| Time & API | Arguments | Status | Return | Repeated | 
                            
                        
                        
                            
| 1619948415.696148 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    786432
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x005a0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948415.696148 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00620000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948416.181148 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    1048576
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x006f0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948416.181148 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x007b0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948416.243148 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    368 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x73e71000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948416.321148 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    1310720
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x00ba0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948416.321148 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00ca0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948416.337148 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0051a000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948416.337148 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    368 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    8192
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x73e72000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948416.337148 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00512000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948416.524148 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00522000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948416.602148 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00555000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948416.602148 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0055b000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948416.602148 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00557000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948416.712148 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00523000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948416.743148 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0052c000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948416.806148 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00670000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948416.946148 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00524000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948417.321148 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00671000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948417.368148 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00525000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948417.368148 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00526000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948417.477148 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00536000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948417.509148 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00527000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948417.509148 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0053a000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948417.509148 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00537000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948417.524148 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00672000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948417.556148 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00528000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948417.571148 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    12288
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00673000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948417.587148 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00529000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948417.634148 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00676000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948458.821148 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00677000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948458.868148 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0051c000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948458.884148 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00678000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948458.946148 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x04950000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948458.946148 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00679000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948458.993148 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0052d000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948458.993148 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    368 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    107520
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x04d50400
 
 | failed | 3221225550 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948460.821148 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0067a000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948460.837148 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x04951000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948460.837148 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0067b000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948460.837148 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0067c000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948460.837148 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0067d000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948460.977148 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0067e000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948461.087148 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0067f000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948461.102148 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00760000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948461.102148 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    8192
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00761000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948461.102148 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    368 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    8
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x04d50178
 
 | failed | 3221225550 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948461.118148 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    368 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    8
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x04d501a0
 
 | failed | 3221225550 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948461.118148 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    368 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    8
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x04d501c8
 
 | failed | 3221225550 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948461.118148 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    368 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    8
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x04d501f0
 
 | failed | 3221225550 | 0 |