| Time & API |
Arguments |
Status |
Return |
Repeated |
1619887282.832874
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
589824
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00280000
|
success
|
0 |
0
|
1619887282.832874
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002d0000
|
success
|
0 |
0
|
1619887283.848874
NtProtectVirtualMemory
|
process_identifier:
1948
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73c51000
|
success
|
0 |
0
|
1619887283.879874
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002ba000
|
success
|
0 |
0
|
1619887283.879874
NtProtectVirtualMemory
|
process_identifier:
1948
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73c52000
|
success
|
0 |
0
|
1619887283.879874
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002b2000
|
success
|
0 |
0
|
1619887285.520874
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002c2000
|
success
|
0 |
0
|
1619887285.614874
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002c3000
|
success
|
0 |
0
|
1619887285.629874
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0033b000
|
success
|
0 |
0
|
1619887285.629874
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00337000
|
success
|
0 |
0
|
1619887285.661874
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002cc000
|
success
|
0 |
0
|
1619887286.145874
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002c4000
|
success
|
0 |
0
|
1619887286.145874
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002c5000
|
success
|
0 |
0
|
1619887286.207874
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002c6000
|
success
|
0 |
0
|
1619887286.254874
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00520000
|
success
|
0 |
0
|
1619887286.442874
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002c7000
|
success
|
0 |
0
|
1619887286.457874
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0031a000
|
success
|
0 |
0
|
1619887286.457874
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00317000
|
success
|
0 |
0
|
1619887286.457874
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0032a000
|
success
|
0 |
0
|
1619887286.504874
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002bb000
|
success
|
0 |
0
|
1619887286.645874
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00316000
|
success
|
0 |
0
|
1619887286.926874
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00700000
|
success
|
0 |
0
|
1619887286.973874
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002ca000
|
success
|
0 |
0
|
1619887287.082874
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00322000
|
success
|
0 |
0
|
1619887287.254874
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00335000
|
success
|
0 |
0
|
1619887292.520874
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002c8000
|
success
|
0 |
0
|
1619887292.614874
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00521000
|
success
|
0 |
0
|
1619887325.926874
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002d1000
|
success
|
0 |
0
|
1619887326.067874
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002c9000
|
success
|
0 |
0
|
1619887326.098874
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
524288
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x05760000
|
success
|
0 |
0
|
1619887326.098874
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x057a0000
|
success
|
0 |
0
|
1619887326.098874
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x057a1000
|
success
|
0 |
0
|
1619887326.145874
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x057a2000
|
success
|
0 |
0
|
1619887326.161874
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x057a3000
|
success
|
0 |
0
|
1619887326.161874
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x057a4000
|
success
|
0 |
0
|
1619887326.176874
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00522000
|
success
|
0 |
0
|
1619887326.192874
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x057a5000
|
success
|
0 |
0
|
1619887326.192874
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x057a6000
|
success
|
0 |
0
|
1619887326.192874
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
16384
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x057a7000
|
success
|
0 |
0
|
1619887326.192874
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
69632
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x057ab000
|
success
|
0 |
0
|
1619887326.192874
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00523000
|
success
|
0 |
0
|
1619887326.192874
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x057bc000
|
success
|
0 |
0
|
1619887326.223874
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x057bd000
|
success
|
0 |
0
|
1619887326.301874
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00524000
|
success
|
0 |
0
|
1619887326.426874
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04860000
|
success
|
0 |
0
|
1619887326.536874
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00701000
|
success
|
0 |
0
|
1619887333.582874
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00702000
|
success
|
0 |
0
|
1619887333.661874
NtAllocateVirtualMemory
|
process_identifier:
1948
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x002b3000
|
success
|
0 |
0
|
1619887333.723374
NtAllocateVirtualMemory
|
process_identifier:
1752
region_size:
2097152
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x008b0000
|
success
|
0 |
0
|
1619887333.723374
NtAllocateVirtualMemory
|
process_identifier:
1752
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00a70000
|
success
|
0 |
0
|