| Time & API |
Arguments |
Status |
Return |
Repeated |
1619384483.859125
NtAllocateVirtualMemory
|
process_identifier:
2196
region_size:
1900544
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00bb0000
|
success
|
0 |
0
|
1619384483.859125
NtAllocateVirtualMemory
|
process_identifier:
2196
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00d40000
|
success
|
0 |
0
|
1619384485.140125
NtProtectVirtualMemory
|
process_identifier:
2196
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73c51000
|
success
|
0 |
0
|
1619384485.453125
NtAllocateVirtualMemory
|
process_identifier:
2196
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003aa000
|
success
|
0 |
0
|
1619384485.453125
NtProtectVirtualMemory
|
process_identifier:
2196
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73c52000
|
success
|
0 |
0
|
1619384485.453125
NtAllocateVirtualMemory
|
process_identifier:
2196
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003a2000
|
success
|
0 |
0
|
1619384485.875125
NtAllocateVirtualMemory
|
process_identifier:
2196
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003b2000
|
success
|
0 |
0
|
1619384485.953125
NtAllocateVirtualMemory
|
process_identifier:
2196
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003b3000
|
success
|
0 |
0
|
1619384485.968125
NtAllocateVirtualMemory
|
process_identifier:
2196
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003eb000
|
success
|
0 |
0
|
1619384485.968125
NtAllocateVirtualMemory
|
process_identifier:
2196
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003e7000
|
success
|
0 |
0
|
1619384486.000125
NtAllocateVirtualMemory
|
process_identifier:
2196
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003bc000
|
success
|
0 |
0
|
1619384486.078125
NtAllocateVirtualMemory
|
process_identifier:
2196
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00890000
|
success
|
0 |
0
|
1619384486.265125
NtAllocateVirtualMemory
|
process_identifier:
2196
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00891000
|
success
|
0 |
0
|
1619384486.281125
NtAllocateVirtualMemory
|
process_identifier:
2196
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003ba000
|
success
|
0 |
0
|
1619384486.343125
NtProtectVirtualMemory
|
process_identifier:
2196
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
454656
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00912000
|
success
|
0 |
0
|
1619384490.781125
NtAllocateVirtualMemory
|
process_identifier:
2196
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003b4000
|
success
|
0 |
0
|
1619384490.781125
NtAllocateVirtualMemory
|
process_identifier:
2196
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00892000
|
success
|
0 |
0
|
1619384490.828125
NtAllocateVirtualMemory
|
process_identifier:
2196
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00893000
|
success
|
0 |
0
|
1619384490.843125
NtAllocateVirtualMemory
|
process_identifier:
2196
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00894000
|
success
|
0 |
0
|
1619384490.921125
NtAllocateVirtualMemory
|
process_identifier:
2196
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00895000
|
success
|
0 |
0
|
1619384491.140125
NtAllocateVirtualMemory
|
process_identifier:
2196
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00896000
|
success
|
0 |
0
|
1619384491.171125
NtAllocateVirtualMemory
|
process_identifier:
2196
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003b5000
|
success
|
0 |
0
|
1619384491.171125
NtAllocateVirtualMemory
|
process_identifier:
2196
region_size:
12288
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00897000
|
success
|
0 |
0
|
1619384491.187125
NtAllocateVirtualMemory
|
process_identifier:
2196
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0089a000
|
success
|
0 |
0
|
1619384491.187125
NtAllocateVirtualMemory
|
process_identifier:
2196
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003da000
|
success
|
0 |
0
|
1619384491.265125
NtAllocateVirtualMemory
|
process_identifier:
2196
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003d2000
|
success
|
0 |
0
|
1619384491.296125
NtAllocateVirtualMemory
|
process_identifier:
2196
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003e5000
|
success
|
0 |
0
|
1619384491.500125
NtAllocateVirtualMemory
|
process_identifier:
2196
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0089b000
|
success
|
0 |
0
|
1619384491.703125
NtAllocateVirtualMemory
|
process_identifier:
2196
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003c6000
|
success
|
0 |
0
|
1619384491.703125
NtAllocateVirtualMemory
|
process_identifier:
2196
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003ca000
|
success
|
0 |
0
|
1619384491.703125
NtAllocateVirtualMemory
|
process_identifier:
2196
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003c7000
|
success
|
0 |
0
|
1619384493.890125
NtAllocateVirtualMemory
|
process_identifier:
2196
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003ab000
|
success
|
0 |
0
|
1619384494.078125
NtAllocateVirtualMemory
|
process_identifier:
2196
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0089c000
|
success
|
0 |
0
|
1619384494.171125
NtAllocateVirtualMemory
|
process_identifier:
2196
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003b6000
|
success
|
0 |
0
|
1619384494.437125
NtAllocateVirtualMemory
|
process_identifier:
2196
region_size:
2031616
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x070d0000
|
success
|
0 |
0
|
1619384494.437125
NtAllocateVirtualMemory
|
process_identifier:
2196
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x07280000
|
success
|
0 |
0
|
1619384494.437125
NtAllocateVirtualMemory
|
process_identifier:
2196
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x07281000
|
success
|
0 |
0
|
1619384494.484125
NtAllocateVirtualMemory
|
process_identifier:
2196
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x07282000
|
success
|
0 |
0
|
1619384494.500125
NtAllocateVirtualMemory
|
process_identifier:
2196
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x07283000
|
success
|
0 |
0
|
1619384494.500125
NtAllocateVirtualMemory
|
process_identifier:
2196
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x07284000
|
success
|
0 |
0
|
1619384494.500125
NtAllocateVirtualMemory
|
process_identifier:
2196
region_size:
12288
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x07286000
|
success
|
0 |
0
|
1619384494.515125
NtAllocateVirtualMemory
|
process_identifier:
2196
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003b7000
|
success
|
0 |
0
|
1619384494.562125
NtAllocateVirtualMemory
|
process_identifier:
2196
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0089d000
|
success
|
0 |
0
|
1619384494.578125
NtAllocateVirtualMemory
|
process_identifier:
2196
region_size:
16384
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x07289000
|
success
|
0 |
0
|
1619384494.578125
NtAllocateVirtualMemory
|
process_identifier:
2196
region_size:
69632
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0728d000
|
success
|
0 |
0
|
1619384494.578125
NtAllocateVirtualMemory
|
process_identifier:
2196
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0729e000
|
success
|
0 |
0
|
1619384494.578125
NtAllocateVirtualMemory
|
process_identifier:
2196
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0729f000
|
success
|
0 |
0
|
1619384494.578125
NtAllocateVirtualMemory
|
process_identifier:
2196
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0089e000
|
success
|
0 |
0
|
1619384494.812125
NtAllocateVirtualMemory
|
process_identifier:
2196
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003b8000
|
success
|
0 |
0
|
1619384505.125125
NtAllocateVirtualMemory
|
process_identifier:
2196
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0089f000
|
success
|
0 |
0
|