| Time & API |
Arguments |
Status |
Return |
Repeated |
1619269222.477776
NtAllocateVirtualMemory
|
process_identifier:
3060
region_size:
1114112
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x007f0000
|
success
|
0 |
0
|
1619269222.477776
NtAllocateVirtualMemory
|
process_identifier:
3060
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x008c0000
|
success
|
0 |
0
|
1619269222.837776
NtAllocateVirtualMemory
|
process_identifier:
3060
region_size:
393216
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00550000
|
success
|
0 |
0
|
1619269222.837776
NtAllocateVirtualMemory
|
process_identifier:
3060
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00570000
|
success
|
0 |
0
|
1619269222.899776
NtProtectVirtualMemory
|
process_identifier:
3060
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73e71000
|
success
|
0 |
0
|
1619269223.102776
NtAllocateVirtualMemory
|
process_identifier:
3060
region_size:
983040
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x02020000
|
success
|
0 |
0
|
1619269223.102776
NtAllocateVirtualMemory
|
process_identifier:
3060
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x020d0000
|
success
|
0 |
0
|
1619269223.118776
NtAllocateVirtualMemory
|
process_identifier:
3060
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004ba000
|
success
|
0 |
0
|
1619269223.118776
NtProtectVirtualMemory
|
process_identifier:
3060
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73e72000
|
success
|
0 |
0
|
1619269223.118776
NtAllocateVirtualMemory
|
process_identifier:
3060
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004b2000
|
success
|
0 |
0
|
1619269223.383776
NtAllocateVirtualMemory
|
process_identifier:
3060
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00552000
|
success
|
0 |
0
|
1619269223.618776
NtAllocateVirtualMemory
|
process_identifier:
3060
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005b5000
|
success
|
0 |
0
|
1619269223.618776
NtAllocateVirtualMemory
|
process_identifier:
3060
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005bb000
|
success
|
0 |
0
|
1619269223.618776
NtAllocateVirtualMemory
|
process_identifier:
3060
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005b7000
|
success
|
0 |
0
|
1619269223.883776
NtAllocateVirtualMemory
|
process_identifier:
3060
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00553000
|
success
|
0 |
0
|
1619269223.977776
NtAllocateVirtualMemory
|
process_identifier:
3060
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0055c000
|
success
|
0 |
0
|
1619269224.180776
NtAllocateVirtualMemory
|
process_identifier:
3060
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006e0000
|
success
|
0 |
0
|
1619269224.243776
NtAllocateVirtualMemory
|
process_identifier:
3060
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00554000
|
success
|
0 |
0
|
1619269225.149776
NtAllocateVirtualMemory
|
process_identifier:
3060
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00555000
|
success
|
0 |
0
|
1619269225.305776
NtAllocateVirtualMemory
|
process_identifier:
3060
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00557000
|
success
|
0 |
0
|
1619269225.430776
NtProtectVirtualMemory
|
process_identifier:
3060
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00260000
|
success
|
0 |
0
|
1619269225.430776
NtAllocateVirtualMemory
|
process_identifier:
3060
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006e1000
|
success
|
0 |
0
|
1619269225.430776
NtProtectVirtualMemory
|
process_identifier:
3060
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00260000
|
success
|
0 |
0
|
1619269225.430776
NtProtectVirtualMemory
|
process_identifier:
3060
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00260000
|
success
|
0 |
0
|
1619269225.430776
NtProtectVirtualMemory
|
process_identifier:
3060
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00260000
|
success
|
0 |
0
|
1619269225.430776
NtProtectVirtualMemory
|
process_identifier:
3060
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00260000
|
success
|
0 |
0
|
1619269225.430776
NtProtectVirtualMemory
|
process_identifier:
3060
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00260000
|
success
|
0 |
0
|
1619269225.430776
NtProtectVirtualMemory
|
process_identifier:
3060
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00260000
|
success
|
0 |
0
|
1619269225.430776
NtProtectVirtualMemory
|
process_identifier:
3060
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00260000
|
success
|
0 |
0
|
1619269225.430776
NtProtectVirtualMemory
|
process_identifier:
3060
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00260000
|
success
|
0 |
0
|
1619269225.430776
NtProtectVirtualMemory
|
process_identifier:
3060
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00260000
|
success
|
0 |
0
|
1619269225.430776
NtProtectVirtualMemory
|
process_identifier:
3060
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00260000
|
success
|
0 |
0
|
1619269225.430776
NtProtectVirtualMemory
|
process_identifier:
3060
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00260000
|
success
|
0 |
0
|
1619269225.430776
NtProtectVirtualMemory
|
process_identifier:
3060
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00260000
|
success
|
0 |
0
|
1619269225.430776
NtProtectVirtualMemory
|
process_identifier:
3060
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00260000
|
success
|
0 |
0
|
1619269225.430776
NtProtectVirtualMemory
|
process_identifier:
3060
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00260000
|
success
|
0 |
0
|
1619269225.430776
NtProtectVirtualMemory
|
process_identifier:
3060
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00260000
|
success
|
0 |
0
|
1619269225.430776
NtProtectVirtualMemory
|
process_identifier:
3060
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00260000
|
success
|
0 |
0
|
1619269225.430776
NtProtectVirtualMemory
|
process_identifier:
3060
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00260000
|
success
|
0 |
0
|