| Time & API | Arguments | Status | Return | Repeated | 
                            
                        
                        
                            
| 1619948412.663633 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3056 region_size:
            
                
                    393216
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x005c0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948412.663633 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3056 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005e0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948413.382633 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    3056 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x73f31000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948413.522633 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3056 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0058a000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948413.522633 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    3056 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    8192
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x73f32000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948413.522633 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3056 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00582000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948413.850633 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3056 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00592000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948414.069633 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3056 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00593000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948414.100633 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3056 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005db000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948414.100633 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3056 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005d7000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948414.194633 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3056 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0059c000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948414.272633 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3056 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00c40000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948414.319633 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3056 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00c41000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948414.319633 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3056 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00c42000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948414.319633 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3056 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00c43000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948414.350633 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3056 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00c44000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948414.366633 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3056 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00594000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948414.694633 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3056 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00595000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948414.710633 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3056 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00596000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948414.757633 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3056 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00597000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948414.757633 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3056 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00c45000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948414.835633 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3056 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005aa000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948414.835633 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3056 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005a7000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948414.850633 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3056 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005ca000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948414.866633 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3056 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0058b000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948414.882633 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3056 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00598000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948414.882633 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3056 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00599000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948414.882633 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3056 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00c46000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948414.897633 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3056 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00b90000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948414.897633 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3056 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00c47000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948414.913633 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3056 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005a6000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948415.194633 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3056 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00c48000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948415.241633 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3056 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00c00000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948415.257633 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3056 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00b91000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948415.257633 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3056 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0059d000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948415.257633 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3056 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00c49000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948415.272633 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3056 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00b92000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948415.272633 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3056 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00c4a000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948415.288633 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3056 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00c4b000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948415.304633 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3056 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00c4c000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948415.304633 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3056 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0059a000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948415.304633 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3056 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00c4d000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948415.350633 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3056 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005e1000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948415.460633 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3056 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00c4e000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948415.475633 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3056 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00c4f000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948415.491633 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3056 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005c2000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948415.522633 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3056 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005d5000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948415.772633 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3056 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x047c0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948415.835633 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3056 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00b93000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948415.944633 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    3056 region_size:
            
                
                    917504
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x05850000
 
 | success | 0 | 0 |