| Process injection |
Process 2008 manipulating memory of non-child process 1320 |
| Process injection |
Process 2008 manipulating memory of non-child process 2984 |
| Process injection |
Process 2008 manipulating memory of non-child process 1760 |
| Process injection |
Process 2008 manipulating memory of non-child process 2452 |
| Process injection |
Process 2008 manipulating memory of non-child process 2952 |
| Process injection |
Process 2008 manipulating memory of non-child process 1160 |
| Process injection |
Process 2008 manipulating memory of non-child process 2796 |
| Process injection |
Process 2008 manipulating memory of non-child process 2468 |
| Process injection |
Process 2008 manipulating memory of non-child process 1816 |
| Process injection |
Process 2008 manipulating memory of non-child process 1208 |
| Process injection |
Process 2008 manipulating memory of non-child process 2604 |
| Process injection |
Process 2008 manipulating memory of non-child process 1888 |
| Process injection |
Process 2008 manipulating memory of non-child process 2136 |
| Process injection |
Process 2008 manipulating memory of non-child process 2964 |
| Process injection |
Process 2008 manipulating memory of non-child process 2424 |
| Process injection |
Process 2008 manipulating memory of non-child process 520 |
| Process injection |
Process 2008 manipulating memory of non-child process 580 |
| Process injection |
Process 2008 manipulating memory of non-child process 3036 |
| Process injection |
Process 2008 manipulating memory of non-child process 3096 |
| Process injection |
Process 2008 manipulating memory of non-child process 3132 |
| Process injection |
Process 2008 manipulating memory of non-child process 3168 |
| Process injection |
Process 2008 manipulating memory of non-child process 3204 |
| Process injection |
Process 2008 manipulating memory of non-child process 3240 |
| Process injection |
Process 2008 manipulating memory of non-child process 3276 |
| Process injection |
Process 2008 manipulating memory of non-child process 3312 |
| Time & API |
Arguments |
Status |
Return |
Repeated |
1619936119.682626
NtAllocateVirtualMemory
|
process_identifier:
1320
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x00000144
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000a0000
|
success
|
0 |
0
|
1619936119.698626
NtAllocateVirtualMemory
|
process_identifier:
2984
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x00000158
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000a0000
|
success
|
0 |
0
|
1619936119.698626
NtAllocateVirtualMemory
|
process_identifier:
1760
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x00000164
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000a0000
|
success
|
0 |
0
|
1619936119.714626
NtAllocateVirtualMemory
|
process_identifier:
2452
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x00000170
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000a0000
|
success
|
0 |
0
|
1619936119.729626
NtAllocateVirtualMemory
|
process_identifier:
2952
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x0000017c
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000a0000
|
success
|
0 |
0
|
1619936119.745626
NtAllocateVirtualMemory
|
process_identifier:
1160
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x00000188
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000a0000
|
success
|
0 |
0
|
1619936119.745626
NtAllocateVirtualMemory
|
process_identifier:
2796
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x00000194
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000a0000
|
success
|
0 |
0
|
1619936119.760626
NtAllocateVirtualMemory
|
process_identifier:
2468
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x000001a0
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000a0000
|
success
|
0 |
0
|
1619936119.776626
NtAllocateVirtualMemory
|
process_identifier:
1816
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x000001ac
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000a0000
|
success
|
0 |
0
|
1619936119.792626
NtAllocateVirtualMemory
|
process_identifier:
1208
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x000001b8
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000a0000
|
success
|
0 |
0
|
1619936119.917626
NtAllocateVirtualMemory
|
process_identifier:
2604
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x000001c4
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000a0000
|
success
|
0 |
0
|
1619936119.964626
NtAllocateVirtualMemory
|
process_identifier:
1888
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x000001d0
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000a0000
|
success
|
0 |
0
|
1619936119.979626
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x000001dc
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000a0000
|
success
|
0 |
0
|
1619936119.979626
NtAllocateVirtualMemory
|
process_identifier:
2964
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x000001e8
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000a0000
|
success
|
0 |
0
|
1619936120.057626
NtAllocateVirtualMemory
|
process_identifier:
2424
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x000001f4
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000a0000
|
success
|
0 |
0
|
1619936120.089626
NtAllocateVirtualMemory
|
process_identifier:
520
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x00000200
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000a0000
|
success
|
0 |
0
|
1619936120.104626
NtAllocateVirtualMemory
|
process_identifier:
580
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x0000020c
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000a0000
|
success
|
0 |
0
|
1619936120.120626
NtAllocateVirtualMemory
|
process_identifier:
3036
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x00000218
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000a0000
|
success
|
0 |
0
|
1619936120.151626
NtAllocateVirtualMemory
|
process_identifier:
3096
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x00000224
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000e0000
|
success
|
0 |
0
|
1619936120.182626
NtAllocateVirtualMemory
|
process_identifier:
3132
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x00000230
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000e0000
|
success
|
0 |
0
|
1619936120.198626
NtAllocateVirtualMemory
|
process_identifier:
3168
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x0000023c
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000a0000
|
success
|
0 |
0
|
1619936120.214626
NtAllocateVirtualMemory
|
process_identifier:
3204
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x00000248
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000a0000
|
success
|
0 |
0
|
1619936120.245626
NtAllocateVirtualMemory
|
process_identifier:
3240
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x00000254
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000a0000
|
success
|
0 |
0
|
1619936120.260626
NtAllocateVirtualMemory
|
process_identifier:
3276
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x00000260
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000a0000
|
success
|
0 |
0
|
1619936120.276626
NtAllocateVirtualMemory
|
process_identifier:
3312
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
4
(PAGE_READWRITE)
process_handle:
0x0000026c
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000a0000
|
success
|
0 |
0
|