NtAllocateVirtualMemory
March 9, 2023, 1:38 p.m.
process_identifier:
1112
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0000000001df0000
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
March 9, 2023, 1:38 p.m.
process_identifier:
1112
region_size:
176128
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0000000001e00000
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
March 9, 2023, 1:38 p.m.
process_identifier:
1112
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fefd0e7000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
March 9, 2023, 1:38 p.m.
process_identifier:
1112
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fefd92f000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
March 9, 2023, 1:38 p.m.
process_identifier:
1112
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fefd799000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
March 9, 2023, 1:38 p.m.
process_identifier:
1112
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0000000076d50000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
March 9, 2023, 1:38 p.m.
process_identifier:
1112
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fefdc7d000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
March 9, 2023, 1:38 p.m.
process_identifier:
1112
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0000000076f8e000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
March 9, 2023, 1:38 p.m.
process_identifier:
1112
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0000000076ee0000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
March 9, 2023, 1:38 p.m.
process_identifier:
1112
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fef835c000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
March 9, 2023, 1:38 p.m.
process_identifier:
1112
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fef82db000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
March 9, 2023, 1:38 p.m.
process_identifier:
1112
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fefb8da000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
March 9, 2023, 1:38 p.m.
process_identifier:
1112
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007feff38b000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
March 9, 2023, 1:38 p.m.
process_identifier:
1112
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fefda31000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
March 9, 2023, 1:38 p.m.
process_identifier:
1112
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fefd851000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
March 9, 2023, 1:38 p.m.
process_identifier:
1112
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fefba71000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
March 9, 2023, 1:38 p.m.
process_identifier:
1112
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fefdf1a000
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
March 9, 2023, 1:38 p.m.
process_identifier:
1236
region_size:
65536
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0000000004f60000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
March 9, 2023, 1:38 p.m.
process_identifier:
2496
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0000000001d10000
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
March 9, 2023, 1:38 p.m.
process_identifier:
2496
region_size:
176128
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0000000001d20000
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
March 9, 2023, 1:38 p.m.
process_identifier:
2496
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fefd0e7000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
March 9, 2023, 1:38 p.m.
process_identifier:
2496
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fefd92f000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
March 9, 2023, 1:38 p.m.
process_identifier:
2496
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fefd799000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
March 9, 2023, 1:38 p.m.
process_identifier:
2496
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0000000076d50000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
March 9, 2023, 1:38 p.m.
process_identifier:
2496
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fefdc7d000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
March 9, 2023, 1:38 p.m.
process_identifier:
2496
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0000000076f8e000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
March 9, 2023, 1:38 p.m.
process_identifier:
2496
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0000000076ee0000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
March 9, 2023, 1:38 p.m.
process_identifier:
2496
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fef835c000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
March 9, 2023, 1:38 p.m.
process_identifier:
2496
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fef82db000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
March 9, 2023, 1:38 p.m.
process_identifier:
2496
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fefb8da000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
March 9, 2023, 1:38 p.m.
process_identifier:
2496
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fefe351000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
March 9, 2023, 1:38 p.m.
process_identifier:
2496
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fefe203000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
March 9, 2023, 1:38 p.m.
process_identifier:
2496
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fefcf81000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
March 9, 2023, 1:38 p.m.
process_identifier:
2496
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fefcb51000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
March 9, 2023, 1:38 p.m.
process_identifier:
2496
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fefcf64000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
March 9, 2023, 1:38 p.m.
process_identifier:
2496
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fefcdde000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
March 9, 2023, 1:38 p.m.
process_identifier:
2496
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fefcd53000
process_handle:
0xffffffffffffffff
1
0
0