NtProtectVirtualMemory
Oct. 11, 2021, 9:55 a.m.
process_identifier:
1468
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00400000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 11, 2021, 9:55 a.m.
process_identifier:
1468
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
745472
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00401000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 11, 2021, 9:55 a.m.
process_identifier:
1468
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x004c4000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 11, 2021, 9:55 a.m.
process_identifier:
1468
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
73728
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x004c6000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 11, 2021, 9:55 a.m.
process_identifier:
1468
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x728b2000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 11, 2021, 9:55 a.m.
process_identifier:
1684
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x728b2000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Oct. 11, 2021, 9:55 a.m.
process_identifier:
1684
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00770000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Oct. 11, 2021, 10:04 a.m.
process_identifier:
2408
region_size:
14487552
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x03120000
allocation_type:
8192
(MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Oct. 11, 2021, 10:04 a.m.
process_identifier:
2408
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x03ef0000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 11, 2021, 10:04 a.m.
process_identifier:
2408
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x7560f000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 11, 2021, 10:04 a.m.
process_identifier:
2408
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x7560f000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 11, 2021, 10:04 a.m.
process_identifier:
2408
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x7560f000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 11, 2021, 10:04 a.m.
process_identifier:
2408
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x7560f000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 11, 2021, 10:04 a.m.
process_identifier:
2408
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x755dc000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 11, 2021, 10:04 a.m.
process_identifier:
2408
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x755fc000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 11, 2021, 10:04 a.m.
process_identifier:
2408
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x755dc000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 11, 2021, 10:04 a.m.
process_identifier:
2408
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x755fc000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 11, 2021, 10:04 a.m.
process_identifier:
2408
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73d53000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 11, 2021, 10:04 a.m.
process_identifier:
2408
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73df7000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 11, 2021, 10:04 a.m.
process_identifier:
2408
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x76809000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 11, 2021, 10:04 a.m.
process_identifier:
2408
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x756b2000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 11, 2021, 10:04 a.m.
process_identifier:
2408
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x755c2000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 11, 2021, 10:04 a.m.
process_identifier:
2408
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x7560f000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 11, 2021, 10:04 a.m.
process_identifier:
2408
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x7560f000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 11, 2021, 10:04 a.m.
process_identifier:
2408
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x7560f000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Oct. 11, 2021, 10:04 a.m.
process_identifier:
2408
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x035e0000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 11, 2021, 10:04 a.m.
process_identifier:
2408
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x728b2000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 11, 2021, 10:05 a.m.
process_identifier:
2408
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x743f1000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Oct. 11, 2021, 10:04 a.m.
process_identifier:
2656
region_size:
15142912
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02d80000
allocation_type:
8192
(MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Oct. 11, 2021, 10:04 a.m.
process_identifier:
2656
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x03bf0000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 11, 2021, 10:04 a.m.
process_identifier:
2656
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x7560f000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 11, 2021, 10:04 a.m.
process_identifier:
2656
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x7560f000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 11, 2021, 10:04 a.m.
process_identifier:
2656
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x7560f000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 11, 2021, 10:04 a.m.
process_identifier:
2656
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x7560f000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 11, 2021, 10:04 a.m.
process_identifier:
2656
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x755dc000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 11, 2021, 10:04 a.m.
process_identifier:
2656
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x755fc000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 11, 2021, 10:04 a.m.
process_identifier:
2656
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x755dc000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 11, 2021, 10:04 a.m.
process_identifier:
2656
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x755fc000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 11, 2021, 10:04 a.m.
process_identifier:
2656
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73d53000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 11, 2021, 10:04 a.m.
process_identifier:
2656
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73df7000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 11, 2021, 10:04 a.m.
process_identifier:
2656
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x76809000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 11, 2021, 10:04 a.m.
process_identifier:
2656
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x756b2000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 11, 2021, 10:04 a.m.
process_identifier:
2656
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x755c2000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 11, 2021, 10:04 a.m.
process_identifier:
2656
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x755c7000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 11, 2021, 10:04 a.m.
process_identifier:
2656
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x755df000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 11, 2021, 10:04 a.m.
process_identifier:
2656
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x755c6000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 11, 2021, 10:04 a.m.
process_identifier:
2656
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x75733000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 11, 2021, 10:04 a.m.
process_identifier:
2656
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x773fd000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 11, 2021, 10:04 a.m.
process_identifier:
2656
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x75737000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 11, 2021, 10:04 a.m.
process_identifier:
2656
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x755b8000
process_handle:
0xffffffff
1
0
0