NtProtectVirtualMemory
June 1, 2021, 5:04 p.m.
process_identifier:
6704
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73772000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
June 1, 2021, 5:04 p.m.
process_identifier:
6704
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x009f0000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:04 p.m.
process_identifier:
1472
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x2f721000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:04 p.m.
process_identifier:
1472
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x64ac1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:04 p.m.
process_identifier:
1472
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6f4c1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:04 p.m.
process_identifier:
1472
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6f5de000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:04 p.m.
process_identifier:
1472
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x64d0e000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:04 p.m.
process_identifier:
1472
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x63aa1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:04 p.m.
process_identifier:
1472
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6400a000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:04 p.m.
process_identifier:
1472
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x75738000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:04 p.m.
process_identifier:
1472
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x70851000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:04 p.m.
process_identifier:
1472
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x70851000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:04 p.m.
process_identifier:
1472
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73ef1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:04 p.m.
process_identifier:
1472
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73771000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:04 p.m.
process_identifier:
1472
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73772000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:04 p.m.
process_identifier:
1472
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73801000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
June 1, 2021, 5:04 p.m.
process_identifier:
1472
region_size:
1376256
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02ab0000
allocation_type:
8192
(MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
June 1, 2021, 5:04 p.m.
process_identifier:
1472
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02bc0000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:04 p.m.
process_identifier:
1472
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x72072000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
June 1, 2021, 5:04 p.m.
process_identifier:
1472
region_size:
2162688
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02c80000
allocation_type:
8192
(MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
June 1, 2021, 5:04 p.m.
process_identifier:
1472
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02e50000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:04 p.m.
process_identifier:
1472
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73c71000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
June 1, 2021, 5:04 p.m.
process_identifier:
1472
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02ac0000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
June 1, 2021, 5:04 p.m.
process_identifier:
1472
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02ac0000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:04 p.m.
process_identifier:
1472
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x744a1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:04 p.m.
process_identifier:
1472
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x70741000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:04 p.m.
process_identifier:
1472
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x7079f000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:04 p.m.
process_identifier:
1472
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x7079f000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:04 p.m.
process_identifier:
1472
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73db1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:04 p.m.
process_identifier:
1472
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73361000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:04 p.m.
process_identifier:
1472
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73711000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
June 1, 2021, 5:04 p.m.
process_identifier:
1472
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x047b0000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
June 1, 2021, 5:04 p.m.
process_identifier:
1472
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x047b0000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
June 1, 2021, 5:04 p.m.
process_identifier:
1472
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04dc0000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
June 1, 2021, 5:04 p.m.
process_identifier:
1472
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04dd0000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:04 p.m.
process_identifier:
1472
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6eca1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:04 p.m.
process_identifier:
1472
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x05d31000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:04 p.m.
process_identifier:
1472
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6ebe1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:04 p.m.
process_identifier:
1472
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6ebe4000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:04 p.m.
process_identifier:
1472
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x743c1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:04 p.m.
process_identifier:
1472
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x507c1000
process_handle:
0xffffffff
1
0
0