| Time & API |
Arguments |
Status |
Return |
Repeated |
1620833274.494374
NtAllocateVirtualMemory
|
process_identifier:
784
region_size:
61440
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x01c10000
|
success
|
0 |
0
|
1620833274.494374
NtProtectVirtualMemory
|
process_identifier:
784
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
188416
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00400000
|
success
|
0 |
0
|
1620833274.494374
NtAllocateVirtualMemory
|
process_identifier:
784
region_size:
28672
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x01c20000
|
success
|
0 |
0
|
1620833274.494374
NtProtectVirtualMemory
|
process_identifier:
784
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
24576
protection:
3758096448
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x0040c000
|
failed
|
3221225541 |
0
|
1620833274.494374
NtProtectVirtualMemory
|
process_identifier:
784
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
3221225536
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00412000
|
failed
|
3221225541 |
0
|
1620833274.510374
NtProtectVirtualMemory
|
process_identifier:
784
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00400000
|
success
|
0 |
0
|
1620833275.635024
NtAllocateVirtualMemory
|
process_identifier:
3076
region_size:
61440
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00340000
|
success
|
0 |
0
|
1620833275.635024
NtProtectVirtualMemory
|
process_identifier:
3076
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
188416
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00400000
|
success
|
0 |
0
|
1620833275.635024
NtAllocateVirtualMemory
|
process_identifier:
3076
region_size:
28672
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00350000
|
success
|
0 |
0
|
1620833275.635024
NtProtectVirtualMemory
|
process_identifier:
3076
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
24576
protection:
3758096448
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x0040c000
|
failed
|
3221225541 |
0
|
1620833275.635024
NtProtectVirtualMemory
|
process_identifier:
3076
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
3221225536
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00412000
|
failed
|
3221225541 |
0
|
1620833275.635024
NtProtectVirtualMemory
|
process_identifier:
3076
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00400000
|
success
|
0 |
0
|
1620833275.698024
NtProtectVirtualMemory
|
process_identifier:
3076
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x77d4f000
|
success
|
0 |
0
|
1620833275.698024
NtAllocateVirtualMemory
|
process_identifier:
3076
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00380000
|
success
|
0 |
0
|