| Time & API | Arguments | Status | Return | Repeated | 
                            
                        
                        
                            
| 1620762746.547125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1404 region_size:
            
                
                    1179648
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x00730000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620762746.547125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1404 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00810000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620762748.282125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1404 region_size:
            
                
                    1048576
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x00540000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620762748.282125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1404 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00600000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620762748.407125 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    1404 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x73b91000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620762748.610125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1404 region_size:
            
                
                    1703936
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x021f0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620762748.610125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1404 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x02350000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620762748.610125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1404 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0040a000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620762748.610125 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    1404 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    8192
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x73b92000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620762748.610125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1404 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00402000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620762748.860125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1404 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00412000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620762748.907125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1404 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00435000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620762748.922125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1404 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0043b000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620762748.922125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1404 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00437000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620762749.078125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1404 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00413000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620762749.094125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1404 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0041c000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620762749.188125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1404 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00640000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620762749.219125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1404 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00426000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620762749.219125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1404 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0042a000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620762749.219125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1404 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00427000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620762749.266125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1404 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00414000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620762749.594125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1404 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00415000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620762749.719125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1404 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00641000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620762751.938125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1404 region_size:
            
                
                    12288
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
 base_address:
            
                
                    0x008a0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620762757.235125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1404 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00642000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620770354.48025 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1712 region_size:
            
                
                    3158016
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
 base_address:
            
                
                    0x02720000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620770355.761125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1176 region_size:
            
                
                    589824
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x003f0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620770355.761125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1176 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00440000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620770355.793125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1176 region_size:
            
                
                    1179648
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x00ac0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620770355.793125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1176 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00ba0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620770355.793125 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    1176 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x73b91000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620770355.793125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1176 region_size:
            
                
                    1179648
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x02060000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620770355.793125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1176 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x02140000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620770355.793125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1176 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x002da000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620770355.793125 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    1176 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    8192
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x73b92000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620770355.793125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1176 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x002d2000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620770355.808125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1176 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x002e2000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620770355.808125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1176 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00405000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620770355.808125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1176 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0040b000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620770355.808125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1176 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00407000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620770355.808125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1176 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x002e3000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620770355.808125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1176 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x002ec000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620770355.808125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1176 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00520000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620770355.808125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1176 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003f6000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620770355.808125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1176 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003fa000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620770355.808125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1176 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003f7000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620770355.824125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1176 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x002e4000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620770355.824125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1176 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x002e5000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620770355.840125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1176 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00521000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620770357.840125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1176 region_size:
            
                
                    12288
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
 base_address:
            
                
                    0x02060000
 
 | success | 0 | 0 |