NtProtectVirtualMemory
May 21, 2021, 9:54 a.m.
process_identifier:
2208
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x64b1d000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 9:54 a.m.
process_identifier:
2208
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x75111000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 9:54 a.m.
process_identifier:
2208
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x75241000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 9:54 a.m.
process_identifier:
2208
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x74f41000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 9:54 a.m.
process_identifier:
2208
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73861000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 9:54 a.m.
process_identifier:
2208
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x721d1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 9:54 a.m.
process_identifier:
2208
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73821000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 9:54 a.m.
process_identifier:
2208
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x737e1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 9:54 a.m.
process_identifier:
2208
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x74e51000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 9:54 a.m.
process_identifier:
2208
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x743f1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 9:54 a.m.
process_identifier:
2208
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x72121000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 9:54 a.m.
process_identifier:
2208
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73ef1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 9:54 a.m.
process_identifier:
2208
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73c91000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 9:54 a.m.
process_identifier:
2208
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x76891000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 9:54 a.m.
process_identifier:
2208
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x736f1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 9:54 a.m.
process_identifier:
2208
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x743e1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 9:54 a.m.
process_identifier:
2208
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x66a91000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 9:54 a.m.
process_identifier:
2208
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6e4c1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 9:54 a.m.
process_identifier:
2208
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x74131000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 9:54 a.m.
process_identifier:
2208
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x72c81000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 9:54 a.m.
process_identifier:
2208
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x74111000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 9:54 a.m.
process_identifier:
2208
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x72de1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 9:54 a.m.
process_identifier:
2208
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73d31000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 9:54 a.m.
process_identifier:
2208
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x743c1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 9:54 a.m.
process_identifier:
2208
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x72c61000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 9:54 a.m.
process_identifier:
2208
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x72961000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 9:54 a.m.
process_identifier:
2208
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x673a1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 9:54 a.m.
process_identifier:
2208
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x66a71000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 9:54 a.m.
process_identifier:
2208
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
20480
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x64b68000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
May 21, 2021, 9:54 a.m.
process_identifier:
2208
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00350000
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
May 21, 2021, 9:54 a.m.
process_identifier:
2208
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00360000
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
May 21, 2021, 9:54 a.m.
process_identifier:
2208
region_size:
151552
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00370000
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 9:54 a.m.
process_identifier:
2208
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73e80000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 9:54 a.m.
process_identifier:
2208
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73771000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 9:54 a.m.
process_identifier:
2208
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x72da4000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 9:54 a.m.
process_identifier:
2208
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73772000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 9:54 a.m.
process_identifier:
2208
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73e01000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 9:54 a.m.
process_identifier:
2208
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x720c1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 9:54 a.m.
process_identifier:
2208
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x72071000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 9:54 a.m.
process_identifier:
7748
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x64b1d000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 9:54 a.m.
process_identifier:
7748
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x75111000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 9:54 a.m.
process_identifier:
7748
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x75241000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 9:54 a.m.
process_identifier:
7748
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x74f41000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 9:54 a.m.
process_identifier:
7748
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73861000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 9:54 a.m.
process_identifier:
7748
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x721d1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 9:54 a.m.
process_identifier:
7748
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73821000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 9:54 a.m.
process_identifier:
7748
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x737e1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 9:54 a.m.
process_identifier:
7748
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x74e51000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 9:54 a.m.
process_identifier:
7748
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x743f1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 9:54 a.m.
process_identifier:
7748
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x72121000
process_handle:
0xffffffff
1
0
0