| Time & API |
Arguments |
Status |
Return |
Repeated |
1619704499.891
NtAllocateVirtualMemory
|
process_identifier:
2144
region_size:
917504
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x004a0000
|
success
|
0 |
0
|
1619704499.891
NtAllocateVirtualMemory
|
process_identifier:
2144
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00540000
|
success
|
0 |
0
|
1619704502.798
NtAllocateVirtualMemory
|
process_identifier:
2144
region_size:
1310720
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00660000
|
success
|
0 |
0
|
1619704502.798
NtAllocateVirtualMemory
|
process_identifier:
2144
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00760000
|
success
|
0 |
0
|
1619704503.782
NtProtectVirtualMemory
|
process_identifier:
2144
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73941000
|
success
|
0 |
0
|
1619704504.86
NtAllocateVirtualMemory
|
process_identifier:
2144
region_size:
2031616
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x02180000
|
success
|
0 |
0
|
1619704504.86
NtAllocateVirtualMemory
|
process_identifier:
2144
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02330000
|
success
|
0 |
0
|
1619704504.86
NtAllocateVirtualMemory
|
process_identifier:
2144
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002ba000
|
success
|
0 |
0
|
1619704504.876
NtProtectVirtualMemory
|
process_identifier:
2144
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73942000
|
success
|
0 |
0
|
1619704504.876
NtAllocateVirtualMemory
|
process_identifier:
2144
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002b2000
|
success
|
0 |
0
|
1619704507.954
NtAllocateVirtualMemory
|
process_identifier:
2144
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002c2000
|
success
|
0 |
0
|
1619704509.266
NtAllocateVirtualMemory
|
process_identifier:
2144
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002e5000
|
success
|
0 |
0
|
1619704509.282
NtAllocateVirtualMemory
|
process_identifier:
2144
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002eb000
|
success
|
0 |
0
|
1619704509.282
NtAllocateVirtualMemory
|
process_identifier:
2144
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002e7000
|
success
|
0 |
0
|
1619704512.329
NtAllocateVirtualMemory
|
process_identifier:
2144
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002c3000
|
success
|
0 |
0
|
1619704512.579
NtAllocateVirtualMemory
|
process_identifier:
2144
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002cc000
|
success
|
0 |
0
|
1619704512.969
NtAllocateVirtualMemory
|
process_identifier:
2144
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00590000
|
success
|
0 |
0
|
1619704513.548
NtAllocateVirtualMemory
|
process_identifier:
2144
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002c4000
|
success
|
0 |
0
|
1619704513.798
NtAllocateVirtualMemory
|
process_identifier:
2144
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002da000
|
success
|
0 |
0
|
1619704513.798
NtAllocateVirtualMemory
|
process_identifier:
2144
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002d7000
|
success
|
0 |
0
|
1619704517.876
NtAllocateVirtualMemory
|
process_identifier:
2144
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002c5000
|
success
|
0 |
0
|
1619704518.251
NtAllocateVirtualMemory
|
process_identifier:
2144
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002bc000
|
success
|
0 |
0
|
1619704519.86
NtAllocateVirtualMemory
|
process_identifier:
2144
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002c6000
|
success
|
0 |
0
|
1619704519.876
NtAllocateVirtualMemory
|
process_identifier:
2144
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002c7000
|
success
|
0 |
0
|
1619704519.907
NtAllocateVirtualMemory
|
process_identifier:
2144
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002d6000
|
success
|
0 |
0
|
1619704520.094
NtAllocateVirtualMemory
|
process_identifier:
2144
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00591000
|
success
|
0 |
0
|
1619704520.126
NtAllocateVirtualMemory
|
process_identifier:
2144
region_size:
12288
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00a70000
|
success
|
0 |
0
|
1619704520.126
NtAllocateVirtualMemory
|
process_identifier:
2144
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002c8000
|
success
|
0 |
0
|
1619704523.141
NtAllocateVirtualMemory
|
process_identifier:
2144
region_size:
12288
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x022d0000
|
success
|
0 |
0
|
1619704525.391
NtAllocateVirtualMemory
|
process_identifier:
2144
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00592000
|
success
|
0 |
0
|
1619704515.390625
NtAllocateVirtualMemory
|
process_identifier:
1908
region_size:
1310720
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x021f0000
|
success
|
0 |
0
|
1619704515.390625
NtAllocateVirtualMemory
|
process_identifier:
1908
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x022f0000
|
success
|
0 |
0
|
1619704515.406625
NtAllocateVirtualMemory
|
process_identifier:
1908
region_size:
2228224
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x02510000
|
success
|
0 |
0
|
1619704515.406625
NtAllocateVirtualMemory
|
process_identifier:
1908
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x026f0000
|
success
|
0 |
0
|
1619704515.422625
NtAllocateVirtualMemory
|
process_identifier:
1908
region_size:
1376256
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x02510000
|
success
|
0 |
0
|
1619704515.422625
NtAllocateVirtualMemory
|
process_identifier:
1908
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02620000
|
success
|
0 |
0
|
1619704517.3595
NtAllocateVirtualMemory
|
process_identifier:
3008
region_size:
1441792
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x02460000
|
success
|
0 |
0
|
1619704517.3595
NtAllocateVirtualMemory
|
process_identifier:
3008
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02580000
|
success
|
0 |
0
|
1619704517.3595
NtAllocateVirtualMemory
|
process_identifier:
3008
region_size:
1507328
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x025c0000
|
success
|
0 |
0
|
1619704517.3595
NtAllocateVirtualMemory
|
process_identifier:
3008
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x026f0000
|
success
|
0 |
0
|
1619704517.4065
NtAllocateVirtualMemory
|
process_identifier:
3008
region_size:
1703936
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x02a00000
|
success
|
0 |
0
|
1619704517.4065
NtAllocateVirtualMemory
|
process_identifier:
3008
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02b60000
|
success
|
0 |
0
|
1619704525.61025
NtProtectVirtualMemory
|
process_identifier:
3156
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73fb1000
|
success
|
0 |
0
|
1619704525.61025
NtAllocateVirtualMemory
|
process_identifier:
3156
region_size:
2162688
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00ab0000
|
success
|
0 |
0
|
1619704525.61025
NtAllocateVirtualMemory
|
process_identifier:
3156
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00c80000
|
success
|
0 |
0
|
1619704525.62625
NtProtectVirtualMemory
|
process_identifier:
3156
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73941000
|
success
|
0 |
0
|
1619704525.62625
NtProtectVirtualMemory
|
process_identifier:
3156
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73881000
|
success
|
0 |
0
|
1619704525.62625
NtAllocateVirtualMemory
|
process_identifier:
3156
region_size:
262144
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x003b0000
|
success
|
0 |
0
|
1619704525.62625
NtAllocateVirtualMemory
|
process_identifier:
3156
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003b0000
|
success
|
0 |
0
|
1619704525.62625
NtProtectVirtualMemory
|
process_identifier:
3156
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73941000
|
success
|
0 |
0
|