NtAllocateVirtualMemory
July 7, 2024, 7:07 p.m.
process_identifier:
2052
region_size:
12062720
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02840000
allocation_type:
8192
(MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
July 7, 2024, 7:07 p.m.
process_identifier:
2052
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x033c0000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 7, 2024, 7:07 p.m.
process_identifier:
2052
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x7564f000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 7, 2024, 7:07 p.m.
process_identifier:
2052
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x7564f000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 7, 2024, 7:07 p.m.
process_identifier:
2052
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x7564f000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 7, 2024, 7:07 p.m.
process_identifier:
2052
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x7564f000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 7, 2024, 7:07 p.m.
process_identifier:
2052
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x7561c000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 7, 2024, 7:07 p.m.
process_identifier:
2052
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x7563c000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 7, 2024, 7:07 p.m.
process_identifier:
2052
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x7561c000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 7, 2024, 7:07 p.m.
process_identifier:
2052
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x7563c000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 7, 2024, 7:07 p.m.
process_identifier:
2052
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x74713000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 7, 2024, 7:07 p.m.
process_identifier:
2052
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x747b7000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 7, 2024, 7:07 p.m.
process_identifier:
2052
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x76af9000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 7, 2024, 7:07 p.m.
process_identifier:
2052
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x75ac2000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 7, 2024, 7:07 p.m.
process_identifier:
2052
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x75602000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 7, 2024, 7:07 p.m.
process_identifier:
2052
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x7564f000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 7, 2024, 7:07 p.m.
process_identifier:
2052
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x7564f000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 7, 2024, 7:07 p.m.
process_identifier:
2052
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x7564f000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
July 7, 2024, 7:07 p.m.
process_identifier:
2052
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x01360000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 7, 2024, 7:08 p.m.
process_identifier:
2052
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x701d1000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
July 7, 2024, 7:07 p.m.
process_identifier:
2160
region_size:
7671808
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02f00000
allocation_type:
8192
(MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
July 7, 2024, 7:07 p.m.
process_identifier:
2160
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x03650000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 7, 2024, 7:07 p.m.
process_identifier:
2160
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x7564f000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 7, 2024, 7:07 p.m.
process_identifier:
2160
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x7564f000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 7, 2024, 7:07 p.m.
process_identifier:
2160
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x7564f000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 7, 2024, 7:07 p.m.
process_identifier:
2160
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x7564f000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 7, 2024, 7:07 p.m.
process_identifier:
2160
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x7561c000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 7, 2024, 7:07 p.m.
process_identifier:
2160
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x7563c000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 7, 2024, 7:07 p.m.
process_identifier:
2160
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x7561c000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 7, 2024, 7:07 p.m.
process_identifier:
2160
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x7563c000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 7, 2024, 7:07 p.m.
process_identifier:
2160
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x74713000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 7, 2024, 7:07 p.m.
process_identifier:
2160
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x747b7000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 7, 2024, 7:07 p.m.
process_identifier:
2160
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x76af9000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 7, 2024, 7:07 p.m.
process_identifier:
2160
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x75ac2000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 7, 2024, 7:07 p.m.
process_identifier:
2160
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x75602000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 7, 2024, 7:07 p.m.
process_identifier:
2160
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x75607000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 7, 2024, 7:07 p.m.
process_identifier:
2160
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x7561f000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 7, 2024, 7:07 p.m.
process_identifier:
2160
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x75606000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 7, 2024, 7:07 p.m.
process_identifier:
2160
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x757f3000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 7, 2024, 7:07 p.m.
process_identifier:
2160
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x778fd000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 7, 2024, 7:07 p.m.
process_identifier:
2160
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x757f7000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 7, 2024, 7:07 p.m.
process_identifier:
2160
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x755f8000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 7, 2024, 7:07 p.m.
process_identifier:
2160
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x755fd000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 7, 2024, 7:07 p.m.
process_identifier:
2160
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x778e2000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 7, 2024, 7:07 p.m.
process_identifier:
2160
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x778d2000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 7, 2024, 7:07 p.m.
process_identifier:
2160
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x75b36000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 7, 2024, 7:07 p.m.
process_identifier:
2160
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x76a94000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 7, 2024, 7:07 p.m.
process_identifier:
2160
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x76a93000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 7, 2024, 7:07 p.m.
process_identifier:
2160
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x76a95000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
July 7, 2024, 7:07 p.m.
process_identifier:
2160
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x76a93000
process_handle:
0xffffffff
1
0
0