| Time & API |
Arguments |
Status |
Return |
Repeated |
1619403928.177
NtAllocateVirtualMemory
|
process_identifier:
2236
region_size:
1114112
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00610000
|
success
|
0 |
0
|
1619403928.177
NtAllocateVirtualMemory
|
process_identifier:
2236
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006e0000
|
success
|
0 |
0
|
1619403928.88
NtProtectVirtualMemory
|
process_identifier:
2236
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73c51000
|
success
|
0 |
0
|
1619403928.927
NtAllocateVirtualMemory
|
process_identifier:
2236
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0061a000
|
success
|
0 |
0
|
1619403928.927
NtProtectVirtualMemory
|
process_identifier:
2236
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73c52000
|
success
|
0 |
0
|
1619403928.927
NtAllocateVirtualMemory
|
process_identifier:
2236
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00612000
|
success
|
0 |
0
|
1619403929.224
NtAllocateVirtualMemory
|
process_identifier:
2236
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00622000
|
success
|
0 |
0
|
1619403929.302
NtAllocateVirtualMemory
|
process_identifier:
2236
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00623000
|
success
|
0 |
0
|
1619403929.318
NtAllocateVirtualMemory
|
process_identifier:
2236
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0065b000
|
success
|
0 |
0
|
1619403929.318
NtAllocateVirtualMemory
|
process_identifier:
2236
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00657000
|
success
|
0 |
0
|
1619403929.365
NtAllocateVirtualMemory
|
process_identifier:
2236
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0062c000
|
success
|
0 |
0
|
1619403930.036
NtAllocateVirtualMemory
|
process_identifier:
2236
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00624000
|
success
|
0 |
0
|
1619403930.146
NtAllocateVirtualMemory
|
process_identifier:
2236
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00626000
|
success
|
0 |
0
|
1619403930.146
NtAllocateVirtualMemory
|
process_identifier:
2236
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x01f50000
|
success
|
0 |
0
|
1619403930.24
NtAllocateVirtualMemory
|
process_identifier:
2236
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0063a000
|
success
|
0 |
0
|
1619403930.24
NtAllocateVirtualMemory
|
process_identifier:
2236
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00637000
|
success
|
0 |
0
|
1619403930.24
NtAllocateVirtualMemory
|
process_identifier:
2236
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0064a000
|
success
|
0 |
0
|
1619403930.286
NtAllocateVirtualMemory
|
process_identifier:
2236
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0061b000
|
success
|
0 |
0
|
1619403930.458
NtAllocateVirtualMemory
|
process_identifier:
2236
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00636000
|
success
|
0 |
0
|
1619403930.474
NtAllocateVirtualMemory
|
process_identifier:
2236
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0062a000
|
success
|
0 |
0
|
1619403930.646
NtAllocateVirtualMemory
|
process_identifier:
2236
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006e1000
|
success
|
0 |
0
|
1619403930.74
NtAllocateVirtualMemory
|
process_identifier:
2236
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02040000
|
success
|
0 |
0
|
1619403930.974
NtAllocateVirtualMemory
|
process_identifier:
2236
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00655000
|
success
|
0 |
0
|
1619403931.083
NtAllocateVirtualMemory
|
process_identifier:
2236
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00642000
|
success
|
0 |
0
|
1619403937.505
NtAllocateVirtualMemory
|
process_identifier:
2236
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00627000
|
success
|
0 |
0
|
1619403937.88
NtAllocateVirtualMemory
|
process_identifier:
2236
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02041000
|
success
|
0 |
0
|
1619403938.083
NtAllocateVirtualMemory
|
process_identifier:
2236
region_size:
1900544
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x04c60000
|
success
|
0 |
0
|
1619403938.083
NtAllocateVirtualMemory
|
process_identifier:
2236
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04df0000
|
success
|
0 |
0
|
1619403938.083
NtAllocateVirtualMemory
|
process_identifier:
2236
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04df1000
|
success
|
0 |
0
|
1619403938.115
NtAllocateVirtualMemory
|
process_identifier:
2236
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04df2000
|
success
|
0 |
0
|
1619403938.161
NtAllocateVirtualMemory
|
process_identifier:
2236
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x01f51000
|
success
|
0 |
0
|
1619403938.302
NtAllocateVirtualMemory
|
process_identifier:
2236
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04df3000
|
success
|
0 |
0
|
1619403938.318
NtAllocateVirtualMemory
|
process_identifier:
2236
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04df4000
|
success
|
0 |
0
|
1619403938.38
NtAllocateVirtualMemory
|
process_identifier:
2236
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04df5000
|
success
|
0 |
0
|
1619403938.38
NtAllocateVirtualMemory
|
process_identifier:
2236
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x01f52000
|
success
|
0 |
0
|
1619403938.458
NtAllocateVirtualMemory
|
process_identifier:
2236
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00628000
|
success
|
0 |
0
|
1619403938.63
NtAllocateVirtualMemory
|
process_identifier:
2236
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x01f53000
|
success
|
0 |
0
|
1619403938.865
NtAllocateVirtualMemory
|
process_identifier:
2236
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00629000
|
success
|
0 |
0
|
1619403938.865
NtAllocateVirtualMemory
|
process_identifier:
2236
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x01f54000
|
success
|
0 |
0
|
1619403938.865
NtAllocateVirtualMemory
|
process_identifier:
2236
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x045e0000
|
success
|
0 |
0
|
1619403938.865
NtAllocateVirtualMemory
|
process_identifier:
2236
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x01f55000
|
success
|
0 |
0
|
1619403938.865
NtAllocateVirtualMemory
|
process_identifier:
2236
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x01f56000
|
success
|
0 |
0
|
1619403938.88
NtAllocateVirtualMemory
|
process_identifier:
2236
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x01f57000
|
success
|
0 |
0
|
1619403938.88
NtAllocateVirtualMemory
|
process_identifier:
2236
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x01f58000
|
success
|
0 |
0
|
1619403938.958
NtAllocateVirtualMemory
|
process_identifier:
2236
region_size:
12288
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x01f59000
|
success
|
0 |
0
|
1619403938.99
NtAllocateVirtualMemory
|
process_identifier:
2236
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00613000
|
success
|
0 |
0
|
1619403939.115
NtProtectVirtualMemory
|
process_identifier:
2236
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x04b00178
|
failed
|
3221225550 |
0
|
1619403939.115
NtProtectVirtualMemory
|
process_identifier:
2236
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x04b001a0
|
failed
|
3221225550 |
0
|
1619403939.115
NtProtectVirtualMemory
|
process_identifier:
2236
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x04b001c8
|
failed
|
3221225550 |
0
|
1619403939.115
NtProtectVirtualMemory
|
process_identifier:
2236
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
11
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x04b5030e
|
failed
|
3221225550 |
0
|