| Time & API |
Arguments |
Status |
Return |
Repeated |
1619626635.533249
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
1703936
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00820000
|
success
|
0 |
0
|
1619626635.533249
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00980000
|
success
|
0 |
0
|
1619626635.923249
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
917504
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00550000
|
success
|
0 |
0
|
1619626635.923249
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005f0000
|
success
|
0 |
0
|
1619626636.064249
NtProtectVirtualMemory
|
process_identifier:
2296
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73e71000
|
success
|
0 |
0
|
1619626636.298249
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
2293760
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00ce0000
|
success
|
0 |
0
|
1619626636.298249
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00ed0000
|
success
|
0 |
0
|
1619626636.314249
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003ba000
|
success
|
0 |
0
|
1619626636.314249
NtProtectVirtualMemory
|
process_identifier:
2296
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73e72000
|
success
|
0 |
0
|
1619626636.314249
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003b2000
|
success
|
0 |
0
|
1619626636.705249
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003c2000
|
success
|
0 |
0
|
1619626636.923249
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003e5000
|
success
|
0 |
0
|
1619626636.939249
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003eb000
|
success
|
0 |
0
|
1619626636.939249
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003e7000
|
success
|
0 |
0
|
1619626637.158249
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003c3000
|
success
|
0 |
0
|
1619626637.220249
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003cc000
|
success
|
0 |
0
|
1619626637.783249
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003c4000
|
success
|
0 |
0
|
1619626637.798249
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003c6000
|
success
|
0 |
0
|
1619626637.892249
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006c0000
|
success
|
0 |
0
|
1619626637.970249
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003da000
|
success
|
0 |
0
|
1619626637.970249
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003d7000
|
success
|
0 |
0
|
1619626638.080249
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003d6000
|
success
|
0 |
0
|
1619626638.111249
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006c1000
|
success
|
0 |
0
|
1619626638.314249
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006c3000
|
success
|
0 |
0
|
1619626638.455249
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003c7000
|
success
|
0 |
0
|
1619626638.455249
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003c8000
|
success
|
0 |
0
|
1619626679.470249
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006c4000
|
success
|
0 |
0
|
1619626679.486249
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005f1000
|
success
|
0 |
0
|
1619626679.595249
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006c5000
|
success
|
0 |
0
|
1619626679.767249
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003bc000
|
success
|
0 |
0
|
1619626679.783249
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006c6000
|
success
|
0 |
0
|
1619626679.830249
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006c7000
|
success
|
0 |
0
|
1619626679.892249
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003c9000
|
success
|
0 |
0
|
1619626679.923249
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006c8000
|
success
|
0 |
0
|
1619626680.064249
NtProtectVirtualMemory
|
process_identifier:
2296
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
290816
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x05570400
|
failed
|
3221225550 |
0
|
1619626687.798249
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006c9000
|
success
|
0 |
0
|
1619626687.798249
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00f30000
|
success
|
0 |
0
|
1619626687.798249
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006ca000
|
success
|
0 |
0
|
1619626687.908249
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006cb000
|
success
|
0 |
0
|
1619626687.986249
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006cc000
|
success
|
0 |
0
|
1619626688.095249
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006cd000
|
success
|
0 |
0
|
1619626688.502249
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006ce000
|
success
|
0 |
0
|
1619626688.548249
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04f00000
|
success
|
0 |
0
|
1619626688.548249
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04f01000
|
success
|
0 |
0
|
1619626688.564249
NtProtectVirtualMemory
|
process_identifier:
2296
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x05570178
|
failed
|
3221225550 |
0
|
1619626688.564249
NtProtectVirtualMemory
|
process_identifier:
2296
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x055701a0
|
failed
|
3221225550 |
0
|
1619626688.564249
NtProtectVirtualMemory
|
process_identifier:
2296
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x055701c8
|
failed
|
3221225550 |
0
|
1619626688.564249
NtProtectVirtualMemory
|
process_identifier:
2296
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x055701f0
|
failed
|
3221225550 |
0
|
1619626688.564249
NtProtectVirtualMemory
|
process_identifier:
2296
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x05570218
|
failed
|
3221225550 |
0
|
1619626688.564249
NtProtectVirtualMemory
|
process_identifier:
2296
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
11
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x055b7d8e
|
failed
|
3221225550 |
0
|