NtAllocateVirtualMemory
Aug. 26, 2021, 8:31 a.m.
process_identifier:
1052
region_size:
2031616
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00b00000
allocation_type:
8192
(MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Aug. 26, 2021, 8:31 a.m.
process_identifier:
1052
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00cb0000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 26, 2021, 8:31 a.m.
process_identifier:
1052
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x731a1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 26, 2021, 8:31 a.m.
process_identifier:
1052
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x731a2000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Aug. 26, 2021, 8:31 a.m.
process_identifier:
1052
region_size:
327680
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00500000
allocation_type:
8192
(MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Aug. 26, 2021, 8:31 a.m.
process_identifier:
1052
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00510000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Aug. 26, 2021, 8:31 a.m.
process_identifier:
1052
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00392000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Aug. 26, 2021, 8:31 a.m.
process_identifier:
1052
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x003c5000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Aug. 26, 2021, 8:31 a.m.
process_identifier:
1052
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x003cb000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Aug. 26, 2021, 8:31 a.m.
process_identifier:
1052
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x003c7000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Aug. 26, 2021, 8:31 a.m.
process_identifier:
1052
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x003ac000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Aug. 26, 2021, 8:31 a.m.
process_identifier:
1052
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00650000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Aug. 26, 2021, 8:31 a.m.
process_identifier:
1052
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0039a000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Aug. 26, 2021, 8:31 a.m.
process_identifier:
1052
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x003ba000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Aug. 26, 2021, 8:31 a.m.
process_identifier:
1052
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x003b7000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Aug. 26, 2021, 8:31 a.m.
process_identifier:
1052
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x003b6000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Aug. 26, 2021, 8:31 a.m.
process_identifier:
1052
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x003bb000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Aug. 26, 2021, 8:31 a.m.
process_identifier:
1052
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x003aa000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Aug. 26, 2021, 8:31 a.m.
process_identifier:
1052
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x003ad000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Aug. 26, 2021, 8:31 a.m.
process_identifier:
1052
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00651000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Aug. 26, 2021, 8:31 a.m.
process_identifier:
1052
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
63488
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x053a0400
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Aug. 26, 2021, 8:31 a.m.
process_identifier:
1052
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x053a0178
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Aug. 26, 2021, 8:31 a.m.
process_identifier:
1052
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x053a01a0
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Aug. 26, 2021, 8:31 a.m.
process_identifier:
1052
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x053a01c8
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Aug. 26, 2021, 8:31 a.m.
process_identifier:
1052
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x053a01f0
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Aug. 26, 2021, 8:31 a.m.
process_identifier:
1052
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x053a0218
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Aug. 26, 2021, 8:31 a.m.
process_identifier:
1052
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
11
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x053affae
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Aug. 26, 2021, 8:31 a.m.
process_identifier:
1052
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
11
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x053affa2
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Aug. 26, 2021, 8:31 a.m.
process_identifier:
1052
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
72
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x053afc00
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Aug. 26, 2021, 8:31 a.m.
process_identifier:
1052
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x053affbc
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Aug. 26, 2021, 8:31 a.m.
process_identifier:
1052
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x053affe0
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Aug. 26, 2021, 8:31 a.m.
process_identifier:
1052
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x053affe8
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Aug. 26, 2021, 8:31 a.m.
process_identifier:
1052
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x053affec
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Aug. 26, 2021, 8:31 a.m.
process_identifier:
1052
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x053afff4
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Aug. 26, 2021, 8:31 a.m.
process_identifier:
1052
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x053afff8
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Aug. 26, 2021, 8:31 a.m.
process_identifier:
1052
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x053afffc
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Aug. 26, 2021, 8:31 a.m.
process_identifier:
1052
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x053b0000
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Aug. 26, 2021, 8:31 a.m.
process_identifier:
1052
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x053b0008
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Aug. 26, 2021, 8:31 a.m.
process_identifier:
1052
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x053b000c
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Aug. 26, 2021, 8:31 a.m.
process_identifier:
1052
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x053b0014
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Aug. 26, 2021, 8:31 a.m.
process_identifier:
1052
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x053b0018
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Aug. 26, 2021, 8:31 a.m.
process_identifier:
1052
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x053b001c
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Aug. 26, 2021, 8:31 a.m.
process_identifier:
1052
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x053b0024
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Aug. 26, 2021, 8:31 a.m.
process_identifier:
1052
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x053b0028
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Aug. 26, 2021, 8:31 a.m.
process_identifier:
1052
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x053b002c
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Aug. 26, 2021, 8:31 a.m.
process_identifier:
1052
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x053b0034
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Aug. 26, 2021, 8:31 a.m.
process_identifier:
1052
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x053b0038
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Aug. 26, 2021, 8:31 a.m.
process_identifier:
1052
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x053b003c
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Aug. 26, 2021, 8:31 a.m.
process_identifier:
1052
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x053b0044
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Aug. 26, 2021, 8:31 a.m.
process_identifier:
1052
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x053b0048
process_handle:
0xffffffff
3221225550
0