NtAllocateVirtualMemory
June 4, 2021, 12:10 p.m.
process_identifier:
3024
region_size:
1179648
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x004a0000
allocation_type:
8192
(MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
June 4, 2021, 12:10 p.m.
process_identifier:
3024
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00580000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 4, 2021, 12:10 p.m.
process_identifier:
3024
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x72831000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
June 4, 2021, 12:10 p.m.
process_identifier:
3024
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x003ca000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 4, 2021, 12:10 p.m.
process_identifier:
3024
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x72832000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
June 4, 2021, 12:10 p.m.
process_identifier:
3024
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x003c2000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
June 4, 2021, 12:10 p.m.
process_identifier:
3024
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x003d2000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
June 4, 2021, 12:10 p.m.
process_identifier:
3024
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x003d3000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
June 4, 2021, 12:10 p.m.
process_identifier:
3024
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0040b000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
June 4, 2021, 12:10 p.m.
process_identifier:
3024
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00407000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
June 4, 2021, 12:10 p.m.
process_identifier:
3024
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x003dc000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
June 4, 2021, 12:10 p.m.
process_identifier:
3024
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00b20000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
June 4, 2021, 12:10 p.m.
process_identifier:
3024
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00b21000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
June 4, 2021, 12:10 p.m.
process_identifier:
3024
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00b22000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
June 4, 2021, 12:10 p.m.
process_identifier:
3024
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00b23000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
June 4, 2021, 12:10 p.m.
process_identifier:
3024
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00b24000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
June 4, 2021, 12:10 p.m.
process_identifier:
3024
region_size:
12288
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00b25000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
June 4, 2021, 12:10 p.m.
process_identifier:
3024
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x003da000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 4, 2021, 12:10 p.m.
process_identifier:
3024
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00d4a000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 4, 2021, 12:10 p.m.
process_identifier:
3024
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00d4a000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 4, 2021, 12:10 p.m.
process_identifier:
3024
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00b30000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 4, 2021, 12:10 p.m.
process_identifier:
3024
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00b30000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 4, 2021, 12:10 p.m.
process_identifier:
3024
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00b30000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 4, 2021, 12:10 p.m.
process_identifier:
3024
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00b32000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 4, 2021, 12:10 p.m.
process_identifier:
3024
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00cfa000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 4, 2021, 12:10 p.m.
process_identifier:
3024
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00cfa000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 4, 2021, 12:10 p.m.
process_identifier:
3024
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00cfa000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 4, 2021, 12:10 p.m.
process_identifier:
3024
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00cfa000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 4, 2021, 12:10 p.m.
process_identifier:
3024
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00cfa000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 4, 2021, 12:10 p.m.
process_identifier:
3024
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00cfa000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 4, 2021, 12:10 p.m.
process_identifier:
3024
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00cfa000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 4, 2021, 12:10 p.m.
process_identifier:
3024
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00cfa000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 4, 2021, 12:10 p.m.
process_identifier:
3024
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00cfa000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 4, 2021, 12:10 p.m.
process_identifier:
3024
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00cfa000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 4, 2021, 12:10 p.m.
process_identifier:
3024
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00cfa000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 4, 2021, 12:10 p.m.
process_identifier:
3024
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00cfa000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 4, 2021, 12:10 p.m.
process_identifier:
3024
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00cfa000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 4, 2021, 12:10 p.m.
process_identifier:
3024
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00cfa000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 4, 2021, 12:10 p.m.
process_identifier:
3024
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00cfa000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 4, 2021, 12:10 p.m.
process_identifier:
3024
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00cfa000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 4, 2021, 12:10 p.m.
process_identifier:
3024
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00cfa000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 4, 2021, 12:10 p.m.
process_identifier:
3024
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00cfa000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 4, 2021, 12:10 p.m.
process_identifier:
3024
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00cfa000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 4, 2021, 12:10 p.m.
process_identifier:
3024
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00cfa000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 4, 2021, 12:10 p.m.
process_identifier:
3024
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00cfa000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 4, 2021, 12:10 p.m.
process_identifier:
3024
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00cfa000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 4, 2021, 12:10 p.m.
process_identifier:
3024
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00cfa000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 4, 2021, 12:10 p.m.
process_identifier:
3024
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00cfa000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 4, 2021, 12:10 p.m.
process_identifier:
3024
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00cfa000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 4, 2021, 12:10 p.m.
process_identifier:
3024
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00cfa000
process_handle:
0xffffffff
1
0
0