| Time & API | 
                                    Arguments | 
                                    Status | 
                                    Return | 
                                    Repeated | 
                                
                            
                        
                        
                            
    1619910854.289784 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    732
                
            
            
             
        
    
        
            region_size:
            
                
                    786432
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
            
             
        
    
        
            base_address:
            
                
                    0x006e0000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910854.289784 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    732
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x00760000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910854.664784 
    NtProtectVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    732
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            length:
            
                
                    4096
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            base_address:
            
                
                    0x73f31000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910854.742784 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    732
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x003ca000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910854.742784 
    NtProtectVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    732
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            length:
            
                
                    8192
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            base_address:
            
                
                    0x73f32000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910854.742784 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    732
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x003c2000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910854.929784 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    732
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x003d2000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910854.976784 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    732
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x003d3000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910855.008784 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    732
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x0040b000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910855.008784 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    732
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x00407000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910855.023784 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    732
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x003dc000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910855.070784 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    732
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x003e6000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910855.086784 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    732
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x00620000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910855.336784 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    732
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x003d4000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910855.367784 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    732
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x00621000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910855.398784 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    732
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x003fa000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910855.414784 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    732
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x003f2000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910855.476784 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    732
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x00405000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910855.601784 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    732
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x003ea000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910855.601784 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    732
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x003e7000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910855.742784 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    732
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x003d5000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910888.758784 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    732
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x00622000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910888.836784 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    732
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x00623000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910888.851784 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    732
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x00624000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910888.883784 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    732
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x003d6000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910888.883784 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    732
                
            
            
             
        
    
        
            region_size:
            
                
                    8192
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x00625000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910889.117784 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    732
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x00627000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910889.336784 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    732
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x003d7000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910889.336784 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    732
                
            
            
             
        
    
        
            region_size:
            
                
                    1507328
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
            
             
        
    
        
            base_address:
            
                
                    0x04da0000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910889.336784 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    732
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x04ed0000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910889.336784 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    732
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x04ed1000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910889.367784 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    732
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x04ed2000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910889.383784 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    732
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x04ed3000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910889.383784 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    732
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x04ed4000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910889.383784 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    732
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x04ed5000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910889.383784 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    732
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x04ed6000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910889.383784 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    732
                
            
            
             
        
    
        
            region_size:
            
                
                    8192
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x04ed7000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910889.383784 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    732
                
            
            
             
        
    
        
            region_size:
            
                
                    16384
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x04ed9000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910889.383784 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    732
                
            
            
             
        
    
        
            region_size:
            
                
                    69632
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x04edd000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910889.414784 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    732
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x00628000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910889.414784 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    732
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x04eee000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910889.414784 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    732
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x04eef000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910889.414784 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    732
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x00629000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910889.414784 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    732
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x04ef0000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910889.633784 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    732
                
            
            
             
        
    
        
            region_size:
            
                
                    8192
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x003d8000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910889.648784 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    732
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x0062a000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910889.726784 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    732
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x003c3000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910889.726784 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    732
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x003da000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910889.804784 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    732
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x003cb000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 |