| Time & API |
Arguments |
Status |
Return |
Repeated |
1620788894.388771
NtAllocateVirtualMemory
|
process_identifier:
2436
region_size:
655360
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x0000000000500000
|
success
|
0 |
0
|
1620788894.388771
NtAllocateVirtualMemory
|
process_identifier:
2436
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0000000000520000
|
success
|
0 |
0
|
1620788894.810771
NtAllocateVirtualMemory
|
process_identifier:
2436
region_size:
2359296
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x0000000002800000
|
success
|
0 |
0
|
1620788894.810771
NtAllocateVirtualMemory
|
process_identifier:
2436
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00000000029c0000
|
success
|
0 |
0
|
1620788894.888771
NtProtectVirtualMemory
|
process_identifier:
2436
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1b61000
|
success
|
0 |
0
|
1620788894.888771
NtProtectVirtualMemory
|
process_identifier:
2436
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1b61000
|
success
|
0 |
0
|
1620788894.904771
NtProtectVirtualMemory
|
process_identifier:
2436
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef21e0000
|
success
|
0 |
0
|
1620788895.107771
NtAllocateVirtualMemory
|
process_identifier:
2436
region_size:
1245184
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x0000000002630000
|
success
|
0 |
0
|
1620788895.123771
NtAllocateVirtualMemory
|
process_identifier:
2436
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00000000026e0000
|
success
|
0 |
0
|
1620788895.138771
NtProtectVirtualMemory
|
process_identifier:
2436
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1b62000
|
success
|
0 |
0
|
1620788895.154771
NtProtectVirtualMemory
|
process_identifier:
2436
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1b62000
|
success
|
0 |
0
|
1620788895.154771
NtProtectVirtualMemory
|
process_identifier:
2436
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1b62000
|
success
|
0 |
0
|
1620788895.154771
NtProtectVirtualMemory
|
process_identifier:
2436
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1b62000
|
success
|
0 |
0
|
1620788895.154771
NtProtectVirtualMemory
|
process_identifier:
2436
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1b62000
|
success
|
0 |
0
|
1620788895.154771
NtProtectVirtualMemory
|
process_identifier:
2436
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1b63000
|
success
|
0 |
0
|
1620788895.154771
NtProtectVirtualMemory
|
process_identifier:
2436
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1b63000
|
success
|
0 |
0
|
1620788895.154771
NtProtectVirtualMemory
|
process_identifier:
2436
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1b63000
|
success
|
0 |
0
|
1620788895.154771
NtProtectVirtualMemory
|
process_identifier:
2436
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1b63000
|
success
|
0 |
0
|
1620788895.154771
NtProtectVirtualMemory
|
process_identifier:
2436
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1b63000
|
success
|
0 |
0
|
1620788895.154771
NtProtectVirtualMemory
|
process_identifier:
2436
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1b63000
|
success
|
0 |
0
|
1620788895.154771
NtProtectVirtualMemory
|
process_identifier:
2436
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1b63000
|
success
|
0 |
0
|
1620788895.154771
NtProtectVirtualMemory
|
process_identifier:
2436
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1b61000
|
success
|
0 |
0
|
1620788895.169771
NtProtectVirtualMemory
|
process_identifier:
2436
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1b62000
|
success
|
0 |
0
|
1620788895.169771
NtProtectVirtualMemory
|
process_identifier:
2436
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1b62000
|
success
|
0 |
0
|
1620788895.169771
NtProtectVirtualMemory
|
process_identifier:
2436
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1b62000
|
success
|
0 |
0
|
1620788895.169771
NtProtectVirtualMemory
|
process_identifier:
2436
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1b62000
|
success
|
0 |
0
|
1620788895.169771
NtProtectVirtualMemory
|
process_identifier:
2436
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1b62000
|
success
|
0 |
0
|
1620788895.748771
NtAllocateVirtualMemory
|
process_identifier:
2436
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff00032000
|
success
|
0 |
0
|
1620788895.779771
NtAllocateVirtualMemory
|
process_identifier:
2436
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff00022000
|
success
|
0 |
0
|
1620788896.076771
NtAllocateVirtualMemory
|
process_identifier:
2436
region_size:
655360
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
1056768
(MEM_RESERVE|MEM_TOP_DOWN)
base_address:
0x000007fffff00000
|
success
|
0 |
0
|
1620788896.076771
NtAllocateVirtualMemory
|
process_identifier:
2436
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007fffff00000
|
success
|
0 |
0
|
1620788896.076771
NtAllocateVirtualMemory
|
process_identifier:
2436
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007fffff00000
|
success
|
0 |
0
|
1620788896.091771
NtAllocateVirtualMemory
|
process_identifier:
2436
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007fffff10000
|
success
|
0 |
0
|
1620788896.091771
NtAllocateVirtualMemory
|
process_identifier:
2436
region_size:
65536
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
1056768
(MEM_RESERVE|MEM_TOP_DOWN)
base_address:
0x000007ffffef0000
|
success
|
0 |
0
|
1620788896.091771
NtAllocateVirtualMemory
|
process_identifier:
2436
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ffffef0000
|
success
|
0 |
0
|
1620788896.091771
NtAllocateVirtualMemory
|
process_identifier:
2436
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff0002a000
|
success
|
0 |
0
|
1620788896.123771
NtAllocateVirtualMemory
|
process_identifier:
2436
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff00033000
|
success
|
0 |
0
|
1620788896.123771
NtAllocateVirtualMemory
|
process_identifier:
2436
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff000dc000
|
success
|
0 |
0
|
1620788896.138771
NtAllocateVirtualMemory
|
process_identifier:
2436
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff00106000
|
success
|
0 |
0
|
1620788896.138771
NtAllocateVirtualMemory
|
process_identifier:
2436
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff000e0000
|
success
|
0 |
0
|
1620788896.466771
NtAllocateVirtualMemory
|
process_identifier:
2436
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff00034000
|
success
|
0 |
0
|
1620788896.498771
NtAllocateVirtualMemory
|
process_identifier:
2436
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff0002b000
|
success
|
0 |
0
|
1620788897.576771
NtAllocateVirtualMemory
|
process_identifier:
2436
region_size:
20480
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff00035000
|
success
|
0 |
0
|
1620788897.576771
NtAllocateVirtualMemory
|
process_identifier:
2436
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff001d0000
|
success
|
0 |
0
|
1620788897.654771
NtAllocateVirtualMemory
|
process_identifier:
2436
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff001d6000
|
success
|
0 |
0
|
1620788898.544771
NtAllocateVirtualMemory
|
process_identifier:
2436
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff001d7000
|
success
|
0 |
0
|
1620788898.544771
NtAllocateVirtualMemory
|
process_identifier:
2436
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff001d9000
|
success
|
0 |
0
|
1620788898.576771
NtAllocateVirtualMemory
|
process_identifier:
2436
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff001da000
|
success
|
0 |
0
|
1620788898.748771
NtAllocateVirtualMemory
|
process_identifier:
2436
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff0003c000
|
success
|
0 |
0
|
1620788899.044771
NtAllocateVirtualMemory
|
process_identifier:
2436
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff001db000
|
success
|
0 |
0
|