| Time & API | Arguments | Status | Return | Repeated | 
                            
                        
                        
                            
| 1619910845.238234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1108 region_size:
            
                
                    720896
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x00350000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910845.238234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1108 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003c0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910845.910234 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    1108 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x73f31000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910846.129234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1108 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003ba000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910846.129234 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    1108 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    8192
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x73f32000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910846.129234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1108 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003b2000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910846.567234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1108 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00402000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910846.738234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1108 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00403000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910846.785234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1108 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x004bb000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910846.785234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1108 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x004b7000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910847.520234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1108 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0040c000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910847.801234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1108 region_size:
            
                
                    8192
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00404000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910847.848234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1108 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005e0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910847.895234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1108 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00406000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910848.082234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1108 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x004aa000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910848.098234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1108 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0049a000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910848.098234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1108 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00497000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910848.270234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1108 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003bb000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910848.301234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1108 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x004a2000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910848.301234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1108 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x004ac000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910848.379234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1108 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00407000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910848.426234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1108 region_size:
            
                
                    327680
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    1056768
                
            
            
                (MEM_RESERVE|MEM_TOP_DOWN)
 base_address:
            
                
                    0x7ef50000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910848.426234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1108 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x7ef50000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910848.426234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1108 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x7ef50000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910848.426234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1108 region_size:
            
                
                    65536
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    1056768
                
            
            
                (MEM_RESERVE|MEM_TOP_DOWN)
 base_address:
            
                
                    0x7ef40000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910848.426234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1108 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x7ef40000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910848.488234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1108 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00408000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910848.551234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1108 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005e1000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910848.567234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1108 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005e2000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910848.629234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1108 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x004b5000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910848.770234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1108 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00409000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910903.145234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1108 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00496000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910903.176234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1108 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005e3000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910903.223234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1108 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00c70000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910903.223234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1108 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005e4000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910903.285234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1108 region_size:
            
                
                    12288
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005e5000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910903.348234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1108 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003b3000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910903.457234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1108 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003c1000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910903.598234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1108 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005e8000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910903.598234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1108 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00c71000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910903.613234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1108 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00c72000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910903.613234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1108 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00c73000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910903.613234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1108 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0040d000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910903.613234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1108 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00c74000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910903.613234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1108 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00c75000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910903.645234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1108 region_size:
            
                
                    24576
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005e9000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910903.645234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1108 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x04b00000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910903.645234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1108 region_size:
            
                
                    20480
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x04b01000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910903.676234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1108 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x04b06000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910903.723234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1108 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0040a000
 
 | success | 0 | 0 |