NtAllocateVirtualMemory
Sept. 22, 2021, 9:18 a.m.
process_identifier:
896
region_size:
1114112
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00610000
allocation_type:
8192
(MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 22, 2021, 9:18 a.m.
process_identifier:
896
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x006e0000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Sept. 22, 2021, 9:18 a.m.
process_identifier:
896
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x731a1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Sept. 22, 2021, 9:18 a.m.
process_identifier:
896
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x731a2000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 22, 2021, 9:18 a.m.
process_identifier:
896
region_size:
393216
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00580000
allocation_type:
8192
(MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 22, 2021, 9:18 a.m.
process_identifier:
896
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x005a0000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 22, 2021, 9:18 a.m.
process_identifier:
896
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00422000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 22, 2021, 9:18 a.m.
process_identifier:
896
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0043c000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 22, 2021, 9:18 a.m.
process_identifier:
896
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00555000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 22, 2021, 9:18 a.m.
process_identifier:
896
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0055b000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 22, 2021, 9:18 a.m.
process_identifier:
896
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00557000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 22, 2021, 9:18 a.m.
process_identifier:
896
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00b40000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 22, 2021, 9:18 a.m.
process_identifier:
896
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0042a000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 22, 2021, 9:18 a.m.
process_identifier:
896
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0044a000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 22, 2021, 9:18 a.m.
process_identifier:
896
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00447000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 22, 2021, 9:18 a.m.
process_identifier:
896
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00446000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 22, 2021, 9:18 a.m.
process_identifier:
896
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0044b000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 22, 2021, 9:18 a.m.
process_identifier:
896
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0043a000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 22, 2021, 9:18 a.m.
process_identifier:
896
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00b41000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Sept. 22, 2021, 9:18 a.m.
process_identifier:
896
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
63488
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00720400
process_handle:
0xffffffff
3221225550
0
NtAllocateVirtualMemory
Sept. 22, 2021, 9:18 a.m.
process_identifier:
896
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00b42000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Sept. 22, 2021, 9:18 a.m.
process_identifier:
896
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00720178
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 22, 2021, 9:18 a.m.
process_identifier:
896
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x007201a0
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 22, 2021, 9:18 a.m.
process_identifier:
896
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x007201c8
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 22, 2021, 9:18 a.m.
process_identifier:
896
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x007201f0
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 22, 2021, 9:18 a.m.
process_identifier:
896
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00720218
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 22, 2021, 9:18 a.m.
process_identifier:
896
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
11
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0072ffae
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 22, 2021, 9:18 a.m.
process_identifier:
896
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
11
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0072ffa2
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 22, 2021, 9:18 a.m.
process_identifier:
896
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
72
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0072fc00
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 22, 2021, 9:18 a.m.
process_identifier:
896
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0072ffbc
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 22, 2021, 9:18 a.m.
process_identifier:
896
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0072ffe0
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 22, 2021, 9:18 a.m.
process_identifier:
896
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0072ffe8
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 22, 2021, 9:18 a.m.
process_identifier:
896
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0072ffec
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 22, 2021, 9:18 a.m.
process_identifier:
896
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0072fff4
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 22, 2021, 9:18 a.m.
process_identifier:
896
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0072fff8
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 22, 2021, 9:18 a.m.
process_identifier:
896
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0072fffc
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 22, 2021, 9:18 a.m.
process_identifier:
896
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00730000
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 22, 2021, 9:18 a.m.
process_identifier:
896
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00730008
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 22, 2021, 9:18 a.m.
process_identifier:
896
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0073000c
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 22, 2021, 9:18 a.m.
process_identifier:
896
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00730014
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 22, 2021, 9:18 a.m.
process_identifier:
896
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00730018
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 22, 2021, 9:18 a.m.
process_identifier:
896
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0073001c
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 22, 2021, 9:18 a.m.
process_identifier:
896
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00730024
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 22, 2021, 9:18 a.m.
process_identifier:
896
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00730028
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 22, 2021, 9:18 a.m.
process_identifier:
896
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0073002c
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 22, 2021, 9:18 a.m.
process_identifier:
896
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00730034
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 22, 2021, 9:18 a.m.
process_identifier:
896
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00730038
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 22, 2021, 9:18 a.m.
process_identifier:
896
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0073003c
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 22, 2021, 9:18 a.m.
process_identifier:
896
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00730044
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 22, 2021, 9:18 a.m.
process_identifier:
896
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00730048
process_handle:
0xffffffff
3221225550
0