| Time & API | Arguments | Status | Return | Repeated | 
                            
                        
                        
                            
| 1619948418.144234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2764 region_size:
            
                
                    1703936
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x00740000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948418.144234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2764 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x008a0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948418.941234 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2764 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x73f31000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948419.097234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2764 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x004da000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948419.097234 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2764 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    8192
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x73f32000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948419.097234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2764 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x004d2000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948419.269234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2764 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x004e2000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948419.331234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2764 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x004e3000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948419.331234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2764 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0051b000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948419.331234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2764 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00517000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948419.363234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2764 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x004ec000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948419.706234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2764 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x004e4000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948419.706234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2764 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x004e5000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948419.753234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2764 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x004e6000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948419.753234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2764 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x007e0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948419.831234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2764 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x004e7000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948419.863234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2764 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x004fa000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948419.863234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2764 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x004f7000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948419.863234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2764 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0050a000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948419.894234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2764 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x004db000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948419.925234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2764 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x004e8000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948419.925234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2764 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x004e9000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948419.988234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2764 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x007e1000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948420.238234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2764 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x004f6000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948420.316234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2764 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x008e0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948420.363234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2764 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00502000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948420.410234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2764 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00515000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948420.535234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2764 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x020c0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948420.550234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2764 region_size:
            
                
                    1703936
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x04da0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948420.550234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2764 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x04f00000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948420.550234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2764 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x04f01000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948420.581234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2764 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x04f02000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948420.581234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2764 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x04f03000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948420.581234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2764 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x04f04000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948420.613234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2764 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x007e2000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948420.613234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2764 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x04f05000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948420.613234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2764 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x04f06000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948420.628234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2764 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x007e3000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948420.628234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2764 region_size:
            
                
                    16384
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x04f07000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948420.628234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2764 region_size:
            
                
                    69632
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x04f0b000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948420.644234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2764 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x04f1c000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948420.706234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2764 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x004ea000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948420.753234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2764 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x007e4000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948420.816234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2764 region_size:
            
                
                    8192
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x007e5000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948420.816234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2764 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x020c1000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948420.816234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2764 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x020c2000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948420.816234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2764 region_size:
            
                
                    8192
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x007e7000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948420.863234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2764 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x008e1000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948420.878234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2764 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x007e9000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948420.956234 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2764 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x020c3000
 
 | success | 0 | 0 |