| Time & API | Arguments | Status | Return | Repeated | 
                            
                        
                        
                            
| 1620833529.744374 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2520 region_size:
            
                
                    917504
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x007f0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620833529.744374 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2520 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00890000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620833531.041374 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2520 region_size:
            
                
                    983040
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x01ff0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620833531.041374 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2520 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x020a0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620833531.072374 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2520 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x73b91000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620833531.150374 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2520 region_size:
            
                
                    524288
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x00570000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620833531.150374 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2520 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005b0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620833531.150374 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2520 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0048a000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620833531.150374 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2520 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    8192
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x73b92000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620833531.150374 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2520 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00482000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620833531.400374 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2520 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00492000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620833531.494374 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2520 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x004c5000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620833531.494374 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2520 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x004cb000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620833531.494374 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2520 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x004c7000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620833531.666374 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2520 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00493000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620833531.697374 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2520 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0049c000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620833531.775374 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2520 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00494000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620833531.791374 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2520 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x006e0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620833531.978374 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2520 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00495000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620833532.306374 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2520 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00496000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620833532.384374 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2520 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0083f000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620833532.384374 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2520 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00830000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620833533.525374 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2520 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00497000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620833533.775374 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2520 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00498000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620833534.759374 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2520 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x004b6000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620833534.759374 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2520 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x006e1000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620833535.822374 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2520 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x004ba000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620833535.822374 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2520 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x004b7000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620833535.822374 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2520 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x006e2000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620833535.838374 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2520 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x006e3000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620833535.916374 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2520 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00499000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620833536.353374 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2520 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00840000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620833536.478374 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2520 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x006e4000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620833582.041374 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2520 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00841000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1620833582.759374 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2520 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x004bb000
 
 | success | 0 | 0 |