| Time & API |
Arguments |
Status |
Return |
Repeated |
1619513307.219879
NtAllocateVirtualMemory
|
process_identifier:
732
region_size:
225280
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x004a0000
|
success
|
0 |
0
|
1619513307.235879
NtAllocateVirtualMemory
|
process_identifier:
732
region_size:
225280
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x004e0000
|
success
|
0 |
0
|
1619513307.251879
NtProtectVirtualMemory
|
process_identifier:
732
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
438272
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00400000
|
success
|
0 |
0
|
1619513307.344879
NtAllocateVirtualMemory
|
process_identifier:
732
region_size:
159744
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00540000
|
success
|
0 |
0
|
1619539782.530271
NtAllocateVirtualMemory
|
process_identifier:
1424
region_size:
65536
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0000000004840000
|
success
|
0 |
0
|
1619540143.402125
NtAllocateVirtualMemory
|
process_identifier:
1164
region_size:
225280
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x004a0000
|
success
|
0 |
0
|
1619540143.402125
NtAllocateVirtualMemory
|
process_identifier:
1164
region_size:
225280
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x004e0000
|
success
|
0 |
0
|
1619540143.433125
NtProtectVirtualMemory
|
process_identifier:
1164
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
438272
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00400000
|
success
|
0 |
0
|
1619540143.465125
NtAllocateVirtualMemory
|
process_identifier:
1164
region_size:
159744
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00550000
|
success
|
0 |
0
|
1619540143.543125
NtAllocateVirtualMemory
|
process_identifier:
1164
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02590000
|
success
|
0 |
0
|
1619540143.543125
NtAllocateVirtualMemory
|
process_identifier:
1164
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x025a0000
|
success
|
0 |
0
|
1619540143.543125
NtAllocateVirtualMemory
|
process_identifier:
1164
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02b00000
|
success
|
0 |
0
|
1619540143.543125
NtAllocateVirtualMemory
|
process_identifier:
1164
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02560000
|
success
|
0 |
0
|
1619540143.543125
NtAllocateVirtualMemory
|
process_identifier:
1164
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02570000
|
success
|
0 |
0
|
1619540143.558125
NtAllocateVirtualMemory
|
process_identifier:
1164
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02580000
|
success
|
0 |
0
|
1619540143.558125
NtAllocateVirtualMemory
|
process_identifier:
1164
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02be0000
|
success
|
0 |
0
|
1619540143.574125
NtAllocateVirtualMemory
|
process_identifier:
1164
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02bf0000
|
success
|
0 |
0
|
1619540143.574125
NtAllocateVirtualMemory
|
process_identifier:
1164
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02c00000
|
success
|
0 |
0
|
1619540143.590125
NtAllocateVirtualMemory
|
process_identifier:
1164
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02c10000
|
success
|
0 |
0
|
1619540143.590125
NtAllocateVirtualMemory
|
process_identifier:
1164
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02c20000
|
success
|
0 |
0
|
1619540143.590125
NtAllocateVirtualMemory
|
process_identifier:
1164
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02c30000
|
success
|
0 |
0
|
1619540143.590125
NtAllocateVirtualMemory
|
process_identifier:
1164
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02c40000
|
success
|
0 |
0
|
1619540143.590125
NtAllocateVirtualMemory
|
process_identifier:
1164
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02c50000
|
success
|
0 |
0
|
1619540143.605125
NtAllocateVirtualMemory
|
process_identifier:
1164
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02c60000
|
success
|
0 |
0
|
1619540143.605125
NtAllocateVirtualMemory
|
process_identifier:
1164
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02c70000
|
success
|
0 |
0
|
1619540143.621125
NtAllocateVirtualMemory
|
process_identifier:
1164
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02c80000
|
success
|
0 |
0
|
1619540143.621125
NtAllocateVirtualMemory
|
process_identifier:
1164
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02c90000
|
success
|
0 |
0
|
1619540143.636125
NtAllocateVirtualMemory
|
process_identifier:
1164
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02ca0000
|
success
|
0 |
0
|
1619540143.636125
NtAllocateVirtualMemory
|
process_identifier:
1164
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02cb0000
|
success
|
0 |
0
|
1619540143.636125
NtAllocateVirtualMemory
|
process_identifier:
1164
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02cc0000
|
success
|
0 |
0
|
1619540143.652125
NtAllocateVirtualMemory
|
process_identifier:
1164
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02cd0000
|
success
|
0 |
0
|
1619540143.652125
NtAllocateVirtualMemory
|
process_identifier:
1164
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02bb0000
|
success
|
0 |
0
|
1619540143.652125
NtAllocateVirtualMemory
|
process_identifier:
1164
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02bc0000
|
success
|
0 |
0
|
1619540143.652125
NtAllocateVirtualMemory
|
process_identifier:
1164
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02bd0000
|
success
|
0 |
0
|
1619540143.668125
NtAllocateVirtualMemory
|
process_identifier:
1164
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02ce0000
|
success
|
0 |
0
|
1619540143.668125
NtAllocateVirtualMemory
|
process_identifier:
1164
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02cf0000
|
success
|
0 |
0
|
1619540143.668125
NtAllocateVirtualMemory
|
process_identifier:
1164
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02d00000
|
success
|
0 |
0
|
1619540143.668125
NtAllocateVirtualMemory
|
process_identifier:
1164
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02d10000
|
success
|
0 |
0
|
1619540143.668125
NtAllocateVirtualMemory
|
process_identifier:
1164
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02d20000
|
success
|
0 |
0
|
1619540143.668125
NtAllocateVirtualMemory
|
process_identifier:
1164
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02d30000
|
success
|
0 |
0
|
1619540143.668125
NtAllocateVirtualMemory
|
process_identifier:
1164
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02d40000
|
success
|
0 |
0
|
1619540143.683125
NtAllocateVirtualMemory
|
process_identifier:
1164
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02d50000
|
success
|
0 |
0
|
1619540143.683125
NtAllocateVirtualMemory
|
process_identifier:
1164
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02d60000
|
success
|
0 |
0
|
1619540143.683125
NtAllocateVirtualMemory
|
process_identifier:
1164
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02d70000
|
success
|
0 |
0
|
1619540143.683125
NtAllocateVirtualMemory
|
process_identifier:
1164
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02d80000
|
success
|
0 |
0
|
1619540143.699125
NtAllocateVirtualMemory
|
process_identifier:
1164
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02d90000
|
success
|
0 |
0
|
1619540143.699125
NtAllocateVirtualMemory
|
process_identifier:
1164
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02da0000
|
success
|
0 |
0
|
1619540143.699125
NtAllocateVirtualMemory
|
process_identifier:
1164
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02db0000
|
success
|
0 |
0
|
1619540143.699125
NtAllocateVirtualMemory
|
process_identifier:
1164
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02b10000
|
success
|
0 |
0
|
1619540143.715125
NtAllocateVirtualMemory
|
process_identifier:
1164
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02b20000
|
success
|
0 |
0
|