| Time & API |
Arguments |
Status |
Return |
Repeated |
1620808775.46925
NtAllocateVirtualMemory
|
process_identifier:
2368
region_size:
786432
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x004b0000
|
success
|
0 |
0
|
1620808775.46925
NtAllocateVirtualMemory
|
process_identifier:
2368
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00530000
|
success
|
0 |
0
|
1620808776.67225
NtProtectVirtualMemory
|
process_identifier:
2368
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73c51000
|
success
|
0 |
0
|
1620808776.85925
NtAllocateVirtualMemory
|
process_identifier:
2368
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002ba000
|
success
|
0 |
0
|
1620808776.85925
NtProtectVirtualMemory
|
process_identifier:
2368
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73c52000
|
success
|
0 |
0
|
1620808776.85925
NtAllocateVirtualMemory
|
process_identifier:
2368
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002b2000
|
success
|
0 |
0
|
1620808778.29725
NtAllocateVirtualMemory
|
process_identifier:
2368
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002c2000
|
success
|
0 |
0
|
1620808778.35925
NtAllocateVirtualMemory
|
process_identifier:
2368
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002c3000
|
success
|
0 |
0
|
1620808778.37525
NtAllocateVirtualMemory
|
process_identifier:
2368
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003ab000
|
success
|
0 |
0
|
1620808778.37525
NtAllocateVirtualMemory
|
process_identifier:
2368
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003a7000
|
success
|
0 |
0
|
1620808778.40625
NtAllocateVirtualMemory
|
process_identifier:
2368
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002cc000
|
success
|
0 |
0
|
1620808778.46925
NtAllocateVirtualMemory
|
process_identifier:
2368
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00860000
|
success
|
0 |
0
|
1620808778.67225
NtAllocateVirtualMemory
|
process_identifier:
2368
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002c4000
|
success
|
0 |
0
|
1620808778.68825
NtAllocateVirtualMemory
|
process_identifier:
2368
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00861000
|
success
|
0 |
0
|
1620808778.70325
NtAllocateVirtualMemory
|
process_identifier:
2368
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002ca000
|
success
|
0 |
0
|
1620808778.76625
NtProtectVirtualMemory
|
process_identifier:
2368
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
520192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x002f2000
|
success
|
0 |
0
|
1620808782.89125
NtAllocateVirtualMemory
|
process_identifier:
2368
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00862000
|
success
|
0 |
0
|
1620808782.92225
NtAllocateVirtualMemory
|
process_identifier:
2368
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00863000
|
success
|
0 |
0
|
1620808782.92225
NtAllocateVirtualMemory
|
process_identifier:
2368
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00864000
|
success
|
0 |
0
|
1620808782.96925
NtAllocateVirtualMemory
|
process_identifier:
2368
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00865000
|
success
|
0 |
0
|
1620808783.17225
NtAllocateVirtualMemory
|
process_identifier:
2368
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002c5000
|
success
|
0 |
0
|
1620808783.18825
NtAllocateVirtualMemory
|
process_identifier:
2368
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00866000
|
success
|
0 |
0
|
1620808783.21925
NtAllocateVirtualMemory
|
process_identifier:
2368
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00867000
|
success
|
0 |
0
|
1620808783.21925
NtAllocateVirtualMemory
|
process_identifier:
2368
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00869000
|
success
|
0 |
0
|
1620808783.21925
NtProtectVirtualMemory
|
process_identifier:
2368
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00372000
|
success
|
0 |
0
|
1620808783.21925
NtProtectVirtualMemory
|
process_identifier:
2368
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00372000
|
success
|
0 |
0
|
1620808783.21925
NtProtectVirtualMemory
|
process_identifier:
2368
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x002f0000
|
success
|
0 |
0
|
1620808783.21925
NtProtectVirtualMemory
|
process_identifier:
2368
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x002f0000
|
success
|
0 |
0
|
1620808783.21925
NtProtectVirtualMemory
|
process_identifier:
2368
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x002f0000
|
success
|
0 |
0
|
1620808783.21925
NtProtectVirtualMemory
|
process_identifier:
2368
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x002f0000
|
success
|
0 |
0
|
1620808783.21925
NtProtectVirtualMemory
|
process_identifier:
2368
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x002f0000
|
success
|
0 |
0
|
1620808783.21925
NtProtectVirtualMemory
|
process_identifier:
2368
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00372000
|
success
|
0 |
0
|
1620808783.21925
NtProtectVirtualMemory
|
process_identifier:
2368
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00372000
|
success
|
0 |
0
|
1620808783.21925
NtProtectVirtualMemory
|
process_identifier:
2368
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00372000
|
success
|
0 |
0
|
1620808783.21925
NtProtectVirtualMemory
|
process_identifier:
2368
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00372000
|
success
|
0 |
0
|
1620808783.21925
NtProtectVirtualMemory
|
process_identifier:
2368
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00372000
|
success
|
0 |
0
|
1620808783.21925
NtProtectVirtualMemory
|
process_identifier:
2368
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00372000
|
success
|
0 |
0
|
1620808783.21925
NtProtectVirtualMemory
|
process_identifier:
2368
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00372000
|
success
|
0 |
0
|
1620808783.21925
NtProtectVirtualMemory
|
process_identifier:
2368
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00372000
|
success
|
0 |
0
|
1620808783.21925
NtProtectVirtualMemory
|
process_identifier:
2368
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00372000
|
success
|
0 |
0
|
1620808783.21925
NtProtectVirtualMemory
|
process_identifier:
2368
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00372000
|
success
|
0 |
0
|
1620808783.21925
NtProtectVirtualMemory
|
process_identifier:
2368
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00372000
|
success
|
0 |
0
|
1620808783.21925
NtProtectVirtualMemory
|
process_identifier:
2368
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00372000
|
success
|
0 |
0
|
1620808783.21925
NtProtectVirtualMemory
|
process_identifier:
2368
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00372000
|
success
|
0 |
0
|
1620808783.21925
NtProtectVirtualMemory
|
process_identifier:
2368
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00372000
|
success
|
0 |
0
|
1620808783.21925
NtProtectVirtualMemory
|
process_identifier:
2368
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00372000
|
success
|
0 |
0
|
1620808783.21925
NtProtectVirtualMemory
|
process_identifier:
2368
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00372000
|
success
|
0 |
0
|
1620808783.21925
NtProtectVirtualMemory
|
process_identifier:
2368
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00372000
|
success
|
0 |
0
|
1620808783.21925
NtProtectVirtualMemory
|
process_identifier:
2368
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00372000
|
success
|
0 |
0
|
1620808783.21925
NtProtectVirtualMemory
|
process_identifier:
2368
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00372000
|
success
|
0 |
0
|