NtAllocateVirtualMemory
Sept. 22, 2021, 10:05 p.m.
process_identifier:
1908
region_size:
1310720
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x004f0000
allocation_type:
8192
(MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 22, 2021, 10:05 p.m.
process_identifier:
1908
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x005f0000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Sept. 22, 2021, 10:05 p.m.
process_identifier:
1908
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x72741000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Sept. 22, 2021, 10:05 p.m.
process_identifier:
1908
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x72742000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 22, 2021, 10:05 p.m.
process_identifier:
1908
region_size:
1179648
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00ab0000
allocation_type:
8192
(MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 22, 2021, 10:05 p.m.
process_identifier:
1908
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00b90000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 22, 2021, 10:05 p.m.
process_identifier:
1908
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00532000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 22, 2021, 10:05 p.m.
process_identifier:
1908
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0054c000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 22, 2021, 10:05 p.m.
process_identifier:
1908
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00565000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 22, 2021, 10:05 p.m.
process_identifier:
1908
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0056b000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 22, 2021, 10:05 p.m.
process_identifier:
1908
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00567000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 22, 2021, 10:05 p.m.
process_identifier:
1908
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00a20000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 22, 2021, 10:05 p.m.
process_identifier:
1908
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0053a000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 22, 2021, 10:05 p.m.
process_identifier:
1908
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0055a000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 22, 2021, 10:05 p.m.
process_identifier:
1908
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00557000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 22, 2021, 10:05 p.m.
process_identifier:
1908
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00556000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 22, 2021, 10:05 p.m.
process_identifier:
1908
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0055b000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 22, 2021, 10:05 p.m.
process_identifier:
1908
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0054a000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 22, 2021, 10:05 p.m.
process_identifier:
1908
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00a21000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Sept. 22, 2021, 10:05 p.m.
process_identifier:
1908
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
63488
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x05310400
process_handle:
0xffffffff
3221225550
0
NtAllocateVirtualMemory
Sept. 22, 2021, 10:05 p.m.
process_identifier:
1908
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00a22000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Sept. 22, 2021, 10:05 p.m.
process_identifier:
1908
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x05310178
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 22, 2021, 10:05 p.m.
process_identifier:
1908
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x053101a0
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 22, 2021, 10:05 p.m.
process_identifier:
1908
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x053101c8
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 22, 2021, 10:05 p.m.
process_identifier:
1908
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x053101f0
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 22, 2021, 10:05 p.m.
process_identifier:
1908
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x05310218
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 22, 2021, 10:05 p.m.
process_identifier:
1908
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
11
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0531ffae
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 22, 2021, 10:05 p.m.
process_identifier:
1908
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
11
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0531ffa2
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 22, 2021, 10:05 p.m.
process_identifier:
1908
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
72
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0531fc00
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 22, 2021, 10:05 p.m.
process_identifier:
1908
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0531ffbc
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 22, 2021, 10:05 p.m.
process_identifier:
1908
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0531ffe0
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 22, 2021, 10:05 p.m.
process_identifier:
1908
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0531ffe8
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 22, 2021, 10:05 p.m.
process_identifier:
1908
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0531ffec
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 22, 2021, 10:05 p.m.
process_identifier:
1908
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0531fff4
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 22, 2021, 10:05 p.m.
process_identifier:
1908
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0531fff8
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 22, 2021, 10:05 p.m.
process_identifier:
1908
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0531fffc
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 22, 2021, 10:05 p.m.
process_identifier:
1908
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x05320000
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 22, 2021, 10:05 p.m.
process_identifier:
1908
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x05320008
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 22, 2021, 10:05 p.m.
process_identifier:
1908
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0532000c
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 22, 2021, 10:05 p.m.
process_identifier:
1908
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x05320014
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 22, 2021, 10:05 p.m.
process_identifier:
1908
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x05320018
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 22, 2021, 10:05 p.m.
process_identifier:
1908
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0532001c
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 22, 2021, 10:05 p.m.
process_identifier:
1908
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x05320024
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 22, 2021, 10:05 p.m.
process_identifier:
1908
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x05320028
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 22, 2021, 10:05 p.m.
process_identifier:
1908
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0532002c
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 22, 2021, 10:05 p.m.
process_identifier:
1908
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x05320034
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 22, 2021, 10:05 p.m.
process_identifier:
1908
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x05320038
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 22, 2021, 10:05 p.m.
process_identifier:
1908
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0532003c
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 22, 2021, 10:05 p.m.
process_identifier:
1908
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x05320044
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 22, 2021, 10:05 p.m.
process_identifier:
1908
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x05320048
process_handle:
0xffffffff
3221225550
0