| Time & API |
Arguments |
Status |
Return |
Repeated |
1620897718.478822
NtAllocateVirtualMemory
|
process_identifier:
2636
region_size:
2293760
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x038a0000
|
success
|
0 |
0
|
1620897718.478822
NtAllocateVirtualMemory
|
process_identifier:
2636
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x03a90000
|
success
|
0 |
0
|
1620897718.478822
NtAllocateVirtualMemory
|
process_identifier:
2636
region_size:
49152
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x03a91000
|
success
|
0 |
0
|
1620897718.494822
NtProtectVirtualMemory
|
process_identifier:
2636
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
876544
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x77d40000
|
success
|
0 |
0
|
1620914357.737875
NtAllocateVirtualMemory
|
process_identifier:
2740
region_size:
393216
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x02540000
|
success
|
0 |
0
|
1620914357.737875
NtAllocateVirtualMemory
|
process_identifier:
2740
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02560000
|
success
|
0 |
0
|
1620914357.737875
NtAllocateVirtualMemory
|
process_identifier:
2740
region_size:
49152
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02561000
|
success
|
0 |
0
|
1620914357.737875
NtProtectVirtualMemory
|
process_identifier:
2740
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
876544
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x77d40000
|
success
|
0 |
0
|
1620914359.393625
NtAllocateVirtualMemory
|
process_identifier:
912
region_size:
720896
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x026c0000
|
success
|
0 |
0
|
1620914359.393625
NtAllocateVirtualMemory
|
process_identifier:
912
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02730000
|
success
|
0 |
0
|
1620914359.393625
NtAllocateVirtualMemory
|
process_identifier:
912
region_size:
49152
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02731000
|
success
|
0 |
0
|
1620914359.409625
NtProtectVirtualMemory
|
process_identifier:
912
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
876544
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x77d40000
|
success
|
0 |
0
|
1620914359.83075
NtAllocateVirtualMemory
|
process_identifier:
2316
region_size:
1048576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x03810000
|
success
|
0 |
0
|
1620914359.83075
NtAllocateVirtualMemory
|
process_identifier:
2316
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x038d0000
|
success
|
0 |
0
|
1620914359.83075
NtAllocateVirtualMemory
|
process_identifier:
2316
region_size:
49152
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x038d1000
|
success
|
0 |
0
|
1620914359.84675
NtProtectVirtualMemory
|
process_identifier:
2316
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
876544
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x77d40000
|
success
|
0 |
0
|