| Time & API |
Arguments |
Status |
Return |
Repeated |
1619686138.104822
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
655360
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00610000
|
success
|
0 |
0
|
1619686138.104822
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00670000
|
success
|
0 |
0
|
1619686138.604822
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
1179648
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x007f0000
|
success
|
0 |
0
|
1619686138.604822
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x008d0000
|
success
|
0 |
0
|
1619686138.682822
NtProtectVirtualMemory
|
process_identifier:
2136
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73e71000
|
success
|
0 |
0
|
1619686138.760822
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
2031616
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x02260000
|
success
|
0 |
0
|
1619686138.760822
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02410000
|
success
|
0 |
0
|
1619686138.776822
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004ca000
|
success
|
0 |
0
|
1619686138.776822
NtProtectVirtualMemory
|
process_identifier:
2136
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73e72000
|
success
|
0 |
0
|
1619686138.776822
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004c2000
|
success
|
0 |
0
|
1619686139.057822
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004d2000
|
success
|
0 |
0
|
1619686139.104822
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004f5000
|
success
|
0 |
0
|
1619686139.104822
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004fb000
|
success
|
0 |
0
|
1619686139.104822
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004f7000
|
success
|
0 |
0
|
1619686139.198822
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004d3000
|
success
|
0 |
0
|
1619686139.213822
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004dc000
|
success
|
0 |
0
|
1619686139.260822
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004d4000
|
success
|
0 |
0
|
1619686139.260822
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00750000
|
success
|
0 |
0
|
1619686139.401822
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004d5000
|
success
|
0 |
0
|
1619686139.448822
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004d6000
|
success
|
0 |
0
|
1619686139.479822
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
28672
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00751000
|
success
|
0 |
0
|
1619686139.541822
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00758000
|
success
|
0 |
0
|
1619686139.541822
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004d7000
|
success
|
0 |
0
|
1619686139.573822
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004d8000
|
success
|
0 |
0
|
1619686139.573822
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00759000
|
success
|
0 |
0
|
1619686139.604822
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004d9000
|
success
|
0 |
0
|
1619686139.619822
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0075a000
|
success
|
0 |
0
|
1619686139.635822
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0075b000
|
success
|
0 |
0
|
1619686139.666822
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0075c000
|
success
|
0 |
0
|
1619686139.682822
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0075d000
|
success
|
0 |
0
|
1619686139.698822
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004dd000
|
success
|
0 |
0
|
1619686139.713822
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0075e000
|
success
|
0 |
0
|
1619686139.713822
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0075f000
|
success
|
0 |
0
|
1619686139.729822
NtProtectVirtualMemory
|
process_identifier:
2136
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
49152
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x00192000
|
success
|
0 |
0
|
1619686139.729822
NtProtectVirtualMemory
|
process_identifier:
2136
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x001a2000
|
success
|
0 |
0
|
1619686139.729822
NtProtectVirtualMemory
|
process_identifier:
2136
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
163840
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x001aa000
|
success
|
0 |
0
|
1619686139.729822
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00760000
|
success
|
0 |
0
|
1619686139.729822
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00770000
|
success
|
0 |
0
|
1619686139.744822
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
327680
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
1056768
(MEM_RESERVE|MEM_TOP_DOWN)
base_address:
0x7ef40000
|
success
|
0 |
0
|
1619686139.744822
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x7ef40000
|
success
|
0 |
0
|
1619686139.744822
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x7ef40000
|
success
|
0 |
0
|
1619686139.744822
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x7ef48000
|
success
|
0 |
0
|
1619686139.744822
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
65536
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
1056768
(MEM_RESERVE|MEM_TOP_DOWN)
base_address:
0x7ef30000
|
success
|
0 |
0
|
1619686139.744822
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x7ef30000
|
success
|
0 |
0
|
1619686139.776822
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00761000
|
success
|
0 |
0
|
1619686139.791822
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00771000
|
success
|
0 |
0
|
1619686139.791822
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004cc000
|
success
|
0 |
0
|
1619686139.791822
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00772000
|
success
|
0 |
0
|
1619686139.823822
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00773000
|
success
|
0 |
0
|
1619686139.869822
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00774000
|
success
|
0 |
0
|