| Time & API | Arguments | Status | Return | Repeated | 
                            
                        
                        
                            
| 1619948412.526343 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    2162688
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x00a90000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948412.526343 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00c60000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948413.370343 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2856 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x73f31000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948413.636343 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x008da000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948413.636343 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2856 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    8192
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x73f32000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948413.636343 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x008d2000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948414.026343 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x008e2000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948414.276343 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x008e3000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948414.276343 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0091b000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948414.276343 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00917000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948414.292343 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x008ec000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948414.933343 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x008e4000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948414.933343 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x008e5000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948414.964343 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x008e6000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948414.980343 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00a40000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948415.042343 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x008e7000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948415.073343 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x008fa000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948415.073343 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x008f7000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948415.089343 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0090a000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948415.120343 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x008db000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948415.151343 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x008f6000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948415.198343 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00a41000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948415.480343 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x008ea000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948415.511343 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00a42000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948415.511343 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00902000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948415.589343 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00915000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948415.745343 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x008e8000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948415.855343 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x045d0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948448.995343 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x04ce0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948448.995343 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00c61000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948449.230343 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0090c000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948449.308343 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x008e9000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948449.495343 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00a43000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948449.589343 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2856 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    243712
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x04d10400
 
 | failed | 3221225550 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948454.448343 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00a44000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948454.464343 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x04e60000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948454.464343 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00a45000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948454.480343 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00a46000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948454.558343 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00a47000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948454.636343 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00a48000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948454.870343 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00a49000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948455.120343 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    8192
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00a4a000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948455.136343 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2856 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    8
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x04d10178
 
 | failed | 3221225550 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948455.136343 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2856 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    8
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x04d101a0
 
 | failed | 3221225550 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948455.136343 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2856 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    8
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x04d101c8
 
 | failed | 3221225550 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948455.136343 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2856 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    8
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x04d101f0
 
 | failed | 3221225550 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948455.136343 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2856 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    8
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x04d10218
 
 | failed | 3221225550 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948455.136343 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2856 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    11
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x04d4c5ce
 
 | failed | 3221225550 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948455.136343 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2856 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    11
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x04d4c5c2
 
 | failed | 3221225550 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948455.136343 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2856 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    72
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x04d4bc00
 
 | failed | 3221225550 | 0 |