| Time & API | Arguments | Status | Return | Repeated | 
                            
                        
                        
                            
| 1619910850.561053 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3000 region_size:
            
                
                    2097152
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x00880000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910850.561053 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3000 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00a40000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910851.358053 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    3000 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x73f31000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910851.577053 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3000 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0048a000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910851.577053 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    3000 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    8192
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x73f32000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910851.577053 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3000 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00482000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910851.843053 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3000 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x004a2000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910851.968053 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3000 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x004a3000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910851.983053 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3000 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x004db000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910851.983053 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3000 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x004d7000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910852.015053 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3000 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x004ac000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910852.093053 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3000 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x01f80000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910852.124053 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3000 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x01f81000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910852.140053 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3000 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x01f82000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910852.140053 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3000 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x01f83000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910852.171053 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3000 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x01f84000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910852.186053 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3000 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x004a4000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910852.593053 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3000 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x004a5000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910852.608053 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3000 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x004a6000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910852.671053 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3000 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x004a7000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910852.780053 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3000 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x004ba000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910852.780053 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3000 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x004b7000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910852.796053 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3000 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x004ca000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910852.811053 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3000 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0048b000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910852.827053 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3000 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x004a8000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910852.843053 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3000 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x004a9000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910852.843053 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3000 region_size:
            
                
                    8192
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x01f85000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910852.843053 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3000 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x01e90000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910852.874053 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3000 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x004b6000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910852.874053 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3000 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x01f87000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910853.265053 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3000 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x01f88000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910853.280053 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3000 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x01f00000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910853.296053 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3000 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x01e91000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910853.296053 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3000 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x004ad000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910853.296053 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3000 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x01f89000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910853.311053 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3000 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x01e92000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910853.327053 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3000 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x01f8a000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910853.343053 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3000 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x01f8b000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910853.343053 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3000 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x004aa000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910853.358053 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3000 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x01f8c000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910853.358053 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3000 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x01f8d000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910853.421053 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3000 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00a41000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910853.561053 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3000 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x01f8e000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910853.593053 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3000 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x004c2000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910853.655053 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3000 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x004d5000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910853.843053 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3000 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x01f8f000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910853.983053 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3000 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x01e93000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910854.108053 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3000 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x046d0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910854.108053 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3000 region_size:
            
                
                    655360
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x04d70000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910854.108053 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3000 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x04dd0000
 
 | success | 0 | 0 |