| Time & API | Arguments | Status | Return | Repeated | 
                            
                        
                        
                            
| 1619931152.1375 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2760 region_size:
            
                
                    1376256
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x006e0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619931152.1375 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2760 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x007f0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619931152.2935 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2760 region_size:
            
                
                    1376256
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x02070000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619931152.2935 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2760 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x02180000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619931152.3715 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2760 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x73e71000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619931152.4655 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2760 region_size:
            
                
                    851968
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x006e0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619931152.4655 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2760 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00770000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619931152.4655 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2760 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0046a000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619931152.4655 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2760 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    8192
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x73e72000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619931152.4655 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2760 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00462000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619931152.6685 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2760 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00472000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619931152.7775 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2760 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x004a5000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619931152.7775 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2760 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x004ab000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619931152.7775 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2760 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x004a7000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619931152.9185 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2760 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00473000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619931152.9805 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2760 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0047c000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619931153.0435 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2760 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00680000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619931153.7465 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2760 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00474000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619931153.7625 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2760 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00475000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619931153.7775 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2760 region_size:
            
                
                    8192
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00476000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619931154.0275 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2760 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00478000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619931154.0275 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2760 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00479000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619931154.6215 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2760 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00496000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619931154.6215 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2760 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0049a000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619931154.6215 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2760 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00497000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619931154.6835 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2760 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00710000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619931154.9025 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2760 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00771000
 
 | success | 0 | 0 |