| Time & API |
Arguments |
Status |
Return |
Repeated |
1620124434.468771
NtAllocateVirtualMemory
|
process_identifier:
580
region_size:
655360
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00000000007e0000
|
success
|
0 |
0
|
1620124434.468771
NtAllocateVirtualMemory
|
process_identifier:
580
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0000000000800000
|
success
|
0 |
0
|
1620124434.968771
NtAllocateVirtualMemory
|
process_identifier:
580
region_size:
720896
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x0000000002910000
|
success
|
0 |
0
|
1620124434.968771
NtAllocateVirtualMemory
|
process_identifier:
580
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0000000002940000
|
success
|
0 |
0
|
1620124435.062771
NtProtectVirtualMemory
|
process_identifier:
580
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1b71000
|
success
|
0 |
0
|
1620124435.062771
NtProtectVirtualMemory
|
process_identifier:
580
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1b71000
|
success
|
0 |
0
|
1620124435.109771
NtProtectVirtualMemory
|
process_identifier:
580
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef21f0000
|
success
|
0 |
0
|
1620124435.374771
NtAllocateVirtualMemory
|
process_identifier:
580
region_size:
1310720
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00000000029c0000
|
success
|
0 |
0
|
1620124435.374771
NtAllocateVirtualMemory
|
process_identifier:
580
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0000000002a80000
|
success
|
0 |
0
|
1620124435.390771
NtProtectVirtualMemory
|
process_identifier:
580
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1b72000
|
success
|
0 |
0
|
1620124435.390771
NtProtectVirtualMemory
|
process_identifier:
580
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1b72000
|
success
|
0 |
0
|
1620124435.390771
NtProtectVirtualMemory
|
process_identifier:
580
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1b72000
|
success
|
0 |
0
|
1620124435.390771
NtProtectVirtualMemory
|
process_identifier:
580
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1b72000
|
success
|
0 |
0
|
1620124435.390771
NtProtectVirtualMemory
|
process_identifier:
580
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1b72000
|
success
|
0 |
0
|
1620124435.390771
NtProtectVirtualMemory
|
process_identifier:
580
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1b73000
|
success
|
0 |
0
|
1620124435.390771
NtProtectVirtualMemory
|
process_identifier:
580
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1b73000
|
success
|
0 |
0
|
1620124435.390771
NtProtectVirtualMemory
|
process_identifier:
580
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1b73000
|
success
|
0 |
0
|
1620124435.390771
NtProtectVirtualMemory
|
process_identifier:
580
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1b73000
|
success
|
0 |
0
|
1620124435.390771
NtProtectVirtualMemory
|
process_identifier:
580
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1b73000
|
success
|
0 |
0
|
1620124435.390771
NtProtectVirtualMemory
|
process_identifier:
580
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1b73000
|
success
|
0 |
0
|
1620124435.406771
NtProtectVirtualMemory
|
process_identifier:
580
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1b73000
|
success
|
0 |
0
|
1620124435.406771
NtProtectVirtualMemory
|
process_identifier:
580
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1b71000
|
success
|
0 |
0
|
1620124435.406771
NtProtectVirtualMemory
|
process_identifier:
580
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1b72000
|
success
|
0 |
0
|
1620124435.406771
NtProtectVirtualMemory
|
process_identifier:
580
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1b72000
|
success
|
0 |
0
|
1620124435.406771
NtProtectVirtualMemory
|
process_identifier:
580
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1b72000
|
success
|
0 |
0
|
1620124435.406771
NtProtectVirtualMemory
|
process_identifier:
580
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1b72000
|
success
|
0 |
0
|
1620124435.406771
NtProtectVirtualMemory
|
process_identifier:
580
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1b72000
|
success
|
0 |
0
|
1620124435.781771
NtAllocateVirtualMemory
|
process_identifier:
580
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff00052000
|
success
|
0 |
0
|
1620124435.828771
NtAllocateVirtualMemory
|
process_identifier:
580
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff00042000
|
success
|
0 |
0
|
1620124436.031771
NtAllocateVirtualMemory
|
process_identifier:
580
region_size:
655360
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
1056768
(MEM_RESERVE|MEM_TOP_DOWN)
base_address:
0x000007fffff00000
|
success
|
0 |
0
|
1620124436.031771
NtAllocateVirtualMemory
|
process_identifier:
580
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007fffff00000
|
success
|
0 |
0
|
1620124436.031771
NtAllocateVirtualMemory
|
process_identifier:
580
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007fffff00000
|
success
|
0 |
0
|
1620124436.031771
NtAllocateVirtualMemory
|
process_identifier:
580
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007fffff10000
|
success
|
0 |
0
|
1620124436.031771
NtAllocateVirtualMemory
|
process_identifier:
580
region_size:
65536
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
1056768
(MEM_RESERVE|MEM_TOP_DOWN)
base_address:
0x000007ffffef0000
|
success
|
0 |
0
|
1620124436.031771
NtAllocateVirtualMemory
|
process_identifier:
580
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ffffef0000
|
success
|
0 |
0
|
1620124436.031771
NtAllocateVirtualMemory
|
process_identifier:
580
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff0004a000
|
success
|
0 |
0
|
1620124436.078771
NtAllocateVirtualMemory
|
process_identifier:
580
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff00053000
|
success
|
0 |
0
|
1620124436.078771
NtAllocateVirtualMemory
|
process_identifier:
580
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff000fc000
|
success
|
0 |
0
|
1620124436.093771
NtAllocateVirtualMemory
|
process_identifier:
580
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff00126000
|
success
|
0 |
0
|
1620124436.093771
NtAllocateVirtualMemory
|
process_identifier:
580
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff00100000
|
success
|
0 |
0
|
1620124436.328771
NtAllocateVirtualMemory
|
process_identifier:
580
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff00054000
|
success
|
0 |
0
|
1620124436.374771
NtAllocateVirtualMemory
|
process_identifier:
580
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff0004b000
|
success
|
0 |
0
|
1620124436.390771
NtAllocateVirtualMemory
|
process_identifier:
580
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff0005c000
|
success
|
0 |
0
|
1620124436.984771
NtAllocateVirtualMemory
|
process_identifier:
580
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff00055000
|
success
|
0 |
0
|
1620124436.999771
NtAllocateVirtualMemory
|
process_identifier:
580
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff00056000
|
success
|
0 |
0
|
1620124436.999771
NtAllocateVirtualMemory
|
process_identifier:
580
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff00057000
|
success
|
0 |
0
|
1620124437.203771
NtAllocateVirtualMemory
|
process_identifier:
580
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff00059000
|
success
|
0 |
0
|
1620124437.218771
NtAllocateVirtualMemory
|
process_identifier:
580
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff001a0000
|
success
|
0 |
0
|
1620124437.234771
NtAllocateVirtualMemory
|
process_identifier:
580
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff001a1000
|
success
|
0 |
0
|
1620124437.234771
NtAllocateVirtualMemory
|
process_identifier:
580
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff0005d000
|
success
|
0 |
0
|