NtAllocateVirtualMemory
Aug. 9, 2021, 11:19 p.m.
process_identifier:
1756
region_size:
2031616
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00ad0000
allocation_type:
8192
(MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Aug. 9, 2021, 11:19 p.m.
process_identifier:
1756
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00c80000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 9, 2021, 11:19 p.m.
process_identifier:
1756
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x72421000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 9, 2021, 11:19 p.m.
process_identifier:
1756
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x72422000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Aug. 9, 2021, 11:19 p.m.
process_identifier:
1756
region_size:
2228224
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x020c0000
allocation_type:
8192
(MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Aug. 9, 2021, 11:19 p.m.
process_identifier:
1756
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x022a0000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Aug. 9, 2021, 11:19 p.m.
process_identifier:
1756
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x003d2000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Aug. 9, 2021, 11:19 p.m.
process_identifier:
1756
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x003ec000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Aug. 9, 2021, 11:19 p.m.
process_identifier:
1756
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x005f0000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Aug. 9, 2021, 11:19 p.m.
process_identifier:
1756
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x005f1000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Aug. 9, 2021, 11:19 p.m.
process_identifier:
1756
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x005f2000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Aug. 9, 2021, 11:19 p.m.
process_identifier:
1756
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x005f3000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Aug. 9, 2021, 11:19 p.m.
process_identifier:
1756
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x005f4000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Aug. 9, 2021, 11:19 p.m.
process_identifier:
1756
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x003da000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Aug. 9, 2021, 11:19 p.m.
process_identifier:
1756
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0040b000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Aug. 9, 2021, 11:19 p.m.
process_identifier:
1756
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00407000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 9, 2021, 11:19 p.m.
process_identifier:
1756
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00a92000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 9, 2021, 11:19 p.m.
process_identifier:
1756
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00a92000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 9, 2021, 11:19 p.m.
process_identifier:
1756
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00980000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 9, 2021, 11:19 p.m.
process_identifier:
1756
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00980000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 9, 2021, 11:19 p.m.
process_identifier:
1756
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00980000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 9, 2021, 11:19 p.m.
process_identifier:
1756
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00982000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 9, 2021, 11:19 p.m.
process_identifier:
1756
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00a6d000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 9, 2021, 11:19 p.m.
process_identifier:
1756
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00a6d000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 9, 2021, 11:19 p.m.
process_identifier:
1756
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00a6d000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 9, 2021, 11:19 p.m.
process_identifier:
1756
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00a6d000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 9, 2021, 11:19 p.m.
process_identifier:
1756
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00a6d000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 9, 2021, 11:19 p.m.
process_identifier:
1756
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00a6d000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 9, 2021, 11:19 p.m.
process_identifier:
1756
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00a6d000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 9, 2021, 11:19 p.m.
process_identifier:
1756
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00a6d000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 9, 2021, 11:19 p.m.
process_identifier:
1756
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00a6d000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 9, 2021, 11:19 p.m.
process_identifier:
1756
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00a6d000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 9, 2021, 11:19 p.m.
process_identifier:
1756
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00a6d000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 9, 2021, 11:19 p.m.
process_identifier:
1756
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00a6d000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 9, 2021, 11:19 p.m.
process_identifier:
1756
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00a6d000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 9, 2021, 11:19 p.m.
process_identifier:
1756
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00a6d000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 9, 2021, 11:19 p.m.
process_identifier:
1756
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00a6d000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 9, 2021, 11:19 p.m.
process_identifier:
1756
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00a6d000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 9, 2021, 11:19 p.m.
process_identifier:
1756
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00a6d000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 9, 2021, 11:19 p.m.
process_identifier:
1756
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00a6d000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 9, 2021, 11:19 p.m.
process_identifier:
1756
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00a6d000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 9, 2021, 11:19 p.m.
process_identifier:
1756
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00a6d000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 9, 2021, 11:19 p.m.
process_identifier:
1756
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00a6d000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 9, 2021, 11:19 p.m.
process_identifier:
1756
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00a6d000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 9, 2021, 11:19 p.m.
process_identifier:
1756
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00a6d000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 9, 2021, 11:19 p.m.
process_identifier:
1756
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00a6d000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 9, 2021, 11:19 p.m.
process_identifier:
1756
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00a6d000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 9, 2021, 11:19 p.m.
process_identifier:
1756
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00a6d000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 9, 2021, 11:19 p.m.
process_identifier:
1756
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00a6d000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 9, 2021, 11:19 p.m.
process_identifier:
1756
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00a6d000
process_handle:
0xffffffff
1
0
0