| Time & API |
Arguments |
Status |
Return |
Repeated |
1619929049.3905
NtAllocateVirtualMemory
|
process_identifier:
3440
region_size:
106496
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000260
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x50480000
|
success
|
0 |
0
|
1619929049.3905
NtAllocateVirtualMemory
|
process_identifier:
3440
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000260
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00130000
|
success
|
0 |
0
|
1619929049.3905
NtAllocateVirtualMemory
|
process_identifier:
3440
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000260
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00140000
|
success
|
0 |
0
|
1619929049.3905
NtAllocateVirtualMemory
|
process_identifier:
3440
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000260
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00150000
|
success
|
0 |
0
|
1619929049.3905
NtAllocateVirtualMemory
|
process_identifier:
3440
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000260
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00010000
|
success
|
0 |
0
|
1619929049.3905
NtAllocateVirtualMemory
|
process_identifier:
3440
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000260
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00020000
|
success
|
0 |
0
|
1619929049.3905
NtAllocateVirtualMemory
|
process_identifier:
3440
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000260
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00160000
|
success
|
0 |
0
|
1619929049.3905
NtAllocateVirtualMemory
|
process_identifier:
3440
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000260
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00170000
|
success
|
0 |
0
|
1619929049.4525
NtAllocateVirtualMemory
|
process_identifier:
3440
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000260
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00230000
|
success
|
0 |
0
|
1619929049.4525
NtAllocateVirtualMemory
|
process_identifier:
3440
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000260
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00250000
|
success
|
0 |
0
|
1619929049.4525
NtAllocateVirtualMemory
|
process_identifier:
3440
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000260
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00260000
|
success
|
0 |
0
|
1619929049.4525
NtAllocateVirtualMemory
|
process_identifier:
3440
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000260
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00270000
|
success
|
0 |
0
|
1619929049.4525
NtAllocateVirtualMemory
|
process_identifier:
3440
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000260
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00280000
|
success
|
0 |
0
|
1619929049.4525
NtAllocateVirtualMemory
|
process_identifier:
3440
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000260
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x002c0000
|
success
|
0 |
0
|
1619929049.4525
NtAllocateVirtualMemory
|
process_identifier:
3440
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000260
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x002d0000
|
success
|
0 |
0
|
1619929049.4525
NtAllocateVirtualMemory
|
process_identifier:
3440
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000260
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x002e0000
|
success
|
0 |
0
|
1619929049.4525
NtAllocateVirtualMemory
|
process_identifier:
3440
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000260
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x002f0000
|
success
|
0 |
0
|
1619929049.4525
NtAllocateVirtualMemory
|
process_identifier:
3440
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000260
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00300000
|
success
|
0 |
0
|
1619929049.4525
NtAllocateVirtualMemory
|
process_identifier:
3440
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000260
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00350000
|
success
|
0 |
0
|
1619929049.4525
NtAllocateVirtualMemory
|
process_identifier:
3440
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000260
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00360000
|
success
|
0 |
0
|
1619929049.4685
NtAllocateVirtualMemory
|
process_identifier:
3440
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000260
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00370000
|
success
|
0 |
0
|
1619929049.4685
NtAllocateVirtualMemory
|
process_identifier:
3440
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000260
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00380000
|
success
|
0 |
0
|
1619929049.4685
NtAllocateVirtualMemory
|
process_identifier:
3440
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000260
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00390000
|
success
|
0 |
0
|
1619929049.4685
NtAllocateVirtualMemory
|
process_identifier:
3440
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000260
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x003a0000
|
success
|
0 |
0
|
1619929049.4685
NtAllocateVirtualMemory
|
process_identifier:
3440
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000260
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x003b0000
|
success
|
0 |
0
|
1619929049.4685
NtAllocateVirtualMemory
|
process_identifier:
3440
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000260
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x003c0000
|
success
|
0 |
0
|
1619929049.4685
NtAllocateVirtualMemory
|
process_identifier:
3440
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000260
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x003d0000
|
success
|
0 |
0
|
1619929049.4685
NtAllocateVirtualMemory
|
process_identifier:
3440
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000260
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00420000
|
success
|
0 |
0
|
1619929049.4685
NtAllocateVirtualMemory
|
process_identifier:
3440
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000260
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00430000
|
success
|
0 |
0
|
1619929049.4685
NtAllocateVirtualMemory
|
process_identifier:
3440
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000260
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00440000
|
success
|
0 |
0
|
1619929049.4685
NtAllocateVirtualMemory
|
process_identifier:
3440
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000260
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00450000
|
success
|
0 |
0
|
1619929049.4685
NtAllocateVirtualMemory
|
process_identifier:
3440
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000260
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00460000
|
success
|
0 |
0
|
1619929049.4685
NtAllocateVirtualMemory
|
process_identifier:
3440
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000260
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00470000
|
success
|
0 |
0
|
1619929049.4685
NtAllocateVirtualMemory
|
process_identifier:
3440
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000260
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00480000
|
success
|
0 |
0
|
1619929049.4685
NtAllocateVirtualMemory
|
process_identifier:
3440
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000260
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00490000
|
success
|
0 |
0
|
1619929049.4685
NtAllocateVirtualMemory
|
process_identifier:
3440
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000260
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x004a0000
|
success
|
0 |
0
|
1619929049.4835
NtAllocateVirtualMemory
|
process_identifier:
3440
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000260
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x004b0000
|
success
|
0 |
0
|
1619929049.4835
NtAllocateVirtualMemory
|
process_identifier:
3440
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000260
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x004c0000
|
success
|
0 |
0
|
1619929049.4835
NtAllocateVirtualMemory
|
process_identifier:
3440
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000260
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x004d0000
|
success
|
0 |
0
|
1619929049.4835
NtAllocateVirtualMemory
|
process_identifier:
3440
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000260
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x004e0000
|
success
|
0 |
0
|
1619929049.4835
NtAllocateVirtualMemory
|
process_identifier:
3440
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000260
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x004f0000
|
success
|
0 |
0
|
1619929049.4835
NtAllocateVirtualMemory
|
process_identifier:
3440
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000260
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00500000
|
success
|
0 |
0
|
1619929049.4835
NtAllocateVirtualMemory
|
process_identifier:
3440
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000260
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00510000
|
success
|
0 |
0
|
1619929049.4835
NtAllocateVirtualMemory
|
process_identifier:
3440
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000260
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00520000
|
success
|
0 |
0
|
1619929049.4835
NtAllocateVirtualMemory
|
process_identifier:
3440
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000260
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x005b0000
|
success
|
0 |
0
|
1619929049.4835
NtAllocateVirtualMemory
|
process_identifier:
3440
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000260
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x005c0000
|
success
|
0 |
0
|
1619929049.4835
NtAllocateVirtualMemory
|
process_identifier:
3440
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000260
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x005d0000
|
success
|
0 |
0
|
1619929049.4835
NtAllocateVirtualMemory
|
process_identifier:
3440
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000260
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x005e0000
|
success
|
0 |
0
|
1619929049.4835
NtAllocateVirtualMemory
|
process_identifier:
3440
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000260
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x005f0000
|
success
|
0 |
0
|
1619929049.4835
NtAllocateVirtualMemory
|
process_identifier:
3440
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0x00000260
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
base_address:
0x00600000
|
success
|
0 |
0
|