| Time & API |
Arguments |
Status |
Return |
Repeated |
1619269229.131269
NtAllocateVirtualMemory
|
process_identifier:
732
region_size:
2293760
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00970000
|
success
|
0 |
0
|
1619269229.131269
NtAllocateVirtualMemory
|
process_identifier:
732
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00b60000
|
success
|
0 |
0
|
1619269229.506269
NtAllocateVirtualMemory
|
process_identifier:
732
region_size:
1835008
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00ba0000
|
success
|
0 |
0
|
1619269229.506269
NtAllocateVirtualMemory
|
process_identifier:
732
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00d20000
|
success
|
0 |
0
|
1619269229.631269
NtProtectVirtualMemory
|
process_identifier:
732
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73e71000
|
success
|
0 |
0
|
1619269229.818269
NtAllocateVirtualMemory
|
process_identifier:
732
region_size:
720896
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00ba0000
|
success
|
0 |
0
|
1619269229.818269
NtAllocateVirtualMemory
|
process_identifier:
732
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00c10000
|
success
|
0 |
0
|
1619269229.834269
NtAllocateVirtualMemory
|
process_identifier:
732
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003ea000
|
success
|
0 |
0
|
1619269229.850269
NtProtectVirtualMemory
|
process_identifier:
732
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73e72000
|
success
|
0 |
0
|
1619269229.850269
NtAllocateVirtualMemory
|
process_identifier:
732
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003e2000
|
success
|
0 |
0
|
1619269230.240269
NtAllocateVirtualMemory
|
process_identifier:
732
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003f2000
|
success
|
0 |
0
|
1619269230.381269
NtAllocateVirtualMemory
|
process_identifier:
732
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00415000
|
success
|
0 |
0
|
1619269230.381269
NtAllocateVirtualMemory
|
process_identifier:
732
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0041b000
|
success
|
0 |
0
|
1619269230.381269
NtAllocateVirtualMemory
|
process_identifier:
732
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00417000
|
success
|
0 |
0
|
1619269230.459269
NtAllocateVirtualMemory
|
process_identifier:
732
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003f3000
|
success
|
0 |
0
|
1619269230.553269
NtAllocateVirtualMemory
|
process_identifier:
732
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003f4000
|
success
|
0 |
0
|
1619269230.568269
NtAllocateVirtualMemory
|
process_identifier:
732
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003f5000
|
success
|
0 |
0
|
1619269230.584269
NtAllocateVirtualMemory
|
process_identifier:
732
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003fc000
|
success
|
0 |
0
|
1619269230.912269
NtAllocateVirtualMemory
|
process_identifier:
732
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003f6000
|
success
|
0 |
0
|
1619269230.928269
NtAllocateVirtualMemory
|
process_identifier:
732
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003f8000
|
success
|
0 |
0
|
1619269230.975269
NtAllocateVirtualMemory
|
process_identifier:
732
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00580000
|
success
|
0 |
0
|
1619269231.162269
NtAllocateVirtualMemory
|
process_identifier:
732
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0040a000
|
success
|
0 |
0
|
1619269231.162269
NtAllocateVirtualMemory
|
process_identifier:
732
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00407000
|
success
|
0 |
0
|
1619269231.256269
NtAllocateVirtualMemory
|
process_identifier:
732
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003f9000
|
success
|
0 |
0
|
1619269231.271269
NtAllocateVirtualMemory
|
process_identifier:
732
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00590000
|
success
|
0 |
0
|
1619269231.365269
NtAllocateVirtualMemory
|
process_identifier:
732
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00406000
|
success
|
0 |
0
|
1619269231.428269
NtAllocateVirtualMemory
|
process_identifier:
732
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00581000
|
success
|
0 |
0
|
1619269231.428269
NtAllocateVirtualMemory
|
process_identifier:
732
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00591000
|
success
|
0 |
0
|
1619269231.475269
NtAllocateVirtualMemory
|
process_identifier:
732
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00592000
|
success
|
0 |
0
|
1619269231.506269
NtAllocateVirtualMemory
|
process_identifier:
732
region_size:
327680
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
1056768
(MEM_RESERVE|MEM_TOP_DOWN)
base_address:
0x7ef40000
|
success
|
0 |
0
|
1619269231.506269
NtAllocateVirtualMemory
|
process_identifier:
732
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x7ef40000
|
success
|
0 |
0
|
1619269231.506269
NtAllocateVirtualMemory
|
process_identifier:
732
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x7ef40000
|
success
|
0 |
0
|
1619269231.506269
NtAllocateVirtualMemory
|
process_identifier:
732
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x7ef48000
|
success
|
0 |
0
|
1619269231.506269
NtAllocateVirtualMemory
|
process_identifier:
732
region_size:
65536
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
1056768
(MEM_RESERVE|MEM_TOP_DOWN)
base_address:
0x7ef30000
|
success
|
0 |
0
|
1619269231.506269
NtAllocateVirtualMemory
|
process_identifier:
732
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x7ef30000
|
success
|
0 |
0
|
1619269231.553269
NtAllocateVirtualMemory
|
process_identifier:
732
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00582000
|
success
|
0 |
0
|
1619269231.662269
NtAllocateVirtualMemory
|
process_identifier:
732
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00593000
|
success
|
0 |
0
|
1619269231.678269
NtAllocateVirtualMemory
|
process_identifier:
732
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00583000
|
success
|
0 |
0
|
1619269287.396269
NtAllocateVirtualMemory
|
process_identifier:
732
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00584000
|
success
|
0 |
0
|
1619269287.459269
NtAllocateVirtualMemory
|
process_identifier:
732
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003fd000
|
success
|
0 |
0
|
1619269287.459269
NtAllocateVirtualMemory
|
process_identifier:
732
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00585000
|
success
|
0 |
0
|
1619269287.475269
NtAllocateVirtualMemory
|
process_identifier:
732
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00586000
|
success
|
0 |
0
|
1619269287.490269
NtAllocateVirtualMemory
|
process_identifier:
732
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00594000
|
success
|
0 |
0
|
1619269287.521269
NtAllocateVirtualMemory
|
process_identifier:
732
region_size:
16384
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00587000
|
success
|
0 |
0
|
1619269287.662269
NtAllocateVirtualMemory
|
process_identifier:
732
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00d21000
|
success
|
0 |
0
|
1619269287.943269
NtAllocateVirtualMemory
|
process_identifier:
732
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0058b000
|
success
|
0 |
0
|
1619269287.975269
NtAllocateVirtualMemory
|
process_identifier:
732
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00595000
|
success
|
0 |
0
|
1619269287.975269
NtAllocateVirtualMemory
|
process_identifier:
732
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00596000
|
success
|
0 |
0
|
1619269287.975269
NtAllocateVirtualMemory
|
process_identifier:
732
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00597000
|
success
|
0 |
0
|
1619269287.975269
NtAllocateVirtualMemory
|
process_identifier:
732
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00598000
|
success
|
0 |
0
|