| Time & API |
Arguments |
Status |
Return |
Repeated |
1619649226.795689
NtAllocateVirtualMemory
|
process_identifier:
2560
region_size:
450560
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x0000023c
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x10410000
|
success
|
0 |
0
|
1619649226.810689
NtAllocateVirtualMemory
|
process_identifier:
2560
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x0000023c
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x001f0000
|
success
|
0 |
0
|
1619649226.810689
NtAllocateVirtualMemory
|
process_identifier:
2560
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x0000023c
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00200000
|
success
|
0 |
0
|
1619649226.810689
NtAllocateVirtualMemory
|
process_identifier:
2560
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x0000023c
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00210000
|
success
|
0 |
0
|
1619649226.810689
NtAllocateVirtualMemory
|
process_identifier:
2560
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x0000023c
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00360000
|
success
|
0 |
0
|
1619649226.810689
NtAllocateVirtualMemory
|
process_identifier:
2560
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x0000023c
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00370000
|
success
|
0 |
0
|
1619649226.810689
NtAllocateVirtualMemory
|
process_identifier:
2560
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x0000023c
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00380000
|
success
|
0 |
0
|
1619649226.810689
NtAllocateVirtualMemory
|
process_identifier:
2560
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x0000023c
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00390000
|
success
|
0 |
0
|
1619649226.842689
NtAllocateVirtualMemory
|
process_identifier:
2560
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x0000023c
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x003a0000
|
success
|
0 |
0
|
1619649226.842689
NtAllocateVirtualMemory
|
process_identifier:
2560
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x0000023c
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x003b0000
|
success
|
0 |
0
|
1619649226.842689
NtAllocateVirtualMemory
|
process_identifier:
2560
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x0000023c
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x003c0000
|
success
|
0 |
0
|
1619649226.842689
NtAllocateVirtualMemory
|
process_identifier:
2560
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x0000023c
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x003d0000
|
success
|
0 |
0
|
1619649226.842689
NtAllocateVirtualMemory
|
process_identifier:
2560
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x0000023c
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00540000
|
success
|
0 |
0
|
1619649226.842689
NtAllocateVirtualMemory
|
process_identifier:
2560
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x0000023c
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00550000
|
success
|
0 |
0
|
1619649226.842689
NtAllocateVirtualMemory
|
process_identifier:
2560
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x0000023c
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00560000
|
success
|
0 |
0
|
1619649226.842689
NtAllocateVirtualMemory
|
process_identifier:
2560
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x0000023c
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00570000
|
success
|
0 |
0
|
1619649226.842689
NtAllocateVirtualMemory
|
process_identifier:
2560
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x0000023c
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00580000
|
success
|
0 |
0
|
1619649226.842689
NtAllocateVirtualMemory
|
process_identifier:
2560
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x0000023c
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00590000
|
success
|
0 |
0
|
1619649226.842689
NtAllocateVirtualMemory
|
process_identifier:
2560
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x0000023c
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x005a0000
|
success
|
0 |
0
|
1619649226.842689
NtAllocateVirtualMemory
|
process_identifier:
2560
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x0000023c
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x005b0000
|
success
|
0 |
0
|
1619649226.842689
NtAllocateVirtualMemory
|
process_identifier:
2560
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x0000023c
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x005c0000
|
success
|
0 |
0
|
1619649226.842689
NtAllocateVirtualMemory
|
process_identifier:
2560
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x0000023c
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x005d0000
|
success
|
0 |
0
|
1619649226.842689
NtAllocateVirtualMemory
|
process_identifier:
2560
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x0000023c
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x005e0000
|
success
|
0 |
0
|
1619649226.842689
NtAllocateVirtualMemory
|
process_identifier:
2560
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x0000023c
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x005f0000
|
success
|
0 |
0
|
1619649226.857689
NtAllocateVirtualMemory
|
process_identifier:
2560
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x0000023c
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00600000
|
success
|
0 |
0
|
1619649226.857689
NtAllocateVirtualMemory
|
process_identifier:
2560
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x0000023c
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00610000
|
success
|
0 |
0
|
1619649226.857689
NtAllocateVirtualMemory
|
process_identifier:
2560
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x0000023c
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00620000
|
success
|
0 |
0
|
1619649226.857689
NtAllocateVirtualMemory
|
process_identifier:
2560
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x0000023c
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00630000
|
success
|
0 |
0
|
1619649226.857689
NtAllocateVirtualMemory
|
process_identifier:
2560
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x0000023c
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x006c0000
|
success
|
0 |
0
|
1619649226.857689
NtAllocateVirtualMemory
|
process_identifier:
2560
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x0000023c
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x006d0000
|
success
|
0 |
0
|
1619649226.857689
NtAllocateVirtualMemory
|
process_identifier:
2560
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x0000023c
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x006e0000
|
success
|
0 |
0
|
1619649226.857689
NtAllocateVirtualMemory
|
process_identifier:
2560
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x0000023c
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x006f0000
|
success
|
0 |
0
|
1619649226.857689
NtAllocateVirtualMemory
|
process_identifier:
2560
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x0000023c
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00780000
|
success
|
0 |
0
|
1619649226.857689
NtAllocateVirtualMemory
|
process_identifier:
2560
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x0000023c
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00790000
|
success
|
0 |
0
|
1619649226.857689
NtAllocateVirtualMemory
|
process_identifier:
2560
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x0000023c
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x007a0000
|
success
|
0 |
0
|
1619649226.857689
NtAllocateVirtualMemory
|
process_identifier:
2560
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x0000023c
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x007b0000
|
success
|
0 |
0
|
1619649226.857689
NtAllocateVirtualMemory
|
process_identifier:
2560
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x0000023c
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x007c0000
|
success
|
0 |
0
|
1619649226.857689
NtAllocateVirtualMemory
|
process_identifier:
2560
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x0000023c
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x007d0000
|
success
|
0 |
0
|
1619649226.857689
NtAllocateVirtualMemory
|
process_identifier:
2560
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x0000023c
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x007e0000
|
success
|
0 |
0
|
1619649226.857689
NtAllocateVirtualMemory
|
process_identifier:
2560
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x0000023c
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x007f0000
|
success
|
0 |
0
|
1619649226.857689
NtAllocateVirtualMemory
|
process_identifier:
2560
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x0000023c
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00800000
|
success
|
0 |
0
|
1619649226.857689
NtAllocateVirtualMemory
|
process_identifier:
2560
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x0000023c
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00810000
|
success
|
0 |
0
|
1619649226.857689
NtAllocateVirtualMemory
|
process_identifier:
2560
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x0000023c
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00820000
|
success
|
0 |
0
|
1619649226.857689
NtAllocateVirtualMemory
|
process_identifier:
2560
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x0000023c
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00830000
|
success
|
0 |
0
|
1619649226.873689
NtAllocateVirtualMemory
|
process_identifier:
2560
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x0000023c
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00940000
|
success
|
0 |
0
|
1619649226.873689
NtAllocateVirtualMemory
|
process_identifier:
2560
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x0000023c
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00950000
|
success
|
0 |
0
|
1619649226.873689
NtAllocateVirtualMemory
|
process_identifier:
2560
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x0000023c
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00960000
|
success
|
0 |
0
|
1619649226.873689
NtAllocateVirtualMemory
|
process_identifier:
2560
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x0000023c
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00970000
|
success
|
0 |
0
|
1619649226.873689
NtAllocateVirtualMemory
|
process_identifier:
2560
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x0000023c
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00980000
|
success
|
0 |
0
|
1619649226.873689
NtAllocateVirtualMemory
|
process_identifier:
2560
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x0000023c
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00990000
|
success
|
0 |
0
|