| Time & API |
Arguments |
Status |
Return |
Repeated |
1619933252.370375
NtAllocateVirtualMemory
|
process_identifier:
1804
region_size:
1310720
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00650000
|
success
|
0 |
0
|
1619933252.370375
NtAllocateVirtualMemory
|
process_identifier:
1804
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00750000
|
success
|
0 |
0
|
1619933252.838375
NtAllocateVirtualMemory
|
process_identifier:
1804
region_size:
720896
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00650000
|
success
|
0 |
0
|
1619933252.838375
NtAllocateVirtualMemory
|
process_identifier:
1804
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006c0000
|
success
|
0 |
0
|
1619933252.885375
NtProtectVirtualMemory
|
process_identifier:
1804
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73b91000
|
success
|
0 |
0
|
1619933252.948375
NtAllocateVirtualMemory
|
process_identifier:
1804
region_size:
1048576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x01f60000
|
success
|
0 |
0
|
1619933252.948375
NtAllocateVirtualMemory
|
process_identifier:
1804
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02020000
|
success
|
0 |
0
|
1619933252.948375
NtAllocateVirtualMemory
|
process_identifier:
1804
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0062a000
|
success
|
0 |
0
|
1619933252.948375
NtProtectVirtualMemory
|
process_identifier:
1804
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73b92000
|
success
|
0 |
0
|
1619933252.948375
NtAllocateVirtualMemory
|
process_identifier:
1804
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00622000
|
success
|
0 |
0
|
1619933253.198375
NtAllocateVirtualMemory
|
process_identifier:
1804
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00632000
|
success
|
0 |
0
|
1619933253.291375
NtAllocateVirtualMemory
|
process_identifier:
1804
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00665000
|
success
|
0 |
0
|
1619933253.307375
NtAllocateVirtualMemory
|
process_identifier:
1804
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0066b000
|
success
|
0 |
0
|
1619933253.307375
NtAllocateVirtualMemory
|
process_identifier:
1804
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00667000
|
success
|
0 |
0
|
1619933253.463375
NtAllocateVirtualMemory
|
process_identifier:
1804
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00633000
|
success
|
0 |
0
|
1619933253.463375
NtAllocateVirtualMemory
|
process_identifier:
1804
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00634000
|
success
|
0 |
0
|
1619933253.479375
NtAllocateVirtualMemory
|
process_identifier:
1804
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0063c000
|
success
|
0 |
0
|
1619933254.041375
NtAllocateVirtualMemory
|
process_identifier:
1804
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x01fa0000
|
success
|
0 |
0
|
1619933254.041375
NtAllocateVirtualMemory
|
process_identifier:
1804
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00635000
|
success
|
0 |
0
|
1619933254.604375
NtAllocateVirtualMemory
|
process_identifier:
1804
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00636000
|
success
|
0 |
0
|
1619933254.854375
NtAllocateVirtualMemory
|
process_identifier:
1804
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00637000
|
success
|
0 |
0
|
1619933254.870375
NtAllocateVirtualMemory
|
process_identifier:
1804
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00656000
|
success
|
0 |
0
|
1619933254.885375
NtAllocateVirtualMemory
|
process_identifier:
1804
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00638000
|
success
|
0 |
0
|
1619933254.885375
NtAllocateVirtualMemory
|
process_identifier:
1804
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0065a000
|
success
|
0 |
0
|
1619933254.885375
NtAllocateVirtualMemory
|
process_identifier:
1804
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00657000
|
success
|
0 |
0
|
1619933254.901375
NtAllocateVirtualMemory
|
process_identifier:
1804
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x01fa1000
|
success
|
0 |
0
|
1619933254.916375
NtAllocateVirtualMemory
|
process_identifier:
1804
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00639000
|
success
|
0 |
0
|
1619933254.932375
NtAllocateVirtualMemory
|
process_identifier:
1804
region_size:
12288
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x01fa2000
|
success
|
0 |
0
|
1619933257.916375
NtAllocateVirtualMemory
|
process_identifier:
1804
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x020a0000
|
success
|
0 |
0
|
1619933295.979375
NtAllocateVirtualMemory
|
process_identifier:
1804
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x01fa5000
|
success
|
0 |
0
|
1619933296.307375
NtAllocateVirtualMemory
|
process_identifier:
1804
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x020a1000
|
success
|
0 |
0
|
1619933296.338375
NtAllocateVirtualMemory
|
process_identifier:
1804
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x01fa6000
|
success
|
0 |
0
|
1619933296.463375
NtAllocateVirtualMemory
|
process_identifier:
1804
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0062c000
|
success
|
0 |
0
|
1619933296.526375
NtAllocateVirtualMemory
|
process_identifier:
1804
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x01fa7000
|
success
|
0 |
0
|
1619933296.573375
NtAllocateVirtualMemory
|
process_identifier:
1804
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x020a2000
|
success
|
0 |
0
|
1619933296.588375
NtAllocateVirtualMemory
|
process_identifier:
1804
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02021000
|
success
|
0 |
0
|
1619933296.588375
NtAllocateVirtualMemory
|
process_identifier:
1804
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02022000
|
success
|
0 |
0
|
1619933296.604375
NtAllocateVirtualMemory
|
process_identifier:
1804
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02023000
|
success
|
0 |
0
|
1619933296.604375
NtAllocateVirtualMemory
|
process_identifier:
1804
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02024000
|
success
|
0 |
0
|
1619933296.604375
NtAllocateVirtualMemory
|
process_identifier:
1804
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02025000
|
success
|
0 |
0
|
1619933296.604375
NtAllocateVirtualMemory
|
process_identifier:
1804
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0063d000
|
success
|
0 |
0
|
1619933296.620375
NtAllocateVirtualMemory
|
process_identifier:
1804
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x01fa8000
|
success
|
0 |
0
|
1619933296.620375
NtAllocateVirtualMemory
|
process_identifier:
1804
region_size:
16384
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02026000
|
success
|
0 |
0
|
1619933296.620375
NtAllocateVirtualMemory
|
process_identifier:
1804
region_size:
69632
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0202a000
|
success
|
0 |
0
|
1619933296.620375
NtAllocateVirtualMemory
|
process_identifier:
1804
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0203b000
|
success
|
0 |
0
|
1619933296.620375
NtAllocateVirtualMemory
|
process_identifier:
1804
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0203c000
|
success
|
0 |
0
|
1619933296.620375
NtAllocateVirtualMemory
|
process_identifier:
1804
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0203d000
|
success
|
0 |
0
|
1619933296.635375
NtAllocateVirtualMemory
|
process_identifier:
1804
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x01fa9000
|
success
|
0 |
0
|
1619933296.666375
NtAllocateVirtualMemory
|
process_identifier:
1804
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x01faa000
|
success
|
0 |
0
|
1619933296.698375
NtAllocateVirtualMemory
|
process_identifier:
1804
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x020a3000
|
success
|
0 |
0
|