| Time & API |
Arguments |
Status |
Return |
Repeated |
1619649224.37625
NtAllocateVirtualMemory
|
process_identifier:
580
region_size:
1114112
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x004d0000
|
success
|
0 |
0
|
1619649224.37625
NtAllocateVirtualMemory
|
process_identifier:
580
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005a0000
|
success
|
0 |
0
|
1619649224.78325
NtAllocateVirtualMemory
|
process_identifier:
580
region_size:
917504
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00710000
|
success
|
0 |
0
|
1619649224.78325
NtAllocateVirtualMemory
|
process_identifier:
580
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x007b0000
|
success
|
0 |
0
|
1619649224.92325
NtProtectVirtualMemory
|
process_identifier:
580
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73e71000
|
success
|
0 |
0
|
1619649225.26725
NtAllocateVirtualMemory
|
process_identifier:
580
region_size:
851968
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x008b0000
|
success
|
0 |
0
|
1619649225.26725
NtAllocateVirtualMemory
|
process_identifier:
580
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00940000
|
success
|
0 |
0
|
1619649225.28325
NtAllocateVirtualMemory
|
process_identifier:
580
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0031a000
|
success
|
0 |
0
|
1619649225.28325
NtProtectVirtualMemory
|
process_identifier:
580
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73e72000
|
success
|
0 |
0
|
1619649225.28325
NtAllocateVirtualMemory
|
process_identifier:
580
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00312000
|
success
|
0 |
0
|
1619649225.53325
NtAllocateVirtualMemory
|
process_identifier:
580
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00322000
|
success
|
0 |
0
|
1619649225.61125
NtAllocateVirtualMemory
|
process_identifier:
580
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00345000
|
success
|
0 |
0
|
1619649225.61125
NtAllocateVirtualMemory
|
process_identifier:
580
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0034b000
|
success
|
0 |
0
|
1619649225.61125
NtAllocateVirtualMemory
|
process_identifier:
580
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00347000
|
success
|
0 |
0
|
1619649225.70425
NtAllocateVirtualMemory
|
process_identifier:
580
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00323000
|
success
|
0 |
0
|
1619649225.73625
NtAllocateVirtualMemory
|
process_identifier:
580
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0032c000
|
success
|
0 |
0
|
1619649226.06425
NtAllocateVirtualMemory
|
process_identifier:
580
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00324000
|
success
|
0 |
0
|
1619649226.07925
NtAllocateVirtualMemory
|
process_identifier:
580
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00326000
|
success
|
0 |
0
|
1619649226.18925
NtAllocateVirtualMemory
|
process_identifier:
580
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00590000
|
success
|
0 |
0
|
1619649226.28325
NtAllocateVirtualMemory
|
process_identifier:
580
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0033a000
|
success
|
0 |
0
|
1619649226.28325
NtAllocateVirtualMemory
|
process_identifier:
580
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00337000
|
success
|
0 |
0
|
1619649226.48625
NtAllocateVirtualMemory
|
process_identifier:
580
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00591000
|
success
|
0 |
0
|
1619649226.72025
NtAllocateVirtualMemory
|
process_identifier:
580
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00327000
|
success
|
0 |
0
|
1619649226.72025
NtAllocateVirtualMemory
|
process_identifier:
580
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00328000
|
success
|
0 |
0
|
1619649226.86125
NtAllocateVirtualMemory
|
process_identifier:
580
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00336000
|
success
|
0 |
0
|
1619649227.01725
NtAllocateVirtualMemory
|
process_identifier:
580
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00329000
|
success
|
0 |
0
|
1619649227.01725
NtAllocateVirtualMemory
|
process_identifier:
580
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00592000
|
success
|
0 |
0
|
1619649227.04825
NtAllocateVirtualMemory
|
process_identifier:
580
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00990000
|
success
|
0 |
0
|
1619649227.04825
NtAllocateVirtualMemory
|
process_identifier:
580
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00991000
|
success
|
0 |
0
|
1619649227.06425
NtAllocateVirtualMemory
|
process_identifier:
580
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00941000
|
success
|
0 |
0
|
1619649227.06425
NtAllocateVirtualMemory
|
process_identifier:
580
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00942000
|
success
|
0 |
0
|
1619649227.07925
NtAllocateVirtualMemory
|
process_identifier:
580
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00943000
|
success
|
0 |
0
|
1619649227.07925
NtAllocateVirtualMemory
|
process_identifier:
580
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00944000
|
success
|
0 |
0
|
1619649227.07925
NtAllocateVirtualMemory
|
process_identifier:
580
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00945000
|
success
|
0 |
0
|
1619649227.09525
NtAllocateVirtualMemory
|
process_identifier:
580
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00992000
|
success
|
0 |
0
|
1619649227.12625
NtAllocateVirtualMemory
|
process_identifier:
580
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00593000
|
success
|
0 |
0
|
1619649227.12625
NtAllocateVirtualMemory
|
process_identifier:
580
region_size:
16384
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00946000
|
success
|
0 |
0
|
1619649227.12625
NtAllocateVirtualMemory
|
process_identifier:
580
region_size:
69632
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0094a000
|
success
|
0 |
0
|
1619649227.12625
NtAllocateVirtualMemory
|
process_identifier:
580
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0095b000
|
success
|
0 |
0
|
1619649227.14225
NtAllocateVirtualMemory
|
process_identifier:
580
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0095c000
|
success
|
0 |
0
|
1619649227.15825
NtAllocateVirtualMemory
|
process_identifier:
580
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00594000
|
success
|
0 |
0
|
1619649227.15825
NtAllocateVirtualMemory
|
process_identifier:
580
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0095d000
|
success
|
0 |
0
|
1619649227.28325
NtAllocateVirtualMemory
|
process_identifier:
580
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00595000
|
success
|
0 |
0
|
1619649227.36125
NtAllocateVirtualMemory
|
process_identifier:
580
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00596000
|
success
|
0 |
0
|
1619649227.36125
NtAllocateVirtualMemory
|
process_identifier:
580
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00993000
|
success
|
0 |
0
|
1619649227.37625
NtAllocateVirtualMemory
|
process_identifier:
580
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x007b1000
|
success
|
0 |
0
|
1619649227.37625
NtAllocateVirtualMemory
|
process_identifier:
580
region_size:
16384
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x007b2000
|
success
|
0 |
0
|
1619649227.37625
NtAllocateVirtualMemory
|
process_identifier:
580
region_size:
69632
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x007b6000
|
success
|
0 |
0
|
1619649227.40825
NtAllocateVirtualMemory
|
process_identifier:
580
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00994000
|
success
|
0 |
0
|
1619649227.40825
NtAllocateVirtualMemory
|
process_identifier:
580
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0032d000
|
success
|
0 |
0
|