| Time & API |
Arguments |
Status |
Return |
Repeated |
1619513303.662793
NtAllocateVirtualMemory
|
process_identifier:
2996
region_size:
1507328
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x0000000000870000
|
success
|
0 |
0
|
1619513303.662793
NtAllocateVirtualMemory
|
process_identifier:
2996
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0000000000960000
|
success
|
0 |
0
|
1619513305.022793
NtProtectVirtualMemory
|
process_identifier:
2996
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1c11000
|
success
|
0 |
0
|
1619513305.490793
NtProtectVirtualMemory
|
process_identifier:
2996
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1e8e000
|
success
|
0 |
0
|
1619513305.490793
NtProtectVirtualMemory
|
process_identifier:
2996
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1e8e000
|
success
|
0 |
0
|
1619513305.615793
NtProtectVirtualMemory
|
process_identifier:
2996
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1e8f000
|
success
|
0 |
0
|
1619513305.615793
NtProtectVirtualMemory
|
process_identifier:
2996
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1e8f000
|
success
|
0 |
0
|
1619513305.615793
NtProtectVirtualMemory
|
process_identifier:
2996
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1e8f000
|
success
|
0 |
0
|
1619513305.615793
NtProtectVirtualMemory
|
process_identifier:
2996
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1e8f000
|
success
|
0 |
0
|
1619513305.615793
NtProtectVirtualMemory
|
process_identifier:
2996
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1e8f000
|
success
|
0 |
0
|
1619513305.615793
NtProtectVirtualMemory
|
process_identifier:
2996
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1e8f000
|
success
|
0 |
0
|
1619513305.615793
NtProtectVirtualMemory
|
process_identifier:
2996
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1e8f000
|
success
|
0 |
0
|
1619513305.615793
NtProtectVirtualMemory
|
process_identifier:
2996
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1e8f000
|
success
|
0 |
0
|
1619513305.615793
NtProtectVirtualMemory
|
process_identifier:
2996
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1e90000
|
success
|
0 |
0
|
1619513305.615793
NtProtectVirtualMemory
|
process_identifier:
2996
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1e90000
|
success
|
0 |
0
|
1619513305.631793
NtProtectVirtualMemory
|
process_identifier:
2996
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1e90000
|
success
|
0 |
0
|
1619513305.631793
NtProtectVirtualMemory
|
process_identifier:
2996
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1e90000
|
success
|
0 |
0
|
1619513305.631793
NtProtectVirtualMemory
|
process_identifier:
2996
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1e90000
|
success
|
0 |
0
|
1619513305.631793
NtProtectVirtualMemory
|
process_identifier:
2996
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1e91000
|
success
|
0 |
0
|
1619513305.631793
NtProtectVirtualMemory
|
process_identifier:
2996
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1e91000
|
success
|
0 |
0
|
1619513305.631793
NtProtectVirtualMemory
|
process_identifier:
2996
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1e91000
|
success
|
0 |
0
|
1619513305.631793
NtProtectVirtualMemory
|
process_identifier:
2996
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1e91000
|
success
|
0 |
0
|
1619513305.631793
NtProtectVirtualMemory
|
process_identifier:
2996
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1e8e000
|
success
|
0 |
0
|
1619513306.084793
NtAllocateVirtualMemory
|
process_identifier:
2996
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff00052000
|
success
|
0 |
0
|
1619513306.240793
NtAllocateVirtualMemory
|
process_identifier:
2996
region_size:
589824
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
1056768
(MEM_RESERVE|MEM_TOP_DOWN)
base_address:
0x000007fffff10000
|
success
|
0 |
0
|
1619513306.240793
NtAllocateVirtualMemory
|
process_identifier:
2996
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007fffff10000
|
success
|
0 |
0
|
1619513306.240793
NtAllocateVirtualMemory
|
process_identifier:
2996
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007fffff10000
|
success
|
0 |
0
|
1619513306.240793
NtAllocateVirtualMemory
|
process_identifier:
2996
region_size:
65536
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
1056768
(MEM_RESERVE|MEM_TOP_DOWN)
base_address:
0x000007fffff00000
|
success
|
0 |
0
|
1619513306.240793
NtAllocateVirtualMemory
|
process_identifier:
2996
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007fffff00000
|
success
|
0 |
0
|
1619513306.240793
NtAllocateVirtualMemory
|
process_identifier:
2996
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff0010a000
|
success
|
0 |
0
|
1619513306.272793
NtAllocateVirtualMemory
|
process_identifier:
2996
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff00042000
|
success
|
0 |
0
|
1619513306.475793
NtAllocateVirtualMemory
|
process_identifier:
2996
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff00053000
|
success
|
0 |
0
|
1619513306.475793
NtAllocateVirtualMemory
|
process_identifier:
2996
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff0011a000
|
success
|
0 |
0
|
1619513306.475793
NtAllocateVirtualMemory
|
process_identifier:
2996
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff00142000
|
success
|
0 |
0
|
1619513306.475793
NtAllocateVirtualMemory
|
process_identifier:
2996
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff0011d000
|
success
|
0 |
0
|
1619513306.537793
NtAllocateVirtualMemory
|
process_identifier:
2996
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff0005c000
|
success
|
0 |
0
|
1619513306.725793
NtAllocateVirtualMemory
|
process_identifier:
2996
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff00054000
|
success
|
0 |
0
|
1619513306.740793
NtAllocateVirtualMemory
|
process_identifier:
2996
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff00190000
|
success
|
0 |
0
|
1619513307.459793
NtAllocateVirtualMemory
|
process_identifier:
2996
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff00055000
|
success
|
0 |
0
|
1619513307.459793
NtAllocateVirtualMemory
|
process_identifier:
2996
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff00057000
|
success
|
0 |
0
|
1619513308.037793
NtAllocateVirtualMemory
|
process_identifier:
2996
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff00191000
|
success
|
0 |
0
|
1619513308.131793
NtAllocateVirtualMemory
|
process_identifier:
2996
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff0010b000
|
success
|
0 |
0
|
1619513308.209793
NtAllocateVirtualMemory
|
process_identifier:
2996
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff00102000
|
success
|
0 |
0
|
1619513309.865793
NtAllocateVirtualMemory
|
process_identifier:
2996
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff00058000
|
success
|
0 |
0
|
1619513310.162793
NtAllocateVirtualMemory
|
process_identifier:
2996
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff0005a000
|
success
|
0 |
0
|
1619513314.600793
NtAllocateVirtualMemory
|
process_identifier:
2996
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff0006f000
|
success
|
0 |
0
|
1619513314.600793
NtAllocateVirtualMemory
|
process_identifier:
2996
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x000007ff00043000
|
success
|
0 |
0
|
1619524199.941249
NtAllocateVirtualMemory
|
process_identifier:
2620
region_size:
655360
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x0000000000760000
|
success
|
0 |
0
|
1619524199.941249
NtAllocateVirtualMemory
|
process_identifier:
2620
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0000000000780000
|
success
|
0 |
0
|
1619524200.425249
NtProtectVirtualMemory
|
process_identifier:
2620
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
base_address:
0x000007fef1c11000
|
success
|
0 |
0
|