| Time & API |
Arguments |
Status |
Return |
Repeated |
1619861118.41196
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
2097152
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00930000
|
success
|
0 |
0
|
1619861118.41196
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00af0000
|
success
|
0 |
0
|
1619861119.31796
NtProtectVirtualMemory
|
process_identifier:
2136
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73f31000
|
success
|
0 |
0
|
1619861119.58396
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0066a000
|
success
|
0 |
0
|
1619861119.58396
NtProtectVirtualMemory
|
process_identifier:
2136
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73f32000
|
success
|
0 |
0
|
1619861119.58396
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00662000
|
success
|
0 |
0
|
1619861120.05296
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00672000
|
success
|
0 |
0
|
1619861120.20896
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00673000
|
success
|
0 |
0
|
1619861120.23996
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006fb000
|
success
|
0 |
0
|
1619861120.23996
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006f7000
|
success
|
0 |
0
|
1619861120.31796
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0067c000
|
success
|
0 |
0
|
1619861120.45896
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02080000
|
success
|
0 |
0
|
1619861120.63096
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0069a000
|
success
|
0 |
0
|
1619861120.66196
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00692000
|
success
|
0 |
0
|
1619861120.66196
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00674000
|
success
|
0 |
0
|
1619861120.78696
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006f5000
|
success
|
0 |
0
|
1619861121.13096
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00675000
|
success
|
0 |
0
|
1619861121.20896
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x045a0000
|
success
|
0 |
0
|
1619861121.20896
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0067a000
|
success
|
0 |
0
|
1619861121.28696
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00676000
|
success
|
0 |
0
|
1619861121.34896
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02081000
|
success
|
0 |
0
|
1619861154.59896
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02083000
|
success
|
0 |
0
|
1619861154.75596
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0069c000
|
success
|
0 |
0
|
1619861154.84896
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00686000
|
success
|
0 |
0
|
1619861154.84896
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0068a000
|
success
|
0 |
0
|
1619861154.84896
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00687000
|
success
|
0 |
0
|
1619861154.86496
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00677000
|
success
|
0 |
0
|
1619861154.88096
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02084000
|
success
|
0 |
0
|
1619861154.88096
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02085000
|
success
|
0 |
0
|
1619861155.00596
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0066b000
|
success
|
0 |
0
|
1619861155.00596
NtProtectVirtualMemory
|
process_identifier:
2136
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
831488
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x051e0400
|
failed
|
3221225550 |
0
|
1619861174.98996
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00678000
|
success
|
0 |
0
|
1619861175.00596
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02086000
|
success
|
0 |
0
|
1619861175.06796
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02087000
|
success
|
0 |
0
|
1619861175.08396
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02088000
|
success
|
0 |
0
|
1619861175.17796
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02089000
|
success
|
0 |
0
|
1619861175.33396
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0208a000
|
success
|
0 |
0
|
1619861175.36496
NtAllocateVirtualMemory
|
process_identifier:
2136
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0208b000
|
success
|
0 |
0
|
1619861175.36496
NtProtectVirtualMemory
|
process_identifier:
2136
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x051e0178
|
failed
|
3221225550 |
0
|
1619861175.36496
NtProtectVirtualMemory
|
process_identifier:
2136
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x051e01a0
|
failed
|
3221225550 |
0
|
1619861175.36496
NtProtectVirtualMemory
|
process_identifier:
2136
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x051e01c8
|
failed
|
3221225550 |
0
|
1619861175.36496
NtProtectVirtualMemory
|
process_identifier:
2136
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x051e01f0
|
failed
|
3221225550 |
0
|
1619861175.36496
NtProtectVirtualMemory
|
process_identifier:
2136
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x051e0218
|
failed
|
3221225550 |
0
|
1619861175.36496
NtProtectVirtualMemory
|
process_identifier:
2136
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
11
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x052abcde
|
failed
|
3221225550 |
0
|
1619861175.36496
NtProtectVirtualMemory
|
process_identifier:
2136
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
11
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x052abcd2
|
failed
|
3221225550 |
0
|
1619861175.36496
NtProtectVirtualMemory
|
process_identifier:
2136
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
72
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x052ab400
|
failed
|
3221225550 |
0
|
1619861175.36496
NtProtectVirtualMemory
|
process_identifier:
2136
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x052abcec
|
failed
|
3221225550 |
0
|
1619861175.36496
NtProtectVirtualMemory
|
process_identifier:
2136
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x052abd10
|
failed
|
3221225550 |
0
|
1619861175.36496
NtProtectVirtualMemory
|
process_identifier:
2136
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x052abd18
|
failed
|
3221225550 |
0
|
1619861175.36496
NtProtectVirtualMemory
|
process_identifier:
2136
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x052abd1c
|
failed
|
3221225550 |
0
|