| Time & API |
Arguments |
Status |
Return |
Repeated |
1619861622.187125
NtAllocateVirtualMemory
|
process_identifier:
624
region_size:
348160
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x02690000
|
success
|
0 |
0
|
1619861622.406125
NtAllocateVirtualMemory
|
process_identifier:
624
region_size:
348160
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x026f0000
|
success
|
0 |
0
|
1619861622.499125
NtAllocateVirtualMemory
|
process_identifier:
624
region_size:
172032
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x02750000
|
success
|
0 |
0
|
1619861622.718125
NtAllocateVirtualMemory
|
process_identifier:
624
region_size:
172032
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x02e40000
|
success
|
0 |
0
|
1619861622.765125
NtAllocateVirtualMemory
|
process_identifier:
624
region_size:
172032
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x02e70000
|
success
|
0 |
0
|
1619861622.796125
NtAllocateVirtualMemory
|
process_identifier:
624
region_size:
172032
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x02ea0000
|
success
|
0 |
0
|
1619861622.828125
NtAllocateVirtualMemory
|
process_identifier:
624
region_size:
172032
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x02ed0000
|
success
|
0 |
0
|
1619861622.906125
NtAllocateVirtualMemory
|
process_identifier:
624
region_size:
172032
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x02f00000
|
success
|
0 |
0
|
1619861633.109125
NtAllocateVirtualMemory
|
process_identifier:
624
region_size:
348160
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x02d90000
|
success
|
0 |
0
|
1619861633.140125
NtAllocateVirtualMemory
|
process_identifier:
624
region_size:
172032
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x02df0000
|
success
|
0 |
0
|
1619861633.171125
NtAllocateVirtualMemory
|
process_identifier:
624
region_size:
172032
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x03450000
|
success
|
0 |
0
|
1619861633.328125
NtAllocateVirtualMemory
|
process_identifier:
624
region_size:
172032
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x03480000
|
success
|
0 |
0
|
1619861633.515125
NtAllocateVirtualMemory
|
process_identifier:
624
region_size:
172032
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x034b0000
|
success
|
0 |
0
|
1619861633.578125
NtAllocateVirtualMemory
|
process_identifier:
624
region_size:
172032
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x034e0000
|
success
|
0 |
0
|
1619861633.640125
NtAllocateVirtualMemory
|
process_identifier:
624
region_size:
172032
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x03510000
|
success
|
0 |
0
|
1619861643.890125
NtAllocateVirtualMemory
|
process_identifier:
624
region_size:
348160
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x033a0000
|
success
|
0 |
0
|
1619861643.921125
NtAllocateVirtualMemory
|
process_identifier:
624
region_size:
172032
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x03400000
|
success
|
0 |
0
|
1619861643.953125
NtAllocateVirtualMemory
|
process_identifier:
624
region_size:
172032
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x04dc0000
|
success
|
0 |
0
|
1619861643.984125
NtAllocateVirtualMemory
|
process_identifier:
624
region_size:
172032
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x05200000
|
success
|
0 |
0
|
1619861644.015125
NtAllocateVirtualMemory
|
process_identifier:
624
region_size:
172032
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x05230000
|
success
|
0 |
0
|
1619861644.062125
NtAllocateVirtualMemory
|
process_identifier:
624
region_size:
172032
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x05260000
|
success
|
0 |
0
|
1619861644.156125
NtAllocateVirtualMemory
|
process_identifier:
624
region_size:
172032
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x05290000
|
success
|
0 |
0
|
1619861654.406125
NtAllocateVirtualMemory
|
process_identifier:
624
region_size:
348160
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x04d10000
|
success
|
0 |
0
|
1619861654.437125
NtAllocateVirtualMemory
|
process_identifier:
624
region_size:
172032
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x04d70000
|
success
|
0 |
0
|
1619861654.468125
NtAllocateVirtualMemory
|
process_identifier:
624
region_size:
172032
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x05370000
|
success
|
0 |
0
|
1619861654.499125
NtAllocateVirtualMemory
|
process_identifier:
624
region_size:
172032
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x053a0000
|
success
|
0 |
0
|
1619861654.546125
NtAllocateVirtualMemory
|
process_identifier:
624
region_size:
172032
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x053d0000
|
success
|
0 |
0
|
1619861654.578125
NtAllocateVirtualMemory
|
process_identifier:
624
region_size:
172032
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x05400000
|
success
|
0 |
0
|
1619861654.609125
NtAllocateVirtualMemory
|
process_identifier:
624
region_size:
172032
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x05430000
|
success
|
0 |
0
|
1619861664.843125
NtAllocateVirtualMemory
|
process_identifier:
624
region_size:
348160
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x052c0000
|
success
|
0 |
0
|
1619861664.874125
NtAllocateVirtualMemory
|
process_identifier:
624
region_size:
172032
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x05320000
|
success
|
0 |
0
|
1619861665.031125
NtAllocateVirtualMemory
|
process_identifier:
624
region_size:
172032
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x05510000
|
success
|
0 |
0
|
1619861665.328125
NtAllocateVirtualMemory
|
process_identifier:
624
region_size:
172032
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x05540000
|
success
|
0 |
0
|
1619861665.406125
NtAllocateVirtualMemory
|
process_identifier:
624
region_size:
172032
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x05570000
|
success
|
0 |
0
|
1619861665.453125
NtAllocateVirtualMemory
|
process_identifier:
624
region_size:
172032
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x055a0000
|
success
|
0 |
0
|
1619861665.593125
NtAllocateVirtualMemory
|
process_identifier:
624
region_size:
172032
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x055d0000
|
success
|
0 |
0
|
1619861675.968125
NtAllocateVirtualMemory
|
process_identifier:
624
region_size:
348160
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x05460000
|
success
|
0 |
0
|
1619861675.999125
NtAllocateVirtualMemory
|
process_identifier:
624
region_size:
172032
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x054c0000
|
success
|
0 |
0
|
1619861676.046125
NtAllocateVirtualMemory
|
process_identifier:
624
region_size:
172032
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x056b0000
|
success
|
0 |
0
|
1619861676.093125
NtAllocateVirtualMemory
|
process_identifier:
624
region_size:
172032
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x056e0000
|
success
|
0 |
0
|
1619884546.100375
NtAllocateVirtualMemory
|
process_identifier:
2196
region_size:
3158016
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00ff0000
|
success
|
0 |
0
|