| Time & API |
Arguments |
Status |
Return |
Repeated |
1619800109.414501
NtAllocateVirtualMemory
|
process_identifier:
1704
region_size:
1572864
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00950000
|
success
|
0 |
0
|
1619800109.429501
NtAllocateVirtualMemory
|
process_identifier:
1704
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00a90000
|
success
|
0 |
0
|
1619800109.758501
NtAllocateVirtualMemory
|
process_identifier:
1704
region_size:
851968
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x004f0000
|
success
|
0 |
0
|
1619800109.758501
NtAllocateVirtualMemory
|
process_identifier:
1704
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00580000
|
success
|
0 |
0
|
1619800109.914501
NtProtectVirtualMemory
|
process_identifier:
1704
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73e71000
|
success
|
0 |
0
|
1619800110.164501
NtAllocateVirtualMemory
|
process_identifier:
1704
region_size:
262144
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x004f0000
|
success
|
0 |
0
|
1619800110.164501
NtAllocateVirtualMemory
|
process_identifier:
1704
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004f0000
|
success
|
0 |
0
|
1619800110.179501
NtAllocateVirtualMemory
|
process_identifier:
1704
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0037a000
|
success
|
0 |
0
|
1619800110.179501
NtProtectVirtualMemory
|
process_identifier:
1704
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73e72000
|
success
|
0 |
0
|
1619800110.179501
NtAllocateVirtualMemory
|
process_identifier:
1704
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00372000
|
success
|
0 |
0
|
1619800110.601501
NtAllocateVirtualMemory
|
process_identifier:
1704
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00392000
|
success
|
0 |
0
|
1619800110.820501
NtAllocateVirtualMemory
|
process_identifier:
1704
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003b5000
|
success
|
0 |
0
|
1619800110.820501
NtAllocateVirtualMemory
|
process_identifier:
1704
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003bb000
|
success
|
0 |
0
|
1619800110.820501
NtAllocateVirtualMemory
|
process_identifier:
1704
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003b7000
|
success
|
0 |
0
|
1619800111.070501
NtAllocateVirtualMemory
|
process_identifier:
1704
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00393000
|
success
|
0 |
0
|
1619800111.164501
NtAllocateVirtualMemory
|
process_identifier:
1704
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0039c000
|
success
|
0 |
0
|
1619800111.258501
NtAllocateVirtualMemory
|
process_identifier:
1704
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00620000
|
success
|
0 |
0
|
1619800111.648501
NtAllocateVirtualMemory
|
process_identifier:
1704
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00394000
|
success
|
0 |
0
|
1619800111.648501
NtAllocateVirtualMemory
|
process_identifier:
1704
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00396000
|
success
|
0 |
0
|
1619800111.742501
NtAllocateVirtualMemory
|
process_identifier:
1704
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00397000
|
success
|
0 |
0
|
1619800111.742501
NtAllocateVirtualMemory
|
process_identifier:
1704
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00398000
|
success
|
0 |
0
|
1619800111.742501
NtAllocateVirtualMemory
|
process_identifier:
1704
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00399000
|
success
|
0 |
0
|
1619800111.789501
NtAllocateVirtualMemory
|
process_identifier:
1704
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003aa000
|
success
|
0 |
0
|
1619800111.789501
NtAllocateVirtualMemory
|
process_identifier:
1704
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003a7000
|
success
|
0 |
0
|
1619800111.945501
NtAllocateVirtualMemory
|
process_identifier:
1704
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003a6000
|
success
|
0 |
0
|
1619800112.008501
NtAllocateVirtualMemory
|
process_identifier:
1704
region_size:
12288
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00621000
|
success
|
0 |
0
|
1619800112.273501
NtAllocateVirtualMemory
|
process_identifier:
1704
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0039a000
|
success
|
0 |
0
|
1619800112.445501
NtAllocateVirtualMemory
|
process_identifier:
1704
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00800000
|
success
|
0 |
0
|
1619800112.445501
NtAllocateVirtualMemory
|
process_identifier:
1704
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00801000
|
success
|
0 |
0
|
1619800112.476501
NtAllocateVirtualMemory
|
process_identifier:
1704
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00624000
|
success
|
0 |
0
|
1619800112.851501
NtAllocateVirtualMemory
|
process_identifier:
1704
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00802000
|
success
|
0 |
0
|
1619800112.898501
NtAllocateVirtualMemory
|
process_identifier:
1704
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00625000
|
success
|
0 |
0
|
1619800112.914501
NtAllocateVirtualMemory
|
process_identifier:
1704
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00803000
|
success
|
0 |
0
|
1619800112.945501
NtAllocateVirtualMemory
|
process_identifier:
1704
region_size:
12288
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00626000
|
success
|
0 |
0
|
1619800112.961501
NtAllocateVirtualMemory
|
process_identifier:
1704
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00804000
|
success
|
0 |
0
|
1619800112.976501
NtAllocateVirtualMemory
|
process_identifier:
1704
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00629000
|
success
|
0 |
0
|
1619800153.976501
NtAllocateVirtualMemory
|
process_identifier:
1704
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0039d000
|
success
|
0 |
0
|
1619800153.976501
NtAllocateVirtualMemory
|
process_identifier:
1704
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0062a000
|
success
|
0 |
0
|
1619800153.992501
NtAllocateVirtualMemory
|
process_identifier:
1704
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00581000
|
success
|
0 |
0
|
1619800154.070501
NtAllocateVirtualMemory
|
process_identifier:
1704
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0062b000
|
success
|
0 |
0
|
1619800154.148501
NtAllocateVirtualMemory
|
process_identifier:
1704
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0037c000
|
success
|
0 |
0
|
1619800154.179501
NtAllocateVirtualMemory
|
process_identifier:
1704
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0062c000
|
success
|
0 |
0
|
1619800154.258501
NtAllocateVirtualMemory
|
process_identifier:
1704
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00805000
|
success
|
0 |
0
|
1619800154.273501
NtAllocateVirtualMemory
|
process_identifier:
1704
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0062d000
|
success
|
0 |
0
|
1619800154.461501
NtProtectVirtualMemory
|
process_identifier:
1704
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
301056
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x05090400
|
failed
|
3221225550 |
0
|
1619800165.414501
NtAllocateVirtualMemory
|
process_identifier:
1704
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0062f000
|
success
|
0 |
0
|
1619800165.414501
NtAllocateVirtualMemory
|
process_identifier:
1704
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00806000
|
success
|
0 |
0
|
1619800165.429501
NtAllocateVirtualMemory
|
process_identifier:
1704
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04fe0000
|
success
|
0 |
0
|
1619800165.445501
NtAllocateVirtualMemory
|
process_identifier:
1704
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04fe1000
|
success
|
0 |
0
|
1619800165.523501
NtAllocateVirtualMemory
|
process_identifier:
1704
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04fe2000
|
success
|
0 |
0
|