NtProtectVirtualMemory
Oct. 10, 2023, 10:06 a.m.
process_identifier:
2556
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x736b1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 10, 2023, 10:06 a.m.
process_identifier:
2556
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73951000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 10, 2023, 10:06 a.m.
process_identifier:
2556
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x72b01000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 10, 2023, 10:06 a.m.
process_identifier:
2556
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x72ac4000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 10, 2023, 10:06 a.m.
process_identifier:
2556
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x72b02000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 10, 2023, 10:06 a.m.
process_identifier:
2556
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x72781000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 10, 2023, 10:06 a.m.
process_identifier:
2556
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x72761000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 10, 2023, 10:06 a.m.
process_identifier:
2556
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73921000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 10, 2023, 10:06 a.m.
process_identifier:
2556
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x72741000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 10, 2023, 10:06 a.m.
process_identifier:
2556
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x75941000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 10, 2023, 10:06 a.m.
process_identifier:
2556
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x764b1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 10, 2023, 10:06 a.m.
process_identifier:
2556
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x75831000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 10, 2023, 10:06 a.m.
process_identifier:
2556
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x72b71000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 10, 2023, 10:06 a.m.
process_identifier:
2556
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x72701000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 10, 2023, 10:06 a.m.
process_identifier:
2556
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x726e1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 10, 2023, 10:06 a.m.
process_identifier:
2556
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x726a1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 10, 2023, 10:06 a.m.
process_identifier:
2556
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x72661000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 10, 2023, 10:06 a.m.
process_identifier:
2556
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x75b71000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 10, 2023, 10:06 a.m.
process_identifier:
2556
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x72651000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 10, 2023, 10:06 a.m.
process_identifier:
2556
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x725f1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 10, 2023, 10:06 a.m.
process_identifier:
2556
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x725a1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 10, 2023, 10:06 a.m.
process_identifier:
2556
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x75bf1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 10, 2023, 10:06 a.m.
process_identifier:
2556
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x75591000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 10, 2023, 10:06 a.m.
process_identifier:
2556
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x72591000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 10, 2023, 10:06 a.m.
process_identifier:
2556
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x730d1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 10, 2023, 10:06 a.m.
process_identifier:
2556
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x72571000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 10, 2023, 10:06 a.m.
process_identifier:
2556
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x724e1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 10, 2023, 10:07 a.m.
process_identifier:
2556
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x72441000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Oct. 10, 2023, 10:07 a.m.
process_identifier:
2556
region_size:
1835008
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04250000
allocation_type:
8192
(MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Oct. 10, 2023, 10:07 a.m.
process_identifier:
2556
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x043d0000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 10, 2023, 10:07 a.m.
process_identifier:
2556
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x72432000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Oct. 10, 2023, 10:07 a.m.
process_identifier:
2556
region_size:
2162688
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x04410000
allocation_type:
8192
(MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Oct. 10, 2023, 10:07 a.m.
process_identifier:
2556
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x045e0000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 10, 2023, 10:07 a.m.
process_identifier:
2556
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x72361000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 10, 2023, 10:07 a.m.
process_identifier:
2556
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x75511000
process_handle:
0xffffffff
1
0
0