Time & API |
Arguments |
Status |
Return |
Repeated |
1620994671.248875
NtProtectVirtualMemory
|
process_identifier:
2856
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00400000
|
success
|
0 |
0
|
1620994671.248875
NtProtectVirtualMemory
|
process_identifier:
2856
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
69632
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00401000
|
success
|
0 |
0
|
1620994671.248875
NtProtectVirtualMemory
|
process_identifier:
2856
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
102400
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x0041b000
|
success
|
0 |
0
|
1620994672.42025
NtAllocateVirtualMemory
|
process_identifier:
2248
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00680000
|
success
|
0 |
0
|
1620994744.561375
NtAllocateVirtualMemory
|
process_identifier:
1424
region_size:
65536
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00000000045b0000
|
success
|
0 |
0
|
1620994687.48375
NtAllocateVirtualMemory
|
process_identifier:
2440
region_size:
851968
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x0000000000ad0000
|
success
|
0 |
0
|
1620994687.48375
NtAllocateVirtualMemory
|
process_identifier:
2440
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0000000000b20000
|
success
|
0 |
0
|
1620994689.38975
NtProtectVirtualMemory
|
process_identifier:
2440
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1781000
|
success
|
0 |
0
|
1620994690.01475
NtProtectVirtualMemory
|
process_identifier:
2440
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef19fe000
|
success
|
0 |
0
|
1620994690.01475
NtProtectVirtualMemory
|
process_identifier:
2440
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef19fe000
|
success
|
0 |
0
|
1620994690.32675
NtProtectVirtualMemory
|
process_identifier:
2440
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef19ff000
|
success
|
0 |
0
|
1620994690.32675
NtProtectVirtualMemory
|
process_identifier:
2440
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef19ff000
|
success
|
0 |
0
|
1620994690.32675
NtProtectVirtualMemory
|
process_identifier:
2440
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef19ff000
|
success
|
0 |
0
|
1620994690.34275
NtProtectVirtualMemory
|
process_identifier:
2440
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef19ff000
|
success
|
0 |
0
|
1620994690.34275
NtProtectVirtualMemory
|
process_identifier:
2440
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef19ff000
|
success
|
0 |
0
|
1620994690.34275
NtProtectVirtualMemory
|
process_identifier:
2440
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef19ff000
|
success
|
0 |
0
|
1620994690.34275
NtProtectVirtualMemory
|
process_identifier:
2440
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef19ff000
|
success
|
0 |
0
|
1620994690.34275
NtProtectVirtualMemory
|
process_identifier:
2440
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef19ff000
|
success
|
0 |
0
|
1620994690.34275
NtProtectVirtualMemory
|
process_identifier:
2440
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1a00000
|
success
|
0 |
0
|
1620994690.35875
NtProtectVirtualMemory
|
process_identifier:
2440
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1a00000
|
success
|
0 |
0
|
1620994690.35875
NtProtectVirtualMemory
|
process_identifier:
2440
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1a00000
|
success
|
0 |
0
|
1620994690.35875
NtProtectVirtualMemory
|
process_identifier:
2440
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1a00000
|
success
|
0 |
0
|
1620994690.35875
NtProtectVirtualMemory
|
process_identifier:
2440
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1a00000
|
success
|
0 |
0
|
1620994690.35875
NtProtectVirtualMemory
|
process_identifier:
2440
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1a01000
|
success
|
0 |
0
|
1620994690.35875
NtProtectVirtualMemory
|
process_identifier:
2440
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1a01000
|
success
|
0 |
0
|
1620994690.35875
NtProtectVirtualMemory
|
process_identifier:
2440
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1a01000
|
success
|
0 |
0
|
1620994690.35875
NtProtectVirtualMemory
|
process_identifier:
2440
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1a01000
|
success
|
0 |
0
|
1620994690.35875
NtProtectVirtualMemory
|
process_identifier:
2440
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef19fe000
|
success
|
0 |
0
|
1620994691.26475
NtAllocateVirtualMemory
|
process_identifier:
2440
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff00032000
|
success
|
0 |
0
|
1620994691.46775
NtAllocateVirtualMemory
|
process_identifier:
2440
region_size:
589824
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
1056768
(MEM_RESERVE|MEM_TOP_DOWN)
base_address:
0x000007fffff10000
|
success
|
0 |
0
|
1620994691.48375
NtAllocateVirtualMemory
|
process_identifier:
2440
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007fffff10000
|
success
|
0 |
0
|
1620994691.48375
NtAllocateVirtualMemory
|
process_identifier:
2440
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007fffff10000
|
success
|
0 |
0
|
1620994691.48375
NtAllocateVirtualMemory
|
process_identifier:
2440
region_size:
65536
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
1056768
(MEM_RESERVE|MEM_TOP_DOWN)
base_address:
0x000007fffff00000
|
success
|
0 |
0
|
1620994691.48375
NtAllocateVirtualMemory
|
process_identifier:
2440
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007fffff00000
|
success
|
0 |
0
|
1620994691.49875
NtAllocateVirtualMemory
|
process_identifier:
2440
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff000ea000
|
success
|
0 |
0
|
1620994691.52975
NtAllocateVirtualMemory
|
process_identifier:
2440
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff00022000
|
success
|
0 |
0
|
1620994691.74875
NtAllocateVirtualMemory
|
process_identifier:
2440
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff00033000
|
success
|
0 |
0
|
1620994691.74875
NtAllocateVirtualMemory
|
process_identifier:
2440
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff00034000
|
success
|
0 |
0
|
1620994691.82675
NtAllocateVirtualMemory
|
process_identifier:
2440
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff000fa000
|
success
|
0 |
0
|
1620994691.82675
NtAllocateVirtualMemory
|
process_identifier:
2440
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff00122000
|
success
|
0 |
0
|
1620994691.82675
NtAllocateVirtualMemory
|
process_identifier:
2440
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff000fd000
|
success
|
0 |
0
|
1620994691.93675
NtAllocateVirtualMemory
|
process_identifier:
2440
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff0003c000
|
success
|
0 |
0
|
1620994692.37375
NtAllocateVirtualMemory
|
process_identifier:
2440
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff00180000
|
success
|
0 |
0
|
1620994693.07675
NtAllocateVirtualMemory
|
process_identifier:
2440
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff00035000
|
success
|
0 |
0
|
1620994693.93675
NtAllocateVirtualMemory
|
process_identifier:
2440
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff00036000
|
success
|
0 |
0
|
1620994695.51475
NtAllocateVirtualMemory
|
process_identifier:
2440
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff00038000
|
success
|
0 |
0
|
1620994695.68675
NtAllocateVirtualMemory
|
process_identifier:
2440
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff00039000
|
success
|
0 |
0
|
1620994695.71775
NtAllocateVirtualMemory
|
process_identifier:
2440
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff001c0000
|
success
|
0 |
0
|
1620994696.15475
NtAllocateVirtualMemory
|
process_identifier:
2440
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff0004f000
|
success
|
0 |
0
|
1620994696.15475
NtAllocateVirtualMemory
|
process_identifier:
2440
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff00084000
|
success
|
0 |
0
|