| Time & API |
Arguments |
Status |
Return |
Repeated |
1619826880.661119
NtAllocateVirtualMemory
|
process_identifier:
880
region_size:
17408000
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000ec
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00400000
|
success
|
0 |
0
|
1619826880.661119
NtAllocateVirtualMemory
|
process_identifier:
880
region_size:
1024000
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000ec
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x001e0000
|
success
|
0 |
0
|
1619831167.600875
NtProtectVirtualMemory
|
process_identifier:
884
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000040
base_address:
0x00601000
|
success
|
0 |
0
|
1619831168.2255
NtAllocateVirtualMemory
|
process_identifier:
1424
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000088
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x06c30000
|
success
|
0 |
0
|
1619831169.2415
NtAllocateVirtualMemory
|
process_identifier:
276
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000bc
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00210000
|
success
|
0 |
0
|
1619831169.2885
NtAllocateVirtualMemory
|
process_identifier:
372
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000bc
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00c00000
|
success
|
0 |
0
|
1619831169.2885
NtAllocateVirtualMemory
|
process_identifier:
424
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000bc
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x0a230000
|
success
|
0 |
0
|
1619831169.3035
NtAllocateVirtualMemory
|
process_identifier:
432
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000bc
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00110000
|
success
|
0 |
0
|
1619831169.3195
NtAllocateVirtualMemory
|
process_identifier:
476
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000bc
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00110000
|
success
|
0 |
0
|
1619831169.3195
NtAllocateVirtualMemory
|
process_identifier:
508
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000bc
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x001d0000
|
success
|
0 |
0
|
1619831169.3345
NtAllocateVirtualMemory
|
process_identifier:
536
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000bc
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x009e0000
|
success
|
0 |
0
|
1619831169.3345
NtAllocateVirtualMemory
|
process_identifier:
544
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000bc
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00190000
|
success
|
0 |
0
|
1619831169.3345
NtAllocateVirtualMemory
|
process_identifier:
656
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000bc
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00400000
|
success
|
0 |
0
|
1619831169.3345
NtAllocateVirtualMemory
|
process_identifier:
720
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000bc
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x000d0000
|
success
|
0 |
0
|
1619831169.3345
NtAllocateVirtualMemory
|
process_identifier:
788
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000bc
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x001c0000
|
success
|
0 |
0
|
1619831169.3345
NtAllocateVirtualMemory
|
process_identifier:
868
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000bc
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00e50000
|
success
|
0 |
0
|
1619831169.3345
NtAllocateVirtualMemory
|
process_identifier:
924
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000bc
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00e50000
|
success
|
0 |
0
|
1619831169.3345
NtAllocateVirtualMemory
|
process_identifier:
956
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000bc
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00f70000
|
success
|
0 |
0
|
1619831169.3505
NtAllocateVirtualMemory
|
process_identifier:
540
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000bc
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00d00000
|
success
|
0 |
0
|
1619831169.3505
NtAllocateVirtualMemory
|
process_identifier:
1080
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000bc
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x014f0000
|
success
|
0 |
0
|
1619831169.3505
NtAllocateVirtualMemory
|
process_identifier:
1260
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000bc
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00190000
|
success
|
0 |
0
|
1619831169.3505
NtAllocateVirtualMemory
|
process_identifier:
1288
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000bc
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00180000
|
success
|
0 |
0
|
1619831169.3975
NtAllocateVirtualMemory
|
process_identifier:
1336
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000bc
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00350000
|
success
|
0 |
0
|
1619831169.4135
NtAllocateVirtualMemory
|
process_identifier:
1384
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000bc
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00130000
|
success
|
0 |
0
|
1619831169.4135
NtAllocateVirtualMemory
|
process_identifier:
1424
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x000000bc
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x06c40000
|
success
|
0 |
0
|
1619831169.4135
NtAllocateVirtualMemory
|
process_identifier:
1592
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000110
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x004b0000
|
success
|
0 |
0
|
1619831169.4135
NtAllocateVirtualMemory
|
process_identifier:
1980
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000110
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00190000
|
success
|
0 |
0
|
1619831169.4285
NtAllocateVirtualMemory
|
process_identifier:
1240
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000110
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00370000
|
success
|
0 |
0
|
1619831169.4285
NtAllocateVirtualMemory
|
process_identifier:
2072
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000110
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00120000
|
success
|
0 |
0
|
1619831169.4285
NtAllocateVirtualMemory
|
process_identifier:
2380
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000110
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x04850000
|
success
|
0 |
0
|
1619831169.4445
NtAllocateVirtualMemory
|
process_identifier:
2460
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000110
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00bb0000
|
success
|
0 |
0
|
1619831169.4445
NtAllocateVirtualMemory
|
process_identifier:
2672
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000110
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x003d0000
|
success
|
0 |
0
|
1619831169.4445
NtAllocateVirtualMemory
|
process_identifier:
2744
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000110
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00b60000
|
success
|
0 |
0
|
1619831169.4445
NtAllocateVirtualMemory
|
process_identifier:
2784
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000110
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x007a0000
|
success
|
0 |
0
|
1619831169.4595
NtAllocateVirtualMemory
|
process_identifier:
2884
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000110
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x03e70000
|
success
|
0 |
0
|
1619831169.4595
NtAllocateVirtualMemory
|
process_identifier:
2940
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000110
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00140000
|
success
|
0 |
0
|
1619831169.4595
NtAllocateVirtualMemory
|
process_identifier:
2132
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000110
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x000f0000
|
success
|
0 |
0
|
1619831169.4595
NtAllocateVirtualMemory
|
process_identifier:
2272
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000110
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x005a0000
|
success
|
0 |
0
|
1619831169.4595
NtAllocateVirtualMemory
|
process_identifier:
376
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000110
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00580000
|
success
|
0 |
0
|
1619831169.4595
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000110
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00d30000
|
success
|
0 |
0
|
1619831169.4755
NtAllocateVirtualMemory
|
process_identifier:
2620
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000110
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x022c0000
|
success
|
0 |
0
|
1619831169.4755
NtAllocateVirtualMemory
|
process_identifier:
880
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000110
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x014e0000
|
success
|
0 |
0
|
1619831169.4755
NtAllocateVirtualMemory
|
process_identifier:
1912
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000110
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00320000
|
success
|
0 |
0
|
1619831170.1785
NtAllocateVirtualMemory
|
process_identifier:
884
region_size:
24576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000110
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00440000
|
success
|
0 |
0
|