| Time & API |
Arguments |
Status |
Return |
Repeated |
1619826880.305103
NtAllocateVirtualMemory
|
process_identifier:
2560
region_size:
1310720
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00850000
|
success
|
0 |
0
|
1619826880.305103
NtAllocateVirtualMemory
|
process_identifier:
2560
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00950000
|
success
|
0 |
0
|
1619826881.070103
NtProtectVirtualMemory
|
process_identifier:
2560
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73f31000
|
success
|
0 |
0
|
1619826881.195103
NtAllocateVirtualMemory
|
process_identifier:
2560
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0038a000
|
success
|
0 |
0
|
1619826881.195103
NtProtectVirtualMemory
|
process_identifier:
2560
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73f32000
|
success
|
0 |
0
|
1619826881.195103
NtAllocateVirtualMemory
|
process_identifier:
2560
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00382000
|
success
|
0 |
0
|
1619826881.383103
NtAllocateVirtualMemory
|
process_identifier:
2560
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00392000
|
success
|
0 |
0
|
1619826881.461103
NtAllocateVirtualMemory
|
process_identifier:
2560
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00393000
|
success
|
0 |
0
|
1619826881.477103
NtAllocateVirtualMemory
|
process_identifier:
2560
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003cb000
|
success
|
0 |
0
|
1619826881.477103
NtAllocateVirtualMemory
|
process_identifier:
2560
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003c7000
|
success
|
0 |
0
|
1619826881.508103
NtAllocateVirtualMemory
|
process_identifier:
2560
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0039c000
|
success
|
0 |
0
|
1619826881.867103
NtAllocateVirtualMemory
|
process_identifier:
2560
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00394000
|
success
|
0 |
0
|
1619826881.867103
NtAllocateVirtualMemory
|
process_identifier:
2560
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00395000
|
success
|
0 |
0
|
1619826881.914103
NtAllocateVirtualMemory
|
process_identifier:
2560
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00396000
|
success
|
0 |
0
|
1619826881.914103
NtAllocateVirtualMemory
|
process_identifier:
2560
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005b0000
|
success
|
0 |
0
|
1619826882.070103
NtAllocateVirtualMemory
|
process_identifier:
2560
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003aa000
|
success
|
0 |
0
|
1619826882.070103
NtAllocateVirtualMemory
|
process_identifier:
2560
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003a7000
|
success
|
0 |
0
|
1619826882.070103
NtAllocateVirtualMemory
|
process_identifier:
2560
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003ba000
|
success
|
0 |
0
|
1619826882.086103
NtAllocateVirtualMemory
|
process_identifier:
2560
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0038b000
|
success
|
0 |
0
|
1619826882.133103
NtAllocateVirtualMemory
|
process_identifier:
2560
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003a6000
|
success
|
0 |
0
|
1619826882.195103
NtAllocateVirtualMemory
|
process_identifier:
2560
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005b1000
|
success
|
0 |
0
|
1619826882.555103
NtAllocateVirtualMemory
|
process_identifier:
2560
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x008d0000
|
success
|
0 |
0
|
1619826882.633103
NtAllocateVirtualMemory
|
process_identifier:
2560
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0039a000
|
success
|
0 |
0
|
1619826882.867103
NtAllocateVirtualMemory
|
process_identifier:
2560
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003b2000
|
success
|
0 |
0
|
1619826882.914103
NtAllocateVirtualMemory
|
process_identifier:
2560
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003c5000
|
success
|
0 |
0
|
1619826883.039103
NtAllocateVirtualMemory
|
process_identifier:
2560
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00397000
|
success
|
0 |
0
|
1619826921.133103
NtAllocateVirtualMemory
|
process_identifier:
2560
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00951000
|
success
|
0 |
0
|
1619826921.211103
NtAllocateVirtualMemory
|
process_identifier:
2560
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005b3000
|
success
|
0 |
0
|
1619826921.320103
NtAllocateVirtualMemory
|
process_identifier:
2560
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003bc000
|
success
|
0 |
0
|
1619826921.398103
NtAllocateVirtualMemory
|
process_identifier:
2560
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00398000
|
success
|
0 |
0
|
1619826921.414103
NtAllocateVirtualMemory
|
process_identifier:
2560
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005b4000
|
success
|
0 |
0
|
1619826921.523103
NtProtectVirtualMemory
|
process_identifier:
2560
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
282112
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x05a10400
|
failed
|
3221225550 |
0
|
1619826927.070103
NtAllocateVirtualMemory
|
process_identifier:
2560
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005b5000
|
success
|
0 |
0
|
1619826927.070103
NtAllocateVirtualMemory
|
process_identifier:
2560
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005b6000
|
success
|
0 |
0
|
1619826927.086103
NtAllocateVirtualMemory
|
process_identifier:
2560
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00399000
|
success
|
0 |
0
|
1619826927.102103
NtAllocateVirtualMemory
|
process_identifier:
2560
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005b7000
|
success
|
0 |
0
|
1619826927.273103
NtAllocateVirtualMemory
|
process_identifier:
2560
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005b8000
|
success
|
0 |
0
|
1619826927.305103
NtAllocateVirtualMemory
|
process_identifier:
2560
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005b9000
|
success
|
0 |
0
|
1619826927.398103
NtAllocateVirtualMemory
|
process_identifier:
2560
region_size:
12288
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005ba000
|
success
|
0 |
0
|
1619826927.430103
NtProtectVirtualMemory
|
process_identifier:
2560
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x05a10178
|
failed
|
3221225550 |
0
|
1619826927.430103
NtProtectVirtualMemory
|
process_identifier:
2560
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x05a101a0
|
failed
|
3221225550 |
0
|
1619826927.430103
NtProtectVirtualMemory
|
process_identifier:
2560
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x05a101c8
|
failed
|
3221225550 |
0
|
1619826927.430103
NtProtectVirtualMemory
|
process_identifier:
2560
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x05a101f0
|
failed
|
3221225550 |
0
|
1619826927.430103
NtProtectVirtualMemory
|
process_identifier:
2560
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x05a10218
|
failed
|
3221225550 |
0
|
1619826927.430103
NtProtectVirtualMemory
|
process_identifier:
2560
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
11
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x05a55b2e
|
failed
|
3221225550 |
0
|
1619826927.430103
NtProtectVirtualMemory
|
process_identifier:
2560
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
11
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x05a55b22
|
failed
|
3221225550 |
0
|
1619826927.430103
NtProtectVirtualMemory
|
process_identifier:
2560
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
72
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x05a55200
|
failed
|
3221225550 |
0
|
1619826927.430103
NtProtectVirtualMemory
|
process_identifier:
2560
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x05a55b3c
|
failed
|
3221225550 |
0
|
1619826927.430103
NtProtectVirtualMemory
|
process_identifier:
2560
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x05a55b60
|
failed
|
3221225550 |
0
|
1619826927.430103
NtProtectVirtualMemory
|
process_identifier:
2560
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x05a55b68
|
failed
|
3221225550 |
0
|