| Time & API | Arguments | Status | Return | Repeated | 
                            
                        
                        
                            
| 1619910850.644081 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    1900544
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x00900000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910850.644081 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00a90000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910851.034081 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    655360
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x00670000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910851.034081 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x006d0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910851.175081 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    368 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x73e71000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910851.331081 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    262144
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x004f0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910851.331081 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x004f0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910851.347081 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0046a000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910851.347081 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    368 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    8192
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x73e72000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910851.347081 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00462000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910851.519081 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00472000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910851.597081 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00495000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910851.613081 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0049b000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910851.613081 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00497000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910851.706081 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00473000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910851.738081 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00474000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910851.738081 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00475000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910851.738081 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00476000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910851.738081 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00477000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910851.738081 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00478000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910851.738081 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0047c000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910851.738081 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0047d000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910851.816081 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00680000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910851.847081 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00681000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910851.863081 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    368 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x00445000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910851.863081 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    368 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x00445000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910851.863081 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    368 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x003a0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910851.863081 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    368 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x003a0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910851.863081 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    368 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x003a0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910851.863081 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    368 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x003a2000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910851.863081 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    368 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x00437000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910851.863081 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    368 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x00437000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910851.863081 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    368 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x00437000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910851.863081 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    368 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x00437000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910851.863081 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    368 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x00437000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910851.863081 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    368 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x00437000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910851.863081 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    368 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x00437000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910851.863081 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    368 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x00437000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910851.863081 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    368 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x00437000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910851.863081 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    368 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x00437000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910851.863081 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    368 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x00437000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910851.863081 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    368 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x00437000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910851.863081 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    368 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x00437000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910852.019081 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00479000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910852.144081 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00682000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910852.144081 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00690000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910852.159081 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0046c000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910852.363081 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00691000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910852.363081 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0047e000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910852.425081 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00486000
 
 | success | 0 | 0 |