| Time & API |
Arguments |
Status |
Return |
Repeated |
1619686133.00156
NtAllocateVirtualMemory
|
process_identifier:
2224
region_size:
393216
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x002a0000
|
success
|
0 |
0
|
1619686133.00156
NtAllocateVirtualMemory
|
process_identifier:
2224
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002c0000
|
success
|
0 |
0
|
1619686133.72056
NtProtectVirtualMemory
|
process_identifier:
2224
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73f31000
|
success
|
0 |
0
|
1619686133.89256
NtAllocateVirtualMemory
|
process_identifier:
2224
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0035a000
|
success
|
0 |
0
|
1619686133.89256
NtProtectVirtualMemory
|
process_identifier:
2224
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73f32000
|
success
|
0 |
0
|
1619686133.89256
NtAllocateVirtualMemory
|
process_identifier:
2224
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00352000
|
success
|
0 |
0
|
1619686134.23656
NtAllocateVirtualMemory
|
process_identifier:
2224
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00362000
|
success
|
0 |
0
|
1619686134.43956
NtAllocateVirtualMemory
|
process_identifier:
2224
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00363000
|
success
|
0 |
0
|
1619686134.47056
NtAllocateVirtualMemory
|
process_identifier:
2224
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003bb000
|
success
|
0 |
0
|
1619686134.48656
NtAllocateVirtualMemory
|
process_identifier:
2224
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003b7000
|
success
|
0 |
0
|
1619686134.53356
NtAllocateVirtualMemory
|
process_identifier:
2224
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0036c000
|
success
|
0 |
0
|
1619686134.93956
NtAllocateVirtualMemory
|
process_identifier:
2224
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00364000
|
success
|
0 |
0
|
1619686134.93956
NtAllocateVirtualMemory
|
process_identifier:
2224
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00365000
|
success
|
0 |
0
|
1619686134.97056
NtAllocateVirtualMemory
|
process_identifier:
2224
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00366000
|
success
|
0 |
0
|
1619686134.98656
NtAllocateVirtualMemory
|
process_identifier:
2224
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00a30000
|
success
|
0 |
0
|
1619686135.04856
NtAllocateVirtualMemory
|
process_identifier:
2224
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0037a000
|
success
|
0 |
0
|
1619686135.04856
NtAllocateVirtualMemory
|
process_identifier:
2224
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00377000
|
success
|
0 |
0
|
1619686135.06456
NtAllocateVirtualMemory
|
process_identifier:
2224
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0038a000
|
success
|
0 |
0
|
1619686135.09556
NtAllocateVirtualMemory
|
process_identifier:
2224
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0035b000
|
success
|
0 |
0
|
1619686135.15856
NtAllocateVirtualMemory
|
process_identifier:
2224
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00376000
|
success
|
0 |
0
|
1619686135.23656
NtAllocateVirtualMemory
|
process_identifier:
2224
region_size:
16384
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00a31000
|
success
|
0 |
0
|
1619686135.42356
NtAllocateVirtualMemory
|
process_identifier:
2224
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02020000
|
success
|
0 |
0
|
1619686135.53356
NtAllocateVirtualMemory
|
process_identifier:
2224
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0036a000
|
success
|
0 |
0
|
1619686135.75156
NtAllocateVirtualMemory
|
process_identifier:
2224
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00382000
|
success
|
0 |
0
|
1619686135.81456
NtAllocateVirtualMemory
|
process_identifier:
2224
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003b5000
|
success
|
0 |
0
|
1619686135.97056
NtAllocateVirtualMemory
|
process_identifier:
2224
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00367000
|
success
|
0 |
0
|
1619686168.97056
NtAllocateVirtualMemory
|
process_identifier:
2224
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002c1000
|
success
|
0 |
0
|
1619686169.12656
NtAllocateVirtualMemory
|
process_identifier:
2224
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0038c000
|
success
|
0 |
0
|
1619686169.12656
NtAllocateVirtualMemory
|
process_identifier:
2224
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00a35000
|
success
|
0 |
0
|
1619686169.32956
NtAllocateVirtualMemory
|
process_identifier:
2224
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00a36000
|
success
|
0 |
0
|
1619686169.34556
NtAllocateVirtualMemory
|
process_identifier:
2224
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00368000
|
success
|
0 |
0
|
1619686169.40856
NtAllocateVirtualMemory
|
process_identifier:
2224
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02021000
|
success
|
0 |
0
|
1619686169.40856
NtProtectVirtualMemory
|
process_identifier:
2224
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
231424
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x05620400
|
failed
|
3221225550 |
0
|
1619686174.12656
NtAllocateVirtualMemory
|
process_identifier:
2224
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00a37000
|
success
|
0 |
0
|
1619686174.14256
NtAllocateVirtualMemory
|
process_identifier:
2224
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00a38000
|
success
|
0 |
0
|
1619686174.14256
NtAllocateVirtualMemory
|
process_identifier:
2224
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00a39000
|
success
|
0 |
0
|
1619686174.23656
NtAllocateVirtualMemory
|
process_identifier:
2224
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00a3a000
|
success
|
0 |
0
|
1619686174.25156
NtAllocateVirtualMemory
|
process_identifier:
2224
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00a3b000
|
success
|
0 |
0
|
1619686174.43956
NtAllocateVirtualMemory
|
process_identifier:
2224
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00369000
|
success
|
0 |
0
|
1619686174.56456
NtAllocateVirtualMemory
|
process_identifier:
2224
region_size:
12288
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00a3c000
|
success
|
0 |
0
|
1619686174.57956
NtProtectVirtualMemory
|
process_identifier:
2224
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x05620178
|
failed
|
3221225550 |
0
|
1619686174.57956
NtProtectVirtualMemory
|
process_identifier:
2224
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x056201a0
|
failed
|
3221225550 |
0
|
1619686174.57956
NtProtectVirtualMemory
|
process_identifier:
2224
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x056201c8
|
failed
|
3221225550 |
0
|
1619686174.57956
NtProtectVirtualMemory
|
process_identifier:
2224
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x056201f0
|
failed
|
3221225550 |
0
|
1619686174.57956
NtProtectVirtualMemory
|
process_identifier:
2224
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x05620218
|
failed
|
3221225550 |
0
|
1619686174.57956
NtProtectVirtualMemory
|
process_identifier:
2224
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
11
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x0565955e
|
failed
|
3221225550 |
0
|
1619686174.57956
NtProtectVirtualMemory
|
process_identifier:
2224
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
11
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x05659552
|
failed
|
3221225550 |
0
|
1619686174.57956
NtProtectVirtualMemory
|
process_identifier:
2224
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
72
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x05658c00
|
failed
|
3221225550 |
0
|
1619686174.57956
NtProtectVirtualMemory
|
process_identifier:
2224
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x0565956c
|
failed
|
3221225550 |
0
|
1619686174.57956
NtProtectVirtualMemory
|
process_identifier:
2224
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x05659590
|
failed
|
3221225550 |
0
|