NtProtectVirtualMemory
May 21, 2021, 1:39 p.m.
process_identifier:
2444
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x65001000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 1:39 p.m.
process_identifier:
2444
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6c9b1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 1:39 p.m.
process_identifier:
2444
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6ca05000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 1:39 p.m.
process_identifier:
2444
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6c9a1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 1:39 p.m.
process_identifier:
2444
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6c971000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 1:40 p.m.
process_identifier:
2444
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6c851000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 1:40 p.m.
process_identifier:
2444
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6b031000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 1:40 p.m.
process_identifier:
2444
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6b034000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 1:40 p.m.
process_identifier:
2444
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6b291000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
May 21, 2021, 1:40 p.m.
process_identifier:
2444
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x07780000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
May 21, 2021, 1:40 p.m.
process_identifier:
2444
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x07780000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
May 21, 2021, 1:40 p.m.
process_identifier:
2444
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x07790000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
May 21, 2021, 1:40 p.m.
process_identifier:
2444
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x077a0000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 1:40 p.m.
process_identifier:
2444
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x507c1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 1:40 p.m.
process_identifier:
1456
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6b617000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 1:40 p.m.
process_identifier:
1456
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6b4e1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 1:40 p.m.
process_identifier:
1456
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6b4a1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 1:40 p.m.
process_identifier:
1456
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6b461000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 1:40 p.m.
process_identifier:
1456
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x74e51000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 1:40 p.m.
process_identifier:
1456
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6b441000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 1:40 p.m.
process_identifier:
1456
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6b391000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 1:40 p.m.
process_identifier:
1456
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x72551000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 1:40 p.m.
process_identifier:
1456
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6b371000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 1:40 p.m.
process_identifier:
1456
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x76891000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 1:40 p.m.
process_identifier:
1456
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6b351000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 1:40 p.m.
process_identifier:
1456
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6b341000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 1:40 p.m.
process_identifier:
1456
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6c7b1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 1:40 p.m.
process_identifier:
1456
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6b331000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 1:40 p.m.
process_identifier:
1456
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6b311000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 1:40 p.m.
process_identifier:
1456
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6b2e1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 1:40 p.m.
process_identifier:
1456
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6b2d1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 1:40 p.m.
process_identifier:
1456
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6b2b1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 1:40 p.m.
process_identifier:
1456
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6b2a1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 1:40 p.m.
process_identifier:
1456
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6b291000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 1:40 p.m.
process_identifier:
1456
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6b271000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 1:40 p.m.
process_identifier:
1456
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6b231000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 1:40 p.m.
process_identifier:
1456
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6c9a1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 1:40 p.m.
process_identifier:
1456
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6c7a1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 1:40 p.m.
process_identifier:
1456
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
16384
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6b64a000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
May 21, 2021, 1:40 p.m.
process_identifier:
1456
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x003c0000
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
May 21, 2021, 1:40 p.m.
process_identifier:
1456
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x003d0000
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
May 21, 2021, 1:40 p.m.
process_identifier:
1456
region_size:
77824
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x003e0000
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 1:40 p.m.
process_identifier:
1456
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73730000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 1:40 p.m.
process_identifier:
1456
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x72471000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 1:40 p.m.
process_identifier:
1456
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73d01000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 1:40 p.m.
process_identifier:
1456
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73e74000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 1:40 p.m.
process_identifier:
1456
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x72472000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 1:40 p.m.
process_identifier:
1456
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x743b1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 21, 2021, 1:40 p.m.
process_identifier:
1456
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x724e1000
process_handle:
0xffffffff
1
0
0