| Time & API |
Arguments |
Status |
Return |
Repeated |
1619948417.990952
NtAllocateVirtualMemory
|
process_identifier:
428
region_size:
720896
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00500000
|
success
|
0 |
0
|
1619948417.990952
NtAllocateVirtualMemory
|
process_identifier:
428
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00570000
|
success
|
0 |
0
|
1619948418.162952
NtAllocateVirtualMemory
|
process_identifier:
428
region_size:
917504
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00c00000
|
success
|
0 |
0
|
1619948418.162952
NtAllocateVirtualMemory
|
process_identifier:
428
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00ca0000
|
success
|
0 |
0
|
1619948418.318952
NtProtectVirtualMemory
|
process_identifier:
428
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73e71000
|
success
|
0 |
0
|
1619948418.490952
NtAllocateVirtualMemory
|
process_identifier:
428
region_size:
1048576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00ce0000
|
success
|
0 |
0
|
1619948418.490952
NtAllocateVirtualMemory
|
process_identifier:
428
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00da0000
|
success
|
0 |
0
|
1619948418.490952
NtAllocateVirtualMemory
|
process_identifier:
428
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0039a000
|
success
|
0 |
0
|
1619948418.506952
NtProtectVirtualMemory
|
process_identifier:
428
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73e72000
|
success
|
0 |
0
|
1619948418.506952
NtAllocateVirtualMemory
|
process_identifier:
428
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00392000
|
success
|
0 |
0
|
1619948418.725952
NtAllocateVirtualMemory
|
process_identifier:
428
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003a2000
|
success
|
0 |
0
|
1619948418.803952
NtAllocateVirtualMemory
|
process_identifier:
428
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003d5000
|
success
|
0 |
0
|
1619948418.803952
NtAllocateVirtualMemory
|
process_identifier:
428
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003db000
|
success
|
0 |
0
|
1619948418.803952
NtAllocateVirtualMemory
|
process_identifier:
428
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003d7000
|
success
|
0 |
0
|
1619948418.881952
NtAllocateVirtualMemory
|
process_identifier:
428
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003a3000
|
success
|
0 |
0
|
1619948418.912952
NtAllocateVirtualMemory
|
process_identifier:
428
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003ac000
|
success
|
0 |
0
|
1619948419.287952
NtAllocateVirtualMemory
|
process_identifier:
428
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003a4000
|
success
|
0 |
0
|
1619948419.303952
NtAllocateVirtualMemory
|
process_identifier:
428
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003a6000
|
success
|
0 |
0
|
1619948419.396952
NtAllocateVirtualMemory
|
process_identifier:
428
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003a7000
|
success
|
0 |
0
|
1619948419.396952
NtAllocateVirtualMemory
|
process_identifier:
428
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00540000
|
success
|
0 |
0
|
1619948419.553952
NtAllocateVirtualMemory
|
process_identifier:
428
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003ca000
|
success
|
0 |
0
|
1619948419.553952
NtAllocateVirtualMemory
|
process_identifier:
428
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003c7000
|
success
|
0 |
0
|
1619948419.771952
NtAllocateVirtualMemory
|
process_identifier:
428
region_size:
36864
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00541000
|
success
|
0 |
0
|
1619948419.787952
NtAllocateVirtualMemory
|
process_identifier:
428
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0054a000
|
success
|
0 |
0
|
1619948419.834952
NtAllocateVirtualMemory
|
process_identifier:
428
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003a8000
|
success
|
0 |
0
|
1619948419.959952
NtAllocateVirtualMemory
|
process_identifier:
428
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0039c000
|
success
|
0 |
0
|
1619948420.006952
NtAllocateVirtualMemory
|
process_identifier:
428
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003a9000
|
success
|
0 |
0
|
1619948420.021952
NtAllocateVirtualMemory
|
process_identifier:
428
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005c0000
|
success
|
0 |
0
|
1619948420.053952
NtAllocateVirtualMemory
|
process_identifier:
428
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003c6000
|
success
|
0 |
0
|
1619948420.100952
NtAllocateVirtualMemory
|
process_identifier:
428
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005c1000
|
success
|
0 |
0
|
1619948420.115952
NtAllocateVirtualMemory
|
process_identifier:
428
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0054b000
|
success
|
0 |
0
|
1619948420.146952
NtAllocateVirtualMemory
|
process_identifier:
428
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005c2000
|
success
|
0 |
0
|
1619948420.162952
NtAllocateVirtualMemory
|
process_identifier:
428
region_size:
12288
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0054c000
|
success
|
0 |
0
|
1619948461.678952
NtAllocateVirtualMemory
|
process_identifier:
428
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0054f000
|
success
|
0 |
0
|
1619948461.881952
NtAllocateVirtualMemory
|
process_identifier:
428
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x044f0000
|
success
|
0 |
0
|
1619948462.037952
NtAllocateVirtualMemory
|
process_identifier:
428
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x044f1000
|
success
|
0 |
0
|
1619948462.084952
NtAllocateVirtualMemory
|
process_identifier:
428
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005c3000
|
success
|
0 |
0
|
1619948462.084952
NtAllocateVirtualMemory
|
process_identifier:
428
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003ad000
|
success
|
0 |
0
|
1619948462.100952
NtAllocateVirtualMemory
|
process_identifier:
428
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x044f2000
|
success
|
0 |
0
|
1619948462.193952
NtProtectVirtualMemory
|
process_identifier:
428
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
287744
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x04e70400
|
failed
|
3221225550 |
0
|
1619948467.709952
NtAllocateVirtualMemory
|
process_identifier:
428
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x044f3000
|
success
|
0 |
0
|
1619948467.740952
NtAllocateVirtualMemory
|
process_identifier:
428
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005c4000
|
success
|
0 |
0
|
1619948467.756952
NtAllocateVirtualMemory
|
process_identifier:
428
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x044f4000
|
success
|
0 |
0
|
1619948467.787952
NtAllocateVirtualMemory
|
process_identifier:
428
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x044f5000
|
success
|
0 |
0
|
1619948467.818952
NtAllocateVirtualMemory
|
process_identifier:
428
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x044f6000
|
success
|
0 |
0
|
1619948467.865952
NtAllocateVirtualMemory
|
process_identifier:
428
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x044f7000
|
success
|
0 |
0
|
1619948468.053952
NtAllocateVirtualMemory
|
process_identifier:
428
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x044f8000
|
success
|
0 |
0
|
1619948468.115952
NtAllocateVirtualMemory
|
process_identifier:
428
region_size:
12288
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x044f9000
|
success
|
0 |
0
|
1619948468.131952
NtProtectVirtualMemory
|
process_identifier:
428
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x04e70178
|
failed
|
3221225550 |
0
|
1619948468.131952
NtProtectVirtualMemory
|
process_identifier:
428
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x04e701a0
|
failed
|
3221225550 |
0
|