NtProtectVirtualMemory
Aug. 4, 2021, 10:40 a.m.
process_identifier:
1488
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6aaad000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 10:41 a.m.
process_identifier:
1488
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6a6be000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 10:41 a.m.
process_identifier:
1488
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04b0c000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 10:41 a.m.
process_identifier:
1488
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04b0c000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 10:41 a.m.
process_identifier:
1488
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04b0c000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 10:41 a.m.
process_identifier:
1488
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04b0c000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 10:41 a.m.
process_identifier:
1488
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04af5000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 10:41 a.m.
process_identifier:
1488
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04af6000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 10:41 a.m.
process_identifier:
1488
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04af6000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 10:41 a.m.
process_identifier:
1488
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04af6000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 10:41 a.m.
process_identifier:
1488
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04af6000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 10:41 a.m.
process_identifier:
1488
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04af5000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 10:41 a.m.
process_identifier:
1488
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04b0c000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 10:41 a.m.
process_identifier:
1488
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04b0c000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 10:41 a.m.
process_identifier:
1488
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04af6000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 10:41 a.m.
process_identifier:
1488
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04af6000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 10:41 a.m.
process_identifier:
1488
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04af6000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 10:41 a.m.
process_identifier:
1488
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04af6000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 10:41 a.m.
process_identifier:
1488
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04af6000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 10:41 a.m.
process_identifier:
1488
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04af6000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 10:41 a.m.
process_identifier:
1488
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04af6000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 10:41 a.m.
process_identifier:
1488
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04af6000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 10:41 a.m.
process_identifier:
1488
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04af6000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 10:41 a.m.
process_identifier:
1488
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04af6000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 10:41 a.m.
process_identifier:
1488
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04af6000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 10:41 a.m.
process_identifier:
1488
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04af6000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 10:41 a.m.
process_identifier:
1488
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04af6000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 10:41 a.m.
process_identifier:
1488
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04af6000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 10:41 a.m.
process_identifier:
1488
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04af6000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 10:41 a.m.
process_identifier:
1488
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04af6000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 10:41 a.m.
process_identifier:
1488
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x08aeb000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 10:41 a.m.
process_identifier:
1488
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x08aeb000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 10:41 a.m.
process_identifier:
1488
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x08aeb000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 10:41 a.m.
process_identifier:
1488
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x08aeb000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 10:41 a.m.
process_identifier:
1488
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x08ac9000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 10:41 a.m.
process_identifier:
1488
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x08ac9000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 10:41 a.m.
process_identifier:
1488
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x08ac9000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 10:41 a.m.
process_identifier:
1488
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x08ac9000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 10:41 a.m.
process_identifier:
1488
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x08ac9000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 10:41 a.m.
process_identifier:
1488
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x08ac9000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 10:41 a.m.
process_identifier:
1488
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x08aeb000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 10:41 a.m.
process_identifier:
1488
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x08aeb000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 10:41 a.m.
process_identifier:
1488
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x08ac9000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 10:41 a.m.
process_identifier:
1488
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x08ac9000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 10:41 a.m.
process_identifier:
1488
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x08ac9000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 10:41 a.m.
process_identifier:
1488
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x08ac9000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 10:41 a.m.
process_identifier:
1488
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x08ac9000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 10:41 a.m.
process_identifier:
1488
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x08ac9000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 10:41 a.m.
process_identifier:
1488
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x08ac9000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 4, 2021, 10:41 a.m.
process_identifier:
1488
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x08ac9000
process_handle:
0xffffffff
1
0
0