NtAllocateVirtualMemory
Oct. 23, 2021, 10:01 a.m.
process_identifier:
2504
region_size:
1310720
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00750000
allocation_type:
8192
(MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Oct. 23, 2021, 10:01 a.m.
process_identifier:
2504
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00850000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 23, 2021, 10:01 a.m.
process_identifier:
2504
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73bd1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 23, 2021, 10:01 a.m.
process_identifier:
2504
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73bd2000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Oct. 23, 2021, 10:01 a.m.
process_identifier:
2504
region_size:
524288
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00540000
allocation_type:
8192
(MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Oct. 23, 2021, 10:01 a.m.
process_identifier:
2504
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00580000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Oct. 23, 2021, 10:01 a.m.
process_identifier:
2504
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x003e2000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Oct. 23, 2021, 10:01 a.m.
process_identifier:
2504
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x003fc000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Oct. 23, 2021, 10:01 a.m.
process_identifier:
2504
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00820000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Oct. 23, 2021, 10:01 a.m.
process_identifier:
2504
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00821000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Oct. 23, 2021, 10:01 a.m.
process_identifier:
2504
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00822000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Oct. 23, 2021, 10:01 a.m.
process_identifier:
2504
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00823000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Oct. 23, 2021, 10:01 a.m.
process_identifier:
2504
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00824000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Oct. 23, 2021, 10:01 a.m.
process_identifier:
2504
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00825000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Oct. 23, 2021, 10:01 a.m.
process_identifier:
2504
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00826000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Oct. 23, 2021, 10:01 a.m.
process_identifier:
2504
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x003ea000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Oct. 23, 2021, 10:01 a.m.
process_identifier:
2504
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0051b000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Oct. 23, 2021, 10:01 a.m.
process_identifier:
2504
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00517000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 23, 2021, 10:01 a.m.
process_identifier:
2504
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x003bc000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 23, 2021, 10:01 a.m.
process_identifier:
2504
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x003bc000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 23, 2021, 10:01 a.m.
process_identifier:
2504
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00310000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 23, 2021, 10:01 a.m.
process_identifier:
2504
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00310000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 23, 2021, 10:01 a.m.
process_identifier:
2504
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00310000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 23, 2021, 10:01 a.m.
process_identifier:
2504
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00312000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 23, 2021, 10:01 a.m.
process_identifier:
2504
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x003a7000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 23, 2021, 10:01 a.m.
process_identifier:
2504
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x003a7000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 23, 2021, 10:01 a.m.
process_identifier:
2504
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x003a7000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 23, 2021, 10:01 a.m.
process_identifier:
2504
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x003a7000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 23, 2021, 10:01 a.m.
process_identifier:
2504
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x003a7000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 23, 2021, 10:01 a.m.
process_identifier:
2504
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x003a7000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 23, 2021, 10:01 a.m.
process_identifier:
2504
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x003a7000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 23, 2021, 10:01 a.m.
process_identifier:
2504
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x003a7000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 23, 2021, 10:01 a.m.
process_identifier:
2504
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x003a7000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 23, 2021, 10:01 a.m.
process_identifier:
2504
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x003a7000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 23, 2021, 10:01 a.m.
process_identifier:
2504
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x003a7000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 23, 2021, 10:01 a.m.
process_identifier:
2504
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x003a7000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 23, 2021, 10:01 a.m.
process_identifier:
2504
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x003a7000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 23, 2021, 10:01 a.m.
process_identifier:
2504
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x003a7000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 23, 2021, 10:01 a.m.
process_identifier:
2504
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x003a7000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 23, 2021, 10:01 a.m.
process_identifier:
2504
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x003a7000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 23, 2021, 10:01 a.m.
process_identifier:
2504
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x003a7000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 23, 2021, 10:01 a.m.
process_identifier:
2504
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x003a7000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 23, 2021, 10:01 a.m.
process_identifier:
2504
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x003a7000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 23, 2021, 10:01 a.m.
process_identifier:
2504
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x003a7000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 23, 2021, 10:01 a.m.
process_identifier:
2504
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x003a7000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 23, 2021, 10:01 a.m.
process_identifier:
2504
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x003a7000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 23, 2021, 10:01 a.m.
process_identifier:
2504
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x003a7000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 23, 2021, 10:01 a.m.
process_identifier:
2504
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x003a7000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 23, 2021, 10:01 a.m.
process_identifier:
2504
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x003a7000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 23, 2021, 10:01 a.m.
process_identifier:
2504
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x003a7000
process_handle:
0xffffffff
1
0
0