| Time & API | Arguments | Status | Return | Repeated | 
                            
                        
                        
                            
| 1619977351.332125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2860 region_size:
            
                
                    1835008
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x008f0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619977351.332125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2860 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00a70000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619977351.832125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2860 region_size:
            
                
                    1900544
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x00af0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619977351.832125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2860 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00c80000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619977352.035125 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2860 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x73e71000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619977352.238125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2860 region_size:
            
                
                    458752
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x008f0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619977352.238125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2860 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00920000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619977352.269125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2860 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x002aa000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619977352.269125 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2860 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    8192
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x73e72000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619977352.269125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2860 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x002a2000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619977352.613125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2860 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x002b2000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619977352.738125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2860 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x002e5000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619977352.738125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2860 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x002eb000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619977352.738125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2860 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x002e7000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619977352.863125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2860 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x002b3000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619977352.910125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2860 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x002bc000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619977352.988125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2860 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x009f0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619977353.191125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2860 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x002b4000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619977353.910125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2860 region_size:
            
                
                    8192
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x002b5000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619977353.957125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2860 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x002b7000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619977353.988125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2860 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x009f1000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619977354.035125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2860 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x002a3000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619977354.035125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2860 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x002ac000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619977354.113125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2860 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x002b8000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619977354.144125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2860 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x002b9000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619977354.269125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2860 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00d60000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619977354.316125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2860 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x002c6000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619977354.379125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2860 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x009f2000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619977354.379125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2860 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x002ca000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619977354.379125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2860 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x002c7000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619977354.426125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2860 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00d61000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619977354.457125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2860 region_size:
            
                
                    12288
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x009f3000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619977354.472125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2860 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x009f6000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619977395.504125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2860 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00d62000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619977395.504125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2860 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x009f7000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619977395.676125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2860 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x009f8000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619977395.816125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2860 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x009f9000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619977395.847125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2860 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x002bd000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619977395.847125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2860 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00d63000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619977395.847125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2860 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x009fa000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619977395.894125 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2860 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    147456
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x05160400
 
 | failed | 3221225550 | 0 | 
                    
                
                    
                        
                        
                            
| 1619977398.535125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2860 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x009fb000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619977398.582125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2860 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x009fc000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619977398.582125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2860 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00d64000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619977398.597125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2860 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x009fd000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619977398.801125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2860 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x009fe000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619977398.801125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2860 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x009ff000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619977399.066125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2860 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00d10000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619977399.129125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2860 region_size:
            
                
                    12288
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00d11000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619977399.144125 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2860 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    8
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x05160178
 
 | failed | 3221225550 | 0 |