| Time & API |
Arguments |
Status |
Return |
Repeated |
1619826880.630436
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003a0000
|
success
|
0 |
0
|
1619826880.833436
NtProtectVirtualMemory
|
process_identifier:
2136
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
45056
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x0048d000
|
success
|
0 |
0
|
1619826880.833436
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x008a0000
|
success
|
0 |
0
|
1619836796.32925
NtProtectVirtualMemory
|
process_identifier:
2340
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00400000
|
success
|
0 |
0
|
1619836796.36025
NtAllocateVirtualMemory
|
process_identifier:
2340
region_size:
720896
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x01ed0000
|
success
|
0 |
0
|
1619836796.36025
NtAllocateVirtualMemory
|
process_identifier:
2340
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x01f40000
|
success
|
0 |
0
|
1619836796.36025
NtAllocateVirtualMemory
|
process_identifier:
2340
region_size:
458752
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x005d0000
|
success
|
0 |
0
|
1619836796.36025
NtProtectVirtualMemory
|
process_identifier:
2340
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
434176
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x005d2000
|
success
|
0 |
0
|
1619836796.68825
NtProtectVirtualMemory
|
process_identifier:
2340
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x02032000
|
success
|
0 |
0
|
1619836796.68825
NtProtectVirtualMemory
|
process_identifier:
2340
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76351000
|
success
|
0 |
0
|
1619836796.68825
NtProtectVirtualMemory
|
process_identifier:
2340
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x02032000
|
success
|
0 |
0
|
1619836796.68825
NtProtectVirtualMemory
|
process_identifier:
2340
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76353000
|
success
|
0 |
0
|
1619836796.68825
NtProtectVirtualMemory
|
process_identifier:
2340
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x02032000
|
success
|
0 |
0
|
1619836796.68825
NtProtectVirtualMemory
|
process_identifier:
2340
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76354000
|
success
|
0 |
0
|
1619836796.68825
NtProtectVirtualMemory
|
process_identifier:
2340
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x02032000
|
success
|
0 |
0
|
1619836796.68825
NtProtectVirtualMemory
|
process_identifier:
2340
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76351000
|
success
|
0 |
0
|
1619836796.70425
NtProtectVirtualMemory
|
process_identifier:
2340
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x02032000
|
success
|
0 |
0
|
1619836796.70425
NtProtectVirtualMemory
|
process_identifier:
2340
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x77d4f000
|
success
|
0 |
0
|
1619836796.70425
NtProtectVirtualMemory
|
process_identifier:
2340
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x02032000
|
success
|
0 |
0
|
1619836796.70425
NtProtectVirtualMemory
|
process_identifier:
2340
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76353000
|
success
|
0 |
0
|
1619836796.70425
NtProtectVirtualMemory
|
process_identifier:
2340
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x02032000
|
success
|
0 |
0
|
1619836796.70425
NtProtectVirtualMemory
|
process_identifier:
2340
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76351000
|
success
|
0 |
0
|
1619836796.70425
NtProtectVirtualMemory
|
process_identifier:
2340
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x02032000
|
success
|
0 |
0
|
1619836796.70425
NtProtectVirtualMemory
|
process_identifier:
2340
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76351000
|
success
|
0 |
0
|
1619836796.70425
NtProtectVirtualMemory
|
process_identifier:
2340
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x02032000
|
success
|
0 |
0
|
1619836796.70425
NtProtectVirtualMemory
|
process_identifier:
2340
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76354000
|
success
|
0 |
0
|
1619836796.70425
NtProtectVirtualMemory
|
process_identifier:
2340
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x02032000
|
success
|
0 |
0
|
1619836796.70425
NtProtectVirtualMemory
|
process_identifier:
2340
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76351000
|
success
|
0 |
0
|
1619836796.407375
NtAllocateVirtualMemory
|
process_identifier:
2984
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x01ed0000
|
success
|
0 |
0
|
1619836796.423375
NtProtectVirtualMemory
|
process_identifier:
2984
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
45056
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x0048d000
|
success
|
0 |
0
|
1619836796.438375
NtAllocateVirtualMemory
|
process_identifier:
2984
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x01f90000
|
success
|
0 |
0
|
1619836802.032375
NtAllocateVirtualMemory
|
process_identifier:
3148
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x007e0000
|
success
|
0 |
0
|
1619836802.048375
NtProtectVirtualMemory
|
process_identifier:
3148
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
45056
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x0048d000
|
success
|
0 |
0
|
1619836802.063375
NtAllocateVirtualMemory
|
process_identifier:
3148
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x008f0000
|
success
|
0 |
0
|
1619836803.48525
NtProtectVirtualMemory
|
process_identifier:
3220
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00400000
|
success
|
0 |
0
|
1619836803.50125
NtAllocateVirtualMemory
|
process_identifier:
3220
region_size:
1245184
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x01f00000
|
success
|
0 |
0
|
1619836803.50125
NtAllocateVirtualMemory
|
process_identifier:
3220
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x01ff0000
|
success
|
0 |
0
|
1619836803.50125
NtAllocateVirtualMemory
|
process_identifier:
3220
region_size:
458752
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x01e00000
|
success
|
0 |
0
|
1619836803.50125
NtProtectVirtualMemory
|
process_identifier:
3220
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
434176
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01e02000
|
success
|
0 |
0
|
1619836803.78225
NtProtectVirtualMemory
|
process_identifier:
3220
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01d82000
|
success
|
0 |
0
|
1619836803.78225
NtProtectVirtualMemory
|
process_identifier:
3220
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76351000
|
success
|
0 |
0
|
1619836803.78225
NtProtectVirtualMemory
|
process_identifier:
3220
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01d82000
|
success
|
0 |
0
|
1619836803.78225
NtProtectVirtualMemory
|
process_identifier:
3220
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76353000
|
success
|
0 |
0
|
1619836803.79825
NtProtectVirtualMemory
|
process_identifier:
3220
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01d82000
|
success
|
0 |
0
|
1619836803.79825
NtProtectVirtualMemory
|
process_identifier:
3220
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76354000
|
success
|
0 |
0
|
1619836803.79825
NtProtectVirtualMemory
|
process_identifier:
3220
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01d82000
|
success
|
0 |
0
|
1619836803.79825
NtProtectVirtualMemory
|
process_identifier:
3220
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76351000
|
success
|
0 |
0
|
1619836803.79825
NtProtectVirtualMemory
|
process_identifier:
3220
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01d82000
|
success
|
0 |
0
|
1619836803.79825
NtProtectVirtualMemory
|
process_identifier:
3220
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x77d4f000
|
success
|
0 |
0
|
1619836803.79825
NtProtectVirtualMemory
|
process_identifier:
3220
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01d82000
|
success
|
0 |
0
|