| Time & API |
Arguments |
Status |
Return |
Repeated |
1619452467.589999
NtAllocateVirtualMemory
|
process_identifier:
472
region_size:
1638400
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00880000
|
success
|
0 |
0
|
1619452467.589999
NtAllocateVirtualMemory
|
process_identifier:
472
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x009d0000
|
success
|
0 |
0
|
1619452468.401999
NtProtectVirtualMemory
|
process_identifier:
472
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73f31000
|
success
|
0 |
0
|
1619452468.558999
NtAllocateVirtualMemory
|
process_identifier:
472
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0048a000
|
success
|
0 |
0
|
1619452468.558999
NtProtectVirtualMemory
|
process_identifier:
472
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73f32000
|
success
|
0 |
0
|
1619452468.558999
NtAllocateVirtualMemory
|
process_identifier:
472
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00482000
|
success
|
0 |
0
|
1619452468.917999
NtAllocateVirtualMemory
|
process_identifier:
472
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00492000
|
success
|
0 |
0
|
1619452469.011999
NtAllocateVirtualMemory
|
process_identifier:
472
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00493000
|
success
|
0 |
0
|
1619452469.026999
NtAllocateVirtualMemory
|
process_identifier:
472
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005cb000
|
success
|
0 |
0
|
1619452469.026999
NtAllocateVirtualMemory
|
process_identifier:
472
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005c7000
|
success
|
0 |
0
|
1619452469.058999
NtAllocateVirtualMemory
|
process_identifier:
472
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0049c000
|
success
|
0 |
0
|
1619452469.495999
NtAllocateVirtualMemory
|
process_identifier:
472
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00494000
|
success
|
0 |
0
|
1619452469.495999
NtAllocateVirtualMemory
|
process_identifier:
472
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00495000
|
success
|
0 |
0
|
1619452469.558999
NtAllocateVirtualMemory
|
process_identifier:
472
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00496000
|
success
|
0 |
0
|
1619452469.589999
NtAllocateVirtualMemory
|
process_identifier:
472
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006c0000
|
success
|
0 |
0
|
1619452469.683999
NtAllocateVirtualMemory
|
process_identifier:
472
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004aa000
|
success
|
0 |
0
|
1619452469.683999
NtAllocateVirtualMemory
|
process_identifier:
472
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004a7000
|
success
|
0 |
0
|
1619452469.698999
NtAllocateVirtualMemory
|
process_identifier:
472
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005ba000
|
success
|
0 |
0
|
1619452469.729999
NtAllocateVirtualMemory
|
process_identifier:
472
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0048b000
|
success
|
0 |
0
|
1619452469.870999
NtAllocateVirtualMemory
|
process_identifier:
472
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004a6000
|
success
|
0 |
0
|
1619452469.979999
NtAllocateVirtualMemory
|
process_identifier:
472
region_size:
16384
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006c1000
|
success
|
0 |
0
|
1619452470.261999
NtAllocateVirtualMemory
|
process_identifier:
472
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00830000
|
success
|
0 |
0
|
1619452470.417999
NtAllocateVirtualMemory
|
process_identifier:
472
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0049a000
|
success
|
0 |
0
|
1619452470.683999
NtAllocateVirtualMemory
|
process_identifier:
472
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005b2000
|
success
|
0 |
0
|
1619452470.745999
NtAllocateVirtualMemory
|
process_identifier:
472
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005c5000
|
success
|
0 |
0
|
1619452471.058999
NtAllocateVirtualMemory
|
process_identifier:
472
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00497000
|
success
|
0 |
0
|
1619452504.058999
NtAllocateVirtualMemory
|
process_identifier:
472
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x009d1000
|
success
|
0 |
0
|
1619452504.229999
NtAllocateVirtualMemory
|
process_identifier:
472
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005bc000
|
success
|
0 |
0
|
1619452504.229999
NtAllocateVirtualMemory
|
process_identifier:
472
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006c5000
|
success
|
0 |
0
|
1619452504.448999
NtAllocateVirtualMemory
|
process_identifier:
472
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006c6000
|
success
|
0 |
0
|
1619452504.495999
NtAllocateVirtualMemory
|
process_identifier:
472
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00498000
|
success
|
0 |
0
|
1619452504.558999
NtAllocateVirtualMemory
|
process_identifier:
472
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00831000
|
success
|
0 |
0
|
1619452504.558999
NtProtectVirtualMemory
|
process_identifier:
472
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
227840
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x04c70400
|
failed
|
3221225550 |
0
|
1619452509.229999
NtAllocateVirtualMemory
|
process_identifier:
472
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006c7000
|
success
|
0 |
0
|
1619452509.245999
NtAllocateVirtualMemory
|
process_identifier:
472
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006c8000
|
success
|
0 |
0
|
1619452509.276999
NtAllocateVirtualMemory
|
process_identifier:
472
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006c9000
|
success
|
0 |
0
|
1619452509.386999
NtAllocateVirtualMemory
|
process_identifier:
472
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006ca000
|
success
|
0 |
0
|
1619452509.386999
NtAllocateVirtualMemory
|
process_identifier:
472
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006cb000
|
success
|
0 |
0
|
1619452509.464999
NtAllocateVirtualMemory
|
process_identifier:
472
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00499000
|
success
|
0 |
0
|
1619452509.604999
NtAllocateVirtualMemory
|
process_identifier:
472
region_size:
12288
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006cc000
|
success
|
0 |
0
|
1619452509.620999
NtProtectVirtualMemory
|
process_identifier:
472
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x04c70178
|
failed
|
3221225550 |
0
|
1619452509.620999
NtProtectVirtualMemory
|
process_identifier:
472
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x04c701a0
|
failed
|
3221225550 |
0
|
1619452509.620999
NtProtectVirtualMemory
|
process_identifier:
472
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x04c701c8
|
failed
|
3221225550 |
0
|
1619452509.620999
NtProtectVirtualMemory
|
process_identifier:
472
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x04c701f0
|
failed
|
3221225550 |
0
|
1619452509.620999
NtProtectVirtualMemory
|
process_identifier:
472
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x04c70218
|
failed
|
3221225550 |
0
|
1619452509.620999
NtProtectVirtualMemory
|
process_identifier:
472
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
11
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x04ca87fe
|
failed
|
3221225550 |
0
|
1619452509.620999
NtProtectVirtualMemory
|
process_identifier:
472
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
11
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x04ca87f2
|
failed
|
3221225550 |
0
|
1619452509.620999
NtProtectVirtualMemory
|
process_identifier:
472
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
72
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x04ca7e00
|
failed
|
3221225550 |
0
|
1619452509.620999
NtProtectVirtualMemory
|
process_identifier:
472
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x04ca880c
|
failed
|
3221225550 |
0
|
1619452509.620999
NtProtectVirtualMemory
|
process_identifier:
472
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x04ca8830
|
failed
|
3221225550 |
0
|