| Time & API | Arguments | Status | Return | Repeated | 
                            
                        
                        
                            
| 1619910853.608212 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1316 region_size:
            
                
                    1179648
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x008f0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910853.608212 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1316 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x009d0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910854.062212 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1316 region_size:
            
                
                    589824
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x003d0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910854.062212 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1316 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00420000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910854.249212 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    1316 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x73e71000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910854.452212 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1316 region_size:
            
                
                    1835008
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x00d30000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910854.452212 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1316 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00eb0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910854.452212 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1316 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x002aa000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910854.468212 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    1316 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    8192
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x73e72000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910854.468212 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1316 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x002a2000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910854.655212 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1316 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x002b2000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910854.749212 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1316 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003e5000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910854.749212 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1316 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003eb000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910854.749212 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1316 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003e7000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910854.843212 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1316 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x002b3000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910854.874212 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1316 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x002bc000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910854.952212 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1316 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00720000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910854.952212 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1316 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x002b4000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910854.968212 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1316 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00721000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910854.983212 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1316 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00722000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910854.983212 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1316 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00723000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910855.030212 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1316 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00724000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910855.046212 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1316 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00725000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910855.202212 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1316 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x002b5000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910855.327212 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1316 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00726000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910855.577212 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1316 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x002b6000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910855.577212 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1316 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x002b7000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910855.812212 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1316 region_size:
            
                
                    8192
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x002b8000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910855.921212 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1316 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x007c0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910856.030212 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1316 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003da000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910856.030212 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1316 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003d7000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910856.077212 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1316 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00727000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910856.108212 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1316 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x007c1000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910856.155212 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1316 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x007c2000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910856.187212 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1316 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003d6000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910856.327212 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1316 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x007c3000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910856.327212 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1316 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00728000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910856.343212 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1316 region_size:
            
                
                    327680
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    1056768
                
            
            
                (MEM_RESERVE|MEM_TOP_DOWN)
 base_address:
            
                
                    0x7ef40000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910856.343212 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1316 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x7ef40000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910856.343212 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1316 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x7ef40000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910856.343212 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1316 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x7ef48000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910856.343212 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1316 region_size:
            
                
                    65536
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    1056768
                
            
            
                (MEM_RESERVE|MEM_TOP_DOWN)
 base_address:
            
                
                    0x7ef30000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910856.343212 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1316 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x7ef30000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910856.374212 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1316 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00729000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910856.374212 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1316 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x002bd000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910856.374212 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1316 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x007c4000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910856.530212 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1316 region_size:
            
                
                    8192
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0072a000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910856.530212 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1316 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0072c000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910856.624212 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1316 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x007c5000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910906.374212 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1316 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0072d000
 
 | success | 0 | 0 |