NtAllocateVirtualMemory
Sept. 23, 2021, 8:23 a.m.
process_identifier:
1040
region_size:
393216
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x004f0000
allocation_type:
8192
(MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 23, 2021, 8:23 a.m.
process_identifier:
1040
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00510000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Sept. 23, 2021, 8:23 a.m.
process_identifier:
1040
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x731a1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Sept. 23, 2021, 8:23 a.m.
process_identifier:
1040
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x731a2000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 23, 2021, 8:23 a.m.
process_identifier:
1040
region_size:
1769472
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02190000
allocation_type:
8192
(MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 23, 2021, 8:23 a.m.
process_identifier:
1040
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02300000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 23, 2021, 8:23 a.m.
process_identifier:
1040
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00552000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 23, 2021, 8:23 a.m.
process_identifier:
1040
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x005c5000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 23, 2021, 8:23 a.m.
process_identifier:
1040
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x005cb000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 23, 2021, 8:23 a.m.
process_identifier:
1040
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x005c7000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 23, 2021, 8:23 a.m.
process_identifier:
1040
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0056c000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 23, 2021, 8:23 a.m.
process_identifier:
1040
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00790000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 23, 2021, 8:23 a.m.
process_identifier:
1040
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0055a000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 23, 2021, 8:23 a.m.
process_identifier:
1040
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x005ba000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 23, 2021, 8:23 a.m.
process_identifier:
1040
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x005b7000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 23, 2021, 8:23 a.m.
process_identifier:
1040
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x005b6000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 23, 2021, 8:23 a.m.
process_identifier:
1040
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x005bb000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 23, 2021, 8:23 a.m.
process_identifier:
1040
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0056a000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 23, 2021, 8:23 a.m.
process_identifier:
1040
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00791000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Sept. 23, 2021, 8:23 a.m.
process_identifier:
1040
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
63488
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00690400
process_handle:
0xffffffff
3221225550
0
NtAllocateVirtualMemory
Sept. 23, 2021, 8:23 a.m.
process_identifier:
1040
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00792000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Sept. 23, 2021, 8:23 a.m.
process_identifier:
1040
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00690178
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 23, 2021, 8:23 a.m.
process_identifier:
1040
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x006901a0
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 23, 2021, 8:23 a.m.
process_identifier:
1040
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x006901c8
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 23, 2021, 8:23 a.m.
process_identifier:
1040
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x006901f0
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 23, 2021, 8:23 a.m.
process_identifier:
1040
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00690218
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 23, 2021, 8:23 a.m.
process_identifier:
1040
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
11
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0069ffae
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 23, 2021, 8:23 a.m.
process_identifier:
1040
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
11
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0069ffa2
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 23, 2021, 8:23 a.m.
process_identifier:
1040
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
72
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0069fc00
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 23, 2021, 8:23 a.m.
process_identifier:
1040
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0069ffbc
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 23, 2021, 8:23 a.m.
process_identifier:
1040
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0069ffe0
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 23, 2021, 8:23 a.m.
process_identifier:
1040
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0069ffe8
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 23, 2021, 8:23 a.m.
process_identifier:
1040
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0069ffec
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 23, 2021, 8:23 a.m.
process_identifier:
1040
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0069fff4
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 23, 2021, 8:23 a.m.
process_identifier:
1040
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0069fff8
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 23, 2021, 8:23 a.m.
process_identifier:
1040
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0069fffc
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 23, 2021, 8:23 a.m.
process_identifier:
1040
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x006a0000
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 23, 2021, 8:23 a.m.
process_identifier:
1040
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x006a0008
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 23, 2021, 8:23 a.m.
process_identifier:
1040
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x006a000c
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 23, 2021, 8:23 a.m.
process_identifier:
1040
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x006a0014
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 23, 2021, 8:23 a.m.
process_identifier:
1040
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x006a0018
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 23, 2021, 8:23 a.m.
process_identifier:
1040
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x006a001c
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 23, 2021, 8:23 a.m.
process_identifier:
1040
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x006a0024
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 23, 2021, 8:23 a.m.
process_identifier:
1040
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x006a0028
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 23, 2021, 8:23 a.m.
process_identifier:
1040
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x006a002c
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 23, 2021, 8:23 a.m.
process_identifier:
1040
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x006a0034
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 23, 2021, 8:23 a.m.
process_identifier:
1040
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x006a0038
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 23, 2021, 8:23 a.m.
process_identifier:
1040
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x006a003c
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 23, 2021, 8:23 a.m.
process_identifier:
1040
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x006a0044
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 23, 2021, 8:23 a.m.
process_identifier:
1040
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x006a0048
process_handle:
0xffffffff
3221225550
0