| Time & API |
Arguments |
Status |
Return |
Repeated |
1619716379.432375
NtAllocateVirtualMemory
|
process_identifier:
2620
region_size:
393216
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00430000
|
success
|
0 |
0
|
1619716379.432375
NtAllocateVirtualMemory
|
process_identifier:
2620
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00450000
|
success
|
0 |
0
|
1619716380.214375
NtProtectVirtualMemory
|
process_identifier:
2620
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73f31000
|
success
|
0 |
0
|
1619716380.448375
NtAllocateVirtualMemory
|
process_identifier:
2620
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0049a000
|
success
|
0 |
0
|
1619716380.448375
NtProtectVirtualMemory
|
process_identifier:
2620
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73f32000
|
success
|
0 |
0
|
1619716380.448375
NtAllocateVirtualMemory
|
process_identifier:
2620
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00492000
|
success
|
0 |
0
|
1619716380.964375
NtAllocateVirtualMemory
|
process_identifier:
2620
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005a2000
|
success
|
0 |
0
|
1619716381.167375
NtAllocateVirtualMemory
|
process_identifier:
2620
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005a3000
|
success
|
0 |
0
|
1619716381.198375
NtAllocateVirtualMemory
|
process_identifier:
2620
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005db000
|
success
|
0 |
0
|
1619716381.198375
NtAllocateVirtualMemory
|
process_identifier:
2620
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005d7000
|
success
|
0 |
0
|
1619716381.276375
NtAllocateVirtualMemory
|
process_identifier:
2620
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005ac000
|
success
|
0 |
0
|
1619716381.510375
NtAllocateVirtualMemory
|
process_identifier:
2620
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00740000
|
success
|
0 |
0
|
1619716381.635375
NtAllocateVirtualMemory
|
process_identifier:
2620
region_size:
2097152
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x04700000
|
success
|
0 |
0
|
1619716381.635375
NtAllocateVirtualMemory
|
process_identifier:
2620
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x048c0000
|
success
|
0 |
0
|
1619716381.635375
NtAllocateVirtualMemory
|
process_identifier:
2620
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x048c1000
|
success
|
0 |
0
|
1619716381.729375
NtAllocateVirtualMemory
|
process_identifier:
2620
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x048c2000
|
success
|
0 |
0
|
1619716381.885375
NtAllocateVirtualMemory
|
process_identifier:
2620
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005a4000
|
success
|
0 |
0
|
1619716381.885375
NtAllocateVirtualMemory
|
process_identifier:
2620
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005b6000
|
success
|
0 |
0
|
1619716381.964375
NtAllocateVirtualMemory
|
process_identifier:
2620
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00741000
|
success
|
0 |
0
|
1619716381.979375
NtAllocateVirtualMemory
|
process_identifier:
2620
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x048c3000
|
success
|
0 |
0
|
1619716381.995375
NtAllocateVirtualMemory
|
process_identifier:
2620
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x048c4000
|
success
|
0 |
0
|
1619716382.010375
NtAllocateVirtualMemory
|
process_identifier:
2620
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005ca000
|
success
|
0 |
0
|
1619716382.089375
NtAllocateVirtualMemory
|
process_identifier:
2620
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005ba000
|
success
|
0 |
0
|
1619716382.089375
NtAllocateVirtualMemory
|
process_identifier:
2620
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005b7000
|
success
|
0 |
0
|
1619716382.089375
NtAllocateVirtualMemory
|
process_identifier:
2620
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00742000
|
success
|
0 |
0
|
1619716382.354375
NtAllocateVirtualMemory
|
process_identifier:
2620
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005a5000
|
success
|
0 |
0
|
1619716382.385375
NtAllocateVirtualMemory
|
process_identifier:
2620
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005c2000
|
success
|
0 |
0
|
1619716382.542375
NtAllocateVirtualMemory
|
process_identifier:
2620
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005d5000
|
success
|
0 |
0
|
1619716382.651375
NtAllocateVirtualMemory
|
process_identifier:
2620
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005a6000
|
success
|
0 |
0
|
1619716421.026375
NtAllocateVirtualMemory
|
process_identifier:
2620
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005cc000
|
success
|
0 |
0
|
1619716421.104375
NtAllocateVirtualMemory
|
process_identifier:
2620
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005a7000
|
success
|
0 |
0
|
1619716421.120375
NtAllocateVirtualMemory
|
process_identifier:
2620
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00743000
|
success
|
0 |
0
|
1619716421.198375
NtAllocateVirtualMemory
|
process_identifier:
2620
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005aa000
|
success
|
0 |
0
|
1619716421.245375
NtAllocateVirtualMemory
|
process_identifier:
2620
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0049b000
|
success
|
0 |
0
|
1619716421.245375
NtProtectVirtualMemory
|
process_identifier:
2620
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
328192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x04800400
|
failed
|
3221225550 |
0
|
1619716432.682375
NtAllocateVirtualMemory
|
process_identifier:
2620
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00744000
|
success
|
0 |
0
|
1619716432.698375
NtAllocateVirtualMemory
|
process_identifier:
2620
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00745000
|
success
|
0 |
0
|
1619716432.714375
NtAllocateVirtualMemory
|
process_identifier:
2620
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005a8000
|
success
|
0 |
0
|
1619716432.714375
NtAllocateVirtualMemory
|
process_identifier:
2620
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00746000
|
success
|
0 |
0
|
1619716432.729375
NtAllocateVirtualMemory
|
process_identifier:
2620
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00747000
|
success
|
0 |
0
|
1619716432.854375
NtAllocateVirtualMemory
|
process_identifier:
2620
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00748000
|
success
|
0 |
0
|
1619716432.995375
NtAllocateVirtualMemory
|
process_identifier:
2620
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00749000
|
success
|
0 |
0
|
1619716433.057375
NtAllocateVirtualMemory
|
process_identifier:
2620
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0074a000
|
success
|
0 |
0
|
1619716433.057375
NtProtectVirtualMemory
|
process_identifier:
2620
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x04800178
|
failed
|
3221225550 |
0
|
1619716433.057375
NtProtectVirtualMemory
|
process_identifier:
2620
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x048001a0
|
failed
|
3221225550 |
0
|
1619716433.057375
NtProtectVirtualMemory
|
process_identifier:
2620
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x048001c8
|
failed
|
3221225550 |
0
|
1619716433.057375
NtProtectVirtualMemory
|
process_identifier:
2620
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x048001f0
|
failed
|
3221225550 |
0
|
1619716433.057375
NtProtectVirtualMemory
|
process_identifier:
2620
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x04800218
|
failed
|
3221225550 |
0
|
1619716433.057375
NtProtectVirtualMemory
|
process_identifier:
2620
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
11
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x04850f7e
|
failed
|
3221225550 |
0
|
1619716433.057375
NtProtectVirtualMemory
|
process_identifier:
2620
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
11
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x04850f72
|
failed
|
3221225550 |
0
|