| Time & API | Arguments | Status | Return | Repeated | 
                            
                        
                        
                            
| 1619948410.849429 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    428 region_size:
            
                
                    500002816
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
 base_address:
            
                
                    0x033b0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948411.380429 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    428 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
 base_address:
            
                
                    0x00df0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948411.583429 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    428 region_size:
            
                
                    589824
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    12288
                
            
            
                (MEM_COMMIT|MEM_RESERVE)
 base_address:
            
                
                    0x21490000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619953501.396125 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2476 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x75011000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619953501.442125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2476 region_size:
            
                
                    1572864
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x00750000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619953501.442125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2476 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00890000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619953501.661125 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2476 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x73f31000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619953501.661125 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2476 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x745e4000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619953501.833125 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2476 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x73f31000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619953501.927125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2476 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0076a000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619953501.927125 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2476 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    8192
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x73f32000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619953501.927125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2476 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00762000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619953502.130125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2476 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00772000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619953502.239125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2476 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00773000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619953502.255125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2476 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x007ab000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619953502.255125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2476 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x007a7000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619953502.302125 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2476 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x75221000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619953502.349125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2476 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0077c000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619953502.411125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2476 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00990000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619953502.489125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2476 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00774000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619953502.489125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2476 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00991000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619953502.505125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2476 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00992000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619953502.583125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2476 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00993000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619953502.958125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2476 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0079a000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619953502.974125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2476 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00792000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619953504.146875 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    732 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x03110000
 
 | success | 0 | 0 |