| Time & API | Arguments | Status | Return | Repeated | 
                            
                        
                        
                            
| 1619918247.734499 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    622592
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
 base_address:
            
                
                    0x02680000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619918247.828499 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    622592
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
 base_address:
            
                
                    0x02e20000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619918248.203499 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    335872
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
 base_address:
            
                
                    0x02720000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619918248.765249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2120 region_size:
            
                
                    1441792
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x00640000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619918248.765249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2120 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00760000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619918248.937249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2120 region_size:
            
                
                    917504
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x00b00000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619918248.937249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2120 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00ba0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619918249.015249 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2120 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x73e71000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619918249.109249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2120 region_size:
            
                
                    917504
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x00be0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619918249.109249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2120 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00c80000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619918249.109249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2120 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005ca000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619918249.109249 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2120 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    8192
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x73e72000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619918249.109249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2120 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005c2000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619918249.328249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2120 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005d2000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619918249.421249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2120 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005f5000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619918249.421249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2120 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005fb000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619918249.421249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2120 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005f7000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619918249.499249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2120 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005d3000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619918249.546249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2120 region_size:
            
                
                    12288
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005d4000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619918249.562249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2120 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005dc000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619918249.671249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2120 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00f50000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619918249.671249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2120 region_size:
            
                
                    57344
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00f51000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619918249.687249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2120 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005d7000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619918250.156249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2120 region_size:
            
                
                    8192
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005d8000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619918250.281249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2120 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005e6000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619918250.437249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2120 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00ba1000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619918250.546249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2120 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005ea000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619918250.546249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2120 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005e7000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619918250.656249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2120 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00740000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619918250.671249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2120 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00f5f000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619918250.765249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2120 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00741000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619918250.781249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2120 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00742000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619918250.828249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2120 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x007c0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619918250.937249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2120 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x007c1000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619918250.953249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2120 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00743000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619918251.578249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2120 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00744000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619918251.624249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2120 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x007c2000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619918251.874249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2120 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00745000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619918251.937249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2120 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00746000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619918251.937249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2120 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005dd000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619918251.937249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2120 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00fb0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619918251.937249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2120 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00fb1000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619918251.937249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2120 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005da000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619918251.937249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2120 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005db000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619918251.953249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2120 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00747000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619918251.968249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2120 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x007c3000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619918251.999249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2120 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x007c4000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619918252.156249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2120 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00748000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619918252.156249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2120 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00749000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619918252.156249 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2120 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0074a000
 
 | success | 0 | 0 |