| Time & API | Arguments | Status | Return | Repeated | 
                            
                        
                        
                            
| 1619948409.961626 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    648 region_size:
            
                
                    2162688
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x00680000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948409.961626 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    648 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00850000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948410.477626 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    648 region_size:
            
                
                    917504
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x00a20000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948410.477626 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    648 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00ac0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948410.696626 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    648 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x73e71000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948411.117626 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    648 region_size:
            
                
                    1900544
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x00b00000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948411.117626 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    648 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00c90000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948411.117626 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    648 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0056a000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948411.117626 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    648 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    8192
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x73e72000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948411.117626 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    648 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00562000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948411.321626 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    648 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00572000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948411.430626 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    648 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00595000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948411.430626 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    648 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0059b000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948411.430626 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    648 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00597000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948411.539626 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    648 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00573000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948411.571626 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    648 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0057c000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948411.649626 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    648 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00b10000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948411.664626 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    648 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00574000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948411.680626 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    648 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00b11000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948411.711626 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    648 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00b12000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948412.102626 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    648 region_size:
            
                
                    8192
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00575000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948412.133626 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    648 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00577000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948412.367626 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    648 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0058a000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948412.367626 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    648 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00587000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948412.555626 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    648 region_size:
            
                
                    16384
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00b13000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948412.571626 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    648 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00b17000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948412.586626 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    648 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00578000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948412.836626 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    648 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00579000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948412.899626 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    648 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00ab0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948412.899626 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    648 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00b18000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948454.617626 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    648 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00b19000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948454.727626 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    648 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0056c000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948454.758626 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    648 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00b1a000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948454.821626 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    648 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00586000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948454.867626 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    648 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00ab1000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948454.899626 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    648 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00b1b000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948454.992626 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    648 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00ab2000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948454.992626 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    648 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00b1c000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948454.992626 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    648 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    320512
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x052b0400
 
 | failed | 3221225550 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948460.742626 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    648 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00b1d000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948460.774626 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    648 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00b1e000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948460.789626 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    648 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00b1f000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948460.946626 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    648 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x04b20000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948460.946626 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    648 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x04b21000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948461.024626 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    648 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00ab3000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948461.039626 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    648 region_size:
            
                
                    12288
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x04b22000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948461.039626 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    648 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    8
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x052b0178
 
 | failed | 3221225550 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948461.055626 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    648 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    8
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x052b01a0
 
 | failed | 3221225550 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948461.055626 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    648 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    8
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x052b01c8
 
 | failed | 3221225550 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948461.055626 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    648 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    8
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x052b01f0
 
 | failed | 3221225550 | 0 |