NtProtectVirtualMemory
Oct. 14, 2021, 6 p.m.
process_identifier:
2336
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
163840
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02300000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 14, 2021, 6 p.m.
process_identifier:
2336
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02328000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 14, 2021, 6 p.m.
process_identifier:
2336
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02330000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 14, 2021, 6 p.m.
process_identifier:
2336
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02338000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 14, 2021, 6 p.m.
process_identifier:
2336
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02340000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 14, 2021, 6 p.m.
process_identifier:
2336
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02348000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 14, 2021, 6 p.m.
process_identifier:
2336
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02350000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 14, 2021, 6 p.m.
process_identifier:
2336
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02358000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 14, 2021, 6 p.m.
process_identifier:
2336
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02360000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 14, 2021, 6 p.m.
process_identifier:
2336
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02368000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 14, 2021, 6 p.m.
process_identifier:
2336
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02370000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 14, 2021, 6 p.m.
process_identifier:
2336
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02378000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 14, 2021, 6 p.m.
process_identifier:
2336
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02380000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 14, 2021, 6 p.m.
process_identifier:
2336
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02388000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 14, 2021, 6 p.m.
process_identifier:
2336
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02390000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 14, 2021, 6 p.m.
process_identifier:
2336
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02398000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 14, 2021, 6 p.m.
process_identifier:
2336
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x023a0000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 14, 2021, 6 p.m.
process_identifier:
2336
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x023a8000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 14, 2021, 6 p.m.
process_identifier:
2336
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x023b0000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 14, 2021, 6 p.m.
process_identifier:
2336
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x023b8000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 14, 2021, 6 p.m.
process_identifier:
2336
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x023c0000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 14, 2021, 6 p.m.
process_identifier:
2336
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x023c8000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 14, 2021, 6 p.m.
process_identifier:
2336
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x023d0000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 14, 2021, 6 p.m.
process_identifier:
2336
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x023d8000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 14, 2021, 6 p.m.
process_identifier:
2336
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x023e0000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 14, 2021, 6 p.m.
process_identifier:
2336
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x023e8000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 14, 2021, 6 p.m.
process_identifier:
2336
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x023f0000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 14, 2021, 6 p.m.
process_identifier:
2336
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x023f8000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 14, 2021, 6 p.m.
process_identifier:
2336
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02400000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 14, 2021, 6 p.m.
process_identifier:
2336
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02408000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 14, 2021, 6 p.m.
process_identifier:
2336
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02410000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 14, 2021, 6 p.m.
process_identifier:
2336
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02418000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 14, 2021, 6 p.m.
process_identifier:
2336
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02420000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 14, 2021, 6 p.m.
process_identifier:
2336
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02428000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 14, 2021, 6 p.m.
process_identifier:
2336
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02430000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 14, 2021, 6 p.m.
process_identifier:
2336
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02438000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 14, 2021, 6 p.m.
process_identifier:
2336
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02440000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 14, 2021, 6 p.m.
process_identifier:
2336
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02448000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 14, 2021, 6 p.m.
process_identifier:
2336
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02450000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 14, 2021, 6 p.m.
process_identifier:
2336
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02458000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 14, 2021, 6 p.m.
process_identifier:
2748
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
163840
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02410000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 14, 2021, 6 p.m.
process_identifier:
2748
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02438000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 14, 2021, 6 p.m.
process_identifier:
2748
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02440000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 14, 2021, 6 p.m.
process_identifier:
2748
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02448000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 14, 2021, 6 p.m.
process_identifier:
2748
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02450000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 14, 2021, 6 p.m.
process_identifier:
2748
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02458000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 14, 2021, 6 p.m.
process_identifier:
2748
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02460000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 14, 2021, 6 p.m.
process_identifier:
2748
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02468000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 14, 2021, 6 p.m.
process_identifier:
2748
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02470000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 14, 2021, 6 p.m.
process_identifier:
2748
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02478000
process_handle:
0xffffffff
1
0
0