| Time & API |
Arguments |
Status |
Return |
Repeated |
1619807150.986999
NtAllocateVirtualMemory
|
process_identifier:
2856
region_size:
2097152
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x007e0000
|
success
|
0 |
0
|
1619807150.986999
NtAllocateVirtualMemory
|
process_identifier:
2856
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x009a0000
|
success
|
0 |
0
|
1619807151.846999
NtAllocateVirtualMemory
|
process_identifier:
2856
region_size:
917504
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x006f0000
|
success
|
0 |
0
|
1619807151.846999
NtAllocateVirtualMemory
|
process_identifier:
2856
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00790000
|
success
|
0 |
0
|
1619807151.877999
NtProtectVirtualMemory
|
process_identifier:
2856
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73b91000
|
success
|
0 |
0
|
1619807152.111999
NtAllocateVirtualMemory
|
process_identifier:
2856
region_size:
1507328
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x01f70000
|
success
|
0 |
0
|
1619807152.111999
NtAllocateVirtualMemory
|
process_identifier:
2856
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x020a0000
|
success
|
0 |
0
|
1619807152.111999
NtAllocateVirtualMemory
|
process_identifier:
2856
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004ba000
|
success
|
0 |
0
|
1619807152.111999
NtProtectVirtualMemory
|
process_identifier:
2856
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73b92000
|
success
|
0 |
0
|
1619807152.111999
NtAllocateVirtualMemory
|
process_identifier:
2856
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004b2000
|
success
|
0 |
0
|
1619807152.408999
NtAllocateVirtualMemory
|
process_identifier:
2856
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004c2000
|
success
|
0 |
0
|
1619807152.549999
NtAllocateVirtualMemory
|
process_identifier:
2856
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004f5000
|
success
|
0 |
0
|
1619807152.564999
NtAllocateVirtualMemory
|
process_identifier:
2856
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004fb000
|
success
|
0 |
0
|
1619807152.564999
NtAllocateVirtualMemory
|
process_identifier:
2856
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004f7000
|
success
|
0 |
0
|
1619807152.877999
NtAllocateVirtualMemory
|
process_identifier:
2856
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004c3000
|
success
|
0 |
0
|
1619807152.939999
NtAllocateVirtualMemory
|
process_identifier:
2856
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004cc000
|
success
|
0 |
0
|
1619807157.080999
NtAllocateVirtualMemory
|
process_identifier:
2856
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004c4000
|
success
|
0 |
0
|
1619807157.111999
NtAllocateVirtualMemory
|
process_identifier:
2856
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004c6000
|
success
|
0 |
0
|
1619807157.236999
NtAllocateVirtualMemory
|
process_identifier:
2856
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00990000
|
success
|
0 |
0
|
1619807157.346999
NtAllocateVirtualMemory
|
process_identifier:
2856
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004ea000
|
success
|
0 |
0
|
1619807157.346999
NtAllocateVirtualMemory
|
process_identifier:
2856
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004e7000
|
success
|
0 |
0
|
1619807157.471999
NtAllocateVirtualMemory
|
process_identifier:
2856
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004e6000
|
success
|
0 |
0
|
1619807157.518999
NtAllocateVirtualMemory
|
process_identifier:
2856
region_size:
16384
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00991000
|
success
|
0 |
0
|
1619807158.080999
NtAllocateVirtualMemory
|
process_identifier:
2856
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004ca000
|
success
|
0 |
0
|
1619807158.502999
NtAllocateVirtualMemory
|
process_identifier:
2856
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004c7000
|
success
|
0 |
0
|
1619807191.533999
NtAllocateVirtualMemory
|
process_identifier:
2856
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00791000
|
success
|
0 |
0
|
1619807191.955999
NtAllocateVirtualMemory
|
process_identifier:
2856
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004bc000
|
success
|
0 |
0
|
1619807191.955999
NtAllocateVirtualMemory
|
process_identifier:
2856
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00995000
|
success
|
0 |
0
|
1619807192.736999
NtAllocateVirtualMemory
|
process_identifier:
2856
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004c8000
|
success
|
0 |
0
|
1619807193.314999
NtAllocateVirtualMemory
|
process_identifier:
2856
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004c9000
|
success
|
0 |
0
|
1619807193.314999
NtAllocateVirtualMemory
|
process_identifier:
2856
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04d10000
|
success
|
0 |
0
|
1619807193.377999
NtAllocateVirtualMemory
|
process_identifier:
2856
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04d11000
|
success
|
0 |
0
|
1619807193.424999
NtAllocateVirtualMemory
|
process_identifier:
2856
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00996000
|
success
|
0 |
0
|
1619807193.455999
NtAllocateVirtualMemory
|
process_identifier:
2856
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04d12000
|
success
|
0 |
0
|
1619807193.455999
NtAllocateVirtualMemory
|
process_identifier:
2856
region_size:
12288
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00997000
|
success
|
0 |
0
|
1619807193.486999
NtAllocateVirtualMemory
|
process_identifier:
2856
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0099a000
|
success
|
0 |
0
|
1619807193.658999
NtProtectVirtualMemory
|
process_identifier:
2856
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
341504
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x06040400
|
failed
|
3221225550 |
0
|
1619807197.189999
NtAllocateVirtualMemory
|
process_identifier:
2856
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0099b000
|
success
|
0 |
0
|
1619807197.205999
NtAllocateVirtualMemory
|
process_identifier:
2856
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04d13000
|
success
|
0 |
0
|
1619807197.205999
NtAllocateVirtualMemory
|
process_identifier:
2856
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004cd000
|
success
|
0 |
0
|
1619807197.205999
NtAllocateVirtualMemory
|
process_identifier:
2856
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0099c000
|
success
|
0 |
0
|
1619807197.221999
NtAllocateVirtualMemory
|
process_identifier:
2856
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0099d000
|
success
|
0 |
0
|
1619807197.221999
NtAllocateVirtualMemory
|
process_identifier:
2856
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0099e000
|
success
|
0 |
0
|
1619807197.252999
NtAllocateVirtualMemory
|
process_identifier:
2856
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0099f000
|
success
|
0 |
0
|
1619807197.596999
NtAllocateVirtualMemory
|
process_identifier:
2856
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04de0000
|
success
|
0 |
0
|
1619807197.674999
NtAllocateVirtualMemory
|
process_identifier:
2856
region_size:
12288
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04de1000
|
success
|
0 |
0
|
1619807197.674999
NtProtectVirtualMemory
|
process_identifier:
2856
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x06040178
|
failed
|
3221225550 |
0
|
1619807197.674999
NtProtectVirtualMemory
|
process_identifier:
2856
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x060401a0
|
failed
|
3221225550 |
0
|
1619807197.674999
NtProtectVirtualMemory
|
process_identifier:
2856
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x060401c8
|
failed
|
3221225550 |
0
|
1619807197.674999
NtProtectVirtualMemory
|
process_identifier:
2856
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x060401f0
|
failed
|
3221225550 |
0
|