NtProtectVirtualMemory
June 1, 2021, 5:05 p.m.
process_identifier:
5096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73772000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
June 1, 2021, 5:05 p.m.
process_identifier:
5096
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00b10000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:05 p.m.
process_identifier:
7072
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x2f7f1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:05 p.m.
process_identifier:
7072
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x64ac1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:05 p.m.
process_identifier:
7072
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6f4c1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:05 p.m.
process_identifier:
7072
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6f5de000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:05 p.m.
process_identifier:
7072
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x64d0e000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:05 p.m.
process_identifier:
7072
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x63aa1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:05 p.m.
process_identifier:
7072
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6400a000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:05 p.m.
process_identifier:
7072
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x75738000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:05 p.m.
process_identifier:
7072
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x70851000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:05 p.m.
process_identifier:
7072
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x70851000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:05 p.m.
process_identifier:
7072
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73ef1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:05 p.m.
process_identifier:
7072
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73771000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:05 p.m.
process_identifier:
7072
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73772000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:05 p.m.
process_identifier:
7072
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73801000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
June 1, 2021, 5:05 p.m.
process_identifier:
7072
region_size:
327680
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02ab0000
allocation_type:
8192
(MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
June 1, 2021, 5:05 p.m.
process_identifier:
7072
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02ac0000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:05 p.m.
process_identifier:
7072
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x72072000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
June 1, 2021, 5:05 p.m.
process_identifier:
7072
region_size:
1900544
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02c30000
allocation_type:
8192
(MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
June 1, 2021, 5:05 p.m.
process_identifier:
7072
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02dc0000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:05 p.m.
process_identifier:
7072
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73c71000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
June 1, 2021, 5:05 p.m.
process_identifier:
7072
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02b00000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
June 1, 2021, 5:05 p.m.
process_identifier:
7072
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02b00000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:05 p.m.
process_identifier:
7072
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x744a1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:05 p.m.
process_identifier:
7072
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x70741000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:05 p.m.
process_identifier:
7072
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x7079f000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:05 p.m.
process_identifier:
7072
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x7079f000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:05 p.m.
process_identifier:
7072
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73db1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:05 p.m.
process_identifier:
7072
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73361000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:05 p.m.
process_identifier:
7072
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73711000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
June 1, 2021, 5:05 p.m.
process_identifier:
7072
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04af0000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
June 1, 2021, 5:05 p.m.
process_identifier:
7072
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04af0000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
June 1, 2021, 5:05 p.m.
process_identifier:
7072
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04b00000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
June 1, 2021, 5:05 p.m.
process_identifier:
7072
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04b10000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:05 p.m.
process_identifier:
7072
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6eca1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:05 p.m.
process_identifier:
7072
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x05d71000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:05 p.m.
process_identifier:
7072
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6ebe1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:05 p.m.
process_identifier:
7072
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6ebe4000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:05 p.m.
process_identifier:
7072
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x743c1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 1, 2021, 5:05 p.m.
process_identifier:
7072
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x507c1000
process_handle:
0xffffffff
1
0
0