| Time & API | Arguments | Status | Return | Repeated | 
                            
                        
                        
                            
| 1619958748.550125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2536 region_size:
            
                
                    1769472
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x007f0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619958748.550125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2536 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00960000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619958749.034125 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2536 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x73f31000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619958749.159125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2536 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x004da000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619958749.159125 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2536 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    8192
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x73f32000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619958749.159125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2536 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x004d2000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619958749.363125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2536 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x004e2000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619958749.425125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2536 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x004e3000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619958749.441125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2536 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0061b000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619958749.441125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2536 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00617000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619958749.472125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2536 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x004ec000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619958749.941125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2536 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x004e4000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619958749.956125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2536 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x004e5000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619958750.019125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2536 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x004e6000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619958750.019125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2536 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x020d0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619958750.128125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2536 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005fa000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619958750.128125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2536 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005f7000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619958750.128125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2536 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0060a000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619958750.175125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2536 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x004db000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619958750.253125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2536 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005f6000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619958750.378125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2536 region_size:
            
                
                    8192
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x020d1000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619958750.722125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2536 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x04610000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619958750.847125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2536 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00602000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619958750.909125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2536 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00615000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619958751.019125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2536 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x004e7000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619958751.066125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2536 region_size:
            
                
                    1900544
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x055c0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619958751.066125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2536 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x05750000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619958751.066125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2536 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x05751000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619958751.081125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2536 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x05752000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619958751.081125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2536 region_size:
            
                
                    8192
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x05753000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619958751.128125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2536 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x020d3000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619958751.144125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2536 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x05755000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619958751.175125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2536 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x05756000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619958751.175125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2536 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x020d4000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619958751.191125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2536 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x004ea000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619958751.253125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2536 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x004e8000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619958751.347125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2536 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00961000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619958751.488125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2536 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x004e9000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619958751.597125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2536 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x020d5000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619958751.613125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2536 region_size:
            
                
                    16384
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x05757000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619958751.613125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2536 region_size:
            
                
                    69632
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0575b000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619958751.613125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2536 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0576c000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619958751.613125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2536 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0576d000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619958751.628125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2536 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0576e000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619958751.628125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2536 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0576f000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619958751.628125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2536 region_size:
            
                
                    12288
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x05770000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619958751.628125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2536 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x020d6000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619958751.644125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2536 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x05773000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619958751.644125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2536 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x020d7000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619958751.706125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2536 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x049c0000
 
 | success | 0 | 0 |