| Time & API |
Arguments |
Status |
Return |
Repeated |
1619363451.914501
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
917504
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00560000
|
success
|
0 |
0
|
1619363451.914501
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00600000
|
success
|
0 |
0
|
1619363452.523501
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
458752
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x003e0000
|
success
|
0 |
0
|
1619363452.523501
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00410000
|
success
|
0 |
0
|
1619363452.570501
NtProtectVirtualMemory
|
process_identifier:
2764
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73b91000
|
success
|
0 |
0
|
1619363452.648501
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
589824
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00560000
|
success
|
0 |
0
|
1619363452.648501
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005b0000
|
success
|
0 |
0
|
1619363452.648501
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0038a000
|
success
|
0 |
0
|
1619363452.648501
NtProtectVirtualMemory
|
process_identifier:
2764
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73b92000
|
success
|
0 |
0
|
1619363452.648501
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00382000
|
success
|
0 |
0
|
1619363452.867501
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00392000
|
success
|
0 |
0
|
1619363452.976501
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003c5000
|
success
|
0 |
0
|
1619363452.976501
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003cb000
|
success
|
0 |
0
|
1619363452.976501
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003c7000
|
success
|
0 |
0
|
1619363453.117501
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00393000
|
success
|
0 |
0
|
1619363453.164501
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0039c000
|
success
|
0 |
0
|
1619363453.258501
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x01ff0000
|
success
|
0 |
0
|
1619363453.289501
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00394000
|
success
|
0 |
0
|
1619363453.304501
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x01ff1000
|
success
|
0 |
0
|
1619363453.383501
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x01ff2000
|
success
|
0 |
0
|
1619363454.367501
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00395000
|
success
|
0 |
0
|
1619363454.758501
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00397000
|
success
|
0 |
0
|
1619363459.101501
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003ba000
|
success
|
0 |
0
|
1619363459.101501
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003b7000
|
success
|
0 |
0
|
1619363459.383501
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x01ff3000
|
success
|
0 |
0
|
1619363459.633501
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00398000
|
success
|
0 |
0
|
1619363459.633501
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x01ff5000
|
success
|
0 |
0
|
1619363459.773501
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00399000
|
success
|
0 |
0
|
1619363459.914501
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x01ff6000
|
success
|
0 |
0
|
1619363460.054501
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003b6000
|
success
|
0 |
0
|
1619363460.117501
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006d0000
|
success
|
0 |
0
|
1619363460.211501
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006d1000
|
success
|
0 |
0
|
1619363460.226501
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x01ff7000
|
success
|
0 |
0
|
1619363460.242501
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006d2000
|
success
|
0 |
0
|
1619363460.258501
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
12288
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x01ff8000
|
success
|
0 |
0
|
1619363460.258501
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0039d000
|
success
|
0 |
0
|
1619363501.758501
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x01ffb000
|
success
|
0 |
0
|
1619363503.195501
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0038c000
|
success
|
0 |
0
|
1619363503.336501
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x01ffc000
|
success
|
0 |
0
|
1619363503.570501
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006d3000
|
success
|
0 |
0
|
1619363503.570501
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x01ffd000
|
success
|
0 |
0
|
1619363503.617501
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x01ffe000
|
success
|
0 |
0
|
1619363503.820501
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006d4000
|
success
|
0 |
0
|
1619363503.820501
NtProtectVirtualMemory
|
process_identifier:
2764
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
268800
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x05470400
|
failed
|
3221225550 |
0
|
1619363505.617501
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x01fff000
|
success
|
0 |
0
|
1619363505.648501
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04d90000
|
success
|
0 |
0
|
1619363505.648501
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04d91000
|
success
|
0 |
0
|
1619363505.664501
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04d92000
|
success
|
0 |
0
|
1619363505.664501
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04d93000
|
success
|
0 |
0
|
1619363505.726501
NtAllocateVirtualMemory
|
process_identifier:
2764
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006d5000
|
success
|
0 |
0
|