| Time & API |
Arguments |
Status |
Return |
Repeated |
1619702029.292001
NtAllocateVirtualMemory
|
process_identifier:
3284
region_size:
1769472
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00dd0000
|
success
|
0 |
0
|
1619702029.292001
NtAllocateVirtualMemory
|
process_identifier:
3284
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00f40000
|
success
|
0 |
0
|
1619702029.745001
NtAllocateVirtualMemory
|
process_identifier:
3284
region_size:
2293760
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x02870000
|
success
|
0 |
0
|
1619702029.776001
NtAllocateVirtualMemory
|
process_identifier:
3284
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02a60000
|
success
|
0 |
0
|
1619702029.948001
NtProtectVirtualMemory
|
process_identifier:
3284
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73e01000
|
success
|
0 |
0
|
1619702030.182001
NtAllocateVirtualMemory
|
process_identifier:
3284
region_size:
1638400
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x026d0000
|
success
|
0 |
0
|
1619702030.182001
NtAllocateVirtualMemory
|
process_identifier:
3284
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02820000
|
success
|
0 |
0
|
1619702030.198001
NtAllocateVirtualMemory
|
process_identifier:
3284
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0099a000
|
success
|
0 |
0
|
1619702030.198001
NtProtectVirtualMemory
|
process_identifier:
3284
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73e02000
|
success
|
0 |
0
|
1619702030.198001
NtAllocateVirtualMemory
|
process_identifier:
3284
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00992000
|
success
|
0 |
0
|
1619702030.542001
NtAllocateVirtualMemory
|
process_identifier:
3284
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x009a2000
|
success
|
0 |
0
|
1619702030.698001
NtAllocateVirtualMemory
|
process_identifier:
3284
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x009d5000
|
success
|
0 |
0
|
1619702030.714001
NtAllocateVirtualMemory
|
process_identifier:
3284
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x009db000
|
success
|
0 |
0
|
1619702030.714001
NtAllocateVirtualMemory
|
process_identifier:
3284
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x009d7000
|
success
|
0 |
0
|
1619702030.807001
NtAllocateVirtualMemory
|
process_identifier:
3284
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x009a3000
|
success
|
0 |
0
|
1619702030.870001
NtAllocateVirtualMemory
|
process_identifier:
3284
region_size:
12288
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x009a4000
|
success
|
0 |
0
|
1619702030.886001
NtAllocateVirtualMemory
|
process_identifier:
3284
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x009ac000
|
success
|
0 |
0
|
1619702030.948001
NtAllocateVirtualMemory
|
process_identifier:
3284
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02810000
|
success
|
0 |
0
|
1619702030.948001
NtAllocateVirtualMemory
|
process_identifier:
3284
region_size:
53248
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02811000
|
success
|
0 |
0
|
1619702031.136001
NtAllocateVirtualMemory
|
process_identifier:
3284
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x009a7000
|
success
|
0 |
0
|
1619702031.370001
NtAllocateVirtualMemory
|
process_identifier:
3284
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x009a8000
|
success
|
0 |
0
|
1619702031.557001
NtAllocateVirtualMemory
|
process_identifier:
3284
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x009b6000
|
success
|
0 |
0
|
1619702031.698001
NtAllocateVirtualMemory
|
process_identifier:
3284
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02a61000
|
success
|
0 |
0
|
1619702031.761001
NtAllocateVirtualMemory
|
process_identifier:
3284
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x009ba000
|
success
|
0 |
0
|
1619702031.761001
NtAllocateVirtualMemory
|
process_identifier:
3284
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x009b7000
|
success
|
0 |
0
|
1619702031.964001
NtAllocateVirtualMemory
|
process_identifier:
3284
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00cf0000
|
success
|
0 |
0
|
1619702031.964001
NtAllocateVirtualMemory
|
process_identifier:
3284
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00cf1000
|
success
|
0 |
0
|
1619702032.011001
NtAllocateVirtualMemory
|
process_identifier:
3284
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00cf2000
|
success
|
0 |
0
|
1619702032.042001
NtAllocateVirtualMemory
|
process_identifier:
3284
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0281e000
|
success
|
0 |
0
|
1619702043.167001
NtAllocateVirtualMemory
|
process_identifier:
3284
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0281f000
|
success
|
0 |
0
|
1619702043.167001
NtAllocateVirtualMemory
|
process_identifier:
3284
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00cf3000
|
success
|
0 |
0
|
1619702043.745001
NtAllocateVirtualMemory
|
process_identifier:
3284
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00cf4000
|
success
|
0 |
0
|
1619702043.776001
NtAllocateVirtualMemory
|
process_identifier:
3284
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x027f0000
|
success
|
0 |
0
|
1619702043.948001
NtAllocateVirtualMemory
|
process_identifier:
3284
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00cf5000
|
success
|
0 |
0
|
1619702044.026001
NtAllocateVirtualMemory
|
process_identifier:
3284
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00cf6000
|
success
|
0 |
0
|
1619702044.026001
NtAllocateVirtualMemory
|
process_identifier:
3284
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x009ad000
|
success
|
0 |
0
|
1619702044.026001
NtAllocateVirtualMemory
|
process_identifier:
3284
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x027e0000
|
success
|
0 |
0
|
1619702044.026001
NtAllocateVirtualMemory
|
process_identifier:
3284
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x027e1000
|
success
|
0 |
0
|
1619702044.026001
NtAllocateVirtualMemory
|
process_identifier:
3284
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x009aa000
|
success
|
0 |
0
|
1619702044.026001
NtAllocateVirtualMemory
|
process_identifier:
3284
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x009ab000
|
success
|
0 |
0
|
1619702044.042001
NtAllocateVirtualMemory
|
process_identifier:
3284
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x027f1000
|
success
|
0 |
0
|
1619702044.057001
NtAllocateVirtualMemory
|
process_identifier:
3284
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00cf7000
|
success
|
0 |
0
|
1619702044.261001
NtAllocateVirtualMemory
|
process_identifier:
3284
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x027f2000
|
success
|
0 |
0
|
1619702044.354001
NtAllocateVirtualMemory
|
process_identifier:
3284
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00cf8000
|
success
|
0 |
0
|
1619702044.354001
NtAllocateVirtualMemory
|
process_identifier:
3284
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00cf9000
|
success
|
0 |
0
|
1619702044.370001
NtAllocateVirtualMemory
|
process_identifier:
3284
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00cfa000
|
success
|
0 |
0
|
1619702044.370001
NtAllocateVirtualMemory
|
process_identifier:
3284
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00cfb000
|
success
|
0 |
0
|
1619702044.401001
NtAllocateVirtualMemory
|
process_identifier:
3284
region_size:
327680
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
1056768
(MEM_RESERVE|MEM_TOP_DOWN)
base_address:
0x7ef40000
|
success
|
0 |
0
|
1619702044.401001
NtAllocateVirtualMemory
|
process_identifier:
3284
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x7ef40000
|
success
|
0 |
0
|
1619702044.401001
NtAllocateVirtualMemory
|
process_identifier:
3284
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x7ef40000
|
success
|
0 |
0
|