| Time & API | 
                                    Arguments | 
                                    Status | 
                                    Return | 
                                    Repeated | 
                                
                            
                        
                        
                            
    1619911871.533 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2292
                
            
            
             
        
    
        
            region_size:
            
                
                    589824
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
            
             
        
    
        
            base_address:
            
                
                    0x03b60000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619911873.58 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2292
                
            
            
             
        
    
        
            region_size:
            
                
                    589824
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
            
             
        
    
        
            base_address:
            
                
                    0x03c80000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619911874.9245 
    NtProtectVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2252
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            length:
            
                
                    4096
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            base_address:
            
                
                    0x750e1000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619911874.9715 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2252
                
            
            
             
        
    
        
            region_size:
            
                
                    2031616
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
            
             
        
    
        
            base_address:
            
                
                    0x00cc0000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619911874.9715 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2252
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x00e70000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619911875.5495 
    NtProtectVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2252
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            length:
            
                
                    4096
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            base_address:
            
                
                    0x73f31000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619911875.5495 
    NtProtectVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2252
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            length:
            
                
                    4096
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            base_address:
            
                
                    0x75044000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619911876.0805 
    NtProtectVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2252
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            length:
            
                
                    4096
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            base_address:
            
                
                    0x73f31000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619911876.2215 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2252
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x006ca000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619911876.2215 
    NtProtectVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2252
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            length:
            
                
                    8192
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            base_address:
            
                
                    0x73f32000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619911876.2215 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2252
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x006c2000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619911876.5335 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2252
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x006d2000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619911876.6745 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2252
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x006d3000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619911876.6905 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2252
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x0070b000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619911876.6905 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2252
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x00707000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619911876.7375 
    NtProtectVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2252
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            length:
            
                
                    4096
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            base_address:
            
                
                    0x750c1000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619911876.7685 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2252
                
            
            
             
        
    
        
            region_size:
            
                
                    8192
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x006d4000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619911876.7685 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2252
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x006dc000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619911876.9085 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2252
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x00eb0000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619911876.9085 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2252
                
            
            
             
        
    
        
            region_size:
            
                
                    53248
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x00eb1000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619911876.9245 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2252
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x006d6000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619911877.4875 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2252
                
            
            
             
        
    
        
            region_size:
            
                
                    8192
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x006d7000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619911877.6125 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2252
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x006d9000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619911877.7215 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2252
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x006e6000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619911877.7525 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2252
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x006fa000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619911877.8625 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2252
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x006f2000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619911877.9405 
    NtProtectVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2252
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            length:
            
                
                    4096
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            base_address:
            
                
                    0x750a1000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619911877.9555 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2252
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x006ea000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619911877.9555 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2252
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x006e7000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619911878.1125 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2252
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x00ebe000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619911878.1905 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2252
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x00e71000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619911878.3935 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2252
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x00ebf000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619911878.4245 
    NtProtectVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2252
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            length:
            
                
                    4096
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            base_address:
            
                
                    0x75091000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619911878.8625 
    NtProtectVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2252
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            length:
            
                
                    4096
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            base_address:
            
                
                    0x71021000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619911879.2835 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2252
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x00e60000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619911879.2835 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2252
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x00e61000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619911879.2835 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2252
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x006da000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619911879.2835 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2252
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x006db000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619911879.2995 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2252
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x006cb000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619911879.6905 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2252
                
            
            
             
        
    
        
            region_size:
            
                
                    327680
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    1056768
                
            
            
                (MEM_RESERVE|MEM_TOP_DOWN)
            
             
        
    
        
            base_address:
            
                
                    0x7ef30000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619911879.6905 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2252
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x7ef30000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619911879.6905 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2252
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x7ef30000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619911879.6905 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2252
                
            
            
             
        
    
        
            region_size:
            
                
                    65536
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    1056768
                
            
            
                (MEM_RESERVE|MEM_TOP_DOWN)
            
             
        
    
        
            base_address:
            
                
                    0x7ef20000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619911879.6905 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2252
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x7ef20000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619911879.8155 
    NtProtectVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2252
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            length:
            
                
                    4096
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            base_address:
            
                
                    0x6a311000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619911879.8465 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2252
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x04f10000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619911879.8625 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2252
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x04f11000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619911879.8625 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2252
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x04f12000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619911879.8625 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2252
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x04f13000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619911881.7995 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2252
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x05130000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 |