| Time & API | Arguments | Status | Return | Repeated | 
                            
                        
                        
                            
| 1619966615.069125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2520 region_size:
            
                
                    1572864
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x00830000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619966615.069125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2520 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00970000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619966615.459125 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2520 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    4096
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x73f31000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619966615.538125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2520 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003ba000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619966615.538125 NtProtectVirtualMemory
 
 | process_identifier:
            
                
                    2520 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 length:
            
                
                    8192
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 base_address:
            
                
                    0x73f32000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619966615.538125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2520 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003b2000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619966615.756125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2520 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003c2000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619966615.834125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2520 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003c3000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619966615.850125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2520 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x0048b000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619966615.850125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2520 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00487000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619966615.913125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2520 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003cc000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619966615.975125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2520 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005a0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619966616.163125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2520 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003ca000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619966616.256125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2520 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003fa000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619966616.288125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2520 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003f2000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619966616.334125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2520 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003c4000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619966616.366125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2520 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00485000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619966616.678125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2520 region_size:
            
                
                    8192
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003c5000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619966616.756125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2520 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003ea000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619966616.756125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2520 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003e7000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619966616.772125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2520 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003bb000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619966616.850125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2520 region_size:
            
                
                    8192
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005a1000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619966617.006125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2520 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x047e0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619966617.053125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2520 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003e6000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619966617.194125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2520 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003c7000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619966617.209125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2520 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005a3000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619966617.397125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2520 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00971000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619966617.538125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2520 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003c8000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619966617.538125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2520 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005a4000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619966617.553125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2520 region_size:
            
                
                    2162688
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x05b40000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619966617.553125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2520 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x05d10000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619966617.553125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2520 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x05d11000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619966617.584125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2520 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x05d12000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619966617.600125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2520 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x05d13000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619966617.600125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2520 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x05d14000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619966617.600125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2520 region_size:
            
                
                    12288
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x05d15000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619966617.600125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2520 region_size:
            
                
                    8192
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x05d18000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619966617.600125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2520 region_size:
            
                
                    8192
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x05d1a000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619966617.600125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2520 region_size:
            
                
                    16384
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x05d1c000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619966617.600125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2520 region_size:
            
                
                    69632
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x05d20000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619966617.631125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2520 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005a5000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619966617.647125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2520 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x05d31000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619966617.663125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2520 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005a6000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619966617.772125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2520 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x047e1000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619966617.897125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2520 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003b3000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619966617.959125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2520 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x047e2000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619966621.803125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2520 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x003c9000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619966621.819125 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2520 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x005a7000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619966622.49175 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2064 region_size:
            
                
                    1114112
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    0
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    8192
                
            
            
                (MEM_RESERVE)
 base_address:
            
                
                    0x007b0000
 
 | success | 0 | 0 | 
                    
                
                    
                        
                        
                            
| 1619966622.49175 NtAllocateVirtualMemory
 
 | process_identifier:
            
                
                    2064 region_size:
            
                
                    4096
 stack_dep_bypass:
            
                
                    0
 stack_pivoted:
            
                
                    0
 heap_dep_bypass:
            
                
                    1
 protection:
            
                
                    64
                
            
            
                (PAGE_EXECUTE_READWRITE)
 process_handle:
            
                
                    0xffffffff
 allocation_type:
            
                
                    4096
                
            
            
                (MEM_COMMIT)
 base_address:
            
                
                    0x00880000
 
 | success | 0 | 0 |