| Time & API | Arguments | Status | Return | Repeated | 
                            
                        
                        
                            
| 1619910853.778017 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2292 region_size:
            
                
                    983040
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x00460000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910853.778017 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2292 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00510000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910854.294017 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2292 region_size:
            
                
                    393216
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x00460000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910854.294017 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2292 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00480000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910854.372017 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2292 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x73e71000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910854.465017 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2292 region_size:
            
                
                    1638400
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x020f0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910854.465017 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2292 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x02240000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910854.465017 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2292 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0032a000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910854.465017 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2292 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    8192
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x73e72000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910854.465017 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2292 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00322000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910854.653017 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2292 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00342000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910854.731017 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2292 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00465000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910854.731017 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2292 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0046b000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910854.731017 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2292 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00467000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910854.825017 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2292 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00343000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910854.872017 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2292 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0034c000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910855.231017 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2292 region_size:
            
                
                    8192
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00344000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910855.247017 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2292 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00346000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910855.340017 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2292 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00730000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910855.387017 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2292 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0035a000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910855.387017 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2292 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00357000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910855.559017 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2292 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00347000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910855.559017 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2292 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00348000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910855.575017 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2292 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00349000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910855.637017 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2292 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00356000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910855.684017 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2292 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00731000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910856.075017 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2292 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00732000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910856.153017 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2292 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x022e0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910856.653017 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2292 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x022e1000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910856.778017 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2292 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x047f0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910856.778017 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2292 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0034a000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910856.872017 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2292 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x022e2000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910889.934017 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2292 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00481000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910890.122017 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2292 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0032c000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910890.122017 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2292 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00733000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910890.169017 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2292 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x022e3000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910890.231017 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2292 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x022e4000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910890.247017 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2292 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x022e5000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910890.278017 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2292 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x022e6000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910890.325017 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2292 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00734000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910890.340017 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2292 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0034d000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910890.340017 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2292 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x022e7000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910890.356017 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2292 region_size:
            
                
                    12288
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00735000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910890.372017 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2292 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00738000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910890.419017 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2292 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    337920
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x05170400
 
 | failed | 3221225550 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910897.622017 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2292 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00739000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910897.622017 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2292 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0073a000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910897.622017 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2292 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x022e8000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910897.653017 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2292 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0073b000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910897.669017 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2292 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0073c000
 
 | success | 0 | 0 |