| Time & API | Arguments | Status | Return | Repeated | 
                            
                        
                        
                            
| 1619910854.502762 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2308 region_size:
            
                
                    1835008
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x00b60000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910854.502762 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2308 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00ce0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910854.924762 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2308 region_size:
            
                
                    1441792
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x009d0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910854.924762 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2308 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00af0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910855.081762 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2308 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x73e71000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910855.377762 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2308 region_size:
            
                
                    1441792
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x00b60000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910855.377762 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2308 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00c80000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910855.377762 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2308 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0041a000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910855.393762 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2308 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    8192
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x73e72000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910855.393762 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2308 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00412000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910855.674762 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2308 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00422000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910855.768762 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2308 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00445000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910855.784762 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2308 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0044b000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910855.784762 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2308 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00447000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910855.877762 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2308 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00423000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910855.909762 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2308 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0042c000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910856.596762 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2308 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00424000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910856.596762 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2308 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00425000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910856.612762 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2308 region_size:
            
                
                    8192
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00426000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910856.815762 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2308 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00428000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910856.815762 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2308 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00429000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910857.127762 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2308 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00830000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910857.237762 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2308 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00840000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910857.237762 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2308 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00436000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910857.237762 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2308 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0043a000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910857.237762 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2308 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00437000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910857.299762 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2308 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00831000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910857.315762 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2308 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00841000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910857.487762 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2308 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00c81000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910857.487762 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2308 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00c82000
 
 | success | 0 | 0 |