| Time & API | Arguments | Status | Return | Repeated | 
                            
                        
                        
                            
| 1619948414.826531 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2984 region_size:
            
                
                    720896
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x00440000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948414.826531 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2984 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x004b0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948415.170531 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2984 region_size:
            
                
                    1245184
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x00760000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948415.170531 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2984 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00850000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948415.264531 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2984 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x73e71000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948415.404531 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2984 region_size:
            
                
                    2162688
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x021e0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948415.404531 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2984 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x023b0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948415.420531 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2984 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0044a000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948415.420531 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2984 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    8192
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x73e72000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948415.420531 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2984 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00442000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948415.623531 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2984 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00452000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948415.732531 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2984 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00475000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948415.732531 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2984 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0047b000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948415.732531 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2984 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00477000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948415.811531 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2984 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00453000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948415.857531 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2984 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0045c000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948416.217531 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2984 region_size:
            
                
                    8192
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00454000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948416.217531 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2984 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00456000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948416.342531 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2984 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00650000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948416.436531 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2984 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00457000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948416.498531 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2984 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x023b1000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948416.514531 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2984 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x023b2000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948416.561531 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2984 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00458000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948416.561531 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2984 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00466000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948416.576531 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2984 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00651000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948416.576531 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2984 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x023b3000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948416.576531 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2984 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x023b4000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948416.623531 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2984 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x023b5000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948416.623531 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2984 region_size:
            
                
                    16384
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x023b6000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948416.623531 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2984 region_size:
            
                
                    69632
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x023ba000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948416.639531 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2984 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00652000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948416.639531 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2984 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0046a000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948416.639531 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2984 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00467000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948416.732531 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2984 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00459000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948416.732531 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2984 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00810000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948416.873531 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2984 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00811000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948416.920531 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2984 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00812000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948416.936531 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2984 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00653000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948416.951531 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2984 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0045d000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948416.951531 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2984 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00813000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948416.967531 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2984 region_size:
            
                
                    12288
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00654000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948454.982531 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2984 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00657000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948455.186531 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2984 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00658000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948455.279531 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2984 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0044c000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948455.326531 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2984 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00659000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948455.389531 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2984 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00814000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948455.404531 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2984 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x023cb000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948455.404531 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2984 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x023cc000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948455.404531 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2984 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x023cd000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948455.404531 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2984 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x023ce000
 
 | success | 0 | 0 |