NtAllocateVirtualMemory
Sept. 8, 2021, 9:41 a.m.
process_identifier:
1280
region_size:
1310720
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00680000
allocation_type:
8192
(MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 8, 2021, 9:41 a.m.
process_identifier:
1280
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00780000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Sept. 8, 2021, 9:41 a.m.
process_identifier:
1280
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x731a1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Sept. 8, 2021, 9:41 a.m.
process_identifier:
1280
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x731a2000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 8, 2021, 9:41 a.m.
process_identifier:
1280
region_size:
1310720
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00830000
allocation_type:
8192
(MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 8, 2021, 9:41 a.m.
process_identifier:
1280
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00930000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 8, 2021, 9:41 a.m.
process_identifier:
1280
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00392000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 8, 2021, 9:41 a.m.
process_identifier:
1280
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x003c5000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 8, 2021, 9:41 a.m.
process_identifier:
1280
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x003cb000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 8, 2021, 9:41 a.m.
process_identifier:
1280
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x003c7000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 8, 2021, 9:41 a.m.
process_identifier:
1280
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x003ac000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 8, 2021, 9:41 a.m.
process_identifier:
1280
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00570000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 8, 2021, 9:41 a.m.
process_identifier:
1280
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x003b6000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 8, 2021, 9:41 a.m.
process_identifier:
1280
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0039a000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 8, 2021, 9:41 a.m.
process_identifier:
1280
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x003ba000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 8, 2021, 9:41 a.m.
process_identifier:
1280
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x003b7000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 8, 2021, 9:41 a.m.
process_identifier:
1280
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x003bb000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 8, 2021, 9:41 a.m.
process_identifier:
1280
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x003aa000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 8, 2021, 9:42 a.m.
process_identifier:
1280
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00571000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Sept. 8, 2021, 9:42 a.m.
process_identifier:
1280
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
63488
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00680400
process_handle:
0xffffffff
3221225550
0
NtAllocateVirtualMemory
Sept. 8, 2021, 9:42 a.m.
process_identifier:
1280
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00572000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Sept. 8, 2021, 9:42 a.m.
process_identifier:
1280
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00680178
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 8, 2021, 9:42 a.m.
process_identifier:
1280
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x006801a0
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 8, 2021, 9:42 a.m.
process_identifier:
1280
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x006801c8
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 8, 2021, 9:42 a.m.
process_identifier:
1280
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x006801f0
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 8, 2021, 9:42 a.m.
process_identifier:
1280
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00680218
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 8, 2021, 9:42 a.m.
process_identifier:
1280
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
11
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0068ffae
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 8, 2021, 9:42 a.m.
process_identifier:
1280
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
11
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0068ffa2
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 8, 2021, 9:42 a.m.
process_identifier:
1280
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
72
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0068fc00
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 8, 2021, 9:42 a.m.
process_identifier:
1280
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0068ffbc
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 8, 2021, 9:42 a.m.
process_identifier:
1280
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0068ffe0
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 8, 2021, 9:42 a.m.
process_identifier:
1280
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0068ffe8
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 8, 2021, 9:42 a.m.
process_identifier:
1280
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0068ffec
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 8, 2021, 9:42 a.m.
process_identifier:
1280
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0068fff4
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 8, 2021, 9:42 a.m.
process_identifier:
1280
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0068fff8
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 8, 2021, 9:42 a.m.
process_identifier:
1280
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0068fffc
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 8, 2021, 9:42 a.m.
process_identifier:
1280
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00690000
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 8, 2021, 9:42 a.m.
process_identifier:
1280
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00690008
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 8, 2021, 9:42 a.m.
process_identifier:
1280
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0069000c
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 8, 2021, 9:42 a.m.
process_identifier:
1280
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00690014
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 8, 2021, 9:42 a.m.
process_identifier:
1280
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00690018
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 8, 2021, 9:42 a.m.
process_identifier:
1280
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0069001c
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 8, 2021, 9:42 a.m.
process_identifier:
1280
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00690024
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 8, 2021, 9:42 a.m.
process_identifier:
1280
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00690028
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 8, 2021, 9:42 a.m.
process_identifier:
1280
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0069002c
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 8, 2021, 9:42 a.m.
process_identifier:
1280
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00690034
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 8, 2021, 9:42 a.m.
process_identifier:
1280
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00690038
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 8, 2021, 9:42 a.m.
process_identifier:
1280
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0069003c
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 8, 2021, 9:42 a.m.
process_identifier:
1280
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00690044
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 8, 2021, 9:42 a.m.
process_identifier:
1280
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00690048
process_handle:
0xffffffff
3221225550
0