| Time & API | Arguments | Status | Return | Repeated | 
                            
                        
                        
                            
| 1619910854.411748 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    376 region_size:
            
                
                    2228224
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x007e0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910854.411748 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    376 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x009c0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910854.880748 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    376 region_size:
            
                
                    1179648
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x00a00000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910854.880748 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    376 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00ae0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910855.114748 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    376 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x73e71000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910855.364748 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    376 region_size:
            
                
                    786432
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x00a00000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910855.364748 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    376 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00a80000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910855.364748 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    376 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0052a000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910855.380748 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    376 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    8192
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x73e72000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910855.380748 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    376 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00522000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910855.786748 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    376 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00532000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910855.942748 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    376 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00565000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910855.942748 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    376 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0056b000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910855.942748 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    376 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00567000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910856.036748 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    376 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00533000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910856.067748 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    376 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0053c000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910856.489748 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    376 region_size:
            
                
                    8192
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00534000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910856.505748 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    376 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00536000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910856.630748 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    376 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00a40000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910856.739748 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    376 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0055a000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910856.739748 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    376 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00557000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910856.864748 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    376 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00556000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910856.942748 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    376 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00a41000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910857.255748 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    376 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00537000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910857.270748 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    376 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0053a000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910857.489748 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    376 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00538000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910857.567748 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    376 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00539000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910857.645748 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    376 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00c40000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910857.661748 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    376 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00a42000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910857.692748 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    376 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00c41000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910857.708748 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    376 region_size:
            
                
                    12288
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00a43000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910895.755748 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    376 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00ae1000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910895.942748 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    376 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0052c000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910895.942748 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    376 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00a46000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910896.005748 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    376 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00c42000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910896.020748 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    376 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00a47000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910896.098748 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    376 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    314880
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x05280400
 
 | failed | 3221225550 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910901.223748 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    376 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00a48000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910901.239748 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    376 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0053d000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910901.239748 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    376 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00c43000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910901.239748 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    376 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00a49000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910901.317748 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    376 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00a4a000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910901.489748 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    376 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00a4b000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910901.505748 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    376 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00a4c000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910901.645748 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    376 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00a4d000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910901.692748 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    376 region_size:
            
                
                    8192
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00a4e000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910901.708748 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    376 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    8
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x05280178
 
 | failed | 3221225550 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910901.708748 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    376 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    8
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x052801a0
 
 | failed | 3221225550 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910901.708748 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    376 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    8
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x052801c8
 
 | failed | 3221225550 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910901.708748 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    376 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    8
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x052801f0
 
 | failed | 3221225550 | 0 |