| Time & API |
Arguments |
Status |
Return |
Repeated |
1619974260.585374
NtAllocateVirtualMemory
|
process_identifier:
2900
region_size:
1966080
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00760000
|
success
|
0 |
0
|
1619974260.585374
NtAllocateVirtualMemory
|
process_identifier:
2900
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00900000
|
success
|
0 |
0
|
1619974261.007374
NtAllocateVirtualMemory
|
process_identifier:
2900
region_size:
1376256
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x005e0000
|
success
|
0 |
0
|
1619974261.007374
NtAllocateVirtualMemory
|
process_identifier:
2900
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006f0000
|
success
|
0 |
0
|
1619974261.038374
NtProtectVirtualMemory
|
process_identifier:
2900
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73b91000
|
success
|
0 |
0
|
1619974261.147374
NtAllocateVirtualMemory
|
process_identifier:
2900
region_size:
262144
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x005e0000
|
success
|
0 |
0
|
1619974261.147374
NtAllocateVirtualMemory
|
process_identifier:
2900
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005e0000
|
success
|
0 |
0
|
1619974261.147374
NtAllocateVirtualMemory
|
process_identifier:
2900
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0043a000
|
success
|
0 |
0
|
1619974261.147374
NtProtectVirtualMemory
|
process_identifier:
2900
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73b92000
|
success
|
0 |
0
|
1619974261.147374
NtAllocateVirtualMemory
|
process_identifier:
2900
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00432000
|
success
|
0 |
0
|
1619974261.366374
NtAllocateVirtualMemory
|
process_identifier:
2900
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00442000
|
success
|
0 |
0
|
1619974261.507374
NtAllocateVirtualMemory
|
process_identifier:
2900
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00475000
|
success
|
0 |
0
|
1619974261.507374
NtAllocateVirtualMemory
|
process_identifier:
2900
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0047b000
|
success
|
0 |
0
|
1619974261.507374
NtAllocateVirtualMemory
|
process_identifier:
2900
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00477000
|
success
|
0 |
0
|
1619974261.772374
NtAllocateVirtualMemory
|
process_identifier:
2900
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00443000
|
success
|
0 |
0
|
1619974261.928374
NtAllocateVirtualMemory
|
process_identifier:
2900
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0044c000
|
success
|
0 |
0
|
1619974262.772374
NtAllocateVirtualMemory
|
process_identifier:
2900
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00444000
|
success
|
0 |
0
|
1619974262.772374
NtAllocateVirtualMemory
|
process_identifier:
2900
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00446000
|
success
|
0 |
0
|
1619974262.928374
NtAllocateVirtualMemory
|
process_identifier:
2900
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006d0000
|
success
|
0 |
0
|
1619974263.085374
NtAllocateVirtualMemory
|
process_identifier:
2900
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0046a000
|
success
|
0 |
0
|
1619974263.085374
NtAllocateVirtualMemory
|
process_identifier:
2900
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00467000
|
success
|
0 |
0
|
1619974263.225374
NtAllocateVirtualMemory
|
process_identifier:
2900
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00466000
|
success
|
0 |
0
|
1619974263.350374
NtAllocateVirtualMemory
|
process_identifier:
2900
region_size:
16384
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006d1000
|
success
|
0 |
0
|
1619974263.944374
NtAllocateVirtualMemory
|
process_identifier:
2900
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0044a000
|
success
|
0 |
0
|
1619974264.522374
NtAllocateVirtualMemory
|
process_identifier:
2900
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00447000
|
success
|
0 |
0
|
1619974297.600374
NtAllocateVirtualMemory
|
process_identifier:
2900
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006f1000
|
success
|
0 |
0
|
1619974297.913374
NtAllocateVirtualMemory
|
process_identifier:
2900
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0043c000
|
success
|
0 |
0
|
1619974297.913374
NtAllocateVirtualMemory
|
process_identifier:
2900
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006d5000
|
success
|
0 |
0
|
1619974298.038374
NtAllocateVirtualMemory
|
process_identifier:
2900
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00448000
|
success
|
0 |
0
|
1619974298.132374
NtAllocateVirtualMemory
|
process_identifier:
2900
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00449000
|
success
|
0 |
0
|
1619974298.132374
NtAllocateVirtualMemory
|
process_identifier:
2900
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x059a0000
|
success
|
0 |
0
|
1619974298.194374
NtAllocateVirtualMemory
|
process_identifier:
2900
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x059a1000
|
success
|
0 |
0
|
1619974298.210374
NtAllocateVirtualMemory
|
process_identifier:
2900
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006d6000
|
success
|
0 |
0
|
1619974298.225374
NtAllocateVirtualMemory
|
process_identifier:
2900
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x059a2000
|
success
|
0 |
0
|
1619974298.241374
NtAllocateVirtualMemory
|
process_identifier:
2900
region_size:
12288
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006d7000
|
success
|
0 |
0
|
1619974298.241374
NtAllocateVirtualMemory
|
process_identifier:
2900
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006da000
|
success
|
0 |
0
|
1619974298.428374
NtProtectVirtualMemory
|
process_identifier:
2900
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
379904
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x05ea0400
|
failed
|
3221225550 |
0
|
1619974301.694374
NtAllocateVirtualMemory
|
process_identifier:
2900
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006db000
|
success
|
0 |
0
|
1619974301.710374
NtAllocateVirtualMemory
|
process_identifier:
2900
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x059a3000
|
success
|
0 |
0
|
1619974301.710374
NtAllocateVirtualMemory
|
process_identifier:
2900
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0044d000
|
success
|
0 |
0
|
1619974301.710374
NtAllocateVirtualMemory
|
process_identifier:
2900
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006dc000
|
success
|
0 |
0
|
1619974301.725374
NtAllocateVirtualMemory
|
process_identifier:
2900
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006dd000
|
success
|
0 |
0
|
1619974301.725374
NtAllocateVirtualMemory
|
process_identifier:
2900
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006de000
|
success
|
0 |
0
|
1619974301.772374
NtAllocateVirtualMemory
|
process_identifier:
2900
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x006df000
|
success
|
0 |
0
|
1619974301.897374
NtAllocateVirtualMemory
|
process_identifier:
2900
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x05a00000
|
success
|
0 |
0
|
1619974301.913374
NtAllocateVirtualMemory
|
process_identifier:
2900
region_size:
12288
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x05a01000
|
success
|
0 |
0
|
1619974301.913374
NtProtectVirtualMemory
|
process_identifier:
2900
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x05ea0178
|
failed
|
3221225550 |
0
|
1619974301.913374
NtProtectVirtualMemory
|
process_identifier:
2900
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x05ea01a0
|
failed
|
3221225550 |
0
|
1619974301.913374
NtProtectVirtualMemory
|
process_identifier:
2900
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x05ea01c8
|
failed
|
3221225550 |
0
|
1619974301.913374
NtProtectVirtualMemory
|
process_identifier:
2900
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x05ea01f0
|
failed
|
3221225550 |
0
|