NtAllocateVirtualMemory
Oct. 7, 2021, 5:27 p.m.
process_identifier:
2384
region_size:
11931648
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00000000029b0000
allocation_type:
8192
(MEM_RESERVE)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
Oct. 7, 2021, 5:27 p.m.
process_identifier:
2384
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0000000003510000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Oct. 7, 2021, 5:27 p.m.
process_identifier:
2384
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0000000077131000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Oct. 7, 2021, 5:27 p.m.
process_identifier:
2384
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0000000077131000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Oct. 7, 2021, 5:27 p.m.
process_identifier:
2384
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0000000077131000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Oct. 7, 2021, 5:27 p.m.
process_identifier:
2384
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0000000077131000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Oct. 7, 2021, 5:27 p.m.
process_identifier:
2384
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0000000077131000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Oct. 7, 2021, 5:27 p.m.
process_identifier:
2384
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0000000077131000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Oct. 7, 2021, 5:27 p.m.
process_identifier:
2384
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00000000770dd000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Oct. 7, 2021, 5:27 p.m.
process_identifier:
2384
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0000000077102000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Oct. 7, 2021, 5:27 p.m.
process_identifier:
2384
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00000000770e4000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Oct. 7, 2021, 5:27 p.m.
process_identifier:
2384
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0000000077102000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Oct. 7, 2021, 5:27 p.m.
process_identifier:
2384
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fefc135000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Oct. 7, 2021, 5:27 p.m.
process_identifier:
2384
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fefc135000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Oct. 7, 2021, 5:27 p.m.
process_identifier:
2384
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fefdda4000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Oct. 7, 2021, 5:27 p.m.
process_identifier:
2384
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fefda01000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Oct. 7, 2021, 5:27 p.m.
process_identifier:
2384
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00000000770ca000
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
Oct. 7, 2021, 5:27 p.m.
process_identifier:
2384
region_size:
65536
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0000000002df0000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Oct. 7, 2021, 5:27 p.m.
process_identifier:
2384
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00000000735bc000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Oct. 7, 2021, 5:28 p.m.
process_identifier:
2384
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0000000074403000
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
Oct. 7, 2021, 5:27 p.m.
process_identifier:
1332
region_size:
3608576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0000000003130000
allocation_type:
8192
(MEM_RESERVE)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
Oct. 7, 2021, 5:27 p.m.
process_identifier:
1332
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00000000034a0000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Oct. 7, 2021, 5:27 p.m.
process_identifier:
1332
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0000000077131000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Oct. 7, 2021, 5:27 p.m.
process_identifier:
1332
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0000000077131000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Oct. 7, 2021, 5:27 p.m.
process_identifier:
1332
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0000000077131000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Oct. 7, 2021, 5:27 p.m.
process_identifier:
1332
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0000000077131000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Oct. 7, 2021, 5:27 p.m.
process_identifier:
1332
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0000000077131000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Oct. 7, 2021, 5:27 p.m.
process_identifier:
1332
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0000000077131000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Oct. 7, 2021, 5:27 p.m.
process_identifier:
1332
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00000000770dd000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Oct. 7, 2021, 5:27 p.m.
process_identifier:
1332
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0000000077102000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Oct. 7, 2021, 5:27 p.m.
process_identifier:
1332
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00000000770e4000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Oct. 7, 2021, 5:27 p.m.
process_identifier:
1332
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0000000077102000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Oct. 7, 2021, 5:27 p.m.
process_identifier:
1332
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fefc135000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Oct. 7, 2021, 5:27 p.m.
process_identifier:
1332
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fefc135000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Oct. 7, 2021, 5:27 p.m.
process_identifier:
1332
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fefdda4000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Oct. 7, 2021, 5:27 p.m.
process_identifier:
1332
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fefda01000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Oct. 7, 2021, 5:27 p.m.
process_identifier:
1332
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00000000770ca000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Oct. 7, 2021, 5:27 p.m.
process_identifier:
1332
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00000000770cf000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Oct. 7, 2021, 5:27 p.m.
process_identifier:
1332
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00000000770cd000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Oct. 7, 2021, 5:27 p.m.
process_identifier:
1332
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00000000770cb000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Oct. 7, 2021, 5:27 p.m.
process_identifier:
1332
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0000000076e56000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Oct. 7, 2021, 5:27 p.m.
process_identifier:
1332
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0000000077206000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Oct. 7, 2021, 5:27 p.m.
process_identifier:
1332
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0000000076e51000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Oct. 7, 2021, 5:27 p.m.
process_identifier:
1332
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00000000770d0000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Oct. 7, 2021, 5:27 p.m.
process_identifier:
1332
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00000000770ca000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Oct. 7, 2021, 5:27 p.m.
process_identifier:
1332
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00000000771df000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Oct. 7, 2021, 5:27 p.m.
process_identifier:
1332
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00000000771eb000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Oct. 7, 2021, 5:27 p.m.
process_identifier:
1332
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007feff3d7000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Oct. 7, 2021, 5:27 p.m.
process_identifier:
1332
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fefdd44000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Oct. 7, 2021, 5:27 p.m.
process_identifier:
1332
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fefdd41000
process_handle:
0xffffffffffffffff
1
0
0