NtProtectVirtualMemory
Jan. 9, 2024, 2:47 p.m.
process_identifier:
3020
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x75b0b000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Jan. 9, 2024, 2:47 p.m.
process_identifier:
3020
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x05130000
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Jan. 9, 2024, 2:47 p.m.
process_identifier:
3020
region_size:
5242880
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x06020000
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Jan. 9, 2024, 2:47 p.m.
process_identifier:
3020
region_size:
5242880
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x06520000
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Jan. 9, 2024, 2:47 p.m.
process_identifier:
2224
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6ad52000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Jan. 9, 2024, 2:47 p.m.
process_identifier:
2224
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00bb0000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Jan. 9, 2024, 2:47 p.m.
process_identifier:
2224
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00bc0000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Jan. 9, 2024, 2:47 p.m.
process_identifier:
2224
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00bd0000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Jan. 9, 2024, 2:47 p.m.
process_identifier:
2224
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00be0000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Jan. 9, 2024, 2:47 p.m.
process_identifier:
2224
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x011a0000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Jan. 9, 2024, 2:47 p.m.
process_identifier:
2224
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x011b0000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Jan. 9, 2024, 2:47 p.m.
process_identifier:
2396
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x2f171000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Jan. 9, 2024, 2:47 p.m.
process_identifier:
2396
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x7425c000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Jan. 9, 2024, 2:47 p.m.
process_identifier:
2396
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x70c37000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Jan. 9, 2024, 2:47 p.m.
process_identifier:
2396
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x7213f000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Jan. 9, 2024, 2:47 p.m.
process_identifier:
2396
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
45056
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x709bd000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Jan. 9, 2024, 2:47 p.m.
process_identifier:
2396
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6fc30000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Jan. 9, 2024, 2:47 p.m.
process_identifier:
2396
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x74e88000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Jan. 9, 2024, 2:47 p.m.
process_identifier:
2396
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6adc1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Jan. 9, 2024, 2:47 p.m.
process_identifier:
2396
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6ad52000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Jan. 9, 2024, 2:47 p.m.
process_identifier:
2396
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6ac49000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Jan. 9, 2024, 2:47 p.m.
process_identifier:
2396
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6ac49000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Jan. 9, 2024, 2:47 p.m.
process_identifier:
2396
region_size:
1441792
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x03bd0000
allocation_type:
8192
(MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Jan. 9, 2024, 2:47 p.m.
process_identifier:
2396
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x03cf0000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Jan. 9, 2024, 2:47 p.m.
process_identifier:
2396
region_size:
1245184
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x03d30000
allocation_type:
8192
(MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Jan. 9, 2024, 2:47 p.m.
process_identifier:
2396
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x03e20000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Jan. 9, 2024, 2:47 p.m.
process_identifier:
2396
region_size:
65536
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x5fff0000
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Jan. 9, 2024, 2:47 p.m.
process_identifier:
2396
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x75a86000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Jan. 9, 2024, 2:47 p.m.
process_identifier:
2396
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x75004000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Jan. 9, 2024, 2:47 p.m.
process_identifier:
2396
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x75003000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Jan. 9, 2024, 2:47 p.m.
process_identifier:
2396
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x75005000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Jan. 9, 2024, 2:47 p.m.
process_identifier:
2396
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x75003000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Jan. 9, 2024, 2:47 p.m.
process_identifier:
2396
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6a8f3000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Jan. 9, 2024, 2:47 p.m.
process_identifier:
2396
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x66cd1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Jan. 9, 2024, 2:47 p.m.
process_identifier:
2396
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x66c74000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Jan. 9, 2024, 2:47 p.m.
process_identifier:
1044
region_size:
786432
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x005d0000
allocation_type:
8192
(MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Jan. 9, 2024, 2:47 p.m.
process_identifier:
1044
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00650000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Jan. 9, 2024, 2:47 p.m.
process_identifier:
1044
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x69e91000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Jan. 9, 2024, 2:47 p.m.
process_identifier:
1044
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x003da000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Jan. 9, 2024, 2:47 p.m.
process_identifier:
1044
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x69e92000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Jan. 9, 2024, 2:47 p.m.
process_identifier:
1044
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x003d2000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Jan. 9, 2024, 2:47 p.m.
process_identifier:
1044
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x003e2000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Jan. 9, 2024, 2:47 p.m.
process_identifier:
1044
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x003e3000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Jan. 9, 2024, 2:47 p.m.
process_identifier:
1044
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0045b000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Jan. 9, 2024, 2:47 p.m.
process_identifier:
1044
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00457000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Jan. 9, 2024, 2:47 p.m.
process_identifier:
1044
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x003ec000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Jan. 9, 2024, 2:47 p.m.
process_identifier:
1044
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x003e4000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Jan. 9, 2024, 2:47 p.m.
process_identifier:
1044
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x003e6000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Jan. 9, 2024, 2:47 p.m.
process_identifier:
1044
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x005f0000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Jan. 9, 2024, 2:47 p.m.
process_identifier:
1044
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0044a000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0