NtProtectVirtualMemory
May 27, 2021, 5:38 p.m.
process_identifier:
8564
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73772000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
May 27, 2021, 5:31 p.m.
process_identifier:
7636
region_size:
2228224
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0000000000800000
allocation_type:
8192
(MEM_RESERVE)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
May 27, 2021, 5:31 p.m.
process_identifier:
7636
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00000000009a0000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
May 27, 2021, 5:38 p.m.
process_identifier:
3752
region_size:
13701120
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02e40000
allocation_type:
8192
(MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
May 27, 2021, 5:38 p.m.
process_identifier:
3752
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x03b50000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 27, 2021, 5:38 p.m.
process_identifier:
3752
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x7560f000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 27, 2021, 5:38 p.m.
process_identifier:
3752
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x7560f000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 27, 2021, 5:38 p.m.
process_identifier:
3752
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x7560f000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 27, 2021, 5:38 p.m.
process_identifier:
3752
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x7560f000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 27, 2021, 5:38 p.m.
process_identifier:
3752
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x755dc000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 27, 2021, 5:38 p.m.
process_identifier:
3752
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x755fc000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 27, 2021, 5:38 p.m.
process_identifier:
3752
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x755dc000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 27, 2021, 5:38 p.m.
process_identifier:
3752
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x755fc000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 27, 2021, 5:38 p.m.
process_identifier:
3752
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73f33000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 27, 2021, 5:38 p.m.
process_identifier:
3752
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73fd7000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 27, 2021, 5:38 p.m.
process_identifier:
3752
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x76809000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 27, 2021, 5:38 p.m.
process_identifier:
3752
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x756b2000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 27, 2021, 5:38 p.m.
process_identifier:
3752
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x755c2000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 27, 2021, 5:38 p.m.
process_identifier:
3752
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x7560f000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 27, 2021, 5:38 p.m.
process_identifier:
3752
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x7560f000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 27, 2021, 5:38 p.m.
process_identifier:
3752
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x7560f000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
May 27, 2021, 5:38 p.m.
process_identifier:
3752
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x032d0000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 27, 2021, 5:38 p.m.
process_identifier:
3752
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73772000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 27, 2021, 5:39 p.m.
process_identifier:
3752
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x745d1000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
May 27, 2021, 5:38 p.m.
process_identifier:
4408
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02600000
allocation_type:
8192
(MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
May 27, 2021, 5:38 p.m.
process_identifier:
4408
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02600000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 27, 2021, 5:38 p.m.
process_identifier:
4408
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x7560f000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 27, 2021, 5:38 p.m.
process_identifier:
4408
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x7560f000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 27, 2021, 5:38 p.m.
process_identifier:
4408
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x7560f000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 27, 2021, 5:38 p.m.
process_identifier:
4408
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x7560f000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 27, 2021, 5:38 p.m.
process_identifier:
4408
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x755dc000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 27, 2021, 5:38 p.m.
process_identifier:
4408
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x755fc000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 27, 2021, 5:38 p.m.
process_identifier:
4408
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x755dc000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 27, 2021, 5:38 p.m.
process_identifier:
4408
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x755fc000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 27, 2021, 5:38 p.m.
process_identifier:
4408
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73f33000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 27, 2021, 5:38 p.m.
process_identifier:
4408
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73fd7000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 27, 2021, 5:38 p.m.
process_identifier:
4408
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x76809000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 27, 2021, 5:38 p.m.
process_identifier:
4408
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x756b2000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 27, 2021, 5:38 p.m.
process_identifier:
4408
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x755c2000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 27, 2021, 5:38 p.m.
process_identifier:
4408
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x755c7000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 27, 2021, 5:38 p.m.
process_identifier:
4408
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x755df000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 27, 2021, 5:38 p.m.
process_identifier:
4408
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x755c6000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 27, 2021, 5:38 p.m.
process_identifier:
4408
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x75733000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 27, 2021, 5:38 p.m.
process_identifier:
4408
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x773fd000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 27, 2021, 5:38 p.m.
process_identifier:
4408
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x75737000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 27, 2021, 5:38 p.m.
process_identifier:
4408
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x755b8000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 27, 2021, 5:38 p.m.
process_identifier:
4408
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x755bd000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 27, 2021, 5:38 p.m.
process_identifier:
4408
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x773e2000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 27, 2021, 5:38 p.m.
process_identifier:
4408
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x773d2000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
May 27, 2021, 5:38 p.m.
process_identifier:
4408
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x74ac6000
process_handle:
0xffffffff
1
0
0