NtAllocateVirtualMemory
Nov. 1, 2021, 6:19 p.m.
process_identifier:
2420
region_size:
2424832
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0000000000750000
allocation_type:
8192
(MEM_RESERVE)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
Nov. 1, 2021, 6:19 p.m.
process_identifier:
2420
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0000000000920000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Nov. 1, 2021, 6:19 p.m.
process_identifier:
2420
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fef0451000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Nov. 1, 2021, 6:19 p.m.
process_identifier:
2420
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fef0aeb000
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
Nov. 1, 2021, 6:19 p.m.
process_identifier:
2420
region_size:
589824
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0000000000510000
allocation_type:
8192
(MEM_RESERVE)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
Nov. 1, 2021, 6:19 p.m.
process_identifier:
2420
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0000000000520000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Nov. 1, 2021, 6:19 p.m.
process_identifier:
2420
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fef0452000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Nov. 1, 2021, 6:19 p.m.
process_identifier:
2420
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fef0452000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Nov. 1, 2021, 6:19 p.m.
process_identifier:
2420
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fef0452000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Nov. 1, 2021, 6:19 p.m.
process_identifier:
2420
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fef0452000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Nov. 1, 2021, 6:19 p.m.
process_identifier:
2420
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fef0452000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Nov. 1, 2021, 6:19 p.m.
process_identifier:
2420
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fef0452000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Nov. 1, 2021, 6:19 p.m.
process_identifier:
2420
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fef0452000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Nov. 1, 2021, 6:19 p.m.
process_identifier:
2420
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fef0452000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Nov. 1, 2021, 6:19 p.m.
process_identifier:
2420
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fef0452000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Nov. 1, 2021, 6:19 p.m.
process_identifier:
2420
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fef0452000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Nov. 1, 2021, 6:19 p.m.
process_identifier:
2420
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fef0452000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Nov. 1, 2021, 6:19 p.m.
process_identifier:
2420
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fef0454000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Nov. 1, 2021, 6:19 p.m.
process_identifier:
2420
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fef0454000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Nov. 1, 2021, 6:19 p.m.
process_identifier:
2420
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fef0454000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Nov. 1, 2021, 6:19 p.m.
process_identifier:
2420
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fef0454000
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
Nov. 1, 2021, 6:19 p.m.
process_identifier:
2420
region_size:
655360
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fffff10000
allocation_type:
1056768
(MEM_RESERVE|MEM_TOP_DOWN)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
Nov. 1, 2021, 6:19 p.m.
process_identifier:
2420
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fffff10000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
Nov. 1, 2021, 6:19 p.m.
process_identifier:
2420
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fffff10000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
Nov. 1, 2021, 6:19 p.m.
process_identifier:
2420
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fffff20000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
Nov. 1, 2021, 6:19 p.m.
process_identifier:
2420
region_size:
65536
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fffff00000
allocation_type:
1056768
(MEM_RESERVE|MEM_TOP_DOWN)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
Nov. 1, 2021, 6:19 p.m.
process_identifier:
2420
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fffff00000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
Nov. 1, 2021, 6:19 p.m.
process_identifier:
2420
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fe90cba000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
Nov. 1, 2021, 6:19 p.m.
process_identifier:
2420
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fe90d6c000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
Nov. 1, 2021, 6:19 p.m.
process_identifier:
2420
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fe90d96000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
Nov. 1, 2021, 6:19 p.m.
process_identifier:
2420
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fe90d70000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
Nov. 1, 2021, 6:19 p.m.
process_identifier:
2420
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fe90ccc000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
Nov. 1, 2021, 6:19 p.m.
process_identifier:
2420
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fe90ccd000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
Nov. 1, 2021, 6:19 p.m.
process_identifier:
2420
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fe90cce000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
Nov. 1, 2021, 6:19 p.m.
process_identifier:
2420
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fe90ccf000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
Nov. 1, 2021, 6:19 p.m.
process_identifier:
2420
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fe90e00000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
Nov. 1, 2021, 6:19 p.m.
process_identifier:
2420
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fe90e01000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
Nov. 1, 2021, 6:19 p.m.
process_identifier:
2420
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fe90e02000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
Nov. 1, 2021, 6:19 p.m.
process_identifier:
2420
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fe90e03000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
Nov. 1, 2021, 6:19 p.m.
process_identifier:
2420
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fe90e04000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
Nov. 1, 2021, 6:19 p.m.
process_identifier:
2420
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fe90e05000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
Nov. 1, 2021, 6:19 p.m.
process_identifier:
2420
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fe90e06000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
Nov. 1, 2021, 6:19 p.m.
process_identifier:
2420
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fe90e07000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
Nov. 1, 2021, 6:19 p.m.
process_identifier:
2420
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fe90e08000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
Nov. 1, 2021, 6:19 p.m.
process_identifier:
2420
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fe90e09000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
Nov. 1, 2021, 6:19 p.m.
process_identifier:
2420
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fe90e0a000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
Nov. 1, 2021, 6:19 p.m.
process_identifier:
2420
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fe90e0b000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
Nov. 1, 2021, 6:19 p.m.
process_identifier:
2420
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fe90e0c000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
Nov. 1, 2021, 6:19 p.m.
process_identifier:
2420
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fe90e0d000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
Nov. 1, 2021, 6:19 p.m.
process_identifier:
2420
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fe90e0e000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0