| Time & API | Arguments | Status | Return | Repeated | 
                            
                        
                        
                            
| 1619948416.781886 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    912 region_size:
            
                
                    2031616
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x00860000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948416.781886 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    912 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00a10000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948417.125886 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    912 region_size:
            
                
                    1638400
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x01fa0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948417.125886 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    912 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x020f0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948417.187886 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    912 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x73e71000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948417.312886 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    912 region_size:
            
                
                    1966080
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x02130000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948417.312886 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    912 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x022d0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948417.328886 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    912 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005aa000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948417.328886 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    912 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    8192
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x73e72000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948417.328886 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    912 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005a2000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948417.515886 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    912 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005b2000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948417.609886 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    912 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005d5000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948417.609886 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    912 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005db000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948417.609886 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    912 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005d7000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948417.687886 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    912 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005b3000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948417.718886 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    912 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005bc000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948418.093886 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    912 region_size:
            
                
                    8192
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005b4000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948418.093886 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    912 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005b6000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948418.203886 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    912 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x01f20000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948418.297886 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    912 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005ca000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948418.297886 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    912 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005c7000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948418.593886 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    912 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005c6000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948418.593886 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    912 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005ba000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948418.656886 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    912 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x01f21000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948418.828886 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    912 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005b7000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948418.828886 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    912 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005b8000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948418.875886 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    912 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005b9000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948460.422886 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    912 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x01f22000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948460.437886 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    912 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x020f1000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948460.531886 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    912 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x01f23000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948460.672886 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    912 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005ac000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948460.734886 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    912 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x01f24000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948460.781886 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    912 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x04450000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948460.797886 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    912 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x01f25000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948460.890886 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    912 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x04451000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948460.906886 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    912 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    370688
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x05600400
 
 | failed | 3221225550 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948468.187886 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    912 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x01f26000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948468.187886 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    912 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x01f27000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948468.281886 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    912 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x01f28000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948468.297886 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    912 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x01f29000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948468.312886 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    912 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x01f2a000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948468.375886 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    912 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x04452000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948468.390886 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    912 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x01f2b000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948468.422886 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    912 region_size:
            
                
                    8192
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x01f2c000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948468.422886 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    912 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    8
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x05600178
 
 | failed | 3221225550 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948468.422886 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    912 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    8
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x056001a0
 
 | failed | 3221225550 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948468.422886 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    912 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    8
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x056001c8
 
 | failed | 3221225550 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948468.422886 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    912 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    8
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x056001f0
 
 | failed | 3221225550 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948468.422886 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    912 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    8
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x05600218
 
 | failed | 3221225550 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948468.422886 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    912 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    11
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x0565b49e
 
 | failed | 3221225550 | 0 |