NtProtectVirtualMemory
March 7, 2023, 7:44 a.m.
process_identifier:
2560
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x72d62000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
March 7, 2023, 7:44 a.m.
process_identifier:
2772
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00a04000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
March 7, 2023, 7:44 a.m.
process_identifier:
2772
region_size:
229376
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x004e0000
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
March 7, 2023, 7:44 a.m.
process_identifier:
2876
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x2fd11000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
March 7, 2023, 7:44 a.m.
process_identifier:
2876
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x71381000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
March 7, 2023, 7:44 a.m.
process_identifier:
2876
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x70601000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
March 7, 2023, 7:44 a.m.
process_identifier:
2876
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x7071e000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
March 7, 2023, 7:44 a.m.
process_identifier:
2876
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x715ce000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
March 7, 2023, 7:44 a.m.
process_identifier:
2876
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6f5e1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
March 7, 2023, 7:44 a.m.
process_identifier:
2876
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6fb4a000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
March 7, 2023, 7:44 a.m.
process_identifier:
2876
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x755c8000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
March 7, 2023, 7:44 a.m.
process_identifier:
2876
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6f3e1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
March 7, 2023, 7:44 a.m.
process_identifier:
2876
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6f3e1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
March 7, 2023, 7:44 a.m.
process_identifier:
2876
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x733a1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
March 7, 2023, 7:44 a.m.
process_identifier:
2876
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x72d61000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
March 7, 2023, 7:44 a.m.
process_identifier:
2876
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x72d62000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
March 7, 2023, 7:44 a.m.
process_identifier:
2876
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6f4a1000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
March 7, 2023, 7:44 a.m.
process_identifier:
2876
region_size:
2228224
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02bc0000
allocation_type:
8192
(MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
March 7, 2023, 7:44 a.m.
process_identifier:
2876
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02da0000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
March 7, 2023, 7:44 a.m.
process_identifier:
2876
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6e362000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
March 7, 2023, 7:44 a.m.
process_identifier:
2876
region_size:
393216
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02b00000
allocation_type:
8192
(MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
March 7, 2023, 7:44 a.m.
process_identifier:
2876
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02b20000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
March 7, 2023, 7:44 a.m.
process_identifier:
2876
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x74211000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
March 7, 2023, 7:44 a.m.
process_identifier:
2876
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x026b0000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
March 7, 2023, 7:44 a.m.
process_identifier:
2876
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x026b0000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
March 7, 2023, 7:44 a.m.
process_identifier:
2876
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6db11000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
March 7, 2023, 7:44 a.m.
process_identifier:
2876
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x69751000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
March 7, 2023, 7:44 a.m.
process_identifier:
2876
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x697af000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
March 7, 2023, 7:44 a.m.
process_identifier:
2876
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x697af000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
March 7, 2023, 7:44 a.m.
process_identifier:
2876
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x69971000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
March 7, 2023, 7:44 a.m.
process_identifier:
2876
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73111000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
March 7, 2023, 7:44 a.m.
process_identifier:
2876
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x72711000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
March 7, 2023, 7:44 a.m.
process_identifier:
2876
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x65001000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
March 7, 2023, 7:44 a.m.
process_identifier:
2876
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x694e1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
March 7, 2023, 7:44 a.m.
process_identifier:
2876
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x694e4000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
March 7, 2023, 7:44 a.m.
process_identifier:
2876
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73921000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
March 7, 2023, 7:44 a.m.
process_identifier:
2876
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x05e60000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
March 7, 2023, 7:44 a.m.
process_identifier:
2876
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x05e60000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
March 7, 2023, 7:44 a.m.
process_identifier:
2876
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x05e70000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
March 7, 2023, 7:44 a.m.
process_identifier:
2876
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x05e80000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
March 7, 2023, 7:44 a.m.
process_identifier:
2876
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x507c1000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
March 7, 2023, 7:44 a.m.
process_identifier:
2944
region_size:
1703936
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00d00000
allocation_type:
8192
(MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
March 7, 2023, 7:44 a.m.
process_identifier:
2944
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00e60000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
March 7, 2023, 7:44 a.m.
process_identifier:
2944
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6dc51000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
March 7, 2023, 7:44 a.m.
process_identifier:
2944
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6dc52000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
March 7, 2023, 7:44 a.m.
process_identifier:
2944
region_size:
1310720
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00600000
allocation_type:
8192
(MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
March 7, 2023, 7:44 a.m.
process_identifier:
2944
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00700000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
March 7, 2023, 7:44 a.m.
process_identifier:
2944
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x003b2000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
March 7, 2023, 7:44 a.m.
process_identifier:
2944
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x003e5000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
March 7, 2023, 7:44 a.m.
process_identifier:
2944
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x003eb000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0