| Time & API |
Arguments |
Status |
Return |
Repeated |
1619649224.667662
NtAllocateVirtualMemory
|
process_identifier:
2732
region_size:
1376256
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00790000
|
success
|
0 |
0
|
1619649224.667662
NtAllocateVirtualMemory
|
process_identifier:
2732
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x008a0000
|
success
|
0 |
0
|
1619649225.432662
NtProtectVirtualMemory
|
process_identifier:
2732
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73f31000
|
success
|
0 |
0
|
1619649225.745662
NtAllocateVirtualMemory
|
process_identifier:
2732
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0051a000
|
success
|
0 |
0
|
1619649225.745662
NtProtectVirtualMemory
|
process_identifier:
2732
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73f32000
|
success
|
0 |
0
|
1619649225.745662
NtAllocateVirtualMemory
|
process_identifier:
2732
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00512000
|
success
|
0 |
0
|
1619649226.089662
NtAllocateVirtualMemory
|
process_identifier:
2732
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00522000
|
success
|
0 |
0
|
1619649226.323662
NtAllocateVirtualMemory
|
process_identifier:
2732
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00523000
|
success
|
0 |
0
|
1619649226.339662
NtAllocateVirtualMemory
|
process_identifier:
2732
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0059b000
|
success
|
0 |
0
|
1619649226.339662
NtAllocateVirtualMemory
|
process_identifier:
2732
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00597000
|
success
|
0 |
0
|
1619649226.385662
NtAllocateVirtualMemory
|
process_identifier:
2732
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0052c000
|
success
|
0 |
0
|
1619649227.104662
NtAllocateVirtualMemory
|
process_identifier:
2732
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00524000
|
success
|
0 |
0
|
1619649227.104662
NtAllocateVirtualMemory
|
process_identifier:
2732
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00525000
|
success
|
0 |
0
|
1619649227.151662
NtAllocateVirtualMemory
|
process_identifier:
2732
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00526000
|
success
|
0 |
0
|
1619649227.151662
NtAllocateVirtualMemory
|
process_identifier:
2732
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00740000
|
success
|
0 |
0
|
1619649227.229662
NtAllocateVirtualMemory
|
process_identifier:
2732
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0053a000
|
success
|
0 |
0
|
1619649227.229662
NtAllocateVirtualMemory
|
process_identifier:
2732
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00537000
|
success
|
0 |
0
|
1619649227.229662
NtAllocateVirtualMemory
|
process_identifier:
2732
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0058a000
|
success
|
0 |
0
|
1619649227.260662
NtAllocateVirtualMemory
|
process_identifier:
2732
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0051b000
|
success
|
0 |
0
|
1619649227.292662
NtAllocateVirtualMemory
|
process_identifier:
2732
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00536000
|
success
|
0 |
0
|
1619649227.776662
NtAllocateVirtualMemory
|
process_identifier:
2732
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00741000
|
success
|
0 |
0
|
1619649227.792662
NtAllocateVirtualMemory
|
process_identifier:
2732
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00527000
|
success
|
0 |
0
|
1619649227.823662
NtAllocateVirtualMemory
|
process_identifier:
2732
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00800000
|
success
|
0 |
0
|
1619649227.823662
NtAllocateVirtualMemory
|
process_identifier:
2732
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x008a1000
|
success
|
0 |
0
|
1619649227.979662
NtAllocateVirtualMemory
|
process_identifier:
2732
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00528000
|
success
|
0 |
0
|
1619649227.979662
NtAllocateVirtualMemory
|
process_identifier:
2732
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00742000
|
success
|
0 |
0
|
1619649227.979662
NtAllocateVirtualMemory
|
process_identifier:
2732
region_size:
1638400
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x04ca0000
|
success
|
0 |
0
|
1619649227.979662
NtAllocateVirtualMemory
|
process_identifier:
2732
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04df0000
|
success
|
0 |
0
|
1619649227.979662
NtAllocateVirtualMemory
|
process_identifier:
2732
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04df1000
|
success
|
0 |
0
|
1619649228.010662
NtAllocateVirtualMemory
|
process_identifier:
2732
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04df2000
|
success
|
0 |
0
|
1619649228.026662
NtAllocateVirtualMemory
|
process_identifier:
2732
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04df3000
|
success
|
0 |
0
|
1619649228.042662
NtAllocateVirtualMemory
|
process_identifier:
2732
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04df4000
|
success
|
0 |
0
|
1619649228.042662
NtAllocateVirtualMemory
|
process_identifier:
2732
region_size:
12288
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04df5000
|
success
|
0 |
0
|
1619649228.042662
NtAllocateVirtualMemory
|
process_identifier:
2732
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00529000
|
success
|
0 |
0
|
1619649228.057662
NtAllocateVirtualMemory
|
process_identifier:
2732
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00743000
|
success
|
0 |
0
|
1619649228.073662
NtAllocateVirtualMemory
|
process_identifier:
2732
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04df8000
|
success
|
0 |
0
|
1619649228.073662
NtAllocateVirtualMemory
|
process_identifier:
2732
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04df9000
|
success
|
0 |
0
|
1619649228.073662
NtAllocateVirtualMemory
|
process_identifier:
2732
region_size:
16384
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04dfa000
|
success
|
0 |
0
|
1619649228.073662
NtAllocateVirtualMemory
|
process_identifier:
2732
region_size:
69632
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04dfe000
|
success
|
0 |
0
|
1619649228.073662
NtAllocateVirtualMemory
|
process_identifier:
2732
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04e0f000
|
success
|
0 |
0
|
1619649228.104662
NtAllocateVirtualMemory
|
process_identifier:
2732
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00744000
|
success
|
0 |
0
|
1619649228.120662
NtAllocateVirtualMemory
|
process_identifier:
2732
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00582000
|
success
|
0 |
0
|
1619649228.167662
NtAllocateVirtualMemory
|
process_identifier:
2732
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00595000
|
success
|
0 |
0
|
1619649228.276662
NtAllocateVirtualMemory
|
process_identifier:
2732
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0052a000
|
success
|
0 |
0
|
1619649228.526662
NtAllocateVirtualMemory
|
process_identifier:
2732
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00801000
|
success
|
0 |
0
|
1619649232.104662
NtAllocateVirtualMemory
|
process_identifier:
2732
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00745000
|
success
|
0 |
0
|
1619649232.573662
NtAllocateVirtualMemory
|
process_identifier:
2732
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00513000
|
success
|
0 |
0
|
1619658698.734501
NtAllocateVirtualMemory
|
process_identifier:
2632
region_size:
2228224
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00720000
|
success
|
0 |
0
|
1619658698.734501
NtAllocateVirtualMemory
|
process_identifier:
2632
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00900000
|
success
|
0 |
0
|
1619658698.797501
NtProtectVirtualMemory
|
process_identifier:
2632
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73f31000
|
success
|
0 |
0
|