| Time & API |
Arguments |
Status |
Return |
Repeated |
1619925770.207124
NtAllocateVirtualMemory
|
process_identifier:
912
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x01df0000
|
success
|
0 |
0
|
1619925770.395124
NtProtectVirtualMemory
|
process_identifier:
912
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
24576
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00476000
|
success
|
0 |
0
|
1619925770.395124
NtAllocateVirtualMemory
|
process_identifier:
912
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x03140000
|
success
|
0 |
0
|
1619925781.003874
NtAllocateVirtualMemory
|
process_identifier:
2216
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004d0000
|
success
|
0 |
0
|
1619925781.035874
NtProtectVirtualMemory
|
process_identifier:
2216
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
24576
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00476000
|
success
|
0 |
0
|
1619925781.035874
NtAllocateVirtualMemory
|
process_identifier:
2216
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x01fc0000
|
success
|
0 |
0
|
1619925787.316751
NtAllocateVirtualMemory
|
process_identifier:
2032
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003e0000
|
success
|
0 |
0
|
1619925787.456751
NtProtectVirtualMemory
|
process_identifier:
2032
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
24576
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00476000
|
success
|
0 |
0
|
1619925787.472751
NtAllocateVirtualMemory
|
process_identifier:
2032
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x007a0000
|
success
|
0 |
0
|
1619925791.097999
NtAllocateVirtualMemory
|
process_identifier:
920
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x007e0000
|
success
|
0 |
0
|
1619925791.285999
NtProtectVirtualMemory
|
process_identifier:
920
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
24576
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00476000
|
success
|
0 |
0
|
1619925791.300999
NtAllocateVirtualMemory
|
process_identifier:
920
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x02000000
|
success
|
0 |
0
|
1619925798.269874
NtAllocateVirtualMemory
|
process_identifier:
2548
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003f0000
|
success
|
0 |
0
|
1619925798.363874
NtProtectVirtualMemory
|
process_identifier:
2548
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
24576
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00476000
|
success
|
0 |
0
|
1619925798.378874
NtAllocateVirtualMemory
|
process_identifier:
2548
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x007b0000
|
success
|
0 |
0
|
1619925799.176626
NtAllocateVirtualMemory
|
process_identifier:
2844
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00320000
|
success
|
0 |
0
|
1619925799.239626
NtProtectVirtualMemory
|
process_identifier:
2844
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
24576
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00476000
|
success
|
0 |
0
|
1619925799.254626
NtAllocateVirtualMemory
|
process_identifier:
2844
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x003e0000
|
success
|
0 |
0
|
1619925802.676501
NtAllocateVirtualMemory
|
process_identifier:
3172
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003e0000
|
success
|
0 |
0
|
1619925802.770501
NtProtectVirtualMemory
|
process_identifier:
3172
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
24576
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00476000
|
success
|
0 |
0
|
1619925802.801501
NtAllocateVirtualMemory
|
process_identifier:
3172
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x01fb0000
|
success
|
0 |
0
|