NtProtectVirtualMemory
Sept. 25, 2021, 10:33 a.m.
process_identifier:
1896
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6a85d000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Sept. 25, 2021, 10:33 a.m.
process_identifier:
1896
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6a216000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Sept. 25, 2021, 10:33 a.m.
process_identifier:
1896
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6a114000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Sept. 25, 2021, 10:33 a.m.
process_identifier:
1896
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6a0d1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Sept. 25, 2021, 10:33 a.m.
process_identifier:
1896
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6a042000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Sept. 25, 2021, 10:33 a.m.
process_identifier:
1896
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x69cd1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Sept. 25, 2021, 10:33 a.m.
process_identifier:
292
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00d61000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 25, 2021, 10:33 a.m.
process_identifier:
292
region_size:
40960
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00350000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Sept. 25, 2021, 10:33 a.m.
process_identifier:
292
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6fb2f000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 25, 2021, 10:33 a.m.
process_identifier:
292
region_size:
65536
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x35180000
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Sept. 25, 2021, 10:33 a.m.
process_identifier:
292
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x75180000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Sept. 25, 2021, 10:33 a.m.
process_identifier:
292
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
65536
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x35180000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Sept. 25, 2021, 10:33 a.m.
process_identifier:
292
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x75179000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Sept. 25, 2021, 10:33 a.m.
process_identifier:
292
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
65536
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x35180000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Sept. 25, 2021, 10:33 a.m.
process_identifier:
292
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x75181000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Sept. 25, 2021, 10:33 a.m.
process_identifier:
292
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x75187000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Sept. 25, 2021, 10:33 a.m.
process_identifier:
292
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6af44000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Sept. 25, 2021, 10:33 a.m.
process_identifier:
292
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x738ba000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Sept. 25, 2021, 10:33 a.m.
process_identifier:
292
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6a216000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Sept. 25, 2021, 10:33 a.m.
process_identifier:
292
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6a042000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Sept. 25, 2021, 10:33 a.m.
process_identifier:
292
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x694a1000
process_handle:
0xffffffff
1
0
0