| Time & API |
Arguments |
Status |
Return |
Repeated |
1619826883.230865
NtAllocateVirtualMemory
|
process_identifier:
2056
region_size:
2293760
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00c30000
|
success
|
0 |
0
|
1619826883.230865
NtAllocateVirtualMemory
|
process_identifier:
2056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00e20000
|
success
|
0 |
0
|
1619826883.683865
NtAllocateVirtualMemory
|
process_identifier:
2056
region_size:
2228224
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x02260000
|
success
|
0 |
0
|
1619826883.683865
NtAllocateVirtualMemory
|
process_identifier:
2056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02440000
|
success
|
0 |
0
|
1619826883.870865
NtProtectVirtualMemory
|
process_identifier:
2056
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73e71000
|
success
|
0 |
0
|
1619826884.042865
NtAllocateVirtualMemory
|
process_identifier:
2056
region_size:
851968
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00a30000
|
success
|
0 |
0
|
1619826884.042865
NtAllocateVirtualMemory
|
process_identifier:
2056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00ac0000
|
success
|
0 |
0
|
1619826884.058865
NtAllocateVirtualMemory
|
process_identifier:
2056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002ca000
|
success
|
0 |
0
|
1619826884.058865
NtProtectVirtualMemory
|
process_identifier:
2056
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73e72000
|
success
|
0 |
0
|
1619826884.058865
NtAllocateVirtualMemory
|
process_identifier:
2056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002c2000
|
success
|
0 |
0
|
1619826884.558865
NtAllocateVirtualMemory
|
process_identifier:
2056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002d2000
|
success
|
0 |
0
|
1619826884.636865
NtAllocateVirtualMemory
|
process_identifier:
2056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002f5000
|
success
|
0 |
0
|
1619826884.651865
NtAllocateVirtualMemory
|
process_identifier:
2056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002fb000
|
success
|
0 |
0
|
1619826884.651865
NtAllocateVirtualMemory
|
process_identifier:
2056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002f7000
|
success
|
0 |
0
|
1619826884.730865
NtAllocateVirtualMemory
|
process_identifier:
2056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002d3000
|
success
|
0 |
0
|
1619826884.776865
NtAllocateVirtualMemory
|
process_identifier:
2056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002dc000
|
success
|
0 |
0
|
1619826885.167865
NtAllocateVirtualMemory
|
process_identifier:
2056
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002d4000
|
success
|
0 |
0
|
1619826885.183865
NtAllocateVirtualMemory
|
process_identifier:
2056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002d6000
|
success
|
0 |
0
|
1619826885.276865
NtAllocateVirtualMemory
|
process_identifier:
2056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00a60000
|
success
|
0 |
0
|
1619826885.433865
NtAllocateVirtualMemory
|
process_identifier:
2056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002ea000
|
success
|
0 |
0
|
1619826885.433865
NtAllocateVirtualMemory
|
process_identifier:
2056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002e7000
|
success
|
0 |
0
|
1619826885.636865
NtAllocateVirtualMemory
|
process_identifier:
2056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002d7000
|
success
|
0 |
0
|
1619826885.651865
NtAllocateVirtualMemory
|
process_identifier:
2056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00ac1000
|
success
|
0 |
0
|
1619826885.667865
NtAllocateVirtualMemory
|
process_identifier:
2056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00ac2000
|
success
|
0 |
0
|
1619826885.714865
NtAllocateVirtualMemory
|
process_identifier:
2056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002e6000
|
success
|
0 |
0
|
1619826885.714865
NtAllocateVirtualMemory
|
process_identifier:
2056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00a61000
|
success
|
0 |
0
|
1619826885.730865
NtAllocateVirtualMemory
|
process_identifier:
2056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00ac3000
|
success
|
0 |
0
|
1619826885.730865
NtAllocateVirtualMemory
|
process_identifier:
2056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00ac4000
|
success
|
0 |
0
|
1619826885.745865
NtAllocateVirtualMemory
|
process_identifier:
2056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00ac5000
|
success
|
0 |
0
|
1619826885.745865
NtAllocateVirtualMemory
|
process_identifier:
2056
region_size:
16384
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00ac6000
|
success
|
0 |
0
|
1619826885.745865
NtAllocateVirtualMemory
|
process_identifier:
2056
region_size:
69632
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00aca000
|
success
|
0 |
0
|
1619826885.776865
NtAllocateVirtualMemory
|
process_identifier:
2056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00a62000
|
success
|
0 |
0
|
1619826885.870865
NtAllocateVirtualMemory
|
process_identifier:
2056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002d8000
|
success
|
0 |
0
|
1619826885.870865
NtAllocateVirtualMemory
|
process_identifier:
2056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002d9000
|
success
|
0 |
0
|
1619826885.980865
NtAllocateVirtualMemory
|
process_identifier:
2056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00ab0000
|
success
|
0 |
0
|
1619826885.995865
NtAllocateVirtualMemory
|
process_identifier:
2056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00a63000
|
success
|
0 |
0
|
1619826886.261865
NtAllocateVirtualMemory
|
process_identifier:
2056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00ab1000
|
success
|
0 |
0
|
1619826886.261865
NtAllocateVirtualMemory
|
process_identifier:
2056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00ab2000
|
success
|
0 |
0
|
1619826886.261865
NtAllocateVirtualMemory
|
process_identifier:
2056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00a64000
|
success
|
0 |
0
|
1619826886.276865
NtAllocateVirtualMemory
|
process_identifier:
2056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00adb000
|
success
|
0 |
0
|
1619826886.276865
NtAllocateVirtualMemory
|
process_identifier:
2056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00adc000
|
success
|
0 |
0
|
1619826886.276865
NtAllocateVirtualMemory
|
process_identifier:
2056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00add000
|
success
|
0 |
0
|
1619826886.276865
NtAllocateVirtualMemory
|
process_identifier:
2056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00ade000
|
success
|
0 |
0
|
1619826886.276865
NtAllocateVirtualMemory
|
process_identifier:
2056
region_size:
12288
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00adf000
|
success
|
0 |
0
|
1619826886.276865
NtAllocateVirtualMemory
|
process_identifier:
2056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00ab3000
|
success
|
0 |
0
|
1619826886.292865
NtAllocateVirtualMemory
|
process_identifier:
2056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00a65000
|
success
|
0 |
0
|
1619826886.292865
NtAllocateVirtualMemory
|
process_identifier:
2056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00ae2000
|
success
|
0 |
0
|
1619826886.292865
NtAllocateVirtualMemory
|
process_identifier:
2056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00a66000
|
success
|
0 |
0
|
1619826886.401865
NtAllocateVirtualMemory
|
process_identifier:
2056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00a67000
|
success
|
0 |
0
|
1619826886.495865
NtAllocateVirtualMemory
|
process_identifier:
2056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00ab4000
|
success
|
0 |
0
|