Use pDummyBuffer instead of pNewBuffer to avoid send malware buffer to NtReadProcessMemory because usually this function is hooked by EDRs