| Time & API | Arguments | Status | Return | Repeated | 
                            
                        
                        
                            
| 1619948416.911119 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    1179648
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x005d0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948416.911119 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x006b0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948417.646119 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2856 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x73f31000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948417.724119 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0053a000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948417.724119 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2856 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    8192
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x73f32000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948417.724119 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00532000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948417.880119 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00552000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948417.974119 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00553000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948417.989119 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0058b000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948417.989119 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00587000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948418.021119 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0055c000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948418.083119 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x007d0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948418.114119 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00554000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948418.114119 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x007d1000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948418.130119 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x007d2000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948418.130119 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x007d3000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948418.161119 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x007d4000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948418.286119 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00555000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948418.317119 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x007d5000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948418.333119 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x007d6000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948418.349119 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0055a000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948418.427119 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0057a000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948418.458119 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00572000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948418.505119 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00585000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948418.614119 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x007d7000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948418.786119 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00556000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948418.911119 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0056a000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948418.911119 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00567000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948457.067119 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0053b000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948457.208119 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x007d8000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948457.302119 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0057c000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948457.349119 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00566000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948457.349119 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00557000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948457.364119 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x007d9000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948457.427119 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2856 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    297984
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x04a10400
 
 | failed | 3221225550 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948463.802119 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x007da000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948463.817119 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00558000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948463.817119 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x007db000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948463.864119 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x007dc000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948463.958119 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x007dd000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948463.974119 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x007de000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948464.130119 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x007df000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948464.411119 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x04ec0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948464.427119 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2856 region_size:
            
                
                    8192
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x04ec1000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948464.458119 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2856 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    8
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x04a10178
 
 | failed | 3221225550 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948464.458119 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2856 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    8
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x04a101a0
 
 | failed | 3221225550 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948464.458119 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2856 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    8
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x04a101c8
 
 | failed | 3221225550 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948464.458119 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2856 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    8
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x04a101f0
 
 | failed | 3221225550 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948464.458119 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2856 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    8
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x04a10218
 
 | failed | 3221225550 | 0 | 
                    
                
                    
                        
                        
                            
| 1619948464.458119 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2856 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    11
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x04a598ee
 
 | failed | 3221225550 | 0 |