| Time & API |
Arguments |
Status |
Return |
Repeated |
1619826881.552279
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
589824
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x004b0000
|
success
|
0 |
0
|
1619826881.552279
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00500000
|
success
|
0 |
0
|
1619826881.865279
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
917504
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x005c0000
|
success
|
0 |
0
|
1619826881.865279
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00660000
|
success
|
0 |
0
|
1619826882.052279
NtProtectVirtualMemory
|
process_identifier:
2404
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73e71000
|
success
|
0 |
0
|
1619826882.349279
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
2293760
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x02290000
|
success
|
0 |
0
|
1619826882.349279
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02480000
|
success
|
0 |
0
|
1619826882.365279
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005ea000
|
success
|
0 |
0
|
1619826882.365279
NtProtectVirtualMemory
|
process_identifier:
2404
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73e72000
|
success
|
0 |
0
|
1619826882.365279
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005e2000
|
success
|
0 |
0
|
1619826882.880279
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005f2000
|
success
|
0 |
0
|
1619826882.974279
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00615000
|
success
|
0 |
0
|
1619826882.974279
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0061b000
|
success
|
0 |
0
|
1619826882.974279
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00617000
|
success
|
0 |
0
|
1619826883.068279
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005f3000
|
success
|
0 |
0
|
1619826883.099279
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005fc000
|
success
|
0 |
0
|
1619826883.443279
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005f4000
|
success
|
0 |
0
|
1619826883.458279
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005f6000
|
success
|
0 |
0
|
1619826883.568279
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00920000
|
success
|
0 |
0
|
1619826883.693279
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005f7000
|
success
|
0 |
0
|
1619826883.708279
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00606000
|
success
|
0 |
0
|
1619826883.708279
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0060a000
|
success
|
0 |
0
|
1619826883.708279
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00607000
|
success
|
0 |
0
|
1619826883.771279
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005f8000
|
success
|
0 |
0
|
1619826884.161279
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
12288
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00921000
|
success
|
0 |
0
|
1619826884.318279
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00924000
|
success
|
0 |
0
|
1619826884.318279
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00925000
|
success
|
0 |
0
|
1619826884.380279
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005f9000
|
success
|
0 |
0
|
1619826884.411279
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x009c0000
|
success
|
0 |
0
|
1619826925.974279
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00926000
|
success
|
0 |
0
|
1619826926.005279
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00661000
|
success
|
0 |
0
|
1619826926.083279
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00927000
|
success
|
0 |
0
|
1619826926.365279
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x009c1000
|
success
|
0 |
0
|
1619826926.365279
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005ec000
|
success
|
0 |
0
|
1619826926.583279
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00928000
|
success
|
0 |
0
|
1619826926.583279
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x009c2000
|
success
|
0 |
0
|
1619826926.599279
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00929000
|
success
|
0 |
0
|
1619826926.693279
NtProtectVirtualMemory
|
process_identifier:
2404
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
1155072
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x05c10400
|
failed
|
3221225550 |
0
|
1619826948.786279
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0092a000
|
success
|
0 |
0
|
1619826948.974279
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0092b000
|
success
|
0 |
0
|
1619826948.974279
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0092c000
|
success
|
0 |
0
|
1619826949.005279
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0092d000
|
success
|
0 |
0
|
1619826949.005279
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0092e000
|
success
|
0 |
0
|
1619826949.161279
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x009c3000
|
success
|
0 |
0
|
1619826949.161279
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0092f000
|
success
|
0 |
0
|
1619826949.208279
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x008a0000
|
success
|
0 |
0
|
1619826949.208279
NtAllocateVirtualMemory
|
process_identifier:
2404
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x008a1000
|
success
|
0 |
0
|
1619826949.208279
NtProtectVirtualMemory
|
process_identifier:
2404
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x05c10178
|
failed
|
3221225550 |
0
|
1619826949.208279
NtProtectVirtualMemory
|
process_identifier:
2404
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x05c101a0
|
failed
|
3221225550 |
0
|
1619826949.208279
NtProtectVirtualMemory
|
process_identifier:
2404
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x05c101c8
|
failed
|
3221225550 |
0
|