| Time & API | Arguments | Status | Return | Repeated | 
                            
                        
                        
                            
| 1619948414.181615 CreateProcessInternalW
 
 | thread_identifier:
            
                
                    3064 thread_handle:
            
                
                    0x00000020
 process_identifier:
            
                
                    580
 current_directory:
 filepath:
 track:
            
                
                    1
 command_line:
            
                
                    winver
 filepath_r:
 stack_pivoted:
            
                
                    0
 creation_flags:
            
                
                    4
                
            
            
                (CREATE_SUSPENDED)
 process_handle:
            
                
                    0x0000002c
 inherit_handles:
            
                
                    0
 
 | success | 1 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948414.181615 NtGetContextThread
 
 | thread_handle:
            
                
                    0x00000020 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948414.181615 WriteProcessMemory
 
 | process_identifier:
            
                
                    580 buffer:
            
                
                    è   ÇWè   Ãè   ReadProcessMemory WÿÓÆè
   VirtualAlloc WÿÓè    [ë@ j@h 0  ÿ³W@ j ÿÐ
Àt ÇW@ j ÿ0WÿpÿpÿÖ
ÀtÇó
  WÃÌ[  $ Ù   d¡0   @@ H y3 2 uò@ÃUåWEÂR<RxÂr Æ1ÉAÆ>ÇocAduïÆr$·4N4°r_ÉÂ
 process_handle:
            
                
                    0x0000002c
 base_address:
            
                
                    0x009316c1
 
 | success | 1 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948414.572615 NtResumeThread
 
 | thread_handle:
            
                
                    0x00000020 suspend_count:
            
                
                    1
 process_identifier:
            
                
                    580
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619961362.395125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1424 region_size:
            
                
                    24576
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0x00000088
 allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
 base_address:
            
                
                    0x06cf0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619961362.395125 WriteProcessMemory
 
 | process_identifier:
            
                
                    1424 buffer:
 process_handle:
            
                
                    0x00000088
 base_address:
            
                
                    0x06cf0000
 
 | success | 1 | 0 | 
                    
                
                    
                        
                        
                            
| 1619961368.411125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    276 region_size:
            
                
                    24576
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0x000000a4
 allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
 base_address:
            
                
                    0x00210000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619961368.411125 WriteProcessMemory
 
 | process_identifier:
            
                
                    276 buffer:
 process_handle:
            
                
                    0x000000a4
 base_address:
            
                
                    0x00210000
 
 | success | 1 | 0 | 
                    
                
                    
                        
                        
                            
| 1619961368.411125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    372 region_size:
            
                
                    24576
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0x000000a4
 allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
 base_address:
            
                
                    0x00c00000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619961368.411125 WriteProcessMemory
 
 | process_identifier:
            
                
                    372 buffer:
 process_handle:
            
                
                    0x000000a4
 base_address:
            
                
                    0x00c00000
 
 | success | 1 | 0 | 
                    
                
                    
                        
                        
                            
| 1619961368.411125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    424 region_size:
            
                
                    24576
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0x000000a4
 allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
 base_address:
            
                
                    0x01310000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619961368.411125 WriteProcessMemory
 
 | process_identifier:
            
                
                    424 buffer:
 process_handle:
            
                
                    0x000000a4
 base_address:
            
                
                    0x01310000
 
 | success | 1 | 0 | 
                    
                
                    
                        
                        
                            
| 1619961368.411125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    432 region_size:
            
                
                    24576
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0x000000a4
 allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
 base_address:
            
                
                    0x00110000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619961368.411125 WriteProcessMemory
 
 | process_identifier:
            
                
                    432 buffer:
 process_handle:
            
                
                    0x000000a4
 base_address:
            
                
                    0x00110000
 
 | success | 1 | 0 | 
                    
                
                    
                        
                        
                            
| 1619961368.411125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    476 region_size:
            
                
                    24576
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0x000000a4
 allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
 base_address:
            
                
                    0x00110000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619961368.411125 WriteProcessMemory
 
 | process_identifier:
            
                
                    476 buffer:
 process_handle:
            
                
                    0x000000a4
 base_address:
            
                
                    0x00110000
 
 | success | 1 | 0 | 
                    
                
                    
                        
                        
                            
| 1619961368.411125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    508 region_size:
            
                
                    24576
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0x000000a4
 allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
 base_address:
            
                
                    0x001d0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619961368.411125 WriteProcessMemory
 
 | process_identifier:
            
                
                    508 buffer:
 process_handle:
            
                
                    0x000000a4
 base_address:
            
                
                    0x001d0000
 
 | success | 1 | 0 | 
                    
                
                    
                        
                        
                            
| 1619961368.411125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    536 region_size:
            
                
                    24576
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0x000000a4
 allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
 base_address:
            
                
                    0x009e0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619961368.411125 WriteProcessMemory
 
 | process_identifier:
            
                
                    536 buffer:
 process_handle:
            
                
                    0x000000a4
 base_address:
            
                
                    0x009e0000
 
 | success | 1 | 0 | 
                    
                
                    
                        
                        
                            
| 1619961368.426125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    544 region_size:
            
                
                    24576
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0x000000a4
 allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
 base_address:
            
                
                    0x00190000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619961368.426125 WriteProcessMemory
 
 | process_identifier:
            
                
                    544 buffer:
 process_handle:
            
                
                    0x000000a4
 base_address:
            
                
                    0x00190000
 
 | success | 1 | 0 | 
                    
                
                    
                        
                        
                            
| 1619961368.426125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    656 region_size:
            
                
                    24576
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0x000000a4
 allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
 base_address:
            
                
                    0x00400000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619961368.426125 WriteProcessMemory
 
 | process_identifier:
            
                
                    656 buffer:
 process_handle:
            
                
                    0x000000a4
 base_address:
            
                
                    0x00400000
 
 | success | 1 | 0 | 
                    
                
                    
                        
                        
                            
| 1619961368.426125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    720 region_size:
            
                
                    24576
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0x000000a4
 allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
 base_address:
            
                
                    0x000d0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619961368.426125 WriteProcessMemory
 
 | process_identifier:
            
                
                    720 buffer:
 process_handle:
            
                
                    0x000000a4
 base_address:
            
                
                    0x000d0000
 
 | success | 1 | 0 | 
                    
                
                    
                        
                        
                            
| 1619961368.426125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    788 region_size:
            
                
                    24576
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0x000000a4
 allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
 base_address:
            
                
                    0x001c0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619961368.426125 WriteProcessMemory
 
 | process_identifier:
            
                
                    788 buffer:
 process_handle:
            
                
                    0x000000a4
 base_address:
            
                
                    0x001c0000
 
 | success | 1 | 0 | 
                    
                
                    
                        
                        
                            
| 1619961368.426125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    868 region_size:
            
                
                    24576
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0x000000a4
 allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
 base_address:
            
                
                    0x00e50000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619961368.426125 WriteProcessMemory
 
 | process_identifier:
            
                
                    868 buffer:
 process_handle:
            
                
                    0x000000a4
 base_address:
            
                
                    0x00e50000
 
 | success | 1 | 0 | 
                    
                
                    
                        
                        
                            
| 1619961368.426125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    924 region_size:
            
                
                    24576
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0x000000a4
 allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
 base_address:
            
                
                    0x00e50000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619961368.426125 WriteProcessMemory
 
 | process_identifier:
            
                
                    924 buffer:
 process_handle:
            
                
                    0x000000a4
 base_address:
            
                
                    0x00e50000
 
 | success | 1 | 0 | 
                    
                
                    
                        
                        
                            
| 1619961368.426125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    956 region_size:
            
                
                    24576
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0x000000a4
 allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
 base_address:
            
                
                    0x00f70000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619961368.426125 WriteProcessMemory
 
 | process_identifier:
            
                
                    956 buffer:
 process_handle:
            
                
                    0x000000a4
 base_address:
            
                
                    0x00f70000
 
 | success | 1 | 0 | 
                    
                
                    
                        
                        
                            
| 1619961368.426125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    540 region_size:
            
                
                    24576
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0x000000a4
 allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
 base_address:
            
                
                    0x00d00000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619961368.426125 WriteProcessMemory
 
 | process_identifier:
            
                
                    540 buffer:
 process_handle:
            
                
                    0x000000a4
 base_address:
            
                
                    0x00d00000
 
 | success | 1 | 0 | 
                    
                
                    
                        
                        
                            
| 1619961368.426125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1080 region_size:
            
                
                    24576
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0x000000a4
 allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
 base_address:
            
                
                    0x014f0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619961368.426125 WriteProcessMemory
 
 | process_identifier:
            
                
                    1080 buffer:
 process_handle:
            
                
                    0x000000a4
 base_address:
            
                
                    0x014f0000
 
 | success | 1 | 0 | 
                    
                
                    
                        
                        
                            
| 1619961368.442125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1260 region_size:
            
                
                    24576
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0x000000a4
 allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
 base_address:
            
                
                    0x00190000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619961368.442125 WriteProcessMemory
 
 | process_identifier:
            
                
                    1260 buffer:
 process_handle:
            
                
                    0x000000a4
 base_address:
            
                
                    0x00190000
 
 | success | 1 | 0 | 
                    
                
                    
                        
                        
                            
| 1619961368.442125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1288 region_size:
            
                
                    24576
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0x000000a4
 allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
 base_address:
            
                
                    0x00180000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619961368.442125 WriteProcessMemory
 
 | process_identifier:
            
                
                    1288 buffer:
 process_handle:
            
                
                    0x000000a4
 base_address:
            
                
                    0x00180000
 
 | success | 1 | 0 | 
                    
                
                    
                        
                        
                            
| 1619961368.442125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1336 region_size:
            
                
                    24576
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0x000000a4
 allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
 base_address:
            
                
                    0x00350000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619961368.442125 WriteProcessMemory
 
 | process_identifier:
            
                
                    1336 buffer:
 process_handle:
            
                
                    0x000000a4
 base_address:
            
                
                    0x00350000
 
 | success | 1 | 0 | 
                    
                
                    
                        
                        
                            
| 1619961368.442125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1384 region_size:
            
                
                    24576
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0x000000a4
 allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
 base_address:
            
                
                    0x00130000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619961368.442125 WriteProcessMemory
 
 | process_identifier:
            
                
                    1384 buffer:
 process_handle:
            
                
                    0x000000a4
 base_address:
            
                
                    0x00130000
 
 | success | 1 | 0 | 
                    
                
                    
                        
                        
                            
| 1619961368.442125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1424 region_size:
            
                
                    24576
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0x000000a4
 allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
 base_address:
            
                
                    0x06d00000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619961368.442125 WriteProcessMemory
 
 | process_identifier:
            
                
                    1424 buffer:
 process_handle:
            
                
                    0x000000a4
 base_address:
            
                
                    0x06d00000
 
 | success | 1 | 0 | 
                    
                
                    
                        
                        
                            
| 1619961368.442125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1592 region_size:
            
                
                    24576
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0x000000a4
 allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
 base_address:
            
                
                    0x004b0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619961368.442125 WriteProcessMemory
 
 | process_identifier:
            
                
                    1592 buffer:
 process_handle:
            
                
                    0x000000a4
 base_address:
            
                
                    0x004b0000
 
 | success | 1 | 0 |