NtProtectVirtualMemory
June 1, 2021, 5:04 p.m.
process_identifier:
7388
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73772000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
June 1, 2021, 5:04 p.m.
process_identifier:
7388
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x009e0000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:04 p.m.
process_identifier:
3872
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x2f4e1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:04 p.m.
process_identifier:
3872
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x64ac1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:04 p.m.
process_identifier:
3872
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6f4c1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:04 p.m.
process_identifier:
3872
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6f5de000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:04 p.m.
process_identifier:
3872
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x64d0e000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:04 p.m.
process_identifier:
3872
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x63aa1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:04 p.m.
process_identifier:
3872
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6400a000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:04 p.m.
process_identifier:
3872
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x75738000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:04 p.m.
process_identifier:
3872
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x70851000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:04 p.m.
process_identifier:
3872
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x70851000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:04 p.m.
process_identifier:
3872
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73ef1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:04 p.m.
process_identifier:
3872
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73771000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:04 p.m.
process_identifier:
3872
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73772000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:04 p.m.
process_identifier:
3872
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73801000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
June 1, 2021, 5:04 p.m.
process_identifier:
3872
region_size:
589824
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02ab0000
allocation_type:
8192
(MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
June 1, 2021, 5:04 p.m.
process_identifier:
3872
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02b00000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:04 p.m.
process_identifier:
3872
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x72072000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
June 1, 2021, 5:04 p.m.
process_identifier:
3872
region_size:
2293760
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02c30000
allocation_type:
8192
(MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
June 1, 2021, 5:04 p.m.
process_identifier:
3872
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02e20000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:04 p.m.
process_identifier:
3872
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73c71000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
June 1, 2021, 5:04 p.m.
process_identifier:
3872
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02ac0000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
June 1, 2021, 5:04 p.m.
process_identifier:
3872
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02ac0000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:04 p.m.
process_identifier:
3872
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x744a1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:04 p.m.
process_identifier:
3872
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x70741000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:04 p.m.
process_identifier:
3872
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x7079f000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:04 p.m.
process_identifier:
3872
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x7079f000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:04 p.m.
process_identifier:
3872
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73db1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:04 p.m.
process_identifier:
3872
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73361000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:04 p.m.
process_identifier:
3872
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73711000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
June 1, 2021, 5:04 p.m.
process_identifier:
3872
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04d60000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
June 1, 2021, 5:04 p.m.
process_identifier:
3872
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04d60000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
June 1, 2021, 5:04 p.m.
process_identifier:
3872
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04de0000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
June 1, 2021, 5:04 p.m.
process_identifier:
3872
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04df0000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:04 p.m.
process_identifier:
3872
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6eca1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:04 p.m.
process_identifier:
3872
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x05b41000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:04 p.m.
process_identifier:
3872
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6ebe1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:04 p.m.
process_identifier:
3872
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6ebe4000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:04 p.m.
process_identifier:
3872
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x743c1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:04 p.m.
process_identifier:
3872
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x507c1000
process_handle:
0xffffffff
1
0
0