| Time & API |
Arguments |
Status |
Return |
Repeated |
1619896954.009875
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
1441792
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x006f0000
|
success
|
0 |
0
|
1619896954.009875
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00810000
|
success
|
0 |
0
|
1619896955.322875
NtProtectVirtualMemory
|
process_identifier:
2764
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73c51000
|
success
|
0 |
0
|
1619896955.556875
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0042a000
|
success
|
0 |
0
|
1619896955.556875
NtProtectVirtualMemory
|
process_identifier:
2764
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73c52000
|
success
|
0 |
0
|
1619896955.556875
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00422000
|
success
|
0 |
0
|
1619896955.884875
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00432000
|
success
|
0 |
0
|
1619896955.994875
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00433000
|
success
|
0 |
0
|
1619896956.009875
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0057b000
|
success
|
0 |
0
|
1619896956.009875
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00577000
|
success
|
0 |
0
|
1619896956.041875
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0043c000
|
success
|
0 |
0
|
1619896956.119875
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x007d0000
|
success
|
0 |
0
|
1619896956.322875
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00434000
|
success
|
0 |
0
|
1619896956.338875
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x007d1000
|
success
|
0 |
0
|
1619896956.353875
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0043a000
|
success
|
0 |
0
|
1619896956.400875
NtProtectVirtualMemory
|
process_identifier:
2764
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
733184
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01042000
|
success
|
0 |
0
|
1619896965.713875
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x007d2000
|
success
|
0 |
0
|
1619896965.759875
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x007d3000
|
success
|
0 |
0
|
1619896965.759875
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x007d4000
|
success
|
0 |
0
|
1619896965.838875
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x007d5000
|
success
|
0 |
0
|
1619896965.838875
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x007d6000
|
success
|
0 |
0
|
1619896966.197875
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00435000
|
success
|
0 |
0
|
1619896966.228875
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x007d7000
|
success
|
0 |
0
|
1619896966.259875
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x007d9000
|
success
|
0 |
0
|
1619896966.259875
NtProtectVirtualMemory
|
process_identifier:
2764
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x010f6000
|
success
|
0 |
0
|
1619896966.259875
NtProtectVirtualMemory
|
process_identifier:
2764
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x010f6000
|
success
|
0 |
0
|
1619896966.259875
NtProtectVirtualMemory
|
process_identifier:
2764
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01040000
|
success
|
0 |
0
|
1619896966.291875
NtProtectVirtualMemory
|
process_identifier:
2764
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01040000
|
success
|
0 |
0
|
1619896966.291875
NtProtectVirtualMemory
|
process_identifier:
2764
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01040000
|
success
|
0 |
0
|
1619896966.291875
NtProtectVirtualMemory
|
process_identifier:
2764
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01040000
|
success
|
0 |
0
|
1619896966.291875
NtProtectVirtualMemory
|
process_identifier:
2764
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x01040000
|
success
|
0 |
0
|
1619896966.291875
NtProtectVirtualMemory
|
process_identifier:
2764
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x010f6000
|
success
|
0 |
0
|
1619896966.291875
NtProtectVirtualMemory
|
process_identifier:
2764
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x010f6000
|
success
|
0 |
0
|
1619896966.291875
NtProtectVirtualMemory
|
process_identifier:
2764
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x010f6000
|
success
|
0 |
0
|
1619896966.291875
NtProtectVirtualMemory
|
process_identifier:
2764
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x010f6000
|
success
|
0 |
0
|
1619896966.291875
NtProtectVirtualMemory
|
process_identifier:
2764
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x010f6000
|
success
|
0 |
0
|
1619896966.291875
NtProtectVirtualMemory
|
process_identifier:
2764
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x010f6000
|
success
|
0 |
0
|
1619896966.291875
NtProtectVirtualMemory
|
process_identifier:
2764
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x010f6000
|
success
|
0 |
0
|
1619896966.291875
NtProtectVirtualMemory
|
process_identifier:
2764
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x010f6000
|
success
|
0 |
0
|
1619896966.291875
NtProtectVirtualMemory
|
process_identifier:
2764
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x010f6000
|
success
|
0 |
0
|
1619896966.291875
NtProtectVirtualMemory
|
process_identifier:
2764
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x010f6000
|
success
|
0 |
0
|
1619896966.291875
NtProtectVirtualMemory
|
process_identifier:
2764
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x010f6000
|
success
|
0 |
0
|
1619896966.291875
NtProtectVirtualMemory
|
process_identifier:
2764
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x010f6000
|
success
|
0 |
0
|
1619896966.291875
NtProtectVirtualMemory
|
process_identifier:
2764
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x010f6000
|
success
|
0 |
0
|
1619896966.291875
NtProtectVirtualMemory
|
process_identifier:
2764
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x010f6000
|
success
|
0 |
0
|
1619896966.291875
NtProtectVirtualMemory
|
process_identifier:
2764
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x010f6000
|
success
|
0 |
0
|
1619896966.291875
NtProtectVirtualMemory
|
process_identifier:
2764
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x010f6000
|
success
|
0 |
0
|
1619896966.291875
NtProtectVirtualMemory
|
process_identifier:
2764
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x010f6000
|
success
|
0 |
0
|
1619896966.291875
NtProtectVirtualMemory
|
process_identifier:
2764
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x010f6000
|
success
|
0 |
0
|
1619896966.291875
NtProtectVirtualMemory
|
process_identifier:
2764
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x010f6000
|
success
|
0 |
0
|