemory
|
process_identifier:
1912
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feff185000
|
success
|
0 |
0
|
1619781073.186531
NtProtectVirtualMemory
|
process_identifier:
1912
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feffb1b000
|
success
|
0 |
0
|
1619781073.202531
NtProtectVirtualMemory
|
process_identifier:
1912
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feffb03000
|
success
|
0 |
0
|
1619781073.217531
NtProtectVirtualMemory
|
process_identifier:
1912
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feffae8000
|
success
|
0 |
0
|
1619781073.233531
NtProtectVirtualMemory
|
process_identifier:
1912
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feffaed000
|
success
|
0 |
0
|
1619781073.233531
NtProtectVirtualMemory
|
process_identifier:
1912
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feffaed000
|
success
|
0 |
0
|
1619781073.233531
NtProtectVirtualMemory
|
process_identifier:
1912
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feffb1b000
|
success
|
0 |
0
|
1619781073.233531
NtProtectVirtualMemory
|
process_identifier:
1912
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feffb1b000
|
success
|
0 |
0
|
1619781073.233531
NtProtectVirtualMemory
|
process_identifier:
1912
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feffae8000
|
success
|
0 |
0
|
1619781073.280531
NtProtectVirtualMemory
|
process_identifier:
1912
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feffb2d000
|
success
|
0 |
0
|
1619781073.280531
NtProtectVirtualMemory
|
process_identifier:
1912
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feffb2d000
|
success
|
0 |
0
|
1619781073.342531
NtProtectVirtualMemory
|
process_identifier:
1912
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feffaed000
|
success
|
0 |
0
|
1619781073.342531
NtProtectVirtualMemory
|
process_identifier:
1912
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feffaf1000
|
success
|
0 |
0
|
1619781073.373531
NtProtectVirtualMemory
|
process_identifier:
1912
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feffafb000
|
success
|
0 |
0
|
1619781073.389531
NtProtectVirtualMemory
|
process_identifier:
1912
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feffafb000
|
success
|
0 |
0
|
1619781073.436531
NtProtectVirtualMemory
|
process_identifier:
1912
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feffae3000
|
success
|
0 |
0
|
1619781073.467531
NtProtectVirtualMemory
|
process_identifier:
1912
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feffb00000
|
success
|
0 |
0
|
1619781073.467531
NtProtectVirtualMemory
|
process_identifier:
1912
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feffaf1000
|
success
|
0 |
0
|
1619781073.467531
NtProtectVirtualMemory
|
process_identifier:
1912
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feffafb000
|
success
|
0 |
0
|
1619781073.467531
NtProtectVirtualMemory
|
process_identifier:
1912
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feffb06000
|
success
|
0 |
0
|
1619781073.467531
NtProtectVirtualMemory
|
process_identifier:
1912
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feffaf1000
|
success
|
0 |
0
|
1619781073.467531
NtProtectVirtualMemory
|
process_identifier:
1912
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feffaf1000
|
success
|
0 |
0
|
1619781073.467531
NtProtectVirtualMemory
|
process_identifier:
1912
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feffafc000
|
success
|
0 |
0
|
1619781073.467531
NtProtectVirtualMemory
|
process_identifier:
1912
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feffafb000
|
success
|
0 |
0
|
1619781073.467531
NtProtectVirtualMemory
|
process_identifier:
1912
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feffaed000
|
success
|
0 |
0
|
1619781073.467531
NtProtectVirtualMemory
|
process_identifier:
1912
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feffafc000
|
success
|
0 |
0
|