| Time & API |
Arguments |
Status |
Return |
Repeated |
1619889908.752251
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
2228224
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x008e0000
|
success
|
0 |
0
|
1619889908.752251
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00ac0000
|
success
|
0 |
0
|
1619889909.924251
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
1966080
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x02210000
|
success
|
0 |
0
|
1619889909.924251
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x023b0000
|
success
|
0 |
0
|
1619889909.986251
NtProtectVirtualMemory
|
process_identifier:
1916
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73b91000
|
success
|
0 |
0
|
1619889910.080251
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
1966080
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x023f0000
|
success
|
0 |
0
|
1619889910.080251
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02590000
|
success
|
0 |
0
|
1619889910.080251
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004ea000
|
success
|
0 |
0
|
1619889910.080251
NtProtectVirtualMemory
|
process_identifier:
1916
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73b92000
|
success
|
0 |
0
|
1619889910.080251
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004e2000
|
success
|
0 |
0
|
1619889910.315251
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004f2000
|
success
|
0 |
0
|
1619889910.408251
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00515000
|
success
|
0 |
0
|
1619889910.408251
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0051b000
|
success
|
0 |
0
|
1619889910.408251
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00517000
|
success
|
0 |
0
|
1619889910.596251
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004f3000
|
success
|
0 |
0
|
1619889910.627251
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004fc000
|
success
|
0 |
0
|
1619889911.346251
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004f4000
|
success
|
0 |
0
|
1619889911.361251
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004f6000
|
success
|
0 |
0
|
1619889911.471251
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006b0000
|
success
|
0 |
0
|
1619889911.643251
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004f7000
|
success
|
0 |
0
|
1619889911.705251
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0050a000
|
success
|
0 |
0
|
1619889911.705251
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00507000
|
success
|
0 |
0
|
1619889912.252251
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004f8000
|
success
|
0 |
0
|
1619889912.252251
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00506000
|
success
|
0 |
0
|
1619889912.315251
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004fa000
|
success
|
0 |
0
|
1619889916.033251
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004f9000
|
success
|
0 |
0
|
1619889916.408251
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00aa0000
|
success
|
0 |
0
|
1619889916.424251
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006b1000
|
success
|
0 |
0
|
1619889916.486251
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00aa1000
|
success
|
0 |
0
|
1619889916.518251
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006b2000
|
success
|
0 |
0
|
1619889916.533251
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00aa2000
|
success
|
0 |
0
|
1619889916.565251
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006b3000
|
success
|
0 |
0
|
1619889916.565251
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006b5000
|
success
|
0 |
0
|
1619889957.596251
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006b6000
|
success
|
0 |
0
|
1619889957.736251
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x023b1000
|
success
|
0 |
0
|
1619889957.940251
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006b7000
|
success
|
0 |
0
|
1619889958.252251
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004fd000
|
success
|
0 |
0
|
1619889958.252251
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004ec000
|
success
|
0 |
0
|
1619889960.205251
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006b8000
|
success
|
0 |
0
|
1619889960.268251
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00aa3000
|
success
|
0 |
0
|
1619889960.268251
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00aa4000
|
success
|
0 |
0
|
1619889960.299251
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006b9000
|
success
|
0 |
0
|
1619889960.502251
NtProtectVirtualMemory
|
process_identifier:
1916
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
662016
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x06330400
|
failed
|
3221225550 |
0
|
1619889970.346251
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006ba000
|
success
|
0 |
0
|
1619889970.502251
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006bb000
|
success
|
0 |
0
|
1619889970.502251
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00aa5000
|
success
|
0 |
0
|
1619889970.627251
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006bc000
|
success
|
0 |
0
|
1619889970.830251
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006bd000
|
success
|
0 |
0
|
1619889970.846251
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006be000
|
success
|
0 |
0
|
1619889971.033251
NtAllocateVirtualMemory
|
process_identifier:
1916
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006bf000
|
success
|
0 |
0
|