| Time & API |
Arguments |
Status |
Return |
Repeated |
1619134516.460474
NtAllocateVirtualMemory
|
process_identifier:
2080
region_size:
1245184
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x006c0000
|
success
|
0 |
0
|
1619134516.460474
NtAllocateVirtualMemory
|
process_identifier:
2080
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x007b0000
|
success
|
0 |
0
|
1619134516.867474
NtAllocateVirtualMemory
|
process_identifier:
2080
region_size:
720896
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x003d0000
|
success
|
0 |
0
|
1619134516.867474
NtAllocateVirtualMemory
|
process_identifier:
2080
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00440000
|
success
|
0 |
0
|
1619134517.007474
NtProtectVirtualMemory
|
process_identifier:
2080
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73e71000
|
success
|
0 |
0
|
1619134517.288474
NtAllocateVirtualMemory
|
process_identifier:
2080
region_size:
1966080
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x020d0000
|
success
|
0 |
0
|
1619134517.288474
NtAllocateVirtualMemory
|
process_identifier:
2080
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02270000
|
success
|
0 |
0
|
1619134517.288474
NtAllocateVirtualMemory
|
process_identifier:
2080
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003fa000
|
success
|
0 |
0
|
1619134517.304474
NtProtectVirtualMemory
|
process_identifier:
2080
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73e72000
|
success
|
0 |
0
|
1619134517.304474
NtAllocateVirtualMemory
|
process_identifier:
2080
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003f2000
|
success
|
0 |
0
|
1619134517.585474
NtAllocateVirtualMemory
|
process_identifier:
2080
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00402000
|
success
|
0 |
0
|
1619134517.773474
NtAllocateVirtualMemory
|
process_identifier:
2080
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00425000
|
success
|
0 |
0
|
1619134517.773474
NtAllocateVirtualMemory
|
process_identifier:
2080
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0042b000
|
success
|
0 |
0
|
1619134517.773474
NtAllocateVirtualMemory
|
process_identifier:
2080
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00427000
|
success
|
0 |
0
|
1619134517.976474
NtAllocateVirtualMemory
|
process_identifier:
2080
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00403000
|
success
|
0 |
0
|
1619134518.007474
NtAllocateVirtualMemory
|
process_identifier:
2080
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0040c000
|
success
|
0 |
0
|
1619134518.054474
NtAllocateVirtualMemory
|
process_identifier:
2080
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00840000
|
success
|
0 |
0
|
1619134518.351474
NtAllocateVirtualMemory
|
process_identifier:
2080
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00404000
|
success
|
0 |
0
|
1619134518.367474
NtAllocateVirtualMemory
|
process_identifier:
2080
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00406000
|
success
|
0 |
0
|
1619134518.460474
NtAllocateVirtualMemory
|
process_identifier:
2080
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00407000
|
success
|
0 |
0
|
1619134518.460474
NtAllocateVirtualMemory
|
process_identifier:
2080
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00408000
|
success
|
0 |
0
|
1619134518.460474
NtAllocateVirtualMemory
|
process_identifier:
2080
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00409000
|
success
|
0 |
0
|
1619134518.523474
NtAllocateVirtualMemory
|
process_identifier:
2080
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0041a000
|
success
|
0 |
0
|
1619134518.523474
NtAllocateVirtualMemory
|
process_identifier:
2080
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00417000
|
success
|
0 |
0
|
1619134518.632474
NtAllocateVirtualMemory
|
process_identifier:
2080
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00416000
|
success
|
0 |
0
|
1619134518.679474
NtAllocateVirtualMemory
|
process_identifier:
2080
region_size:
12288
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00841000
|
success
|
0 |
0
|
1619134518.913474
NtAllocateVirtualMemory
|
process_identifier:
2080
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0040a000
|
success
|
0 |
0
|
1619134519.054474
NtAllocateVirtualMemory
|
process_identifier:
2080
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x008d0000
|
success
|
0 |
0
|
1619134519.054474
NtAllocateVirtualMemory
|
process_identifier:
2080
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x008d1000
|
success
|
0 |
0
|
1619134519.070474
NtAllocateVirtualMemory
|
process_identifier:
2080
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00844000
|
success
|
0 |
0
|
1619134519.304474
NtAllocateVirtualMemory
|
process_identifier:
2080
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x008d2000
|
success
|
0 |
0
|
1619134519.351474
NtAllocateVirtualMemory
|
process_identifier:
2080
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00845000
|
success
|
0 |
0
|
1619134519.367474
NtAllocateVirtualMemory
|
process_identifier:
2080
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x008d3000
|
success
|
0 |
0
|
1619134519.382474
NtAllocateVirtualMemory
|
process_identifier:
2080
region_size:
12288
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00846000
|
success
|
0 |
0
|
1619134519.413474
NtAllocateVirtualMemory
|
process_identifier:
2080
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x008d4000
|
success
|
0 |
0
|
1619134519.413474
NtAllocateVirtualMemory
|
process_identifier:
2080
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00849000
|
success
|
0 |
0
|
1619134560.413474
NtAllocateVirtualMemory
|
process_identifier:
2080
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0040d000
|
success
|
0 |
0
|
1619134560.413474
NtAllocateVirtualMemory
|
process_identifier:
2080
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0084a000
|
success
|
0 |
0
|
1619134560.429474
NtAllocateVirtualMemory
|
process_identifier:
2080
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00441000
|
success
|
0 |
0
|
1619134560.492474
NtAllocateVirtualMemory
|
process_identifier:
2080
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0084b000
|
success
|
0 |
0
|
1619134560.554474
NtAllocateVirtualMemory
|
process_identifier:
2080
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003fc000
|
success
|
0 |
0
|
1619134560.585474
NtAllocateVirtualMemory
|
process_identifier:
2080
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0084c000
|
success
|
0 |
0
|
1619134560.663474
NtAllocateVirtualMemory
|
process_identifier:
2080
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x008d5000
|
success
|
0 |
0
|
1619134560.679474
NtAllocateVirtualMemory
|
process_identifier:
2080
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0084d000
|
success
|
0 |
0
|
1619134560.804474
NtProtectVirtualMemory
|
process_identifier:
2080
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
269824
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x05260400
|
failed
|
3221225550 |
0
|
1619134565.585474
NtAllocateVirtualMemory
|
process_identifier:
2080
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0084f000
|
success
|
0 |
0
|
1619134565.585474
NtAllocateVirtualMemory
|
process_identifier:
2080
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x008d6000
|
success
|
0 |
0
|
1619134565.585474
NtAllocateVirtualMemory
|
process_identifier:
2080
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x045a0000
|
success
|
0 |
0
|
1619134565.601474
NtAllocateVirtualMemory
|
process_identifier:
2080
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x045a1000
|
success
|
0 |
0
|
1619134565.679474
NtAllocateVirtualMemory
|
process_identifier:
2080
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x045a2000
|
success
|
0 |
0
|