| Process injection |
Process 1380 manipulating memory of non-child process 1424 |
| Time & API |
Arguments |
Status |
Return |
Repeated |
1619826882.092008
NtAllocateVirtualMemory
|
process_identifier:
1424
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x00000000000000e8
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0000000006c30000
|
success
|
0 |
0
|
1619826882.170008
NtAllocateVirtualMemory
|
process_identifier:
1424
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x00000000000000ec
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0000000006c30000
|
success
|
0 |
0
|
1619826882.186008
NtAllocateVirtualMemory
|
process_identifier:
1424
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x00000000000000ec
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0000000006c30000
|
success
|
0 |
0
|
1619826882.202008
NtAllocateVirtualMemory
|
process_identifier:
1424
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x00000000000000ec
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0000000006c30000
|
success
|
0 |
0
|
1619826882.202008
NtAllocateVirtualMemory
|
process_identifier:
1424
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x00000000000000ec
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0000000006c30000
|
success
|
0 |
0
|
1619826882.233008
NtAllocateVirtualMemory
|
process_identifier:
1424
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x00000000000000ec
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0000000006c30000
|
success
|
0 |
0
|
1619826882.248008
NtAllocateVirtualMemory
|
process_identifier:
1424
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x00000000000000ec
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0000000006c30000
|
success
|
0 |
0
|
1619826882.280008
NtAllocateVirtualMemory
|
process_identifier:
1424
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x00000000000000ec
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0000000006c30000
|
success
|
0 |
0
|
1619826882.280008
NtAllocateVirtualMemory
|
process_identifier:
1424
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x00000000000000ec
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0000000006c30000
|
success
|
0 |
0
|
1619826882.342008
NtAllocateVirtualMemory
|
process_identifier:
1424
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x00000000000000ec
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0000000006c30000
|
success
|
0 |
0
|
1619826882.358008
NtAllocateVirtualMemory
|
process_identifier:
1424
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x00000000000000ec
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0000000006c30000
|
success
|
0 |
0
|
1619826882.373008
NtAllocateVirtualMemory
|
process_identifier:
1424
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x00000000000000ec
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0000000006c30000
|
success
|
0 |
0
|
1619826882.373008
NtAllocateVirtualMemory
|
process_identifier:
1424
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x00000000000000ec
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0000000006c30000
|
success
|
0 |
0
|
1619826882.389008
NtAllocateVirtualMemory
|
process_identifier:
1424
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x00000000000000ec
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0000000006c30000
|
success
|
0 |
0
|
1619826882.420008
NtAllocateVirtualMemory
|
process_identifier:
1424
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x00000000000000ec
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0000000006c30000
|
success
|
0 |
0
|
1619826882.436008
NtAllocateVirtualMemory
|
process_identifier:
1424
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x00000000000000ec
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0000000006c30000
|
success
|
0 |
0
|
1619826882.436008
NtAllocateVirtualMemory
|
process_identifier:
1424
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x00000000000000ec
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0000000006c30000
|
success
|
0 |
0
|
1619826882.452008
NtAllocateVirtualMemory
|
process_identifier:
1424
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x00000000000000ec
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0000000006c30000
|
success
|
0 |
0
|
1619826882.467008
NtAllocateVirtualMemory
|
process_identifier:
1424
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x00000000000000ec
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0000000006c30000
|
success
|
0 |
0
|
1619826882.498008
NtAllocateVirtualMemory
|
process_identifier:
1424
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x00000000000000ec
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0000000006c30000
|
success
|
0 |
0
|
1619826882.498008
NtAllocateVirtualMemory
|
process_identifier:
1424
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x00000000000000ec
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0000000006c30000
|
success
|
0 |
0
|
1619826886.545008
NtAllocateVirtualMemory
|
process_identifier:
1424
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x0000000000000178
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0000000006c40000
|
success
|
0 |
0
|
1619826886.561008
NtAllocateVirtualMemory
|
process_identifier:
1424
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x0000000000000178
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0000000006c40000
|
success
|
0 |
0
|
1619826886.577008
NtAllocateVirtualMemory
|
process_identifier:
1424
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x0000000000000178
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0000000006c40000
|
success
|
0 |
0
|
1619826886.577008
NtAllocateVirtualMemory
|
process_identifier:
1424
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x0000000000000178
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0000000006c40000
|
success
|
0 |
0
|
1619826886.577008
NtAllocateVirtualMemory
|
process_identifier:
1424
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x0000000000000178
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0000000006c40000
|
success
|
0 |
0
|
1619826886.592008
NtAllocateVirtualMemory
|
process_identifier:
1424
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x0000000000000178
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0000000006c40000
|
success
|
0 |
0
|
1619826886.592008
NtAllocateVirtualMemory
|
process_identifier:
1424
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x0000000000000178
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0000000006c40000
|
success
|
0 |
0
|
1619826886.592008
NtAllocateVirtualMemory
|
process_identifier:
1424
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x0000000000000178
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0000000006c40000
|
success
|
0 |
0
|
1619826886.592008
NtAllocateVirtualMemory
|
process_identifier:
1424
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x0000000000000178
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0000000006c40000
|
success
|
0 |
0
|
1619826886.623008
NtAllocateVirtualMemory
|
process_identifier:
1424
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x0000000000000178
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0000000006c40000
|
success
|
0 |
0
|
1619826886.623008
NtAllocateVirtualMemory
|
process_identifier:
1424
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x0000000000000178
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0000000006c40000
|
success
|
0 |
0
|
1619826886.623008
NtAllocateVirtualMemory
|
process_identifier:
1424
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x0000000000000178
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0000000006c40000
|
success
|
0 |
0
|
1619826886.623008
NtAllocateVirtualMemory
|
process_identifier:
1424
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x0000000000000178
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0000000006c40000
|
success
|
0 |
0
|
1619826886.639008
NtAllocateVirtualMemory
|
process_identifier:
1424
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x0000000000000178
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0000000006c40000
|
success
|
0 |
0
|
1619826886.639008
NtAllocateVirtualMemory
|
process_identifier:
1424
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x0000000000000178
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0000000006c40000
|
success
|
0 |
0
|
1619826886.639008
NtAllocateVirtualMemory
|
process_identifier:
1424
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x0000000000000178
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0000000006c40000
|
success
|
0 |
0
|
1619826886.639008
NtAllocateVirtualMemory
|
process_identifier:
1424
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x0000000000000178
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0000000006c40000
|
success
|
0 |
0
|
1619826886.655008
NtAllocateVirtualMemory
|
process_identifier:
1424
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x0000000000000178
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0000000006c40000
|
success
|
0 |
0
|
1619826886.655008
NtAllocateVirtualMemory
|
process_identifier:
1424
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x0000000000000178
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0000000006c40000
|
success
|
0 |
0
|
1619826886.670008
NtAllocateVirtualMemory
|
process_identifier:
1424
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x0000000000000178
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0000000006c40000
|
success
|
0 |
0
|
1619826886.686008
NtAllocateVirtualMemory
|
process_identifier:
1424
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x0000000000000178
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0000000006c40000
|
success
|
0 |
0
|
1619826887.842008
NtAllocateVirtualMemory
|
process_identifier:
1424
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x000000000000017c
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0000000006c40000
|
success
|
0 |
0
|
1619826887.842008
NtAllocateVirtualMemory
|
process_identifier:
1424
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x000000000000017c
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0000000006c40000
|
success
|
0 |
0
|
1619826887.842008
NtAllocateVirtualMemory
|
process_identifier:
1424
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x000000000000017c
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0000000006c40000
|
success
|
0 |
0
|
1619826887.842008
NtAllocateVirtualMemory
|
process_identifier:
1424
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x000000000000017c
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0000000006c40000
|
success
|
0 |
0
|
1619826887.842008
NtAllocateVirtualMemory
|
process_identifier:
1424
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x000000000000017c
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0000000006c40000
|
success
|
0 |
0
|
1619826887.858008
NtAllocateVirtualMemory
|
process_identifier:
1424
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x000000000000017c
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0000000006c40000
|
success
|
0 |
0
|
1619826887.858008
NtAllocateVirtualMemory
|
process_identifier:
1424
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x000000000000017c
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0000000006c40000
|
success
|
0 |
0
|