NtAllocateVirtualMemory
Sept. 2, 2024, 10:11 a.m.
process_identifier:
1880
region_size:
262144
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x003f0000
allocation_type:
8192
(MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 2, 2024, 10:11 a.m.
process_identifier:
1880
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x003f0000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Sept. 2, 2024, 10:11 a.m.
process_identifier:
1880
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73f31000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Sept. 2, 2024, 10:11 a.m.
process_identifier:
1880
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73f32000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 2, 2024, 10:11 a.m.
process_identifier:
1880
region_size:
1966080
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02170000
allocation_type:
8192
(MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 2, 2024, 10:11 a.m.
process_identifier:
1880
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x02310000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 2, 2024, 10:11 a.m.
process_identifier:
1880
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00462000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 2, 2024, 10:11 a.m.
process_identifier:
1880
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0047c000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 2, 2024, 10:11 a.m.
process_identifier:
1880
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x007f0000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 2, 2024, 10:11 a.m.
process_identifier:
1880
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00495000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 2, 2024, 10:11 a.m.
process_identifier:
1880
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0049b000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 2, 2024, 10:11 a.m.
process_identifier:
1880
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00497000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Sept. 2, 2024, 10:11 a.m.
process_identifier:
1880
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x024a2000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Sept. 2, 2024, 10:11 a.m.
process_identifier:
2092
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x76971000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Sept. 2, 2024, 10:11 a.m.
process_identifier:
2092
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x74fc1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Sept. 2, 2024, 10:11 a.m.
process_identifier:
2092
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x74471000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Sept. 2, 2024, 10:11 a.m.
process_identifier:
2092
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x74451000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Sept. 2, 2024, 10:11 a.m.
process_identifier:
2092
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x743e1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Sept. 2, 2024, 10:11 a.m.
process_identifier:
2092
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x742f1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Sept. 2, 2024, 10:11 a.m.
process_identifier:
2092
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x74001000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Sept. 2, 2024, 10:11 a.m.
process_identifier:
2092
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73341000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Sept. 2, 2024, 10:11 a.m.
process_identifier:
2092
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x732e1000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 2, 2024, 10:11 a.m.
process_identifier:
2092
region_size:
2486069
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x10000000
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
process_handle:
0xffffffff
3221225496
0
NtAllocateVirtualMemory
Sept. 2, 2024, 10:11 a.m.
process_identifier:
2092
region_size:
2486272
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x10580000
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Sept. 2, 2024, 10:11 a.m.
process_identifier:
2092
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x732a1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Sept. 2, 2024, 10:11 a.m.
process_identifier:
2092
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x7327c000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Sept. 2, 2024, 10:11 a.m.
process_identifier:
2092
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x7308b000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Sept. 2, 2024, 10:11 a.m.
process_identifier:
2092
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x72fea000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Sept. 2, 2024, 10:11 a.m.
process_identifier:
2092
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x72f72000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Sept. 2, 2024, 10:11 a.m.
process_identifier:
2092
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x72f43000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Sept. 2, 2024, 10:12 a.m.
process_identifier:
2092
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x72c51000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Sept. 2, 2024, 10:12 a.m.
process_identifier:
2092
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x72b51000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Sept. 2, 2024, 10:12 a.m.
process_identifier:
2092
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x72b41000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Sept. 2, 2024, 10:12 a.m.
process_identifier:
2092
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x72af1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Sept. 2, 2024, 10:12 a.m.
process_identifier:
2092
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x72a11000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Sept. 2, 2024, 10:12 a.m.
process_identifier:
2092
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x72ad1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Sept. 2, 2024, 10:12 a.m.
process_identifier:
2092
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x72ab1000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 2, 2024, 10:12 a.m.
process_identifier:
2700
region_size:
1900544
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00b90000
allocation_type:
8192
(MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 2, 2024, 10:12 a.m.
process_identifier:
2700
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00d20000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Sept. 2, 2024, 10:12 a.m.
process_identifier:
2700
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x71d01000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
Sept. 2, 2024, 10:12 a.m.
process_identifier:
2700
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x71d02000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 2, 2024, 10:12 a.m.
process_identifier:
2700
region_size:
1179648
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00a00000
allocation_type:
8192
(MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 2, 2024, 10:12 a.m.
process_identifier:
2700
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00ae0000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 2, 2024, 10:12 a.m.
process_identifier:
2700
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00432000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 2, 2024, 10:12 a.m.
process_identifier:
2700
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00465000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 2, 2024, 10:12 a.m.
process_identifier:
2700
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0046b000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 2, 2024, 10:12 a.m.
process_identifier:
2700
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00467000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 2, 2024, 10:12 a.m.
process_identifier:
2700
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x0044c000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 2, 2024, 10:12 a.m.
process_identifier:
2700
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x009d0000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
Sept. 2, 2024, 10:12 a.m.
process_identifier:
2700
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00456000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0