NtAllocateVirtualMemory
Sept. 28, 2021, 1:45 p.m.
process_identifier:
2236
region_size:
1572864
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00760000
allocation_type:
8192
(MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 28, 2021, 1:45 p.m.
process_identifier:
2236
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x008a0000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Sept. 28, 2021, 1:45 p.m.
process_identifier:
2236
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x731a1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Sept. 28, 2021, 1:45 p.m.
process_identifier:
2236
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x731a2000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 28, 2021, 1:45 p.m.
process_identifier:
2236
region_size:
2162688
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00c00000
allocation_type:
8192
(MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 28, 2021, 1:45 p.m.
process_identifier:
2236
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00dd0000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 28, 2021, 1:45 p.m.
process_identifier:
2236
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00552000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 28, 2021, 1:45 p.m.
process_identifier:
2236
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00585000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 28, 2021, 1:45 p.m.
process_identifier:
2236
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0058b000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 28, 2021, 1:45 p.m.
process_identifier:
2236
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00587000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 28, 2021, 1:45 p.m.
process_identifier:
2236
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0056c000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 28, 2021, 1:45 p.m.
process_identifier:
2236
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00770000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 28, 2021, 1:45 p.m.
process_identifier:
2236
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0055a000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 28, 2021, 1:45 p.m.
process_identifier:
2236
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0057a000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 28, 2021, 1:45 p.m.
process_identifier:
2236
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00577000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 28, 2021, 1:45 p.m.
process_identifier:
2236
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00576000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 28, 2021, 1:45 p.m.
process_identifier:
2236
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0057b000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 28, 2021, 1:45 p.m.
process_identifier:
2236
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0056a000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 28, 2021, 1:45 p.m.
process_identifier:
2236
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0055c000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 28, 2021, 1:45 p.m.
process_identifier:
2236
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00771000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Sept. 28, 2021, 1:45 p.m.
process_identifier:
2236
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
63488
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x05290400
process_handle:
0xffffffff
3221225550
0
NtAllocateVirtualMemory
Sept. 28, 2021, 1:45 p.m.
process_identifier:
2236
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00772000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Sept. 28, 2021, 1:45 p.m.
process_identifier:
2236
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x05290178
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 28, 2021, 1:45 p.m.
process_identifier:
2236
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x052901a0
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 28, 2021, 1:45 p.m.
process_identifier:
2236
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x052901c8
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 28, 2021, 1:45 p.m.
process_identifier:
2236
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x052901f0
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 28, 2021, 1:45 p.m.
process_identifier:
2236
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x05290218
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 28, 2021, 1:45 p.m.
process_identifier:
2236
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
11
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0529ffae
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 28, 2021, 1:45 p.m.
process_identifier:
2236
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
11
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0529ffa2
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 28, 2021, 1:45 p.m.
process_identifier:
2236
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
72
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0529fc00
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 28, 2021, 1:45 p.m.
process_identifier:
2236
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0529ffbc
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 28, 2021, 1:45 p.m.
process_identifier:
2236
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0529ffe0
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 28, 2021, 1:45 p.m.
process_identifier:
2236
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0529ffe8
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 28, 2021, 1:45 p.m.
process_identifier:
2236
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0529ffec
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 28, 2021, 1:45 p.m.
process_identifier:
2236
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0529fff4
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 28, 2021, 1:45 p.m.
process_identifier:
2236
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0529fff8
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 28, 2021, 1:45 p.m.
process_identifier:
2236
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0529fffc
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 28, 2021, 1:45 p.m.
process_identifier:
2236
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x052a0000
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 28, 2021, 1:45 p.m.
process_identifier:
2236
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x052a0008
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 28, 2021, 1:45 p.m.
process_identifier:
2236
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x052a000c
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 28, 2021, 1:45 p.m.
process_identifier:
2236
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x052a0014
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 28, 2021, 1:45 p.m.
process_identifier:
2236
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x052a0018
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 28, 2021, 1:45 p.m.
process_identifier:
2236
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x052a001c
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 28, 2021, 1:45 p.m.
process_identifier:
2236
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x052a0024
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 28, 2021, 1:45 p.m.
process_identifier:
2236
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x052a0028
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 28, 2021, 1:45 p.m.
process_identifier:
2236
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x052a002c
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 28, 2021, 1:45 p.m.
process_identifier:
2236
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x052a0034
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 28, 2021, 1:45 p.m.
process_identifier:
2236
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x052a0038
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 28, 2021, 1:45 p.m.
process_identifier:
2236
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x052a003c
process_handle:
0xffffffff
3221225550
0
NtProtectVirtualMemory
Sept. 28, 2021, 1:45 p.m.
process_identifier:
2236
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x052a0044
process_handle:
0xffffffff
3221225550
0