NtProtectVirtualMemory
March 21, 2021, 10:29 a.m.
process_identifier:
7956
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x6c149000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
March 21, 2021, 10:29 a.m.
process_identifier:
7956
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x74841000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
March 21, 2021, 10:29 a.m.
process_identifier:
7956
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x72321000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
March 21, 2021, 10:29 a.m.
process_identifier:
7956
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x778e1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
March 21, 2021, 10:29 a.m.
process_identifier:
7956
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x77631000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
March 21, 2021, 10:29 a.m.
process_identifier:
7956
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x724b1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
March 21, 2021, 10:29 a.m.
process_identifier:
7956
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x721a4000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
March 21, 2021, 10:29 a.m.
process_identifier:
7956
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x72322000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
March 21, 2021, 10:29 a.m.
process_identifier:
7956
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x74551000
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
March 21, 2021, 10:29 a.m.
process_identifier:
7956
region_size:
225280
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x01a90000
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
March 21, 2021, 10:29 a.m.
process_identifier:
7956
region_size:
274432
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x01de0000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
March 21, 2021, 10:29 a.m.
process_identifier:
7956
region_size:
135168
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x01e40000
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
March 21, 2021, 10:29 a.m.
process_identifier:
7956
region_size:
139264
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00400000
allocation_type:
8192
(MEM_RESERVE)
process_handle:
0xffffffff
3221225496
0
NtAllocateVirtualMemory
March 21, 2021, 10:29 a.m.
process_identifier:
7956
region_size:
139264
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x01e70000
allocation_type:
8192
(MEM_RESERVE)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
March 21, 2021, 10:29 a.m.
process_identifier:
7956
region_size:
122880
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x01e71000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
March 21, 2021, 10:29 a.m.
process_identifier:
7956
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x01e8f000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
March 21, 2021, 10:29 a.m.
process_identifier:
7956
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x01e91000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtAllocateVirtualMemory
March 21, 2021, 10:29 a.m.
process_identifier:
7956
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x01af0000
allocation_type:
4096
(MEM_COMMIT)
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
March 21, 2021, 10:29 a.m.
process_identifier:
7956
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x77681000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
March 21, 2021, 10:29 a.m.
process_identifier:
7956
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x75791000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
March 21, 2021, 10:29 a.m.
process_identifier:
7956
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x75771000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
March 21, 2021, 10:29 a.m.
process_identifier:
7956
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x71f11000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
March 21, 2021, 10:29 a.m.
process_identifier:
7956
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x71e91000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
March 21, 2021, 10:29 a.m.
process_identifier:
7956
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x73e21000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
March 21, 2021, 10:29 a.m.
process_identifier:
7956
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x75c61000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
March 21, 2021, 10:29 a.m.
process_identifier:
7956
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x75661000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
March 21, 2021, 10:29 a.m.
process_identifier:
7956
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x75301000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
March 21, 2021, 10:29 a.m.
process_identifier:
7956
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x75e61000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
March 21, 2021, 10:29 a.m.
process_identifier:
7956
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x75661000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
March 21, 2021, 10:29 a.m.
process_identifier:
7956
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x75341000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
March 21, 2021, 10:29 a.m.
process_identifier:
7956
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x75621000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
March 21, 2021, 10:29 a.m.
process_identifier:
7956
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x71e71000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
March 21, 2021, 10:29 a.m.
process_identifier:
7956
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x754e1000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
March 21, 2021, 10:29 a.m.
process_identifier:
7956
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x75471000
process_handle:
0xffffffff
1
0
0
NtProtectVirtualMemory
March 21, 2021, 10:29 a.m.
process_identifier:
7956
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x75981000
process_handle:
0xffffffff
1
0
0