| Time & API |
Arguments |
Status |
Return |
Repeated |
1619464052.9845
NtAllocateVirtualMemory
|
process_identifier:
2852
region_size:
17408000
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000ec
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00400000
|
success
|
0 |
0
|
1619464052.9845
NtAllocateVirtualMemory
|
process_identifier:
2852
region_size:
1024000
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000ec
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x001e0000
|
success
|
0 |
0
|
1619488180.9765
NtProtectVirtualMemory
|
process_identifier:
2868
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000040
base_address:
0x00a81000
|
success
|
0 |
0
|
1619488181.147125
NtAllocateVirtualMemory
|
process_identifier:
1424
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000088
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x06c30000
|
success
|
0 |
0
|
1619488182.179125
NtAllocateVirtualMemory
|
process_identifier:
276
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000c0
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00210000
|
success
|
0 |
0
|
1619488182.179125
NtAllocateVirtualMemory
|
process_identifier:
372
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000c0
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00eb0000
|
success
|
0 |
0
|
1619488182.179125
NtAllocateVirtualMemory
|
process_identifier:
424
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000c0
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x0a200000
|
success
|
0 |
0
|
1619488182.179125
NtAllocateVirtualMemory
|
process_identifier:
432
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000c0
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00110000
|
success
|
0 |
0
|
1619488182.179125
NtAllocateVirtualMemory
|
process_identifier:
476
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000c0
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00110000
|
success
|
0 |
0
|
1619488182.179125
NtAllocateVirtualMemory
|
process_identifier:
508
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000c0
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x001d0000
|
success
|
0 |
0
|
1619488182.179125
NtAllocateVirtualMemory
|
process_identifier:
536
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000c0
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x009e0000
|
success
|
0 |
0
|
1619488182.179125
NtAllocateVirtualMemory
|
process_identifier:
544
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000c0
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00190000
|
success
|
0 |
0
|
1619488182.179125
NtAllocateVirtualMemory
|
process_identifier:
656
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000c0
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00400000
|
success
|
0 |
0
|
1619488182.179125
NtAllocateVirtualMemory
|
process_identifier:
720
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000c0
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x000d0000
|
success
|
0 |
0
|
1619488182.179125
NtAllocateVirtualMemory
|
process_identifier:
788
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000c0
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x001c0000
|
success
|
0 |
0
|
1619488182.194125
NtAllocateVirtualMemory
|
process_identifier:
868
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000c0
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00e50000
|
success
|
0 |
0
|
1619488182.194125
NtAllocateVirtualMemory
|
process_identifier:
924
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000c0
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00e50000
|
success
|
0 |
0
|
1619488182.194125
NtAllocateVirtualMemory
|
process_identifier:
956
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000c0
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00f70000
|
success
|
0 |
0
|
1619488182.194125
NtAllocateVirtualMemory
|
process_identifier:
540
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000c0
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00d10000
|
success
|
0 |
0
|
1619488182.194125
NtAllocateVirtualMemory
|
process_identifier:
1080
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000c0
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x014f0000
|
success
|
0 |
0
|
1619488182.194125
NtAllocateVirtualMemory
|
process_identifier:
1260
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000c0
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00190000
|
success
|
0 |
0
|
1619488182.210125
NtAllocateVirtualMemory
|
process_identifier:
1288
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000c0
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00180000
|
success
|
0 |
0
|
1619488182.210125
NtAllocateVirtualMemory
|
process_identifier:
1336
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000c0
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00350000
|
success
|
0 |
0
|
1619488182.210125
NtAllocateVirtualMemory
|
process_identifier:
1384
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000c0
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00130000
|
success
|
0 |
0
|
1619488182.210125
NtAllocateVirtualMemory
|
process_identifier:
1424
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000c0
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x06c40000
|
success
|
0 |
0
|
1619488182.210125
NtAllocateVirtualMemory
|
process_identifier:
1592
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000c0
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x004b0000
|
success
|
0 |
0
|
1619488182.210125
NtAllocateVirtualMemory
|
process_identifier:
1980
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000c0
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00190000
|
success
|
0 |
0
|
1619488182.210125
NtAllocateVirtualMemory
|
process_identifier:
1240
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000c0
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00370000
|
success
|
0 |
0
|
1619488182.210125
NtAllocateVirtualMemory
|
process_identifier:
2072
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000c0
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00120000
|
success
|
0 |
0
|
1619488182.210125
NtAllocateVirtualMemory
|
process_identifier:
2224
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000c0
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00470000
|
success
|
0 |
0
|
1619488182.694125
NtAllocateVirtualMemory
|
process_identifier:
2380
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000c0
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x04850000
|
success
|
0 |
0
|
1619488182.694125
NtAllocateVirtualMemory
|
process_identifier:
2460
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000c0
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00bb0000
|
success
|
0 |
0
|
1619488182.694125
NtAllocateVirtualMemory
|
process_identifier:
2672
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000c0
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x003d0000
|
success
|
0 |
0
|
1619488182.694125
NtAllocateVirtualMemory
|
process_identifier:
2744
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000c0
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00550000
|
success
|
0 |
0
|
1619488182.694125
NtAllocateVirtualMemory
|
process_identifier:
2784
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000c0
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x007c0000
|
success
|
0 |
0
|
1619488182.694125
NtAllocateVirtualMemory
|
process_identifier:
2884
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000c0
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x03f90000
|
success
|
0 |
0
|
1619488182.694125
NtAllocateVirtualMemory
|
process_identifier:
2940
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000c0
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00140000
|
success
|
0 |
0
|
1619488182.694125
NtAllocateVirtualMemory
|
process_identifier:
2132
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000c0
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x000f0000
|
success
|
0 |
0
|
1619488182.694125
NtAllocateVirtualMemory
|
process_identifier:
2616
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000c0
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x005a0000
|
success
|
0 |
0
|
1619488182.694125
NtAllocateVirtualMemory
|
process_identifier:
472
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000c0
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00ed0000
|
success
|
0 |
0
|
1619488182.694125
NtAllocateVirtualMemory
|
process_identifier:
2424
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000c0
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00170000
|
success
|
0 |
0
|
1619488182.694125
NtAllocateVirtualMemory
|
process_identifier:
2436
region_size:
23790
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000c0
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00000000
|
failed
|
3221225738 |
0
|
1619488182.694125
NtAllocateVirtualMemory
|
process_identifier:
2852
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000c0
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x01560000
|
success
|
0 |
0
|
1619488182.710125
NtAllocateVirtualMemory
|
process_identifier:
1752
region_size:
23790
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000c0
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00000000
|
failed
|
3221225738 |
0
|
1619488182.710125
NtAllocateVirtualMemory
|
process_identifier:
2868
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000c0
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00440000
|
success
|
0 |
0
|