| Time & API | 
                                    Arguments | 
                                    Status | 
                                    Return | 
                                    Repeated | 
                                
                            
                        
                        
                            
    1619948416.776662 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2340
                
            
            
             
        
    
        
            region_size:
            
                
                    589824
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
            
             
        
    
        
            base_address:
            
                
                    0x005b0000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619948416.776662 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2340
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x00600000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619948417.323662 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2340
                
            
            
             
        
    
        
            region_size:
            
                
                    655360
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
            
             
        
    
        
            base_address:
            
                
                    0x01e90000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619948417.323662 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2340
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x01ef0000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619948417.370662 
    NtProtectVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2340
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            length:
            
                
                    4096
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            base_address:
            
                
                    0x73e71000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619948417.464662 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2340
                
            
            
             
        
    
        
            region_size:
            
                
                    983040
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
            
             
        
    
        
            base_address:
            
                
                    0x01f90000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619948417.464662 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2340
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x02040000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619948417.464662 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2340
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x004fa000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619948417.464662 
    NtProtectVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2340
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            length:
            
                
                    8192
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            base_address:
            
                
                    0x73e72000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619948417.464662 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2340
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x004f2000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619948417.651662 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2340
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x00502000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619948417.729662 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2340
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x00525000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619948417.729662 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2340
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x0052b000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619948417.729662 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2340
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x00527000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619948417.823662 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2340
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x00503000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619948417.901662 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2340
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x00504000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619948417.932662 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2340
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x00505000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619948417.932662 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2340
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x0050c000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619948418.292662 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2340
                
            
            
             
        
    
        
            region_size:
            
                
                    8192
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x00506000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619948418.292662 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2340
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x00508000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619948418.370662 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2340
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x01e90000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619948418.589662 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2340
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x0051a000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619948418.589662 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2340
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x00517000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619948418.682662 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2340
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x00509000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619948418.698662 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2340
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x01f40000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619948418.792662 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2340
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x00516000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619948418.854662 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2340
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x01e91000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619948418.854662 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2340
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x01f41000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619948418.901662 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2340
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x01f42000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619948418.917662 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2340
                
            
            
             
        
    
        
            region_size:
            
                
                    327680
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    1056768
                
            
            
                (MEM_RESERVE|MEM_TOP_DOWN)
            
             
        
    
        
            base_address:
            
                
                    0x7ef40000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619948418.917662 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2340
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x7ef40000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619948418.917662 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2340
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x7ef40000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619948418.917662 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2340
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x7ef48000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619948418.917662 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2340
                
            
            
             
        
    
        
            region_size:
            
                
                    65536
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    1056768
                
            
            
                (MEM_RESERVE|MEM_TOP_DOWN)
            
             
        
    
        
            base_address:
            
                
                    0x7ef30000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619948418.917662 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2340
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x7ef30000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619948418.964662 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2340
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x01e92000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619948418.964662 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2340
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x01f43000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619948419.104662 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2340
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x0050d000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619948419.120662 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2340
                
            
            
             
        
    
        
            region_size:
            
                
                    12288
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x01e93000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619948419.229662 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2340
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x01f44000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619948419.245662 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2340
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x01f45000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619948419.260662 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2340
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x01e96000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619948419.307662 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2340
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x01e97000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619948419.307662 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2340
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x01f46000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619948419.307662 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2340
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x004fc000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619948419.307662 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2340
                
            
            
             
        
    
        
            region_size:
            
                
                    12288
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x01e98000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619948419.323662 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2340
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x01e9b000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619948419.339662 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2340
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x01e9c000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619948419.354662 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2340
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x01f47000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 | 
                        
                    
                
                    
                        
                        
                            
    1619948419.370662 
    NtAllocateVirtualMemory
    
         
        
            
        
    
 | 
    
        
            process_identifier:
            
                
                    2340
                
            
            
             
        
    
        
            region_size:
            
                
                    4096
                
            
            
             
        
    
        
            stack_dep_bypass:
            
                
                    0
                
            
            
             
        
    
        
            stack_pivoted:
            
                
                    0
                
            
            
             
        
    
        
            heap_dep_bypass:
            
                
                    1
                
            
            
             
        
    
        
            protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
            
             
        
    
        
            process_handle:
            
                
                    0xffffffff
                
            
            
             
        
    
        
            allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
            
             
        
    
        
            base_address:
            
                
                    0x01e9d000
                
            
            
             
        
    
 | 
    
        success
    
 | 
0 | 
    
        0
    
 |