| Time & API | 
                                    Arguments | 
                                    Status | 
                                    Return | 
                                    Repeated | 
                                
                            
                        
                        
                            
    1619910846.01756 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    784
                
            
            
             
        
    
        
            region_size:
            
                
                    720896
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
            
             
        
    
        
            base_address:
            
                
                    0x004f0000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910846.01756 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    784
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x00560000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910846.45556 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    784
                
            
            
             
        
    
        
            region_size:
            
                
                    1114112
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
            
             
        
    
        
            base_address:
            
                
                    0x00750000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910846.45556 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    784
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x00820000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910846.62656 
    NtProtectVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    784
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            length:
            
                
                    4096
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            base_address:
            
                
                    0x73e71000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910846.87656 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    784
                
            
            
             
        
    
        
            region_size:
            
                
                    1048576
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
            
             
        
    
        
            base_address:
            
                
                    0x021d0000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910846.87656 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    784
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x02290000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910846.89256 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    784
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x003aa000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910846.89256 
    NtProtectVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    784
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            length:
            
                
                    8192
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            base_address:
            
                
                    0x73e72000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910846.89256 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    784
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x003a2000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910847.17356 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    784
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x003c2000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910847.25156 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    784
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x003e5000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910847.25156 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    784
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x003eb000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910847.26756 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    784
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x003e7000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910847.34556 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    784
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x003c3000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910847.37656 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    784
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x003cc000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910847.43956 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    784
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x00540000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910847.45556 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    784
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x003c4000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910847.62656 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    784
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x003c5000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910847.67356 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    784
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x003ac000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910847.86156 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    784
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x003d6000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910847.87656 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    784
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x00541000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910847.98656 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    784
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x003da000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910847.98656 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    784
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x003d7000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910848.04856 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    784
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x003c6000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910848.08056 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    784
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x003c7000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910848.12656 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    784
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x003c8000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910848.15856 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    784
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x00542000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619910848.48656 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    784
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x02291000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 |