| Time & API |
Arguments |
Status |
Return |
Repeated |
1619504646.406375
NtAllocateVirtualMemory
|
process_identifier:
1416
region_size:
2097152
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x008e0000
|
success
|
0 |
0
|
1619504646.406375
NtAllocateVirtualMemory
|
process_identifier:
1416
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00aa0000
|
success
|
0 |
0
|
1619504650.094375
NtProtectVirtualMemory
|
process_identifier:
1416
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73a41000
|
success
|
0 |
0
|
1619504650.547375
NtAllocateVirtualMemory
|
process_identifier:
1416
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0044a000
|
success
|
0 |
0
|
1619504650.547375
NtProtectVirtualMemory
|
process_identifier:
1416
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73a42000
|
success
|
0 |
0
|
1619504650.547375
NtAllocateVirtualMemory
|
process_identifier:
1416
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00442000
|
success
|
0 |
0
|
1619504651.625375
NtAllocateVirtualMemory
|
process_identifier:
1416
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00452000
|
success
|
0 |
0
|
1619504651.938375
NtAllocateVirtualMemory
|
process_identifier:
1416
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00453000
|
success
|
0 |
0
|
1619504652.078375
NtAllocateVirtualMemory
|
process_identifier:
1416
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0048b000
|
success
|
0 |
0
|
1619504652.078375
NtAllocateVirtualMemory
|
process_identifier:
1416
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00487000
|
success
|
0 |
0
|
1619504655.328375
NtAllocateVirtualMemory
|
process_identifier:
1416
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0045c000
|
success
|
0 |
0
|
1619504657.094375
NtAllocateVirtualMemory
|
process_identifier:
1416
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00454000
|
success
|
0 |
0
|
1619504657.109375
NtAllocateVirtualMemory
|
process_identifier:
1416
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00455000
|
success
|
0 |
0
|
1619504657.328375
NtAllocateVirtualMemory
|
process_identifier:
1416
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00456000
|
success
|
0 |
0
|
1619504657.344375
NtAllocateVirtualMemory
|
process_identifier:
1416
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00820000
|
success
|
0 |
0
|
1619504657.500375
NtAllocateVirtualMemory
|
process_identifier:
1416
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0046a000
|
success
|
0 |
0
|
1619504657.500375
NtAllocateVirtualMemory
|
process_identifier:
1416
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00467000
|
success
|
0 |
0
|
1619504657.500375
NtAllocateVirtualMemory
|
process_identifier:
1416
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0047a000
|
success
|
0 |
0
|
1619504657.656375
NtAllocateVirtualMemory
|
process_identifier:
1416
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0044b000
|
success
|
0 |
0
|
1619504657.813375
NtAllocateVirtualMemory
|
process_identifier:
1416
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00821000
|
success
|
0 |
0
|
1619504659.750375
NtAllocateVirtualMemory
|
process_identifier:
1416
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00457000
|
success
|
0 |
0
|
1619504659.953375
NtAllocateVirtualMemory
|
process_identifier:
1416
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00472000
|
success
|
0 |
0
|
1619504660.031375
NtAllocateVirtualMemory
|
process_identifier:
1416
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00485000
|
success
|
0 |
0
|
1619504661.203375
NtAllocateVirtualMemory
|
process_identifier:
1416
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0047c000
|
success
|
0 |
0
|
1619504661.203375
NtAllocateVirtualMemory
|
process_identifier:
1416
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00822000
|
success
|
0 |
0
|
1619504703.844375
NtAllocateVirtualMemory
|
process_identifier:
1416
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00aa1000
|
success
|
0 |
0
|
1619504712.625375
NtAllocateVirtualMemory
|
process_identifier:
1416
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00823000
|
success
|
0 |
0
|
1619504713.484375
NtAllocateVirtualMemory
|
process_identifier:
1416
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00824000
|
success
|
0 |
0
|
1619504717.438375
NtAllocateVirtualMemory
|
process_identifier:
1416
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00466000
|
success
|
0 |
0
|
1619504718.250375
NtAllocateVirtualMemory
|
process_identifier:
1416
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00458000
|
success
|
0 |
0
|
1619504719.094375
NtAllocateVirtualMemory
|
process_identifier:
1416
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00825000
|
success
|
0 |
0
|
1619504720.844375
NtAllocateVirtualMemory
|
process_identifier:
1416
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0045a000
|
success
|
0 |
0
|
1619504721.750375
NtAllocateVirtualMemory
|
process_identifier:
1416
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04850000
|
success
|
0 |
0
|
1619504721.750375
NtProtectVirtualMemory
|
process_identifier:
1416
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
289280
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x04a10400
|
failed
|
3221225550 |
0
|
1619504725.813375
NtAllocateVirtualMemory
|
process_identifier:
1416
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00826000
|
success
|
0 |
0
|
1619504725.828375
NtAllocateVirtualMemory
|
process_identifier:
1416
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00459000
|
success
|
0 |
0
|
1619504725.828375
NtAllocateVirtualMemory
|
process_identifier:
1416
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00827000
|
success
|
0 |
0
|
1619504725.969375
NtAllocateVirtualMemory
|
process_identifier:
1416
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00828000
|
success
|
0 |
0
|
1619504726.047375
NtAllocateVirtualMemory
|
process_identifier:
1416
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00829000
|
success
|
0 |
0
|
1619504726.047375
NtAllocateVirtualMemory
|
process_identifier:
1416
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0082a000
|
success
|
0 |
0
|
1619504726.125375
NtAllocateVirtualMemory
|
process_identifier:
1416
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0082b000
|
success
|
0 |
0
|
1619504726.156375
NtAllocateVirtualMemory
|
process_identifier:
1416
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0082c000
|
success
|
0 |
0
|
1619504726.156375
NtProtectVirtualMemory
|
process_identifier:
1416
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x04a10178
|
failed
|
3221225550 |
0
|
1619504726.156375
NtProtectVirtualMemory
|
process_identifier:
1416
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x04a101a0
|
failed
|
3221225550 |
0
|
1619504726.156375
NtProtectVirtualMemory
|
process_identifier:
1416
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x04a101c8
|
failed
|
3221225550 |
0
|
1619504726.156375
NtProtectVirtualMemory
|
process_identifier:
1416
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x04a101f0
|
failed
|
3221225550 |
0
|
1619504726.156375
NtProtectVirtualMemory
|
process_identifier:
1416
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x04a10218
|
failed
|
3221225550 |
0
|
1619504726.156375
NtProtectVirtualMemory
|
process_identifier:
1416
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
11
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x04a5771e
|
failed
|
3221225550 |
0
|
1619504726.156375
NtProtectVirtualMemory
|
process_identifier:
1416
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
11
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x04a57712
|
failed
|
3221225550 |
0
|
1619504726.156375
NtProtectVirtualMemory
|
process_identifier:
1416
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
72
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x04a56e00
|
failed
|
3221225550 |
0
|