NtAllocateVirtualMemory
Sept. 22, 2021, 9:45 a.m.
process_identifier:
2220
region_size:
327680
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00500000
allocation_type:
8192
(MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 22, 2021, 9:45 a.m.
process_identifier:
2220
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00510000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Sept. 22, 2021, 9:45 a.m.
process_identifier:
2220
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x72741000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Sept. 22, 2021, 9:45 a.m.
process_identifier:
2220
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x72742000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 22, 2021, 9:45 a.m.
process_identifier:
2220
region_size:
524288
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x01eb0000
allocation_type:
8192
(MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 22, 2021, 9:45 a.m.
process_identifier:
2220
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x01ef0000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 22, 2021, 9:45 a.m.
process_identifier:
2220
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00502000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 22, 2021, 9:45 a.m.
process_identifier:
2220
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00575000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 22, 2021, 9:45 a.m.
process_identifier:
2220
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0057b000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 22, 2021, 9:45 a.m.
process_identifier:
2220
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00577000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 22, 2021, 9:45 a.m.
process_identifier:
2220
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0055c000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 22, 2021, 9:45 a.m.
process_identifier:
2220
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x01ed0000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 22, 2021, 9:45 a.m.
process_identifier:
2220
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0050a000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 22, 2021, 9:45 a.m.
process_identifier:
2220
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0056a000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 22, 2021, 9:45 a.m.
process_identifier:
2220
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00567000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 22, 2021, 9:45 a.m.
process_identifier:
2220
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00566000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 22, 2021, 9:45 a.m.
process_identifier:
2220
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0056b000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 22, 2021, 9:46 a.m.
process_identifier:
2220
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0055a000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 22, 2021, 9:46 a.m.
process_identifier:
2220
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x01ed1000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Sept. 22, 2021, 9:46 a.m.
process_identifier:
2220
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
63488
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04db0400
process_handle:
0xffffffff
3221225550
0
NtAllocateVirtualMemory
Sept. 22, 2021, 9:46 a.m.
process_identifier:
2220
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x01ed2000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Sept. 22, 2021, 9:46 a.m.
process_identifier:
2220
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04db0178
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 22, 2021, 9:46 a.m.
process_identifier:
2220
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04db01a0
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 22, 2021, 9:46 a.m.
process_identifier:
2220
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04db01c8
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 22, 2021, 9:46 a.m.
process_identifier:
2220
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04db01f0
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 22, 2021, 9:46 a.m.
process_identifier:
2220
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04db0218
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 22, 2021, 9:46 a.m.
process_identifier:
2220
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
11
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04dbffae
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 22, 2021, 9:46 a.m.
process_identifier:
2220
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
11
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04dbffa2
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 22, 2021, 9:46 a.m.
process_identifier:
2220
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
72
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04dbfc00
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 22, 2021, 9:46 a.m.
process_identifier:
2220
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04dbffbc
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 22, 2021, 9:46 a.m.
process_identifier:
2220
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04dbffe0
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 22, 2021, 9:46 a.m.
process_identifier:
2220
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04dbffe8
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 22, 2021, 9:46 a.m.
process_identifier:
2220
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04dbffec
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 22, 2021, 9:46 a.m.
process_identifier:
2220
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04dbfff4
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 22, 2021, 9:46 a.m.
process_identifier:
2220
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04dbfff8
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 22, 2021, 9:46 a.m.
process_identifier:
2220
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04dbfffc
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 22, 2021, 9:46 a.m.
process_identifier:
2220
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04dc0000
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 22, 2021, 9:46 a.m.
process_identifier:
2220
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04dc0008
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 22, 2021, 9:46 a.m.
process_identifier:
2220
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04dc000c
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 22, 2021, 9:46 a.m.
process_identifier:
2220
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04dc0014
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 22, 2021, 9:46 a.m.
process_identifier:
2220
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04dc0018
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 22, 2021, 9:46 a.m.
process_identifier:
2220
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04dc001c
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 22, 2021, 9:46 a.m.
process_identifier:
2220
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04dc0024
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 22, 2021, 9:46 a.m.
process_identifier:
2220
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04dc0028
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 22, 2021, 9:46 a.m.
process_identifier:
2220
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04dc002c
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 22, 2021, 9:46 a.m.
process_identifier:
2220
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04dc0034
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 22, 2021, 9:46 a.m.
process_identifier:
2220
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04dc0038
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 22, 2021, 9:46 a.m.
process_identifier:
2220
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04dc003c
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 22, 2021, 9:46 a.m.
process_identifier:
2220
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04dc0044
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 22, 2021, 9:46 a.m.
process_identifier:
2220
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04dc0048
process_handle:
0xffffffff
3221225550
0