| Time & API | Arguments | Status | Return | Repeated | 
                            
                        
                        
                            
| 1620808744.87425 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2128 region_size:
            
                
                    524288
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x0000000000730000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620808744.87425 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2128 region_size:
            
                
                    8192
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0000000000730000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620808745.87425 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2128 region_size:
            
                
                    1703936
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x0000000000cf0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620808745.87425 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2128 region_size:
            
                
                    8192
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0000000000e10000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620808745.98425 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2128 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 base_address:
            
                
                    0x000007fef1b41000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620808745.98425 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2128 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 base_address:
            
                
                    0x000007fef1b41000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620808746.01525 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2128 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 base_address:
            
                
                    0x000007fef21c0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620808746.31225 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2128 region_size:
            
                
                    589824
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x0000000000b40000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620808746.31225 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2128 region_size:
            
                
                    8192
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0000000000b50000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620808746.32725 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2128 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 base_address:
            
                
                    0x000007fef1b42000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620808746.32725 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2128 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 base_address:
            
                
                    0x000007fef1b42000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620808746.32725 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2128 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 base_address:
            
                
                    0x000007fef1b42000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620808746.32725 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2128 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 base_address:
            
                
                    0x000007fef1b42000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620808746.32725 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2128 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 base_address:
            
                
                    0x000007fef1b42000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620808746.32725 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2128 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 base_address:
            
                
                    0x000007fef1b43000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620808746.32725 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2128 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 base_address:
            
                
                    0x000007fef1b43000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620808746.32725 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2128 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 base_address:
            
                
                    0x000007fef1b43000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620808746.32725 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2128 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 base_address:
            
                
                    0x000007fef1b43000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620808746.32725 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2128 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 base_address:
            
                
                    0x000007fef1b43000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620808746.32725 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2128 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 base_address:
            
                
                    0x000007fef1b43000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620808746.32725 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2128 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 base_address:
            
                
                    0x000007fef1b43000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620808746.32725 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2128 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 base_address:
            
                
                    0x000007fef1b41000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620808746.32725 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2128 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 base_address:
            
                
                    0x000007fef1b42000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620808746.32725 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2128 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 base_address:
            
                
                    0x000007fef1b42000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620808746.32725 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2128 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 base_address:
            
                
                    0x000007fef1b42000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620808746.32725 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2128 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 base_address:
            
                
                    0x000007fef1b42000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620808746.32725 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2128 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 base_address:
            
                
                    0x000007fef1b42000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620808746.87425 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2128 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x000007ff00052000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620808746.89025 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2128 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x000007ff00042000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620808747.06225 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2128 region_size:
            
                
                    655360
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 allocation_type:
            
                
                    1056768
                
            
            
                (MEM_RESERVE|MEM_TOP_DOWN)
 base_address:
            
                
                    0x000007fffff00000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620808747.07725 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2128 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x000007fffff00000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620808747.07725 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2128 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x000007fffff00000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620808747.07725 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2128 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x000007fffff10000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620808747.09325 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2128 region_size:
            
                
                    65536
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 allocation_type:
            
                
                    1056768
                
            
            
                (MEM_RESERVE|MEM_TOP_DOWN)
 base_address:
            
                
                    0x000007ffffef0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620808747.09325 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2128 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x000007ffffef0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620808747.09325 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2128 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x000007ff0004a000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620808747.20225 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2128 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x000007ff00053000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620808747.21825 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2128 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x000007ff000fc000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620808747.23425 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2128 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x000007ff00126000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620808747.23425 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2128 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x000007ff00100000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620808747.68725 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2128 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x000007ff00054000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620808747.71825 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2128 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x000007ff0004b000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620808747.73425 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2128 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x000007ff0005c000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620808748.73425 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2128 region_size:
            
                
                    20480
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x000007ff00055000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620808748.74925 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2128 region_size:
            
                
                    20480
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x000007ff001e0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620808748.79625 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2128 region_size:
            
                
                    8192
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x000007ff001e5000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620808748.99925 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2128 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x000007ff00210000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620808755.23425 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2128 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x000007ff001e7000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620808755.53125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2128 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x000007ff001e8000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620808755.54625 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2128 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x000007ff001e9000
 
 | success | 0 | 0 |