NtAllocateVirtualMemory
July 7, 2021, 9:25 a.m.
process_identifier:
3332
region_size:
2293760
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00bb0000
allocation_type:
8192
(MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
July 7, 2021, 9:25 a.m.
process_identifier:
3332
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00da0000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 7, 2021, 9:25 a.m.
process_identifier:
3332
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6fba1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 7, 2021, 9:25 a.m.
process_identifier:
3332
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6fba2000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
July 7, 2021, 9:25 a.m.
process_identifier:
3332
region_size:
458752
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00480000
allocation_type:
8192
(MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
July 7, 2021, 9:25 a.m.
process_identifier:
3332
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x004b0000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
July 7, 2021, 9:25 a.m.
process_identifier:
3332
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x003a2000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
July 7, 2021, 9:25 a.m.
process_identifier:
3332
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x003bc000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
July 7, 2021, 9:25 a.m.
process_identifier:
3332
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00880000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
July 7, 2021, 9:25 a.m.
process_identifier:
3332
region_size:
12288
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00881000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
July 7, 2021, 9:25 a.m.
process_identifier:
3332
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x003aa000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
July 7, 2021, 9:25 a.m.
process_identifier:
3332
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x003db000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
July 7, 2021, 9:25 a.m.
process_identifier:
3332
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x003d7000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 7, 2021, 9:25 a.m.
process_identifier:
3332
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
311296
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00962000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
July 7, 2021, 9:25 a.m.
process_identifier:
3332
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00884000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
July 7, 2021, 9:25 a.m.
process_identifier:
3332
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00885000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
July 7, 2021, 9:25 a.m.
process_identifier:
3332
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00886000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
July 7, 2021, 9:25 a.m.
process_identifier:
3332
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x003d5000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 7, 2021, 9:25 a.m.
process_identifier:
3332
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x009b0000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 7, 2021, 9:25 a.m.
process_identifier:
3332
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x009b0000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 7, 2021, 9:25 a.m.
process_identifier:
3332
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00960000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 7, 2021, 9:25 a.m.
process_identifier:
3332
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00960000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 7, 2021, 9:25 a.m.
process_identifier:
3332
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00960000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 7, 2021, 9:25 a.m.
process_identifier:
3332
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00960000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 7, 2021, 9:25 a.m.
process_identifier:
3332
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00960000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 7, 2021, 9:25 a.m.
process_identifier:
3332
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x009ae000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 7, 2021, 9:25 a.m.
process_identifier:
3332
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x009b0000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 7, 2021, 9:25 a.m.
process_identifier:
3332
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x009b0000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 7, 2021, 9:25 a.m.
process_identifier:
3332
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x009b0000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 7, 2021, 9:25 a.m.
process_identifier:
3332
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x009b0000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 7, 2021, 9:25 a.m.
process_identifier:
3332
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x009b0000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 7, 2021, 9:25 a.m.
process_identifier:
3332
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x009b0000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 7, 2021, 9:25 a.m.
process_identifier:
3332
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x009b0000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 7, 2021, 9:25 a.m.
process_identifier:
3332
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x009b0000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 7, 2021, 9:25 a.m.
process_identifier:
3332
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x009b0000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 7, 2021, 9:25 a.m.
process_identifier:
3332
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x009b0000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 7, 2021, 9:25 a.m.
process_identifier:
3332
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x009b0000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 7, 2021, 9:25 a.m.
process_identifier:
3332
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x009b0000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 7, 2021, 9:25 a.m.
process_identifier:
3332
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x009b0000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 7, 2021, 9:25 a.m.
process_identifier:
3332
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x009b0000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 7, 2021, 9:25 a.m.
process_identifier:
3332
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x009b0000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 7, 2021, 9:25 a.m.
process_identifier:
3332
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x009b0000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 7, 2021, 9:25 a.m.
process_identifier:
3332
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x009b0000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 7, 2021, 9:25 a.m.
process_identifier:
3332
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x009b0000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 7, 2021, 9:25 a.m.
process_identifier:
3332
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x009b0000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 7, 2021, 9:25 a.m.
process_identifier:
3332
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x009b0000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 7, 2021, 9:25 a.m.
process_identifier:
3332
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x009b0000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 7, 2021, 9:25 a.m.
process_identifier:
3332
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x009b0000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 7, 2021, 9:25 a.m.
process_identifier:
3332
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x009b0000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 7, 2021, 9:25 a.m.
process_identifier:
3332
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x009b0000
process_handle:
0xffffffff
1
0
0