Time & API |
Arguments |
Status |
Return |
Repeated |
1621007381.731999
NtProtectVirtualMemory
|
process_identifier:
2216
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00400000
|
success
|
0 |
0
|
1621007381.731999
NtProtectVirtualMemory
|
process_identifier:
2216
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
40960
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00401000
|
success
|
0 |
0
|
1621007381.731999
NtProtectVirtualMemory
|
process_identifier:
2216
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
20480
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x0040f000
|
success
|
0 |
0
|
1621007382.903876
NtAllocateVirtualMemory
|
process_identifier:
196
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003e0000
|
success
|
0 |
0
|
1621007392.977938
NtProtectVirtualMemory
|
process_identifier:
2632
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x77531000
|
success
|
0 |
0
|
1621007392.977938
NtProtectVirtualMemory
|
process_identifier:
2632
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x75a01000
|
success
|
0 |
0
|
1621007392.977938
NtAllocateVirtualMemory
|
process_identifier:
2632
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004d0000
|
success
|
0 |
0
|
1621007392.992938
NtAllocateVirtualMemory
|
process_identifier:
2632
region_size:
819200
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02b00000
|
success
|
0 |
0
|
1621007414.271069
NtProtectVirtualMemory
|
process_identifier:
2656
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x77531000
|
success
|
0 |
0
|
1621007414.271069
NtProtectVirtualMemory
|
process_identifier:
2656
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x75a01000
|
success
|
0 |
0
|
1621007414.271069
NtAllocateVirtualMemory
|
process_identifier:
2656
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00500000
|
success
|
0 |
0
|
1621007414.271069
NtAllocateVirtualMemory
|
process_identifier:
2656
region_size:
442368
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00540000
|
success
|
0 |
0
|
1621007421.612079
NtProtectVirtualMemory
|
process_identifier:
2840
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x1004b000
|
success
|
0 |
0
|
1621007421.612079
NtProtectVirtualMemory
|
process_identifier:
2840
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x743c1000
|
success
|
0 |
0
|
1621007421.612079
NtProtectVirtualMemory
|
process_identifier:
2840
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x74561000
|
success
|
0 |
0
|
1621007421.690079
NtAllocateVirtualMemory
|
process_identifier:
2840
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02610000
|
success
|
0 |
0
|
1621007421.690079
NtAllocateVirtualMemory
|
process_identifier:
2840
region_size:
258048
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02620000
|
success
|
0 |
0
|
1621007430.60259
NtAllocateVirtualMemory
|
process_identifier:
2144
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x007e0000
|
success
|
0 |
0
|
1621007430.60259
NtAllocateVirtualMemory
|
process_identifier:
2144
region_size:
40960
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x007f0000
|
success
|
0 |
0
|
1621007430.60259
NtAllocateVirtualMemory
|
process_identifier:
2144
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x007f0000
|
success
|
0 |
0
|
1621007430.60259
NtAllocateVirtualMemory
|
process_identifier:
2144
region_size:
425984
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02c30000
|
success
|
0 |
0
|
1621007430.99359
NtProtectVirtualMemory
|
process_identifier:
2144
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x77531000
|
success
|
0 |
0
|
1621007430.99359
NtProtectVirtualMemory
|
process_identifier:
2144
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x75a01000
|
success
|
0 |
0
|
1621007430.99359
NtProtectVirtualMemory
|
process_identifier:
2144
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x02e57000
|
success
|
0 |
0
|
1621007430.99359
NtProtectVirtualMemory
|
process_identifier:
2144
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x0224a000
|
success
|
0 |
0
|
1621007430.99359
NtProtectVirtualMemory
|
process_identifier:
2144
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x02c8a000
|
success
|
0 |
0
|
1621007431.00959
NtAllocateVirtualMemory
|
process_identifier:
2144
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02250000
|
success
|
0 |
0
|
1621007431.00959
NtAllocateVirtualMemory
|
process_identifier:
2144
region_size:
143360
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x022b0000
|
success
|
0 |
0
|
1621007431.10259
NtAllocateVirtualMemory
|
process_identifier:
2144
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02260000
|
success
|
0 |
0
|
1621007431.11859
NtAllocateVirtualMemory
|
process_identifier:
2144
region_size:
159744
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x022b0000
|
success
|
0 |
0
|
1621007431.14959
NtAllocateVirtualMemory
|
process_identifier:
2144
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x022b0000
|
success
|
0 |
0
|
1621007431.14959
NtAllocateVirtualMemory
|
process_identifier:
2144
region_size:
598016
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x030f0000
|
success
|
0 |
0
|
1621007431.35259
NtAllocateVirtualMemory
|
process_identifier:
2144
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x022c0000
|
success
|
0 |
0
|
1621007431.36859
NtAllocateVirtualMemory
|
process_identifier:
2144
region_size:
352256
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x030f0000
|
success
|
0 |
0
|
1621007431.44659
NtAllocateVirtualMemory
|
process_identifier:
2144
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x022d0000
|
success
|
0 |
0
|
1621007431.50959
NtAllocateVirtualMemory
|
process_identifier:
2144
region_size:
360448
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x030f0000
|
success
|
0 |
0
|