NtAllocateVirtualMemory
Sept. 2, 2021, 9:14 a.m.
process_identifier:
2484
region_size:
2228224
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00b00000
allocation_type:
8192
(MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 2, 2021, 9:14 a.m.
process_identifier:
2484
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00ce0000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Sept. 2, 2021, 9:14 a.m.
process_identifier:
2484
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x731a1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Sept. 2, 2021, 9:14 a.m.
process_identifier:
2484
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x731a2000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 2, 2021, 9:14 a.m.
process_identifier:
2484
region_size:
1114112
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00bd0000
allocation_type:
8192
(MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 2, 2021, 9:14 a.m.
process_identifier:
2484
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00ca0000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 2, 2021, 9:14 a.m.
process_identifier:
2484
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00422000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 2, 2021, 9:14 a.m.
process_identifier:
2484
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00455000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 2, 2021, 9:14 a.m.
process_identifier:
2484
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0045b000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 2, 2021, 9:14 a.m.
process_identifier:
2484
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00457000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 2, 2021, 9:14 a.m.
process_identifier:
2484
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0043c000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 2, 2021, 9:14 a.m.
process_identifier:
2484
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00840000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 2, 2021, 9:14 a.m.
process_identifier:
2484
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00446000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 2, 2021, 9:14 a.m.
process_identifier:
2484
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0042a000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 2, 2021, 9:14 a.m.
process_identifier:
2484
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0044a000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 2, 2021, 9:14 a.m.
process_identifier:
2484
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00447000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 2, 2021, 9:14 a.m.
process_identifier:
2484
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0044b000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 2, 2021, 9:14 a.m.
process_identifier:
2484
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0043a000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 2, 2021, 9:14 a.m.
process_identifier:
2484
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00841000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Sept. 2, 2021, 9:14 a.m.
process_identifier:
2484
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
63488
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x05120400
process_handle:
0xffffffff
3221225550
0
NtAllocateVirtualMemory
Sept. 2, 2021, 9:14 a.m.
process_identifier:
2484
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00842000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Sept. 2, 2021, 9:14 a.m.
process_identifier:
2484
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x05120178
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 2, 2021, 9:14 a.m.
process_identifier:
2484
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x051201a0
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 2, 2021, 9:14 a.m.
process_identifier:
2484
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x051201c8
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 2, 2021, 9:14 a.m.
process_identifier:
2484
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x051201f0
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 2, 2021, 9:14 a.m.
process_identifier:
2484
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x05120218
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 2, 2021, 9:14 a.m.
process_identifier:
2484
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
11
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0512ffae
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 2, 2021, 9:14 a.m.
process_identifier:
2484
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
11
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0512ffa2
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 2, 2021, 9:14 a.m.
process_identifier:
2484
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
72
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0512fc00
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 2, 2021, 9:14 a.m.
process_identifier:
2484
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0512ffbc
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 2, 2021, 9:14 a.m.
process_identifier:
2484
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0512ffe0
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 2, 2021, 9:14 a.m.
process_identifier:
2484
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0512ffe8
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 2, 2021, 9:14 a.m.
process_identifier:
2484
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0512ffec
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 2, 2021, 9:14 a.m.
process_identifier:
2484
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0512fff4
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 2, 2021, 9:14 a.m.
process_identifier:
2484
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0512fff8
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 2, 2021, 9:14 a.m.
process_identifier:
2484
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0512fffc
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 2, 2021, 9:14 a.m.
process_identifier:
2484
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x05130000
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 2, 2021, 9:14 a.m.
process_identifier:
2484
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x05130008
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 2, 2021, 9:14 a.m.
process_identifier:
2484
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0513000c
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 2, 2021, 9:14 a.m.
process_identifier:
2484
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x05130014
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 2, 2021, 9:14 a.m.
process_identifier:
2484
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x05130018
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 2, 2021, 9:14 a.m.
process_identifier:
2484
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0513001c
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 2, 2021, 9:14 a.m.
process_identifier:
2484
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x05130024
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 2, 2021, 9:14 a.m.
process_identifier:
2484
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x05130028
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 2, 2021, 9:14 a.m.
process_identifier:
2484
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0513002c
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 2, 2021, 9:14 a.m.
process_identifier:
2484
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x05130034
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 2, 2021, 9:14 a.m.
process_identifier:
2484
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x05130038
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 2, 2021, 9:14 a.m.
process_identifier:
2484
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0513003c
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 2, 2021, 9:14 a.m.
process_identifier:
2484
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x05130044
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 2, 2021, 9:14 a.m.
process_identifier:
2484
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x05130048
process_handle:
0xffffffff
3221225550
0