NtProtectVirtualMemory
Nov. 7, 2022, 10:28 a.m.
process_identifier:
2064
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6c318000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Nov. 7, 2022, 10:29 a.m.
process_identifier:
2064
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6be52000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Nov. 7, 2022, 10:28 a.m.
process_identifier:
2472
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0000000010041000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Nov. 7, 2022, 10:28 a.m.
process_identifier:
2472
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fefb941000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Nov. 7, 2022, 10:28 a.m.
process_identifier:
2472
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fefe52d000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Nov. 7, 2022, 10:28 a.m.
process_identifier:
2472
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fefddaf000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Nov. 7, 2022, 10:28 a.m.
process_identifier:
2472
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fefdbc9000
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
Nov. 7, 2022, 10:28 a.m.
process_identifier:
2472
region_size:
184320
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0000000001e00000
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
Nov. 7, 2022, 10:28 a.m.
process_identifier:
2472
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00000000004d0000
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Nov. 7, 2022, 10:28 a.m.
process_identifier:
2472
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fefd517000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Nov. 7, 2022, 10:28 a.m.
process_identifier:
2472
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0000000077400000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Nov. 7, 2022, 10:28 a.m.
process_identifier:
2472
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00000000774de000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Nov. 7, 2022, 10:28 a.m.
process_identifier:
2472
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00000000771d0000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Nov. 7, 2022, 10:28 a.m.
process_identifier:
2472
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fef915c000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Nov. 7, 2022, 10:28 a.m.
process_identifier:
2472
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fef90db000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Nov. 7, 2022, 10:28 a.m.
process_identifier:
2472
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fefbd0a000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Nov. 7, 2022, 10:28 a.m.
process_identifier:
2472
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fefe31b000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Nov. 7, 2022, 10:28 a.m.
process_identifier:
2472
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fefdcc1000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Nov. 7, 2022, 10:28 a.m.
process_identifier:
2472
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fefdbe1000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Nov. 7, 2022, 10:28 a.m.
process_identifier:
2472
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fefc021000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Nov. 7, 2022, 10:28 a.m.
process_identifier:
2472
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fefe8aa000
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
Nov. 7, 2022, 10:29 a.m.
process_identifier:
1236
region_size:
65536
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0000000006910000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Nov. 7, 2022, 10:29 a.m.
process_identifier:
2828
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0000000010041000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Nov. 7, 2022, 10:29 a.m.
process_identifier:
2828
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fefb941000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Nov. 7, 2022, 10:29 a.m.
process_identifier:
2828
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fefe52d000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Nov. 7, 2022, 10:29 a.m.
process_identifier:
2828
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fefddaf000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Nov. 7, 2022, 10:29 a.m.
process_identifier:
2828
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fefdbc9000
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
Nov. 7, 2022, 10:29 a.m.
process_identifier:
2828
region_size:
184320
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00000000005d0000
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
Nov. 7, 2022, 10:29 a.m.
process_identifier:
2828
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0000000000600000
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Nov. 7, 2022, 10:29 a.m.
process_identifier:
2828
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fefd517000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Nov. 7, 2022, 10:29 a.m.
process_identifier:
2828
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0000000077400000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Nov. 7, 2022, 10:29 a.m.
process_identifier:
2828
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00000000774de000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Nov. 7, 2022, 10:29 a.m.
process_identifier:
2828
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00000000771d0000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Nov. 7, 2022, 10:29 a.m.
process_identifier:
2828
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fef915c000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Nov. 7, 2022, 10:29 a.m.
process_identifier:
2828
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fef90db000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Nov. 7, 2022, 10:29 a.m.
process_identifier:
2828
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fefbd0a000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Nov. 7, 2022, 10:29 a.m.
process_identifier:
2828
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fefe471000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Nov. 7, 2022, 10:29 a.m.
process_identifier:
2828
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007feff9a3000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Nov. 7, 2022, 10:29 a.m.
process_identifier:
2828
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fefd3b1000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Nov. 7, 2022, 10:29 a.m.
process_identifier:
2828
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fefcf81000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Nov. 7, 2022, 10:29 a.m.
process_identifier:
2828
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fefd394000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Nov. 7, 2022, 10:29 a.m.
process_identifier:
2828
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fefd20e000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Nov. 7, 2022, 10:29 a.m.
process_identifier:
2828
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fefd183000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Nov. 7, 2022, 10:29 a.m.
process_identifier:
2964
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0000000010041000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Nov. 7, 2022, 10:29 a.m.
process_identifier:
2964
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fefb941000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Nov. 7, 2022, 10:29 a.m.
process_identifier:
2964
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fefe52d000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Nov. 7, 2022, 10:29 a.m.
process_identifier:
2964
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fefddaf000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Nov. 7, 2022, 10:29 a.m.
process_identifier:
2964
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fefdbc9000
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
Nov. 7, 2022, 10:29 a.m.
process_identifier:
2964
region_size:
184320
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0000000001d10000
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
Nov. 7, 2022, 10:29 a.m.
process_identifier:
2964
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0000000001d40000
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
process_handle:
0xffffffffffffffff
1
0
0