| Time & API | Arguments | Status | Return | Repeated | 
                            
                        
                        
                            
| 1620795388.64475 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1688 region_size:
            
                
                    2293760
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x00a00000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620795388.64475 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1688 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00bf0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620795389.42675 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1688 region_size:
            
                
                    1572864
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x00c30000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620795389.42675 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1688 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00d70000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620795389.51975 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    1688 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x73b91000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620795389.75475 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1688 region_size:
            
                
                    1310720
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x00680000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620795389.75475 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1688 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00780000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620795389.75475 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1688 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003aa000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620795389.76975 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    1688 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    8192
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x73b92000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620795389.76975 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1688 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003a2000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620795390.14475 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1688 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00432000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620795390.23875 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1688 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00455000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620795390.23875 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1688 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0045b000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620795390.23875 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1688 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00457000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620795390.41075 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1688 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00433000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620795390.44175 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1688 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0043c000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620795395.06675 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1688 region_size:
            
                
                    8192
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00434000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620795395.08275 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1688 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00436000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620795395.22375 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1688 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00437000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620795395.23875 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1688 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00720000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620795395.42675 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1688 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00438000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620795395.44175 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1688 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00439000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620795395.47375 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1688 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0044a000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620795395.47375 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1688 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00447000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620795395.67675 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1688 region_size:
            
                
                    16384
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00721000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620795395.69175 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1688 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003ac000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620795396.26975 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1688 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0043a000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620795396.37975 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1688 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00c30000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620795396.73875 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1688 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00c31000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620795396.89475 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1688 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00c60000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620795430.67675 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1688 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00446000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620795430.69175 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1688 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00725000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620795430.69175 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1688 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0044b000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620795430.70775 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1688 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00c32000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620795430.80175 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1688 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00c33000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620795430.80175 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1688 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00c34000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620795430.83275 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1688 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00c35000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620795430.84875 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1688 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003a3000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620795430.89475 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1688 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00726000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620795430.89475 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1688 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00c36000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620795430.89475 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1688 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0043d000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620795430.92675 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1688 region_size:
            
                
                    12288
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00727000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620795430.94175 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1688 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0072a000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620795431.03575 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    1688 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    324096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x04eb0400
 
 | failed | 3221225550 | 0 | 
                    
                
                    
                        
                        
                            
| 1620795433.81675 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1688 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0072b000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620795433.81675 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1688 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00c37000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620795433.81675 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1688 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0072c000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620795433.83275 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1688 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0072d000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620795433.83275 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1688 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0072e000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620795433.84875 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1688 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0072f000
 
 | success | 0 | 0 |