NtAllocateVirtualMemory
Aug. 10, 2021, 5:42 p.m.
process_identifier:
1136
region_size:
1048576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x003e0000
allocation_type:
8192
(MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Aug. 10, 2021, 5:42 p.m.
process_identifier:
1136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x004a0000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 10, 2021, 5:42 p.m.
process_identifier:
1136
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x731a1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 10, 2021, 5:42 p.m.
process_identifier:
1136
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x731a2000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Aug. 10, 2021, 5:42 p.m.
process_identifier:
1136
region_size:
1114112
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x005a0000
allocation_type:
8192
(MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Aug. 10, 2021, 5:42 p.m.
process_identifier:
1136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00670000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Aug. 10, 2021, 5:42 p.m.
process_identifier:
1136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x003e2000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Aug. 10, 2021, 5:42 p.m.
process_identifier:
1136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00415000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Aug. 10, 2021, 5:42 p.m.
process_identifier:
1136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0041b000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Aug. 10, 2021, 5:42 p.m.
process_identifier:
1136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00417000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Aug. 10, 2021, 5:42 p.m.
process_identifier:
1136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x003fc000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Aug. 10, 2021, 5:42 p.m.
process_identifier:
1136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x005b0000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Aug. 10, 2021, 5:42 p.m.
process_identifier:
1136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x003ea000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Aug. 10, 2021, 5:42 p.m.
process_identifier:
1136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0040a000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Aug. 10, 2021, 5:42 p.m.
process_identifier:
1136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00407000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Aug. 10, 2021, 5:42 p.m.
process_identifier:
1136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00406000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Aug. 10, 2021, 5:42 p.m.
process_identifier:
1136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0040b000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Aug. 10, 2021, 5:42 p.m.
process_identifier:
1136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x003fa000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Aug. 10, 2021, 5:42 p.m.
process_identifier:
1136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x005b1000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 10, 2021, 5:42 p.m.
process_identifier:
1136
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
63488
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04e10400
process_handle:
0xffffffff
3221225550
0
NtAllocateVirtualMemory
Aug. 10, 2021, 5:42 p.m.
process_identifier:
1136
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x005b2000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 10, 2021, 5:42 p.m.
process_identifier:
1136
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04e10178
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Aug. 10, 2021, 5:42 p.m.
process_identifier:
1136
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04e101a0
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Aug. 10, 2021, 5:42 p.m.
process_identifier:
1136
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04e101c8
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Aug. 10, 2021, 5:42 p.m.
process_identifier:
1136
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04e101f0
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Aug. 10, 2021, 5:42 p.m.
process_identifier:
1136
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04e10218
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Aug. 10, 2021, 5:42 p.m.
process_identifier:
1136
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
11
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04e1ffae
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Aug. 10, 2021, 5:42 p.m.
process_identifier:
1136
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
11
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04e1ffa2
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Aug. 10, 2021, 5:42 p.m.
process_identifier:
1136
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
72
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04e1fc00
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Aug. 10, 2021, 5:42 p.m.
process_identifier:
1136
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04e1ffbc
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Aug. 10, 2021, 5:42 p.m.
process_identifier:
1136
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04e1ffe0
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Aug. 10, 2021, 5:42 p.m.
process_identifier:
1136
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04e1ffe8
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Aug. 10, 2021, 5:42 p.m.
process_identifier:
1136
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04e1ffec
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Aug. 10, 2021, 5:42 p.m.
process_identifier:
1136
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04e1fff4
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Aug. 10, 2021, 5:42 p.m.
process_identifier:
1136
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04e1fff8
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Aug. 10, 2021, 5:42 p.m.
process_identifier:
1136
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04e1fffc
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Aug. 10, 2021, 5:42 p.m.
process_identifier:
1136
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04e20000
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Aug. 10, 2021, 5:42 p.m.
process_identifier:
1136
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04e20008
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Aug. 10, 2021, 5:42 p.m.
process_identifier:
1136
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04e2000c
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Aug. 10, 2021, 5:42 p.m.
process_identifier:
1136
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04e20014
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Aug. 10, 2021, 5:42 p.m.
process_identifier:
1136
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04e20018
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Aug. 10, 2021, 5:42 p.m.
process_identifier:
1136
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04e2001c
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Aug. 10, 2021, 5:42 p.m.
process_identifier:
1136
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04e20024
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Aug. 10, 2021, 5:42 p.m.
process_identifier:
1136
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04e20028
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Aug. 10, 2021, 5:42 p.m.
process_identifier:
1136
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04e2002c
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Aug. 10, 2021, 5:42 p.m.
process_identifier:
1136
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04e20034
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Aug. 10, 2021, 5:42 p.m.
process_identifier:
1136
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04e20038
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Aug. 10, 2021, 5:42 p.m.
process_identifier:
1136
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04e2003c
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Aug. 10, 2021, 5:42 p.m.
process_identifier:
1136
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04e20044
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Aug. 10, 2021, 5:42 p.m.
process_identifier:
1136
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04e20048
process_handle:
0xffffffff
3221225550
0