| Time & API |
Arguments |
Status |
Return |
Repeated |
1619357208.22027
NtAllocateVirtualMemory
|
process_identifier:
3048
region_size:
1048576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00000000009e0000
|
success
|
0 |
0
|
1619357208.22027
NtAllocateVirtualMemory
|
process_identifier:
3048
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0000000000a60000
|
success
|
0 |
0
|
1619357209.51727
NtAllocateVirtualMemory
|
process_identifier:
3048
region_size:
1703936
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x0000000002370000
|
success
|
0 |
0
|
1619357209.51727
NtAllocateVirtualMemory
|
process_identifier:
3048
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0000000002490000
|
success
|
0 |
0
|
1619357211.09527
NtProtectVirtualMemory
|
process_identifier:
3048
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1c31000
|
success
|
0 |
0
|
1619357211.09527
NtProtectVirtualMemory
|
process_identifier:
3048
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1c31000
|
success
|
0 |
0
|
1619357211.15727
NtProtectVirtualMemory
|
process_identifier:
3048
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef22b0000
|
success
|
0 |
0
|
1619357213.01727
NtAllocateVirtualMemory
|
process_identifier:
3048
region_size:
2555904
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x0000000002510000
|
success
|
0 |
0
|
1619357213.01727
NtAllocateVirtualMemory
|
process_identifier:
3048
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0000000002700000
|
success
|
0 |
0
|
1619357213.09527
NtProtectVirtualMemory
|
process_identifier:
3048
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1c32000
|
success
|
0 |
0
|
1619357213.09527
NtProtectVirtualMemory
|
process_identifier:
3048
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1c32000
|
success
|
0 |
0
|
1619357213.09527
NtProtectVirtualMemory
|
process_identifier:
3048
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1c32000
|
success
|
0 |
0
|
1619357213.11027
NtProtectVirtualMemory
|
process_identifier:
3048
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1c32000
|
success
|
0 |
0
|
1619357213.11027
NtProtectVirtualMemory
|
process_identifier:
3048
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1c32000
|
success
|
0 |
0
|
1619357213.11027
NtProtectVirtualMemory
|
process_identifier:
3048
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1c33000
|
success
|
0 |
0
|
1619357213.11027
NtProtectVirtualMemory
|
process_identifier:
3048
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1c33000
|
success
|
0 |
0
|
1619357213.11027
NtProtectVirtualMemory
|
process_identifier:
3048
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1c33000
|
success
|
0 |
0
|
1619357213.11027
NtProtectVirtualMemory
|
process_identifier:
3048
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1c33000
|
success
|
0 |
0
|
1619357213.11027
NtProtectVirtualMemory
|
process_identifier:
3048
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1c33000
|
success
|
0 |
0
|
1619357213.12627
NtProtectVirtualMemory
|
process_identifier:
3048
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1c33000
|
success
|
0 |
0
|
1619357213.12627
NtProtectVirtualMemory
|
process_identifier:
3048
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1c33000
|
success
|
0 |
0
|
1619357213.12627
NtProtectVirtualMemory
|
process_identifier:
3048
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1c31000
|
success
|
0 |
0
|
1619357213.12627
NtProtectVirtualMemory
|
process_identifier:
3048
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1c32000
|
success
|
0 |
0
|
1619357213.12627
NtProtectVirtualMemory
|
process_identifier:
3048
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1c32000
|
success
|
0 |
0
|
1619357213.12627
NtProtectVirtualMemory
|
process_identifier:
3048
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1c32000
|
success
|
0 |
0
|
1619357213.12627
NtProtectVirtualMemory
|
process_identifier:
3048
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1c32000
|
success
|
0 |
0
|
1619357213.14227
NtProtectVirtualMemory
|
process_identifier:
3048
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1c32000
|
success
|
0 |
0
|
1619357214.29827
NtAllocateVirtualMemory
|
process_identifier:
3048
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff00022000
|
success
|
0 |
0
|
1619357214.78227
NtAllocateVirtualMemory
|
process_identifier:
3048
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff00012000
|
success
|
0 |
0
|
1619357215.40727
NtAllocateVirtualMemory
|
process_identifier:
3048
region_size:
655360
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
1056768
(MEM_RESERVE|MEM_TOP_DOWN)
base_address:
0x000007fffff00000
|
success
|
0 |
0
|
1619357215.40727
NtAllocateVirtualMemory
|
process_identifier:
3048
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007fffff00000
|
success
|
0 |
0
|
1619357215.42327
NtAllocateVirtualMemory
|
process_identifier:
3048
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007fffff00000
|
success
|
0 |
0
|
1619357215.42327
NtAllocateVirtualMemory
|
process_identifier:
3048
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007fffff10000
|
success
|
0 |
0
|
1619357215.42327
NtAllocateVirtualMemory
|
process_identifier:
3048
region_size:
65536
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
1056768
(MEM_RESERVE|MEM_TOP_DOWN)
base_address:
0x000007ffffef0000
|
success
|
0 |
0
|
1619357215.42327
NtAllocateVirtualMemory
|
process_identifier:
3048
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ffffef0000
|
success
|
0 |
0
|
1619357215.47027
NtAllocateVirtualMemory
|
process_identifier:
3048
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff0001a000
|
success
|
0 |
0
|
1619357216.22027
NtAllocateVirtualMemory
|
process_identifier:
3048
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff00023000
|
success
|
0 |
0
|
1619357216.23527
NtAllocateVirtualMemory
|
process_identifier:
3048
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff000cc000
|
success
|
0 |
0
|
1619357216.26727
NtAllocateVirtualMemory
|
process_identifier:
3048
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff000f6000
|
success
|
0 |
0
|
1619357216.26727
NtAllocateVirtualMemory
|
process_identifier:
3048
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff000d0000
|
success
|
0 |
0
|
1619357218.47027
NtAllocateVirtualMemory
|
process_identifier:
3048
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff00024000
|
success
|
0 |
0
|
1619357218.67327
NtAllocateVirtualMemory
|
process_identifier:
3048
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff0002c000
|
success
|
0 |
0
|
1619357220.42327
NtAllocateVirtualMemory
|
process_identifier:
3048
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff0001b000
|
success
|
0 |
0
|
1619357224.22027
NtAllocateVirtualMemory
|
process_identifier:
3048
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff00025000
|
success
|
0 |
0
|
1619357225.09527
NtAllocateVirtualMemory
|
process_identifier:
3048
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff00026000
|
success
|
0 |
0
|
1619357225.37627
NtAllocateVirtualMemory
|
process_identifier:
3048
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff00027000
|
success
|
0 |
0
|
1619357225.56327
NtAllocateVirtualMemory
|
process_identifier:
3048
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff00160000
|
success
|
0 |
0
|
1619357225.67327
NtAllocateVirtualMemory
|
process_identifier:
3048
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff0003b000
|
success
|
0 |
0
|
1619357225.68827
NtAllocateVirtualMemory
|
process_identifier:
3048
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff0002a000
|
success
|
0 |
0
|
1619357256.90727
NtAllocateVirtualMemory
|
process_identifier:
3048
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff00028000
|
success
|
0 |
0
|