| Time & API |
Arguments |
Status |
Return |
Repeated |
1620808789.249375
NtAllocateVirtualMemory
|
process_identifier:
2288
region_size:
983040
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x006f0000
|
success
|
0 |
0
|
1620808789.249375
NtAllocateVirtualMemory
|
process_identifier:
2288
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x007a0000
|
success
|
0 |
0
|
1620808795.937375
NtAllocateVirtualMemory
|
process_identifier:
2288
region_size:
1703936
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x021b0000
|
success
|
0 |
0
|
1620808795.937375
NtAllocateVirtualMemory
|
process_identifier:
2288
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02310000
|
success
|
0 |
0
|
1620808796.281375
NtProtectVirtualMemory
|
process_identifier:
2288
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73b91000
|
success
|
0 |
0
|
1620808796.468375
NtAllocateVirtualMemory
|
process_identifier:
2288
region_size:
262144
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x005f0000
|
success
|
0 |
0
|
1620808796.468375
NtAllocateVirtualMemory
|
process_identifier:
2288
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005f0000
|
success
|
0 |
0
|
1620808796.468375
NtAllocateVirtualMemory
|
process_identifier:
2288
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0051a000
|
success
|
0 |
0
|
1620808796.468375
NtProtectVirtualMemory
|
process_identifier:
2288
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73b92000
|
success
|
0 |
0
|
1620808796.468375
NtAllocateVirtualMemory
|
process_identifier:
2288
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00512000
|
success
|
0 |
0
|
1620808796.952375
NtAllocateVirtualMemory
|
process_identifier:
2288
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00522000
|
success
|
0 |
0
|
1620808797.281375
NtAllocateVirtualMemory
|
process_identifier:
2288
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00545000
|
success
|
0 |
0
|
1620808797.312375
NtAllocateVirtualMemory
|
process_identifier:
2288
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0054b000
|
success
|
0 |
0
|
1620808797.312375
NtAllocateVirtualMemory
|
process_identifier:
2288
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00547000
|
success
|
0 |
0
|
1620808797.765375
NtAllocateVirtualMemory
|
process_identifier:
2288
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00523000
|
success
|
0 |
0
|
1620808798.593375
NtAllocateVirtualMemory
|
process_identifier:
2288
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0052c000
|
success
|
0 |
0
|
1620808798.999375
NtAllocateVirtualMemory
|
process_identifier:
2288
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00690000
|
success
|
0 |
0
|
1620808799.843375
NtAllocateVirtualMemory
|
process_identifier:
2288
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00524000
|
success
|
0 |
0
|
1620808800.015375
NtAllocateVirtualMemory
|
process_identifier:
2288
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00691000
|
success
|
0 |
0
|
1620808800.218375
NtProtectVirtualMemory
|
process_identifier:
2288
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
794624
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00982000
|
success
|
0 |
0
|
1620808807.234375
NtAllocateVirtualMemory
|
process_identifier:
2288
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00692000
|
success
|
0 |
0
|
1620808807.421375
NtAllocateVirtualMemory
|
process_identifier:
2288
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00525000
|
success
|
0 |
0
|
1620808807.421375
NtAllocateVirtualMemory
|
process_identifier:
2288
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00693000
|
success
|
0 |
0
|
1620808807.437375
NtAllocateVirtualMemory
|
process_identifier:
2288
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00694000
|
success
|
0 |
0
|
1620808807.702375
NtAllocateVirtualMemory
|
process_identifier:
2288
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00695000
|
success
|
0 |
0
|
1620808807.702375
NtAllocateVirtualMemory
|
process_identifier:
2288
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00696000
|
success
|
0 |
0
|
1620808808.577375
NtAllocateVirtualMemory
|
process_identifier:
2288
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00697000
|
success
|
0 |
0
|
1620808809.140375
NtAllocateVirtualMemory
|
process_identifier:
2288
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00526000
|
success
|
0 |
0
|
1620808809.140375
NtAllocateVirtualMemory
|
process_identifier:
2288
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00527000
|
success
|
0 |
0
|
1620808811.218375
NtAllocateVirtualMemory
|
process_identifier:
2288
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00528000
|
success
|
0 |
0
|
1620808811.437375
NtAllocateVirtualMemory
|
process_identifier:
2288
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00790000
|
success
|
0 |
0
|
1620808811.577375
NtAllocateVirtualMemory
|
process_identifier:
2288
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0053a000
|
success
|
0 |
0
|
1620808811.577375
NtAllocateVirtualMemory
|
process_identifier:
2288
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00537000
|
success
|
0 |
0
|
1620808811.718375
NtAllocateVirtualMemory
|
process_identifier:
2288
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00791000
|
success
|
0 |
0
|
1620808811.718375
NtAllocateVirtualMemory
|
process_identifier:
2288
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00792000
|
success
|
0 |
0
|
1620808811.781375
NtAllocateVirtualMemory
|
process_identifier:
2288
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00698000
|
success
|
0 |
0
|
1620808811.827375
NtAllocateVirtualMemory
|
process_identifier:
2288
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00536000
|
success
|
0 |
0
|
1620808813.265375
NtAllocateVirtualMemory
|
process_identifier:
2288
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00793000
|
success
|
0 |
0
|
1620808813.312375
NtAllocateVirtualMemory
|
process_identifier:
2288
region_size:
327680
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
1056768
(MEM_RESERVE|MEM_TOP_DOWN)
base_address:
0x7ef40000
|
success
|
0 |
0
|
1620808813.312375
NtAllocateVirtualMemory
|
process_identifier:
2288
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x7ef40000
|
success
|
0 |
0
|
1620808813.312375
NtAllocateVirtualMemory
|
process_identifier:
2288
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x7ef40000
|
success
|
0 |
0
|
1620808813.312375
NtAllocateVirtualMemory
|
process_identifier:
2288
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x7ef48000
|
success
|
0 |
0
|
1620808813.312375
NtAllocateVirtualMemory
|
process_identifier:
2288
region_size:
65536
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
1056768
(MEM_RESERVE|MEM_TOP_DOWN)
base_address:
0x7ef30000
|
success
|
0 |
0
|
1620808813.312375
NtAllocateVirtualMemory
|
process_identifier:
2288
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x7ef30000
|
success
|
0 |
0
|
1620808813.343375
NtAllocateVirtualMemory
|
process_identifier:
2288
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00794000
|
success
|
0 |
0
|
1620808813.343375
NtAllocateVirtualMemory
|
process_identifier:
2288
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00699000
|
success
|
0 |
0
|
1620808813.359375
NtAllocateVirtualMemory
|
process_identifier:
2288
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0052d000
|
success
|
0 |
0
|
1620808813.359375
NtAllocateVirtualMemory
|
process_identifier:
2288
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0069a000
|
success
|
0 |
0
|
1620808813.843375
NtAllocateVirtualMemory
|
process_identifier:
2288
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0069b000
|
success
|
0 |
0
|
1620808813.984375
NtAllocateVirtualMemory
|
process_identifier:
2288
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00795000
|
success
|
0 |
0
|