| Time & API | Arguments | Status | Return | Repeated | 
                            
                        
                        
                            
| 1619934610.438751 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1476 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x01db0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619934610.532751 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1476 region_size:
            
                
                    36864
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
 base_address:
            
                
                    0x01e30000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619934610.563751 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1476 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
 base_address:
            
                
                    0x01f70000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619934611.438626 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2196 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x00400000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619934611.485626 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2196 region_size:
            
                
                    655360
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x01db0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619934611.485626 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2196 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x01e10000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619934611.485626 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2196 region_size:
            
                
                    327680
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
 base_address:
            
                
                    0x00530000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619934611.485626 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2196 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 length:
            
                
                    299008
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x00532000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619934611.813626 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2196 region_size:
            
                
                    1376256
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x02060000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619934611.813626 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2196 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x02170000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619934612.688626 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2196 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x00522000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619934612.688626 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2196 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x76351000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619934612.688626 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2196 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x00522000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619934612.688626 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2196 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x76353000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619934612.688626 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2196 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x00522000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619934612.688626 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2196 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x76354000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619934612.688626 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2196 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x00522000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619934612.688626 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2196 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x76351000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619934612.688626 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2196 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x00522000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619934612.688626 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2196 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x77d4f000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619934612.688626 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2196 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x00522000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619934612.688626 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2196 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x76353000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619934612.688626 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2196 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x00522000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619934612.688626 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2196 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x76351000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619934612.688626 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2196 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x00522000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619934612.688626 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2196 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x76351000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619934612.688626 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2196 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x00522000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619934612.688626 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2196 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x76354000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619934612.704626 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2196 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x00522000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619934612.704626 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2196 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x76351000
 
 | success | 0 | 0 |