| Time & API |
Arguments |
Status |
Return |
Repeated |
1619630383.582249
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
1769472
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x008d0000
|
success
|
0 |
0
|
1619630383.582249
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00a40000
|
success
|
0 |
0
|
1619630384.114249
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
786432
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x004a0000
|
success
|
0 |
0
|
1619630384.114249
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00520000
|
success
|
0 |
0
|
1619630384.161249
NtProtectVirtualMemory
|
process_identifier:
1916
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73b91000
|
success
|
0 |
0
|
1619630384.223249
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
1900544
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x02010000
|
success
|
0 |
0
|
1619630384.223249
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x021a0000
|
success
|
0 |
0
|
1619630384.239249
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004aa000
|
success
|
0 |
0
|
1619630384.239249
NtProtectVirtualMemory
|
process_identifier:
1916
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73b92000
|
success
|
0 |
0
|
1619630384.239249
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004a2000
|
success
|
0 |
0
|
1619630384.504249
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004b2000
|
success
|
0 |
0
|
1619630384.645249
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004d5000
|
success
|
0 |
0
|
1619630384.645249
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004db000
|
success
|
0 |
0
|
1619630384.645249
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004d7000
|
success
|
0 |
0
|
1619630384.817249
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004b3000
|
success
|
0 |
0
|
1619630384.848249
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004bc000
|
success
|
0 |
0
|
1619630385.473249
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004b4000
|
success
|
0 |
0
|
1619630385.473249
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004b6000
|
success
|
0 |
0
|
1619630385.567249
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004b7000
|
success
|
0 |
0
|
1619630385.598249
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x008f0000
|
success
|
0 |
0
|
1619630385.786249
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004ca000
|
success
|
0 |
0
|
1619630385.786249
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004c7000
|
success
|
0 |
0
|
1619630386.051249
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x008f1000
|
success
|
0 |
0
|
1619630386.364249
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004c6000
|
success
|
0 |
0
|
1619630386.457249
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004ba000
|
success
|
0 |
0
|
1619630386.489249
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x008f3000
|
success
|
0 |
0
|
1619630386.504249
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x021a1000
|
success
|
0 |
0
|
1619630386.520249
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x021a2000
|
success
|
0 |
0
|
1619630386.536249
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x021a3000
|
success
|
0 |
0
|
1619630386.536249
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004b8000
|
success
|
0 |
0
|
1619630386.801249
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x008f4000
|
success
|
0 |
0
|
1619630390.176249
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x021a5000
|
success
|
0 |
0
|
1619630391.020249
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x021a6000
|
success
|
0 |
0
|
1619630391.629249
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
16384
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x021a7000
|
success
|
0 |
0
|
1619630391.629249
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
69632
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x021ab000
|
success
|
0 |
0
|
1619630392.129249
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x008f5000
|
success
|
0 |
0
|
1619630392.207249
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00521000
|
success
|
0 |
0
|
1619630392.770249
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004b9000
|
success
|
0 |
0
|
1619630392.957249
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x022a0000
|
success
|
0 |
0
|
1619630393.161249
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x022a1000
|
success
|
0 |
0
|
1619630393.192249
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x008f6000
|
success
|
0 |
0
|
1619630393.207249
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x022a2000
|
success
|
0 |
0
|
1619630393.239249
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004bd000
|
success
|
0 |
0
|
1619630393.239249
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x022a3000
|
success
|
0 |
0
|
1619630393.254249
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
12288
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x008f7000
|
success
|
0 |
0
|
1619630393.270249
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x008fa000
|
success
|
0 |
0
|
1619630393.270249
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x021bc000
|
success
|
0 |
0
|
1619630393.270249
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x021bd000
|
success
|
0 |
0
|
1619630393.286249
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x021be000
|
success
|
0 |
0
|
1619630393.286249
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x021bf000
|
success
|
0 |
0
|