| Time & API |
Arguments |
Status |
Return |
Repeated |
1619685965.82725
NtAllocateVirtualMemory
|
process_identifier:
1404
region_size:
1638400
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00ae0000
|
success
|
0 |
0
|
1619685965.82725
NtAllocateVirtualMemory
|
process_identifier:
1404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00c30000
|
success
|
0 |
0
|
1619685966.99925
NtAllocateVirtualMemory
|
process_identifier:
1404
region_size:
786432
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00520000
|
success
|
0 |
0
|
1619685966.99925
NtAllocateVirtualMemory
|
process_identifier:
1404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005a0000
|
success
|
0 |
0
|
1619685967.06225
NtProtectVirtualMemory
|
process_identifier:
1404
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73b91000
|
success
|
0 |
0
|
1619685967.17125
NtAllocateVirtualMemory
|
process_identifier:
1404
region_size:
2097152
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x02390000
|
success
|
0 |
0
|
1619685967.17125
NtAllocateVirtualMemory
|
process_identifier:
1404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02550000
|
success
|
0 |
0
|
1619685967.17125
NtAllocateVirtualMemory
|
process_identifier:
1404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0031a000
|
success
|
0 |
0
|
1619685967.17125
NtProtectVirtualMemory
|
process_identifier:
1404
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73b92000
|
success
|
0 |
0
|
1619685967.17125
NtAllocateVirtualMemory
|
process_identifier:
1404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00312000
|
success
|
0 |
0
|
1619685967.42125
NtAllocateVirtualMemory
|
process_identifier:
1404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00322000
|
success
|
0 |
0
|
1619685967.51525
NtAllocateVirtualMemory
|
process_identifier:
1404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00345000
|
success
|
0 |
0
|
1619685967.51525
NtAllocateVirtualMemory
|
process_identifier:
1404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0034b000
|
success
|
0 |
0
|
1619685967.51525
NtAllocateVirtualMemory
|
process_identifier:
1404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00347000
|
success
|
0 |
0
|
1619685967.64025
NtAllocateVirtualMemory
|
process_identifier:
1404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00323000
|
success
|
0 |
0
|
1619685967.67125
NtAllocateVirtualMemory
|
process_identifier:
1404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0032c000
|
success
|
0 |
0
|
1619685967.78125
NtAllocateVirtualMemory
|
process_identifier:
1404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00530000
|
success
|
0 |
0
|
1619685967.79625
NtAllocateVirtualMemory
|
process_identifier:
1404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00324000
|
success
|
0 |
0
|
1619685967.79625
NtAllocateVirtualMemory
|
process_identifier:
1404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00531000
|
success
|
0 |
0
|
1619685967.85925
NtAllocateVirtualMemory
|
process_identifier:
1404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00532000
|
success
|
0 |
0
|
1619685968.45225
NtAllocateVirtualMemory
|
process_identifier:
1404
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00325000
|
success
|
0 |
0
|
1619685968.46825
NtAllocateVirtualMemory
|
process_identifier:
1404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00327000
|
success
|
0 |
0
|
1619685968.68725
NtAllocateVirtualMemory
|
process_identifier:
1404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0033a000
|
success
|
0 |
0
|
1619685968.68725
NtAllocateVirtualMemory
|
process_identifier:
1404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00337000
|
success
|
0 |
0
|
1619685968.89025
NtAllocateVirtualMemory
|
process_identifier:
1404
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00533000
|
success
|
0 |
0
|
1619685969.10925
NtAllocateVirtualMemory
|
process_identifier:
1404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00328000
|
success
|
0 |
0
|
1619685969.12425
NtAllocateVirtualMemory
|
process_identifier:
1404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00535000
|
success
|
0 |
0
|
1619685969.20225
NtAllocateVirtualMemory
|
process_identifier:
1404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00329000
|
success
|
0 |
0
|
1619685969.32725
NtAllocateVirtualMemory
|
process_identifier:
1404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00536000
|
success
|
0 |
0
|
1619685969.53125
NtAllocateVirtualMemory
|
process_identifier:
1404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00336000
|
success
|
0 |
0
|
1619685969.57725
NtAllocateVirtualMemory
|
process_identifier:
1404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006d0000
|
success
|
0 |
0
|
1619685969.65625
NtAllocateVirtualMemory
|
process_identifier:
1404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006d1000
|
success
|
0 |
0
|
1619685969.70225
NtAllocateVirtualMemory
|
process_identifier:
1404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00537000
|
success
|
0 |
0
|
1619685969.73425
NtAllocateVirtualMemory
|
process_identifier:
1404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006d2000
|
success
|
0 |
0
|
1619685969.76525
NtAllocateVirtualMemory
|
process_identifier:
1404
region_size:
12288
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00538000
|
success
|
0 |
0
|
1619685969.78125
NtAllocateVirtualMemory
|
process_identifier:
1404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0032d000
|
success
|
0 |
0
|
1619686011.28125
NtAllocateVirtualMemory
|
process_identifier:
1404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0053b000
|
success
|
0 |
0
|
1619686011.45225
NtAllocateVirtualMemory
|
process_identifier:
1404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0053c000
|
success
|
0 |
0
|
1619686011.57725
NtAllocateVirtualMemory
|
process_identifier:
1404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0031c000
|
success
|
0 |
0
|
1619686011.62425
NtAllocateVirtualMemory
|
process_identifier:
1404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0053d000
|
success
|
0 |
0
|
1619686011.62425
NtAllocateVirtualMemory
|
process_identifier:
1404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006d3000
|
success
|
0 |
0
|
1619686011.64025
NtAllocateVirtualMemory
|
process_identifier:
1404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0053e000
|
success
|
0 |
0
|
1619686011.82725
NtAllocateVirtualMemory
|
process_identifier:
1404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006d4000
|
success
|
0 |
0
|
1619686011.84325
NtProtectVirtualMemory
|
process_identifier:
1404
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
288256
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x052e0400
|
failed
|
3221225550 |
0
|
1619686014.32725
NtAllocateVirtualMemory
|
process_identifier:
1404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0053f000
|
success
|
0 |
0
|
1619686014.34325
NtAllocateVirtualMemory
|
process_identifier:
1404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x049c0000
|
success
|
0 |
0
|
1619686014.35925
NtAllocateVirtualMemory
|
process_identifier:
1404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x049c1000
|
success
|
0 |
0
|
1619686014.37425
NtAllocateVirtualMemory
|
process_identifier:
1404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x049c2000
|
success
|
0 |
0
|
1619686014.39025
NtAllocateVirtualMemory
|
process_identifier:
1404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x049c3000
|
success
|
0 |
0
|
1619686014.51525
NtAllocateVirtualMemory
|
process_identifier:
1404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006d5000
|
success
|
0 |
0
|