| Time & API |
Arguments |
Status |
Return |
Repeated |
1619706886.981999
NtAllocateVirtualMemory
|
process_identifier:
1912
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00360000
|
success
|
0 |
0
|
1619706887.418999
NtProtectVirtualMemory
|
process_identifier:
1912
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00483000
|
success
|
0 |
0
|
1619706887.418999
NtAllocateVirtualMemory
|
process_identifier:
1912
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00670000
|
success
|
0 |
0
|
1619706520.61052
NtAllocateVirtualMemory
|
process_identifier:
1424
region_size:
65536
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffffffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0000000004150000
|
success
|
0 |
0
|
1619706890.621999
NtAllocateVirtualMemory
|
process_identifier:
3000
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003e0000
|
success
|
0 |
0
|
1619706890.762999
NtProtectVirtualMemory
|
process_identifier:
3000
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00483000
|
success
|
0 |
0
|
1619706890.762999
NtAllocateVirtualMemory
|
process_identifier:
3000
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x01ec0000
|
success
|
0 |
0
|
1619706901.481999
NtAllocateVirtualMemory
|
process_identifier:
1128
region_size:
851968
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x02840000
|
success
|
0 |
0
|
1619706901.481999
NtAllocateVirtualMemory
|
process_identifier:
1128
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x028d0000
|
success
|
0 |
0
|
1619706902.403999
NtProtectVirtualMemory
|
process_identifier:
1128
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x737c1000
|
success
|
0 |
0
|
1619706902.512999
NtAllocateVirtualMemory
|
process_identifier:
1128
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x01f4a000
|
success
|
0 |
0
|
1619706902.512999
NtProtectVirtualMemory
|
process_identifier:
1128
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x737c2000
|
success
|
0 |
0
|
1619706902.512999
NtAllocateVirtualMemory
|
process_identifier:
1128
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x01f42000
|
success
|
0 |
0
|
1619706902.824999
NtAllocateVirtualMemory
|
process_identifier:
1128
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02092000
|
success
|
0 |
0
|
1619706902.918999
NtAllocateVirtualMemory
|
process_identifier:
1128
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x028d1000
|
success
|
0 |
0
|
1619706902.965999
NtAllocateVirtualMemory
|
process_identifier:
1128
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x028d2000
|
success
|
0 |
0
|
1619706903.043999
NtAllocateVirtualMemory
|
process_identifier:
1128
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x020ba000
|
success
|
0 |
0
|
1619706903.418999
NtAllocateVirtualMemory
|
process_identifier:
1128
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02093000
|
success
|
0 |
0
|
1619706903.574999
NtAllocateVirtualMemory
|
process_identifier:
1128
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02094000
|
success
|
0 |
0
|
1619706903.606999
NtAllocateVirtualMemory
|
process_identifier:
1128
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x020cb000
|
success
|
0 |
0
|
1619706903.606999
NtAllocateVirtualMemory
|
process_identifier:
1128
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x020c7000
|
success
|
0 |
0
|
1619706903.762999
NtAllocateVirtualMemory
|
process_identifier:
1128
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x01f4b000
|
success
|
0 |
0
|
1619706903.887999
NtAllocateVirtualMemory
|
process_identifier:
1128
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x020b2000
|
success
|
0 |
0
|
1619706903.903999
NtAllocateVirtualMemory
|
process_identifier:
1128
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x020c5000
|
success
|
0 |
0
|
1619706904.434999
NtAllocateVirtualMemory
|
process_identifier:
1128
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02095000
|
success
|
0 |
0
|
1619706904.809999
NtAllocateVirtualMemory
|
process_identifier:
1128
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x020bc000
|
success
|
0 |
0
|
1619706905.168999
NtAllocateVirtualMemory
|
process_identifier:
1128
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x020b3000
|
success
|
0 |
0
|
1619706905.215999
NtAllocateVirtualMemory
|
process_identifier:
1128
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x03130000
|
success
|
0 |
0
|
1619706906.824999
NtAllocateVirtualMemory
|
process_identifier:
1128
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02096000
|
success
|
0 |
0
|
1619706908.199999
NtAllocateVirtualMemory
|
process_identifier:
1128
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x020cc000
|
success
|
0 |
0
|
1619706909.074999
NtAllocateVirtualMemory
|
process_identifier:
1128
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x020b4000
|
success
|
0 |
0
|
1619706909.074999
NtAllocateVirtualMemory
|
process_identifier:
1128
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x020b5000
|
success
|
0 |
0
|
1619706909.074999
NtAllocateVirtualMemory
|
process_identifier:
1128
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x020b6000
|
success
|
0 |
0
|
1619706909.074999
NtAllocateVirtualMemory
|
process_identifier:
1128
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x020b7000
|
success
|
0 |
0
|
1619706909.074999
NtAllocateVirtualMemory
|
process_identifier:
1128
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x020b8000
|
success
|
0 |
0
|
1619706909.074999
NtAllocateVirtualMemory
|
process_identifier:
1128
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x020b9000
|
success
|
0 |
0
|
1619706909.074999
NtAllocateVirtualMemory
|
process_identifier:
1128
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x03140000
|
success
|
0 |
0
|
1619706909.074999
NtAllocateVirtualMemory
|
process_identifier:
1128
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x03141000
|
success
|
0 |
0
|
1619706909.074999
NtAllocateVirtualMemory
|
process_identifier:
1128
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x03142000
|
success
|
0 |
0
|
1619706909.074999
NtAllocateVirtualMemory
|
process_identifier:
1128
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x03143000
|
success
|
0 |
0
|
1619706909.074999
NtAllocateVirtualMemory
|
process_identifier:
1128
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x03144000
|
success
|
0 |
0
|
1619706909.074999
NtAllocateVirtualMemory
|
process_identifier:
1128
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x03145000
|
success
|
0 |
0
|
1619706909.074999
NtAllocateVirtualMemory
|
process_identifier:
1128
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x03146000
|
success
|
0 |
0
|
1619706909.074999
NtAllocateVirtualMemory
|
process_identifier:
1128
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x03147000
|
success
|
0 |
0
|
1619706909.074999
NtAllocateVirtualMemory
|
process_identifier:
1128
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x03148000
|
success
|
0 |
0
|
1619706909.074999
NtAllocateVirtualMemory
|
process_identifier:
1128
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x03149000
|
success
|
0 |
0
|
1619706909.074999
NtAllocateVirtualMemory
|
process_identifier:
1128
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0314a000
|
success
|
0 |
0
|
1619706909.074999
NtAllocateVirtualMemory
|
process_identifier:
1128
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0314b000
|
success
|
0 |
0
|
1619706909.074999
NtAllocateVirtualMemory
|
process_identifier:
1128
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0314c000
|
success
|
0 |
0
|
1619706909.074999
NtAllocateVirtualMemory
|
process_identifier:
1128
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0314d000
|
success
|
0 |
0
|