| Time & API |
Arguments |
Status |
Return |
Repeated |
1620753705.836876
NtAllocateVirtualMemory
|
process_identifier:
2468
region_size:
548864
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x02340000
|
success
|
0 |
0
|
1620753705.836876
NtAllocateVirtualMemory
|
process_identifier:
2468
region_size:
163840
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02360000
|
success
|
0 |
0
|
1620753708.164876
NtAllocateVirtualMemory
|
process_identifier:
2468
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x02c70000
|
success
|
0 |
0
|
1620753708.226876
NtAllocateVirtualMemory
|
process_identifier:
2468
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x02c70000
|
success
|
0 |
0
|
1620753708.242876
NtAllocateVirtualMemory
|
process_identifier:
2468
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x02c70000
|
success
|
0 |
0
|
1620753708.320876
NtAllocateVirtualMemory
|
process_identifier:
2468
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x02c70000
|
success
|
0 |
0
|
1620753708.367876
NtAllocateVirtualMemory
|
process_identifier:
2468
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x02c70000
|
success
|
0 |
0
|
1620753708.398876
NtAllocateVirtualMemory
|
process_identifier:
2468
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x02c70000
|
success
|
0 |
0
|
1620753708.414876
NtAllocateVirtualMemory
|
process_identifier:
2468
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x02c70000
|
success
|
0 |
0
|
1620753708.445876
NtAllocateVirtualMemory
|
process_identifier:
2468
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x02c70000
|
success
|
0 |
0
|
1620753708.476876
NtAllocateVirtualMemory
|
process_identifier:
2468
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x02c70000
|
success
|
0 |
0
|
1620753708.554876
NtAllocateVirtualMemory
|
process_identifier:
2468
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x02c70000
|
success
|
0 |
0
|
1620753708.586876
NtAllocateVirtualMemory
|
process_identifier:
2468
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x02c70000
|
success
|
0 |
0
|
1620753708.633876
NtAllocateVirtualMemory
|
process_identifier:
2468
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x02c70000
|
success
|
0 |
0
|
1620753708.664876
NtAllocateVirtualMemory
|
process_identifier:
2468
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x02c70000
|
success
|
0 |
0
|
1620753708.711876
NtAllocateVirtualMemory
|
process_identifier:
2468
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x02c70000
|
success
|
0 |
0
|
1620753708.726876
NtAllocateVirtualMemory
|
process_identifier:
2468
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x02c70000
|
success
|
0 |
0
|
1620753708.726876
NtAllocateVirtualMemory
|
process_identifier:
2468
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x02c70000
|
success
|
0 |
0
|
1620753708.773876
NtAllocateVirtualMemory
|
process_identifier:
2468
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x02c70000
|
success
|
0 |
0
|
1620753708.804876
NtAllocateVirtualMemory
|
process_identifier:
2468
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x02c70000
|
success
|
0 |
0
|
1620753708.851876
NtAllocateVirtualMemory
|
process_identifier:
2468
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x02c70000
|
success
|
0 |
0
|
1620753708.898876
NtAllocateVirtualMemory
|
process_identifier:
2468
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x02c70000
|
success
|
0 |
0
|
1620753708.945876
NtAllocateVirtualMemory
|
process_identifier:
2468
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x02c70000
|
success
|
0 |
0
|
1620753708.976876
NtAllocateVirtualMemory
|
process_identifier:
2468
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x02c70000
|
success
|
0 |
0
|
1620753709.039876
NtAllocateVirtualMemory
|
process_identifier:
2468
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x02c70000
|
success
|
0 |
0
|
1620753709.070876
NtAllocateVirtualMemory
|
process_identifier:
2468
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x02c70000
|
success
|
0 |
0
|
1620753709.070876
NtAllocateVirtualMemory
|
process_identifier:
2468
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x02c70000
|
success
|
0 |
0
|
1620753709.070876
NtAllocateVirtualMemory
|
process_identifier:
2468
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x02c70000
|
success
|
0 |
0
|
1620753709.070876
NtAllocateVirtualMemory
|
process_identifier:
2468
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x02c70000
|
success
|
0 |
0
|
1620753709.086876
NtAllocateVirtualMemory
|
process_identifier:
2468
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x02c70000
|
success
|
0 |
0
|
1620753709.086876
NtAllocateVirtualMemory
|
process_identifier:
2468
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x02c70000
|
success
|
0 |
0
|
1620753709.117876
NtAllocateVirtualMemory
|
process_identifier:
2468
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x02c70000
|
success
|
0 |
0
|
1620753709.179876
NtAllocateVirtualMemory
|
process_identifier:
2468
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x02c70000
|
success
|
0 |
0
|
1620753709.211876
NtAllocateVirtualMemory
|
process_identifier:
2468
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x02c70000
|
success
|
0 |
0
|
1620753709.258876
NtAllocateVirtualMemory
|
process_identifier:
2468
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x02c70000
|
success
|
0 |
0
|
1620753709.289876
NtAllocateVirtualMemory
|
process_identifier:
2468
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x02c70000
|
success
|
0 |
0
|
1620753709.336876
NtAllocateVirtualMemory
|
process_identifier:
2468
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x02c70000
|
success
|
0 |
0
|
1620753709.367876
NtProtectVirtualMemory
|
process_identifier:
2468
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00400000
|
success
|
0 |
0
|
1620753709.367876
NtProtectVirtualMemory
|
process_identifier:
2468
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00401000
|
success
|
0 |
0
|
1620753709.367876
NtProtectVirtualMemory
|
process_identifier:
2468
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00402000
|
success
|
0 |
0
|
1620753709.367876
NtProtectVirtualMemory
|
process_identifier:
2468
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00403000
|
success
|
0 |
0
|
1620753709.367876
NtProtectVirtualMemory
|
process_identifier:
2468
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00404000
|
success
|
0 |
0
|
1620753709.367876
NtProtectVirtualMemory
|
process_identifier:
2468
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00405000
|
success
|
0 |
0
|
1620753709.367876
NtProtectVirtualMemory
|
process_identifier:
2468
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00406000
|
success
|
0 |
0
|
1620753709.367876
NtProtectVirtualMemory
|
process_identifier:
2468
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00407000
|
success
|
0 |
0
|
1620753709.367876
NtProtectVirtualMemory
|
process_identifier:
2468
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00408000
|
success
|
0 |
0
|
1620753709.367876
NtProtectVirtualMemory
|
process_identifier:
2468
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00409000
|
success
|
0 |
0
|
1620753709.367876
NtProtectVirtualMemory
|
process_identifier:
2468
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x0040a000
|
success
|
0 |
0
|
1620753709.367876
NtProtectVirtualMemory
|
process_identifier:
2468
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x0040b000
|
success
|
0 |
0
|
1620753709.367876
NtProtectVirtualMemory
|
process_identifier:
2468
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x0040c000
|
success
|
0 |
0
|