| Time & API | Arguments | Status | Return | Repeated | 
                            
                        
                        
                            
| 1619948417.657567 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1464 region_size:
            
                
                    1310720
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x007c0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948417.657567 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1464 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x008c0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948418.173567 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1464 region_size:
            
                
                    983040
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x02020000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948418.173567 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1464 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x020d0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948418.329567 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    1464 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x73e71000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948418.564567 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1464 region_size:
            
                
                    1572864
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x02110000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948418.564567 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1464 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x02250000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948418.579567 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1464 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005fa000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948418.595567 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    1464 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    8192
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x73e72000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948418.595567 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1464 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005f2000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948418.985567 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1464 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00602000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948419.095567 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1464 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00665000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948419.095567 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1464 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0066b000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948419.095567 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1464 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00667000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948419.173567 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1464 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00603000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948419.189567 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1464 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0060c000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948419.251567 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1464 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00800000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948419.626567 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1464 region_size:
            
                
                    8192
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00604000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948419.626567 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1464 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00606000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948419.720567 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1464 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00607000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948419.720567 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1464 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00608000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948419.735567 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1464 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00801000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948419.782567 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1464 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0065a000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948419.782567 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1464 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00657000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948419.892567 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1464 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00656000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948419.939567 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1464 region_size:
            
                
                    20480
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00802000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948420.157567 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1464 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0060a000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948420.235567 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1464 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00609000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948420.282567 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1464 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x02030000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948420.314567 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1464 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00807000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948420.329567 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1464 region_size:
            
                
                    8192
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00808000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948420.517567 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1464 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0080a000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948420.595567 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1464 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x02031000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948420.657567 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1464 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x02032000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948420.689567 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1464 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0080b000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948420.735567 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1464 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x02033000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948420.751567 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1464 region_size:
            
                
                    12288
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0080c000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948420.767567 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1464 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0080f000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948420.767567 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1464 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0060d000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948461.782567 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1464 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x02034000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948461.782567 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1464 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x049d0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948461.798567 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1464 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x020d1000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948461.876567 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1464 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x049d1000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948461.892567 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1464 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x049d2000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948461.985567 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1464 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005fc000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948462.048567 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1464 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x049d3000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948462.064567 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1464 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x02035000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948462.079567 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1464 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x049d4000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948462.173567 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    1464 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    271872
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x04f70400
 
 | failed | 3221225550 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948466.767567 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1464 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x049d5000
 
 | success | 0 | 0 |