Summary | ZeroBOX

123.exe

Generic Malware Anti_VM PE32 PE File .NET EXE
Category Machine Started Completed
FILE s1_win7_x6402 Aug. 19, 2021, 9:36 a.m. Aug. 19, 2021, 9:49 a.m.
Size 3.7MB
Type PE32 executable (console) Intel 80386, for MS Windows
MD5 f9fd13cdacab6e8e8a57b6d48c2434f4
SHA256 90ef06ea132c91802abc50611fd1201c3158ea52c47e97829ab87b48729a26b7
CRC32 75FB3F96
ssdeep 98304:T52fFWXjiXTTclL2UUNgUMl6i13ctPRrZ9rm7D6otP9Kg:T0NIiX/cUUUNjWaJ/R8P9b
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • anti_vm_detect - Possibly employs anti-virtualization techniques
  • Is_DotNET_EXE - (no description)
  • IsPE32 - (no description)
  • themida_packer - themida packer

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
164.124.101.2 Active Moloch
45.67.228.87 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Time & API Arguments Status Return Repeated

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0
Time & API Arguments Status Return Repeated

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x005f9948
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x005f9948
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x005f9988
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0
Time & API Arguments Status Return Repeated

GlobalMemoryStatusEx

1 1 0
section
section \xf0\x9f\x87\xae\xf0\x9f\x87\xb9
section .themida
section .boot
Time & API Arguments Status Return Repeated

__exception__

stacktrace:
123+0x4af155 @ 0x12ef155
123+0x4b83e6 @ 0x12f83e6

exception.instruction_r: c9 c2 10 00 cc cc cc cc cc e9 7a 5b 98 8b 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.instruction: leave
exception.module: KERNELBASE.dll
exception.exception_code: 0xc000008e
exception.offset: 46887
exception.address: 0x7566b727
registers.esp: 2490100
registers.edi: 15360000
registers.eax: 2490100
registers.ebp: 2490180
registers.edx: 2130566132
registers.ebx: 0
registers.esi: 2008380459
registers.ecx: 3951558656
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: ed e9 06 0e 18 00 78 00 4c 02 f9 ff c9 01 bc ff
exception.symbol: 123+0x3475ee
exception.instruction: in eax, dx
exception.module: 123.exe
exception.exception_code: 0xc0000096
exception.offset: 3438062
exception.address: 0x11875ee
registers.esp: 2490220
registers.edi: 18606388
registers.eax: 1750617430
registers.ebp: 15360000
registers.edx: 2130532438
registers.ebx: 0
registers.esi: 17631212
registers.ecx: 20
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: ed e9 56 a1 02 00 c3 e9 dd e6 02 00 ae 18 7d 43
exception.symbol: 123+0x4a619c
exception.instruction: in eax, dx
exception.module: 123.exe
exception.exception_code: 0xc0000096
exception.offset: 4874652
exception.address: 0x12e619c
registers.esp: 2490220
registers.edi: 18606388
registers.eax: 1447909480
registers.ebp: 15360000
registers.edx: 22104
registers.ebx: 2256917605
registers.esi: 17631212
registers.ecx: 10
1 0 0
Time & API Arguments Status Return Repeated

NtProtectVirtualMemory

process_identifier: 1428
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x76a44000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1428
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x75671000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1428
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x76a5c000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1428
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x75671000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1428
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x76a43000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1428
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x75671000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1428
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x76a41000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1428
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x75671000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1428
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x76a47000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1428
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x7566e000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1428
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x76a43000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1428
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x7567b000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1428
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x76a45000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1428
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x7567b000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1428
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x76a41000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1428
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x7566d000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1428
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x76a45000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1428
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x7566c000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1428
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x76a45000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1428
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x7566b000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1428
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x76a41000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1428
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x75671000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1428
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x76a44000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1428
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x75670000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1428
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x76a41000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1428
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x75671000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1428
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x76a41000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1428
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x7566d000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1428
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x76a5a000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1428
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x770d3000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1428
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x76abf000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1428
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x76a6c000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1428
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x7566b000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1428
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x76a6d000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1428
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x7566c000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1428
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x76a45000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1428
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x76a5c000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1428
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x76a63000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1428
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x76a68000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1428
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x76abe000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1428
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x76a65000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1428
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x76a43000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1428
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x75671000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1428
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x76a44000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1428
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x75678000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1428
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x76a41000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1428
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x75678000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1428
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x76a6c000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1428
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x75678000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1428
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x76a45000
process_handle: 0xffffffff
1 0 0
description 123.exe tried to sleep 195 seconds, actually delayed analysis time by 195 seconds
Time & API Arguments Status Return Repeated

GetAdaptersAddresses

flags: 15
family: 0
111 0
section {u'size_of_data': u'0x00016e00', u'virtual_address': u'0x00002000', u'entropy': 7.988265243065631, u'name': u' ', u'virtual_size': u'0x0002e000'} entropy 7.98826524307 description A section with a high entropy has been found
section {u'size_of_data': u'0x00000800', u'virtual_address': u'0x00030000', u'entropy': 7.450190695372962, u'name': u' ', u'virtual_size': u'0x0000102a'} entropy 7.45019069537 description A section with a high entropy has been found
section {u'size_of_data': u'0x0002ea00', u'virtual_address': u'0x00032000', u'entropy': 7.99898732295391, u'name': u'\\xf0\\x9f\\x87\\xae\\xf0\\x9f\\x87\\xb9', u'virtual_size': u'0x0002e9f8'} entropy 7.99898732295 description A section with a high entropy has been found
section {u'size_of_data': u'0x0033aa00', u'virtual_address': u'0x00548000', u'entropy': 7.934186684860236, u'name': u'.boot', u'virtual_size': u'0x0033aa00'} entropy 7.93418668486 description A section with a high entropy has been found
section {u'size_of_data': u'0x00000a00', u'virtual_address': u'0x00884000', u'entropy': 7.295794166009077, u'name': u'\\xf0\\x9f\\x87\\xae\\xf0\\x9f\\x87\\xb9', u'virtual_size': u'0x000008d0'} entropy 7.29579416601 description A section with a high entropy has been found
entropy 0.94821664465 description Overall entropy of this PE file is high
host 45.67.228.87
Time & API Arguments Status Return Repeated

FindWindowA

class_name: FilemonClass
window_name:
0 0

FindWindowA

class_name: FilemonClass
window_name:
0 0

FindWindowA

class_name: File Monitor - Sysinternals: www.sysinternals.com
window_name:
0 0

FindWindowA

class_name: PROCMON_WINDOW_CLASS
window_name:
0 0

FindWindowA

class_name: Process Monitor - Sysinternals: www.sysinternals.com
window_name:
0 0

FindWindowA

class_name: RegmonClass
window_name:
0 0

FindWindowA

class_name: RegmonClass
window_name:
0 0

FindWindowA

class_name: Registry Monitor - Sysinternals: www.sysinternals.com
window_name:
0 0

FindWindowA

class_name: 18467-41
window_name:
0 0

FindWindowA

class_name: Regmonclass
window_name:
0 0

FindWindowA

class_name: Regmonclass
window_name:
0 0

FindWindowA

class_name: 18467-41
window_name:
0 0

FindWindowA

class_name: Filemonclass
window_name:
0 0

FindWindowA

class_name: Filemonclass
window_name:
0 0

FindWindowA

class_name: PROCMON_WINDOW_CLASS
window_name:
0 0

FindWindowA

class_name: Regmonclass
window_name:
0 0

FindWindowA

class_name: Regmonclass
window_name:
0 0

FindWindowA

class_name: 18467-41
window_name:
0 0

FindWindowA

class_name: Filemonclass
window_name:
0 0

FindWindowA

class_name: Filemonclass
window_name:
0 0

FindWindowA

class_name: PROCMON_WINDOW_CLASS
window_name:
0 0

FindWindowA

class_name: Regmonclass
window_name:
0 0

FindWindowA

class_name: Regmonclass
window_name:
0 0

FindWindowA

class_name: 18467-41
window_name:
0 0

FindWindowA

class_name: Filemonclass
window_name:
0 0

FindWindowA

class_name: Filemonclass
window_name:
0 0

FindWindowA

class_name: PROCMON_WINDOW_CLASS
window_name:
0 0

FindWindowA

class_name: Regmonclass
window_name:
0 0

FindWindowA

class_name: Regmonclass
window_name:
0 0

FindWindowA

class_name: 18467-41
window_name:
0 0

FindWindowA

class_name: Filemonclass
window_name:
0 0

FindWindowA

class_name: Filemonclass
window_name:
0 0

FindWindowA

class_name: PROCMON_WINDOW_CLASS
window_name:
0 0

FindWindowA

class_name: Regmonclass
window_name:
0 0

FindWindowA

class_name: Regmonclass
window_name:
0 0

FindWindowA

class_name: 18467-41
window_name:
0 0

FindWindowA

class_name: Filemonclass
window_name:
0 0

FindWindowA

class_name: Filemonclass
window_name:
0 0

FindWindowA

class_name: PROCMON_WINDOW_CLASS
window_name:
0 0

FindWindowA

class_name: Regmonclass
window_name:
0 0

FindWindowA

class_name: Regmonclass
window_name:
0 0

FindWindowA

class_name: 18467-41
window_name:
0 0

FindWindowA

class_name: Filemonclass
window_name:
0 0

FindWindowA

class_name: Filemonclass
window_name:
0 0

FindWindowA

class_name: PROCMON_WINDOW_CLASS
window_name:
0 0

FindWindowA

class_name: Regmonclass
window_name:
0 0

FindWindowA

class_name: Regmonclass
window_name:
0 0

FindWindowA

class_name: 18467-41
window_name:
0 0

FindWindowA

class_name: Filemonclass
window_name:
0 0

FindWindowA

class_name: Filemonclass
window_name:
0 0
registry HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\SystemBiosVersion
registry HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\VideoBiosVersion
Time & API Arguments Status Return Repeated

NtQuerySystemInformation

information_class: 76 (SystemFirmwareTableInformation)
3221225507 0
Time & API Arguments Status Return Repeated

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: ed e9 56 a1 02 00 c3 e9 dd e6 02 00 ae 18 7d 43
exception.symbol: 123+0x4a619c
exception.instruction: in eax, dx
exception.module: 123.exe
exception.exception_code: 0xc0000096
exception.offset: 4874652
exception.address: 0x12e619c
registers.esp: 2490220
registers.edi: 18606388
registers.eax: 1447909480
registers.ebp: 15360000
registers.edx: 22104
registers.ebx: 2256917605
registers.esi: 17631212
registers.ecx: 10
1 0 0
Lionic Trojan.Win32.Generic.4!c
Elastic malicious (high confidence)
Qihoo-360 Win32/Trojan.Generic.HxMBWj8A
Sangfor Trojan.Win32.Save.a
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Generik.MECOXIR
APEX Malicious
Paloalto generic.ml
Kaspersky UDS:DangerousObject.Multi.Generic
NANO-Antivirus Virus.Win32.Gen-Crypt.ccnc
Avast FileRepMalware
McAfee-GW-Edition Artemis!Trojan
FireEye Generic.mg.f9fd13cdacab6e8e
Kingsoft Win32.Heur.KVMH008.a.(kcloud)
Gridinsoft Trojan.Heur!.012126B1
Microsoft Trojan:Win32/Sabsik.TE.B!ml
GData MSIL.Trojan-Stealer.NetSteal.X3JFFQ
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win.Generic.R429793
McAfee Artemis!F9FD13CDACAB
VBA32 BScope.Trojan.Wacatac
Rising Trojan.Generic@ML.83 (RDML:onlItLC6hLq0pumle46Cxw)
SentinelOne Static AI - Suspicious PE
eGambit PE.Heur.InvalidSig
AVG FileRepMalware
MaxSecure Trojan.Malware.300983.susgen
dead_host 45.67.228.87:58067