| Time & API |
Arguments |
Status |
Return |
Repeated |
1619803340.287
NtAllocateVirtualMemory
|
process_identifier:
796
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003e0000
|
success
|
0 |
0
|
1619803340.49
NtProtectVirtualMemory
|
process_identifier:
796
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00461000
|
success
|
0 |
0
|
1619803340.49
NtAllocateVirtualMemory
|
process_identifier:
796
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x02e50000
|
success
|
0 |
0
|
1619803341.397125
NtAllocateVirtualMemory
|
process_identifier:
708
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003d0000
|
success
|
0 |
0
|
1619803341.428125
NtProtectVirtualMemory
|
process_identifier:
708
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00461000
|
success
|
0 |
0
|
1619803341.428125
NtAllocateVirtualMemory
|
process_identifier:
708
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00590000
|
success
|
0 |
0
|
1619803343.037
NtProtectVirtualMemory
|
process_identifier:
2960
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00400000
|
success
|
0 |
0
|
1619803343.131
NtAllocateVirtualMemory
|
process_identifier:
2960
region_size:
1638400
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x02080000
|
success
|
0 |
0
|
1619803343.131
NtAllocateVirtualMemory
|
process_identifier:
2960
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x021d0000
|
success
|
0 |
0
|
1619803343.131
NtAllocateVirtualMemory
|
process_identifier:
2960
region_size:
630784
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x01f50000
|
success
|
0 |
0
|
1619803343.131
NtProtectVirtualMemory
|
process_identifier:
2960
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
602112
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01f52000
|
success
|
0 |
0
|
1619803348.444
NtProtectVirtualMemory
|
process_identifier:
2960
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x02072000
|
success
|
0 |
0
|
1619803348.444
NtProtectVirtualMemory
|
process_identifier:
2960
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76351000
|
success
|
0 |
0
|
1619803348.444
NtProtectVirtualMemory
|
process_identifier:
2960
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x02072000
|
success
|
0 |
0
|
1619803348.444
NtProtectVirtualMemory
|
process_identifier:
2960
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76353000
|
success
|
0 |
0
|
1619803348.444
NtProtectVirtualMemory
|
process_identifier:
2960
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x02072000
|
success
|
0 |
0
|
1619803348.444
NtProtectVirtualMemory
|
process_identifier:
2960
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76354000
|
success
|
0 |
0
|
1619803348.444
NtProtectVirtualMemory
|
process_identifier:
2960
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x02072000
|
success
|
0 |
0
|
1619803348.444
NtProtectVirtualMemory
|
process_identifier:
2960
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76351000
|
success
|
0 |
0
|
1619803348.444
NtProtectVirtualMemory
|
process_identifier:
2960
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x02072000
|
success
|
0 |
0
|
1619803348.444
NtProtectVirtualMemory
|
process_identifier:
2960
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x77d4f000
|
success
|
0 |
0
|
1619803348.444
NtProtectVirtualMemory
|
process_identifier:
2960
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x02072000
|
success
|
0 |
0
|
1619803348.444
NtProtectVirtualMemory
|
process_identifier:
2960
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76353000
|
success
|
0 |
0
|
1619803348.444
NtProtectVirtualMemory
|
process_identifier:
2960
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x02072000
|
success
|
0 |
0
|
1619803348.444
NtProtectVirtualMemory
|
process_identifier:
2960
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76351000
|
success
|
0 |
0
|
1619803348.444
NtProtectVirtualMemory
|
process_identifier:
2960
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x02072000
|
success
|
0 |
0
|
1619803348.444
NtProtectVirtualMemory
|
process_identifier:
2960
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76351000
|
success
|
0 |
0
|
1619803348.444
NtProtectVirtualMemory
|
process_identifier:
2960
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x02072000
|
success
|
0 |
0
|
1619803348.444
NtProtectVirtualMemory
|
process_identifier:
2960
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76354000
|
success
|
0 |
0
|
1619803348.444
NtProtectVirtualMemory
|
process_identifier:
2960
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x02072000
|
success
|
0 |
0
|
1619803348.444
NtProtectVirtualMemory
|
process_identifier:
2960
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76351000
|
success
|
0 |
0
|
1619803343.083875
NtAllocateVirtualMemory
|
process_identifier:
2496
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003d0000
|
success
|
0 |
0
|
1619803343.099875
NtProtectVirtualMemory
|
process_identifier:
2496
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00461000
|
success
|
0 |
0
|
1619803343.099875
NtAllocateVirtualMemory
|
process_identifier:
2496
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x007c0000
|
success
|
0 |
0
|
1619803356.787498
NtAllocateVirtualMemory
|
process_identifier:
3212
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00370000
|
success
|
0 |
0
|
1619803356.803498
NtProtectVirtualMemory
|
process_identifier:
3212
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00461000
|
success
|
0 |
0
|
1619803356.803498
NtAllocateVirtualMemory
|
process_identifier:
3212
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x01fa0000
|
success
|
0 |
0
|
1619803357.88125
NtProtectVirtualMemory
|
process_identifier:
3284
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00400000
|
success
|
0 |
0
|
1619803357.89725
NtAllocateVirtualMemory
|
process_identifier:
3284
region_size:
2293760
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x02000000
|
success
|
0 |
0
|
1619803357.89725
NtAllocateVirtualMemory
|
process_identifier:
3284
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x021f0000
|
success
|
0 |
0
|
1619803357.89725
NtAllocateVirtualMemory
|
process_identifier:
3284
region_size:
630784
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x01f40000
|
success
|
0 |
0
|
1619803357.89725
NtProtectVirtualMemory
|
process_identifier:
3284
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
602112
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01f42000
|
success
|
0 |
0
|
1619803357.94425
NtProtectVirtualMemory
|
process_identifier:
3284
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01ff2000
|
success
|
0 |
0
|
1619803357.94425
NtProtectVirtualMemory
|
process_identifier:
3284
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76351000
|
success
|
0 |
0
|
1619803357.94425
NtProtectVirtualMemory
|
process_identifier:
3284
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01ff2000
|
success
|
0 |
0
|
1619803357.94425
NtProtectVirtualMemory
|
process_identifier:
3284
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76353000
|
success
|
0 |
0
|
1619803357.94425
NtProtectVirtualMemory
|
process_identifier:
3284
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01ff2000
|
success
|
0 |
0
|
1619803357.94425
NtProtectVirtualMemory
|
process_identifier:
3284
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76354000
|
success
|
0 |
0
|
1619803357.94425
NtProtectVirtualMemory
|
process_identifier:
3284
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01ff2000
|
success
|
0 |
0
|
1619803357.94425
NtProtectVirtualMemory
|
process_identifier:
3284
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76351000
|
success
|
0 |
0
|