NtProtectVirtualMemory
July 3, 2023, 10:37 a.m.
process_identifier:
1516
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00401000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 3, 2023, 10:37 a.m.
process_identifier:
2144
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x74601000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 3, 2023, 10:37 a.m.
process_identifier:
2144
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73f51000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 3, 2023, 10:37 a.m.
process_identifier:
2216
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x74601000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 3, 2023, 10:37 a.m.
process_identifier:
2216
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73f21000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 3, 2023, 10:37 a.m.
process_identifier:
2276
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x74601000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 3, 2023, 10:37 a.m.
process_identifier:
2276
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73f51000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 3, 2023, 10:37 a.m.
process_identifier:
2320
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
12288
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00401000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 3, 2023, 10:37 a.m.
process_identifier:
2320
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73f31000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
July 3, 2023, 10:37 a.m.
process_identifier:
2320
region_size:
1179648
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x01e10000
allocation_type:
8192
(MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
July 3, 2023, 10:37 a.m.
process_identifier:
2320
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x01ef0000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 3, 2023, 10:37 a.m.
process_identifier:
2320
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73f22000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
July 3, 2023, 10:37 a.m.
process_identifier:
2320
region_size:
1048576
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x020e0000
allocation_type:
8192
(MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
July 3, 2023, 10:37 a.m.
process_identifier:
2320
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x021a0000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 3, 2023, 10:37 a.m.
process_identifier:
2320
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73522000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 3, 2023, 10:37 a.m.
process_identifier:
2320
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73e9b000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 3, 2023, 10:37 a.m.
process_identifier:
2320
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x72ee1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 3, 2023, 10:37 a.m.
process_identifier:
2320
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x72ee2000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
July 3, 2023, 10:37 a.m.
process_identifier:
2320
region_size:
458752
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x020e0000
allocation_type:
8192
(MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
July 3, 2023, 10:37 a.m.
process_identifier:
2320
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02110000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
July 3, 2023, 10:37 a.m.
process_identifier:
2320
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x01ea2000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
July 3, 2023, 10:37 a.m.
process_identifier:
2320
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x01ed5000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
July 3, 2023, 10:37 a.m.
process_identifier:
2320
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x01edb000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
July 3, 2023, 10:37 a.m.
process_identifier:
2320
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x01ed7000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
July 3, 2023, 10:37 a.m.
process_identifier:
2320
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x01ebc000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 3, 2023, 10:37 a.m.
process_identifier:
2320
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73dca000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
July 3, 2023, 10:37 a.m.
process_identifier:
2320
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04900000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
July 3, 2023, 10:37 a.m.
process_identifier:
2320
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x01eaa000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
July 3, 2023, 10:37 a.m.
process_identifier:
2320
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x01eca000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
July 3, 2023, 10:37 a.m.
process_identifier:
2320
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x01ec7000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
July 3, 2023, 10:37 a.m.
process_identifier:
2320
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04901000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
July 3, 2023, 10:37 a.m.
process_identifier:
2320
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x01ec6000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 3, 2023, 10:37 a.m.
process_identifier:
2320
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73d4f000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 3, 2023, 10:30 a.m.
process_identifier:
2740
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fef3fc3000
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
July 3, 2023, 10:30 a.m.
process_identifier:
2740
region_size:
786432
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0000000001f20000
allocation_type:
8192
(MEM_RESERVE)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
July 3, 2023, 10:30 a.m.
process_identifier:
2740
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0000000001f60000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
July 3, 2023, 10:30 a.m.
process_identifier:
2740
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fef28ba000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
July 3, 2023, 10:30 a.m.
process_identifier:
2740
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fef31c5000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
July 3, 2023, 10:30 a.m.
process_identifier:
2740
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fef2221000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
July 3, 2023, 10:30 a.m.
process_identifier:
2740
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fef28bb000
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
July 3, 2023, 10:30 a.m.
process_identifier:
2740
region_size:
2228224
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00000000020c0000
allocation_type:
8192
(MEM_RESERVE)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
July 3, 2023, 10:30 a.m.
process_identifier:
2740
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0000000002260000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
July 3, 2023, 10:30 a.m.
process_identifier:
2740
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fef2222000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
July 3, 2023, 10:30 a.m.
process_identifier:
2740
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fef2222000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
July 3, 2023, 10:30 a.m.
process_identifier:
2740
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fef2222000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
July 3, 2023, 10:30 a.m.
process_identifier:
2740
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fef2222000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
July 3, 2023, 10:30 a.m.
process_identifier:
2740
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fef2222000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
July 3, 2023, 10:30 a.m.
process_identifier:
2740
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fef2222000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
July 3, 2023, 10:30 a.m.
process_identifier:
2740
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fef2222000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
July 3, 2023, 10:30 a.m.
process_identifier:
2740
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fef2222000
process_handle:
0xffffffffffffffff
1
0
0