| Time & API |
Arguments |
Status |
Return |
Repeated |
1619610601.64075
NtAllocateVirtualMemory
|
process_identifier:
1208
region_size:
2228224
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00930000
|
success
|
0 |
0
|
1619610601.64075
NtAllocateVirtualMemory
|
process_identifier:
1208
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00b10000
|
success
|
0 |
0
|
1619610601.93775
NtAllocateVirtualMemory
|
process_identifier:
1208
region_size:
2097152
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00ca0000
|
success
|
0 |
0
|
1619610601.93775
NtAllocateVirtualMemory
|
process_identifier:
1208
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00e60000
|
success
|
0 |
0
|
1619610601.96875
NtProtectVirtualMemory
|
process_identifier:
1208
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73b91000
|
success
|
0 |
0
|
1619610602.28175
NtAllocateVirtualMemory
|
process_identifier:
1208
region_size:
589824
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00470000
|
success
|
0 |
0
|
1619610602.28175
NtAllocateVirtualMemory
|
process_identifier:
1208
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004c0000
|
success
|
0 |
0
|
1619610602.28175
NtAllocateVirtualMemory
|
process_identifier:
1208
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0031a000
|
success
|
0 |
0
|
1619610602.31275
NtProtectVirtualMemory
|
process_identifier:
1208
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73b92000
|
success
|
0 |
0
|
1619610602.31275
NtAllocateVirtualMemory
|
process_identifier:
1208
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00312000
|
success
|
0 |
0
|
1619610602.71875
NtAllocateVirtualMemory
|
process_identifier:
1208
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00322000
|
success
|
0 |
0
|
1619610608.09375
NtAllocateVirtualMemory
|
process_identifier:
1208
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00445000
|
success
|
0 |
0
|
1619610608.17275
NtAllocateVirtualMemory
|
process_identifier:
1208
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0044b000
|
success
|
0 |
0
|
1619610608.17275
NtAllocateVirtualMemory
|
process_identifier:
1208
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00447000
|
success
|
0 |
0
|
1619610608.84375
NtAllocateVirtualMemory
|
process_identifier:
1208
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00323000
|
success
|
0 |
0
|
1619610608.89075
NtAllocateVirtualMemory
|
process_identifier:
1208
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0032c000
|
success
|
0 |
0
|
1619610608.95375
NtAllocateVirtualMemory
|
process_identifier:
1208
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x008f0000
|
success
|
0 |
0
|
1619610609.51575
NtAllocateVirtualMemory
|
process_identifier:
1208
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00324000
|
success
|
0 |
0
|
1619610609.51575
NtAllocateVirtualMemory
|
process_identifier:
1208
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00326000
|
success
|
0 |
0
|
1619610609.65675
NtAllocateVirtualMemory
|
process_identifier:
1208
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00327000
|
success
|
0 |
0
|
1619610609.65675
NtAllocateVirtualMemory
|
process_identifier:
1208
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00328000
|
success
|
0 |
0
|
1619610609.65675
NtAllocateVirtualMemory
|
process_identifier:
1208
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00329000
|
success
|
0 |
0
|
1619610609.75075
NtAllocateVirtualMemory
|
process_identifier:
1208
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0043a000
|
success
|
0 |
0
|
1619610609.75075
NtAllocateVirtualMemory
|
process_identifier:
1208
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00437000
|
success
|
0 |
0
|
1619610609.89075
NtAllocateVirtualMemory
|
process_identifier:
1208
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00436000
|
success
|
0 |
0
|
1619610609.95375
NtAllocateVirtualMemory
|
process_identifier:
1208
region_size:
12288
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x008f1000
|
success
|
0 |
0
|
1619610610.25075
NtAllocateVirtualMemory
|
process_identifier:
1208
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0032a000
|
success
|
0 |
0
|
1619610610.46875
NtAllocateVirtualMemory
|
process_identifier:
1208
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00b90000
|
success
|
0 |
0
|
1619610610.46875
NtAllocateVirtualMemory
|
process_identifier:
1208
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00b91000
|
success
|
0 |
0
|
1619610610.51575
NtAllocateVirtualMemory
|
process_identifier:
1208
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x008f4000
|
success
|
0 |
0
|
1619610611.25075
NtAllocateVirtualMemory
|
process_identifier:
1208
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00b92000
|
success
|
0 |
0
|
1619610611.28175
NtAllocateVirtualMemory
|
process_identifier:
1208
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x008f5000
|
success
|
0 |
0
|
1619610611.29775
NtAllocateVirtualMemory
|
process_identifier:
1208
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00b93000
|
success
|
0 |
0
|
1619610611.32875
NtAllocateVirtualMemory
|
process_identifier:
1208
region_size:
12288
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x008f6000
|
success
|
0 |
0
|
1619610611.34375
NtAllocateVirtualMemory
|
process_identifier:
1208
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00b94000
|
success
|
0 |
0
|
1619610611.35975
NtAllocateVirtualMemory
|
process_identifier:
1208
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x008f9000
|
success
|
0 |
0
|
1619610652.35975
NtAllocateVirtualMemory
|
process_identifier:
1208
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0032d000
|
success
|
0 |
0
|
1619610652.37575
NtAllocateVirtualMemory
|
process_identifier:
1208
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x008fa000
|
success
|
0 |
0
|
1619610652.40675
NtAllocateVirtualMemory
|
process_identifier:
1208
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00e61000
|
success
|
0 |
0
|
1619610652.56275
NtAllocateVirtualMemory
|
process_identifier:
1208
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x008fb000
|
success
|
0 |
0
|
1619610652.71875
NtAllocateVirtualMemory
|
process_identifier:
1208
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0031c000
|
success
|
0 |
0
|
1619610652.73475
NtAllocateVirtualMemory
|
process_identifier:
1208
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x008fc000
|
success
|
0 |
0
|
1619610652.85975
NtAllocateVirtualMemory
|
process_identifier:
1208
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00b95000
|
success
|
0 |
0
|
1619610652.89075
NtAllocateVirtualMemory
|
process_identifier:
1208
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x008fd000
|
success
|
0 |
0
|
1619610653.10975
NtProtectVirtualMemory
|
process_identifier:
1208
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
296448
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x05440400
|
failed
|
3221225550 |
0
|
1619610655.76575
NtAllocateVirtualMemory
|
process_identifier:
1208
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x008ff000
|
success
|
0 |
0
|
1619610655.76575
NtAllocateVirtualMemory
|
process_identifier:
1208
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00b96000
|
success
|
0 |
0
|
1619610655.76575
NtAllocateVirtualMemory
|
process_identifier:
1208
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04ed0000
|
success
|
0 |
0
|
1619610655.76575
NtAllocateVirtualMemory
|
process_identifier:
1208
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04ed1000
|
success
|
0 |
0
|
1619610655.81275
NtAllocateVirtualMemory
|
process_identifier:
1208
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04ed2000
|
success
|
0 |
0
|