NtProtectVirtualMemory
Feb. 7, 2024, 7:53 a.m.
process_identifier:
2556
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x734c2000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Feb. 7, 2024, 7:53 a.m.
process_identifier:
2556
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02b20000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Feb. 7, 2024, 7:53 a.m.
process_identifier:
2616
region_size:
9637888
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02e80000
allocation_type:
8192
(MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Feb. 7, 2024, 7:53 a.m.
process_identifier:
2616
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x037b0000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Feb. 7, 2024, 7:53 a.m.
process_identifier:
2616
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x758af000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Feb. 7, 2024, 7:53 a.m.
process_identifier:
2616
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x758af000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Feb. 7, 2024, 7:53 a.m.
process_identifier:
2616
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x758af000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Feb. 7, 2024, 7:53 a.m.
process_identifier:
2616
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x758af000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Feb. 7, 2024, 7:53 a.m.
process_identifier:
2616
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x7587c000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Feb. 7, 2024, 7:53 a.m.
process_identifier:
2616
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x7589c000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Feb. 7, 2024, 7:53 a.m.
process_identifier:
2616
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x7587c000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Feb. 7, 2024, 7:53 a.m.
process_identifier:
2616
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x7589c000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Feb. 7, 2024, 7:53 a.m.
process_identifier:
2616
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73783000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Feb. 7, 2024, 7:53 a.m.
process_identifier:
2616
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73827000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Feb. 7, 2024, 7:53 a.m.
process_identifier:
2616
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x757c9000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Feb. 7, 2024, 7:53 a.m.
process_identifier:
2616
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x75522000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Feb. 7, 2024, 7:53 a.m.
process_identifier:
2616
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x75862000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Feb. 7, 2024, 7:53 a.m.
process_identifier:
2616
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x758af000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Feb. 7, 2024, 7:53 a.m.
process_identifier:
2616
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x758af000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Feb. 7, 2024, 7:53 a.m.
process_identifier:
2616
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x758af000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Feb. 7, 2024, 7:53 a.m.
process_identifier:
2616
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x03460000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Feb. 7, 2024, 7:53 a.m.
process_identifier:
2616
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x734c2000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Feb. 7, 2024, 7:54 a.m.
process_identifier:
2616
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6f861000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Feb. 7, 2024, 7:53 a.m.
process_identifier:
2716
region_size:
4591616
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x03060000
allocation_type:
8192
(MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Feb. 7, 2024, 7:53 a.m.
process_identifier:
2716
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x034c0000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Feb. 7, 2024, 7:53 a.m.
process_identifier:
2716
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x758af000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Feb. 7, 2024, 7:53 a.m.
process_identifier:
2716
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x758af000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Feb. 7, 2024, 7:53 a.m.
process_identifier:
2716
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x758af000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Feb. 7, 2024, 7:53 a.m.
process_identifier:
2716
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x758af000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Feb. 7, 2024, 7:53 a.m.
process_identifier:
2716
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x7587c000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Feb. 7, 2024, 7:53 a.m.
process_identifier:
2716
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x7589c000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Feb. 7, 2024, 7:53 a.m.
process_identifier:
2716
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x7587c000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Feb. 7, 2024, 7:53 a.m.
process_identifier:
2716
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x7589c000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Feb. 7, 2024, 7:53 a.m.
process_identifier:
2716
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73783000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Feb. 7, 2024, 7:53 a.m.
process_identifier:
2716
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73827000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Feb. 7, 2024, 7:53 a.m.
process_identifier:
2716
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x757c9000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Feb. 7, 2024, 7:53 a.m.
process_identifier:
2716
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x75522000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Feb. 7, 2024, 7:53 a.m.
process_identifier:
2716
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x75862000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Feb. 7, 2024, 7:53 a.m.
process_identifier:
2716
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x75867000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Feb. 7, 2024, 7:53 a.m.
process_identifier:
2716
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x7587f000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Feb. 7, 2024, 7:53 a.m.
process_identifier:
2716
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x75866000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Feb. 7, 2024, 7:53 a.m.
process_identifier:
2716
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x755c3000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Feb. 7, 2024, 7:53 a.m.
process_identifier:
2716
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x76f6d000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Feb. 7, 2024, 7:53 a.m.
process_identifier:
2716
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x755c7000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Feb. 7, 2024, 7:53 a.m.
process_identifier:
2716
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x75858000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Feb. 7, 2024, 7:53 a.m.
process_identifier:
2716
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x7585d000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Feb. 7, 2024, 7:53 a.m.
process_identifier:
2716
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x76f52000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Feb. 7, 2024, 7:53 a.m.
process_identifier:
2716
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x76f42000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Feb. 7, 2024, 7:53 a.m.
process_identifier:
2716
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x746c6000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Feb. 7, 2024, 7:53 a.m.
process_identifier:
2716
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x75764000
process_handle:
0xffffffff
1
0
0