NtProtectVirtualMemory
Oct. 23, 2021, 10:21 a.m.
process_identifier:
2364
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6aa06000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 23, 2021, 10:21 a.m.
process_identifier:
2364
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6a9eb000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 23, 2021, 10:21 a.m.
process_identifier:
2364
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6a9f7000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 23, 2021, 10:21 a.m.
process_identifier:
2364
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6a9db000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 23, 2021, 10:21 a.m.
process_identifier:
2364
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6a9d6000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 23, 2021, 10:21 a.m.
process_identifier:
2364
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6aa1b000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 23, 2021, 10:21 a.m.
process_identifier:
2364
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6a9b7000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 23, 2021, 10:21 a.m.
process_identifier:
2364
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6a9fb000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 23, 2021, 10:21 a.m.
process_identifier:
2364
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6aa22000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 23, 2021, 10:21 a.m.
process_identifier:
2364
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6aa0b000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 23, 2021, 10:21 a.m.
process_identifier:
2364
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6aa06000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 23, 2021, 10:21 a.m.
process_identifier:
2364
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6a9eb000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 23, 2021, 10:21 a.m.
process_identifier:
2364
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6a9f7000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 23, 2021, 10:21 a.m.
process_identifier:
2364
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6a9db000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 23, 2021, 10:21 a.m.
process_identifier:
2364
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6a9d6000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 23, 2021, 10:21 a.m.
process_identifier:
2364
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6aa1b000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 23, 2021, 10:21 a.m.
process_identifier:
2364
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6a9b7000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 23, 2021, 10:21 a.m.
process_identifier:
2364
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6a9fb000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 23, 2021, 10:21 a.m.
process_identifier:
2364
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6a46e000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 23, 2021, 10:21 a.m.
process_identifier:
2364
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04c56000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 23, 2021, 10:21 a.m.
process_identifier:
2364
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04c56000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 23, 2021, 10:21 a.m.
process_identifier:
2364
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04c56000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 23, 2021, 10:21 a.m.
process_identifier:
2364
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04c56000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 23, 2021, 10:21 a.m.
process_identifier:
2364
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04c53000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 23, 2021, 10:21 a.m.
process_identifier:
2364
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04c56000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 23, 2021, 10:21 a.m.
process_identifier:
2364
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04c56000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 23, 2021, 10:21 a.m.
process_identifier:
2364
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04c53000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 23, 2021, 10:21 a.m.
process_identifier:
2648
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02510000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 23, 2021, 10:21 a.m.
process_identifier:
2648
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02510000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 23, 2021, 10:21 a.m.
process_identifier:
2648
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02511000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 23, 2021, 10:21 a.m.
process_identifier:
2648
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02511000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 23, 2021, 10:21 a.m.
process_identifier:
2648
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02511000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 23, 2021, 10:21 a.m.
process_identifier:
2648
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02511000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 23, 2021, 10:21 a.m.
process_identifier:
2648
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02511000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 23, 2021, 10:21 a.m.
process_identifier:
2648
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02511000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 23, 2021, 10:21 a.m.
process_identifier:
2648
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02511000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 23, 2021, 10:21 a.m.
process_identifier:
2648
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02511000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 23, 2021, 10:21 a.m.
process_identifier:
2648
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02512000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 23, 2021, 10:21 a.m.
process_identifier:
2648
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02512000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 23, 2021, 10:21 a.m.
process_identifier:
2648
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02512000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Oct. 23, 2021, 10:21 a.m.
process_identifier:
2648
region_size:
1441792
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04580000
allocation_type:
8192
(MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Oct. 23, 2021, 10:21 a.m.
process_identifier:
2648
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x046a0000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 23, 2021, 10:21 a.m.
process_identifier:
2648
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02512000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 23, 2021, 10:21 a.m.
process_identifier:
2648
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02512000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 23, 2021, 10:21 a.m.
process_identifier:
2648
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02513000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 23, 2021, 10:21 a.m.
process_identifier:
3024
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fef2ad2000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Oct. 23, 2021, 10:21 a.m.
process_identifier:
3024
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007feff150000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Oct. 23, 2021, 10:21 a.m.
process_identifier:
3024
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fefa871000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Oct. 23, 2021, 10:21 a.m.
process_identifier:
3024
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fef3287000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Oct. 23, 2021, 10:21 a.m.
process_identifier:
3024
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007feff30d000
process_handle:
0xffffffffffffffff
1
0
0