| Time & API |
Arguments |
Status |
Return |
Repeated |
1620918751.352125
NtProtectVirtualMemory
|
process_identifier:
2308
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x749f4000
|
success
|
0 |
0
|
1620918762.586125
NtAllocateVirtualMemory
|
process_identifier:
2308
region_size:
1114112
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x04fe0000
|
success
|
0 |
0
|
1620918762.586125
NtAllocateVirtualMemory
|
process_identifier:
2308
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x050b0000
|
success
|
0 |
0
|
1620918762.633125
NtAllocateVirtualMemory
|
process_identifier:
2308
region_size:
720896
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x04fe0000
|
success
|
0 |
0
|
1620918762.633125
NtAllocateVirtualMemory
|
process_identifier:
2308
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x05050000
|
success
|
0 |
0
|
1620918821.649375
NtAllocateVirtualMemory
|
process_identifier:
1424
region_size:
65536
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0000000007750000
|
success
|
0 |
0
|
1620918777.32025
NtProtectVirtualMemory
|
process_identifier:
1888
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1ec7000
|
success
|
0 |
0
|
1620918777.32025
NtProtectVirtualMemory
|
process_identifier:
1888
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feff53d000
|
success
|
0 |
0
|
1620918794.305875
NtProtectVirtualMemory
|
process_identifier:
1300
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x74389000
|
success
|
0 |
0
|
1620918794.305875
NtProtectVirtualMemory
|
process_identifier:
1300
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x1006a000
|
success
|
0 |
0
|
1620918794.305875
NtProtectVirtualMemory
|
process_identifier:
1300
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x77531000
|
success
|
0 |
0
|
1620918794.305875
NtProtectVirtualMemory
|
process_identifier:
1300
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x75a01000
|
success
|
0 |
0
|
1620918801.72725
NtProtectVirtualMemory
|
process_identifier:
2840
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x7441c000
|
success
|
0 |
0
|
1620918801.74225
NtProtectVirtualMemory
|
process_identifier:
2840
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x742f1000
|
success
|
0 |
0
|
1620918805.445
NtProtectVirtualMemory
|
process_identifier:
364
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x74455000
|
success
|
0 |
0
|
1620918808.68075
NtProtectVirtualMemory
|
process_identifier:
2168
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x7464d000
|
success
|
0 |
0
|
1620918814.774625
NtProtectVirtualMemory
|
process_identifier:
2484
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1da7000
|
success
|
0 |
0
|
1620918814.774625
NtProtectVirtualMemory
|
process_identifier:
2484
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007feff53d000
|
success
|
0 |
0
|
1620918826.78925
NtProtectVirtualMemory
|
process_identifier:
3288
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x728e9000
|
success
|
0 |
0
|
1620918826.78925
NtProtectVirtualMemory
|
process_identifier:
3288
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x1006a000
|
success
|
0 |
0
|
1620918826.78925
NtProtectVirtualMemory
|
process_identifier:
3288
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x77531000
|
success
|
0 |
0
|
1620918826.78925
NtProtectVirtualMemory
|
process_identifier:
3288
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x75a01000
|
success
|
0 |
0
|
1620918835.852875
NtProtectVirtualMemory
|
process_identifier:
3444
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x7391c000
|
success
|
0 |
0
|
1620918835.852875
NtProtectVirtualMemory
|
process_identifier:
3444
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x740c1000
|
success
|
0 |
0
|
1620918840.820875
NtProtectVirtualMemory
|
process_identifier:
3556
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x736ad000
|
success
|
0 |
0
|
1620918845.508625
NtProtectVirtualMemory
|
process_identifier:
3684
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73895000
|
success
|
0 |
0
|