| Time & API | Arguments | Status | Return | Repeated | 
                            
                        
                        
                            
| 1619948409.966689 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2864 region_size:
            
                
                    524288
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x00480000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948409.966689 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2864 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x004c0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948410.545689 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2864 region_size:
            
                
                    2228224
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x00c70000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948410.545689 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2864 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00e50000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948410.763689 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2864 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x73e71000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948411.123689 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2864 region_size:
            
                
                    458752
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x00500000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948411.123689 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2864 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00530000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948411.123689 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2864 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003ba000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948411.123689 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2864 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    8192
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x73e72000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948411.123689 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2864 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003b2000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948411.466689 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2864 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003c2000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948411.732689 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2864 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003e5000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948411.748689 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2864 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003eb000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948411.748689 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2864 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003e7000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948411.982689 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2864 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003c3000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948412.045689 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2864 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003cc000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948412.576689 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2864 region_size:
            
                
                    8192
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003c4000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948412.591689 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2864 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003c6000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948412.732689 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2864 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00ac0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948412.873689 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2864 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003da000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948412.873689 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2864 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003d7000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948413.373689 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2864 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003d6000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948413.373689 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2864 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003ca000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948443.873689 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2864 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003bc000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948443.904689 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2864 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003c7000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948443.920689 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2864 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003c8000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948444.060689 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2864 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003c9000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948444.248689 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2864 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00ac1000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948444.404689 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2864 region_size:
            
                
                    12288
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00ac2000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948444.435689 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2864 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00e90000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948444.654689 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2864 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00e91000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948444.701689 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2864 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00e92000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948444.716689 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2864 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00e93000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948444.716689 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2864 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003cd000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948444.716689 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2864 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00e94000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948444.748689 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2864 region_size:
            
                
                    8192
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00ac5000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948444.779689 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2864 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00e95000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948444.810689 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2864 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00eaf000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948444.810689 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2864 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00ea0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948444.873689 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2864 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00ac7000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948444.873689 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2864 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00e96000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948445.623689 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2864 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00e97000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948445.623689 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2864 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00e98000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948445.638689 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2864 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00ac8000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948445.654689 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2864 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00e99000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948445.654689 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2864 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00e9a000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948445.670689 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2864 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00e9b000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948445.670689 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2864 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003ce000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948445.685689 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2864 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00e9c000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948445.716689 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2864 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x06330000
 
 | success | 0 | 0 |