| Time & API | Arguments | Status | Return | Repeated | 
                            
                        
                        
                            
| 1619910846.438879 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2264 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x004c0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910846.438879 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2264 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x004c0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910846.470879 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2264 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x004c0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910846.501879 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2264 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x004c0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910846.517879 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2264 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x004c0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910846.532879 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2264 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x004c0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910846.548879 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2264 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x004c0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910846.548879 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2264 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x004c0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910846.563879 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2264 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x004c0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910846.579879 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2264 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x004c0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910846.610879 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2264 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x004c0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910846.626879 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2264 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x004c0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910846.642879 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2264 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x004c0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910846.657879 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2264 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x004c0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910846.657879 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2264 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x004c0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910846.673879 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2264 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x004c0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910846.673879 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2264 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x00455000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910846.688879 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2264 region_size:
            
                
                    176128
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x00400000
 
 | failed | 3221225496 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910846.688879 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2264 region_size:
            
                
                    176128
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x004d0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910846.688879 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2264 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 length:
            
                
                    172032
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x004d1000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910864.360879 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2264 region_size:
            
                
                    12288
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
 base_address:
            
                
                    0x00510000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910864.360879 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2264 region_size:
            
                
                    12288
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x10000000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910864.360879 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2264 region_size:
            
                
                    8192
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x10001000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910864.360879 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2264 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
 base_address:
            
                
                    0x01d40000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910864.438879 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2264 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
 base_address:
            
                
                    0x01d50000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619910864.438879 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2264 region_size:
            
                
                    131072
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
 base_address:
            
                
                    0x01d60000
 
 | success | 0 | 0 |