| Time & API |
Arguments |
Status |
Return |
Repeated |
1619999682.4153
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
2097152
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00850000
|
success
|
0 |
0
|
1619999682.4313
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00a10000
|
success
|
0 |
0
|
1619999682.9783
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
589824
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x004b0000
|
success
|
0 |
0
|
1619999682.9783
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00500000
|
success
|
0 |
0
|
1619999683.0563
NtProtectVirtualMemory
|
process_identifier:
2296
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73e71000
|
success
|
0 |
0
|
1619999683.1183
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
1441792
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00a50000
|
success
|
0 |
0
|
1619999683.1183
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00b70000
|
success
|
0 |
0
|
1619999683.1183
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0035a000
|
success
|
0 |
0
|
1619999683.1183
NtProtectVirtualMemory
|
process_identifier:
2296
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73e72000
|
success
|
0 |
0
|
1619999683.1183
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00352000
|
success
|
0 |
0
|
1619999683.3373
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00362000
|
success
|
0 |
0
|
1619999683.4623
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00485000
|
success
|
0 |
0
|
1619999683.4623
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0048b000
|
success
|
0 |
0
|
1619999683.4623
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00487000
|
success
|
0 |
0
|
1619999683.5563
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00363000
|
success
|
0 |
0
|
1619999683.6033
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00364000
|
success
|
0 |
0
|
1619999683.6033
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0036c000
|
success
|
0 |
0
|
1619999683.6653
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x009f0000
|
success
|
0 |
0
|
1619999683.7123
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00365000
|
success
|
0 |
0
|
1619999683.7903
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00366000
|
success
|
0 |
0
|
1619999683.8063
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x009f1000
|
success
|
0 |
0
|
1619999683.9313
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00367000
|
success
|
0 |
0
|
1619999683.9623
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x009f2000
|
success
|
0 |
0
|
1619999683.9933
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00368000
|
success
|
0 |
0
|
1619999683.9933
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00a0f000
|
success
|
0 |
0
|
1619999683.9933
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00a00000
|
success
|
0 |
0
|
1619999684.0253
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00476000
|
success
|
0 |
0
|
1619999684.1343
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0047a000
|
success
|
0 |
0
|
1619999684.1343
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00477000
|
success
|
0 |
0
|
1619999684.1503
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x009f3000
|
success
|
0 |
0
|
1619999684.1503
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x009f4000
|
success
|
0 |
0
|
1619999684.2593
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00369000
|
success
|
0 |
0
|
1619999684.2903
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00af0000
|
success
|
0 |
0
|
1619999684.3223
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
12288
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x009f5000
|
success
|
0 |
0
|
1619999684.3843
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x009f8000
|
success
|
0 |
0
|
1619999684.4623
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00af1000
|
success
|
0 |
0
|
1619999684.4933
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00b71000
|
success
|
0 |
0
|
1619999684.5093
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00b72000
|
success
|
0 |
0
|
1619999684.5253
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
12288
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00b73000
|
success
|
0 |
0
|
1619999684.5253
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
16384
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00b76000
|
success
|
0 |
0
|
1619999684.5253
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
20480
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00b7a000
|
success
|
0 |
0
|
1619999684.5403
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00af2000
|
success
|
0 |
0
|
1619999684.6503
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00af3000
|
success
|
0 |
0
|
1619999684.6503
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x0036d000
|
success
|
0 |
0
|
1619999684.8223
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00af4000
|
success
|
0 |
0
|
1619999684.8373
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x009f9000
|
success
|
0 |
0
|
1619999684.8683
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x009fa000
|
success
|
0 |
0
|
1619999685.0563
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
16384
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00b7f000
|
success
|
0 |
0
|
1619999685.0563
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
69632
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00b83000
|
success
|
0 |
0
|
1619999685.1033
NtAllocateVirtualMemory
|
process_identifier:
2296
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x009fc000
|
success
|
0 |
0
|