| Time & API |
Arguments |
Status |
Return |
Repeated |
1619826882.33396
NtAllocateVirtualMemory
|
process_identifier:
420
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003d0000
|
success
|
0 |
0
|
1619826882.47496
NtProtectVirtualMemory
|
process_identifier:
420
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x0045e000
|
success
|
0 |
0
|
1619826882.48996
NtAllocateVirtualMemory
|
process_identifier:
420
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00550000
|
success
|
0 |
0
|
1619826883.357486
NtProtectVirtualMemory
|
process_identifier:
1376
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00400000
|
success
|
0 |
0
|
1619826883.404486
NtAllocateVirtualMemory
|
process_identifier:
1376
region_size:
1441792
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x01e80000
|
success
|
0 |
0
|
1619826883.404486
NtAllocateVirtualMemory
|
process_identifier:
1376
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x01fa0000
|
success
|
0 |
0
|
1619826883.404486
NtAllocateVirtualMemory
|
process_identifier:
1376
region_size:
335872
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x01da0000
|
success
|
0 |
0
|
1619826883.419486
NtProtectVirtualMemory
|
process_identifier:
1376
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
307200
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01da2000
|
success
|
0 |
0
|
1619826883.810486
NtAllocateVirtualMemory
|
process_identifier:
1376
region_size:
2097152
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x01fe0000
|
success
|
0 |
0
|
1619826883.810486
NtAllocateVirtualMemory
|
process_identifier:
1376
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x021a0000
|
success
|
0 |
0
|
1619826884.388486
NtProtectVirtualMemory
|
process_identifier:
1376
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x005b2000
|
success
|
0 |
0
|
1619826884.388486
NtProtectVirtualMemory
|
process_identifier:
1376
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76351000
|
success
|
0 |
0
|
1619826884.388486
NtProtectVirtualMemory
|
process_identifier:
1376
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x005b2000
|
success
|
0 |
0
|
1619826884.388486
NtProtectVirtualMemory
|
process_identifier:
1376
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76353000
|
success
|
0 |
0
|
1619826884.388486
NtProtectVirtualMemory
|
process_identifier:
1376
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x005b2000
|
success
|
0 |
0
|
1619826884.388486
NtProtectVirtualMemory
|
process_identifier:
1376
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76354000
|
success
|
0 |
0
|
1619826884.388486
NtProtectVirtualMemory
|
process_identifier:
1376
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x005b2000
|
success
|
0 |
0
|
1619826884.388486
NtProtectVirtualMemory
|
process_identifier:
1376
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76351000
|
success
|
0 |
0
|
1619826884.388486
NtProtectVirtualMemory
|
process_identifier:
1376
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x005b2000
|
success
|
0 |
0
|
1619826884.388486
NtProtectVirtualMemory
|
process_identifier:
1376
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x77d4f000
|
success
|
0 |
0
|
1619826884.388486
NtProtectVirtualMemory
|
process_identifier:
1376
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x005b2000
|
success
|
0 |
0
|
1619826884.388486
NtProtectVirtualMemory
|
process_identifier:
1376
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76353000
|
success
|
0 |
0
|
1619826884.388486
NtProtectVirtualMemory
|
process_identifier:
1376
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x005b2000
|
success
|
0 |
0
|
1619826884.388486
NtProtectVirtualMemory
|
process_identifier:
1376
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76351000
|
success
|
0 |
0
|
1619826884.388486
NtProtectVirtualMemory
|
process_identifier:
1376
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x005b2000
|
success
|
0 |
0
|
1619826884.388486
NtProtectVirtualMemory
|
process_identifier:
1376
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76351000
|
success
|
0 |
0
|
1619826884.388486
NtProtectVirtualMemory
|
process_identifier:
1376
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x005b2000
|
success
|
0 |
0
|
1619826884.388486
NtProtectVirtualMemory
|
process_identifier:
1376
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76354000
|
success
|
0 |
0
|
1619826884.388486
NtProtectVirtualMemory
|
process_identifier:
1376
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x005b2000
|
success
|
0 |
0
|
1619826884.388486
NtProtectVirtualMemory
|
process_identifier:
1376
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x76351000
|
success
|
0 |
0
|