| Time & API |
Arguments |
Status |
Return |
Repeated |
1619641095.999626
NtAllocateVirtualMemory
|
process_identifier:
2144
region_size:
1638400
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x007e0000
|
success
|
0 |
0
|
1619641095.999626
NtAllocateVirtualMemory
|
process_identifier:
2144
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00930000
|
success
|
0 |
0
|
1619641096.015626
NtAllocateVirtualMemory
|
process_identifier:
2144
region_size:
2097152
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00c90000
|
success
|
0 |
0
|
1619641096.015626
NtAllocateVirtualMemory
|
process_identifier:
2144
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00e50000
|
success
|
0 |
0
|
1619641096.015626
NtProtectVirtualMemory
|
process_identifier:
2144
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73b91000
|
success
|
0 |
0
|
1619641096.046626
NtAllocateVirtualMemory
|
process_identifier:
2144
region_size:
655360
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00650000
|
success
|
0 |
0
|
1619641096.046626
NtAllocateVirtualMemory
|
process_identifier:
2144
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006b0000
|
success
|
0 |
0
|
1619641096.061626
NtAllocateVirtualMemory
|
process_identifier:
2144
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003fa000
|
success
|
0 |
0
|
1619641096.061626
NtProtectVirtualMemory
|
process_identifier:
2144
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73b92000
|
success
|
0 |
0
|
1619641096.061626
NtAllocateVirtualMemory
|
process_identifier:
2144
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003f2000
|
success
|
0 |
0
|
1619641096.061626
NtAllocateVirtualMemory
|
process_identifier:
2144
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00482000
|
success
|
0 |
0
|
1619641096.077626
NtAllocateVirtualMemory
|
process_identifier:
2144
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004a5000
|
success
|
0 |
0
|
1619641096.077626
NtAllocateVirtualMemory
|
process_identifier:
2144
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004ab000
|
success
|
0 |
0
|
1619641096.077626
NtAllocateVirtualMemory
|
process_identifier:
2144
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004a7000
|
success
|
0 |
0
|
1619641096.077626
NtAllocateVirtualMemory
|
process_identifier:
2144
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00483000
|
success
|
0 |
0
|
1619641096.077626
NtAllocateVirtualMemory
|
process_identifier:
2144
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00484000
|
success
|
0 |
0
|
1619641096.077626
NtAllocateVirtualMemory
|
process_identifier:
2144
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00485000
|
success
|
0 |
0
|
1619641096.077626
NtAllocateVirtualMemory
|
process_identifier:
2144
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0048c000
|
success
|
0 |
0
|
1619641096.108626
NtAllocateVirtualMemory
|
process_identifier:
2144
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00486000
|
success
|
0 |
0
|
1619641096.108626
NtAllocateVirtualMemory
|
process_identifier:
2144
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00487000
|
success
|
0 |
0
|
1619641096.108626
NtAllocateVirtualMemory
|
process_identifier:
2144
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00488000
|
success
|
0 |
0
|
1619641096.108626
NtAllocateVirtualMemory
|
process_identifier:
2144
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00680000
|
success
|
0 |
0
|
1619641096.108626
NtAllocateVirtualMemory
|
process_identifier:
2144
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00496000
|
success
|
0 |
0
|