| Time & API | Arguments | Status | Return | Repeated | 
                            
                        
                        
                            
| 1619949858.216125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    1376256
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x005e0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619949858.216125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x006f0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619949858.576125 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2856 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x73f31000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619949858.654125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0057a000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619949858.654125 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2856 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    8192
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x73f32000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619949858.654125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00572000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619949858.872125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00582000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619949858.935125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00583000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619949858.951125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005bb000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619949858.966125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005b7000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619949858.997125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0058c000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619949859.388125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00584000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619949859.388125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00585000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619949859.435125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00586000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619949859.451125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00c00000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619949859.544125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0059a000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619949859.544125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00597000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619949859.560125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005aa000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619949859.591125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0057b000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619949859.622125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00596000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619949859.701125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    8192
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00c01000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619949860.091125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0058a000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619949860.201125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x043c0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619949860.279125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00587000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619949860.326125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00c03000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619949860.341125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005a2000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619949860.388125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005b5000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619949860.497125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x006f1000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619949860.591125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00588000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619949860.701125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    327680
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x054a0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619949860.701125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x054b0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619949860.701125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x054b1000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619949860.732125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x054b2000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619949860.747125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x054b3000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619949860.747125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x054b4000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619949860.747125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    12288
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x054b5000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619949860.747125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    8192
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x054b8000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619949860.747125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    16384
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x054ba000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619949860.747125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    69632
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x054be000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619949860.763125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00589000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619949860.794125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00c04000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619949860.794125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x054cf000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619949860.794125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x054d0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619949860.810125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x054d1000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619949860.810125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00c05000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619949861.091125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x043c1000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619949861.169125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00c06000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619949865.404125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x043c2000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619949865.404125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00573000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619949865.55975 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2632 region_size:
            
                
                    1376256
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x00610000
 
 | success | 0 | 0 |