NtProtectVirtualMemory
Aug. 10, 2021, 9:29 p.m.
process_identifier:
2476
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x007b2000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 10, 2021, 9:29 p.m.
process_identifier:
2476
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x74140000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 10, 2021, 9:29 p.m.
process_identifier:
2476
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x768e1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 10, 2021, 9:29 p.m.
process_identifier:
2476
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
16384
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0080c000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Aug. 10, 2021, 9:29 p.m.
process_identifier:
2476
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00860000
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Aug. 10, 2021, 9:29 p.m.
process_identifier:
2476
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00870000
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Aug. 10, 2021, 9:29 p.m.
process_identifier:
2476
region_size:
167936
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00890000
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 10, 2021, 9:29 p.m.
process_identifier:
2576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00792000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 10, 2021, 9:29 p.m.
process_identifier:
2576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x74140000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 10, 2021, 9:29 p.m.
process_identifier:
2576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x768e1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 10, 2021, 9:29 p.m.
process_identifier:
2576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
16384
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x007ec000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Aug. 10, 2021, 9:29 p.m.
process_identifier:
2576
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x008c0000
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Aug. 10, 2021, 9:29 p.m.
process_identifier:
2576
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x008d0000
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Aug. 10, 2021, 9:29 p.m.
process_identifier:
2576
region_size:
167936
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x008e0000
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 10, 2021, 9:29 p.m.
process_identifier:
2576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x767c1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 10, 2021, 9:29 p.m.
process_identifier:
2576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x74dc1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 10, 2021, 9:29 p.m.
process_identifier:
2576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x76b41000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 10, 2021, 9:29 p.m.
process_identifier:
2576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x739f1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 10, 2021, 9:29 p.m.
process_identifier:
2576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x739d1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 10, 2021, 9:29 p.m.
process_identifier:
2576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x739c1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 10, 2021, 9:29 p.m.
process_identifier:
2576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x739b1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 10, 2021, 9:29 p.m.
process_identifier:
2576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x739a1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 10, 2021, 9:29 p.m.
process_identifier:
2576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73991000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 10, 2021, 9:29 p.m.
process_identifier:
2576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73931000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 10, 2021, 9:29 p.m.
process_identifier:
2576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x738f1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 10, 2021, 9:29 p.m.
process_identifier:
2576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x738b1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 10, 2021, 9:29 p.m.
process_identifier:
2576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73891000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 10, 2021, 9:29 p.m.
process_identifier:
2576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x731c1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 10, 2021, 9:29 p.m.
process_identifier:
2576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x75131000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 10, 2021, 9:29 p.m.
process_identifier:
2272
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00802000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 10, 2021, 9:29 p.m.
process_identifier:
2272
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x74140000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 10, 2021, 9:29 p.m.
process_identifier:
2272
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x768e1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 10, 2021, 9:29 p.m.
process_identifier:
2272
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
16384
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0085c000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Aug. 10, 2021, 9:29 p.m.
process_identifier:
2272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00350000
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Aug. 10, 2021, 9:29 p.m.
process_identifier:
2272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00360000
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Aug. 10, 2021, 9:29 p.m.
process_identifier:
2272
region_size:
167936
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x008b0000
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 10, 2021, 9:29 p.m.
process_identifier:
2272
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x767c1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 10, 2021, 9:29 p.m.
process_identifier:
2272
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x74dc1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 10, 2021, 9:29 p.m.
process_identifier:
2272
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x76b41000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 10, 2021, 9:29 p.m.
process_identifier:
2272
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x739f1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 10, 2021, 9:29 p.m.
process_identifier:
2272
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x739d1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 10, 2021, 9:29 p.m.
process_identifier:
2272
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x739c1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 10, 2021, 9:29 p.m.
process_identifier:
2272
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x739b1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 10, 2021, 9:29 p.m.
process_identifier:
2272
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x739a1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 10, 2021, 9:29 p.m.
process_identifier:
2272
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73991000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 10, 2021, 9:29 p.m.
process_identifier:
2272
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73931000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 10, 2021, 9:29 p.m.
process_identifier:
2272
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x738f1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 10, 2021, 9:29 p.m.
process_identifier:
2272
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x738b1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 10, 2021, 9:29 p.m.
process_identifier:
2272
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73891000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 10, 2021, 9:29 p.m.
process_identifier:
2272
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x731c1000
process_handle:
0xffffffff
1
0
0