NtProtectVirtualMemory
May 20, 2021, 9:48 a.m.
process_identifier:
8024
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x05a01000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 20, 2021, 9:48 a.m.
process_identifier:
8024
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6ebb1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 20, 2021, 9:48 a.m.
process_identifier:
8024
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6ec05000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 20, 2021, 9:48 a.m.
process_identifier:
8024
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x673a1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 20, 2021, 9:48 a.m.
process_identifier:
8024
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x66c91000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 20, 2021, 9:48 a.m.
process_identifier:
8024
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6e621000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 20, 2021, 9:49 a.m.
process_identifier:
8024
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6e8c1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 20, 2021, 9:49 a.m.
process_identifier:
8024
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6e8c4000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 20, 2021, 9:49 a.m.
process_identifier:
8024
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x743c1000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
May 20, 2021, 9:49 a.m.
process_identifier:
8024
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04fa0000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
May 20, 2021, 9:49 a.m.
process_identifier:
8024
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04fa0000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
May 20, 2021, 9:49 a.m.
process_identifier:
8024
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04fb0000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
May 20, 2021, 9:49 a.m.
process_identifier:
8024
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04fc0000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 20, 2021, 9:49 a.m.
process_identifier:
8024
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x507c1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 20, 2021, 9:48 a.m.
process_identifier:
6928
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0214e000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 20, 2021, 9:48 a.m.
process_identifier:
6928
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73861000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 20, 2021, 9:48 a.m.
process_identifier:
6928
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x736f1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 20, 2021, 9:48 a.m.
process_identifier:
6928
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6eac1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 20, 2021, 9:48 a.m.
process_identifier:
6928
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x72931000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 20, 2021, 9:48 a.m.
process_identifier:
6928
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x726d1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 20, 2021, 9:48 a.m.
process_identifier:
6928
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x74e51000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 20, 2021, 9:48 a.m.
process_identifier:
6928
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x72de1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 20, 2021, 9:48 a.m.
process_identifier:
6928
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x70ac1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 20, 2021, 9:48 a.m.
process_identifier:
6928
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73ef1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 20, 2021, 9:48 a.m.
process_identifier:
6928
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x70aa1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 20, 2021, 9:48 a.m.
process_identifier:
6928
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x76891000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 20, 2021, 9:48 a.m.
process_identifier:
6928
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x707d1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 20, 2021, 9:48 a.m.
process_identifier:
6928
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x74481000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 20, 2021, 9:48 a.m.
process_identifier:
6928
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x66a91000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 20, 2021, 9:48 a.m.
process_identifier:
6928
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6e4c1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 20, 2021, 9:48 a.m.
process_identifier:
6928
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x745d1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 20, 2021, 9:48 a.m.
process_identifier:
6928
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x707a1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 20, 2021, 9:48 a.m.
process_identifier:
6928
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x74131000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 20, 2021, 9:48 a.m.
process_identifier:
6928
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x70781000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 20, 2021, 9:48 a.m.
process_identifier:
6928
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x74111000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 20, 2021, 9:48 a.m.
process_identifier:
6928
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x743c1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 20, 2021, 9:48 a.m.
process_identifier:
6928
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x70761000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 20, 2021, 9:48 a.m.
process_identifier:
6928
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x70721000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 20, 2021, 9:48 a.m.
process_identifier:
6928
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x673a1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 20, 2021, 9:48 a.m.
process_identifier:
6928
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x66a71000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 20, 2021, 9:49 a.m.
process_identifier:
6928
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
20480
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02160000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
May 20, 2021, 9:49 a.m.
process_identifier:
6928
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00920000
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
May 20, 2021, 9:49 a.m.
process_identifier:
6928
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00980000
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
May 20, 2021, 9:49 a.m.
process_identifier:
6928
region_size:
77824
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00990000
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 20, 2021, 9:49 a.m.
process_identifier:
6928
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x75111000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 20, 2021, 9:49 a.m.
process_identifier:
6928
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x75241000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 20, 2021, 9:49 a.m.
process_identifier:
6928
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x74f41000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 20, 2021, 9:49 a.m.
process_identifier:
6928
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x740f1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 20, 2021, 9:49 a.m.
process_identifier:
6928
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73e80000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 20, 2021, 9:49 a.m.
process_identifier:
6928
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73771000
process_handle:
0xffffffff
1
0
0