NtProtectVirtualMemory
May 21, 2021, 11:44 a.m.
process_identifier:
1684
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x65001000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 11:44 a.m.
process_identifier:
1684
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6c9b1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 11:44 a.m.
process_identifier:
1684
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6ca05000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 11:44 a.m.
process_identifier:
1684
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6c9a1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 11:44 a.m.
process_identifier:
1684
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6c971000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 11:44 a.m.
process_identifier:
1684
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6c851000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 11:44 a.m.
process_identifier:
1684
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6b031000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 11:44 a.m.
process_identifier:
1684
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6b034000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 11:44 a.m.
process_identifier:
1684
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6b291000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
May 21, 2021, 11:44 a.m.
process_identifier:
1684
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0a660000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
May 21, 2021, 11:44 a.m.
process_identifier:
1684
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0a660000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
May 21, 2021, 11:44 a.m.
process_identifier:
1684
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0a670000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
May 21, 2021, 11:44 a.m.
process_identifier:
1684
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0a680000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 11:44 a.m.
process_identifier:
1684
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x507c1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 11:44 a.m.
process_identifier:
2552
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6b617000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 11:44 a.m.
process_identifier:
2552
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6b4e1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 11:44 a.m.
process_identifier:
2552
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6b4a1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 11:44 a.m.
process_identifier:
2552
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6b461000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 11:44 a.m.
process_identifier:
2552
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x74e51000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 11:44 a.m.
process_identifier:
2552
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6b441000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 11:44 a.m.
process_identifier:
2552
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6b391000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 11:44 a.m.
process_identifier:
2552
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x72551000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 11:44 a.m.
process_identifier:
2552
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6b371000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 11:44 a.m.
process_identifier:
2552
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x76891000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 11:44 a.m.
process_identifier:
2552
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6b351000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 11:44 a.m.
process_identifier:
2552
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6b341000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 11:44 a.m.
process_identifier:
2552
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6c7b1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 11:44 a.m.
process_identifier:
2552
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6b331000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 11:44 a.m.
process_identifier:
2552
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6b311000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 11:44 a.m.
process_identifier:
2552
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6b2e1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 11:44 a.m.
process_identifier:
2552
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6b2d1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 11:44 a.m.
process_identifier:
2552
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6b2b1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 11:44 a.m.
process_identifier:
2552
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6b2a1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 11:44 a.m.
process_identifier:
2552
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6b291000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 11:44 a.m.
process_identifier:
2552
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6b271000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 11:44 a.m.
process_identifier:
2552
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6b231000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 11:44 a.m.
process_identifier:
2552
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6c9a1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 11:44 a.m.
process_identifier:
2552
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6c7a1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 11:45 a.m.
process_identifier:
2552
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
16384
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6b64a000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
May 21, 2021, 11:45 a.m.
process_identifier:
2552
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00800000
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
May 21, 2021, 11:45 a.m.
process_identifier:
2552
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00810000
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
May 21, 2021, 11:45 a.m.
process_identifier:
2552
region_size:
77824
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00840000
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 11:45 a.m.
process_identifier:
2552
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73730000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 11:45 a.m.
process_identifier:
2552
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x72471000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 11:45 a.m.
process_identifier:
2552
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73d01000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 11:45 a.m.
process_identifier:
2552
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73e74000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 11:45 a.m.
process_identifier:
2552
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x72472000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 11:45 a.m.
process_identifier:
2552
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x743b1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 11:45 a.m.
process_identifier:
2552
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x724e1000
process_handle:
0xffffffff
1
0
0