NtProtectVirtualMemory
Dec. 14, 2023, 10:13 a.m.
process_identifier:
3044
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
163840
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x028a0000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Dec. 14, 2023, 10:13 a.m.
process_identifier:
3044
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x028c8000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Dec. 14, 2023, 10:13 a.m.
process_identifier:
3044
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x028d0000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Dec. 14, 2023, 10:13 a.m.
process_identifier:
3044
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x028d8000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Dec. 14, 2023, 10:13 a.m.
process_identifier:
3044
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x028e0000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Dec. 14, 2023, 10:13 a.m.
process_identifier:
3044
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x028e8000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Dec. 14, 2023, 10:13 a.m.
process_identifier:
3044
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x028f0000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Dec. 14, 2023, 10:13 a.m.
process_identifier:
3044
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x028f8000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Dec. 14, 2023, 10:13 a.m.
process_identifier:
3044
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02900000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Dec. 14, 2023, 10:13 a.m.
process_identifier:
3044
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02908000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Dec. 14, 2023, 10:13 a.m.
process_identifier:
3044
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02910000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Dec. 14, 2023, 10:13 a.m.
process_identifier:
3044
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02918000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Dec. 14, 2023, 10:13 a.m.
process_identifier:
3044
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02920000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Dec. 14, 2023, 10:13 a.m.
process_identifier:
3044
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02928000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Dec. 14, 2023, 10:13 a.m.
process_identifier:
3044
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02930000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Dec. 14, 2023, 10:13 a.m.
process_identifier:
3044
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02938000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Dec. 14, 2023, 10:13 a.m.
process_identifier:
3044
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02940000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Dec. 14, 2023, 10:13 a.m.
process_identifier:
3044
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02948000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Dec. 14, 2023, 10:13 a.m.
process_identifier:
3044
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02950000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Dec. 14, 2023, 10:13 a.m.
process_identifier:
3044
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02958000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Dec. 14, 2023, 10:13 a.m.
process_identifier:
3044
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02960000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Dec. 14, 2023, 10:13 a.m.
process_identifier:
3044
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02968000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Dec. 14, 2023, 10:13 a.m.
process_identifier:
3044
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02970000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Dec. 14, 2023, 10:13 a.m.
process_identifier:
3044
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02978000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Dec. 14, 2023, 10:13 a.m.
process_identifier:
3044
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02980000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Dec. 14, 2023, 10:13 a.m.
process_identifier:
3044
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02988000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Dec. 14, 2023, 10:13 a.m.
process_identifier:
3044
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02990000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Dec. 14, 2023, 10:13 a.m.
process_identifier:
3044
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02998000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Dec. 14, 2023, 10:13 a.m.
process_identifier:
3044
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x029a0000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Dec. 14, 2023, 10:13 a.m.
process_identifier:
3044
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x029a8000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Dec. 14, 2023, 10:13 a.m.
process_identifier:
3044
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x029b0000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Dec. 14, 2023, 10:13 a.m.
process_identifier:
3044
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x029b8000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Dec. 14, 2023, 10:13 a.m.
process_identifier:
3044
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x029c0000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Dec. 14, 2023, 10:13 a.m.
process_identifier:
3044
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x029c8000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Dec. 14, 2023, 10:13 a.m.
process_identifier:
3044
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x029d0000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Dec. 14, 2023, 10:13 a.m.
process_identifier:
3044
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x029d8000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Dec. 14, 2023, 10:13 a.m.
process_identifier:
3044
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x029e0000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Dec. 14, 2023, 10:13 a.m.
process_identifier:
3044
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x029e8000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Dec. 14, 2023, 10:13 a.m.
process_identifier:
3044
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x029f0000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Dec. 14, 2023, 10:13 a.m.
process_identifier:
292
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
163840
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x028a0000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Dec. 14, 2023, 10:13 a.m.
process_identifier:
292
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x028c8000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Dec. 14, 2023, 10:13 a.m.
process_identifier:
292
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x028d0000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Dec. 14, 2023, 10:13 a.m.
process_identifier:
292
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x028d8000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Dec. 14, 2023, 10:13 a.m.
process_identifier:
292
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x028e0000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Dec. 14, 2023, 10:13 a.m.
process_identifier:
292
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x028e8000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Dec. 14, 2023, 10:13 a.m.
process_identifier:
292
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x028f0000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Dec. 14, 2023, 10:13 a.m.
process_identifier:
292
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x028f8000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Dec. 14, 2023, 10:13 a.m.
process_identifier:
292
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02900000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Dec. 14, 2023, 10:13 a.m.
process_identifier:
292
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02908000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Dec. 14, 2023, 10:13 a.m.
process_identifier:
292
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
32768
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02910000
process_handle:
0xffffffff
1
0
0