| Time & API |
Arguments |
Status |
Return |
Repeated |
1620808806.50025
NtAllocateVirtualMemory
|
process_identifier:
420
region_size:
1769472
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00b90000
|
success
|
0 |
0
|
1620808806.50025
NtAllocateVirtualMemory
|
process_identifier:
420
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00d00000
|
success
|
0 |
0
|
1620808807.04725
NtAllocateVirtualMemory
|
process_identifier:
420
region_size:
1048576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00630000
|
success
|
0 |
0
|
1620808807.04725
NtAllocateVirtualMemory
|
process_identifier:
420
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006f0000
|
success
|
0 |
0
|
1620808807.09425
NtProtectVirtualMemory
|
process_identifier:
420
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73b91000
|
success
|
0 |
0
|
1620808807.20325
NtAllocateVirtualMemory
|
process_identifier:
420
region_size:
983040
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00470000
|
success
|
0 |
0
|
1620808807.20325
NtAllocateVirtualMemory
|
process_identifier:
420
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00520000
|
success
|
0 |
0
|
1620808807.20325
NtAllocateVirtualMemory
|
process_identifier:
420
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0029a000
|
success
|
0 |
0
|
1620808807.20325
NtProtectVirtualMemory
|
process_identifier:
420
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73b92000
|
success
|
0 |
0
|
1620808807.20325
NtAllocateVirtualMemory
|
process_identifier:
420
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00292000
|
success
|
0 |
0
|
1620808807.48425
NtAllocateVirtualMemory
|
process_identifier:
420
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002a2000
|
success
|
0 |
0
|
1620808807.57825
NtAllocateVirtualMemory
|
process_identifier:
420
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002c5000
|
success
|
0 |
0
|
1620808807.59425
NtAllocateVirtualMemory
|
process_identifier:
420
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002cb000
|
success
|
0 |
0
|
1620808807.59425
NtAllocateVirtualMemory
|
process_identifier:
420
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002c7000
|
success
|
0 |
0
|
1620808807.78125
NtAllocateVirtualMemory
|
process_identifier:
420
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002a3000
|
success
|
0 |
0
|
1620808807.81325
NtAllocateVirtualMemory
|
process_identifier:
420
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002ac000
|
success
|
0 |
0
|
1620808808.65625
NtAllocateVirtualMemory
|
process_identifier:
420
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002a4000
|
success
|
0 |
0
|
1620808808.65625
NtAllocateVirtualMemory
|
process_identifier:
420
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002a6000
|
success
|
0 |
0
|
1620808808.81325
NtAllocateVirtualMemory
|
process_identifier:
420
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00500000
|
success
|
0 |
0
|
1620808808.96925
NtAllocateVirtualMemory
|
process_identifier:
420
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002ba000
|
success
|
0 |
0
|
1620808808.96925
NtAllocateVirtualMemory
|
process_identifier:
420
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002b7000
|
success
|
0 |
0
|
1620808809.07825
NtAllocateVirtualMemory
|
process_identifier:
420
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002b6000
|
success
|
0 |
0
|
1620808809.15625
NtAllocateVirtualMemory
|
process_identifier:
420
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00501000
|
success
|
0 |
0
|
1620808809.48425
NtAllocateVirtualMemory
|
process_identifier:
420
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0029c000
|
success
|
0 |
0
|
1620808809.50025
NtAllocateVirtualMemory
|
process_identifier:
420
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002a7000
|
success
|
0 |
0
|
1620808810.23425
NtAllocateVirtualMemory
|
process_identifier:
420
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002aa000
|
success
|
0 |
0
|
1620808816.18825
NtAllocateVirtualMemory
|
process_identifier:
420
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002a8000
|
success
|
0 |
0
|
1620808816.34425
NtAllocateVirtualMemory
|
process_identifier:
420
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00bb0000
|
success
|
0 |
0
|
1620808849.42225
NtAllocateVirtualMemory
|
process_identifier:
420
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00502000
|
success
|
0 |
0
|
1620808850.03125
NtAllocateVirtualMemory
|
process_identifier:
420
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00293000
|
success
|
0 |
0
|
1620808850.04725
NtAllocateVirtualMemory
|
process_identifier:
420
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002a9000
|
success
|
0 |
0
|
1620808850.23425
NtAllocateVirtualMemory
|
process_identifier:
420
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x023b0000
|
success
|
0 |
0
|
1620808850.23425
NtAllocateVirtualMemory
|
process_identifier:
420
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x023b1000
|
success
|
0 |
0
|
1620808850.26625
NtAllocateVirtualMemory
|
process_identifier:
420
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x023b2000
|
success
|
0 |
0
|
1620808850.28125
NtAllocateVirtualMemory
|
process_identifier:
420
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002bb000
|
success
|
0 |
0
|
1620808850.29725
NtAllocateVirtualMemory
|
process_identifier:
420
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00503000
|
success
|
0 |
0
|
1620808850.32825
NtAllocateVirtualMemory
|
process_identifier:
420
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x023b3000
|
success
|
0 |
0
|
1620808850.37525
NtAllocateVirtualMemory
|
process_identifier:
420
region_size:
12288
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00504000
|
success
|
0 |
0
|
1620808850.37525
NtAllocateVirtualMemory
|
process_identifier:
420
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00507000
|
success
|
0 |
0
|
1620808850.57825
NtAllocateVirtualMemory
|
process_identifier:
420
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00508000
|
success
|
0 |
0
|
1620808850.59425
NtProtectVirtualMemory
|
process_identifier:
420
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
502784
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x05a50400
|
failed
|
3221225550 |
0
|
1620808854.95325
NtAllocateVirtualMemory
|
process_identifier:
420
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x023b4000
|
success
|
0 |
0
|
1620808854.95325
NtAllocateVirtualMemory
|
process_identifier:
420
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00509000
|
success
|
0 |
0
|
1620808854.95325
NtAllocateVirtualMemory
|
process_identifier:
420
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002ad000
|
success
|
0 |
0
|
1620808854.96925
NtAllocateVirtualMemory
|
process_identifier:
420
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0050a000
|
success
|
0 |
0
|
1620808854.96925
NtAllocateVirtualMemory
|
process_identifier:
420
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0050b000
|
success
|
0 |
0
|
1620808855.00025
NtAllocateVirtualMemory
|
process_identifier:
420
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0050c000
|
success
|
0 |
0
|
1620808855.00025
NtAllocateVirtualMemory
|
process_identifier:
420
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0050d000
|
success
|
0 |
0
|
1620808855.17225
NtAllocateVirtualMemory
|
process_identifier:
420
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x023b5000
|
success
|
0 |
0
|
1620808855.18825
NtAllocateVirtualMemory
|
process_identifier:
420
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04db0000
|
success
|
0 |
0
|