| Time & API |
Arguments |
Status |
Return |
Repeated |
1619826881.787952
NtAllocateVirtualMemory
|
process_identifier:
2308
region_size:
57344
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12289
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x004c0000
|
success
|
0 |
0
|
1619826881.990952
NtProtectVirtualMemory
|
process_identifier:
2308
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x77d5f000
|
success
|
0 |
0
|
1619826881.990952
NtProtectVirtualMemory
|
process_identifier:
2308
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x77d60000
|
success
|
0 |
0
|
1619826881.990952
NtProtectVirtualMemory
|
process_identifier:
2308
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x77d6c000
|
success
|
0 |
0
|
1619826882.006952
NtProtectVirtualMemory
|
process_identifier:
2308
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x77d71000
|
success
|
0 |
0
|
1619826882.006952
NtProtectVirtualMemory
|
process_identifier:
2308
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x77d4f000
|
success
|
0 |
0
|
1619826882.006952
NtProtectVirtualMemory
|
process_identifier:
2308
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x77d4f000
|
success
|
0 |
0
|
1619826882.006952
NtProtectVirtualMemory
|
process_identifier:
2308
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x77d50000
|
success
|
0 |
0
|
1619826882.006952
NtProtectVirtualMemory
|
process_identifier:
2308
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x77d50000
|
success
|
0 |
0
|
1619826882.006952
NtProtectVirtualMemory
|
process_identifier:
2308
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x77d4f000
|
success
|
0 |
0
|
1619826882.006952
NtProtectVirtualMemory
|
process_identifier:
2308
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x77d50000
|
success
|
0 |
0
|
1619826882.006952
NtProtectVirtualMemory
|
process_identifier:
2308
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x77d50000
|
success
|
0 |
0
|
1619826882.006952
NtProtectVirtualMemory
|
process_identifier:
2308
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x77d4f000
|
success
|
0 |
0
|
1619826882.006952
NtProtectVirtualMemory
|
process_identifier:
2308
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x77d4f000
|
success
|
0 |
0
|
1619826882.006952
NtProtectVirtualMemory
|
process_identifier:
2308
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x77d4f000
|
success
|
0 |
0
|
1619826882.006952
NtProtectVirtualMemory
|
process_identifier:
2308
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x77d50000
|
success
|
0 |
0
|
1619826882.006952
NtProtectVirtualMemory
|
process_identifier:
2308
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x77d50000
|
success
|
0 |
0
|
1619826882.006952
NtProtectVirtualMemory
|
process_identifier:
2308
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x77d4f000
|
success
|
0 |
0
|
1619826882.006952
NtProtectVirtualMemory
|
process_identifier:
2308
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x77d50000
|
success
|
0 |
0
|
1619826882.006952
NtProtectVirtualMemory
|
process_identifier:
2308
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x77d50000
|
success
|
0 |
0
|
1619826882.006952
NtProtectVirtualMemory
|
process_identifier:
2308
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x77d50000
|
success
|
0 |
0
|
1619826882.006952
NtProtectVirtualMemory
|
process_identifier:
2308
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x77d4f000
|
success
|
0 |
0
|
1619826882.006952
NtProtectVirtualMemory
|
process_identifier:
2308
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x77d4f000
|
success
|
0 |
0
|
1619826882.006952
NtProtectVirtualMemory
|
process_identifier:
2308
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x77d4f000
|
success
|
0 |
0
|
1619826882.006952
NtProtectVirtualMemory
|
process_identifier:
2308
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x77d4f000
|
success
|
0 |
0
|
1619826882.006952
NtProtectVirtualMemory
|
process_identifier:
2308
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x77d4f000
|
success
|
0 |
0
|
1619826882.006952
NtProtectVirtualMemory
|
process_identifier:
2308
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x77d50000
|
success
|
0 |
0
|
1619826882.006952
NtProtectVirtualMemory
|
process_identifier:
2308
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x77d50000
|
success
|
0 |
0
|
1619826882.006952
NtProtectVirtualMemory
|
process_identifier:
2308
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x77d50000
|
success
|
0 |
0
|
1619826882.006952
NtProtectVirtualMemory
|
process_identifier:
2308
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x77d50000
|
success
|
0 |
0
|
1619826882.006952
NtProtectVirtualMemory
|
process_identifier:
2308
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x77d50000
|
success
|
0 |
0
|
1619826882.006952
NtProtectVirtualMemory
|
process_identifier:
2308
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x77d50000
|
success
|
0 |
0
|
1619826882.006952
NtProtectVirtualMemory
|
process_identifier:
2308
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x77d50000
|
success
|
0 |
0
|
1619826882.006952
NtProtectVirtualMemory
|
process_identifier:
2308
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x77d4f000
|
success
|
0 |
0
|
1619826882.006952
NtProtectVirtualMemory
|
process_identifier:
2308
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x77d50000
|
success
|
0 |
0
|
1619826882.006952
NtProtectVirtualMemory
|
process_identifier:
2308
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x77d4f000
|
success
|
0 |
0
|
1619826882.006952
NtProtectVirtualMemory
|
process_identifier:
2308
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x77d4f000
|
success
|
0 |
0
|
1619826882.006952
NtProtectVirtualMemory
|
process_identifier:
2308
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x77d51000
|
success
|
0 |
0
|
1619826882.006952
NtProtectVirtualMemory
|
process_identifier:
2308
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x77d51000
|
success
|
0 |
0
|
1619826882.006952
NtProtectVirtualMemory
|
process_identifier:
2308
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x77d4f000
|
success
|
0 |
0
|
1619826882.006952
NtProtectVirtualMemory
|
process_identifier:
2308
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x77d4f000
|
success
|
0 |
0
|
1619826882.006952
NtProtectVirtualMemory
|
process_identifier:
2308
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x77d51000
|
success
|
0 |
0
|
1619826882.006952
NtProtectVirtualMemory
|
process_identifier:
2308
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x77d50000
|
success
|
0 |
0
|