| Time & API |
Arguments |
Status |
Return |
Repeated |
1619269222.799241
NtAllocateVirtualMemory
|
process_identifier:
3064
region_size:
393216
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00280000
|
success
|
0 |
0
|
1619269222.799241
NtAllocateVirtualMemory
|
process_identifier:
3064
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002a0000
|
success
|
0 |
0
|
1619269223.236241
NtAllocateVirtualMemory
|
process_identifier:
3064
region_size:
393216
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x002e0000
|
success
|
0 |
0
|
1619269223.236241
NtAllocateVirtualMemory
|
process_identifier:
3064
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00300000
|
success
|
0 |
0
|
1619269223.393241
NtProtectVirtualMemory
|
process_identifier:
3064
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73e71000
|
success
|
0 |
0
|
1619269223.705241
NtAllocateVirtualMemory
|
process_identifier:
3064
region_size:
786432
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00470000
|
success
|
0 |
0
|
1619269223.705241
NtAllocateVirtualMemory
|
process_identifier:
3064
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004f0000
|
success
|
0 |
0
|
1619269223.705241
NtAllocateVirtualMemory
|
process_identifier:
3064
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0029a000
|
success
|
0 |
0
|
1619269223.721241
NtProtectVirtualMemory
|
process_identifier:
3064
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73e72000
|
success
|
0 |
0
|
1619269223.721241
NtAllocateVirtualMemory
|
process_identifier:
3064
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00292000
|
success
|
0 |
0
|
1619269224.127241
NtAllocateVirtualMemory
|
process_identifier:
3064
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002e2000
|
success
|
0 |
0
|
1619269224.221241
NtAllocateVirtualMemory
|
process_identifier:
3064
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00345000
|
success
|
0 |
0
|
1619269224.221241
NtAllocateVirtualMemory
|
process_identifier:
3064
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0034b000
|
success
|
0 |
0
|
1619269224.221241
NtAllocateVirtualMemory
|
process_identifier:
3064
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00347000
|
success
|
0 |
0
|
1619269224.315241
NtAllocateVirtualMemory
|
process_identifier:
3064
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002e3000
|
success
|
0 |
0
|
1619269224.330241
NtAllocateVirtualMemory
|
process_identifier:
3064
region_size:
12288
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002e4000
|
success
|
0 |
0
|
1619269224.346241
NtAllocateVirtualMemory
|
process_identifier:
3064
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002ec000
|
success
|
0 |
0
|
1619269224.408241
NtAllocateVirtualMemory
|
process_identifier:
3064
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04830000
|
success
|
0 |
0
|
1619269224.408241
NtAllocateVirtualMemory
|
process_identifier:
3064
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04940000
|
success
|
0 |
0
|
1619269224.408241
NtAllocateVirtualMemory
|
process_identifier:
3064
region_size:
69632
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04941000
|
success
|
0 |
0
|
1619269224.424241
NtAllocateVirtualMemory
|
process_identifier:
3064
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002e7000
|
success
|
0 |
0
|
1619269224.768241
NtAllocateVirtualMemory
|
process_identifier:
3064
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002e8000
|
success
|
0 |
0
|
1619269224.893241
NtAllocateVirtualMemory
|
process_identifier:
3064
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002f6000
|
success
|
0 |
0
|
1619269225.018241
NtAllocateVirtualMemory
|
process_identifier:
3064
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00301000
|
success
|
0 |
0
|
1619269225.111241
NtAllocateVirtualMemory
|
process_identifier:
3064
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002fa000
|
success
|
0 |
0
|
1619269225.111241
NtAllocateVirtualMemory
|
process_identifier:
3064
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002f7000
|
success
|
0 |
0
|
1619269225.205241
NtAllocateVirtualMemory
|
process_identifier:
3064
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00760000
|
success
|
0 |
0
|
1619269225.221241
NtAllocateVirtualMemory
|
process_identifier:
3064
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04952000
|
success
|
0 |
0
|
1619269225.315241
NtAllocateVirtualMemory
|
process_identifier:
3064
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00761000
|
success
|
0 |
0
|
1619269225.346241
NtAllocateVirtualMemory
|
process_identifier:
3064
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00762000
|
success
|
0 |
0
|
1619269225.377241
NtAllocateVirtualMemory
|
process_identifier:
3064
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04953000
|
success
|
0 |
0
|
1619269225.486241
NtAllocateVirtualMemory
|
process_identifier:
3064
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00763000
|
success
|
0 |
0
|
1619269226.033241
NtAllocateVirtualMemory
|
process_identifier:
3064
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00764000
|
success
|
0 |
0
|
1619269226.065241
NtAllocateVirtualMemory
|
process_identifier:
3064
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04954000
|
success
|
0 |
0
|
1619269226.236241
NtAllocateVirtualMemory
|
process_identifier:
3064
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00765000
|
success
|
0 |
0
|
1619269226.283241
NtAllocateVirtualMemory
|
process_identifier:
3064
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00766000
|
success
|
0 |
0
|
1619269226.283241
NtAllocateVirtualMemory
|
process_identifier:
3064
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002ed000
|
success
|
0 |
0
|
1619269226.283241
NtAllocateVirtualMemory
|
process_identifier:
3064
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00e60000
|
success
|
0 |
0
|
1619269226.283241
NtAllocateVirtualMemory
|
process_identifier:
3064
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00e61000
|
success
|
0 |
0
|
1619269226.283241
NtAllocateVirtualMemory
|
process_identifier:
3064
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002ea000
|
success
|
0 |
0
|
1619269226.283241
NtAllocateVirtualMemory
|
process_identifier:
3064
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002eb000
|
success
|
0 |
0
|
1619269226.299241
NtAllocateVirtualMemory
|
process_identifier:
3064
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00767000
|
success
|
0 |
0
|
1619269226.299241
NtAllocateVirtualMemory
|
process_identifier:
3064
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04955000
|
success
|
0 |
0
|
1619269226.346241
NtAllocateVirtualMemory
|
process_identifier:
3064
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04956000
|
success
|
0 |
0
|
1619269226.549241
NtAllocateVirtualMemory
|
process_identifier:
3064
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00768000
|
success
|
0 |
0
|
1619269226.549241
NtAllocateVirtualMemory
|
process_identifier:
3064
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00769000
|
success
|
0 |
0
|
1619269226.549241
NtAllocateVirtualMemory
|
process_identifier:
3064
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0076a000
|
success
|
0 |
0
|
1619269226.549241
NtAllocateVirtualMemory
|
process_identifier:
3064
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0076b000
|
success
|
0 |
0
|
1619269226.580241
NtAllocateVirtualMemory
|
process_identifier:
3064
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04957000
|
success
|
0 |
0
|
1619269226.580241
NtAllocateVirtualMemory
|
process_identifier:
3064
region_size:
327680
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
1056768
(MEM_RESERVE|MEM_TOP_DOWN)
base_address:
0x7ef40000
|
success
|
0 |
0
|