NtAllocateVirtualMemory
June 26, 2021, 10:21 a.m.
process_identifier:
812
region_size:
655360
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00550000
allocation_type:
8192
(MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
June 26, 2021, 10:21 a.m.
process_identifier:
812
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x005b0000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 26, 2021, 10:21 a.m.
process_identifier:
812
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6fc91000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
June 26, 2021, 10:21 a.m.
process_identifier:
812
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0057a000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 26, 2021, 10:21 a.m.
process_identifier:
812
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6fc92000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
June 26, 2021, 10:21 a.m.
process_identifier:
812
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00572000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
June 26, 2021, 10:21 a.m.
process_identifier:
812
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00582000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
June 26, 2021, 10:21 a.m.
process_identifier:
812
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00583000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
June 26, 2021, 10:21 a.m.
process_identifier:
812
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x005fb000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
June 26, 2021, 10:21 a.m.
process_identifier:
812
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x005f7000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
June 26, 2021, 10:21 a.m.
process_identifier:
812
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0058c000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
June 26, 2021, 10:21 a.m.
process_identifier:
812
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02090000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
June 26, 2021, 10:21 a.m.
process_identifier:
812
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00584000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
June 26, 2021, 10:21 a.m.
process_identifier:
812
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02091000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
June 26, 2021, 10:21 a.m.
process_identifier:
812
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02092000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
June 26, 2021, 10:21 a.m.
process_identifier:
812
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02093000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
June 26, 2021, 10:21 a.m.
process_identifier:
812
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02094000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
June 26, 2021, 10:21 a.m.
process_identifier:
812
region_size:
12288
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02095000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
June 26, 2021, 10:21 a.m.
process_identifier:
812
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0058a000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 26, 2021, 10:21 a.m.
process_identifier:
812
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00be4000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 26, 2021, 10:21 a.m.
process_identifier:
812
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00be4000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 26, 2021, 10:21 a.m.
process_identifier:
812
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00a50000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 26, 2021, 10:21 a.m.
process_identifier:
812
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00a50000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 26, 2021, 10:21 a.m.
process_identifier:
812
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00a50000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 26, 2021, 10:21 a.m.
process_identifier:
812
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00a52000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 26, 2021, 10:21 a.m.
process_identifier:
812
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00b64000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 26, 2021, 10:21 a.m.
process_identifier:
812
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00b64000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 26, 2021, 10:21 a.m.
process_identifier:
812
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00b64000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 26, 2021, 10:21 a.m.
process_identifier:
812
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00b64000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 26, 2021, 10:21 a.m.
process_identifier:
812
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00b64000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 26, 2021, 10:21 a.m.
process_identifier:
812
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00b64000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 26, 2021, 10:21 a.m.
process_identifier:
812
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00b64000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 26, 2021, 10:21 a.m.
process_identifier:
812
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00b64000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 26, 2021, 10:21 a.m.
process_identifier:
812
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00b64000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 26, 2021, 10:21 a.m.
process_identifier:
812
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00b64000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 26, 2021, 10:21 a.m.
process_identifier:
812
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00b64000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 26, 2021, 10:21 a.m.
process_identifier:
812
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00b64000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 26, 2021, 10:21 a.m.
process_identifier:
812
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00b64000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 26, 2021, 10:21 a.m.
process_identifier:
812
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00b64000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 26, 2021, 10:21 a.m.
process_identifier:
812
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00b64000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 26, 2021, 10:21 a.m.
process_identifier:
812
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00b64000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 26, 2021, 10:21 a.m.
process_identifier:
812
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00b64000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 26, 2021, 10:21 a.m.
process_identifier:
812
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00b64000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 26, 2021, 10:21 a.m.
process_identifier:
812
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00b64000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 26, 2021, 10:21 a.m.
process_identifier:
812
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00b64000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 26, 2021, 10:21 a.m.
process_identifier:
812
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00b64000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 26, 2021, 10:21 a.m.
process_identifier:
812
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00b64000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 26, 2021, 10:21 a.m.
process_identifier:
812
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00b64000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 26, 2021, 10:21 a.m.
process_identifier:
812
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00b64000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
June 26, 2021, 10:21 a.m.
process_identifier:
812
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00b64000
process_handle:
0xffffffff
1
0
0