| Time & API |
Arguments |
Status |
Return |
Repeated |
1620726217.595355
NtAllocateVirtualMemory
|
process_identifier:
364
region_size:
1376256
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x0000000000880000
|
success
|
0 |
0
|
1620726217.595355
NtAllocateVirtualMemory
|
process_identifier:
364
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0000000000950000
|
success
|
0 |
0
|
1620726218.282355
NtAllocateVirtualMemory
|
process_identifier:
364
region_size:
1835008
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00000000021f0000
|
success
|
0 |
0
|
1620726218.282355
NtAllocateVirtualMemory
|
process_identifier:
364
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0000000002330000
|
success
|
0 |
0
|
1620726218.579355
NtProtectVirtualMemory
|
process_identifier:
364
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef19c1000
|
success
|
0 |
0
|
1620726218.579355
NtProtectVirtualMemory
|
process_identifier:
364
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef19c1000
|
success
|
0 |
0
|
1620726218.673355
NtProtectVirtualMemory
|
process_identifier:
364
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef2040000
|
success
|
0 |
0
|
1620726219.407355
NtAllocateVirtualMemory
|
process_identifier:
364
region_size:
2293760
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00000000023b0000
|
success
|
0 |
0
|
1620726219.407355
NtAllocateVirtualMemory
|
process_identifier:
364
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0000000002560000
|
success
|
0 |
0
|
1620726219.485355
NtProtectVirtualMemory
|
process_identifier:
364
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef19c2000
|
success
|
0 |
0
|
1620726219.485355
NtProtectVirtualMemory
|
process_identifier:
364
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef19c2000
|
success
|
0 |
0
|
1620726219.485355
NtProtectVirtualMemory
|
process_identifier:
364
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef19c2000
|
success
|
0 |
0
|
1620726219.485355
NtProtectVirtualMemory
|
process_identifier:
364
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef19c2000
|
success
|
0 |
0
|
1620726219.485355
NtProtectVirtualMemory
|
process_identifier:
364
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef19c2000
|
success
|
0 |
0
|
1620726219.485355
NtProtectVirtualMemory
|
process_identifier:
364
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef19c3000
|
success
|
0 |
0
|
1620726219.485355
NtProtectVirtualMemory
|
process_identifier:
364
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef19c3000
|
success
|
0 |
0
|
1620726219.485355
NtProtectVirtualMemory
|
process_identifier:
364
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef19c3000
|
success
|
0 |
0
|
1620726219.501355
NtProtectVirtualMemory
|
process_identifier:
364
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef19c3000
|
success
|
0 |
0
|
1620726219.501355
NtProtectVirtualMemory
|
process_identifier:
364
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef19c3000
|
success
|
0 |
0
|
1620726219.501355
NtProtectVirtualMemory
|
process_identifier:
364
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef19c3000
|
success
|
0 |
0
|
1620726219.501355
NtProtectVirtualMemory
|
process_identifier:
364
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef19c3000
|
success
|
0 |
0
|
1620726219.501355
NtProtectVirtualMemory
|
process_identifier:
364
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef19c1000
|
success
|
0 |
0
|
1620726219.501355
NtProtectVirtualMemory
|
process_identifier:
364
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef19c2000
|
success
|
0 |
0
|
1620726219.501355
NtProtectVirtualMemory
|
process_identifier:
364
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef19c2000
|
success
|
0 |
0
|
1620726219.517355
NtProtectVirtualMemory
|
process_identifier:
364
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef19c2000
|
success
|
0 |
0
|
1620726219.517355
NtProtectVirtualMemory
|
process_identifier:
364
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef19c2000
|
success
|
0 |
0
|
1620726219.517355
NtProtectVirtualMemory
|
process_identifier:
364
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef19c2000
|
success
|
0 |
0
|
1620726220.532355
NtAllocateVirtualMemory
|
process_identifier:
364
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff00032000
|
success
|
0 |
0
|
1620726220.579355
NtAllocateVirtualMemory
|
process_identifier:
364
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff00022000
|
success
|
0 |
0
|
1620726220.688355
NtAllocateVirtualMemory
|
process_identifier:
364
region_size:
655360
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
1056768
(MEM_RESERVE|MEM_TOP_DOWN)
base_address:
0x000007fffff00000
|
success
|
0 |
0
|
1620726220.688355
NtAllocateVirtualMemory
|
process_identifier:
364
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007fffff00000
|
success
|
0 |
0
|
1620726220.688355
NtAllocateVirtualMemory
|
process_identifier:
364
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007fffff00000
|
success
|
0 |
0
|
1620726220.688355
NtAllocateVirtualMemory
|
process_identifier:
364
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007fffff10000
|
success
|
0 |
0
|
1620726220.704355
NtAllocateVirtualMemory
|
process_identifier:
364
region_size:
65536
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
1056768
(MEM_RESERVE|MEM_TOP_DOWN)
base_address:
0x000007ffffef0000
|
success
|
0 |
0
|
1620726220.704355
NtAllocateVirtualMemory
|
process_identifier:
364
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ffffef0000
|
success
|
0 |
0
|
1620726220.704355
NtAllocateVirtualMemory
|
process_identifier:
364
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff0002a000
|
success
|
0 |
0
|
1620726220.751355
NtAllocateVirtualMemory
|
process_identifier:
364
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff00033000
|
success
|
0 |
0
|
1620726220.782355
NtAllocateVirtualMemory
|
process_identifier:
364
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff000dc000
|
success
|
0 |
0
|
1620726220.782355
NtAllocateVirtualMemory
|
process_identifier:
364
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff00106000
|
success
|
0 |
0
|
1620726220.782355
NtAllocateVirtualMemory
|
process_identifier:
364
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff000e0000
|
success
|
0 |
0
|
1620726221.204355
NtAllocateVirtualMemory
|
process_identifier:
364
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff00034000
|
success
|
0 |
0
|
1620726221.282355
NtAllocateVirtualMemory
|
process_identifier:
364
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff0002b000
|
success
|
0 |
0
|
1620726221.298355
NtAllocateVirtualMemory
|
process_identifier:
364
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff0003c000
|
success
|
0 |
0
|
1620726221.657355
NtAllocateVirtualMemory
|
process_identifier:
364
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff00035000
|
success
|
0 |
0
|
1620726222.767355
NtAllocateVirtualMemory
|
process_identifier:
364
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff00036000
|
success
|
0 |
0
|
1620726223.204355
NtAllocateVirtualMemory
|
process_identifier:
364
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff00037000
|
success
|
0 |
0
|
1620726223.235355
NtAllocateVirtualMemory
|
process_identifier:
364
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff00038000
|
success
|
0 |
0
|
1620726223.235355
NtAllocateVirtualMemory
|
process_identifier:
364
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff00180000
|
success
|
0 |
0
|
1620726223.267355
NtAllocateVirtualMemory
|
process_identifier:
364
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff00182000
|
success
|
0 |
0
|
1620726223.923355
NtAllocateVirtualMemory
|
process_identifier:
364
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff00183000
|
success
|
0 |
0
|