| Time & API | Arguments | Status | Return | Repeated | 
                            
                        
                        
                            
| 1619910850.863598 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2852 region_size:
            
                
                    2097152
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x00b10000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910850.863598 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2852 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00cd0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910851.785598 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2852 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x73f31000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910851.879598 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2852 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003ba000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910851.879598 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2852 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    8192
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x73f32000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910851.879598 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2852 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003b2000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910852.066598 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2852 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003c2000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910852.176598 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2852 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003c3000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910852.191598 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2852 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003fb000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910852.191598 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2852 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003f7000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910852.222598 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2852 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003cc000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910852.301598 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2852 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00590000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910852.363598 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2852 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00591000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910852.363598 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2852 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003c4000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910852.379598 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2852 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00592000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910852.582598 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2852 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00593000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910852.629598 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2852 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003ca000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910852.707598 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2852 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003ea000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910852.722598 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2852 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003e2000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910852.785598 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2852 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003c5000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910852.801598 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2852 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003f5000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910853.191598 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2852 region_size:
            
                
                    8192
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003c6000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910853.285598 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2852 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003da000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910853.285598 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2852 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003d7000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910853.285598 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2852 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003bb000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910853.332598 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2852 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003d6000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910853.426598 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2852 region_size:
            
                
                    12288
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00594000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910853.457598 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2852 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00597000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910853.472598 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2852 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00ab0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910854.082598 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2852 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003c8000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910854.097598 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2852 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00598000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910854.129598 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2852 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00cd1000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910854.347598 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2852 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003c9000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910854.363598 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2852 region_size:
            
                
                    2228224
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x05560000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910854.363598 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2852 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x05740000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910854.363598 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2852 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x05741000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910854.394598 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2852 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x05742000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910854.410598 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2852 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x05743000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910854.410598 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2852 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x05744000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910854.410598 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2852 region_size:
            
                
                    16384
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x05745000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910854.410598 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2852 region_size:
            
                
                    69632
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x05749000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910854.410598 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2852 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0575a000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910854.410598 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2852 region_size:
            
                
                    8192
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0575b000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910854.410598 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2852 region_size:
            
                
                    12288
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0575d000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910854.426598 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2852 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x02190000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910854.457598 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2852 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00599000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910854.472598 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2852 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0059a000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910854.551598 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2852 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00ab1000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910854.566598 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2852 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003cb000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910854.582598 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2852 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0059b000
 
 | success | 0 | 0 |