| Time & API |
Arguments |
Status |
Return |
Repeated |
1619432269.486086
NtAllocateVirtualMemory
|
process_identifier:
192
region_size:
1376256
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x02fc0000
|
success
|
0 |
0
|
1619432269.486086
NtAllocateVirtualMemory
|
process_identifier:
192
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x030d0000
|
success
|
0 |
0
|
1619432269.829086
NtProtectVirtualMemory
|
process_identifier:
192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73f31000
|
success
|
0 |
0
|
1619432269.923086
NtAllocateVirtualMemory
|
process_identifier:
192
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0275a000
|
success
|
0 |
0
|
1619432269.923086
NtProtectVirtualMemory
|
process_identifier:
192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73f32000
|
success
|
0 |
0
|
1619432269.923086
NtAllocateVirtualMemory
|
process_identifier:
192
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02752000
|
success
|
0 |
0
|
1619432270.111086
NtAllocateVirtualMemory
|
process_identifier:
192
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02762000
|
success
|
0 |
0
|
1619432270.189086
NtAllocateVirtualMemory
|
process_identifier:
192
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x030d1000
|
success
|
0 |
0
|
1619432270.220086
NtAllocateVirtualMemory
|
process_identifier:
192
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x030d2000
|
success
|
0 |
0
|
1619432270.329086
NtAllocateVirtualMemory
|
process_identifier:
192
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0278a000
|
success
|
0 |
0
|
1619432270.626086
NtAllocateVirtualMemory
|
process_identifier:
192
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02763000
|
success
|
0 |
0
|
1619432270.829086
NtAllocateVirtualMemory
|
process_identifier:
192
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02764000
|
success
|
0 |
0
|
1619432270.861086
NtAllocateVirtualMemory
|
process_identifier:
192
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0279b000
|
success
|
0 |
0
|
1619432270.861086
NtAllocateVirtualMemory
|
process_identifier:
192
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02797000
|
success
|
0 |
0
|
1619432271.001086
NtAllocateVirtualMemory
|
process_identifier:
192
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0275b000
|
success
|
0 |
0
|
1619432271.111086
NtAllocateVirtualMemory
|
process_identifier:
192
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02782000
|
success
|
0 |
0
|
1619432271.126086
NtAllocateVirtualMemory
|
process_identifier:
192
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02795000
|
success
|
0 |
0
|
1619432271.533086
NtAllocateVirtualMemory
|
process_identifier:
192
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02765000
|
success
|
0 |
0
|
1619432272.033086
NtAllocateVirtualMemory
|
process_identifier:
192
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0278c000
|
success
|
0 |
0
|
1619432272.173086
NtAllocateVirtualMemory
|
process_identifier:
192
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02783000
|
success
|
0 |
0
|
1619432272.204086
NtAllocateVirtualMemory
|
process_identifier:
192
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x030c0000
|
success
|
0 |
0
|
1619432272.470086
NtAllocateVirtualMemory
|
process_identifier:
192
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02766000
|
success
|
0 |
0
|
1619432272.564086
NtAllocateVirtualMemory
|
process_identifier:
192
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0279c000
|
success
|
0 |
0
|
1619432272.892086
NtAllocateVirtualMemory
|
process_identifier:
192
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02784000
|
success
|
0 |
0
|
1619432272.892086
NtAllocateVirtualMemory
|
process_identifier:
192
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02785000
|
success
|
0 |
0
|
1619432272.892086
NtAllocateVirtualMemory
|
process_identifier:
192
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02786000
|
success
|
0 |
0
|
1619432272.908086
NtAllocateVirtualMemory
|
process_identifier:
192
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02787000
|
success
|
0 |
0
|
1619432272.908086
NtAllocateVirtualMemory
|
process_identifier:
192
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02788000
|
success
|
0 |
0
|
1619432272.908086
NtAllocateVirtualMemory
|
process_identifier:
192
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02789000
|
success
|
0 |
0
|
1619432272.908086
NtAllocateVirtualMemory
|
process_identifier:
192
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x031a0000
|
success
|
0 |
0
|
1619432272.908086
NtAllocateVirtualMemory
|
process_identifier:
192
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x031a1000
|
success
|
0 |
0
|
1619432272.908086
NtAllocateVirtualMemory
|
process_identifier:
192
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x031a2000
|
success
|
0 |
0
|
1619432272.908086
NtAllocateVirtualMemory
|
process_identifier:
192
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x031a3000
|
success
|
0 |
0
|
1619432272.908086
NtAllocateVirtualMemory
|
process_identifier:
192
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x031a4000
|
success
|
0 |
0
|
1619432272.908086
NtAllocateVirtualMemory
|
process_identifier:
192
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x031a5000
|
success
|
0 |
0
|
1619432272.908086
NtAllocateVirtualMemory
|
process_identifier:
192
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x031a6000
|
success
|
0 |
0
|
1619432272.908086
NtAllocateVirtualMemory
|
process_identifier:
192
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x031a7000
|
success
|
0 |
0
|
1619432272.908086
NtAllocateVirtualMemory
|
process_identifier:
192
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x031a8000
|
success
|
0 |
0
|
1619432272.908086
NtAllocateVirtualMemory
|
process_identifier:
192
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x031a9000
|
success
|
0 |
0
|
1619432272.908086
NtAllocateVirtualMemory
|
process_identifier:
192
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x031aa000
|
success
|
0 |
0
|
1619432272.908086
NtAllocateVirtualMemory
|
process_identifier:
192
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x031ab000
|
success
|
0 |
0
|
1619432272.908086
NtAllocateVirtualMemory
|
process_identifier:
192
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x031ac000
|
success
|
0 |
0
|
1619432272.908086
NtAllocateVirtualMemory
|
process_identifier:
192
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x031ad000
|
success
|
0 |
0
|
1619432272.908086
NtAllocateVirtualMemory
|
process_identifier:
192
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x031ae000
|
success
|
0 |
0
|
1619432272.908086
NtAllocateVirtualMemory
|
process_identifier:
192
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x031af000
|
success
|
0 |
0
|
1619432272.908086
NtAllocateVirtualMemory
|
process_identifier:
192
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x031b0000
|
success
|
0 |
0
|
1619432272.908086
NtAllocateVirtualMemory
|
process_identifier:
192
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x031b1000
|
success
|
0 |
0
|
1619432272.923086
NtAllocateVirtualMemory
|
process_identifier:
192
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x031b2000
|
success
|
0 |
0
|
1619432272.970086
NtAllocateVirtualMemory
|
process_identifier:
192
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x031b3000
|
success
|
0 |
0
|
1619432272.970086
NtAllocateVirtualMemory
|
process_identifier:
192
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x031b4000
|
success
|
0 |
0
|