| Time & API |
Arguments |
Status |
Return |
Repeated |
1619701843.489124
NtAllocateVirtualMemory
|
process_identifier:
2040
region_size:
2228224
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00870000
|
success
|
0 |
0
|
1619701843.489124
NtAllocateVirtualMemory
|
process_identifier:
2040
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00a50000
|
success
|
0 |
0
|
1619701844.489124
NtProtectVirtualMemory
|
process_identifier:
2040
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73c51000
|
success
|
0 |
0
|
1619701844.552124
NtAllocateVirtualMemory
|
process_identifier:
2040
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0040a000
|
success
|
0 |
0
|
1619701844.552124
NtProtectVirtualMemory
|
process_identifier:
2040
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73c52000
|
success
|
0 |
0
|
1619701844.568124
NtAllocateVirtualMemory
|
process_identifier:
2040
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00402000
|
success
|
0 |
0
|
1619701844.943124
NtAllocateVirtualMemory
|
process_identifier:
2040
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00412000
|
success
|
0 |
0
|
1619701845.052124
NtAllocateVirtualMemory
|
process_identifier:
2040
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00413000
|
success
|
0 |
0
|
1619701845.068124
NtAllocateVirtualMemory
|
process_identifier:
2040
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0044b000
|
success
|
0 |
0
|
1619701845.068124
NtAllocateVirtualMemory
|
process_identifier:
2040
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00447000
|
success
|
0 |
0
|
1619701845.099124
NtAllocateVirtualMemory
|
process_identifier:
2040
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0041c000
|
success
|
0 |
0
|
1619701845.693124
NtAllocateVirtualMemory
|
process_identifier:
2040
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00414000
|
success
|
0 |
0
|
1619701845.693124
NtAllocateVirtualMemory
|
process_identifier:
2040
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00415000
|
success
|
0 |
0
|
1619701845.739124
NtAllocateVirtualMemory
|
process_identifier:
2040
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00416000
|
success
|
0 |
0
|
1619701845.755124
NtAllocateVirtualMemory
|
process_identifier:
2040
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00ab0000
|
success
|
0 |
0
|
1619701845.864124
NtAllocateVirtualMemory
|
process_identifier:
2040
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0042a000
|
success
|
0 |
0
|
1619701845.864124
NtAllocateVirtualMemory
|
process_identifier:
2040
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00427000
|
success
|
0 |
0
|
1619701845.880124
NtAllocateVirtualMemory
|
process_identifier:
2040
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0043a000
|
success
|
0 |
0
|
1619701845.911124
NtAllocateVirtualMemory
|
process_identifier:
2040
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0040b000
|
success
|
0 |
0
|
1619701846.068124
NtAllocateVirtualMemory
|
process_identifier:
2040
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00426000
|
success
|
0 |
0
|
1619701846.099124
NtAllocateVirtualMemory
|
process_identifier:
2040
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00417000
|
success
|
0 |
0
|
1619701846.130124
NtAllocateVirtualMemory
|
process_identifier:
2040
region_size:
458752
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00b50000
|
success
|
0 |
0
|
1619701846.130124
NtAllocateVirtualMemory
|
process_identifier:
2040
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00b80000
|
success
|
0 |
0
|
1619701846.130124
NtAllocateVirtualMemory
|
process_identifier:
2040
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00b81000
|
success
|
0 |
0
|
1619701846.146124
NtAllocateVirtualMemory
|
process_identifier:
2040
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00b82000
|
success
|
0 |
0
|
1619701846.208124
NtAllocateVirtualMemory
|
process_identifier:
2040
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00ab1000
|
success
|
0 |
0
|
1619701846.208124
NtAllocateVirtualMemory
|
process_identifier:
2040
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00b83000
|
success
|
0 |
0
|
1619701846.224124
NtAllocateVirtualMemory
|
process_identifier:
2040
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00b84000
|
success
|
0 |
0
|
1619701846.271124
NtAllocateVirtualMemory
|
process_identifier:
2040
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00b85000
|
success
|
0 |
0
|
1619701846.286124
NtAllocateVirtualMemory
|
process_identifier:
2040
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00ab2000
|
success
|
0 |
0
|
1619701846.318124
NtAllocateVirtualMemory
|
process_identifier:
2040
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00418000
|
success
|
0 |
0
|
1619701846.396124
NtAllocateVirtualMemory
|
process_identifier:
2040
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00432000
|
success
|
0 |
0
|
1619701846.427124
NtAllocateVirtualMemory
|
process_identifier:
2040
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00445000
|
success
|
0 |
0
|
1619701850.364124
NtAllocateVirtualMemory
|
process_identifier:
2040
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00a51000
|
success
|
0 |
0
|
1619701850.724124
NtAllocateVirtualMemory
|
process_identifier:
2040
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00ab3000
|
success
|
0 |
0
|
1619701850.724124
NtAllocateVirtualMemory
|
process_identifier:
2040
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00419000
|
success
|
0 |
0
|
1619701850.739124
NtAllocateVirtualMemory
|
process_identifier:
2040
region_size:
16384
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00b86000
|
success
|
0 |
0
|
1619701850.739124
NtAllocateVirtualMemory
|
process_identifier:
2040
region_size:
69632
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00b8a000
|
success
|
0 |
0
|
1619701850.739124
NtAllocateVirtualMemory
|
process_identifier:
2040
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00b9b000
|
success
|
0 |
0
|
1619701850.739124
NtAllocateVirtualMemory
|
process_identifier:
2040
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00b9c000
|
success
|
0 |
0
|
1619701850.755124
NtAllocateVirtualMemory
|
process_identifier:
2040
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00b9d000
|
success
|
0 |
0
|
1619701850.755124
NtAllocateVirtualMemory
|
process_identifier:
2040
region_size:
12288
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00b9e000
|
success
|
0 |
0
|
1619701850.771124
NtAllocateVirtualMemory
|
process_identifier:
2040
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00ab4000
|
success
|
0 |
0
|
1619701850.771124
NtAllocateVirtualMemory
|
process_identifier:
2040
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00ba1000
|
success
|
0 |
0
|
1619701850.771124
NtAllocateVirtualMemory
|
process_identifier:
2040
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00ba2000
|
success
|
0 |
0
|
1619701850.771124
NtAllocateVirtualMemory
|
process_identifier:
2040
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00ab5000
|
success
|
0 |
0
|
1619701850.833124
NtAllocateVirtualMemory
|
process_identifier:
2040
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04670000
|
success
|
0 |
0
|
1619701851.083124
NtAllocateVirtualMemory
|
process_identifier:
2040
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0041a000
|
success
|
0 |
0
|
1619701851.552249
NtAllocateVirtualMemory
|
process_identifier:
2200
region_size:
1114112
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00460000
|
success
|
0 |
0
|
1619701851.552249
NtAllocateVirtualMemory
|
process_identifier:
2200
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00530000
|
success
|
0 |
0
|