NtProtectVirtualMemory
Nov. 4, 2021, 2:43 p.m.
process_identifier:
2320
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x7734f000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Nov. 4, 2021, 2:43 p.m.
process_identifier:
2320
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x772c0000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Nov. 4, 2021, 2:43 p.m.
process_identifier:
2320
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
335872
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00401000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Nov. 4, 2021, 2:43 p.m.
process_identifier:
2320
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
94208
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00453000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Nov. 4, 2021, 2:43 p.m.
process_identifier:
2320
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0046a000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Nov. 4, 2021, 2:43 p.m.
process_identifier:
2320
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0046e000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Nov. 4, 2021, 2:43 p.m.
process_identifier:
2320
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0046f000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Nov. 4, 2021, 2:43 p.m.
process_identifier:
2320
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
307200
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00470000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Nov. 4, 2021, 2:43 p.m.
process_identifier:
2320
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
16384
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x004bb000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Nov. 4, 2021, 2:43 p.m.
process_identifier:
2320
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00468000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Nov. 4, 2021, 2:43 p.m.
process_identifier:
2320
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00453000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Nov. 4, 2021, 2:43 p.m.
process_identifier:
2320
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00453000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Nov. 4, 2021, 2:43 p.m.
process_identifier:
2320
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00453000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Nov. 4, 2021, 2:43 p.m.
process_identifier:
2320
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00453000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Nov. 4, 2021, 2:43 p.m.
process_identifier:
2320
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00468000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Nov. 4, 2021, 2:43 p.m.
process_identifier:
2592
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x7734f000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Nov. 4, 2021, 2:43 p.m.
process_identifier:
2592
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x772c0000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Nov. 4, 2021, 2:43 p.m.
process_identifier:
2592
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
335872
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00401000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Nov. 4, 2021, 2:43 p.m.
process_identifier:
2592
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
94208
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00453000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Nov. 4, 2021, 2:43 p.m.
process_identifier:
2592
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0046a000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Nov. 4, 2021, 2:43 p.m.
process_identifier:
2592
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0046e000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Nov. 4, 2021, 2:43 p.m.
process_identifier:
2592
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0046f000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Nov. 4, 2021, 2:43 p.m.
process_identifier:
2592
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
307200
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00470000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Nov. 4, 2021, 2:43 p.m.
process_identifier:
2592
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
16384
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x004bb000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Nov. 4, 2021, 2:43 p.m.
process_identifier:
2592
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00468000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Nov. 4, 2021, 2:43 p.m.
process_identifier:
2592
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00453000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Nov. 4, 2021, 2:43 p.m.
process_identifier:
2592
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00453000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Nov. 4, 2021, 2:43 p.m.
process_identifier:
2592
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00453000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Nov. 4, 2021, 2:43 p.m.
process_identifier:
2592
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00453000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Nov. 4, 2021, 2:43 p.m.
process_identifier:
2592
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00468000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Nov. 4, 2021, 2:43 p.m.
process_identifier:
2656
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00400000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Nov. 4, 2021, 2:43 p.m.
process_identifier:
2656
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x7734f000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Nov. 4, 2021, 2:43 p.m.
process_identifier:
2656
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x772c0000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Nov. 4, 2021, 2:43 p.m.
process_identifier:
2656
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
335872
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00401000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Nov. 4, 2021, 2:43 p.m.
process_identifier:
2656
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
94208
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00453000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Nov. 4, 2021, 2:43 p.m.
process_identifier:
2656
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0046a000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Nov. 4, 2021, 2:43 p.m.
process_identifier:
2656
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0046e000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Nov. 4, 2021, 2:43 p.m.
process_identifier:
2656
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0046f000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Nov. 4, 2021, 2:43 p.m.
process_identifier:
2656
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
307200
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00470000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Nov. 4, 2021, 2:43 p.m.
process_identifier:
2656
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
16384
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x004bb000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Nov. 4, 2021, 2:43 p.m.
process_identifier:
2656
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00468000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Nov. 4, 2021, 2:43 p.m.
process_identifier:
2656
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00453000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Nov. 4, 2021, 2:43 p.m.
process_identifier:
2656
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00453000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Nov. 4, 2021, 2:43 p.m.
process_identifier:
2656
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00400000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Nov. 4, 2021, 2:43 p.m.
process_identifier:
2656
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00453000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Nov. 4, 2021, 2:43 p.m.
process_identifier:
2656
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00453000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Nov. 4, 2021, 2:43 p.m.
process_identifier:
2656
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00468000
process_handle:
0xffffffff
1
0
0