NtAllocateVirtualMemory
June 2, 2021, 9:36 a.m.
process_identifier:
2952
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x026fb000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
June 2, 2021, 9:36 a.m.
process_identifier:
2952
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0274f000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
June 2, 2021, 9:36 a.m.
process_identifier:
2952
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02659000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
June 2, 2021, 9:36 a.m.
process_identifier:
2952
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x049a0000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
June 2, 2021, 9:36 a.m.
process_identifier:
2952
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x049a1000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
June 2, 2021, 9:36 a.m.
process_identifier:
2952
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x049a2000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
June 2, 2021, 9:36 a.m.
process_identifier:
2952
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04a10000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
June 2, 2021, 9:36 a.m.
process_identifier:
2952
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04a11000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
June 2, 2021, 9:36 a.m.
process_identifier:
2952
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0265a000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 2, 2021, 9:36 a.m.
process_identifier:
2952
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04980178
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
June 2, 2021, 9:36 a.m.
process_identifier:
2952
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x049801a0
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
June 2, 2021, 9:36 a.m.
process_identifier:
2952
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x049801c8
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
June 2, 2021, 9:36 a.m.
process_identifier:
2952
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
11
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x049847ae
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
June 2, 2021, 9:36 a.m.
process_identifier:
2952
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
11
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x049847a2
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
June 2, 2021, 9:36 a.m.
process_identifier:
2952
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
72
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04980208
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
June 2, 2021, 9:36 a.m.
process_identifier:
2952
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04982b3c
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
June 2, 2021, 9:36 a.m.
process_identifier:
2952
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04982b60
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
June 2, 2021, 9:36 a.m.
process_identifier:
2952
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04982b68
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
June 2, 2021, 9:36 a.m.
process_identifier:
2952
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04982b6c
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
June 2, 2021, 9:36 a.m.
process_identifier:
2952
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04982b74
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
June 2, 2021, 9:36 a.m.
process_identifier:
2952
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04982b78
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
June 2, 2021, 9:36 a.m.
process_identifier:
2952
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04982b7c
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
June 2, 2021, 9:36 a.m.
process_identifier:
2952
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04982b80
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
June 2, 2021, 9:36 a.m.
process_identifier:
2952
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04982b88
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
June 2, 2021, 9:36 a.m.
process_identifier:
2952
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04982b8c
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
June 2, 2021, 9:36 a.m.
process_identifier:
2952
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04982b94
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
June 2, 2021, 9:36 a.m.
process_identifier:
2952
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04982b98
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
June 2, 2021, 9:36 a.m.
process_identifier:
2952
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04982b9c
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
June 2, 2021, 9:36 a.m.
process_identifier:
2952
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04982ba4
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
June 2, 2021, 9:36 a.m.
process_identifier:
2952
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04982ba8
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
June 2, 2021, 9:36 a.m.
process_identifier:
2952
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04982bac
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
June 2, 2021, 9:36 a.m.
process_identifier:
2952
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04982bb4
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
June 2, 2021, 9:36 a.m.
process_identifier:
2952
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04982bb8
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
June 2, 2021, 9:36 a.m.
process_identifier:
2952
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04982bbc
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
June 2, 2021, 9:36 a.m.
process_identifier:
2952
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04982bc4
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
June 2, 2021, 9:36 a.m.
process_identifier:
2952
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04982bc8
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
June 2, 2021, 9:36 a.m.
process_identifier:
2952
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04982bcc
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
June 2, 2021, 9:36 a.m.
process_identifier:
2952
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04982bd0
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
June 2, 2021, 9:36 a.m.
process_identifier:
2952
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04982bd8
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
June 2, 2021, 9:36 a.m.
process_identifier:
2952
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04982bdc
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
June 2, 2021, 9:36 a.m.
process_identifier:
2952
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04982be0
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
June 2, 2021, 9:36 a.m.
process_identifier:
2952
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04982be8
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
June 2, 2021, 9:36 a.m.
process_identifier:
2952
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04982bec
process_handle:
0xffffffff
3221225550
0
NtAllocateVirtualMemory
June 2, 2021, 9:36 a.m.
process_identifier:
2952
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04a13000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
June 2, 2021, 9:36 a.m.
process_identifier:
2952
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x049a3000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
June 2, 2021, 9:36 a.m.
process_identifier:
8780
region_size:
2031616
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00920000
allocation_type:
8192
(MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
June 2, 2021, 9:36 a.m.
process_identifier:
8780
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00ad0000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 2, 2021, 9:36 a.m.
process_identifier:
8780
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6fba1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 2, 2021, 9:36 a.m.
process_identifier:
8780
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6fba2000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
June 2, 2021, 9:36 a.m.
process_identifier:
8780
region_size:
2031616
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x022b0000
allocation_type:
8192
(MEM_RESERVE)
process_handle:
0xffffffff
1
0
0