| Time & API | Arguments | Status | Return | Repeated | 
                            
                        
                        
                            
| 1619948415.559698 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2364 region_size:
            
                
                    2228224
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x007f0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948415.559698 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2364 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x009d0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948416.262698 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2364 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x73f31000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948416.418698 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2364 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0032a000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948416.418698 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2364 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    8192
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x73f32000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948416.418698 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2364 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00322000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948416.637698 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2364 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00342000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948416.762698 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2364 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00343000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948416.762698 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2364 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0047b000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948416.762698 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2364 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00477000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948417.262698 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2364 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00344000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948417.262698 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2364 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00345000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948417.262698 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2364 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00346000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948417.293698 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2364 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0034c000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948417.340698 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2364 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0034a000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948417.637698 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2364 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x009c0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948417.668698 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2364 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0036a000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948417.684698 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2364 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00362000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948417.715698 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2364 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00347000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948417.715698 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2364 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00356000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948417.715698 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2364 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0035a000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948417.715698 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2364 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00357000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948417.731698 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2364 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0032b000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948417.871698 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2364 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00475000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948418.012698 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2364 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00348000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948456.325698 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2364 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x009c1000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948456.465698 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2364 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x009d1000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948456.528698 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2364 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00349000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948456.575698 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2364 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0036c000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948456.575698 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2364 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x009c2000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948456.668698 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2364 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x009c3000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948456.684698 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2364 region_size:
            
                
                    1310720
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x04aa0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948456.684698 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2364 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x04ba0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948456.684698 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2364 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x04ba1000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948456.700698 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2364 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x04ba2000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948456.715698 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2364 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x04ba3000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948456.715698 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2364 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x04ba4000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948456.731698 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2364 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x04ba5000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948456.731698 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2364 region_size:
            
                
                    16384
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x04ba6000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948456.731698 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2364 region_size:
            
                
                    69632
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x04baa000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948456.731698 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2364 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x04bbb000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948456.746698 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2364 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x04bbc000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948456.746698 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2364 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x04bbd000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948456.746698 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2364 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x04bbe000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948456.762698 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2364 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x04bbf000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948456.762698 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2364 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x04bc0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948456.762698 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2364 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x04bc1000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948456.778698 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2364 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x01140000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948456.793698 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2364 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x009c4000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948456.809698 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2364 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x04bc2000
 
 | success | 0 | 0 |