| Time & API |
Arguments |
Status |
Return |
Repeated |
1620018313.057249
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
393216
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00380000
|
success
|
0 |
0
|
1620018313.057249
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x003a0000
|
success
|
0 |
0
|
1620018313.275249
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
589824
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00520000
|
success
|
0 |
0
|
1620018313.275249
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00570000
|
success
|
0 |
0
|
1620018313.353249
NtProtectVirtualMemory
|
process_identifier:
2104
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73e71000
|
success
|
0 |
0
|
1620018313.432249
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
1179648
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00760000
|
success
|
0 |
0
|
1620018313.432249
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00840000
|
success
|
0 |
0
|
1620018313.432249
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0042a000
|
success
|
0 |
0
|
1620018313.432249
NtProtectVirtualMemory
|
process_identifier:
2104
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73e72000
|
success
|
0 |
0
|
1620018313.432249
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00422000
|
success
|
0 |
0
|
1620018313.603249
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00442000
|
success
|
0 |
0
|
1620018313.682249
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00465000
|
success
|
0 |
0
|
1620018313.697249
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0046b000
|
success
|
0 |
0
|
1620018313.697249
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00467000
|
success
|
0 |
0
|
1620018313.775249
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00443000
|
success
|
0 |
0
|
1620018313.869249
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0044c000
|
success
|
0 |
0
|
1620018314.307249
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00444000
|
success
|
0 |
0
|
1620018314.307249
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00446000
|
success
|
0 |
0
|
1620018314.416249
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00447000
|
success
|
0 |
0
|
1620018314.447249
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00830000
|
success
|
0 |
0
|
1620018314.635249
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0045a000
|
success
|
0 |
0
|
1620018314.635249
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00457000
|
success
|
0 |
0
|
1620018314.869249
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
36864
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00831000
|
success
|
0 |
0
|
1620018314.885249
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0083a000
|
success
|
0 |
0
|
1620018314.947249
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00448000
|
success
|
0 |
0
|
1620018315.135249
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0042c000
|
success
|
0 |
0
|
1620018315.182249
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00449000
|
success
|
0 |
0
|
1620018315.213249
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00a80000
|
success
|
0 |
0
|
1620018315.244249
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00456000
|
success
|
0 |
0
|
1620018315.291249
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00a81000
|
success
|
0 |
0
|
1620018315.307249
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0083b000
|
success
|
0 |
0
|
1620018315.353249
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00a82000
|
success
|
0 |
0
|
1620018315.369249
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
12288
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0083c000
|
success
|
0 |
0
|
1620018356.900249
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0083f000
|
success
|
0 |
0
|
1620018357.072249
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04d90000
|
success
|
0 |
0
|
1620018357.182249
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04d91000
|
success
|
0 |
0
|
1620018357.213249
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00a83000
|
success
|
0 |
0
|
1620018357.213249
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0044d000
|
success
|
0 |
0
|
1620018357.228249
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04d92000
|
success
|
0 |
0
|
1620018357.338249
NtProtectVirtualMemory
|
process_identifier:
2104
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
132608
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x04ea0400
|
failed
|
3221225550 |
0
|
1620018359.572249
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04d93000
|
success
|
0 |
0
|
1620018359.572249
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00a84000
|
success
|
0 |
0
|
1620018359.572249
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04d94000
|
success
|
0 |
0
|
1620018359.572249
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04d95000
|
success
|
0 |
0
|
1620018359.572249
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04d96000
|
success
|
0 |
0
|
1620018359.650249
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04d97000
|
success
|
0 |
0
|
1620018359.775249
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04d98000
|
success
|
0 |
0
|
1620018359.963249
NtAllocateVirtualMemory
|
process_identifier:
2104
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04d99000
|
success
|
0 |
0
|
1620018359.978249
NtProtectVirtualMemory
|
process_identifier:
2104
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x04ea0178
|
failed
|
3221225550 |
0
|
1620018359.994249
NtProtectVirtualMemory
|
process_identifier:
2104
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x04ea01a0
|
failed
|
3221225550 |
0
|