| Time & API |
Arguments |
Status |
Return |
Repeated |
1619134516.436895
NtAllocateVirtualMemory
|
process_identifier:
3068
region_size:
1245184
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x0000000000850000
|
success
|
0 |
0
|
1619134516.436895
NtAllocateVirtualMemory
|
process_identifier:
3068
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0000000000900000
|
success
|
0 |
0
|
1619134517.296895
NtAllocateVirtualMemory
|
process_identifier:
3068
region_size:
1966080
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x0000000000da0000
|
success
|
0 |
0
|
1619134517.296895
NtAllocateVirtualMemory
|
process_identifier:
3068
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0000000000f00000
|
success
|
0 |
0
|
1619134517.374895
NtProtectVirtualMemory
|
process_identifier:
3068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1b61000
|
success
|
0 |
0
|
1619134517.374895
NtProtectVirtualMemory
|
process_identifier:
3068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1b61000
|
success
|
0 |
0
|
1619134517.405895
NtProtectVirtualMemory
|
process_identifier:
3068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef21e0000
|
success
|
0 |
0
|
1619134517.686895
NtAllocateVirtualMemory
|
process_identifier:
3068
region_size:
2097152
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x0000000000f80000
|
success
|
0 |
0
|
1619134517.686895
NtAllocateVirtualMemory
|
process_identifier:
3068
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0000000001100000
|
success
|
0 |
0
|
1619134517.702895
NtProtectVirtualMemory
|
process_identifier:
3068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1b62000
|
success
|
0 |
0
|
1619134517.702895
NtProtectVirtualMemory
|
process_identifier:
3068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1b62000
|
success
|
0 |
0
|
1619134517.702895
NtProtectVirtualMemory
|
process_identifier:
3068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1b62000
|
success
|
0 |
0
|
1619134517.702895
NtProtectVirtualMemory
|
process_identifier:
3068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1b62000
|
success
|
0 |
0
|
1619134517.702895
NtProtectVirtualMemory
|
process_identifier:
3068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1b62000
|
success
|
0 |
0
|
1619134517.702895
NtProtectVirtualMemory
|
process_identifier:
3068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1b63000
|
success
|
0 |
0
|
1619134517.702895
NtProtectVirtualMemory
|
process_identifier:
3068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1b63000
|
success
|
0 |
0
|
1619134517.702895
NtProtectVirtualMemory
|
process_identifier:
3068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1b63000
|
success
|
0 |
0
|
1619134517.718895
NtProtectVirtualMemory
|
process_identifier:
3068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1b63000
|
success
|
0 |
0
|
1619134517.718895
NtProtectVirtualMemory
|
process_identifier:
3068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1b63000
|
success
|
0 |
0
|
1619134517.718895
NtProtectVirtualMemory
|
process_identifier:
3068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1b63000
|
success
|
0 |
0
|
1619134517.718895
NtProtectVirtualMemory
|
process_identifier:
3068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1b63000
|
success
|
0 |
0
|
1619134517.718895
NtProtectVirtualMemory
|
process_identifier:
3068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1b61000
|
success
|
0 |
0
|
1619134517.718895
NtProtectVirtualMemory
|
process_identifier:
3068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1b62000
|
success
|
0 |
0
|
1619134517.718895
NtProtectVirtualMemory
|
process_identifier:
3068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1b62000
|
success
|
0 |
0
|
1619134517.718895
NtProtectVirtualMemory
|
process_identifier:
3068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1b62000
|
success
|
0 |
0
|
1619134517.718895
NtProtectVirtualMemory
|
process_identifier:
3068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1b62000
|
success
|
0 |
0
|
1619134517.718895
NtProtectVirtualMemory
|
process_identifier:
3068
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1b62000
|
success
|
0 |
0
|
1619134518.093895
NtAllocateVirtualMemory
|
process_identifier:
3068
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff00032000
|
success
|
0 |
0
|
1619134518.124895
NtAllocateVirtualMemory
|
process_identifier:
3068
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff00022000
|
success
|
0 |
0
|
1619134518.280895
NtAllocateVirtualMemory
|
process_identifier:
3068
region_size:
655360
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
1056768
(MEM_RESERVE|MEM_TOP_DOWN)
base_address:
0x000007fffff00000
|
success
|
0 |
0
|
1619134518.280895
NtAllocateVirtualMemory
|
process_identifier:
3068
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007fffff00000
|
success
|
0 |
0
|
1619134518.280895
NtAllocateVirtualMemory
|
process_identifier:
3068
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007fffff00000
|
success
|
0 |
0
|
1619134518.280895
NtAllocateVirtualMemory
|
process_identifier:
3068
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007fffff10000
|
success
|
0 |
0
|
1619134518.280895
NtAllocateVirtualMemory
|
process_identifier:
3068
region_size:
65536
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
1056768
(MEM_RESERVE|MEM_TOP_DOWN)
base_address:
0x000007ffffef0000
|
success
|
0 |
0
|
1619134518.280895
NtAllocateVirtualMemory
|
process_identifier:
3068
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ffffef0000
|
success
|
0 |
0
|
1619134518.280895
NtAllocateVirtualMemory
|
process_identifier:
3068
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff0002a000
|
success
|
0 |
0
|
1619134518.327895
NtAllocateVirtualMemory
|
process_identifier:
3068
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff00033000
|
success
|
0 |
0
|
1619134518.327895
NtAllocateVirtualMemory
|
process_identifier:
3068
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff000dc000
|
success
|
0 |
0
|
1619134518.327895
NtAllocateVirtualMemory
|
process_identifier:
3068
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff00106000
|
success
|
0 |
0
|
1619134518.327895
NtAllocateVirtualMemory
|
process_identifier:
3068
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff000e0000
|
success
|
0 |
0
|
1619134518.577895
NtAllocateVirtualMemory
|
process_identifier:
3068
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff00034000
|
success
|
0 |
0
|
1619134518.624895
NtAllocateVirtualMemory
|
process_identifier:
3068
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff0002b000
|
success
|
0 |
0
|
1619134518.624895
NtAllocateVirtualMemory
|
process_identifier:
3068
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff0003c000
|
success
|
0 |
0
|
1619134519.155895
NtAllocateVirtualMemory
|
process_identifier:
3068
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff00035000
|
success
|
0 |
0
|
1619134519.343895
NtAllocateVirtualMemory
|
process_identifier:
3068
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff00036000
|
success
|
0 |
0
|
1619134519.405895
NtAllocateVirtualMemory
|
process_identifier:
3068
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff00037000
|
success
|
0 |
0
|
1619134520.155895
NtAllocateVirtualMemory
|
process_identifier:
3068
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff00038000
|
success
|
0 |
0
|
1619134520.468895
NtAllocateVirtualMemory
|
process_identifier:
3068
region_size:
20480
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff001e0000
|
success
|
0 |
0
|
1619134520.468895
NtAllocateVirtualMemory
|
process_identifier:
3068
region_size:
16384
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff001e5000
|
success
|
0 |
0
|
1619134520.593895
NtAllocateVirtualMemory
|
process_identifier:
3068
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff001e9000
|
success
|
0 |
0
|