| Time & API |
Arguments |
Status |
Return |
Repeated |
1619999685.100429
NtAllocateVirtualMemory
|
process_identifier:
2636
region_size:
262144
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00420000
|
success
|
0 |
0
|
1619999685.100429
NtAllocateVirtualMemory
|
process_identifier:
2636
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00420000
|
success
|
0 |
0
|
1619999685.569429
NtAllocateVirtualMemory
|
process_identifier:
2636
region_size:
851968
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x005d0000
|
success
|
0 |
0
|
1619999685.569429
NtAllocateVirtualMemory
|
process_identifier:
2636
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00660000
|
success
|
0 |
0
|
1619999685.615429
NtProtectVirtualMemory
|
process_identifier:
2636
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73e71000
|
success
|
0 |
0
|
1619999685.694429
NtAllocateVirtualMemory
|
process_identifier:
2636
region_size:
2097152
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x02010000
|
success
|
0 |
0
|
1619999685.694429
NtAllocateVirtualMemory
|
process_identifier:
2636
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x021d0000
|
success
|
0 |
0
|
1619999685.694429
NtAllocateVirtualMemory
|
process_identifier:
2636
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004ca000
|
success
|
0 |
0
|
1619999685.694429
NtProtectVirtualMemory
|
process_identifier:
2636
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73e72000
|
success
|
0 |
0
|
1619999685.694429
NtAllocateVirtualMemory
|
process_identifier:
2636
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004c2000
|
success
|
0 |
0
|
1619999685.897429
NtAllocateVirtualMemory
|
process_identifier:
2636
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005d2000
|
success
|
0 |
0
|
1619999685.959429
NtAllocateVirtualMemory
|
process_identifier:
2636
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005f5000
|
success
|
0 |
0
|
1619999685.959429
NtAllocateVirtualMemory
|
process_identifier:
2636
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005fb000
|
success
|
0 |
0
|
1619999685.959429
NtAllocateVirtualMemory
|
process_identifier:
2636
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005f7000
|
success
|
0 |
0
|
1619999686.053429
NtAllocateVirtualMemory
|
process_identifier:
2636
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005d3000
|
success
|
0 |
0
|
1619999686.053429
NtAllocateVirtualMemory
|
process_identifier:
2636
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005d4000
|
success
|
0 |
0
|
1619999686.069429
NtAllocateVirtualMemory
|
process_identifier:
2636
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005dc000
|
success
|
0 |
0
|
1619999686.115429
NtAllocateVirtualMemory
|
process_identifier:
2636
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00810000
|
success
|
0 |
0
|
1619999686.178429
NtAllocateVirtualMemory
|
process_identifier:
2636
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x021d1000
|
success
|
0 |
0
|
1619999686.178429
NtAllocateVirtualMemory
|
process_identifier:
2636
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x021d2000
|
success
|
0 |
0
|
1619999686.225429
NtAllocateVirtualMemory
|
process_identifier:
2636
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005d5000
|
success
|
0 |
0
|
1619999686.240429
NtAllocateVirtualMemory
|
process_identifier:
2636
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005e6000
|
success
|
0 |
0
|
1619999686.256429
NtAllocateVirtualMemory
|
process_identifier:
2636
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00811000
|
success
|
0 |
0
|
1619999686.303429
NtAllocateVirtualMemory
|
process_identifier:
2636
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x021d3000
|
success
|
0 |
0
|
1619999686.303429
NtAllocateVirtualMemory
|
process_identifier:
2636
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x021d4000
|
success
|
0 |
0
|
1619999686.381429
NtAllocateVirtualMemory
|
process_identifier:
2636
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x021d5000
|
success
|
0 |
0
|
1619999686.397429
NtAllocateVirtualMemory
|
process_identifier:
2636
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00812000
|
success
|
0 |
0
|
1619999686.397429
NtAllocateVirtualMemory
|
process_identifier:
2636
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005ea000
|
success
|
0 |
0
|
1619999686.397429
NtAllocateVirtualMemory
|
process_identifier:
2636
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005e7000
|
success
|
0 |
0
|
1619999686.490429
NtAllocateVirtualMemory
|
process_identifier:
2636
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005d6000
|
success
|
0 |
0
|
1619999686.490429
NtAllocateVirtualMemory
|
process_identifier:
2636
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005d7000
|
success
|
0 |
0
|
1619999686.709429
NtAllocateVirtualMemory
|
process_identifier:
2636
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005d8000
|
success
|
0 |
0
|
1619999686.803429
NtAllocateVirtualMemory
|
process_identifier:
2636
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00813000
|
success
|
0 |
0
|
1619999686.819429
NtAllocateVirtualMemory
|
process_identifier:
2636
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005d9000
|
success
|
0 |
0
|
1619999686.834429
NtAllocateVirtualMemory
|
process_identifier:
2636
region_size:
12288
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00814000
|
success
|
0 |
0
|
1619999687.022429
NtAllocateVirtualMemory
|
process_identifier:
2636
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00830000
|
success
|
0 |
0
|
1619999725.053429
NtAllocateVirtualMemory
|
process_identifier:
2636
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00817000
|
success
|
0 |
0
|
1619999725.069429
NtAllocateVirtualMemory
|
process_identifier:
2636
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00831000
|
success
|
0 |
0
|
1619999725.272429
NtAllocateVirtualMemory
|
process_identifier:
2636
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x004cc000
|
success
|
0 |
0
|
1619999725.319429
NtAllocateVirtualMemory
|
process_identifier:
2636
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00818000
|
success
|
0 |
0
|
1619999725.334429
NtAllocateVirtualMemory
|
process_identifier:
2636
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00832000
|
success
|
0 |
0
|
1619999725.350429
NtAllocateVirtualMemory
|
process_identifier:
2636
region_size:
16384
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x021d6000
|
success
|
0 |
0
|
1619999725.350429
NtAllocateVirtualMemory
|
process_identifier:
2636
region_size:
69632
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x021da000
|
success
|
0 |
0
|
1619999725.350429
NtAllocateVirtualMemory
|
process_identifier:
2636
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x021eb000
|
success
|
0 |
0
|
1619999725.350429
NtAllocateVirtualMemory
|
process_identifier:
2636
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x021ec000
|
success
|
0 |
0
|
1619999725.350429
NtAllocateVirtualMemory
|
process_identifier:
2636
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x021ed000
|
success
|
0 |
0
|
1619999725.350429
NtAllocateVirtualMemory
|
process_identifier:
2636
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x021ee000
|
success
|
0 |
0
|
1619999725.350429
NtAllocateVirtualMemory
|
process_identifier:
2636
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x005dd000
|
success
|
0 |
0
|
1619999725.365429
NtAllocateVirtualMemory
|
process_identifier:
2636
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00819000
|
success
|
0 |
0
|
1619999725.365429
NtAllocateVirtualMemory
|
process_identifier:
2636
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x021ef000
|
success
|
0 |
0
|