| Time & API |
Arguments |
Status |
Return |
Repeated |
1619861117.744662
NtAllocateVirtualMemory
|
process_identifier:
3056
region_size:
1048576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00720000
|
success
|
0 |
0
|
1619861117.744662
NtAllocateVirtualMemory
|
process_identifier:
3056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x007e0000
|
success
|
0 |
0
|
1619861118.229662
NtAllocateVirtualMemory
|
process_identifier:
3056
region_size:
2031616
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x02040000
|
success
|
0 |
0
|
1619861118.229662
NtAllocateVirtualMemory
|
process_identifier:
3056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x021f0000
|
success
|
0 |
0
|
1619861118.400662
NtProtectVirtualMemory
|
process_identifier:
3056
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73e71000
|
success
|
0 |
0
|
1619861118.541662
NtAllocateVirtualMemory
|
process_identifier:
3056
region_size:
524288
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00580000
|
success
|
0 |
0
|
1619861118.541662
NtAllocateVirtualMemory
|
process_identifier:
3056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005c0000
|
success
|
0 |
0
|
1619861118.541662
NtAllocateVirtualMemory
|
process_identifier:
3056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0041a000
|
success
|
0 |
0
|
1619861118.541662
NtProtectVirtualMemory
|
process_identifier:
3056
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73e72000
|
success
|
0 |
0
|
1619861118.541662
NtAllocateVirtualMemory
|
process_identifier:
3056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00412000
|
success
|
0 |
0
|
1619861118.869662
NtAllocateVirtualMemory
|
process_identifier:
3056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00422000
|
success
|
0 |
0
|
1619861118.947662
NtAllocateVirtualMemory
|
process_identifier:
3056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00455000
|
success
|
0 |
0
|
1619861118.963662
NtAllocateVirtualMemory
|
process_identifier:
3056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0045b000
|
success
|
0 |
0
|
1619861118.963662
NtAllocateVirtualMemory
|
process_identifier:
3056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00457000
|
success
|
0 |
0
|
1619861119.041662
NtAllocateVirtualMemory
|
process_identifier:
3056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00423000
|
success
|
0 |
0
|
1619861119.041662
NtAllocateVirtualMemory
|
process_identifier:
3056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00424000
|
success
|
0 |
0
|
1619861119.041662
NtAllocateVirtualMemory
|
process_identifier:
3056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00425000
|
success
|
0 |
0
|
1619861119.072662
NtAllocateVirtualMemory
|
process_identifier:
3056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00426000
|
success
|
0 |
0
|
1619861119.072662
NtAllocateVirtualMemory
|
process_identifier:
3056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0042c000
|
success
|
0 |
0
|
1619861119.307662
NtAllocateVirtualMemory
|
process_identifier:
3056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00427000
|
success
|
0 |
0
|
1619861119.479662
NtAllocateVirtualMemory
|
process_identifier:
3056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00428000
|
success
|
0 |
0
|
1619861119.541662
NtAllocateVirtualMemory
|
process_identifier:
3056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00429000
|
success
|
0 |
0
|
1619861119.541662
NtAllocateVirtualMemory
|
process_identifier:
3056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00610000
|
success
|
0 |
0
|
1619861120.057662
NtAllocateVirtualMemory
|
process_identifier:
3056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04270000
|
success
|
0 |
0
|
1619861120.213662
NtAllocateVirtualMemory
|
process_identifier:
3056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00446000
|
success
|
0 |
0
|
1619861120.260662
NtAllocateVirtualMemory
|
process_identifier:
3056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0044a000
|
success
|
0 |
0
|
1619861120.260662
NtAllocateVirtualMemory
|
process_identifier:
3056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00447000
|
success
|
0 |
0
|
1619861120.291662
NtAllocateVirtualMemory
|
process_identifier:
3056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00611000
|
success
|
0 |
0
|
1619861120.494662
NtAllocateVirtualMemory
|
process_identifier:
3056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04271000
|
success
|
0 |
0
|
1619861120.525662
NtAllocateVirtualMemory
|
process_identifier:
3056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04272000
|
success
|
0 |
0
|
1619861120.541662
NtAllocateVirtualMemory
|
process_identifier:
3056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04273000
|
success
|
0 |
0
|
1619861120.557662
NtAllocateVirtualMemory
|
process_identifier:
3056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04274000
|
success
|
0 |
0
|
1619861120.650662
NtAllocateVirtualMemory
|
process_identifier:
3056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00413000
|
success
|
0 |
0
|
1619861120.650662
NtAllocateVirtualMemory
|
process_identifier:
3056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04275000
|
success
|
0 |
0
|
1619861120.744662
NtAllocateVirtualMemory
|
process_identifier:
3056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04276000
|
success
|
0 |
0
|
1619861120.744662
NtAllocateVirtualMemory
|
process_identifier:
3056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04277000
|
success
|
0 |
0
|
1619861120.760662
NtAllocateVirtualMemory
|
process_identifier:
3056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04278000
|
success
|
0 |
0
|
1619861120.775662
NtAllocateVirtualMemory
|
process_identifier:
3056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04279000
|
success
|
0 |
0
|
1619861120.775662
NtAllocateVirtualMemory
|
process_identifier:
3056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0427a000
|
success
|
0 |
0
|
1619861150.807662
NtAllocateVirtualMemory
|
process_identifier:
3056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00612000
|
success
|
0 |
0
|
1619861150.900662
NtAllocateVirtualMemory
|
process_identifier:
3056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0427b000
|
success
|
0 |
0
|
1619861151.369662
NtAllocateVirtualMemory
|
process_identifier:
3056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0427c000
|
success
|
0 |
0
|
1619861152.494662
NtAllocateVirtualMemory
|
process_identifier:
3056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00613000
|
success
|
0 |
0
|
1619861152.494662
NtAllocateVirtualMemory
|
process_identifier:
3056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0427d000
|
success
|
0 |
0
|
1619861152.494662
NtAllocateVirtualMemory
|
process_identifier:
3056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0427e000
|
success
|
0 |
0
|
1619861152.494662
NtAllocateVirtualMemory
|
process_identifier:
3056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0427f000
|
success
|
0 |
0
|
1619861152.510662
NtAllocateVirtualMemory
|
process_identifier:
3056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x050e0000
|
success
|
0 |
0
|
1619861152.510662
NtAllocateVirtualMemory
|
process_identifier:
3056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x050e1000
|
success
|
0 |
0
|
1619861152.541662
NtAllocateVirtualMemory
|
process_identifier:
3056
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00614000
|
success
|
0 |
0
|
1619861152.557662
NtAllocateVirtualMemory
|
process_identifier:
3056
region_size:
20480
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00615000
|
success
|
0 |
0
|