| Time & API |
Arguments |
Status |
Return |
Repeated |
1619948412.040979
NtAllocateVirtualMemory
|
process_identifier:
2772
region_size:
720896
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x004b0000
|
success
|
0 |
0
|
1619948412.040979
NtAllocateVirtualMemory
|
process_identifier:
2772
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00520000
|
success
|
0 |
0
|
1619948412.384979
NtAllocateVirtualMemory
|
process_identifier:
2772
region_size:
2228224
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00b00000
|
success
|
0 |
0
|
1619948412.384979
NtAllocateVirtualMemory
|
process_identifier:
2772
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00ce0000
|
success
|
0 |
0
|
1619948412.540979
NtProtectVirtualMemory
|
process_identifier:
2772
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73e71000
|
success
|
0 |
0
|
1619948412.681979
NtAllocateVirtualMemory
|
process_identifier:
2772
region_size:
1179648
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x009d0000
|
success
|
0 |
0
|
1619948412.681979
NtAllocateVirtualMemory
|
process_identifier:
2772
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00ab0000
|
success
|
0 |
0
|
1619948412.681979
NtAllocateVirtualMemory
|
process_identifier:
2772
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0051a000
|
success
|
0 |
0
|
1619948412.681979
NtProtectVirtualMemory
|
process_identifier:
2772
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73e72000
|
success
|
0 |
0
|
1619948412.681979
NtAllocateVirtualMemory
|
process_identifier:
2772
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00512000
|
success
|
0 |
0
|
1619948412.900979
NtAllocateVirtualMemory
|
process_identifier:
2772
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00562000
|
success
|
0 |
0
|
1619948413.025979
NtAllocateVirtualMemory
|
process_identifier:
2772
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00585000
|
success
|
0 |
0
|
1619948413.025979
NtAllocateVirtualMemory
|
process_identifier:
2772
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0058b000
|
success
|
0 |
0
|
1619948413.025979
NtAllocateVirtualMemory
|
process_identifier:
2772
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00587000
|
success
|
0 |
0
|
1619948413.119979
NtAllocateVirtualMemory
|
process_identifier:
2772
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00563000
|
success
|
0 |
0
|
1619948413.150979
NtAllocateVirtualMemory
|
process_identifier:
2772
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0056c000
|
success
|
0 |
0
|
1619948413.228979
NtAllocateVirtualMemory
|
process_identifier:
2772
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00a30000
|
success
|
0 |
0
|
1619948413.400979
NtAllocateVirtualMemory
|
process_identifier:
2772
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00564000
|
success
|
0 |
0
|
1619948414.103979
NtAllocateVirtualMemory
|
process_identifier:
2772
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00565000
|
success
|
0 |
0
|
1619948414.150979
NtAllocateVirtualMemory
|
process_identifier:
2772
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00567000
|
success
|
0 |
0
|
1619948414.181979
NtAllocateVirtualMemory
|
process_identifier:
2772
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00a31000
|
success
|
0 |
0
|
1619948414.244979
NtAllocateVirtualMemory
|
process_identifier:
2772
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00513000
|
success
|
0 |
0
|
1619948414.244979
NtAllocateVirtualMemory
|
process_identifier:
2772
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0051c000
|
success
|
0 |
0
|
1619948414.290979
NtAllocateVirtualMemory
|
process_identifier:
2772
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00568000
|
success
|
0 |
0
|
1619948414.322979
NtAllocateVirtualMemory
|
process_identifier:
2772
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00569000
|
success
|
0 |
0
|
1619948414.415979
NtAllocateVirtualMemory
|
process_identifier:
2772
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00de0000
|
success
|
0 |
0
|
1619948414.431979
NtAllocateVirtualMemory
|
process_identifier:
2772
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00576000
|
success
|
0 |
0
|
1619948414.462979
NtAllocateVirtualMemory
|
process_identifier:
2772
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00a32000
|
success
|
0 |
0
|
1619948414.462979
NtAllocateVirtualMemory
|
process_identifier:
2772
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0057a000
|
success
|
0 |
0
|
1619948414.462979
NtAllocateVirtualMemory
|
process_identifier:
2772
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00577000
|
success
|
0 |
0
|
1619948414.494979
NtAllocateVirtualMemory
|
process_identifier:
2772
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00de1000
|
success
|
0 |
0
|
1619948414.525979
NtAllocateVirtualMemory
|
process_identifier:
2772
region_size:
12288
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00a33000
|
success
|
0 |
0
|
1619948414.556979
NtAllocateVirtualMemory
|
process_identifier:
2772
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00a36000
|
success
|
0 |
0
|
1619948455.556979
NtAllocateVirtualMemory
|
process_identifier:
2772
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00de2000
|
success
|
0 |
0
|
1619948455.556979
NtAllocateVirtualMemory
|
process_identifier:
2772
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00a37000
|
success
|
0 |
0
|
1619948455.759979
NtAllocateVirtualMemory
|
process_identifier:
2772
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00a38000
|
success
|
0 |
0
|
1619948455.931979
NtAllocateVirtualMemory
|
process_identifier:
2772
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00a39000
|
success
|
0 |
0
|
1619948455.931979
NtAllocateVirtualMemory
|
process_identifier:
2772
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0056d000
|
success
|
0 |
0
|
1619948455.931979
NtAllocateVirtualMemory
|
process_identifier:
2772
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00de3000
|
success
|
0 |
0
|
1619948455.931979
NtAllocateVirtualMemory
|
process_identifier:
2772
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00a3a000
|
success
|
0 |
0
|
1619948455.978979
NtProtectVirtualMemory
|
process_identifier:
2772
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
292352
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x05700400
|
failed
|
3221225550 |
0
|
1619948461.150979
NtAllocateVirtualMemory
|
process_identifier:
2772
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00a3b000
|
success
|
0 |
0
|
1619948461.181979
NtAllocateVirtualMemory
|
process_identifier:
2772
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00de4000
|
success
|
0 |
0
|
1619948461.197979
NtAllocateVirtualMemory
|
process_identifier:
2772
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00a3c000
|
success
|
0 |
0
|
1619948461.228979
NtAllocateVirtualMemory
|
process_identifier:
2772
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00a3d000
|
success
|
0 |
0
|
1619948461.353979
NtAllocateVirtualMemory
|
process_identifier:
2772
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00a3e000
|
success
|
0 |
0
|
1619948461.384979
NtAllocateVirtualMemory
|
process_identifier:
2772
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00a3f000
|
success
|
0 |
0
|
1619948461.540979
NtAllocateVirtualMemory
|
process_identifier:
2772
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04f80000
|
success
|
0 |
0
|
1619948461.697979
NtAllocateVirtualMemory
|
process_identifier:
2772
region_size:
12288
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04f81000
|
success
|
0 |
0
|
1619948461.697979
NtProtectVirtualMemory
|
process_identifier:
2772
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x05700178
|
failed
|
3221225550 |
0
|