NtProtectVirtualMemory
July 4, 2021, 10:55 a.m.
process_identifier:
5032
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fef3d33000
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
July 4, 2021, 10:55 a.m.
process_identifier:
5032
region_size:
1966080
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00000000020a0000
allocation_type:
8192
(MEM_RESERVE)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
July 4, 2021, 10:55 a.m.
process_identifier:
5032
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0000000002200000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
July 4, 2021, 10:55 a.m.
process_identifier:
5032
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fef292a000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
July 4, 2021, 10:55 a.m.
process_identifier:
5032
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fef1f55000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
July 4, 2021, 10:55 a.m.
process_identifier:
5032
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fef2291000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
July 4, 2021, 10:55 a.m.
process_identifier:
5032
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fef292b000
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
July 4, 2021, 10:55 a.m.
process_identifier:
5032
region_size:
786432
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0000000001fd0000
allocation_type:
8192
(MEM_RESERVE)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
July 4, 2021, 10:55 a.m.
process_identifier:
5032
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0000000002010000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
July 4, 2021, 10:55 a.m.
process_identifier:
5032
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fef2292000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
July 4, 2021, 10:55 a.m.
process_identifier:
5032
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fef2292000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
July 4, 2021, 10:55 a.m.
process_identifier:
5032
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fef2292000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
July 4, 2021, 10:55 a.m.
process_identifier:
5032
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fef2292000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
July 4, 2021, 10:55 a.m.
process_identifier:
5032
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fef2292000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
July 4, 2021, 10:55 a.m.
process_identifier:
5032
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fef2292000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
July 4, 2021, 10:55 a.m.
process_identifier:
5032
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fef2292000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
July 4, 2021, 10:55 a.m.
process_identifier:
5032
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fef2292000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
July 4, 2021, 10:55 a.m.
process_identifier:
5032
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fef2292000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
July 4, 2021, 10:55 a.m.
process_identifier:
5032
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fef2292000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
July 4, 2021, 10:55 a.m.
process_identifier:
5032
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fef2292000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
July 4, 2021, 10:55 a.m.
process_identifier:
5032
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fef2294000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
July 4, 2021, 10:55 a.m.
process_identifier:
5032
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fef2294000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
July 4, 2021, 10:55 a.m.
process_identifier:
5032
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fef2294000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
July 4, 2021, 10:55 a.m.
process_identifier:
5032
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fef2294000
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
July 4, 2021, 10:55 a.m.
process_identifier:
5032
region_size:
655360
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fffff10000
allocation_type:
1056768
(MEM_RESERVE|MEM_TOP_DOWN)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
July 4, 2021, 10:55 a.m.
process_identifier:
5032
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fffff10000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
July 4, 2021, 10:55 a.m.
process_identifier:
5032
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fffff10000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
July 4, 2021, 10:55 a.m.
process_identifier:
5032
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fffff20000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
July 4, 2021, 10:55 a.m.
process_identifier:
5032
region_size:
65536
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fffff00000
allocation_type:
1056768
(MEM_RESERVE|MEM_TOP_DOWN)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
July 4, 2021, 10:55 a.m.
process_identifier:
5032
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fffff00000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
July 4, 2021, 10:55 a.m.
process_identifier:
5032
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fe92b1a000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
July 4, 2021, 10:55 a.m.
process_identifier:
5032
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fe92bcc000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
July 4, 2021, 10:55 a.m.
process_identifier:
5032
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fe92bf6000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
July 4, 2021, 10:55 a.m.
process_identifier:
5032
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fe92bd0000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
July 4, 2021, 10:55 a.m.
process_identifier:
5032
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fe92b2c000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
July 4, 2021, 10:55 a.m.
process_identifier:
5032
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fef1d36000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
July 4, 2021, 10:55 a.m.
process_identifier:
5032
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fefdddd000
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
July 4, 2021, 10:55 a.m.
process_identifier:
5032
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fe92c40000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
July 4, 2021, 10:56 a.m.
process_identifier:
5032
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fe92b2a000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
July 4, 2021, 10:56 a.m.
process_identifier:
5032
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fe92b1b000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
July 4, 2021, 10:56 a.m.
process_identifier:
5032
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fe92b3b000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
July 4, 2021, 10:56 a.m.
process_identifier:
5032
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fe92b6c000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
July 4, 2021, 10:56 a.m.
process_identifier:
5032
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fe92b3d000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
July 4, 2021, 10:56 a.m.
process_identifier:
5032
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fef7aa0000
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
July 4, 2021, 10:56 a.m.
process_identifier:
5032
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fe92b12000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
July 4, 2021, 10:56 a.m.
process_identifier:
5032
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fe92c80000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
July 4, 2021, 10:56 a.m.
process_identifier:
5032
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fe92b6d000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
July 4, 2021, 10:56 a.m.
process_identifier:
5032
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fe92c81000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
July 4, 2021, 10:56 a.m.
process_identifier:
5032
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fef7da6000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
July 4, 2021, 10:56 a.m.
process_identifier:
5032
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fef7d51000
process_handle:
0xffffffffffffffff
1
0
0