NtAllocateVirtualMemory
June 25, 2024, 5:18 a.m.
process_identifier:
1712
region_size:
331776
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0000000002c00000
allocation_type:
8192
(MEM_RESERVE)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
June 25, 2024, 5:18 a.m.
process_identifier:
1712
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0000000002c50000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
June 25, 2024, 5:18 a.m.
process_identifier:
1712
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00000000772b1000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
June 25, 2024, 5:18 a.m.
process_identifier:
1712
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00000000772b1000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
June 25, 2024, 5:18 a.m.
process_identifier:
1712
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00000000772b1000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
June 25, 2024, 5:18 a.m.
process_identifier:
1712
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00000000772b1000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
June 25, 2024, 5:18 a.m.
process_identifier:
1712
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00000000772b1000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
June 25, 2024, 5:18 a.m.
process_identifier:
1712
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00000000772b1000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
June 25, 2024, 5:18 a.m.
process_identifier:
1712
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000000007725d000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
June 25, 2024, 5:18 a.m.
process_identifier:
1712
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0000000077282000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
June 25, 2024, 5:18 a.m.
process_identifier:
1712
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0000000077264000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
June 25, 2024, 5:18 a.m.
process_identifier:
1712
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0000000077282000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
June 25, 2024, 5:18 a.m.
process_identifier:
1712
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fefc7d5000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
June 25, 2024, 5:18 a.m.
process_identifier:
1712
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fefc7d5000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
June 25, 2024, 5:18 a.m.
process_identifier:
1712
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fefe4f4000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
June 25, 2024, 5:18 a.m.
process_identifier:
1712
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007feff871000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
June 25, 2024, 5:18 a.m.
process_identifier:
1712
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000000007724a000
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
June 25, 2024, 5:18 a.m.
process_identifier:
1712
region_size:
65536
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0000000002f40000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
June 25, 2024, 5:19 a.m.
process_identifier:
1712
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fef16e9000
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
June 25, 2024, 5:18 a.m.
process_identifier:
2084
region_size:
10424320
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00000000021a0000
allocation_type:
8192
(MEM_RESERVE)
process_handle:
0xffffffffffffffff
1
0
0
NtAllocateVirtualMemory
June 25, 2024, 5:18 a.m.
process_identifier:
2084
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0000000002b90000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
June 25, 2024, 5:18 a.m.
process_identifier:
2084
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00000000772b1000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
June 25, 2024, 5:18 a.m.
process_identifier:
2084
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00000000772b1000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
June 25, 2024, 5:18 a.m.
process_identifier:
2084
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00000000772b1000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
June 25, 2024, 5:18 a.m.
process_identifier:
2084
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00000000772b1000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
June 25, 2024, 5:18 a.m.
process_identifier:
2084
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00000000772b1000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
June 25, 2024, 5:18 a.m.
process_identifier:
2084
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00000000772b1000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
June 25, 2024, 5:18 a.m.
process_identifier:
2084
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000000007725d000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
June 25, 2024, 5:18 a.m.
process_identifier:
2084
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0000000077282000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
June 25, 2024, 5:18 a.m.
process_identifier:
2084
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0000000077264000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
June 25, 2024, 5:18 a.m.
process_identifier:
2084
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0000000077282000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
June 25, 2024, 5:18 a.m.
process_identifier:
2084
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fefc7d5000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
June 25, 2024, 5:18 a.m.
process_identifier:
2084
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fefc7d5000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
June 25, 2024, 5:18 a.m.
process_identifier:
2084
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fefe4f4000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
June 25, 2024, 5:18 a.m.
process_identifier:
2084
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007feff871000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
June 25, 2024, 5:18 a.m.
process_identifier:
2084
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000000007724a000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
June 25, 2024, 5:18 a.m.
process_identifier:
2084
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000000007724f000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
June 25, 2024, 5:18 a.m.
process_identifier:
2084
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000000007724d000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
June 25, 2024, 5:18 a.m.
process_identifier:
2084
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000000007724b000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
June 25, 2024, 5:18 a.m.
process_identifier:
2084
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0000000076fd6000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
June 25, 2024, 5:18 a.m.
process_identifier:
2084
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0000000077706000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
June 25, 2024, 5:18 a.m.
process_identifier:
2084
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0000000076fd1000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
June 25, 2024, 5:18 a.m.
process_identifier:
2084
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0000000077250000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
June 25, 2024, 5:18 a.m.
process_identifier:
2084
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000000007724a000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
June 25, 2024, 5:18 a.m.
process_identifier:
2084
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00000000776df000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
June 25, 2024, 5:18 a.m.
process_identifier:
2084
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00000000776eb000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
June 25, 2024, 5:18 a.m.
process_identifier:
2084
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fefe1a7000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
June 25, 2024, 5:18 a.m.
process_identifier:
2084
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fefe494000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
June 25, 2024, 5:18 a.m.
process_identifier:
2084
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fefe491000
process_handle:
0xffffffffffffffff
1
0
0
NtProtectVirtualMemory
June 25, 2024, 5:18 a.m.
process_identifier:
2084
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x000007fefe496000
process_handle:
0xffffffffffffffff
1
0
0