NtAllocateVirtualMemory
Oct. 16, 2023, 10:55 a.m.
process_identifier:
2788
region_size:
1904640
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02cb0000
allocation_type:
8192
(MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Oct. 16, 2023, 10:55 a.m.
process_identifier:
2788
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02e80000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 16, 2023, 10:55 a.m.
process_identifier:
2788
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x758af000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 16, 2023, 10:55 a.m.
process_identifier:
2788
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x758af000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 16, 2023, 10:55 a.m.
process_identifier:
2788
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x758af000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 16, 2023, 10:55 a.m.
process_identifier:
2788
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x758af000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 16, 2023, 10:55 a.m.
process_identifier:
2788
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x7587c000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 16, 2023, 10:55 a.m.
process_identifier:
2788
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x7589c000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 16, 2023, 10:55 a.m.
process_identifier:
2788
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x7587c000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 16, 2023, 10:55 a.m.
process_identifier:
2788
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x7589c000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 16, 2023, 10:55 a.m.
process_identifier:
2788
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73573000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 16, 2023, 10:55 a.m.
process_identifier:
2788
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73617000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 16, 2023, 10:55 a.m.
process_identifier:
2788
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x757c9000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 16, 2023, 10:55 a.m.
process_identifier:
2788
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x75522000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 16, 2023, 10:55 a.m.
process_identifier:
2788
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x75862000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 16, 2023, 10:55 a.m.
process_identifier:
2788
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x758af000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 16, 2023, 10:55 a.m.
process_identifier:
2788
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x758af000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 16, 2023, 10:55 a.m.
process_identifier:
2788
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x758af000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Oct. 16, 2023, 10:55 a.m.
process_identifier:
2788
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x03210000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 16, 2023, 10:55 a.m.
process_identifier:
2788
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x733b2000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 16, 2023, 10:56 a.m.
process_identifier:
2788
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6ff01000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Oct. 16, 2023, 10:55 a.m.
process_identifier:
2868
region_size:
2625536
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x026f0000
allocation_type:
8192
(MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Oct. 16, 2023, 10:55 a.m.
process_identifier:
2868
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02970000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 16, 2023, 10:55 a.m.
process_identifier:
2868
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x758af000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 16, 2023, 10:55 a.m.
process_identifier:
2868
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x758af000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 16, 2023, 10:55 a.m.
process_identifier:
2868
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x758af000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 16, 2023, 10:55 a.m.
process_identifier:
2868
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x758af000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 16, 2023, 10:55 a.m.
process_identifier:
2868
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x7587c000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 16, 2023, 10:55 a.m.
process_identifier:
2868
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x7589c000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 16, 2023, 10:55 a.m.
process_identifier:
2868
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x7587c000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 16, 2023, 10:55 a.m.
process_identifier:
2868
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x7589c000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 16, 2023, 10:55 a.m.
process_identifier:
2868
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73573000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 16, 2023, 10:55 a.m.
process_identifier:
2868
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73617000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 16, 2023, 10:55 a.m.
process_identifier:
2868
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x757c9000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 16, 2023, 10:55 a.m.
process_identifier:
2868
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x75522000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 16, 2023, 10:55 a.m.
process_identifier:
2868
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x75862000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 16, 2023, 10:55 a.m.
process_identifier:
2868
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x75867000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 16, 2023, 10:55 a.m.
process_identifier:
2868
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x7587f000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 16, 2023, 10:55 a.m.
process_identifier:
2868
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x75866000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 16, 2023, 10:55 a.m.
process_identifier:
2868
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x755c3000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 16, 2023, 10:55 a.m.
process_identifier:
2868
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x76f6d000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 16, 2023, 10:55 a.m.
process_identifier:
2868
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x755c7000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 16, 2023, 10:55 a.m.
process_identifier:
2868
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x75858000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 16, 2023, 10:55 a.m.
process_identifier:
2868
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x7585d000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 16, 2023, 10:55 a.m.
process_identifier:
2868
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x76f52000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 16, 2023, 10:55 a.m.
process_identifier:
2868
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x76f42000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 16, 2023, 10:55 a.m.
process_identifier:
2868
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x746c6000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 16, 2023, 10:55 a.m.
process_identifier:
2868
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x75764000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 16, 2023, 10:55 a.m.
process_identifier:
2868
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x75763000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Oct. 16, 2023, 10:55 a.m.
process_identifier:
2868
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x75765000
process_handle:
0xffffffff
1
0
0