| Time & API | Arguments | Status | Return | Repeated | 
                            
                        
                        
                            
| 1619956464.13425 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3040 region_size:
            
                
                    2293760
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x009a0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619956464.13425 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3040 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00b90000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619956464.57225 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    3040 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x73f31000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619956464.65025 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3040 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0046a000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619956464.65025 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    3040 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    8192
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x73f32000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619956464.65025 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3040 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00462000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619956464.86925 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3040 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00472000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619956464.97825 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3040 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00473000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619956464.97825 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3040 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x004ab000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619956464.97825 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3040 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x004a7000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619956464.99425 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3040 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0047c000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619956465.04125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3040 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00a10000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619956465.36925 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3040 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00474000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619956465.36925 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3040 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00475000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619956465.44725 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3040 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00476000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619956465.65025 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3040 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0048a000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619956465.65025 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3040 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00487000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619956465.66625 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3040 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0049a000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619956465.69725 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3040 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0046b000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619956465.82225 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3040 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00a11000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619956466.00925 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3040 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00477000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619956466.04125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3040 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00a12000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619956466.05625 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3040 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00486000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619956466.24425 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3040 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00b91000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619956466.38425 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3040 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00478000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619956466.40025 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3040 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00a13000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619956466.40025 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3040 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00479000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619956466.41625 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3040 region_size:
            
                
                    1048576
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x04970000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619956466.41625 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3040 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x04a30000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619956466.41625 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3040 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x04a31000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619956466.44725 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3040 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x04a32000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619956466.47825 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3040 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x04a33000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619956466.47825 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3040 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x04a34000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619956466.47825 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3040 region_size:
            
                
                    12288
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x04a35000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619956466.47825 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3040 region_size:
            
                
                    8192
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x04a38000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619956466.52525 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3040 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00a14000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619956466.52525 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3040 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x04a3a000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619956466.54125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3040 region_size:
            
                
                    16384
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x04a3b000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619956466.54125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3040 region_size:
            
                
                    69632
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x04a3f000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619956466.54125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3040 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x04a50000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619956466.57225 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3040 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00a15000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619956466.58725 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3040 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00492000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619956466.63425 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3040 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x004a5000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619956466.74425 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3040 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0047a000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619956467.21225 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3040 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x04ac0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619956467.399375 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2228 region_size:
            
                
                    1245184
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x008d0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619956467.399375 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2228 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x009c0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619956467.524375 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2228 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x73f31000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619956467.586375 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2228 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003ba000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619956467.586375 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2228 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    8192
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x73f32000
 
 | success | 0 | 0 |