| Time & API |
Arguments |
Status |
Return |
Repeated |
1619910850.199653
NtAllocateVirtualMemory
|
process_identifier:
2060
region_size:
1114112
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00680000
|
success
|
0 |
0
|
1619910850.199653
NtAllocateVirtualMemory
|
process_identifier:
2060
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00750000
|
success
|
0 |
0
|
1619910850.527653
NtProtectVirtualMemory
|
process_identifier:
2060
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73f31000
|
success
|
0 |
0
|
1619910850.668653
NtAllocateVirtualMemory
|
process_identifier:
2060
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003ea000
|
success
|
0 |
0
|
1619910850.668653
NtProtectVirtualMemory
|
process_identifier:
2060
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73f32000
|
success
|
0 |
0
|
1619910850.668653
NtAllocateVirtualMemory
|
process_identifier:
2060
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003e2000
|
success
|
0 |
0
|
1619910850.839653
NtAllocateVirtualMemory
|
process_identifier:
2060
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003f2000
|
success
|
0 |
0
|
1619910850.933653
NtAllocateVirtualMemory
|
process_identifier:
2060
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003f3000
|
success
|
0 |
0
|
1619910850.949653
NtAllocateVirtualMemory
|
process_identifier:
2060
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0052b000
|
success
|
0 |
0
|
1619910850.949653
NtAllocateVirtualMemory
|
process_identifier:
2060
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00527000
|
success
|
0 |
0
|
1619910850.964653
NtAllocateVirtualMemory
|
process_identifier:
2060
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003fc000
|
success
|
0 |
0
|
1619910851.324653
NtAllocateVirtualMemory
|
process_identifier:
2060
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003f4000
|
success
|
0 |
0
|
1619910851.324653
NtAllocateVirtualMemory
|
process_identifier:
2060
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003f5000
|
success
|
0 |
0
|
1619910851.371653
NtAllocateVirtualMemory
|
process_identifier:
2060
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003f6000
|
success
|
0 |
0
|
1619910851.386653
NtAllocateVirtualMemory
|
process_identifier:
2060
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00830000
|
success
|
0 |
0
|
1619910851.449653
NtAllocateVirtualMemory
|
process_identifier:
2060
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0040a000
|
success
|
0 |
0
|
1619910851.449653
NtAllocateVirtualMemory
|
process_identifier:
2060
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00407000
|
success
|
0 |
0
|
1619910851.449653
NtAllocateVirtualMemory
|
process_identifier:
2060
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0041a000
|
success
|
0 |
0
|
1619910851.480653
NtAllocateVirtualMemory
|
process_identifier:
2060
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003eb000
|
success
|
0 |
0
|
1619910851.574653
NtAllocateVirtualMemory
|
process_identifier:
2060
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00406000
|
success
|
0 |
0
|
1619910851.636653
NtAllocateVirtualMemory
|
process_identifier:
2060
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00831000
|
success
|
0 |
0
|
1619910851.855653
NtAllocateVirtualMemory
|
process_identifier:
2060
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00970000
|
success
|
0 |
0
|
1619910851.980653
NtAllocateVirtualMemory
|
process_identifier:
2060
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003fa000
|
success
|
0 |
0
|
1619910852.043653
NtAllocateVirtualMemory
|
process_identifier:
2060
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00412000
|
success
|
0 |
0
|
1619910852.089653
NtAllocateVirtualMemory
|
process_identifier:
2060
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00525000
|
success
|
0 |
0
|
1619910852.230653
NtAllocateVirtualMemory
|
process_identifier:
2060
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00751000
|
success
|
0 |
0
|
1619910852.574653
NtAllocateVirtualMemory
|
process_identifier:
2060
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003f7000
|
success
|
0 |
0
|
1619910852.699653
NtAllocateVirtualMemory
|
process_identifier:
2060
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003f8000
|
success
|
0 |
0
|
1619910852.714653
NtAllocateVirtualMemory
|
process_identifier:
2060
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00832000
|
success
|
0 |
0
|
1619910852.730653
NtAllocateVirtualMemory
|
process_identifier:
2060
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003f9000
|
success
|
0 |
0
|
1619910852.730653
NtAllocateVirtualMemory
|
process_identifier:
2060
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00833000
|
success
|
0 |
0
|
1619910852.730653
NtAllocateVirtualMemory
|
process_identifier:
2060
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00834000
|
success
|
0 |
0
|
1619910852.730653
NtAllocateVirtualMemory
|
process_identifier:
2060
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00835000
|
success
|
0 |
0
|
1619910852.746653
NtAllocateVirtualMemory
|
process_identifier:
2060
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00836000
|
success
|
0 |
0
|
1619910852.793653
NtAllocateVirtualMemory
|
process_identifier:
2060
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00837000
|
success
|
0 |
0
|
1619910852.824653
NtAllocateVirtualMemory
|
process_identifier:
2060
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00838000
|
success
|
0 |
0
|
1619910852.918653
NtProtectVirtualMemory
|
process_identifier:
2060
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x04be0178
|
failed
|
3221225550 |
0
|
1619910852.918653
NtProtectVirtualMemory
|
process_identifier:
2060
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x04be01a0
|
failed
|
3221225550 |
0
|
1619910852.918653
NtProtectVirtualMemory
|
process_identifier:
2060
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x04be01c8
|
failed
|
3221225550 |
0
|
1619910852.918653
NtProtectVirtualMemory
|
process_identifier:
2060
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
11
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x04c0aade
|
failed
|
3221225550 |
0
|
1619910852.918653
NtProtectVirtualMemory
|
process_identifier:
2060
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
11
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x04c0aad2
|
failed
|
3221225550 |
0
|
1619910852.918653
NtProtectVirtualMemory
|
process_identifier:
2060
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
72
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x04be0208
|
failed
|
3221225550 |
0
|
1619910852.918653
NtProtectVirtualMemory
|
process_identifier:
2060
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x04bfb9f0
|
failed
|
3221225550 |
0
|
1619910852.918653
NtProtectVirtualMemory
|
process_identifier:
2060
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x04bfba10
|
failed
|
3221225550 |
0
|
1619910852.918653
NtProtectVirtualMemory
|
process_identifier:
2060
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x04bfba18
|
failed
|
3221225550 |
0
|
1619910852.918653
NtProtectVirtualMemory
|
process_identifier:
2060
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x04bfba1c
|
failed
|
3221225550 |
0
|
1619910852.918653
NtProtectVirtualMemory
|
process_identifier:
2060
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x04bfba24
|
failed
|
3221225550 |
0
|
1619910852.918653
NtProtectVirtualMemory
|
process_identifier:
2060
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x04bfba28
|
failed
|
3221225550 |
0
|
1619910852.918653
NtProtectVirtualMemory
|
process_identifier:
2060
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x04bfba2c
|
failed
|
3221225550 |
0
|
1619910852.918653
NtProtectVirtualMemory
|
process_identifier:
2060
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x04bfba30
|
failed
|
3221225550 |
0
|