| Time & API | Arguments | Status | Return | Repeated | 
                            
                        
                        
                            
| 1620833920.755125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    392 region_size:
            
                
                    1703936
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x00af0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620833920.755125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    392 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00c50000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620833921.208125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    392 region_size:
            
                
                    1179648
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x007f0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620833921.208125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    392 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x008d0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620833921.255125 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    392 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x73b91000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620833921.349125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    392 region_size:
            
                
                    2097152
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x00fb0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620833921.349125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    392 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x01170000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620833921.364125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    392 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0029a000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620833921.364125 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    392 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    8192
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x73b92000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620833921.364125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    392 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00292000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620833921.630125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    392 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x002a2000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620833922.271125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    392 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x002c5000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620833922.286125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    392 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x002cb000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620833922.286125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    392 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x002c7000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620833922.474125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    392 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x002a3000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620833922.536125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    392 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x002ac000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620833922.568125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    392 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00600000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620833922.693125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    392 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x002a4000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620833922.693125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    392 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x002a5000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620833922.724125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    392 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x002a6000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620833922.771125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    392 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00601000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620833922.802125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    392 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x002b6000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620833922.896125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    392 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x002ba000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620833922.896125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    392 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x002b7000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620833922.911125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    392 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x002a7000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620833922.911125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    392 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00602000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620833922.927125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    392 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00603000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620833922.974125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    392 region_size:
            
                
                    12288
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00604000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620833923.427125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    392 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x002a8000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620833923.443125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    392 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x002a9000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620833923.505125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    392 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00607000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620833923.552125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    392 region_size:
            
                
                    8192
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00608000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620833924.411125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    392 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00b10000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620833924.646125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    392 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x04ff0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620833924.646125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    392 region_size:
            
                
                    139264
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x04ff1000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620833924.786125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    392 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x05013000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620833924.786125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    392 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x002ad000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620833925.099125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    392 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00b11000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620833925.114125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    392 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x05014000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620833925.193125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    392 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x05015000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620833925.302125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    392 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x05016000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620833925.349125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    392 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x05017000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620833925.349125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    392 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00b12000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620833925.349125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    392 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0029c000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620833925.349125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    392 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00293000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620833925.349125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    392 region_size:
            
                
                    16384
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x05018000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620833929.677125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    392 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0501c000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620833932.349125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    392 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0501d000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620833932.661125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    392 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0501e000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620833943.880125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    392 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00b13000
 
 | success | 0 | 0 |