| Time & API |
Arguments |
Status |
Return |
Repeated |
1619464019.063125
NtAllocateVirtualMemory
|
process_identifier:
2008
region_size:
1245184
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x008d0000
|
success
|
0 |
0
|
1619464019.063125
NtAllocateVirtualMemory
|
process_identifier:
2008
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x009c0000
|
success
|
0 |
0
|
1619464023.016125
NtAllocateVirtualMemory
|
process_identifier:
2008
region_size:
1638400
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x021d0000
|
success
|
0 |
0
|
1619464023.016125
NtAllocateVirtualMemory
|
process_identifier:
2008
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02320000
|
success
|
0 |
0
|
1619464023.047125
NtProtectVirtualMemory
|
process_identifier:
2008
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73b91000
|
success
|
0 |
0
|
1619464023.094125
NtAllocateVirtualMemory
|
process_identifier:
2008
region_size:
1966080
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x02360000
|
success
|
0 |
0
|
1619464023.094125
NtAllocateVirtualMemory
|
process_identifier:
2008
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02500000
|
success
|
0 |
0
|
1619464023.094125
NtAllocateVirtualMemory
|
process_identifier:
2008
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002ba000
|
success
|
0 |
0
|
1619464023.094125
NtProtectVirtualMemory
|
process_identifier:
2008
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73b92000
|
success
|
0 |
0
|
1619464023.094125
NtAllocateVirtualMemory
|
process_identifier:
2008
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002b2000
|
success
|
0 |
0
|
1619464023.297125
NtAllocateVirtualMemory
|
process_identifier:
2008
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002c2000
|
success
|
0 |
0
|
1619464023.375125
NtAllocateVirtualMemory
|
process_identifier:
2008
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00365000
|
success
|
0 |
0
|
1619464023.375125
NtAllocateVirtualMemory
|
process_identifier:
2008
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0036b000
|
success
|
0 |
0
|
1619464023.375125
NtAllocateVirtualMemory
|
process_identifier:
2008
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00367000
|
success
|
0 |
0
|
1619464023.516125
NtAllocateVirtualMemory
|
process_identifier:
2008
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002c3000
|
success
|
0 |
0
|
1619464023.563125
NtAllocateVirtualMemory
|
process_identifier:
2008
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002cc000
|
success
|
0 |
0
|
1619464023.610125
NtAllocateVirtualMemory
|
process_identifier:
2008
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00760000
|
success
|
0 |
0
|
1619464024.297125
NtAllocateVirtualMemory
|
process_identifier:
2008
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002c4000
|
success
|
0 |
0
|
1619464024.297125
NtAllocateVirtualMemory
|
process_identifier:
2008
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002c6000
|
success
|
0 |
0
|
1619464024.438125
NtAllocateVirtualMemory
|
process_identifier:
2008
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002c7000
|
success
|
0 |
0
|
1619464024.438125
NtAllocateVirtualMemory
|
process_identifier:
2008
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002c8000
|
success
|
0 |
0
|
1619464024.453125
NtAllocateVirtualMemory
|
process_identifier:
2008
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00761000
|
success
|
0 |
0
|
1619464024.469125
NtAllocateVirtualMemory
|
process_identifier:
2008
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0035a000
|
success
|
0 |
0
|
1619464024.469125
NtAllocateVirtualMemory
|
process_identifier:
2008
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00357000
|
success
|
0 |
0
|
1619464024.516125
NtAllocateVirtualMemory
|
process_identifier:
2008
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00356000
|
success
|
0 |
0
|
1619464024.532125
NtAllocateVirtualMemory
|
process_identifier:
2008
region_size:
20480
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00762000
|
success
|
0 |
0
|
1619464024.766125
NtAllocateVirtualMemory
|
process_identifier:
2008
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002ca000
|
success
|
0 |
0
|
1619464024.891125
NtAllocateVirtualMemory
|
process_identifier:
2008
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002c9000
|
success
|
0 |
0
|
1619464025.047125
NtAllocateVirtualMemory
|
process_identifier:
2008
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00920000
|
success
|
0 |
0
|
1619464025.172125
NtAllocateVirtualMemory
|
process_identifier:
2008
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00767000
|
success
|
0 |
0
|
1619464025.203125
NtAllocateVirtualMemory
|
process_identifier:
2008
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00768000
|
success
|
0 |
0
|
1619464026.235125
NtAllocateVirtualMemory
|
process_identifier:
2008
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0076a000
|
success
|
0 |
0
|
1619464026.469125
NtAllocateVirtualMemory
|
process_identifier:
2008
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00921000
|
success
|
0 |
0
|
1619464026.547125
NtAllocateVirtualMemory
|
process_identifier:
2008
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00922000
|
success
|
0 |
0
|
1619464026.547125
NtAllocateVirtualMemory
|
process_identifier:
2008
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0076b000
|
success
|
0 |
0
|
1619464026.594125
NtAllocateVirtualMemory
|
process_identifier:
2008
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00923000
|
success
|
0 |
0
|
1619464026.610125
NtAllocateVirtualMemory
|
process_identifier:
2008
region_size:
12288
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0076c000
|
success
|
0 |
0
|
1619464026.610125
NtAllocateVirtualMemory
|
process_identifier:
2008
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0076f000
|
success
|
0 |
0
|
1619464026.625125
NtAllocateVirtualMemory
|
process_identifier:
2008
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002cd000
|
success
|
0 |
0
|
1619464067.625125
NtAllocateVirtualMemory
|
process_identifier:
2008
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00924000
|
success
|
0 |
0
|
1619464067.625125
NtAllocateVirtualMemory
|
process_identifier:
2008
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02310000
|
success
|
0 |
0
|
1619464067.625125
NtAllocateVirtualMemory
|
process_identifier:
2008
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02321000
|
success
|
0 |
0
|
1619464068.188125
NtAllocateVirtualMemory
|
process_identifier:
2008
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02311000
|
success
|
0 |
0
|
1619464068.203125
NtAllocateVirtualMemory
|
process_identifier:
2008
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02312000
|
success
|
0 |
0
|
1619464068.625125
NtAllocateVirtualMemory
|
process_identifier:
2008
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002bc000
|
success
|
0 |
0
|
1619464068.813125
NtAllocateVirtualMemory
|
process_identifier:
2008
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02313000
|
success
|
0 |
0
|
1619464068.844125
NtAllocateVirtualMemory
|
process_identifier:
2008
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00925000
|
success
|
0 |
0
|
1619464068.860125
NtAllocateVirtualMemory
|
process_identifier:
2008
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02314000
|
success
|
0 |
0
|
1619464069.047125
NtAllocateVirtualMemory
|
process_identifier:
2008
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02315000
|
success
|
0 |
0
|
1619464069.047125
NtProtectVirtualMemory
|
process_identifier:
2008
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
654848
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x05aa0400
|
failed
|
3221225550 |
0
|