| Time & API |
Arguments |
Status |
Return |
Repeated |
1620726222.860125
NtAllocateVirtualMemory
|
process_identifier:
2520
region_size:
524288
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x004f0000
|
success
|
0 |
0
|
1620726222.860125
NtAllocateVirtualMemory
|
process_identifier:
2520
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00530000
|
success
|
0 |
0
|
1620726223.078125
NtAllocateVirtualMemory
|
process_identifier:
2520
region_size:
2293760
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x02090000
|
success
|
0 |
0
|
1620726223.078125
NtAllocateVirtualMemory
|
process_identifier:
2520
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02280000
|
success
|
0 |
0
|
1620726223.203125
NtProtectVirtualMemory
|
process_identifier:
2520
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73b91000
|
success
|
0 |
0
|
1620726223.344125
NtAllocateVirtualMemory
|
process_identifier:
2520
region_size:
2228224
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x022c0000
|
success
|
0 |
0
|
1620726223.344125
NtAllocateVirtualMemory
|
process_identifier:
2520
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x024a0000
|
success
|
0 |
0
|
1620726223.344125
NtAllocateVirtualMemory
|
process_identifier:
2520
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0059a000
|
success
|
0 |
0
|
1620726223.360125
NtProtectVirtualMemory
|
process_identifier:
2520
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73b92000
|
success
|
0 |
0
|
1620726223.360125
NtAllocateVirtualMemory
|
process_identifier:
2520
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00592000
|
success
|
0 |
0
|
1620726223.625125
NtAllocateVirtualMemory
|
process_identifier:
2520
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x008f2000
|
success
|
0 |
0
|
1620726223.735125
NtAllocateVirtualMemory
|
process_identifier:
2520
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00915000
|
success
|
0 |
0
|
1620726223.735125
NtAllocateVirtualMemory
|
process_identifier:
2520
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0091b000
|
success
|
0 |
0
|
1620726223.735125
NtAllocateVirtualMemory
|
process_identifier:
2520
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00917000
|
success
|
0 |
0
|
1620726223.860125
NtAllocateVirtualMemory
|
process_identifier:
2520
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x008f3000
|
success
|
0 |
0
|
1620726223.891125
NtAllocateVirtualMemory
|
process_identifier:
2520
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x008fc000
|
success
|
0 |
0
|
1620726223.953125
NtAllocateVirtualMemory
|
process_identifier:
2520
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x008f4000
|
success
|
0 |
0
|
1620726223.969125
NtAllocateVirtualMemory
|
process_identifier:
2520
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00aa0000
|
success
|
0 |
0
|
1620726224.250125
NtAllocateVirtualMemory
|
process_identifier:
2520
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x008f5000
|
success
|
0 |
0
|
1620726224.360125
NtAllocateVirtualMemory
|
process_identifier:
2520
region_size:
49152
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00aa1000
|
success
|
0 |
0
|
1620726224.500125
NtAllocateVirtualMemory
|
process_identifier:
2520
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00aad000
|
success
|
0 |
0
|
1620726224.672125
NtAllocateVirtualMemory
|
process_identifier:
2520
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00906000
|
success
|
0 |
0
|
1620726224.672125
NtAllocateVirtualMemory
|
process_identifier:
2520
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0090a000
|
success
|
0 |
0
|
1620726224.672125
NtAllocateVirtualMemory
|
process_identifier:
2520
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00907000
|
success
|
0 |
0
|
1620726224.953125
NtAllocateVirtualMemory
|
process_identifier:
2520
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x008f6000
|
success
|
0 |
0
|
1620726225.016125
NtAllocateVirtualMemory
|
process_identifier:
2520
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x008f8000
|
success
|
0 |
0
|
1620726225.063125
NtAllocateVirtualMemory
|
process_identifier:
2520
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00aae000
|
success
|
0 |
0
|
1620726225.125125
NtAllocateVirtualMemory
|
process_identifier:
2520
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00ab0000
|
success
|
0 |
0
|
1620726225.125125
NtProtectVirtualMemory
|
process_identifier:
2520
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73ab9000
|
success
|
0 |
0
|
1620726225.125125
NtAllocateVirtualMemory
|
process_identifier:
2520
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02210000
|
success
|
0 |
0
|
1620726225.125125
NtAllocateVirtualMemory
|
process_identifier:
2520
region_size:
20480
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02211000
|
success
|
0 |
0
|
1620726225.141125
NtAllocateVirtualMemory
|
process_identifier:
2520
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02216000
|
success
|
0 |
0
|
1620726225.266125
NtAllocateVirtualMemory
|
process_identifier:
2520
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x008f9000
|
success
|
0 |
0
|
1620726258.282125
NtAllocateVirtualMemory
|
process_identifier:
2520
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02217000
|
success
|
0 |
0
|
1620726258.282125
NtAllocateVirtualMemory
|
process_identifier:
2520
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02218000
|
success
|
0 |
0
|
1620726258.313125
NtAllocateVirtualMemory
|
process_identifier:
2520
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0221e000
|
success
|
0 |
0
|
1620726258.375125
NtAllocateVirtualMemory
|
process_identifier:
2520
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x023f0000
|
success
|
0 |
0
|
1620726258.375125
NtAllocateVirtualMemory
|
process_identifier:
2520
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0221f000
|
success
|
0 |
0
|
1620726258.391125
NtAllocateVirtualMemory
|
process_identifier:
2520
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02420000
|
success
|
0 |
0
|
1620726258.391125
NtAllocateVirtualMemory
|
process_identifier:
2520
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02421000
|
success
|
0 |
0
|
1620726258.391125
NtAllocateVirtualMemory
|
process_identifier:
2520
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02422000
|
success
|
0 |
0
|
1620726258.407125
NtAllocateVirtualMemory
|
process_identifier:
2520
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02423000
|
success
|
0 |
0
|
1620726258.438125
NtAllocateVirtualMemory
|
process_identifier:
2520
region_size:
16384
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02424000
|
success
|
0 |
0
|
1620726258.500125
NtAllocateVirtualMemory
|
process_identifier:
2520
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02428000
|
success
|
0 |
0
|
1620726258.688125
NtAllocateVirtualMemory
|
process_identifier:
2520
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02281000
|
success
|
0 |
0
|
1620726258.735125
NtAllocateVirtualMemory
|
process_identifier:
2520
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0059c000
|
success
|
0 |
0
|
1620726258.844125
NtAllocateVirtualMemory
|
process_identifier:
2520
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02429000
|
success
|
0 |
0
|
1620726258.907125
NtAllocateVirtualMemory
|
process_identifier:
2520
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x023f1000
|
success
|
0 |
0
|
1620726258.907125
NtAllocateVirtualMemory
|
process_identifier:
2520
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0242a000
|
success
|
0 |
0
|
1620726258.953125
NtAllocateVirtualMemory
|
process_identifier:
2520
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x023f2000
|
success
|
0 |
0
|