NtAllocateVirtualMemory
May 19, 2021, 1:32 p.m.
process_identifier:
2208
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x026fb000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
May 19, 2021, 1:32 p.m.
process_identifier:
2208
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0270f000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
May 19, 2021, 1:32 p.m.
process_identifier:
2208
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02699000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
May 19, 2021, 1:32 p.m.
process_identifier:
2208
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02980000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
May 19, 2021, 1:32 p.m.
process_identifier:
2208
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02981000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
May 19, 2021, 1:32 p.m.
process_identifier:
2208
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02982000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
May 19, 2021, 1:32 p.m.
process_identifier:
2208
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x029f0000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
May 19, 2021, 1:32 p.m.
process_identifier:
2208
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x029f1000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
May 19, 2021, 1:32 p.m.
process_identifier:
2208
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0269a000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 19, 2021, 1:32 p.m.
process_identifier:
2208
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02960178
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
May 19, 2021, 1:32 p.m.
process_identifier:
2208
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x029601a0
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
May 19, 2021, 1:32 p.m.
process_identifier:
2208
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x029601c8
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
May 19, 2021, 1:32 p.m.
process_identifier:
2208
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
11
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x029647ae
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
May 19, 2021, 1:32 p.m.
process_identifier:
2208
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
11
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x029647a2
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
May 19, 2021, 1:32 p.m.
process_identifier:
2208
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
72
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02960208
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
May 19, 2021, 1:32 p.m.
process_identifier:
2208
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02962b3c
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
May 19, 2021, 1:32 p.m.
process_identifier:
2208
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02962b60
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
May 19, 2021, 1:32 p.m.
process_identifier:
2208
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02962b68
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
May 19, 2021, 1:32 p.m.
process_identifier:
2208
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02962b6c
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
May 19, 2021, 1:32 p.m.
process_identifier:
2208
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02962b74
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
May 19, 2021, 1:32 p.m.
process_identifier:
2208
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02962b78
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
May 19, 2021, 1:32 p.m.
process_identifier:
2208
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02962b7c
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
May 19, 2021, 1:32 p.m.
process_identifier:
2208
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02962b80
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
May 19, 2021, 1:32 p.m.
process_identifier:
2208
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02962b88
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
May 19, 2021, 1:32 p.m.
process_identifier:
2208
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02962b8c
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
May 19, 2021, 1:32 p.m.
process_identifier:
2208
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02962b94
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
May 19, 2021, 1:32 p.m.
process_identifier:
2208
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02962b98
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
May 19, 2021, 1:32 p.m.
process_identifier:
2208
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02962b9c
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
May 19, 2021, 1:32 p.m.
process_identifier:
2208
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02962ba4
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
May 19, 2021, 1:32 p.m.
process_identifier:
2208
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02962ba8
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
May 19, 2021, 1:32 p.m.
process_identifier:
2208
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02962bac
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
May 19, 2021, 1:32 p.m.
process_identifier:
2208
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02962bb4
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
May 19, 2021, 1:32 p.m.
process_identifier:
2208
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02962bb8
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
May 19, 2021, 1:32 p.m.
process_identifier:
2208
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02962bbc
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
May 19, 2021, 1:32 p.m.
process_identifier:
2208
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02962bc4
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
May 19, 2021, 1:32 p.m.
process_identifier:
2208
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02962bc8
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
May 19, 2021, 1:32 p.m.
process_identifier:
2208
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02962bcc
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
May 19, 2021, 1:32 p.m.
process_identifier:
2208
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02962bd0
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
May 19, 2021, 1:32 p.m.
process_identifier:
2208
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02962bd8
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
May 19, 2021, 1:32 p.m.
process_identifier:
2208
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02962bdc
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
May 19, 2021, 1:32 p.m.
process_identifier:
2208
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02962be0
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
May 19, 2021, 1:32 p.m.
process_identifier:
2208
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02962be8
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
May 19, 2021, 1:32 p.m.
process_identifier:
2208
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02962bec
process_handle:
0xffffffff
3221225550
0
NtAllocateVirtualMemory
May 19, 2021, 1:32 p.m.
process_identifier:
2208
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x029f3000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
May 19, 2021, 1:32 p.m.
process_identifier:
2208
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02983000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
May 19, 2021, 1:32 p.m.
process_identifier:
7636
region_size:
1245184
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x006a0000
allocation_type:
8192
(MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
May 19, 2021, 1:32 p.m.
process_identifier:
7636
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00790000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 19, 2021, 1:32 p.m.
process_identifier:
7636
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6fba1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 19, 2021, 1:32 p.m.
process_identifier:
7636
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6fba2000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
May 19, 2021, 1:32 p.m.
process_identifier:
7636
region_size:
1703936
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00ca0000
allocation_type:
8192
(MEM_RESERVE)
process_handle:
0xffffffff
1
0
0