| Time & API |
Arguments |
Status |
Return |
Repeated |
1620808800.640625
NtAllocateVirtualMemory
|
process_identifier:
648
region_size:
1179648
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x007f0000
|
success
|
0 |
0
|
1620808800.640625
NtAllocateVirtualMemory
|
process_identifier:
648
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x008d0000
|
success
|
0 |
0
|
1620808802.156625
NtAllocateVirtualMemory
|
process_identifier:
648
region_size:
1310720
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x020a0000
|
success
|
0 |
0
|
1620808802.156625
NtAllocateVirtualMemory
|
process_identifier:
648
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x021a0000
|
success
|
0 |
0
|
1620808802.265625
NtProtectVirtualMemory
|
process_identifier:
648
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73b91000
|
success
|
0 |
0
|
1620808802.421625
NtAllocateVirtualMemory
|
process_identifier:
648
region_size:
2293760
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x021e0000
|
success
|
0 |
0
|
1620808802.421625
NtAllocateVirtualMemory
|
process_identifier:
648
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x023d0000
|
success
|
0 |
0
|
1620808802.437625
NtAllocateVirtualMemory
|
process_identifier:
648
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005ca000
|
success
|
0 |
0
|
1620808802.452625
NtProtectVirtualMemory
|
process_identifier:
648
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73b92000
|
success
|
0 |
0
|
1620808802.452625
NtAllocateVirtualMemory
|
process_identifier:
648
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005c2000
|
success
|
0 |
0
|
1620808802.702625
NtAllocateVirtualMemory
|
process_identifier:
648
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005d2000
|
success
|
0 |
0
|
1620808802.781625
NtAllocateVirtualMemory
|
process_identifier:
648
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005f5000
|
success
|
0 |
0
|
1620808802.781625
NtAllocateVirtualMemory
|
process_identifier:
648
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005fb000
|
success
|
0 |
0
|
1620808802.781625
NtAllocateVirtualMemory
|
process_identifier:
648
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005f7000
|
success
|
0 |
0
|
1620808802.968625
NtAllocateVirtualMemory
|
process_identifier:
648
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005d3000
|
success
|
0 |
0
|
1620808803.062625
NtAllocateVirtualMemory
|
process_identifier:
648
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005d4000
|
success
|
0 |
0
|
1620808803.062625
NtAllocateVirtualMemory
|
process_identifier:
648
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005d5000
|
success
|
0 |
0
|
1620808803.077625
NtAllocateVirtualMemory
|
process_identifier:
648
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005dc000
|
success
|
0 |
0
|
1620808803.734625
NtAllocateVirtualMemory
|
process_identifier:
648
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005d6000
|
success
|
0 |
0
|
1620808803.749625
NtAllocateVirtualMemory
|
process_identifier:
648
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005d8000
|
success
|
0 |
0
|
1620808803.827625
NtAllocateVirtualMemory
|
process_identifier:
648
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x007d0000
|
success
|
0 |
0
|
1620808803.999625
NtAllocateVirtualMemory
|
process_identifier:
648
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005ea000
|
success
|
0 |
0
|
1620808803.999625
NtAllocateVirtualMemory
|
process_identifier:
648
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005e7000
|
success
|
0 |
0
|
1620808804.140625
NtAllocateVirtualMemory
|
process_identifier:
648
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005d9000
|
success
|
0 |
0
|
1620808804.140625
NtAllocateVirtualMemory
|
process_identifier:
648
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x007f0000
|
success
|
0 |
0
|
1620808804.202625
NtAllocateVirtualMemory
|
process_identifier:
648
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x007f1000
|
success
|
0 |
0
|
1620808804.296625
NtAllocateVirtualMemory
|
process_identifier:
648
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005e6000
|
success
|
0 |
0
|
1620808804.499625
NtAllocateVirtualMemory
|
process_identifier:
648
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x007d1000
|
success
|
0 |
0
|
1620808804.515625
NtAllocateVirtualMemory
|
process_identifier:
648
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x007f2000
|
success
|
0 |
0
|
1620808804.546625
NtAllocateVirtualMemory
|
process_identifier:
648
region_size:
327680
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
1056768
(MEM_RESERVE|MEM_TOP_DOWN)
base_address:
0x7ef40000
|
success
|
0 |
0
|
1620808804.546625
NtAllocateVirtualMemory
|
process_identifier:
648
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x7ef40000
|
success
|
0 |
0
|
1620808804.546625
NtAllocateVirtualMemory
|
process_identifier:
648
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x7ef40000
|
success
|
0 |
0
|
1620808804.546625
NtAllocateVirtualMemory
|
process_identifier:
648
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x7ef48000
|
success
|
0 |
0
|
1620808804.546625
NtAllocateVirtualMemory
|
process_identifier:
648
region_size:
65536
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
1056768
(MEM_RESERVE|MEM_TOP_DOWN)
base_address:
0x7ef30000
|
success
|
0 |
0
|
1620808804.546625
NtAllocateVirtualMemory
|
process_identifier:
648
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x7ef30000
|
success
|
0 |
0
|
1620808804.562625
NtAllocateVirtualMemory
|
process_identifier:
648
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x007f3000
|
success
|
0 |
0
|
1620808804.593625
NtAllocateVirtualMemory
|
process_identifier:
648
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x023d1000
|
success
|
0 |
0
|
1620808804.624625
NtAllocateVirtualMemory
|
process_identifier:
648
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x023d2000
|
success
|
0 |
0
|
1620808804.624625
NtAllocateVirtualMemory
|
process_identifier:
648
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x023d3000
|
success
|
0 |
0
|
1620808804.624625
NtAllocateVirtualMemory
|
process_identifier:
648
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x023d4000
|
success
|
0 |
0
|
1620808804.624625
NtAllocateVirtualMemory
|
process_identifier:
648
region_size:
16384
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x023d5000
|
success
|
0 |
0
|
1620808804.624625
NtAllocateVirtualMemory
|
process_identifier:
648
region_size:
69632
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x023d9000
|
success
|
0 |
0
|
1620808804.718625
NtAllocateVirtualMemory
|
process_identifier:
648
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x007d2000
|
success
|
0 |
0
|
1620808804.765625
NtAllocateVirtualMemory
|
process_identifier:
648
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x023ea000
|
success
|
0 |
0
|
1620808804.765625
NtAllocateVirtualMemory
|
process_identifier:
648
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x023eb000
|
success
|
0 |
0
|
1620808804.937625
NtAllocateVirtualMemory
|
process_identifier:
648
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x023ec000
|
success
|
0 |
0
|
1620808805.702625
NtAllocateVirtualMemory
|
process_identifier:
648
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x007d3000
|
success
|
0 |
0
|
1620808813.124625
NtAllocateVirtualMemory
|
process_identifier:
648
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x021a1000
|
success
|
0 |
0
|
1620808813.640625
NtAllocateVirtualMemory
|
process_identifier:
648
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x007f4000
|
success
|
0 |
0
|
1620808813.656625
NtAllocateVirtualMemory
|
process_identifier:
648
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005dd000
|
success
|
0 |
0
|