| Time & API |
Arguments |
Status |
Return |
Repeated |
1619340491.187125
NtAllocateVirtualMemory
|
process_identifier:
1908
region_size:
524288
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00380000
|
success
|
0 |
0
|
1619340491.187125
NtAllocateVirtualMemory
|
process_identifier:
1908
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003c0000
|
success
|
0 |
0
|
1619340492.343125
NtProtectVirtualMemory
|
process_identifier:
1908
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73c51000
|
success
|
0 |
0
|
1619340492.468125
NtAllocateVirtualMemory
|
process_identifier:
1908
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x008fa000
|
success
|
0 |
0
|
1619340492.468125
NtProtectVirtualMemory
|
process_identifier:
1908
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73c52000
|
success
|
0 |
0
|
1619340492.468125
NtAllocateVirtualMemory
|
process_identifier:
1908
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x008f2000
|
success
|
0 |
0
|
1619340492.765125
NtAllocateVirtualMemory
|
process_identifier:
1908
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00902000
|
success
|
0 |
0
|
1619340492.921125
NtAllocateVirtualMemory
|
process_identifier:
1908
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00903000
|
success
|
0 |
0
|
1619340492.937125
NtAllocateVirtualMemory
|
process_identifier:
1908
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0093b000
|
success
|
0 |
0
|
1619340492.937125
NtAllocateVirtualMemory
|
process_identifier:
1908
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00937000
|
success
|
0 |
0
|
1619340492.984125
NtAllocateVirtualMemory
|
process_identifier:
1908
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0090c000
|
success
|
0 |
0
|
1619340493.609125
NtAllocateVirtualMemory
|
process_identifier:
1908
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00904000
|
success
|
0 |
0
|
1619340493.609125
NtAllocateVirtualMemory
|
process_identifier:
1908
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00905000
|
success
|
0 |
0
|
1619340493.640125
NtAllocateVirtualMemory
|
process_identifier:
1908
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00906000
|
success
|
0 |
0
|
1619340493.656125
NtAllocateVirtualMemory
|
process_identifier:
1908
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04370000
|
success
|
0 |
0
|
1619340493.749125
NtAllocateVirtualMemory
|
process_identifier:
1908
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0091a000
|
success
|
0 |
0
|
1619340493.749125
NtAllocateVirtualMemory
|
process_identifier:
1908
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00917000
|
success
|
0 |
0
|
1619340493.749125
NtAllocateVirtualMemory
|
process_identifier:
1908
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0092a000
|
success
|
0 |
0
|
1619340493.796125
NtAllocateVirtualMemory
|
process_identifier:
1908
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x008fb000
|
success
|
0 |
0
|
1619340493.874125
NtAllocateVirtualMemory
|
process_identifier:
1908
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04371000
|
success
|
0 |
0
|
1619340493.984125
NtAllocateVirtualMemory
|
process_identifier:
1908
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00916000
|
success
|
0 |
0
|
1619340494.249125
NtAllocateVirtualMemory
|
process_identifier:
1908
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0090a000
|
success
|
0 |
0
|
1619340494.374125
NtAllocateVirtualMemory
|
process_identifier:
1908
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04373000
|
success
|
0 |
0
|
1619340494.406125
NtAllocateVirtualMemory
|
process_identifier:
1908
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x045a0000
|
success
|
0 |
0
|
1619340494.499125
NtAllocateVirtualMemory
|
process_identifier:
1908
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00922000
|
success
|
0 |
0
|
1619340494.656125
NtAllocateVirtualMemory
|
process_identifier:
1908
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00935000
|
success
|
0 |
0
|
1619340494.906125
NtAllocateVirtualMemory
|
process_identifier:
1908
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00907000
|
success
|
0 |
0
|
1619340495.124125
NtAllocateVirtualMemory
|
process_identifier:
1908
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0092c000
|
success
|
0 |
0
|
1619340495.515125
NtAllocateVirtualMemory
|
process_identifier:
1908
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003c1000
|
success
|
0 |
0
|
1619340495.640125
NtAllocateVirtualMemory
|
process_identifier:
1908
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00908000
|
success
|
0 |
0
|
1619340495.828125
NtAllocateVirtualMemory
|
process_identifier:
1908
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00909000
|
success
|
0 |
0
|
1619340496.124125
NtAllocateVirtualMemory
|
process_identifier:
1908
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04374000
|
success
|
0 |
0
|
1619340496.140125
NtAllocateVirtualMemory
|
process_identifier:
1908
region_size:
1835008
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x05540000
|
success
|
0 |
0
|
1619340496.140125
NtAllocateVirtualMemory
|
process_identifier:
1908
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x056c0000
|
success
|
0 |
0
|
1619340496.140125
NtAllocateVirtualMemory
|
process_identifier:
1908
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x056c1000
|
success
|
0 |
0
|
1619340496.218125
NtAllocateVirtualMemory
|
process_identifier:
1908
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x056c2000
|
success
|
0 |
0
|
1619340496.234125
NtAllocateVirtualMemory
|
process_identifier:
1908
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x056c3000
|
success
|
0 |
0
|
1619340496.234125
NtAllocateVirtualMemory
|
process_identifier:
1908
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x056c4000
|
success
|
0 |
0
|
1619340496.234125
NtAllocateVirtualMemory
|
process_identifier:
1908
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x056c6000
|
success
|
0 |
0
|
1619340496.234125
NtAllocateVirtualMemory
|
process_identifier:
1908
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x008f3000
|
success
|
0 |
0
|
1619340496.265125
NtAllocateVirtualMemory
|
process_identifier:
1908
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04375000
|
success
|
0 |
0
|
1619340496.281125
NtAllocateVirtualMemory
|
process_identifier:
1908
region_size:
16384
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x056c8000
|
success
|
0 |
0
|
1619340496.281125
NtAllocateVirtualMemory
|
process_identifier:
1908
region_size:
69632
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x056cc000
|
success
|
0 |
0
|
1619340496.281125
NtAllocateVirtualMemory
|
process_identifier:
1908
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x056dd000
|
success
|
0 |
0
|
1619340496.296125
NtAllocateVirtualMemory
|
process_identifier:
1908
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x056de000
|
success
|
0 |
0
|
1619340496.296125
NtAllocateVirtualMemory
|
process_identifier:
1908
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04ae0000
|
success
|
0 |
0
|
1619340496.296125
NtAllocateVirtualMemory
|
process_identifier:
1908
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04376000
|
success
|
0 |
0
|
1619340496.374125
NtAllocateVirtualMemory
|
process_identifier:
1908
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x045a1000
|
success
|
0 |
0
|
1619340496.656125
NtAllocateVirtualMemory
|
process_identifier:
1908
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x045a2000
|
success
|
0 |
0
|
1619340510.140125
NtAllocateVirtualMemory
|
process_identifier:
1908
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04377000
|
success
|
0 |
0
|