| Time & API |
Arguments |
Status |
Return |
Repeated |
1619269225.610567
NtAllocateVirtualMemory
|
process_identifier:
2224
region_size:
1310720
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00590000
|
success
|
0 |
0
|
1619269225.610567
NtAllocateVirtualMemory
|
process_identifier:
2224
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00690000
|
success
|
0 |
0
|
1619269225.985567
NtAllocateVirtualMemory
|
process_identifier:
2224
region_size:
393216
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x005e0000
|
success
|
0 |
0
|
1619269225.985567
NtAllocateVirtualMemory
|
process_identifier:
2224
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00600000
|
success
|
0 |
0
|
1619269226.078567
NtProtectVirtualMemory
|
process_identifier:
2224
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73e71000
|
success
|
0 |
0
|
1619269226.297567
NtAllocateVirtualMemory
|
process_identifier:
2224
region_size:
1245184
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x009f0000
|
success
|
0 |
0
|
1619269226.297567
NtAllocateVirtualMemory
|
process_identifier:
2224
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00ae0000
|
success
|
0 |
0
|
1619269226.297567
NtAllocateVirtualMemory
|
process_identifier:
2224
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0057a000
|
success
|
0 |
0
|
1619269226.313567
NtProtectVirtualMemory
|
process_identifier:
2224
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73e72000
|
success
|
0 |
0
|
1619269226.313567
NtAllocateVirtualMemory
|
process_identifier:
2224
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00572000
|
success
|
0 |
0
|
1619269226.625567
NtAllocateVirtualMemory
|
process_identifier:
2224
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00592000
|
success
|
0 |
0
|
1619269226.703567
NtAllocateVirtualMemory
|
process_identifier:
2224
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005b5000
|
success
|
0 |
0
|
1619269226.703567
NtAllocateVirtualMemory
|
process_identifier:
2224
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005bb000
|
success
|
0 |
0
|
1619269226.703567
NtAllocateVirtualMemory
|
process_identifier:
2224
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005b7000
|
success
|
0 |
0
|
1619269226.797567
NtAllocateVirtualMemory
|
process_identifier:
2224
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00593000
|
success
|
0 |
0
|
1619269226.828567
NtAllocateVirtualMemory
|
process_identifier:
2224
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0059c000
|
success
|
0 |
0
|
1619269226.828567
NtAllocateVirtualMemory
|
process_identifier:
2224
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00594000
|
success
|
0 |
0
|
1619269226.875567
NtAllocateVirtualMemory
|
process_identifier:
2224
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04260000
|
success
|
0 |
0
|
1619269227.094567
NtAllocateVirtualMemory
|
process_identifier:
2224
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04261000
|
success
|
0 |
0
|
1619269227.188567
NtProtectVirtualMemory
|
process_identifier:
2224
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
475136
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00cd2000
|
success
|
0 |
0
|
1619269236.282567
NtAllocateVirtualMemory
|
process_identifier:
2224
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04262000
|
success
|
0 |
0
|
1619269236.297567
NtAllocateVirtualMemory
|
process_identifier:
2224
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00595000
|
success
|
0 |
0
|
1619269236.297567
NtAllocateVirtualMemory
|
process_identifier:
2224
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04263000
|
success
|
0 |
0
|
1619269236.313567
NtAllocateVirtualMemory
|
process_identifier:
2224
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04264000
|
success
|
0 |
0
|
1619269236.438567
NtAllocateVirtualMemory
|
process_identifier:
2224
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04265000
|
success
|
0 |
0
|
1619269236.453567
NtAllocateVirtualMemory
|
process_identifier:
2224
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04266000
|
success
|
0 |
0
|
1619269236.828567
NtAllocateVirtualMemory
|
process_identifier:
2224
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00596000
|
success
|
0 |
0
|
1619269236.875567
NtAllocateVirtualMemory
|
process_identifier:
2224
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04267000
|
success
|
0 |
0
|
1619269237.063567
NtAllocateVirtualMemory
|
process_identifier:
2224
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04268000
|
success
|
0 |
0
|
1619269237.063567
NtProtectVirtualMemory
|
process_identifier:
2224
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00d46000
|
success
|
0 |
0
|
1619269237.063567
NtProtectVirtualMemory
|
process_identifier:
2224
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00d46000
|
success
|
0 |
0
|
1619269237.063567
NtProtectVirtualMemory
|
process_identifier:
2224
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00cd0000
|
success
|
0 |
0
|
1619269237.063567
NtProtectVirtualMemory
|
process_identifier:
2224
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00cd0000
|
success
|
0 |
0
|
1619269237.063567
NtProtectVirtualMemory
|
process_identifier:
2224
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00cd0000
|
success
|
0 |
0
|
1619269237.063567
NtProtectVirtualMemory
|
process_identifier:
2224
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00cd0000
|
success
|
0 |
0
|
1619269237.063567
NtProtectVirtualMemory
|
process_identifier:
2224
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00cd0000
|
success
|
0 |
0
|
1619269237.063567
NtProtectVirtualMemory
|
process_identifier:
2224
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00d46000
|
success
|
0 |
0
|
1619269237.063567
NtProtectVirtualMemory
|
process_identifier:
2224
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00d46000
|
success
|
0 |
0
|
1619269237.063567
NtProtectVirtualMemory
|
process_identifier:
2224
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00d46000
|
success
|
0 |
0
|
1619269237.063567
NtProtectVirtualMemory
|
process_identifier:
2224
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00d46000
|
success
|
0 |
0
|
1619269237.063567
NtProtectVirtualMemory
|
process_identifier:
2224
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00d46000
|
success
|
0 |
0
|
1619269237.063567
NtProtectVirtualMemory
|
process_identifier:
2224
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00d46000
|
success
|
0 |
0
|
1619269237.063567
NtProtectVirtualMemory
|
process_identifier:
2224
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00d46000
|
success
|
0 |
0
|
1619269237.063567
NtProtectVirtualMemory
|
process_identifier:
2224
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00d46000
|
success
|
0 |
0
|
1619269237.063567
NtProtectVirtualMemory
|
process_identifier:
2224
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00d46000
|
success
|
0 |
0
|
1619269237.063567
NtProtectVirtualMemory
|
process_identifier:
2224
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00d46000
|
success
|
0 |
0
|
1619269237.063567
NtProtectVirtualMemory
|
process_identifier:
2224
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00d46000
|
success
|
0 |
0
|
1619269237.063567
NtProtectVirtualMemory
|
process_identifier:
2224
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00d46000
|
success
|
0 |
0
|
1619269237.063567
NtProtectVirtualMemory
|
process_identifier:
2224
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00d46000
|
success
|
0 |
0
|
1619269237.063567
NtProtectVirtualMemory
|
process_identifier:
2224
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00d46000
|
success
|
0 |
0
|