NtProtectVirtualMemory
|
process_identifier:
1372
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
163840
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x024a0000
process_handle:
0xffffffff
|
1
|
0 |
0
|
NtProtectVirtualMemory
|
process_identifier:
1372
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x024c8000
process_handle:
0xffffffff
|
1
|
0 |
0
|
NtProtectVirtualMemory
|
process_identifier:
1372
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x024d0000
process_handle:
0xffffffff
|
1
|
0 |
0
|
NtProtectVirtualMemory
|
process_identifier:
1372
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x024d8000
process_handle:
0xffffffff
|
1
|
0 |
0
|
NtProtectVirtualMemory
|
process_identifier:
1372
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x024e0000
process_handle:
0xffffffff
|
1
|
0 |
0
|
NtProtectVirtualMemory
|
process_identifier:
1372
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x024e8000
process_handle:
0xffffffff
|
1
|
0 |
0
|
NtProtectVirtualMemory
|
process_identifier:
1372
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x024f0000
process_handle:
0xffffffff
|
1
|
0 |
0
|
NtProtectVirtualMemory
|
process_identifier:
1372
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x024f8000
process_handle:
0xffffffff
|
1
|
0 |
0
|
NtProtectVirtualMemory
|
process_identifier:
1372
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02500000
process_handle:
0xffffffff
|
1
|
0 |
0
|
NtProtectVirtualMemory
|
process_identifier:
1372
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02508000
process_handle:
0xffffffff
|
1
|
0 |
0
|
NtProtectVirtualMemory
|
process_identifier:
1372
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02510000
process_handle:
0xffffffff
|
1
|
0 |
0
|
NtProtectVirtualMemory
|
process_identifier:
1372
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02518000
process_handle:
0xffffffff
|
1
|
0 |
0
|
NtProtectVirtualMemory
|
process_identifier:
1372
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02520000
process_handle:
0xffffffff
|
1
|
0 |
0
|
NtProtectVirtualMemory
|
process_identifier:
1372
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02528000
process_handle:
0xffffffff
|
1
|
0 |
0
|
NtProtectVirtualMemory
|
process_identifier:
1372
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02530000
process_handle:
0xffffffff
|
1
|
0 |
0
|
NtProtectVirtualMemory
|
process_identifier:
1372
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02538000
process_handle:
0xffffffff
|
1
|
0 |
0
|
NtProtectVirtualMemory
|
process_identifier:
1372
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02540000
process_handle:
0xffffffff
|
1
|
0 |
0
|
NtProtectVirtualMemory
|
process_identifier:
1372
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02548000
process_handle:
0xffffffff
|
1
|
0 |
0
|
NtProtectVirtualMemory
|
process_identifier:
1372
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02550000
process_handle:
0xffffffff
|
1
|
0 |
0
|
NtProtectVirtualMemory
|
process_identifier:
1372
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02558000
process_handle:
0xffffffff
|
1
|
0 |
0
|
NtProtectVirtualMemory
|
process_identifier:
1372
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02560000
process_handle:
0xffffffff
|
1
|
0 |
0
|
NtProtectVirtualMemory
|
process_identifier:
1372
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02568000
process_handle:
0xffffffff
|
1
|
0 |
0
|
NtProtectVirtualMemory
|
process_identifier:
1372
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02570000
process_handle:
0xffffffff
|
1
|
0 |
0
|
NtProtectVirtualMemory
|
process_identifier:
1372
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02578000
process_handle:
0xffffffff
|
1
|
0 |
0
|
NtProtectVirtualMemory
|
process_identifier:
1372
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02580000
process_handle:
0xffffffff
|
1
|
0 |
0
|
NtProtectVirtualMemory
|
process_identifier:
1372
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02588000
process_handle:
0xffffffff
|
1
|
0 |
0
|
NtProtectVirtualMemory
|
process_identifier:
1372
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02590000
process_handle:
0xffffffff
|
1
|
0 |
0
|
NtProtectVirtualMemory
|
process_identifier:
1372
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02598000
process_handle:
0xffffffff
|
1
|
0 |
0
|
NtProtectVirtualMemory
|
process_identifier:
1372
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x025a0000
process_handle:
0xffffffff
|
1
|
0 |
0
|
NtProtectVirtualMemory
|
process_identifier:
1372
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x025a8000
process_handle:
0xffffffff
|
1
|
0 |
0
|
NtProtectVirtualMemory
|
process_identifier:
2108
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73be1000
process_handle:
0xffffffff
|
1
|
0 |
0
|
NtProtectVirtualMemory
|
process_identifier:
2248
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73c01000
process_handle:
0xffffffff
|
1
|
0 |
0
|
NtProtectVirtualMemory
|
process_identifier:
2348
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73be1000
process_handle:
0xffffffff
|
1
|
0 |
0
|
NtProtectVirtualMemory
|
process_identifier:
2436
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73c01000
process_handle:
0xffffffff
|
1
|
0 |
0
|