| Time & API |
Arguments |
Status |
Return |
Repeated |
1619641271.415999
NtAllocateVirtualMemory
|
process_identifier:
2340
region_size:
786432
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00700000
|
success
|
0 |
0
|
1619641271.415999
NtAllocateVirtualMemory
|
process_identifier:
2340
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00780000
|
success
|
0 |
0
|
1619641272.321999
NtProtectVirtualMemory
|
process_identifier:
2340
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73c51000
|
success
|
0 |
0
|
1619641272.384999
NtAllocateVirtualMemory
|
process_identifier:
2340
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0050a000
|
success
|
0 |
0
|
1619641272.384999
NtProtectVirtualMemory
|
process_identifier:
2340
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73c52000
|
success
|
0 |
0
|
1619641272.384999
NtAllocateVirtualMemory
|
process_identifier:
2340
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00502000
|
success
|
0 |
0
|
1619641272.665999
NtAllocateVirtualMemory
|
process_identifier:
2340
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00512000
|
success
|
0 |
0
|
1619641273.118999
NtAllocateVirtualMemory
|
process_identifier:
2340
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00513000
|
success
|
0 |
0
|
1619641273.149999
NtAllocateVirtualMemory
|
process_identifier:
2340
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0054b000
|
success
|
0 |
0
|
1619641273.149999
NtAllocateVirtualMemory
|
process_identifier:
2340
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00547000
|
success
|
0 |
0
|
1619641273.181999
NtAllocateVirtualMemory
|
process_identifier:
2340
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0051c000
|
success
|
0 |
0
|
1619641273.274999
NtAllocateVirtualMemory
|
process_identifier:
2340
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00730000
|
success
|
0 |
0
|
1619641273.602999
NtAllocateVirtualMemory
|
process_identifier:
2340
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0051a000
|
success
|
0 |
0
|
1619641273.696999
NtAllocateVirtualMemory
|
process_identifier:
2340
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0053a000
|
success
|
0 |
0
|
1619641273.790999
NtAllocateVirtualMemory
|
process_identifier:
2340
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00532000
|
success
|
0 |
0
|
1619641273.837999
NtAllocateVirtualMemory
|
process_identifier:
2340
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00514000
|
success
|
0 |
0
|
1619641273.868999
NtAllocateVirtualMemory
|
process_identifier:
2340
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00545000
|
success
|
0 |
0
|
1619641274.431999
NtAllocateVirtualMemory
|
process_identifier:
2340
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00515000
|
success
|
0 |
0
|
1619641274.493999
NtAllocateVirtualMemory
|
process_identifier:
2340
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0052a000
|
success
|
0 |
0
|
1619641274.493999
NtAllocateVirtualMemory
|
process_identifier:
2340
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00527000
|
success
|
0 |
0
|
1619641274.493999
NtAllocateVirtualMemory
|
process_identifier:
2340
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0050b000
|
success
|
0 |
0
|
1619641274.618999
NtAllocateVirtualMemory
|
process_identifier:
2340
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00731000
|
success
|
0 |
0
|
1619641275.134999
NtAllocateVirtualMemory
|
process_identifier:
2340
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04860000
|
success
|
0 |
0
|
1619641275.524999
NtAllocateVirtualMemory
|
process_identifier:
2340
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00526000
|
success
|
0 |
0
|
1619641276.993999
NtAllocateVirtualMemory
|
process_identifier:
2340
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00517000
|
success
|
0 |
0
|
1619641277.149999
NtAllocateVirtualMemory
|
process_identifier:
2340
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00733000
|
success
|
0 |
0
|
1619641277.540999
NtAllocateVirtualMemory
|
process_identifier:
2340
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00781000
|
success
|
0 |
0
|
1619641277.743999
NtAllocateVirtualMemory
|
process_identifier:
2340
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00518000
|
success
|
0 |
0
|
1619641277.759999
NtAllocateVirtualMemory
|
process_identifier:
2340
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00734000
|
success
|
0 |
0
|
1619641277.759999
NtAllocateVirtualMemory
|
process_identifier:
2340
region_size:
327680
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x04f30000
|
success
|
0 |
0
|
1619641277.759999
NtAllocateVirtualMemory
|
process_identifier:
2340
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04f40000
|
success
|
0 |
0
|
1619641277.759999
NtAllocateVirtualMemory
|
process_identifier:
2340
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04f41000
|
success
|
0 |
0
|
1619641277.806999
NtAllocateVirtualMemory
|
process_identifier:
2340
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04f42000
|
success
|
0 |
0
|
1619641277.806999
NtAllocateVirtualMemory
|
process_identifier:
2340
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04f43000
|
success
|
0 |
0
|
1619641277.806999
NtAllocateVirtualMemory
|
process_identifier:
2340
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04f44000
|
success
|
0 |
0
|
1619641277.806999
NtAllocateVirtualMemory
|
process_identifier:
2340
region_size:
12288
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04f45000
|
success
|
0 |
0
|
1619641277.806999
NtAllocateVirtualMemory
|
process_identifier:
2340
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04f48000
|
success
|
0 |
0
|
1619641277.806999
NtAllocateVirtualMemory
|
process_identifier:
2340
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04f4a000
|
success
|
0 |
0
|
1619641277.806999
NtAllocateVirtualMemory
|
process_identifier:
2340
region_size:
16384
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04f4c000
|
success
|
0 |
0
|
1619641277.806999
NtAllocateVirtualMemory
|
process_identifier:
2340
region_size:
69632
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04f50000
|
success
|
0 |
0
|
1619641277.837999
NtAllocateVirtualMemory
|
process_identifier:
2340
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00735000
|
success
|
0 |
0
|
1619641277.868999
NtAllocateVirtualMemory
|
process_identifier:
2340
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04f61000
|
success
|
0 |
0
|
1619641277.868999
NtAllocateVirtualMemory
|
process_identifier:
2340
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00736000
|
success
|
0 |
0
|
1619641278.149999
NtAllocateVirtualMemory
|
process_identifier:
2340
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04861000
|
success
|
0 |
0
|
1619641278.243999
NtAllocateVirtualMemory
|
process_identifier:
2340
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00503000
|
success
|
0 |
0
|
1619641283.415999
NtAllocateVirtualMemory
|
process_identifier:
2340
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04862000
|
success
|
0 |
0
|
1619641301.212999
NtAllocateVirtualMemory
|
process_identifier:
2340
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00519000
|
success
|
0 |
0
|
1619641301.243999
NtAllocateVirtualMemory
|
process_identifier:
2340
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00737000
|
success
|
0 |
0
|
1619641302.057249
NtAllocateVirtualMemory
|
process_identifier:
3104
region_size:
262144
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x003b0000
|
success
|
0 |
0
|
1619641302.057249
NtAllocateVirtualMemory
|
process_identifier:
3104
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003b0000
|
success
|
0 |
0
|