| Process injection |
Process 2308 manipulating memory of non-child process 2420 |
| Process injection |
Process 2308 manipulating memory of non-child process 2040 |
| Process injection |
Process 2308 manipulating memory of non-child process 2196 |
| Process injection |
Process 2308 manipulating memory of non-child process 2340 |
| Process injection |
Process 2308 manipulating memory of non-child process 944 |
| Process injection |
Process 2308 manipulating memory of non-child process 1824 |
| Process injection |
Process 2308 manipulating memory of non-child process 2764 |
| Process injection |
Process 2308 manipulating memory of non-child process 1760 |
| Process injection |
Process 2308 manipulating memory of non-child process 1932 |
| Process injection |
Process 2308 manipulating memory of non-child process 2864 |
| Process injection |
Process 2308 manipulating memory of non-child process 3100 |
| Process injection |
Process 2308 manipulating memory of non-child process 3136 |
| Process injection |
Process 2308 manipulating memory of non-child process 3172 |
| Process injection |
Process 2308 manipulating memory of non-child process 3220 |
| Process injection |
Process 2308 manipulating memory of non-child process 3264 |
| Process injection |
Process 2308 manipulating memory of non-child process 3352 |
| Process injection |
Process 2308 manipulating memory of non-child process 3416 |
| Process injection |
Process 2308 manipulating memory of non-child process 3468 |
| Process injection |
Process 2308 manipulating memory of non-child process 3504 |
| Time & API |
Arguments |
Status |
Return |
Repeated |
1619816647.399625
NtAllocateVirtualMemory
|
process_identifier:
2420
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x0000013c
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000a0000
|
success
|
0 |
0
|
1619816647.431625
NtAllocateVirtualMemory
|
process_identifier:
2040
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x00000150
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000a0000
|
success
|
0 |
0
|
1619816647.462625
NtAllocateVirtualMemory
|
process_identifier:
2196
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x0000015c
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000a0000
|
success
|
0 |
0
|
1619816647.571625
NtAllocateVirtualMemory
|
process_identifier:
2340
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x00000168
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000a0000
|
success
|
0 |
0
|
1619816647.649625
NtAllocateVirtualMemory
|
process_identifier:
944
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x00000174
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000a0000
|
success
|
0 |
0
|
1619816647.712625
NtAllocateVirtualMemory
|
process_identifier:
1824
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x00000180
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000a0000
|
success
|
0 |
0
|
1619816647.759625
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x0000018c
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000a0000
|
success
|
0 |
0
|
1619816647.837625
NtAllocateVirtualMemory
|
process_identifier:
1760
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x00000198
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000a0000
|
success
|
0 |
0
|
1619816647.852625
NtAllocateVirtualMemory
|
process_identifier:
1932
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x000001a4
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000a0000
|
success
|
0 |
0
|
1619816647.899625
NtAllocateVirtualMemory
|
process_identifier:
2864
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x000001b0
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000e0000
|
success
|
0 |
0
|
1619816647.977625
NtAllocateVirtualMemory
|
process_identifier:
3100
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x000001bc
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000a0000
|
success
|
0 |
0
|
1619816648.009625
NtAllocateVirtualMemory
|
process_identifier:
3136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x000001c8
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000e0000
|
success
|
0 |
0
|
1619816648.040625
NtAllocateVirtualMemory
|
process_identifier:
3172
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x000001d4
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000e0000
|
success
|
0 |
0
|
1619816648.071625
NtAllocateVirtualMemory
|
process_identifier:
3220
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x000001e0
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000a0000
|
success
|
0 |
0
|
1619816648.134625
NtAllocateVirtualMemory
|
process_identifier:
3264
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x000001ec
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000e0000
|
success
|
0 |
0
|
1619816648.165625
NtAllocateVirtualMemory
|
process_identifier:
3352
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x000001f8
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000a0000
|
success
|
0 |
0
|
1619816648.212625
NtAllocateVirtualMemory
|
process_identifier:
3416
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x00000204
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000a0000
|
success
|
0 |
0
|
1619816648.227625
NtAllocateVirtualMemory
|
process_identifier:
3468
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x00000210
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000a0000
|
success
|
0 |
0
|
1619816648.243625
NtAllocateVirtualMemory
|
process_identifier:
3504
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x0000021c
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000e0000
|
success
|
0 |
0
|