| Time & API |
Arguments |
Status |
Return |
Repeated |
1619134514.676436
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
2162688
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00c80000
|
success
|
0 |
0
|
1619134514.676436
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00e50000
|
success
|
0 |
0
|
1619134515.051436
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
1769472
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x02290000
|
success
|
0 |
0
|
1619134515.051436
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02400000
|
success
|
0 |
0
|
1619134515.161436
NtProtectVirtualMemory
|
process_identifier:
2764
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73e71000
|
success
|
0 |
0
|
1619134515.395436
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
393216
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00480000
|
success
|
0 |
0
|
1619134515.395436
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004a0000
|
success
|
0 |
0
|
1619134515.395436
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003aa000
|
success
|
0 |
0
|
1619134515.395436
NtProtectVirtualMemory
|
process_identifier:
2764
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73e72000
|
success
|
0 |
0
|
1619134515.395436
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003a2000
|
success
|
0 |
0
|
1619134515.708436
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003b2000
|
success
|
0 |
0
|
1619134515.801436
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003d5000
|
success
|
0 |
0
|
1619134515.801436
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003db000
|
success
|
0 |
0
|
1619134515.801436
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003d7000
|
success
|
0 |
0
|
1619134515.880436
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003b3000
|
success
|
0 |
0
|
1619134515.911436
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003bc000
|
success
|
0 |
0
|
1619134515.926436
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003b4000
|
success
|
0 |
0
|
1619134515.942436
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00570000
|
success
|
0 |
0
|
1619134515.973436
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003b5000
|
success
|
0 |
0
|
1619134515.973436
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003b6000
|
success
|
0 |
0
|
1619134515.989436
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00571000
|
success
|
0 |
0
|
1619134516.020436
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003b7000
|
success
|
0 |
0
|
1619134516.051436
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003b8000
|
success
|
0 |
0
|
1619134516.051436
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003ac000
|
success
|
0 |
0
|
1619134516.051436
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003bd000
|
success
|
0 |
0
|
1619134516.067436
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00573000
|
success
|
0 |
0
|
1619134516.067436
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003b9000
|
success
|
0 |
0
|
1619134516.098436
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00579000
|
success
|
0 |
0
|
1619134516.098436
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003c6000
|
success
|
0 |
0
|
1619134516.098436
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003ca000
|
success
|
0 |
0
|
1619134516.098436
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003c7000
|
success
|
0 |
0
|
1619134516.114436
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003a3000
|
success
|
0 |
0
|
1619134516.130436
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00580000
|
success
|
0 |
0
|
1619134516.145436
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0057a000
|
success
|
0 |
0
|
1619134516.208436
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00581000
|
success
|
0 |
0
|
1619134516.208436
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003be000
|
success
|
0 |
0
|
1619134516.208436
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0057b000
|
success
|
0 |
0
|
1619134516.223436
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00582000
|
success
|
0 |
0
|
1619134516.223436
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0057c000
|
success
|
0 |
0
|
1619134516.255436
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004a1000
|
success
|
0 |
0
|
1619134516.270436
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004a2000
|
success
|
0 |
0
|
1619134516.270436
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004a3000
|
success
|
0 |
0
|
1619134516.270436
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004a4000
|
success
|
0 |
0
|
1619134516.270436
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
16384
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004a5000
|
success
|
0 |
0
|
1619134516.270436
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
69632
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004a9000
|
success
|
0 |
0
|
1619134516.286436
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00583000
|
success
|
0 |
0
|
1619134516.301436
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0057d000
|
success
|
0 |
0
|
1619134516.301436
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004ba000
|
success
|
0 |
0
|
1619134516.301436
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004bb000
|
success
|
0 |
0
|
1619134516.301436
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004bc000
|
success
|
0 |
0
|