| Time & API |
Arguments |
Status |
Return |
Repeated |
1619270650.454625
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
393216
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00400000
|
success
|
0 |
0
|
1619270650.454625
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00420000
|
success
|
0 |
0
|
1619270650.782625
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
1245184
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00640000
|
success
|
0 |
0
|
1619270650.798625
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00730000
|
success
|
0 |
0
|
1619270650.970625
NtProtectVirtualMemory
|
process_identifier:
2104
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73e71000
|
success
|
0 |
0
|
1619270651.376625
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
2097152
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00b00000
|
success
|
0 |
0
|
1619270651.376625
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00cc0000
|
success
|
0 |
0
|
1619270651.376625
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0046a000
|
success
|
0 |
0
|
1619270651.376625
NtProtectVirtualMemory
|
process_identifier:
2104
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73e72000
|
success
|
0 |
0
|
1619270651.376625
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00462000
|
success
|
0 |
0
|
1619270651.892625
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00472000
|
success
|
0 |
0
|
1619270652.188625
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00495000
|
success
|
0 |
0
|
1619270652.188625
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0049b000
|
success
|
0 |
0
|
1619270652.188625
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00497000
|
success
|
0 |
0
|
1619270652.407625
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00473000
|
success
|
0 |
0
|
1619270652.517625
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0047c000
|
success
|
0 |
0
|
1619270652.704625
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00770000
|
success
|
0 |
0
|
1619270653.235625
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00474000
|
success
|
0 |
0
|
1619270653.282625
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00771000
|
success
|
0 |
0
|
1619270653.392625
NtProtectVirtualMemory
|
process_identifier:
2104
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
413696
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00fa2000
|
success
|
0 |
0
|
1619270663.563625
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00772000
|
success
|
0 |
0
|
1619270663.610625
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00475000
|
success
|
0 |
0
|
1619270663.610625
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00773000
|
success
|
0 |
0
|
1619270663.657625
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00774000
|
success
|
0 |
0
|
1619270663.720625
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00775000
|
success
|
0 |
0
|
1619270663.720625
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00776000
|
success
|
0 |
0
|
1619270663.845625
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
16384
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00777000
|
success
|
0 |
0
|
1619270663.860625
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00476000
|
success
|
0 |
0
|
1619270663.860625
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0077b000
|
success
|
0 |
0
|
1619270664.298625
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00486000
|
success
|
0 |
0
|
1619270664.298625
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0048a000
|
success
|
0 |
0
|
1619270664.298625
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00487000
|
success
|
0 |
0
|
1619270664.313625
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0077c000
|
success
|
0 |
0
|
1619270664.688625
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00477000
|
success
|
0 |
0
|
1619270664.751625
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00478000
|
success
|
0 |
0
|
1619270664.767625
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00479000
|
success
|
0 |
0
|
1619270664.767625
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0077d000
|
success
|
0 |
0
|
1619270664.767625
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00cc1000
|
success
|
0 |
0
|
1619270664.782625
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00cc2000
|
success
|
0 |
0
|
1619270664.798625
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00cc3000
|
success
|
0 |
0
|
1619270664.798625
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00cc4000
|
success
|
0 |
0
|
1619270664.798625
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00cc5000
|
success
|
0 |
0
|
1619270664.798625
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
12288
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00cc7000
|
success
|
0 |
0
|
1619270664.813625
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00cb0000
|
success
|
0 |
0
|
1619270664.829625
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
16384
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00cca000
|
success
|
0 |
0
|
1619270664.829625
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
69632
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00cce000
|
success
|
0 |
0
|
1619270664.829625
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0077e000
|
success
|
0 |
0
|
1619270664.845625
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00cdf000
|
success
|
0 |
0
|
1619270664.876625
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0077f000
|
success
|
0 |
0
|
1619270664.954625
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00d80000
|
success
|
0 |
0
|