| Time & API |
Arguments |
Status |
Return |
Repeated |
1619686134.321458
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
1703936
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x008a0000
|
success
|
0 |
0
|
1619686134.321458
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00a00000
|
success
|
0 |
0
|
1619686134.509458
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
1310720
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00530000
|
success
|
0 |
0
|
1619686134.509458
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00630000
|
success
|
0 |
0
|
1619686134.868458
NtProtectVirtualMemory
|
process_identifier:
2404
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73e71000
|
success
|
0 |
0
|
1619686134.977458
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
524288
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00570000
|
success
|
0 |
0
|
1619686134.977458
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005b0000
|
success
|
0 |
0
|
1619686134.977458
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0041a000
|
success
|
0 |
0
|
1619686134.977458
NtProtectVirtualMemory
|
process_identifier:
2404
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73e72000
|
success
|
0 |
0
|
1619686134.977458
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00412000
|
success
|
0 |
0
|
1619686135.306458
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00422000
|
success
|
0 |
0
|
1619686135.540458
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00545000
|
success
|
0 |
0
|
1619686135.540458
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0054b000
|
success
|
0 |
0
|
1619686135.540458
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00547000
|
success
|
0 |
0
|
1619686135.665458
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00423000
|
success
|
0 |
0
|
1619686135.712458
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0042c000
|
success
|
0 |
0
|
1619686136.165458
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00424000
|
success
|
0 |
0
|
1619686136.165458
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00426000
|
success
|
0 |
0
|
1619686136.306458
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006b0000
|
success
|
0 |
0
|
1619686136.431458
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00427000
|
success
|
0 |
0
|
1619686136.462458
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0053a000
|
success
|
0 |
0
|
1619686136.462458
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00537000
|
success
|
0 |
0
|
1619686136.696458
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00428000
|
success
|
0 |
0
|
1619686136.727458
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00429000
|
success
|
0 |
0
|
1619686136.743458
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006b1000
|
success
|
0 |
0
|
1619686136.993458
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00536000
|
success
|
0 |
0
|
1619686137.024458
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x007f0000
|
success
|
0 |
0
|
1619686137.087458
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006b2000
|
success
|
0 |
0
|
1619686137.087458
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x007f1000
|
success
|
0 |
0
|
1619686137.118458
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
12288
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006b3000
|
success
|
0 |
0
|
1619686178.149458
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x007f2000
|
success
|
0 |
0
|
1619686178.149458
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006b6000
|
success
|
0 |
0
|
1619686178.368458
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006b7000
|
success
|
0 |
0
|
1619686178.556458
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0041c000
|
success
|
0 |
0
|
1619686178.634458
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006b8000
|
success
|
0 |
0
|
1619686178.649458
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x007f3000
|
success
|
0 |
0
|
1619686178.665458
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0042d000
|
success
|
0 |
0
|
1619686178.665458
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006b9000
|
success
|
0 |
0
|
1619686178.790458
NtProtectVirtualMemory
|
process_identifier:
2404
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
285696
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x05340400
|
failed
|
3221225550 |
0
|
1619686184.962458
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006ba000
|
success
|
0 |
0
|
1619686185.040458
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006bb000
|
success
|
0 |
0
|
1619686185.040458
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x007f4000
|
success
|
0 |
0
|
1619686185.056458
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006bc000
|
success
|
0 |
0
|
1619686185.227458
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006bd000
|
success
|
0 |
0
|
1619686185.274458
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006be000
|
success
|
0 |
0
|
1619686185.384458
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006bf000
|
success
|
0 |
0
|
1619686185.415458
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04b40000
|
success
|
0 |
0
|
1619686185.415458
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04b41000
|
success
|
0 |
0
|
1619686185.415458
NtProtectVirtualMemory
|
process_identifier:
2404
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x05340178
|
failed
|
3221225550 |
0
|
1619686185.431458
NtProtectVirtualMemory
|
process_identifier:
2404
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x053401a0
|
failed
|
3221225550 |
0
|