| Time & API |
Arguments |
Status |
Return |
Repeated |
1619279608.261751
NtAllocateVirtualMemory
|
process_identifier:
1272
region_size:
671744
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000120
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x10410000
|
success
|
0 |
0
|
1619279608.276751
NtAllocateVirtualMemory
|
process_identifier:
1272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000120
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x000f0000
|
success
|
0 |
0
|
1619279608.276751
NtAllocateVirtualMemory
|
process_identifier:
1272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000120
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00100000
|
success
|
0 |
0
|
1619279608.276751
NtAllocateVirtualMemory
|
process_identifier:
1272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000120
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00110000
|
success
|
0 |
0
|
1619279608.417751
NtAllocateVirtualMemory
|
process_identifier:
1272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000120
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00020000
|
success
|
0 |
0
|
1619279608.417751
NtAllocateVirtualMemory
|
process_identifier:
1272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000120
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00030000
|
success
|
0 |
0
|
1619279608.417751
NtAllocateVirtualMemory
|
process_identifier:
1272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000120
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00120000
|
success
|
0 |
0
|
1619279608.417751
NtAllocateVirtualMemory
|
process_identifier:
1272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000120
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00130000
|
success
|
0 |
0
|
1619279609.042751
NtAllocateVirtualMemory
|
process_identifier:
1272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000120
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00140000
|
success
|
0 |
0
|
1619279609.042751
NtAllocateVirtualMemory
|
process_identifier:
1272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000120
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00150000
|
success
|
0 |
0
|
1619279609.042751
NtAllocateVirtualMemory
|
process_identifier:
1272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000120
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00160000
|
success
|
0 |
0
|
1619279609.042751
NtAllocateVirtualMemory
|
process_identifier:
1272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000120
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00170000
|
success
|
0 |
0
|
1619279609.058751
NtAllocateVirtualMemory
|
process_identifier:
1272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000120
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00220000
|
success
|
0 |
0
|
1619279609.058751
NtAllocateVirtualMemory
|
process_identifier:
1272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000120
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00230000
|
success
|
0 |
0
|
1619279609.058751
NtAllocateVirtualMemory
|
process_identifier:
1272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000120
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00240000
|
success
|
0 |
0
|
1619279609.058751
NtAllocateVirtualMemory
|
process_identifier:
1272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000120
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00250000
|
success
|
0 |
0
|
1619279609.058751
NtAllocateVirtualMemory
|
process_identifier:
1272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000120
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00260000
|
success
|
0 |
0
|
1619279609.058751
NtAllocateVirtualMemory
|
process_identifier:
1272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000120
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x002b0000
|
success
|
0 |
0
|
1619279609.058751
NtAllocateVirtualMemory
|
process_identifier:
1272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000120
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x002c0000
|
success
|
0 |
0
|
1619279609.167751
NtAllocateVirtualMemory
|
process_identifier:
1272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000120
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x002d0000
|
success
|
0 |
0
|
1619279609.167751
NtAllocateVirtualMemory
|
process_identifier:
1272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000120
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x002e0000
|
success
|
0 |
0
|
1619279609.167751
NtAllocateVirtualMemory
|
process_identifier:
1272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000120
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x002f0000
|
success
|
0 |
0
|
1619279609.167751
NtAllocateVirtualMemory
|
process_identifier:
1272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000120
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00300000
|
success
|
0 |
0
|
1619279609.167751
NtAllocateVirtualMemory
|
process_identifier:
1272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000120
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00310000
|
success
|
0 |
0
|
1619279609.167751
NtAllocateVirtualMemory
|
process_identifier:
1272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000120
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00320000
|
success
|
0 |
0
|
1619279609.167751
NtAllocateVirtualMemory
|
process_identifier:
1272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000120
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00330000
|
success
|
0 |
0
|
1619279609.167751
NtAllocateVirtualMemory
|
process_identifier:
1272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000120
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00340000
|
success
|
0 |
0
|
1619279609.167751
NtAllocateVirtualMemory
|
process_identifier:
1272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000120
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00350000
|
success
|
0 |
0
|
1619279609.167751
NtAllocateVirtualMemory
|
process_identifier:
1272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000120
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00360000
|
success
|
0 |
0
|
1619279609.167751
NtAllocateVirtualMemory
|
process_identifier:
1272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000120
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00370000
|
success
|
0 |
0
|
1619279609.167751
NtAllocateVirtualMemory
|
process_identifier:
1272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000120
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00380000
|
success
|
0 |
0
|
1619279609.167751
NtAllocateVirtualMemory
|
process_identifier:
1272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000120
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00390000
|
success
|
0 |
0
|
1619279609.167751
NtAllocateVirtualMemory
|
process_identifier:
1272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000120
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x003a0000
|
success
|
0 |
0
|
1619279609.167751
NtAllocateVirtualMemory
|
process_identifier:
1272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000120
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x003b0000
|
success
|
0 |
0
|
1619279609.292751
NtAllocateVirtualMemory
|
process_identifier:
1272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000120
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x003c0000
|
success
|
0 |
0
|
1619279609.292751
NtAllocateVirtualMemory
|
process_identifier:
1272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000120
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x003d0000
|
success
|
0 |
0
|
1619279609.292751
NtAllocateVirtualMemory
|
process_identifier:
1272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000120
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x003e0000
|
success
|
0 |
0
|
1619279609.292751
NtAllocateVirtualMemory
|
process_identifier:
1272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000120
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x003f0000
|
success
|
0 |
0
|
1619279609.292751
NtAllocateVirtualMemory
|
process_identifier:
1272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000120
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00400000
|
success
|
0 |
0
|
1619279609.292751
NtAllocateVirtualMemory
|
process_identifier:
1272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000120
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00410000
|
success
|
0 |
0
|
1619279609.292751
NtAllocateVirtualMemory
|
process_identifier:
1272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000120
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00420000
|
success
|
0 |
0
|
1619279609.292751
NtAllocateVirtualMemory
|
process_identifier:
1272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000120
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00430000
|
success
|
0 |
0
|
1619279609.308751
NtAllocateVirtualMemory
|
process_identifier:
1272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000120
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00440000
|
success
|
0 |
0
|
1619279609.308751
NtAllocateVirtualMemory
|
process_identifier:
1272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000120
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00450000
|
success
|
0 |
0
|
1619279609.308751
NtAllocateVirtualMemory
|
process_identifier:
1272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000120
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00460000
|
success
|
0 |
0
|
1619279609.308751
NtAllocateVirtualMemory
|
process_identifier:
1272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000120
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00470000
|
success
|
0 |
0
|
1619279609.308751
NtAllocateVirtualMemory
|
process_identifier:
1272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000120
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00480000
|
success
|
0 |
0
|
1619279609.308751
NtAllocateVirtualMemory
|
process_identifier:
1272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000120
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00490000
|
success
|
0 |
0
|
1619279609.308751
NtAllocateVirtualMemory
|
process_identifier:
1272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000120
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x004a0000
|
success
|
0 |
0
|
1619279609.308751
NtAllocateVirtualMemory
|
process_identifier:
1272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000120
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x004b0000
|
success
|
0 |
0
|