| Time & API | Arguments | Status | Return | Repeated | 
                            
                        
                        
                            
| 1619910850.690081 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2504 region_size:
            
                
                    2031616
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x00b20000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910850.690081 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2504 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00cd0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910851.049081 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2504 region_size:
            
                
                    393216
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x00450000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910851.049081 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2504 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00470000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910851.237081 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2504 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x73e71000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910851.456081 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2504 region_size:
            
                
                    655360
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x00600000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910851.456081 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2504 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00660000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910851.471081 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2504 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0032a000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910851.471081 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2504 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    8192
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x73e72000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910851.471081 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2504 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00322000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910851.690081 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2504 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00332000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910851.799081 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2504 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00465000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910851.815081 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2504 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0046b000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910851.815081 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2504 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00467000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910851.893081 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2504 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00333000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910851.940081 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2504 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0033c000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910852.002081 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2504 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x007f0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910852.002081 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2504 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00334000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910852.018081 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2504 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x007f1000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910852.018081 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2504 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x007f2000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910852.018081 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2504 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x007f3000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910852.049081 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2504 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x007f4000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910852.049081 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2504 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x007f5000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910852.221081 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2504 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00335000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910852.377081 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2504 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x007f6000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910852.784081 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2504 region_size:
            
                
                    8192
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00336000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910852.831081 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2504 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00338000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910852.862081 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2504 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x007f7000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910852.893081 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2504 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00323000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910852.893081 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2504 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0032c000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910852.893081 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2504 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x007f8000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910852.940081 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2504 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00339000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910852.956081 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2504 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00800000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910853.018081 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2504 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00801000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910853.049081 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2504 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00456000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910853.096081 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2504 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x007f9000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910853.096081 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2504 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0045a000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910853.096081 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2504 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00457000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910853.112081 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2504 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00802000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910853.143081 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2504 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0033d000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910853.159081 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2504 region_size:
            
                
                    12288
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x007fa000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910853.174081 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2504 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x007fd000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910853.174081 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2504 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00803000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910894.174081 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2504 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x007fe000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910894.377081 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2504 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x007ff000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910894.581081 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2504 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x04de0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910894.581081 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2504 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00804000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910894.581081 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2504 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x04de1000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910894.659081 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2504 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    313856
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x05130400
 
 | failed | 3221225550 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910899.862081 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2504 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x04de2000
 
 | success | 0 | 0 |