| Time & API | Arguments | Status | Return | Repeated | 
                            
                        
                        
                            
| 1619948410.709793 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    2031616
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x0000000000840000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948410.709793 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    8192
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00000000009b0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948413.506793 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    368 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 base_address:
            
                
                    0x000007fef1aa1000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948414.272793 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    368 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 base_address:
            
                
                    0x000007fef1d1e000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948414.272793 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    368 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 base_address:
            
                
                    0x000007fef1d1e000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948414.569793 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    368 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 base_address:
            
                
                    0x000007fef1d1f000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948414.569793 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    368 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 base_address:
            
                
                    0x000007fef1d1f000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948414.584793 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    368 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 base_address:
            
                
                    0x000007fef1d1f000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948414.584793 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    368 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 base_address:
            
                
                    0x000007fef1d1f000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948414.584793 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    368 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 base_address:
            
                
                    0x000007fef1d1f000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948414.584793 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    368 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 base_address:
            
                
                    0x000007fef1d1f000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948414.584793 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    368 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 base_address:
            
                
                    0x000007fef1d1f000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948414.584793 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    368 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 base_address:
            
                
                    0x000007fef1d1f000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948414.584793 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    368 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 base_address:
            
                
                    0x000007fef1d20000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948414.584793 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    368 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 base_address:
            
                
                    0x000007fef1d20000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948414.600793 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    368 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 base_address:
            
                
                    0x000007fef1d20000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948414.600793 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    368 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 base_address:
            
                
                    0x000007fef1d20000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948414.616793 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    368 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 base_address:
            
                
                    0x000007fef1d20000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948414.616793 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    368 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 base_address:
            
                
                    0x000007fef1d21000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948414.616793 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    368 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 base_address:
            
                
                    0x000007fef1d21000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948414.616793 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    368 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 base_address:
            
                
                    0x000007fef1d21000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948414.616793 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    368 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 base_address:
            
                
                    0x000007fef1d21000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948414.616793 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    368 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 base_address:
            
                
                    0x000007fef1d1e000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948415.647793 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x000007ff00042000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948416.084793 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    589824
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 allocation_type:
            
                
                    1056768
                
            
            
                (MEM_RESERVE|MEM_TOP_DOWN)
 base_address:
            
                
                    0x000007fffff10000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948416.084793 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x000007fffff10000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948416.084793 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x000007fffff10000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948416.084793 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    65536
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 allocation_type:
            
                
                    1056768
                
            
            
                (MEM_RESERVE|MEM_TOP_DOWN)
 base_address:
            
                
                    0x000007fffff00000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948416.084793 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x000007fffff00000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948416.100793 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x000007ff000fa000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948416.147793 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x000007ff00032000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948416.694793 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x000007ff00043000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948416.741793 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x000007ff0010a000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948416.741793 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x000007ff00132000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948416.741793 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x000007ff0010d000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948416.834793 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x000007ff0004c000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948419.022793 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    8192
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x000007ff00044000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948421.038793 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x000007ff00046000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948421.819793 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x000007ff00180000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948422.303793 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x000007ff000fb000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948422.459793 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x000007ff000f2000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948422.663793 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x000007ff0005f000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948422.678793 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x000007ff00094000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948422.678793 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x000007ff00063000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948422.741793 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x000007ff00047000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948423.553793 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x000007ff00181000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948423.741793 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x000007ff0004a000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948424.334793 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x000007ff00033000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948427.225793 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x000007ff00048000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948427.756793 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    368 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffffffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x000007ff001c0000
 
 | success | 0 | 0 |