| Time & API |
Arguments |
Status |
Return |
Repeated |
1619978945.89675
NtAllocateVirtualMemory
|
process_identifier:
708
region_size:
1572864
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00810000
|
success
|
0 |
0
|
1619978945.89675
NtAllocateVirtualMemory
|
process_identifier:
708
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00950000
|
success
|
0 |
0
|
1619978946.38075
NtAllocateVirtualMemory
|
process_identifier:
708
region_size:
1638400
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00cb0000
|
success
|
0 |
0
|
1619978946.38075
NtAllocateVirtualMemory
|
process_identifier:
708
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00e00000
|
success
|
0 |
0
|
1619978946.41275
NtProtectVirtualMemory
|
process_identifier:
708
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73b91000
|
success
|
0 |
0
|
1619978946.49075
NtAllocateVirtualMemory
|
process_identifier:
708
region_size:
2228224
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00e40000
|
success
|
0 |
0
|
1619978946.49075
NtAllocateVirtualMemory
|
process_identifier:
708
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x01020000
|
success
|
0 |
0
|
1619978946.50575
NtAllocateVirtualMemory
|
process_identifier:
708
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003da000
|
success
|
0 |
0
|
1619978946.50575
NtProtectVirtualMemory
|
process_identifier:
708
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73b92000
|
success
|
0 |
0
|
1619978946.50575
NtAllocateVirtualMemory
|
process_identifier:
708
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003d2000
|
success
|
0 |
0
|
1619978946.72475
NtAllocateVirtualMemory
|
process_identifier:
708
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003e2000
|
success
|
0 |
0
|
1619978946.81875
NtAllocateVirtualMemory
|
process_identifier:
708
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00415000
|
success
|
0 |
0
|
1619978946.83475
NtAllocateVirtualMemory
|
process_identifier:
708
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0041b000
|
success
|
0 |
0
|
1619978946.83475
NtAllocateVirtualMemory
|
process_identifier:
708
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00417000
|
success
|
0 |
0
|
1619978946.99075
NtAllocateVirtualMemory
|
process_identifier:
708
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003e3000
|
success
|
0 |
0
|
1619978947.02175
NtAllocateVirtualMemory
|
process_identifier:
708
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003ec000
|
success
|
0 |
0
|
1619978947.61575
NtAllocateVirtualMemory
|
process_identifier:
708
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003e4000
|
success
|
0 |
0
|
1619978947.63075
NtAllocateVirtualMemory
|
process_identifier:
708
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003e6000
|
success
|
0 |
0
|
1619978953.36575
NtAllocateVirtualMemory
|
process_identifier:
708
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00630000
|
success
|
0 |
0
|
1619978953.42775
NtAllocateVirtualMemory
|
process_identifier:
708
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003e7000
|
success
|
0 |
0
|
1619978953.42775
NtAllocateVirtualMemory
|
process_identifier:
708
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003f6000
|
success
|
0 |
0
|
1619978987.22475
NtAllocateVirtualMemory
|
process_identifier:
708
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003dc000
|
success
|
0 |
0
|
1619978987.28775
NtAllocateVirtualMemory
|
process_identifier:
708
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00631000
|
success
|
0 |
0
|
1619978987.30275
NtAllocateVirtualMemory
|
process_identifier:
708
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003fa000
|
success
|
0 |
0
|
1619978987.30275
NtAllocateVirtualMemory
|
process_identifier:
708
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003f7000
|
success
|
0 |
0
|
1619978987.34975
NtAllocateVirtualMemory
|
process_identifier:
708
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003e8000
|
success
|
0 |
0
|
1619978987.44375
NtAllocateVirtualMemory
|
process_identifier:
708
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003e9000
|
success
|
0 |
0
|
1619978987.44375
NtAllocateVirtualMemory
|
process_identifier:
708
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00fd0000
|
success
|
0 |
0
|
1619978987.49075
NtAllocateVirtualMemory
|
process_identifier:
708
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00fd1000
|
success
|
0 |
0
|
1619978987.52175
NtAllocateVirtualMemory
|
process_identifier:
708
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00632000
|
success
|
0 |
0
|
1619978987.52175
NtAllocateVirtualMemory
|
process_identifier:
708
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00fd2000
|
success
|
0 |
0
|
1619978987.53775
NtAllocateVirtualMemory
|
process_identifier:
708
region_size:
12288
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00633000
|
success
|
0 |
0
|
1619978987.53775
NtAllocateVirtualMemory
|
process_identifier:
708
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00636000
|
success
|
0 |
0
|
1619978987.74075
NtProtectVirtualMemory
|
process_identifier:
708
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
421888
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x05410400
|
failed
|
3221225550 |
0
|
1619978991.31875
NtAllocateVirtualMemory
|
process_identifier:
708
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00637000
|
success
|
0 |
0
|
1619978991.33475
NtAllocateVirtualMemory
|
process_identifier:
708
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00fd3000
|
success
|
0 |
0
|
1619978991.33475
NtAllocateVirtualMemory
|
process_identifier:
708
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003ed000
|
success
|
0 |
0
|
1619978991.33475
NtAllocateVirtualMemory
|
process_identifier:
708
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00638000
|
success
|
0 |
0
|
1619978991.34975
NtAllocateVirtualMemory
|
process_identifier:
708
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00639000
|
success
|
0 |
0
|
1619978991.39675
NtAllocateVirtualMemory
|
process_identifier:
708
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0063a000
|
success
|
0 |
0
|
1619978991.41275
NtAllocateVirtualMemory
|
process_identifier:
708
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0063b000
|
success
|
0 |
0
|
1619978991.55275
NtAllocateVirtualMemory
|
process_identifier:
708
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0063c000
|
success
|
0 |
0
|
1619978991.56875
NtAllocateVirtualMemory
|
process_identifier:
708
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0063d000
|
success
|
0 |
0
|
1619978991.56875
NtProtectVirtualMemory
|
process_identifier:
708
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x05410178
|
failed
|
3221225550 |
0
|
1619978991.56875
NtProtectVirtualMemory
|
process_identifier:
708
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x054101a0
|
failed
|
3221225550 |
0
|
1619978991.56875
NtProtectVirtualMemory
|
process_identifier:
708
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x054101c8
|
failed
|
3221225550 |
0
|
1619978991.56875
NtProtectVirtualMemory
|
process_identifier:
708
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x054101f0
|
failed
|
3221225550 |
0
|
1619978991.56875
NtProtectVirtualMemory
|
process_identifier:
708
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x05410218
|
failed
|
3221225550 |
0
|
1619978991.56875
NtProtectVirtualMemory
|
process_identifier:
708
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
11
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x05477d5e
|
failed
|
3221225550 |
0
|
1619978991.56875
NtProtectVirtualMemory
|
process_identifier:
708
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
11
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x05477d52
|
failed
|
3221225550 |
0
|