| Time & API |
Arguments |
Status |
Return |
Repeated |
1620930719.349874
NtAllocateVirtualMemory
|
process_identifier:
2504
region_size:
262144
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00300000
|
success
|
0 |
0
|
1620930719.349874
NtAllocateVirtualMemory
|
process_identifier:
2504
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00300000
|
success
|
0 |
0
|
1620930719.724874
NtAllocateVirtualMemory
|
process_identifier:
2504
region_size:
2228224
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x02050000
|
success
|
0 |
0
|
1620930719.724874
NtAllocateVirtualMemory
|
process_identifier:
2504
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02230000
|
success
|
0 |
0
|
1620930719.912874
NtProtectVirtualMemory
|
process_identifier:
2504
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73e71000
|
success
|
0 |
0
|
1620930720.131874
NtAllocateVirtualMemory
|
process_identifier:
2504
region_size:
1769472
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x02050000
|
success
|
0 |
0
|
1620930720.131874
NtAllocateVirtualMemory
|
process_identifier:
2504
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x021c0000
|
success
|
0 |
0
|
1620930720.131874
NtAllocateVirtualMemory
|
process_identifier:
2504
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004aa000
|
success
|
0 |
0
|
1620930720.146874
NtProtectVirtualMemory
|
process_identifier:
2504
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73e72000
|
success
|
0 |
0
|
1620930720.146874
NtAllocateVirtualMemory
|
process_identifier:
2504
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004a2000
|
success
|
0 |
0
|
1620930720.459874
NtAllocateVirtualMemory
|
process_identifier:
2504
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004b2000
|
success
|
0 |
0
|
1620930720.646874
NtAllocateVirtualMemory
|
process_identifier:
2504
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004d5000
|
success
|
0 |
0
|
1620930720.662874
NtAllocateVirtualMemory
|
process_identifier:
2504
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004db000
|
success
|
0 |
0
|
1620930720.662874
NtAllocateVirtualMemory
|
process_identifier:
2504
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004d7000
|
success
|
0 |
0
|
1620930720.849874
NtAllocateVirtualMemory
|
process_identifier:
2504
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004b3000
|
success
|
0 |
0
|
1620930720.928874
NtAllocateVirtualMemory
|
process_identifier:
2504
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004bc000
|
success
|
0 |
0
|
1620930722.021874
NtAllocateVirtualMemory
|
process_identifier:
2504
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004b4000
|
success
|
0 |
0
|
1620930722.053874
NtAllocateVirtualMemory
|
process_identifier:
2504
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004b6000
|
success
|
0 |
0
|
1620930722.396874
NtAllocateVirtualMemory
|
process_identifier:
2504
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00730000
|
success
|
0 |
0
|
1620930722.537874
NtAllocateVirtualMemory
|
process_identifier:
2504
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004ca000
|
success
|
0 |
0
|
1620930722.537874
NtAllocateVirtualMemory
|
process_identifier:
2504
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004c7000
|
success
|
0 |
0
|
1620930722.678874
NtAllocateVirtualMemory
|
process_identifier:
2504
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004c6000
|
success
|
0 |
0
|
1620930722.724874
NtAllocateVirtualMemory
|
process_identifier:
2504
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00731000
|
success
|
0 |
0
|
1620930723.068874
NtAllocateVirtualMemory
|
process_identifier:
2504
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004ba000
|
success
|
0 |
0
|
1620930723.131874
NtAllocateVirtualMemory
|
process_identifier:
2504
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004ac000
|
success
|
0 |
0
|
1620930723.193874
NtAllocateVirtualMemory
|
process_identifier:
2504
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004b7000
|
success
|
0 |
0
|
1620930723.709874
NtAllocateVirtualMemory
|
process_identifier:
2504
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004cb000
|
success
|
0 |
0
|
1620930723.990874
NtAllocateVirtualMemory
|
process_identifier:
2504
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004b8000
|
success
|
0 |
0
|
1620930724.099874
NtAllocateVirtualMemory
|
process_identifier:
2504
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02050000
|
success
|
0 |
0
|
1620930757.256874
NtAllocateVirtualMemory
|
process_identifier:
2504
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02231000
|
success
|
0 |
0
|
1620930757.443874
NtAllocateVirtualMemory
|
process_identifier:
2504
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004a3000
|
success
|
0 |
0
|
1620930757.443874
NtAllocateVirtualMemory
|
process_identifier:
2504
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00732000
|
success
|
0 |
0
|
1620930757.459874
NtAllocateVirtualMemory
|
process_identifier:
2504
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004b9000
|
success
|
0 |
0
|
1620930757.568874
NtAllocateVirtualMemory
|
process_identifier:
2504
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x043b0000
|
success
|
0 |
0
|
1620930757.568874
NtAllocateVirtualMemory
|
process_identifier:
2504
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x043b1000
|
success
|
0 |
0
|
1620930757.615874
NtAllocateVirtualMemory
|
process_identifier:
2504
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x043b2000
|
success
|
0 |
0
|
1620930757.662874
NtAllocateVirtualMemory
|
process_identifier:
2504
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00733000
|
success
|
0 |
0
|
1620930757.678874
NtAllocateVirtualMemory
|
process_identifier:
2504
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x043b3000
|
success
|
0 |
0
|
1620930757.693874
NtAllocateVirtualMemory
|
process_identifier:
2504
region_size:
12288
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00734000
|
success
|
0 |
0
|
1620930757.724874
NtAllocateVirtualMemory
|
process_identifier:
2504
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00737000
|
success
|
0 |
0
|
1620930757.849874
NtProtectVirtualMemory
|
process_identifier:
2504
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
220672
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x05e30400
|
failed
|
3221225550 |
0
|
1620930764.709874
NtAllocateVirtualMemory
|
process_identifier:
2504
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00738000
|
success
|
0 |
0
|
1620930764.709874
NtAllocateVirtualMemory
|
process_identifier:
2504
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x043b4000
|
success
|
0 |
0
|
1620930764.709874
NtAllocateVirtualMemory
|
process_identifier:
2504
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004bd000
|
success
|
0 |
0
|
1620930764.709874
NtAllocateVirtualMemory
|
process_identifier:
2504
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00739000
|
success
|
0 |
0
|
1620930764.724874
NtAllocateVirtualMemory
|
process_identifier:
2504
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0073a000
|
success
|
0 |
0
|
1620930764.740874
NtAllocateVirtualMemory
|
process_identifier:
2504
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0073b000
|
success
|
0 |
0
|
1620930764.834874
NtAllocateVirtualMemory
|
process_identifier:
2504
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0073c000
|
success
|
0 |
0
|
1620930765.162874
NtAllocateVirtualMemory
|
process_identifier:
2504
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x043b5000
|
success
|
0 |
0
|
1620930765.162874
NtAllocateVirtualMemory
|
process_identifier:
2504
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0073d000
|
success
|
0 |
0
|