NtAllocateVirtualMemory
Oct. 15, 2021, 9:38 a.m.
process_identifier:
1196
region_size:
1441792
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00670000
allocation_type:
8192
(MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Oct. 15, 2021, 9:38 a.m.
process_identifier:
1196
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00790000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 15, 2021, 9:38 a.m.
process_identifier:
1196
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x731a1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 15, 2021, 9:38 a.m.
process_identifier:
1196
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x731a2000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Oct. 15, 2021, 9:38 a.m.
process_identifier:
1196
region_size:
1835008
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02280000
allocation_type:
8192
(MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Oct. 15, 2021, 9:38 a.m.
process_identifier:
1196
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02400000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Oct. 15, 2021, 9:38 a.m.
process_identifier:
1196
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00342000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Oct. 15, 2021, 9:38 a.m.
process_identifier:
1196
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0035c000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Oct. 15, 2021, 9:38 a.m.
process_identifier:
1196
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00560000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Oct. 15, 2021, 9:38 a.m.
process_identifier:
1196
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00375000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Oct. 15, 2021, 9:38 a.m.
process_identifier:
1196
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0037b000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Oct. 15, 2021, 9:38 a.m.
process_identifier:
1196
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00377000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Oct. 15, 2021, 9:38 a.m.
process_identifier:
1196
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0034a000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Oct. 15, 2021, 9:38 a.m.
process_identifier:
1196
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0036a000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Oct. 15, 2021, 9:38 a.m.
process_identifier:
1196
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00367000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Oct. 15, 2021, 9:38 a.m.
process_identifier:
1196
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00366000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Oct. 15, 2021, 9:38 a.m.
process_identifier:
1196
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0036b000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Oct. 15, 2021, 9:38 a.m.
process_identifier:
1196
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0035a000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Oct. 15, 2021, 9:38 a.m.
process_identifier:
1196
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00561000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Oct. 15, 2021, 9:38 a.m.
process_identifier:
1196
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00562000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 15, 2021, 9:38 a.m.
process_identifier:
1196
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x001c0000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 15, 2021, 9:38 a.m.
process_identifier:
1196
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x001c0000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 15, 2021, 9:38 a.m.
process_identifier:
1196
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x001c0000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 15, 2021, 9:38 a.m.
process_identifier:
1196
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x001c0000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 15, 2021, 9:38 a.m.
process_identifier:
1196
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x001c0000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 15, 2021, 9:38 a.m.
process_identifier:
1196
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x001c0000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 15, 2021, 9:38 a.m.
process_identifier:
1196
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x001c0000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 15, 2021, 9:38 a.m.
process_identifier:
1196
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x001c0000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 15, 2021, 9:38 a.m.
process_identifier:
1196
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x001c0000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 15, 2021, 9:38 a.m.
process_identifier:
1196
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x001c0000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 15, 2021, 9:38 a.m.
process_identifier:
1196
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x001c0000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 15, 2021, 9:38 a.m.
process_identifier:
1196
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x001c0000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 15, 2021, 9:38 a.m.
process_identifier:
1196
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x001c0000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 15, 2021, 9:38 a.m.
process_identifier:
1196
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x001c0000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 15, 2021, 9:38 a.m.
process_identifier:
1196
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x001c0000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 15, 2021, 9:38 a.m.
process_identifier:
1196
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x001c0000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 15, 2021, 9:38 a.m.
process_identifier:
1196
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x001c0000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 15, 2021, 9:38 a.m.
process_identifier:
1196
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x001c0000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 15, 2021, 9:38 a.m.
process_identifier:
1196
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x001c0000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 15, 2021, 9:38 a.m.
process_identifier:
1196
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x001c0000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 15, 2021, 9:38 a.m.
process_identifier:
1196
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x001c0000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 15, 2021, 9:38 a.m.
process_identifier:
1196
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x001c0000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 15, 2021, 9:38 a.m.
process_identifier:
1196
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x001c0000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 15, 2021, 9:38 a.m.
process_identifier:
1196
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x001c0000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 15, 2021, 9:38 a.m.
process_identifier:
1196
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x001c0000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 15, 2021, 9:38 a.m.
process_identifier:
1196
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x001c0000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 15, 2021, 9:38 a.m.
process_identifier:
1196
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x001c0000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 15, 2021, 9:38 a.m.
process_identifier:
1196
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x001c0000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 15, 2021, 9:38 a.m.
process_identifier:
1196
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x001c0000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 15, 2021, 9:38 a.m.
process_identifier:
1196
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x001c0000
process_handle:
0xffffffff
1
0
0