| Time & API |
Arguments |
Status |
Return |
Repeated |
1619800313.475751
NtAllocateVirtualMemory
|
process_identifier:
2760
region_size:
28672
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00510000
|
success
|
0 |
0
|
1619800316.710751
NtAllocateVirtualMemory
|
process_identifier:
2760
region_size:
67108864
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x03310000
|
success
|
0 |
0
|
1619800316.757751
NtProtectVirtualMemory
|
process_identifier:
2760
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
876544
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x77d40000
|
success
|
0 |
0
|
1619800317.304374
NtAllocateVirtualMemory
|
process_identifier:
2544
region_size:
28672
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00550000
|
success
|
0 |
0
|
1619800319.913374
NtAllocateVirtualMemory
|
process_identifier:
2544
region_size:
67108864
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x02460000
|
success
|
0 |
0
|
1619800319.929374
NtProtectVirtualMemory
|
process_identifier:
2544
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
876544
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x77d40000
|
success
|
0 |
0
|
1619800328.335374
NtAllocateVirtualMemory
|
process_identifier:
1752
region_size:
28672
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004b0000
|
success
|
0 |
0
|
1619800334.929374
NtAllocateVirtualMemory
|
process_identifier:
1752
region_size:
67108864
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x03600000
|
success
|
0 |
0
|
1619800334.960374
NtProtectVirtualMemory
|
process_identifier:
1752
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
876544
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x77d40000
|
success
|
0 |
0
|
1619800335.335501
NtAllocateVirtualMemory
|
process_identifier:
2256
region_size:
28672
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004a0000
|
success
|
0 |
0
|
1619800339.272501
NtAllocateVirtualMemory
|
process_identifier:
2256
region_size:
67108864
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x02680000
|
success
|
0 |
0
|
1619800339.288501
NtProtectVirtualMemory
|
process_identifier:
2256
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
876544
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x77d40000
|
success
|
0 |
0
|
1619800340.585374
NtAllocateVirtualMemory
|
process_identifier:
1056
region_size:
28672
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002f0000
|
success
|
0 |
0
|
1619800343.569374
NtAllocateVirtualMemory
|
process_identifier:
1056
region_size:
67108864
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x02fe0000
|
success
|
0 |
0
|
1619800343.600374
NtProtectVirtualMemory
|
process_identifier:
1056
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
876544
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x77d40000
|
success
|
0 |
0
|
1619800344.304001
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
28672
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003b0000
|
success
|
0 |
0
|
1619800349.069001
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
67108864
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x02c20000
|
success
|
0 |
0
|
1619800349.085001
NtProtectVirtualMemory
|
process_identifier:
1948
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
876544
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x77d40000
|
success
|
0 |
0
|
1619800350.147876
NtAllocateVirtualMemory
|
process_identifier:
3100
region_size:
28672
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002b0000
|
success
|
0 |
0
|
1619800353.350876
NtAllocateVirtualMemory
|
process_identifier:
3100
region_size:
67108864
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x03020000
|
success
|
0 |
0
|
1619800353.382876
NtProtectVirtualMemory
|
process_identifier:
3100
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
876544
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x77d40000
|
success
|
0 |
0
|
1619800354.444124
NtAllocateVirtualMemory
|
process_identifier:
3220
region_size:
28672
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x01c30000
|
success
|
0 |
0
|
1619800357.647124
NtAllocateVirtualMemory
|
process_identifier:
3220
region_size:
67108864
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x02a70000
|
success
|
0 |
0
|
1619800357.679124
NtProtectVirtualMemory
|
process_identifier:
3220
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
876544
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x77d40000
|
success
|
0 |
0
|
1619800358.882501
NtAllocateVirtualMemory
|
process_identifier:
3344
region_size:
28672
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00390000
|
success
|
0 |
0
|
1619800361.929501
NtAllocateVirtualMemory
|
process_identifier:
3344
region_size:
67108864
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x029f0000
|
success
|
0 |
0
|
1619800361.944501
NtProtectVirtualMemory
|
process_identifier:
3344
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
876544
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x77d40000
|
success
|
0 |
0
|
1619800363.085626
NtAllocateVirtualMemory
|
process_identifier:
3456
region_size:
28672
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00490000
|
success
|
0 |
0
|
1619800366.288626
NtAllocateVirtualMemory
|
process_identifier:
3456
region_size:
67108864
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x02c00000
|
success
|
0 |
0
|
1619800366.304626
NtProtectVirtualMemory
|
process_identifier:
3456
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
876544
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x77d40000
|
success
|
0 |
0
|
1619800367.429751
NtAllocateVirtualMemory
|
process_identifier:
3576
region_size:
28672
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00740000
|
success
|
0 |
0
|
1619800370.569751
NtAllocateVirtualMemory
|
process_identifier:
3576
region_size:
67108864
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x02aa0000
|
success
|
0 |
0
|
1619800370.600751
NtProtectVirtualMemory
|
process_identifier:
3576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
876544
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x77d40000
|
success
|
0 |
0
|
1619800371.725124
NtAllocateVirtualMemory
|
process_identifier:
3704
region_size:
28672
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00390000
|
success
|
0 |
0
|
1619800376.022124
NtAllocateVirtualMemory
|
process_identifier:
3704
region_size:
67108864
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x02cb0000
|
success
|
0 |
0
|
1619800376.085124
NtProtectVirtualMemory
|
process_identifier:
3704
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
876544
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x77d40000
|
success
|
0 |
0
|
1619800378.679374
NtAllocateVirtualMemory
|
process_identifier:
3912
region_size:
28672
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00340000
|
success
|
0 |
0
|