NtAllocateVirtualMemory
Nov. 30, 2023, 7:06 a.m.
process_identifier:
2652
region_size:
1507328
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00000000009c0000
allocation_type:
8192
(MEM_RESERVE)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
Nov. 30, 2023, 7:06 a.m.
process_identifier:
2652
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0000000000ab0000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Nov. 30, 2023, 7:06 a.m.
process_identifier:
2652
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fef39d1000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Nov. 30, 2023, 7:06 a.m.
process_identifier:
2652
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fef406b000
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
Nov. 30, 2023, 7:06 a.m.
process_identifier:
2652
region_size:
1900544
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0000000002380000
allocation_type:
8192
(MEM_RESERVE)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
Nov. 30, 2023, 7:06 a.m.
process_identifier:
2652
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00000000024d0000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Nov. 30, 2023, 7:06 a.m.
process_identifier:
2652
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fef39d2000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Nov. 30, 2023, 7:06 a.m.
process_identifier:
2652
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fef39d2000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Nov. 30, 2023, 7:06 a.m.
process_identifier:
2652
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fef39d2000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Nov. 30, 2023, 7:06 a.m.
process_identifier:
2652
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fef39d2000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Nov. 30, 2023, 7:06 a.m.
process_identifier:
2652
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fef39d2000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Nov. 30, 2023, 7:06 a.m.
process_identifier:
2652
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fef39d2000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Nov. 30, 2023, 7:06 a.m.
process_identifier:
2652
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fef39d2000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Nov. 30, 2023, 7:06 a.m.
process_identifier:
2652
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fef39d2000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Nov. 30, 2023, 7:06 a.m.
process_identifier:
2652
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fef39d2000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Nov. 30, 2023, 7:06 a.m.
process_identifier:
2652
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fef39d2000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Nov. 30, 2023, 7:06 a.m.
process_identifier:
2652
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fef39d2000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Nov. 30, 2023, 7:06 a.m.
process_identifier:
2652
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fef39d4000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Nov. 30, 2023, 7:06 a.m.
process_identifier:
2652
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fef39d4000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Nov. 30, 2023, 7:06 a.m.
process_identifier:
2652
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fef39d4000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
Nov. 30, 2023, 7:06 a.m.
process_identifier:
2652
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fef39d4000
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
Nov. 30, 2023, 7:06 a.m.
process_identifier:
2652
region_size:
655360
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fffff10000
allocation_type:
1056768
(MEM_RESERVE|MEM_TOP_DOWN)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
Nov. 30, 2023, 7:06 a.m.
process_identifier:
2652
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fffff10000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
Nov. 30, 2023, 7:06 a.m.
process_identifier:
2652
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fffff10000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
Nov. 30, 2023, 7:06 a.m.
process_identifier:
2652
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fffff20000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
Nov. 30, 2023, 7:06 a.m.
process_identifier:
2652
region_size:
65536
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fffff00000
allocation_type:
1056768
(MEM_RESERVE|MEM_TOP_DOWN)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
Nov. 30, 2023, 7:06 a.m.
process_identifier:
2652
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fffff00000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
Nov. 30, 2023, 7:06 a.m.
process_identifier:
2652
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fe9423a000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
Nov. 30, 2023, 7:06 a.m.
process_identifier:
2652
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fe9424c000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
Nov. 30, 2023, 7:06 a.m.
process_identifier:
2652
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fe94380000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
Nov. 30, 2023, 7:06 a.m.
process_identifier:
2652
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fe942ec000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
Nov. 30, 2023, 7:06 a.m.
process_identifier:
2652
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fe94316000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
Nov. 30, 2023, 7:06 a.m.
process_identifier:
2652
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fe942f0000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
Nov. 30, 2023, 7:06 a.m.
process_identifier:
2652
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fe9423c000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
Nov. 30, 2023, 7:06 a.m.
process_identifier:
2652
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fe94381000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
Nov. 30, 2023, 7:06 a.m.
process_identifier:
2652
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fe9423b000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
Nov. 30, 2023, 7:06 a.m.
process_identifier:
2652
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fe9425b000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
Nov. 30, 2023, 7:06 a.m.
process_identifier:
2652
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fe94382000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
Nov. 30, 2023, 7:06 a.m.
process_identifier:
2652
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fe9428c000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
Nov. 30, 2023, 7:06 a.m.
process_identifier:
2652
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fe9425d000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
Nov. 30, 2023, 7:06 a.m.
process_identifier:
2652
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fe94232000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
Nov. 30, 2023, 7:06 a.m.
process_identifier:
2652
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fe94383000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
Nov. 30, 2023, 7:06 a.m.
process_identifier:
2652
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fe94384000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
Nov. 30, 2023, 7:06 a.m.
process_identifier:
2652
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fe94385000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
Nov. 30, 2023, 7:06 a.m.
process_identifier:
2652
region_size:
16384
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fe94386000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
Nov. 30, 2023, 7:06 a.m.
process_identifier:
2652
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fe943d0000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
Nov. 30, 2023, 7:06 a.m.
process_identifier:
2652
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fe9424d000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
Nov. 30, 2023, 7:06 a.m.
process_identifier:
2652
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fe9438a000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
Nov. 30, 2023, 7:06 a.m.
process_identifier:
2652
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fe9438b000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
Nov. 30, 2023, 7:06 a.m.
process_identifier:
2652
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fe9424a000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0