| Time & API |
Arguments |
Status |
Return |
Repeated |
1619790866.172874
NtAllocateVirtualMemory
|
process_identifier:
2264
region_size:
655360
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00540000
|
success
|
0 |
0
|
1619790866.172874
NtAllocateVirtualMemory
|
process_identifier:
2264
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005a0000
|
success
|
0 |
0
|
1619790867.125874
NtProtectVirtualMemory
|
process_identifier:
2264
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73f31000
|
success
|
0 |
0
|
1619790867.329874
NtAllocateVirtualMemory
|
process_identifier:
2264
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0054a000
|
success
|
0 |
0
|
1619790867.329874
NtProtectVirtualMemory
|
process_identifier:
2264
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73f32000
|
success
|
0 |
0
|
1619790867.329874
NtAllocateVirtualMemory
|
process_identifier:
2264
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00542000
|
success
|
0 |
0
|
1619790867.735874
NtAllocateVirtualMemory
|
process_identifier:
2264
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00552000
|
success
|
0 |
0
|
1619790867.969874
NtAllocateVirtualMemory
|
process_identifier:
2264
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00553000
|
success
|
0 |
0
|
1619790868.000874
NtAllocateVirtualMemory
|
process_identifier:
2264
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0058b000
|
success
|
0 |
0
|
1619790868.000874
NtAllocateVirtualMemory
|
process_identifier:
2264
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00587000
|
success
|
0 |
0
|
1619790868.047874
NtAllocateVirtualMemory
|
process_identifier:
2264
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0055c000
|
success
|
0 |
0
|
1619790868.235874
NtAllocateVirtualMemory
|
process_identifier:
2264
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00b40000
|
success
|
0 |
0
|
1619790868.329874
NtAllocateVirtualMemory
|
process_identifier:
2264
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00b41000
|
success
|
0 |
0
|
1619790868.375874
NtAllocateVirtualMemory
|
process_identifier:
2264
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00554000
|
success
|
0 |
0
|
1619790868.391874
NtAllocateVirtualMemory
|
process_identifier:
2264
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00b42000
|
success
|
0 |
0
|
1619790868.391874
NtAllocateVirtualMemory
|
process_identifier:
2264
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00b43000
|
success
|
0 |
0
|
1619790868.454874
NtAllocateVirtualMemory
|
process_identifier:
2264
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00b44000
|
success
|
0 |
0
|
1619790868.954874
NtAllocateVirtualMemory
|
process_identifier:
2264
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00b45000
|
success
|
0 |
0
|
1619790869.016874
NtAllocateVirtualMemory
|
process_identifier:
2264
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00b46000
|
success
|
0 |
0
|
1619790869.110874
NtAllocateVirtualMemory
|
process_identifier:
2264
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0055a000
|
success
|
0 |
0
|
1619790869.204874
NtAllocateVirtualMemory
|
process_identifier:
2264
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0057a000
|
success
|
0 |
0
|
1619790869.235874
NtAllocateVirtualMemory
|
process_identifier:
2264
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00572000
|
success
|
0 |
0
|
1619790869.266874
NtAllocateVirtualMemory
|
process_identifier:
2264
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00555000
|
success
|
0 |
0
|
1619790869.282874
NtAllocateVirtualMemory
|
process_identifier:
2264
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00585000
|
success
|
0 |
0
|
1619790869.688874
NtAllocateVirtualMemory
|
process_identifier:
2264
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00556000
|
success
|
0 |
0
|
1619790869.719874
NtAllocateVirtualMemory
|
process_identifier:
2264
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00b47000
|
success
|
0 |
0
|
1619790869.735874
NtAllocateVirtualMemory
|
process_identifier:
2264
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0057c000
|
success
|
0 |
0
|
1619790869.797874
NtAllocateVirtualMemory
|
process_identifier:
2264
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00558000
|
success
|
0 |
0
|
1619790869.844874
NtAllocateVirtualMemory
|
process_identifier:
2264
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00b48000
|
success
|
0 |
0
|
1619790869.875874
NtAllocateVirtualMemory
|
process_identifier:
2264
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0056a000
|
success
|
0 |
0
|
1619790869.875874
NtAllocateVirtualMemory
|
process_identifier:
2264
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00567000
|
success
|
0 |
0
|
1619790910.985874
NtAllocateVirtualMemory
|
process_identifier:
2264
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0054b000
|
success
|
0 |
0
|
1619790911.125874
NtAllocateVirtualMemory
|
process_identifier:
2264
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00b49000
|
success
|
0 |
0
|
1619790911.235874
NtAllocateVirtualMemory
|
process_identifier:
2264
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00b4a000
|
success
|
0 |
0
|
1619790911.282874
NtAllocateVirtualMemory
|
process_identifier:
2264
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00566000
|
success
|
0 |
0
|
1619790911.313874
NtAllocateVirtualMemory
|
process_identifier:
2264
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00559000
|
success
|
0 |
0
|
1619790911.313874
NtAllocateVirtualMemory
|
process_identifier:
2264
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00b4b000
|
success
|
0 |
0
|
1619790911.360874
NtAllocateVirtualMemory
|
process_identifier:
2264
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00573000
|
success
|
0 |
0
|
1619790911.375874
NtProtectVirtualMemory
|
process_identifier:
2264
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
244736
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x05470400
|
failed
|
3221225550 |
0
|
1619790917.594874
NtAllocateVirtualMemory
|
process_identifier:
2264
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00b4c000
|
success
|
0 |
0
|
1619790917.594874
NtAllocateVirtualMemory
|
process_identifier:
2264
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04d10000
|
success
|
0 |
0
|
1619790917.594874
NtAllocateVirtualMemory
|
process_identifier:
2264
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00b4d000
|
success
|
0 |
0
|
1619790917.625874
NtAllocateVirtualMemory
|
process_identifier:
2264
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00b4e000
|
success
|
0 |
0
|
1619790917.719874
NtAllocateVirtualMemory
|
process_identifier:
2264
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00b4f000
|
success
|
0 |
0
|
1619790917.860874
NtAllocateVirtualMemory
|
process_identifier:
2264
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04e30000
|
success
|
0 |
0
|
1619790918.063874
NtAllocateVirtualMemory
|
process_identifier:
2264
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04e31000
|
success
|
0 |
0
|
1619790918.329874
NtAllocateVirtualMemory
|
process_identifier:
2264
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04e32000
|
success
|
0 |
0
|
1619790918.344874
NtProtectVirtualMemory
|
process_identifier:
2264
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x05470178
|
failed
|
3221225550 |
0
|
1619790918.344874
NtProtectVirtualMemory
|
process_identifier:
2264
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x054701a0
|
failed
|
3221225550 |
0
|
1619790918.344874
NtProtectVirtualMemory
|
process_identifier:
2264
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x054701c8
|
failed
|
3221225550 |
0
|