NtProtectVirtualMemory
Oct. 21, 2021, 6:25 p.m.
process_identifier:
2280
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6aa06000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 21, 2021, 6:25 p.m.
process_identifier:
2280
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6a9eb000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 21, 2021, 6:25 p.m.
process_identifier:
2280
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6a9f7000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 21, 2021, 6:25 p.m.
process_identifier:
2280
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6a9db000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 21, 2021, 6:25 p.m.
process_identifier:
2280
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6a9d6000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 21, 2021, 6:25 p.m.
process_identifier:
2280
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6aa1b000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 21, 2021, 6:25 p.m.
process_identifier:
2280
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6a9b7000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 21, 2021, 6:25 p.m.
process_identifier:
2280
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6a9fb000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 21, 2021, 6:25 p.m.
process_identifier:
2280
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6aa22000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 21, 2021, 6:25 p.m.
process_identifier:
2280
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6aa0b000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 21, 2021, 6:25 p.m.
process_identifier:
2280
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6aa06000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 21, 2021, 6:25 p.m.
process_identifier:
2280
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6a9eb000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 21, 2021, 6:25 p.m.
process_identifier:
2280
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6a9f7000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 21, 2021, 6:25 p.m.
process_identifier:
2280
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6a9db000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 21, 2021, 6:25 p.m.
process_identifier:
2280
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6a9d6000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 21, 2021, 6:25 p.m.
process_identifier:
2280
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6aa1b000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 21, 2021, 6:25 p.m.
process_identifier:
2280
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6a9b7000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 21, 2021, 6:25 p.m.
process_identifier:
2280
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6a9fb000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 21, 2021, 6:25 p.m.
process_identifier:
2280
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6a46e000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 21, 2021, 6:25 p.m.
process_identifier:
2280
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04d66000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 21, 2021, 6:25 p.m.
process_identifier:
2280
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04d66000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 21, 2021, 6:25 p.m.
process_identifier:
2280
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04d66000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 21, 2021, 6:25 p.m.
process_identifier:
2280
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04d66000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 21, 2021, 6:25 p.m.
process_identifier:
2280
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x03a99000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 21, 2021, 6:25 p.m.
process_identifier:
2280
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04d66000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 21, 2021, 6:25 p.m.
process_identifier:
2280
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04d66000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 21, 2021, 6:25 p.m.
process_identifier:
2280
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x03a99000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 21, 2021, 6:25 p.m.
process_identifier:
2612
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02830000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 21, 2021, 6:25 p.m.
process_identifier:
2612
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02831000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 21, 2021, 6:25 p.m.
process_identifier:
2612
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02831000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 21, 2021, 6:25 p.m.
process_identifier:
2612
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02831000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 21, 2021, 6:25 p.m.
process_identifier:
2612
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02831000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 21, 2021, 6:25 p.m.
process_identifier:
2612
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02831000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 21, 2021, 6:25 p.m.
process_identifier:
2612
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02831000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 21, 2021, 6:25 p.m.
process_identifier:
2612
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02831000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 21, 2021, 6:25 p.m.
process_identifier:
2612
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02831000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 21, 2021, 6:25 p.m.
process_identifier:
2612
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02831000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 21, 2021, 6:25 p.m.
process_identifier:
2612
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02832000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 21, 2021, 6:25 p.m.
process_identifier:
2612
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02832000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 21, 2021, 6:25 p.m.
process_identifier:
2612
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02832000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Oct. 21, 2021, 6:25 p.m.
process_identifier:
2612
region_size:
655360
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x03ae0000
allocation_type:
8192
(MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Oct. 21, 2021, 6:25 p.m.
process_identifier:
2612
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x03b40000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 21, 2021, 6:25 p.m.
process_identifier:
2612
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02832000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 21, 2021, 6:25 p.m.
process_identifier:
2612
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02833000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 21, 2021, 6:25 p.m.
process_identifier:
2612
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02833000
process_handle:
0xffffffff
1
0
0