| Time & API |
Arguments |
Status |
Return |
Repeated |
1727110793.81275
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x6fc91000
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
844
|
success
|
0 |
0
|
1727110793.82875
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x0043a000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
844
|
success
|
0 |
0
|
1727110793.82875
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x6fc92000
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
844
|
success
|
0 |
0
|
1727110793.82875
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x00432000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
844
|
success
|
0 |
0
|
1727110793.84375
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x00442000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
844
|
success
|
0 |
0
|
1727110793.85975
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x00443000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
844
|
success
|
0 |
0
|
1727110793.85975
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x0057b000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
844
|
success
|
0 |
0
|
1727110793.85975
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x00577000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
844
|
success
|
0 |
0
|
1727110793.85975
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x0044c000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
844
|
success
|
0 |
0
|
1727110793.89075
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x00720000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
844
|
success
|
0 |
0
|
1727110793.89075
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x00444000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
844
|
success
|
0 |
0
|
1727110793.89075
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x00456000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
844
|
success
|
0 |
0
|
1727110793.90675
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x0044a000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
844
|
success
|
0 |
0
|
1727110793.90675
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x0056a000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
844
|
success
|
0 |
0
|
1727110793.90675
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x00562000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
844
|
success
|
0 |
0
|
1727110793.92275
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x00575000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
844
|
success
|
0 |
0
|
1727110793.95375
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x0043b000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
844
|
success
|
0 |
0
|
1727110793.95375
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x0045a000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
844
|
success
|
0 |
0
|
1727110793.95375
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x00457000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
844
|
success
|
0 |
0
|
1727110794.73425
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x6f6e1000
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2492
|
success
|
0 |
0
|
1727110794.73425
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x003ca000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2492
|
success
|
0 |
0
|
1727110794.73425
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x6f6e2000
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2492
|
success
|
0 |
0
|
1727110794.73425
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x003c2000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2492
|
success
|
0 |
0
|
1727110794.75025
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x003d2000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2492
|
success
|
0 |
0
|
1727110794.75025
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x003d3000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2492
|
success
|
0 |
0
|
1727110794.75025
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x0040b000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2492
|
success
|
0 |
0
|
1727110794.75025
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x00407000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2492
|
success
|
0 |
0
|
1727110794.75025
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x003dc000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2492
|
success
|
0 |
0
|
1727110794.76525
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x00560000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2492
|
success
|
0 |
0
|
1727110794.76525
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x003fa000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2492
|
success
|
0 |
0
|
1727110794.78125
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x003f2000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2492
|
success
|
0 |
0
|
1727110794.78125
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x003d4000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2492
|
success
|
0 |
0
|
1727110794.78125
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x00405000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2492
|
success
|
0 |
0
|
1727110794.79725
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x003d5000
region_size:
8192
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2492
|
success
|
0 |
0
|
1727110794.79725
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x003d7000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2492
|
success
|
0 |
0
|
1727110794.79725
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x003ea000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2492
|
success
|
0 |
0
|
1727110794.79725
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x003e7000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2492
|
success
|
0 |
0
|
1727110794.81225
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x003cb000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2492
|
success
|
0 |
0
|
1727110795.37525
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x04540000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2492
|
success
|
0 |
0
|
1727110795.37525
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x003e6000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2492
|
success
|
0 |
0
|
1727110799.39025
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x003da000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2492
|
success
|
0 |
0
|
1727110799.40625
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x003d8000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2492
|
success
|
0 |
0
|
1727110799.42225
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x04541000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2492
|
success
|
0 |
0
|
1727110799.45325
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x003c3000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2492
|
success
|
0 |
0
|
1727110799.45325
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x04542000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2492
|
success
|
0 |
0
|
1727110802.09325
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x003eb000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2492
|
success
|
0 |
0
|
1727110802.51525
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x04543000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2492
|
success
|
0 |
0
|
1727110803.01525
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x00561000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2492
|
success
|
0 |
0
|
1727110803.01525
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x7ef20000
region_size:
327680
allocation_type:
1056768
(MEM_RESERVE|MEM_TOP_DOWN)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2492
|
success
|
0 |
0
|
1727110803.01525
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x7ef20000
region_size:
4096
allocation_type:
4096
(MEM_COMMIT)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2492
|
success
|
0 |
0
|