NtProtectVirtualMemory
Aug. 4, 2021, 9:23 a.m.
process_identifier:
1144
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
163840
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02770000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 9:23 a.m.
process_identifier:
1144
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02798000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 9:23 a.m.
process_identifier:
1144
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x027a0000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 9:23 a.m.
process_identifier:
1144
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x027a8000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 9:23 a.m.
process_identifier:
1144
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x027b0000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 9:23 a.m.
process_identifier:
1144
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x027b8000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 9:23 a.m.
process_identifier:
1144
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x027c0000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 9:23 a.m.
process_identifier:
1144
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x027c8000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 9:23 a.m.
process_identifier:
1144
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x027d0000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 9:23 a.m.
process_identifier:
1144
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x027d8000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 9:23 a.m.
process_identifier:
1144
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x027e0000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 9:23 a.m.
process_identifier:
1144
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x027e8000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 9:23 a.m.
process_identifier:
1144
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x027f0000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 9:23 a.m.
process_identifier:
1144
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x027f8000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 9:23 a.m.
process_identifier:
1144
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02800000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 9:23 a.m.
process_identifier:
1144
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02808000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 9:23 a.m.
process_identifier:
1144
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02810000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 9:23 a.m.
process_identifier:
1144
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02818000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 9:23 a.m.
process_identifier:
1144
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02820000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 9:23 a.m.
process_identifier:
1144
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02828000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 9:23 a.m.
process_identifier:
1144
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02830000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 9:23 a.m.
process_identifier:
1144
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02838000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 9:23 a.m.
process_identifier:
1144
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02840000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 9:23 a.m.
process_identifier:
1144
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02848000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 9:23 a.m.
process_identifier:
1144
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02850000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 9:23 a.m.
process_identifier:
1144
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02858000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 9:23 a.m.
process_identifier:
1144
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02860000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 9:23 a.m.
process_identifier:
1144
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02868000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 9:23 a.m.
process_identifier:
1144
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02870000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 9:23 a.m.
process_identifier:
1144
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02878000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 9:23 a.m.
process_identifier:
1144
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02880000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 9:23 a.m.
process_identifier:
1144
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02888000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 9:23 a.m.
process_identifier:
1144
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02890000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 9:23 a.m.
process_identifier:
1144
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02898000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 9:23 a.m.
process_identifier:
1144
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x028a0000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 9:23 a.m.
process_identifier:
2252
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73bf0000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 9:23 a.m.
process_identifier:
2252
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x76001000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 9:23 a.m.
process_identifier:
2252
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x74d31000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 9:23 a.m.
process_identifier:
2252
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73b91000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 9:23 a.m.
process_identifier:
2252
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73b81000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 9:23 a.m.
process_identifier:
2252
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
16384
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73c62000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Aug. 4, 2021, 9:23 a.m.
process_identifier:
2252
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00410000
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Aug. 4, 2021, 9:23 a.m.
process_identifier:
2252
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00420000
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Aug. 4, 2021, 9:23 a.m.
process_identifier:
2252
region_size:
147456
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00760000
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 9:23 a.m.
process_identifier:
2252
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73b21000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 9:23 a.m.
process_identifier:
2252
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73ad1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 9:23 a.m.
process_identifier:
2252
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73841000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 9:23 a.m.
process_identifier:
2252
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73801000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 9:23 a.m.
process_identifier:
2252
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73791000
process_handle:
0xffffffff
1
0
0