| Time & API |
Arguments |
Status |
Return |
Repeated |
1619861122.399988
CreateProcessInternalW
|
thread_identifier:
2060
thread_handle:
0x00000070
process_identifier:
2064
current_directory:
filepath:
track:
1
command_line:
winver
filepath_r:
stack_pivoted:
0
creation_flags:
4
(CREATE_SUSPENDED)
process_handle:
0x00000058
inherit_handles:
0
|
success
|
1 |
0
|
1619861122.399988
NtGetContextThread
|
thread_handle:
0x00000070
|
success
|
0 |
0
|
1619861122.399988
WriteProcessMemory
|
process_identifier:
2064
buffer:
è ÇWè Ãè ReadProcessMemory WÿÓÆè
VirtualAlloc WÿÓè [ë@ j@h 0 ÿ³Õ@ j ÿÐ
Àt ÇÕ@ j ÿ0WÿpÿpÿÖ
ÀtÇ4 WÃî\ $ d¡0 @@ H y3 2 uò@ÃUåWEÂR<RxÂr Æ1ÉAÆ>ÇocAduïÆr$·4N4°r_ÉÂ
process_handle:
0x00000058
base_address:
0x003b16c1
|
success
|
1 |
0
|
1619861122.774988
NtResumeThread
|
thread_handle:
0x00000070
suspend_count:
1
process_identifier:
2064
|
success
|
0 |
0
|
1619893166.575125
NtAllocateVirtualMemory
|
process_identifier:
1424
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000088
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x06c30000
|
success
|
0 |
0
|
1619893166.575125
WriteProcessMemory
|
process_identifier:
1424
buffer:
process_handle:
0x00000088
base_address:
0x06c30000
|
success
|
1 |
0
|
1619893167.606125
NtAllocateVirtualMemory
|
process_identifier:
276
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000c0
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00210000
|
success
|
0 |
0
|
1619893167.606125
WriteProcessMemory
|
process_identifier:
276
buffer:
process_handle:
0x000000c0
base_address:
0x00210000
|
success
|
1 |
0
|
1619893167.606125
NtAllocateVirtualMemory
|
process_identifier:
372
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000c0
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00c00000
|
success
|
0 |
0
|
1619893167.606125
WriteProcessMemory
|
process_identifier:
372
buffer:
process_handle:
0x000000c0
base_address:
0x00c00000
|
success
|
1 |
0
|
1619893167.606125
NtAllocateVirtualMemory
|
process_identifier:
424
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000c0
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x0a210000
|
success
|
0 |
0
|
1619893167.606125
WriteProcessMemory
|
process_identifier:
424
buffer:
process_handle:
0x000000c0
base_address:
0x0a210000
|
success
|
1 |
0
|
1619893167.606125
NtAllocateVirtualMemory
|
process_identifier:
432
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000c0
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00110000
|
success
|
0 |
0
|
1619893167.606125
WriteProcessMemory
|
process_identifier:
432
buffer:
process_handle:
0x000000c0
base_address:
0x00110000
|
success
|
1 |
0
|
1619893167.606125
NtAllocateVirtualMemory
|
process_identifier:
476
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000c0
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00110000
|
success
|
0 |
0
|
1619893167.606125
WriteProcessMemory
|
process_identifier:
476
buffer:
process_handle:
0x000000c0
base_address:
0x00110000
|
success
|
1 |
0
|
1619893167.606125
NtAllocateVirtualMemory
|
process_identifier:
508
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000c0
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x001d0000
|
success
|
0 |
0
|
1619893167.606125
WriteProcessMemory
|
process_identifier:
508
buffer:
process_handle:
0x000000c0
base_address:
0x001d0000
|
success
|
1 |
0
|
1619893167.622125
NtAllocateVirtualMemory
|
process_identifier:
536
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000c0
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x009e0000
|
success
|
0 |
0
|
1619893167.622125
WriteProcessMemory
|
process_identifier:
536
buffer:
process_handle:
0x000000c0
base_address:
0x009e0000
|
success
|
1 |
0
|
1619893167.622125
NtAllocateVirtualMemory
|
process_identifier:
544
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000c0
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00190000
|
success
|
0 |
0
|
1619893167.622125
WriteProcessMemory
|
process_identifier:
544
buffer:
process_handle:
0x000000c0
base_address:
0x00190000
|
success
|
1 |
0
|
1619893167.622125
NtAllocateVirtualMemory
|
process_identifier:
656
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000c0
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00400000
|
success
|
0 |
0
|
1619893167.622125
WriteProcessMemory
|
process_identifier:
656
buffer:
process_handle:
0x000000c0
base_address:
0x00400000
|
success
|
1 |
0
|
1619893167.622125
NtAllocateVirtualMemory
|
process_identifier:
720
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000c0
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x000d0000
|
success
|
0 |
0
|
1619893167.622125
WriteProcessMemory
|
process_identifier:
720
buffer:
process_handle:
0x000000c0
base_address:
0x000d0000
|
success
|
1 |
0
|
1619893167.622125
NtAllocateVirtualMemory
|
process_identifier:
788
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000c0
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x001c0000
|
success
|
0 |
0
|
1619893167.622125
WriteProcessMemory
|
process_identifier:
788
buffer:
process_handle:
0x000000c0
base_address:
0x001c0000
|
success
|
1 |
0
|
1619893167.622125
NtAllocateVirtualMemory
|
process_identifier:
868
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000c0
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00e50000
|
success
|
0 |
0
|
1619893167.622125
WriteProcessMemory
|
process_identifier:
868
buffer:
process_handle:
0x000000c0
base_address:
0x00e50000
|
success
|
1 |
0
|
1619893167.622125
NtAllocateVirtualMemory
|
process_identifier:
924
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000c0
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00e50000
|
success
|
0 |
0
|
1619893167.622125
WriteProcessMemory
|
process_identifier:
924
buffer:
process_handle:
0x000000c0
base_address:
0x00e50000
|
success
|
1 |
0
|
1619893167.622125
NtAllocateVirtualMemory
|
process_identifier:
956
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000c0
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00f70000
|
success
|
0 |
0
|
1619893167.622125
WriteProcessMemory
|
process_identifier:
956
buffer:
process_handle:
0x000000c0
base_address:
0x00f70000
|
success
|
1 |
0
|
1619893167.622125
NtAllocateVirtualMemory
|
process_identifier:
540
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000c0
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00d10000
|
success
|
0 |
0
|
1619893167.622125
WriteProcessMemory
|
process_identifier:
540
buffer:
process_handle:
0x000000c0
base_address:
0x00d10000
|
success
|
1 |
0
|
1619893167.622125
NtAllocateVirtualMemory
|
process_identifier:
1080
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000c0
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x014f0000
|
success
|
0 |
0
|
1619893167.622125
WriteProcessMemory
|
process_identifier:
1080
buffer:
process_handle:
0x000000c0
base_address:
0x014f0000
|
success
|
1 |
0
|
1619893167.622125
NtAllocateVirtualMemory
|
process_identifier:
1260
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000c0
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00190000
|
success
|
0 |
0
|
1619893167.622125
WriteProcessMemory
|
process_identifier:
1260
buffer:
process_handle:
0x000000c0
base_address:
0x00190000
|
success
|
1 |
0
|
1619893167.622125
NtAllocateVirtualMemory
|
process_identifier:
1288
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000c0
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00180000
|
success
|
0 |
0
|
1619893167.622125
WriteProcessMemory
|
process_identifier:
1288
buffer:
process_handle:
0x000000c0
base_address:
0x00180000
|
success
|
1 |
0
|
1619893167.622125
NtAllocateVirtualMemory
|
process_identifier:
1336
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000c0
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00350000
|
success
|
0 |
0
|
1619893167.622125
WriteProcessMemory
|
process_identifier:
1336
buffer:
process_handle:
0x000000c0
base_address:
0x00350000
|
success
|
1 |
0
|
1619893167.638125
NtAllocateVirtualMemory
|
process_identifier:
1384
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000c0
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00130000
|
success
|
0 |
0
|
1619893167.638125
WriteProcessMemory
|
process_identifier:
1384
buffer:
process_handle:
0x000000c0
base_address:
0x00130000
|
success
|
1 |
0
|
1619893167.638125
NtAllocateVirtualMemory
|
process_identifier:
1424
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000c0
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x06c40000
|
success
|
0 |
0
|
1619893167.638125
WriteProcessMemory
|
process_identifier:
1424
buffer:
process_handle:
0x000000c0
base_address:
0x06c40000
|
success
|
1 |
0
|
1619893167.638125
NtAllocateVirtualMemory
|
process_identifier:
1592
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000c0
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x004b0000
|
success
|
0 |
0
|
1619893167.638125
WriteProcessMemory
|
process_identifier:
1592
buffer:
process_handle:
0x000000c0
base_address:
0x004b0000
|
success
|
1 |
0
|