| Time & API | Arguments | Status | Return | Repeated | 
                            
                        
                        
                            
| 1619948416.516408 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    428 region_size:
            
                
                    327680
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x00400000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948416.516408 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    428 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00410000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948416.938408 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    428 region_size:
            
                
                    1376256
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x005e0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948416.938408 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    428 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x006f0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948417.282408 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    428 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x73e71000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948417.469408 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    428 region_size:
            
                
                    1638400
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x01fc0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948417.469408 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    428 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x02110000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948417.469408 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    428 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005aa000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948417.469408 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    428 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    8192
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x73e72000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948417.469408 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    428 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005a2000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948417.735408 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    428 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005b2000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948417.813408 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    428 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005e5000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948417.813408 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    428 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005eb000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948417.813408 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    428 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005e7000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948417.891408 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    428 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005b3000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948417.923408 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    428 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005bc000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948418.298408 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    428 region_size:
            
                
                    8192
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005b4000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948418.313408 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    428 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005b6000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948418.423408 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    428 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00980000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948418.516408 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    428 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005ca000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948418.516408 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    428 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005c7000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948418.657408 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    428 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00981000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948418.876408 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    428 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005c6000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948418.891408 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    428 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005ba000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948418.891408 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    428 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005b7000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948418.891408 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    428 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00982000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948419.063408 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    428 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005b8000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948419.126408 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    428 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005b9000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948419.126408 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    428 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x02030000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948419.141408 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    428 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00983000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948460.141408 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    428 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00984000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948460.173408 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    428 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x006f1000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948460.251408 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    428 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00985000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948460.376408 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    428 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005ac000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948460.454408 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    428 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00986000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948460.501408 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    428 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x02031000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948460.516408 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    428 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00987000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948460.610408 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    428 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00988000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948460.610408 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    428 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    286208
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x04f90400
 
 | failed | 3221225550 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948465.798408 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    428 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x02032000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948465.798408 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    428 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00989000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948465.813408 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    428 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0098a000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948465.813408 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    428 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0098b000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948465.891408 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    428 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0098c000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948465.923408 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    428 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0098d000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948466.360408 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    428 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x04d20000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948466.360408 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    428 region_size:
            
                
                    8192
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x04d21000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948466.376408 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    428 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    8
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x04f90178
 
 | failed | 3221225550 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948466.376408 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    428 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    8
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x04f901a0
 
 | failed | 3221225550 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948466.376408 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    428 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    8
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x04f901c8
 
 | failed | 3221225550 | 0 |