| Time & API |
Arguments |
Status |
Return |
Repeated |
1619826881.662279
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
1900544
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x009e0000
|
success
|
0 |
0
|
1619826881.662279
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00b70000
|
success
|
0 |
0
|
1619826882.271279
NtProtectVirtualMemory
|
process_identifier:
2136
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73f31000
|
success
|
0 |
0
|
1619826882.365279
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003ca000
|
success
|
0 |
0
|
1619826882.365279
NtProtectVirtualMemory
|
process_identifier:
2136
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73f32000
|
success
|
0 |
0
|
1619826882.365279
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003c2000
|
success
|
0 |
0
|
1619826882.552279
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003d2000
|
success
|
0 |
0
|
1619826882.646279
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003d3000
|
success
|
0 |
0
|
1619826882.662279
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0040b000
|
success
|
0 |
0
|
1619826882.662279
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00407000
|
success
|
0 |
0
|
1619826882.677279
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003dc000
|
success
|
0 |
0
|
1619826882.755279
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005b0000
|
success
|
0 |
0
|
1619826883.068279
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003d4000
|
success
|
0 |
0
|
1619826883.068279
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003d5000
|
success
|
0 |
0
|
1619826883.115279
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003d6000
|
success
|
0 |
0
|
1619826883.208279
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003ea000
|
success
|
0 |
0
|
1619826883.208279
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003e7000
|
success
|
0 |
0
|
1619826883.208279
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003fa000
|
success
|
0 |
0
|
1619826883.255279
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003cb000
|
success
|
0 |
0
|
1619826883.333279
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003e6000
|
success
|
0 |
0
|
1619826883.396279
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005b1000
|
success
|
0 |
0
|
1619826883.646279
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003f2000
|
success
|
0 |
0
|
1619826883.724279
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00405000
|
success
|
0 |
0
|
1619826916.880279
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00b71000
|
success
|
0 |
0
|
1619826917.037279
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003fc000
|
success
|
0 |
0
|
1619826917.130279
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003d7000
|
success
|
0 |
0
|
1619826917.240279
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005b3000
|
success
|
0 |
0
|
1619826917.240279
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
1376256
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x04eb0000
|
success
|
0 |
0
|
1619826917.240279
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04fc0000
|
success
|
0 |
0
|
1619826917.240279
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04fc1000
|
success
|
0 |
0
|
1619826917.271279
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04fc2000
|
success
|
0 |
0
|
1619826917.287279
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04fc3000
|
success
|
0 |
0
|
1619826917.287279
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04fc4000
|
success
|
0 |
0
|
1619826917.287279
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003d8000
|
success
|
0 |
0
|
1619826917.318279
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005b4000
|
success
|
0 |
0
|
1619826917.318279
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
16384
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04fc6000
|
success
|
0 |
0
|
1619826917.318279
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
69632
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04fca000
|
success
|
0 |
0
|
1619826917.318279
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04fdb000
|
success
|
0 |
0
|
1619826917.318279
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04fdc000
|
success
|
0 |
0
|
1619826917.318279
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04fdd000
|
success
|
0 |
0
|
1619826917.333279
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005b5000
|
success
|
0 |
0
|
1619826937.427279
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04910000
|
success
|
0 |
0
|
1619826937.427279
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003da000
|
success
|
0 |
0
|
1619838450.184876
NtAllocateVirtualMemory
|
process_identifier:
2948
region_size:
1966080
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00d00000
|
success
|
0 |
0
|
1619838450.184876
NtAllocateVirtualMemory
|
process_identifier:
2948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00ea0000
|
success
|
0 |
0
|
1619838450.340876
NtProtectVirtualMemory
|
process_identifier:
2948
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73f31000
|
success
|
0 |
0
|
1619838450.371876
NtAllocateVirtualMemory
|
process_identifier:
2948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003ca000
|
success
|
0 |
0
|
1619838450.371876
NtProtectVirtualMemory
|
process_identifier:
2948
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73f32000
|
success
|
0 |
0
|
1619838450.371876
NtAllocateVirtualMemory
|
process_identifier:
2948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003c2000
|
success
|
0 |
0
|
1619838450.434876
NtAllocateVirtualMemory
|
process_identifier:
2948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003d2000
|
success
|
0 |
0
|