| Time & API |
Arguments |
Status |
Return |
Repeated |
1619781470.858625
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
917504
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00240000
|
success
|
0 |
0
|
1619781470.858625
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002e0000
|
success
|
0 |
0
|
1619781471.343625
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
1703936
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x02240000
|
success
|
0 |
0
|
1619781471.343625
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x023a0000
|
success
|
0 |
0
|
1619781471.515625
NtProtectVirtualMemory
|
process_identifier:
1948
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73b91000
|
success
|
0 |
0
|
1619781471.749625
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
2097152
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x023e0000
|
success
|
0 |
0
|
1619781471.749625
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x025a0000
|
success
|
0 |
0
|
1619781471.749625
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002aa000
|
success
|
0 |
0
|
1619781471.749625
NtProtectVirtualMemory
|
process_identifier:
1948
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73b92000
|
success
|
0 |
0
|
1619781471.749625
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002a2000
|
success
|
0 |
0
|
1619781472.077625
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002c2000
|
success
|
0 |
0
|
1619781472.140625
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00325000
|
success
|
0 |
0
|
1619781472.140625
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0032b000
|
success
|
0 |
0
|
1619781472.140625
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00327000
|
success
|
0 |
0
|
1619781472.327625
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002c3000
|
success
|
0 |
0
|
1619781472.343625
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002c4000
|
success
|
0 |
0
|
1619781472.343625
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002cc000
|
success
|
0 |
0
|
1619781472.358625
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00660000
|
success
|
0 |
0
|
1619781472.358625
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002c5000
|
success
|
0 |
0
|
1619781472.358625
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002c6000
|
success
|
0 |
0
|
1619781472.358625
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00661000
|
success
|
0 |
0
|
1619781472.390625
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002c7000
|
success
|
0 |
0
|
1619781472.421625
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002c8000
|
success
|
0 |
0
|
1619781472.421625
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002ac000
|
success
|
0 |
0
|
1619781472.421625
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002c9000
|
success
|
0 |
0
|
1619781472.421625
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002cd000
|
success
|
0 |
0
|
1619781472.436625
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00663000
|
success
|
0 |
0
|
1619781472.452625
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00669000
|
success
|
0 |
0
|
1619781472.468625
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x025a1000
|
success
|
0 |
0
|
1619781472.483625
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x025a2000
|
success
|
0 |
0
|
1619781472.483625
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002a3000
|
success
|
0 |
0
|
1619781472.483625
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00670000
|
success
|
0 |
0
|
1619781472.483625
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002d6000
|
success
|
0 |
0
|
1619781472.499625
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x025a3000
|
success
|
0 |
0
|
1619781472.499625
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x025a4000
|
success
|
0 |
0
|
1619781472.499625
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0066a000
|
success
|
0 |
0
|
1619781472.515625
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
16384
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x025a5000
|
success
|
0 |
0
|
1619781472.515625
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
69632
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x025a9000
|
success
|
0 |
0
|
1619781472.515625
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002da000
|
success
|
0 |
0
|
1619781472.515625
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002d7000
|
success
|
0 |
0
|
1619781472.515625
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0066b000
|
success
|
0 |
0
|
1619781472.530625
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00671000
|
success
|
0 |
0
|
1619781472.530625
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002ce000
|
success
|
0 |
0
|
1619781472.530625
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0066c000
|
success
|
0 |
0
|
1619781472.546625
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0066d000
|
success
|
0 |
0
|
1619781472.546625
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00672000
|
success
|
0 |
0
|
1619781472.546625
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0066e000
|
success
|
0 |
0
|
1619781472.546625
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0066f000
|
success
|
0 |
0
|
1619781472.561625
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00673000
|
success
|
0 |
0
|
1619781472.561625
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00730000
|
success
|
0 |
0
|