| Time & API |
Arguments |
Status |
Return |
Repeated |
1619826884.392089
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
2293760
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x007e0000
|
success
|
0 |
0
|
1619826884.392089
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x009d0000
|
success
|
0 |
0
|
1619826884.736089
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
1769472
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x01fa0000
|
success
|
0 |
0
|
1619826884.736089
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02110000
|
success
|
0 |
0
|
1619826884.892089
NtProtectVirtualMemory
|
process_identifier:
2296
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73e71000
|
success
|
0 |
0
|
1619826885.158089
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
720896
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x006d0000
|
success
|
0 |
0
|
1619826885.158089
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00740000
|
success
|
0 |
0
|
1619826885.158089
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0058a000
|
success
|
0 |
0
|
1619826885.173089
NtProtectVirtualMemory
|
process_identifier:
2296
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73e72000
|
success
|
0 |
0
|
1619826885.173089
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00582000
|
success
|
0 |
0
|
1619826885.470089
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005d2000
|
success
|
0 |
0
|
1619826885.580089
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005f5000
|
success
|
0 |
0
|
1619826885.580089
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005fb000
|
success
|
0 |
0
|
1619826885.580089
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005f7000
|
success
|
0 |
0
|
1619826885.658089
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005d3000
|
success
|
0 |
0
|
1619826885.689089
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005dc000
|
success
|
0 |
0
|
1619826886.033089
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005d4000
|
success
|
0 |
0
|
1619826886.048089
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005d6000
|
success
|
0 |
0
|
1619826886.142089
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00780000
|
success
|
0 |
0
|
1619826886.220089
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005d7000
|
success
|
0 |
0
|
1619826886.345089
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005e6000
|
success
|
0 |
0
|
1619826886.345089
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005ea000
|
success
|
0 |
0
|
1619826886.345089
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005e7000
|
success
|
0 |
0
|
1619826886.439089
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005d8000
|
success
|
0 |
0
|
1619826886.611089
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00781000
|
success
|
0 |
0
|
1619826886.673089
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00741000
|
success
|
0 |
0
|
1619826886.673089
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00742000
|
success
|
0 |
0
|
1619826886.689089
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00743000
|
success
|
0 |
0
|
1619826886.705089
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005d9000
|
success
|
0 |
0
|
1619826886.720089
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00782000
|
success
|
0 |
0
|
1619826886.736089
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00744000
|
success
|
0 |
0
|
1619826886.736089
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00745000
|
success
|
0 |
0
|
1619826886.767089
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00783000
|
success
|
0 |
0
|
1619826886.767089
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
16384
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00746000
|
success
|
0 |
0
|
1619826886.767089
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
69632
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0074a000
|
success
|
0 |
0
|
1619826886.783089
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005da000
|
success
|
0 |
0
|
1619826887.017089
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x009c0000
|
success
|
0 |
0
|
1619826887.017089
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x009c1000
|
success
|
0 |
0
|
1619826887.189089
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00784000
|
success
|
0 |
0
|
1619826887.298089
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x009c2000
|
success
|
0 |
0
|
1619826887.361089
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x009c3000
|
success
|
0 |
0
|
1619826887.361089
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005dd000
|
success
|
0 |
0
|
1619826887.377089
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
12288
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00785000
|
success
|
0 |
0
|
1619826887.377089
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00788000
|
success
|
0 |
0
|
1619826887.392089
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02111000
|
success
|
0 |
0
|
1619826887.517089
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x009c4000
|
success
|
0 |
0
|
1619826887.517089
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00789000
|
success
|
0 |
0
|
1619826887.517089
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0075b000
|
success
|
0 |
0
|
1619826887.517089
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0075c000
|
success
|
0 |
0
|
1619826887.533089
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0075d000
|
success
|
0 |
0
|