NtAllocateVirtualMemory
Aug. 9, 2021, 6:59 p.m.
process_identifier:
2108
region_size:
524288
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00530000
allocation_type:
8192
(MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Aug. 9, 2021, 6:59 p.m.
process_identifier:
2108
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00570000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 9, 2021, 6:59 p.m.
process_identifier:
2108
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73a71000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 9, 2021, 6:59 p.m.
process_identifier:
2108
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73a72000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Aug. 9, 2021, 6:59 p.m.
process_identifier:
2108
region_size:
1441792
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00a70000
allocation_type:
8192
(MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Aug. 9, 2021, 6:59 p.m.
process_identifier:
2108
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00b90000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Aug. 9, 2021, 6:59 p.m.
process_identifier:
2108
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00552000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Aug. 9, 2021, 6:59 p.m.
process_identifier:
2108
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x005c5000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Aug. 9, 2021, 6:59 p.m.
process_identifier:
2108
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x005cb000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Aug. 9, 2021, 6:59 p.m.
process_identifier:
2108
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x005c7000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Aug. 9, 2021, 6:59 p.m.
process_identifier:
2108
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0056c000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Aug. 9, 2021, 6:59 p.m.
process_identifier:
2108
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00ac0000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Aug. 9, 2021, 6:59 p.m.
process_identifier:
2108
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0055a000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Aug. 9, 2021, 6:59 p.m.
process_identifier:
2108
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x005ba000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Aug. 9, 2021, 6:59 p.m.
process_identifier:
2108
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x005b7000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Aug. 9, 2021, 6:59 p.m.
process_identifier:
2108
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x005b6000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Aug. 9, 2021, 6:59 p.m.
process_identifier:
2108
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x005bb000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Aug. 9, 2021, 6:59 p.m.
process_identifier:
2108
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0056a000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Aug. 9, 2021, 6:59 p.m.
process_identifier:
2108
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00ac1000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 9, 2021, 6:59 p.m.
process_identifier:
2108
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
63488
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04f00400
process_handle:
0xffffffff
3221225550
0
NtAllocateVirtualMemory
Aug. 9, 2021, 6:59 p.m.
process_identifier:
2108
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00ac2000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 9, 2021, 6:59 p.m.
process_identifier:
2108
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04f00178
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Aug. 9, 2021, 6:59 p.m.
process_identifier:
2108
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04f001a0
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Aug. 9, 2021, 6:59 p.m.
process_identifier:
2108
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04f001c8
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Aug. 9, 2021, 6:59 p.m.
process_identifier:
2108
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04f001f0
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Aug. 9, 2021, 6:59 p.m.
process_identifier:
2108
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04f00218
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Aug. 9, 2021, 6:59 p.m.
process_identifier:
2108
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
11
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04f0ffae
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Aug. 9, 2021, 6:59 p.m.
process_identifier:
2108
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
11
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04f0ffa2
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Aug. 9, 2021, 6:59 p.m.
process_identifier:
2108
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
72
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04f0fc00
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Aug. 9, 2021, 6:59 p.m.
process_identifier:
2108
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04f0ffbc
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Aug. 9, 2021, 6:59 p.m.
process_identifier:
2108
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04f0ffe0
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Aug. 9, 2021, 6:59 p.m.
process_identifier:
2108
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04f0ffe8
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Aug. 9, 2021, 6:59 p.m.
process_identifier:
2108
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04f0ffec
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Aug. 9, 2021, 6:59 p.m.
process_identifier:
2108
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04f0fff4
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Aug. 9, 2021, 6:59 p.m.
process_identifier:
2108
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04f0fff8
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Aug. 9, 2021, 6:59 p.m.
process_identifier:
2108
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04f0fffc
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Aug. 9, 2021, 6:59 p.m.
process_identifier:
2108
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04f10000
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Aug. 9, 2021, 6:59 p.m.
process_identifier:
2108
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04f10008
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Aug. 9, 2021, 6:59 p.m.
process_identifier:
2108
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04f1000c
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Aug. 9, 2021, 6:59 p.m.
process_identifier:
2108
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04f10014
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Aug. 9, 2021, 6:59 p.m.
process_identifier:
2108
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04f10018
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Aug. 9, 2021, 6:59 p.m.
process_identifier:
2108
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04f1001c
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Aug. 9, 2021, 6:59 p.m.
process_identifier:
2108
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04f10024
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Aug. 9, 2021, 6:59 p.m.
process_identifier:
2108
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04f10028
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Aug. 9, 2021, 6:59 p.m.
process_identifier:
2108
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04f1002c
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Aug. 9, 2021, 6:59 p.m.
process_identifier:
2108
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04f10034
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Aug. 9, 2021, 6:59 p.m.
process_identifier:
2108
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04f10038
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Aug. 9, 2021, 6:59 p.m.
process_identifier:
2108
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04f1003c
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Aug. 9, 2021, 6:59 p.m.
process_identifier:
2108
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04f10044
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Aug. 9, 2021, 6:59 p.m.
process_identifier:
2108
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04f10048
process_handle:
0xffffffff
3221225550
0