| Time & API | Arguments | Status | Return | Repeated | 
                            
                        
                        
                            
| 1620845213.18075 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1940 region_size:
            
                
                    1835008
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x00880000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620845213.18075 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1940 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00a00000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620845213.89875 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    1940 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x73c51000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620845213.94575 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1940 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0042a000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620845213.94575 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    1940 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    8192
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x73c52000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620845213.94575 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1940 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00422000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620845214.36775 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1940 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00532000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620845214.43075 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1940 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00533000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620845214.44575 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1940 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0056b000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620845214.44575 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1940 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00567000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620845214.47675 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1940 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0053c000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620845214.63375 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1940 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00690000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620845214.64875 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1940 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0055a000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620845215.00875 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1940 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00534000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620845215.14875 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1940 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00552000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620845215.19575 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1940 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00565000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620845215.38375 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1940 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00535000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620845215.38375 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1940 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0054a000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620845215.38375 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1940 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00547000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620845215.60175 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1940 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00691000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620845248.63375 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1940 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00692000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620845248.68075 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1940 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00546000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620845248.74275 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1940 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00536000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620845248.74275 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1940 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00693000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620845248.74275 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1940 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00694000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620845248.74275 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1940 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00695000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620845248.74275 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1940 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00696000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620845248.77375 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1940 region_size:
            
                
                    8192
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00697000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620845249.07075 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1940 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00699000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620845250.22675 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1940 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00537000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620845250.22675 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1940 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0069a000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620845250.24275 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1940 region_size:
            
                
                    2097152
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x04ea0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620845250.24275 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1940 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x05060000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620845250.24275 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1940 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x05061000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620845250.25875 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1940 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x05062000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620845250.28975 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1940 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x05063000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620845250.28975 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1940 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x05064000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620845250.28975 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1940 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x05065000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620845250.28975 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1940 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x05066000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620845250.28975 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1940 region_size:
            
                
                    16384
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x05067000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620845250.28975 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1940 region_size:
            
                
                    69632
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0506b000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620845250.28975 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1940 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0507c000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620845250.32075 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1940 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0069b000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620845250.32075 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1940 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0507d000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620845250.32075 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1940 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0507e000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620845250.36775 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1940 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0507f000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620845250.38375 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1940 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00538000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620845250.38375 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1940 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0069c000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620845250.66475 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1940 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00539000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620845250.71175 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1940 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00423000
 
 | success | 0 | 0 |