| Time & API | Arguments | Status | Return | Repeated | 
                            
                        
                        
                            
| 1620836667.412249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1888 region_size:
            
                
                    655360
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x00480000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620836667.412249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1888 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x004e0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620836667.943249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1888 region_size:
            
                
                    1179648
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x00900000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620836667.943249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1888 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x009e0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620836667.974249 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    1888 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x73b91000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620836668.037249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1888 region_size:
            
                
                    262144
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x00520000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620836668.037249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1888 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00520000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620836668.037249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1888 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0039a000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620836668.037249 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    1888 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    8192
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x73b92000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620836668.037249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1888 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00392000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620836668.271249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1888 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003a2000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620836668.474249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1888 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00495000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620836668.474249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1888 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0049b000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620836668.474249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1888 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00497000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620836668.615249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1888 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003a3000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620836668.834249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1888 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003a4000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620836668.834249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1888 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003a5000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620836668.849249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1888 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003ac000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620836669.443249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1888 region_size:
            
                
                    8192
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003a6000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620836669.443249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1888 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003a8000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620836669.584249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1888 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00730000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620836669.771249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1888 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0048a000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620836669.771249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1888 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00487000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620836669.959249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1888 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003a9000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620836670.006249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1888 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00750000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620836671.928249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1888 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00751000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620836673.693249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1888 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00486000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620836673.693249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1888 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00731000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620836674.428249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1888 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00752000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620836674.568249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1888 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00753000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620836674.584249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1888 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00732000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620836674.724249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1888 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003ad000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620836674.787249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1888 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00754000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620836674.787249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1888 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00755000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620836674.787249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1888 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00733000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620836674.803249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1888 region_size:
            
                
                    327680
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    1056768
                
            
            
                (MEM_RESERVE|MEM_TOP_DOWN)
 base_address:
            
                
                    0x7ef40000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620836674.803249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1888 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x7ef40000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620836674.803249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1888 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x7ef40000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620836674.803249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1888 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x7ef48000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620836674.803249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1888 region_size:
            
                
                    65536
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    1056768
                
            
            
                (MEM_RESERVE|MEM_TOP_DOWN)
 base_address:
            
                
                    0x7ef30000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620836674.818249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1888 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x7ef30000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620836674.912249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1888 region_size:
            
                
                    16384
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00734000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620836675.053249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1888 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00756000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620836675.099249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1888 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00757000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620836675.099249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1888 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00393000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620836726.287249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1888 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00738000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620836726.381249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1888 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00739000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620836727.006249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1888 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0073a000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620836727.459249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1888 region_size:
            
                
                    20480
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0073b000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620836728.662249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1888 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x009e1000
 
 | success | 0 | 0 |