Time & API |
Arguments |
Status |
Return |
Repeated |
1727545303.0785
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x02480000
region_size:
745472
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
2416
|
success
|
0 |
0
|
1727545401.9685
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x038e0000
region_size:
405504
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545402.0625
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x035b0000
region_size:
4096
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545402.0625
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x035b0000
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545402.0625
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x76789000
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545402.0625
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x035b0000
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545402.0625
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x03600000
region_size:
4096
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545402.0625
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x03600000
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545402.0625
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x03600000
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545402.0625
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x035b0000
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545402.0625
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x76789000
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545402.0625
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x03610000
region_size:
4096
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545402.0625
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x03610000
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545402.0625
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x03610000
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545402.0625
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x03660000
region_size:
4096
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545402.0625
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x03660000
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545402.0625
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x76747000
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545402.0625
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x03660000
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545402.0625
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x03670000
region_size:
4096
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545402.0625
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x03670000
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545402.0625
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x03670000
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545402.0625
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x03660000
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545402.0625
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x76747000
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545402.0625
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x036c0000
region_size:
4096
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545402.0625
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x036c0000
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545402.0625
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x036c0000
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545402.0625
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x76747000
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545402.0625
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x036d0000
region_size:
4096
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545402.0625
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x036d0000
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545402.0625
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x76747000
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545402.0625
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x036d0000
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545402.0625
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x036e0000
region_size:
4096
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545402.0625
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x036e0000
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545402.0625
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x036e0000
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545402.0785
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x036d0000
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545402.0785
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x76747000
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545402.0785
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x036f0000
region_size:
4096
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545402.0785
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x036f0000
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545402.0785
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x036f0000
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545402.0785
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x76747000
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545402.0785
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x03700000
region_size:
4096
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545402.0785
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x03700000
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545402.0785
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x76747000
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545402.0785
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x03700000
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545402.0785
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x03810000
region_size:
4096
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545402.0785
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x03810000
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545402.0785
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x03810000
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545402.0785
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x03700000
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545402.0785
NtProtectVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x76747000
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|
1727545402.0785
NtAllocateVirtualMemory
|
process_handle:
0xffffffff
base_address:
0x03820000
region_size:
4096
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
protection:
64
(PAGE_EXECUTE_READWRITE)
process_identifier:
348
|
success
|
0 |
0
|