| Time & API | Arguments | Status | Return | Repeated | 
                            
                        
                        
                            
| 1619948418.662793 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2196 region_size:
            
                
                    2293760
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x00a10000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948418.662793 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2196 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00c00000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948419.100793 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2196 region_size:
            
                
                    917504
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x004e0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948419.100793 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2196 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00580000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948419.272793 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2196 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x73e71000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948419.662793 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2196 region_size:
            
                
                    655360
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x00a10000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948419.662793 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2196 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00a70000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948419.678793 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2196 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0051a000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948419.678793 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2196 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    8192
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x73e72000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948419.678793 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2196 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00512000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948420.147793 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2196 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00522000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948420.334793 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2196 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00545000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948420.334793 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2196 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0054b000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948420.334793 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2196 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00547000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948420.443793 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2196 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00523000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948420.459793 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2196 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00524000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948420.459793 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2196 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0052c000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948420.506793 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2196 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x009e0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948420.678793 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2196 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00525000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948421.209793 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2196 region_size:
            
                
                    8192
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00526000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948421.334793 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2196 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0053a000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948421.334793 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2196 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00537000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948421.443793 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2196 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00536000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948421.475793 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2196 region_size:
            
                
                    8192
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x009e1000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948421.787793 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2196 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00528000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948421.787793 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2196 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00529000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948421.803793 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2196 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x009e3000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948421.897793 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2196 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00d30000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948421.959793 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2196 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00d31000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948421.990793 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2196 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x009e4000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948422.006793 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2196 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00d32000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948422.022793 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2196 region_size:
            
                
                    12288
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x009e5000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948422.053793 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2196 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x009e8000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948463.068793 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2196 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00581000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948463.147793 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2196 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x009e9000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948463.256793 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2196 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0051c000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948463.272793 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2196 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x009ea000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948463.318793 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2196 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00d33000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948463.318793 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2196 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0052d000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948463.318793 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2196 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00d34000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948463.334793 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2196 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x009eb000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948463.397793 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2196 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x009ec000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948463.397793 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2196 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    188416
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x055a0400
 
 | failed | 3221225550 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948466.412793 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2196 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x009ed000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948466.412793 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2196 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00d35000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948466.412793 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2196 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x009ee000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948466.412793 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2196 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x009ef000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948466.490793 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2196 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x04b80000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948466.600793 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2196 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x04b81000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948467.053793 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2196 region_size:
            
                
                    12288
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x04b82000
 
 | success | 0 | 0 |