| Time & API | Arguments | Status | Return | Repeated | 
                            
                        
                        
                            
| 1619968574.38175 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1476 region_size:
            
                
                    2228224
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x006f0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619968574.38175 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1476 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x008d0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619968574.58475 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1476 region_size:
            
                
                    1835008
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x00aa0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619968574.58475 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1476 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00c20000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619968574.63175 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    1476 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x73e71000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619968574.69375 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1476 region_size:
            
                
                    1572864
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x00aa0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619968574.69375 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1476 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00be0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619968574.70975 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1476 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0052a000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619968574.70975 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    1476 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    8192
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x73e72000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619968574.70975 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1476 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00522000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619968574.89675 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1476 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00542000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619968574.97575 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1476 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00565000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619968574.97575 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1476 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0056b000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619968574.97575 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1476 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00567000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619968575.08475 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1476 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00543000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619968575.11575 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1476 region_size:
            
                
                    12288
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00544000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619968575.13175 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1476 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0054c000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619968575.17875 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1476 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x04350000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619968575.17875 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1476 region_size:
            
                
                    53248
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x04351000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619968575.17875 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1476 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00547000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619968575.53775 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1476 region_size:
            
                
                    8192
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00548000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619968575.60075 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1476 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0435e000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619968575.64675 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1476 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00556000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619968575.77175 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1476 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00c21000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619968575.83475 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1476 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0055a000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619968575.83475 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1476 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00557000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619968575.95975 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1476 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x006c0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619968576.00675 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1476 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x006c1000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619968576.03775 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1476 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x006c2000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619968576.06875 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1476 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0435f000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619968576.10075 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1476 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x006c3000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619968576.61575 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1476 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x006c4000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619968576.61575 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1476 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x021f0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619968576.64675 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1476 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x021f1000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619968576.81875 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1476 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x006c5000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619968576.85075 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1476 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x006c6000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619968576.85075 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1476 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0054d000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619968576.85075 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1476 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x02200000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619968576.86575 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1476 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x02201000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619968576.86575 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1476 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0054a000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619968576.86575 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1476 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0054b000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619968576.86575 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1476 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x006c7000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619968576.88175 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1476 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x021f2000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619968577.06875 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1476 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x021f3000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619968577.10075 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1476 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x006c8000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619968577.11575 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1476 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x006c9000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619968577.11575 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1476 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x006ca000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619968577.11575 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1476 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x006cb000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619968577.16275 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1476 region_size:
            
                
                    327680
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    1056768
                
            
            
                (MEM_RESERVE|MEM_TOP_DOWN)
 base_address:
            
                
                    0x7ef40000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619968577.16275 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    1476 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x7ef40000
 
 | success | 0 | 0 |