NtProtectVirtualMemory
May 21, 2021, 10:11 a.m.
process_identifier:
2864
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x05b51000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 10:11 a.m.
process_identifier:
2864
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6ebb1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 10:11 a.m.
process_identifier:
2864
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6ec05000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 10:11 a.m.
process_identifier:
2864
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x673a1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 10:11 a.m.
process_identifier:
2864
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x66c91000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 10:11 a.m.
process_identifier:
2864
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6e621000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 10:12 a.m.
process_identifier:
2864
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6e8c1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 10:12 a.m.
process_identifier:
2864
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6e8c4000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 10:12 a.m.
process_identifier:
2864
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x743c1000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
May 21, 2021, 10:12 a.m.
process_identifier:
2864
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x07970000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
May 21, 2021, 10:12 a.m.
process_identifier:
2864
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x07970000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
May 21, 2021, 10:12 a.m.
process_identifier:
2864
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x07980000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
May 21, 2021, 10:12 a.m.
process_identifier:
2864
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x07990000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 10:12 a.m.
process_identifier:
2864
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x507c1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 10:11 a.m.
process_identifier:
6928
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x62047000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 10:11 a.m.
process_identifier:
6928
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6eac1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 10:11 a.m.
process_identifier:
6928
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x72931000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 10:11 a.m.
process_identifier:
6928
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x726d1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 10:11 a.m.
process_identifier:
6928
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x74e51000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 10:11 a.m.
process_identifier:
6928
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x72de1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 10:11 a.m.
process_identifier:
6928
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x70ac1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 10:11 a.m.
process_identifier:
6928
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73ef1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 10:11 a.m.
process_identifier:
6928
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x736f1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 10:11 a.m.
process_identifier:
6928
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x76891000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 10:11 a.m.
process_identifier:
6928
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x70aa1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 10:11 a.m.
process_identifier:
6928
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x74481000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 10:11 a.m.
process_identifier:
6928
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x66a91000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 10:11 a.m.
process_identifier:
6928
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6e4c1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 10:11 a.m.
process_identifier:
6928
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x745d1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 10:11 a.m.
process_identifier:
6928
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x707c1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 10:11 a.m.
process_identifier:
6928
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x74131000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 10:11 a.m.
process_identifier:
6928
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x707a1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 10:11 a.m.
process_identifier:
6928
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x74111000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 10:11 a.m.
process_identifier:
6928
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x743c1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 10:11 a.m.
process_identifier:
6928
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x70781000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 10:11 a.m.
process_identifier:
6928
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x70741000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 10:11 a.m.
process_identifier:
6928
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x673a1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 10:11 a.m.
process_identifier:
6928
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x66a71000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 10:12 a.m.
process_identifier:
6928
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
16384
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6207a000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
May 21, 2021, 10:12 a.m.
process_identifier:
6928
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00330000
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
May 21, 2021, 10:12 a.m.
process_identifier:
6928
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00340000
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
May 21, 2021, 10:12 a.m.
process_identifier:
6928
region_size:
77824
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00370000
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 10:12 a.m.
process_identifier:
6928
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73e80000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 10:12 a.m.
process_identifier:
6928
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73771000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 10:12 a.m.
process_identifier:
6928
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73861000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 10:12 a.m.
process_identifier:
6928
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x72da4000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 10:12 a.m.
process_identifier:
6928
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73772000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 10:12 a.m.
process_identifier:
6928
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73e01000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 10:12 a.m.
process_identifier:
6928
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73db1000
process_handle:
0xffffffff
1
0
0