| Time & API |
Arguments |
Status |
Return |
Repeated |
1619512009.572501
NtAllocateVirtualMemory
|
process_identifier:
2008
region_size:
110592
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00320000
|
success
|
0 |
0
|
1619512009.635501
NtProtectVirtualMemory
|
process_identifier:
2008
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
180224
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00400000
|
success
|
0 |
0
|
1619512010.869501
NtProtectVirtualMemory
|
process_identifier:
2008
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
81920
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00414000
|
success
|
0 |
0
|
1619512010.869501
NtAllocateVirtualMemory
|
process_identifier:
2008
region_size:
94208
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x02df0000
|
success
|
0 |
0
|
1619512011.119501
NtProtectVirtualMemory
|
process_identifier:
2008
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
81920
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00414000
|
success
|
0 |
0
|
1619512012.119501
NtAllocateVirtualMemory
|
process_identifier:
2008
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x000b0000
|
success
|
0 |
0
|
1619512012.119501
NtAllocateVirtualMemory
|
process_identifier:
2008
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x000f0000
|
success
|
0 |
0
|
1619512014.010501
NtAllocateVirtualMemory
|
process_identifier:
2008
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x000a0000
|
success
|
0 |
0
|
1619512014.010501
NtAllocateVirtualMemory
|
process_identifier:
2008
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00170000
|
success
|
0 |
0
|
1619512014.119501
NtAllocateVirtualMemory
|
process_identifier:
2008
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x02ed0000
|
success
|
0 |
0
|
1619512015.432501
NtAllocateVirtualMemory
|
process_identifier:
2008
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x02e80000
|
success
|
0 |
0
|
1619512015.432501
NtAllocateVirtualMemory
|
process_identifier:
2008
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00110000
|
success
|
0 |
0
|
1619512015.432501
NtAllocateVirtualMemory
|
process_identifier:
2008
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00120000
|
success
|
0 |
0
|
1619512017.072501
NtAllocateVirtualMemory
|
process_identifier:
2008
region_size:
12288
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x03f50000
|
success
|
0 |
0
|
1619512017.072501
NtAllocateVirtualMemory
|
process_identifier:
2008
region_size:
12288
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x03f60000
|
success
|
0 |
0
|
1619512021.104501
NtAllocateVirtualMemory
|
process_identifier:
2008
region_size:
98304
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x03f50000
|
success
|
0 |
0
|
1619512021.104501
NtAllocateVirtualMemory
|
process_identifier:
2008
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x04800000
|
success
|
0 |
0
|
1619512021.104501
NtAllocateVirtualMemory
|
process_identifier:
2008
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x04840000
|
success
|
0 |
0
|
1619512021.104501
NtAllocateVirtualMemory
|
process_identifier:
2008
region_size:
36864
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x04840000
|
success
|
0 |
0
|
1619512021.104501
NtAllocateVirtualMemory
|
process_identifier:
2008
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x04860000
|
success
|
0 |
0
|