| Time & API | 
                                    Arguments | 
                                    Status | 
                                    Return | 
                                    Repeated | 
                                
                            
                        
                        
                            
    1619910854.522633 
    NtProtectVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    3004
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            length:
            
                
                    90112
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            base_address:
            
                
                    0x00401000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910854.803633 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    3004
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
            
             
        
    
        
            base_address:
            
                
                    0x77ec0000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910854.819633 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    3004
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
            
             
        
    
        
            base_address:
            
                
                    0x77930000
                
            
            
             
        
    
 | 
    
        failed
    
 | 
3221225496 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910854.819633 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    3004
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
            
             
        
    
        
            base_address:
            
                
                    0x77940000
                
            
            
             
        
    
 | 
    
        failed
    
 | 
3221225496 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910854.819633 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    3004
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
            
             
        
    
        
            base_address:
            
                
                    0x77950000
                
            
            
             
        
    
 | 
    
        failed
    
 | 
3221225496 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910854.819633 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    3004
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
            
             
        
    
        
            base_address:
            
                
                    0x77960000
                
            
            
             
        
    
 | 
    
        failed
    
 | 
3221225496 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910854.819633 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    3004
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
            
             
        
    
        
            base_address:
            
                
                    0x77970000
                
            
            
             
        
    
 | 
    
        failed
    
 | 
3221225496 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910854.819633 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    3004
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
            
             
        
    
        
            base_address:
            
                
                    0x77980000
                
            
            
             
        
    
 | 
    
        failed
    
 | 
3221225496 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910854.819633 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    3004
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
            
             
        
    
        
            base_address:
            
                
                    0x77990000
                
            
            
             
        
    
 | 
    
        failed
    
 | 
3221225496 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910854.819633 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    3004
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
            
             
        
    
        
            base_address:
            
                
                    0x779a0000
                
            
            
             
        
    
 | 
    
        failed
    
 | 
3221225496 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910854.819633 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    3004
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
            
             
        
    
        
            base_address:
            
                
                    0x779b0000
                
            
            
             
        
    
 | 
    
        failed
    
 | 
3221225496 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910854.819633 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    3004
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
            
             
        
    
        
            base_address:
            
                
                    0x779c0000
                
            
            
             
        
    
 | 
    
        failed
    
 | 
3221225496 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910854.819633 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    3004
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
            
             
        
    
        
            base_address:
            
                
                    0x779d0000
                
            
            
             
        
    
 | 
    
        failed
    
 | 
3221225496 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910854.819633 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    3004
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
            
             
        
    
        
            base_address:
            
                
                    0x779e0000
                
            
            
             
        
    
 | 
    
        failed
    
 | 
3221225496 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910854.819633 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    3004
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
            
             
        
    
        
            base_address:
            
                
                    0x779f0000
                
            
            
             
        
    
 | 
    
        failed
    
 | 
3221225496 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910854.819633 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    3004
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
            
             
        
    
        
            base_address:
            
                
                    0x77a00000
                
            
            
             
        
    
 | 
    
        failed
    
 | 
3221225496 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910854.819633 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    3004
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
            
             
        
    
        
            base_address:
            
                
                    0x77a10000
                
            
            
             
        
    
 | 
    
        failed
    
 | 
3221225496 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910854.819633 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    3004
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
            
             
        
    
        
            base_address:
            
                
                    0x77a20000
                
            
            
             
        
    
 | 
    
        failed
    
 | 
3221225496 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910854.819633 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    3004
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
            
             
        
    
        
            base_address:
            
                
                    0x77a30000
                
            
            
             
        
    
 | 
    
        failed
    
 | 
3221225496 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910854.819633 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    3004
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
            
             
        
    
        
            base_address:
            
                
                    0x77a40000
                
            
            
             
        
    
 | 
    
        failed
    
 | 
3221225496 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910854.819633 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    3004
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
            
             
        
    
        
            base_address:
            
                
                    0x77a50000
                
            
            
             
        
    
 | 
    
        failed
    
 | 
3221225496 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910854.819633 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    3004
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
            
             
        
    
        
            base_address:
            
                
                    0x77a60000
                
            
            
             
        
    
 | 
    
        failed
    
 | 
3221225496 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910854.819633 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    3004
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
            
             
        
    
        
            base_address:
            
                
                    0x77a70000
                
            
            
             
        
    
 | 
    
        failed
    
 | 
3221225496 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910854.819633 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    3004
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
            
             
        
    
        
            base_address:
            
                
                    0x77a80000
                
            
            
             
        
    
 | 
    
        failed
    
 | 
3221225496 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910854.819633 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    3004
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
            
             
        
    
        
            base_address:
            
                
                    0x77a90000
                
            
            
             
        
    
 | 
    
        failed
    
 | 
3221225496 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910854.819633 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    3004
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
            
             
        
    
        
            base_address:
            
                
                    0x77aa0000
                
            
            
             
        
    
 | 
    
        failed
    
 | 
3221225496 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910854.819633 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    3004
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
            
             
        
    
        
            base_address:
            
                
                    0x77ab0000
                
            
            
             
        
    
 | 
    
        failed
    
 | 
3221225496 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910854.819633 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    3004
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
            
             
        
    
        
            base_address:
            
                
                    0x77ac0000
                
            
            
             
        
    
 | 
    
        failed
    
 | 
3221225496 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910854.819633 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    3004
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
            
             
        
    
        
            base_address:
            
                
                    0x77ad0000
                
            
            
             
        
    
 | 
    
        failed
    
 | 
3221225496 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910854.819633 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    3004
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
            
             
        
    
        
            base_address:
            
                
                    0x77ae0000
                
            
            
             
        
    
 | 
    
        failed
    
 | 
3221225496 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910854.819633 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    3004
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
            
             
        
    
        
            base_address:
            
                
                    0x77af0000
                
            
            
             
        
    
 | 
    
        failed
    
 | 
3221225496 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910854.819633 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    3004
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
            
             
        
    
        
            base_address:
            
                
                    0x77b00000
                
            
            
             
        
    
 | 
    
        failed
    
 | 
3221225496 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910854.819633 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    3004
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
            
             
        
    
        
            base_address:
            
                
                    0x77b10000
                
            
            
             
        
    
 | 
    
        failed
    
 | 
3221225496 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910854.819633 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    3004
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
            
             
        
    
        
            base_address:
            
                
                    0x77b20000
                
            
            
             
        
    
 | 
    
        failed
    
 | 
3221225496 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910854.819633 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    3004
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
            
             
        
    
        
            base_address:
            
                
                    0x77b30000
                
            
            
             
        
    
 | 
    
        failed
    
 | 
3221225496 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910854.819633 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    3004
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
            
             
        
    
        
            base_address:
            
                
                    0x77b40000
                
            
            
             
        
    
 | 
    
        failed
    
 | 
3221225496 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910854.819633 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    3004
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
            
             
        
    
        
            base_address:
            
                
                    0x77b50000
                
            
            
             
        
    
 | 
    
        failed
    
 | 
3221225496 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910854.819633 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    3004
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
            
             
        
    
        
            base_address:
            
                
                    0x77b60000
                
            
            
             
        
    
 | 
    
        failed
    
 | 
3221225496 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910854.819633 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    3004
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
            
             
        
    
        
            base_address:
            
                
                    0x77b70000
                
            
            
             
        
    
 | 
    
        failed
    
 | 
3221225496 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910854.819633 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    3004
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
            
             
        
    
        
            base_address:
            
                
                    0x77b80000
                
            
            
             
        
    
 | 
    
        failed
    
 | 
3221225496 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910854.819633 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    3004
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
            
             
        
    
        
            base_address:
            
                
                    0x77b90000
                
            
            
             
        
    
 | 
    
        failed
    
 | 
3221225496 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910854.819633 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    3004
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
            
             
        
    
        
            base_address:
            
                
                    0x77ba0000
                
            
            
             
        
    
 | 
    
        failed
    
 | 
3221225496 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910854.819633 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    3004
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
            
             
        
    
        
            base_address:
            
                
                    0x77bb0000
                
            
            
             
        
    
 | 
    
        failed
    
 | 
3221225496 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910854.819633 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    3004
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
            
             
        
    
        
            base_address:
            
                
                    0x77bc0000
                
            
            
             
        
    
 | 
    
        failed
    
 | 
3221225496 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910854.819633 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    3004
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
            
             
        
    
        
            base_address:
            
                
                    0x77bd0000
                
            
            
             
        
    
 | 
    
        failed
    
 | 
3221225496 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910854.819633 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    3004
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
            
             
        
    
        
            base_address:
            
                
                    0x77be0000
                
            
            
             
        
    
 | 
    
        failed
    
 | 
3221225496 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910854.819633 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    3004
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
            
             
        
    
        
            base_address:
            
                
                    0x77bf0000
                
            
            
             
        
    
 | 
    
        failed
    
 | 
3221225496 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910854.819633 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    3004
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
            
             
        
    
        
            base_address:
            
                
                    0x77c00000
                
            
            
             
        
    
 | 
    
        failed
    
 | 
3221225496 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910854.819633 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    3004
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
            
             
        
    
        
            base_address:
            
                
                    0x77c10000
                
            
            
             
        
    
 | 
    
        failed
    
 | 
3221225496 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910854.819633 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    3004
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
            
             
        
    
        
            base_address:
            
                
                    0x77c20000
                
            
            
             
        
    
 | 
    
        failed
    
 | 
3221225496 | 
    
        0
    
 |