Summary | ZeroBOX

VideoRecoderDriveMaster.exe

Malicious Packer PE64 PE File
Category Machine Started Completed
FILE s1_win7_x6401 Sept. 20, 2021, 10:13 a.m. Sept. 20, 2021, 10:18 a.m.
Size 8.4MB
Type PE32+ executable (console) x86-64, for MS Windows
MD5 89059c81d1e7400ddfb518e9c7fa026b
SHA256 afe8ce41cfe6aed40a92574505092c6068576d12e8269d7106b5dc895deb8be8
CRC32 A3D2317C
ssdeep 196608:fN9CcArjuqTq4Ka23sJKyILDU//yGd+BtHu3HR4IWg:fNVAIdWQvIX
Yara
  • Malicious_Packer_Zero - Malicious Packer
  • IsPE64 - (no description)
  • PE_Header_Zero - PE File Signature
  • themida_packer - themida packer

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
No hosts contacted.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

section
section .exports
section .imports
section .themida
section .boot
Time & API Arguments Status Return Repeated

__exception__

stacktrace:
RaiseException+0x3d FreeEnvironmentStringsW-0x373 kernelbase+0xa49d @ 0x7fefd6da49d
NvOptimusEnablementCuda+0x48f6be videorecoderdrivemaster+0xbef5f6 @ 0x14088f5f6
NvOptimusEnablementCuda+0x56c27f videorecoderdrivemaster+0xccc1b7 @ 0x14096c1b7
HeapWalk-0x1ce0 kernel32+0x0 @ 0x76e40000
0x121fbb8
0x121fbb8
0x121fbb8
0xdd174
0xa33a1
0xce4c000000030
0xce4c000000030
0xce4c000000030
0xce4c000000030
0xce4c000000030
0xce4c000000030
0xce4c000000030
0xce4c000000030
0xce4c000000030
0xce4c000000030
0xce4c000000030
0xce4c000000030
0xce4c000000030
0xce4c000000030
0xce4c000000030
0xce4c000000030
0xce4c000000030
0xce4c000000030
0xce4c000000030
0xce4c000000030
0xce4c000000030
0xce4c000000030
0xce4c000000030
0xce4c000000030
0xce4c000000030
0xce4c000000030
0xce4c000000030
0xce4c000000030
0xce4c000000030
0xce4c000000030
0xce4c000000030
0xce4c000000030
0xce4c000000030
0xce4c000000030
0xce4c000000030
0xce4c000000030
0xce4c000000030
0xce4c000000030
0xce4c000000030
0xce4c000000030
0xce4c000000030
0xce4c000000030
0xce4c000000030
0xce4c000000030
0xce4c000000030
0xce4c000000030
0xce4c000000030
0xce4c000000030
0xce4c000000030
0xce4c000000030
0xce4c000000030
0xce4c000000030
0xce4c000000030
0xce4c000000030
0xce4c000000030

exception.instruction_r: 48 81 c4 c8 00 00 00 c3 48 85 f6 74 08 83 3b 00
exception.symbol: RaiseException+0x3d FreeEnvironmentStringsW-0x373 kernelbase+0xa49d
exception.instruction: add rsp, 0xc8
exception.module: KERNELBASE.dll
exception.exception_code: 0xc000008e
exception.offset: 42141
exception.address: 0x7fefd6da49d
registers.r14: 0
registers.r15: 0
registers.rcx: 19002544
registers.rsi: 1999256272
registers.r10: 0
registers.rbx: 5375006609
registers.rsp: 19004368
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 19004376
registers.rdi: 5373517824
registers.rax: 1980117671
registers.r13: 0
1 0 0

__exception__

stacktrace:
RtlRestoreContext+0x293 __chkstk-0x1fe ntdll+0x50bd2 @ 0x77210bd2

exception.instruction_r: 48 cf 48 83 ec 30 4c 8b c4 48 81 ec d0 04 00 00
exception.symbol: RtlRestoreContext+0x293 __chkstk-0x1fe ntdll+0x50bd2
exception.instruction: iretq
exception.module: ntdll.dll
exception.exception_code: 0xc0000005
exception.offset: 330706
exception.address: 0x77210bd2
registers.r14: 0
registers.r15: 0
registers.rcx: 19002544
registers.rsi: 0
registers.r10: 0
registers.rbx: 5375006609
registers.rsp: 19004456
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1980117671
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 19002544
registers.rsi: 0
registers.r10: 0
registers.rbx: 5375006609
registers.rsp: 19004456
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1980117671
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 19002544
registers.rsi: 0
registers.r10: 0
registers.rbx: 5375006609
registers.rsp: 19004456
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1980117671
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 19002544
registers.rsi: 0
registers.r10: 0
registers.rbx: 5375006609
registers.rsp: 19004456
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1980117671
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 19002544
registers.rsi: 0
registers.r10: 0
registers.rbx: 5375006609
registers.rsp: 19004456
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1980117671
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 19002544
registers.rsi: 0
registers.r10: 0
registers.rbx: 5375006609
registers.rsp: 19004456
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1980117671
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 19002544
registers.rsi: 0
registers.r10: 0
registers.rbx: 5375006609
registers.rsp: 19004456
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1980117671
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 19002544
registers.rsi: 0
registers.r10: 0
registers.rbx: 5375006609
registers.rsp: 19004456
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1980117671
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 19002544
registers.rsi: 0
registers.r10: 0
registers.rbx: 5375006609
registers.rsp: 19004456
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1980117671
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 19002544
registers.rsi: 0
registers.r10: 0
registers.rbx: 5375006609
registers.rsp: 19004456
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1980117671
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 19002544
registers.rsi: 0
registers.r10: 0
registers.rbx: 5375006609
registers.rsp: 19004456
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1980117671
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 19002544
registers.rsi: 0
registers.r10: 0
registers.rbx: 5375006609
registers.rsp: 19004456
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1980117671
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 19002544
registers.rsi: 0
registers.r10: 0
registers.rbx: 5375006609
registers.rsp: 19004456
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1980117671
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 19002544
registers.rsi: 0
registers.r10: 0
registers.rbx: 5375006609
registers.rsp: 19004456
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1980117671
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 19002544
registers.rsi: 0
registers.r10: 0
registers.rbx: 5375006609
registers.rsp: 19004456
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1980117671
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 19002544
registers.rsi: 0
registers.r10: 0
registers.rbx: 5375006609
registers.rsp: 19004456
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1980117671
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 19002544
registers.rsi: 0
registers.r10: 0
registers.rbx: 5375006609
registers.rsp: 19004456
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1980117671
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 19002544
registers.rsi: 0
registers.r10: 0
registers.rbx: 5375006609
registers.rsp: 19004456
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1980117671
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 19002544
registers.rsi: 0
registers.r10: 0
registers.rbx: 5375006609
registers.rsp: 19004456
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1980117671
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 19002544
registers.rsi: 0
registers.r10: 0
registers.rbx: 5375006609
registers.rsp: 19004456
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1980117671
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 19002544
registers.rsi: 0
registers.r10: 0
registers.rbx: 5375006609
registers.rsp: 19004456
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1980117671
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 19002544
registers.rsi: 0
registers.r10: 0
registers.rbx: 5375006609
registers.rsp: 19004456
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1980117671
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 19002544
registers.rsi: 0
registers.r10: 0
registers.rbx: 5375006609
registers.rsp: 19004456
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1980117671
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 19002544
registers.rsi: 0
registers.r10: 0
registers.rbx: 5375006609
registers.rsp: 19004456
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1980117671
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 19002544
registers.rsi: 0
registers.r10: 0
registers.rbx: 5375006609
registers.rsp: 19004456
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1980117671
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 19002544
registers.rsi: 0
registers.r10: 0
registers.rbx: 5375006609
registers.rsp: 19004456
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1980117671
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 19002544
registers.rsi: 0
registers.r10: 0
registers.rbx: 5375006609
registers.rsp: 19004456
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1980117671
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 19002544
registers.rsi: 0
registers.r10: 0
registers.rbx: 5375006609
registers.rsp: 19004456
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1980117671
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 19002544
registers.rsi: 0
registers.r10: 0
registers.rbx: 5375006609
registers.rsp: 19004456
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1980117671
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 19002544
registers.rsi: 0
registers.r10: 0
registers.rbx: 5375006609
registers.rsp: 19004456
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1980117671
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 19002544
registers.rsi: 0
registers.r10: 0
registers.rbx: 5375006609
registers.rsp: 19004456
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1980117671
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 19002544
registers.rsi: 0
registers.r10: 0
registers.rbx: 5375006609
registers.rsp: 19004456
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1980117671
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 19002544
registers.rsi: 0
registers.r10: 0
registers.rbx: 5375006609
registers.rsp: 19004456
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1980117671
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 19002544
registers.rsi: 0
registers.r10: 0
registers.rbx: 5375006609
registers.rsp: 19004456
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1980117671
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 19002544
registers.rsi: 0
registers.r10: 0
registers.rbx: 5375006609
registers.rsp: 19004456
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1980117671
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 19002544
registers.rsi: 0
registers.r10: 0
registers.rbx: 5375006609
registers.rsp: 19004456
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1980117671
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 19002544
registers.rsi: 0
registers.r10: 0
registers.rbx: 5375006609
registers.rsp: 19004456
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1980117671
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 19002544
registers.rsi: 0
registers.r10: 0
registers.rbx: 5375006609
registers.rsp: 19004456
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1980117671
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 19002544
registers.rsi: 0
registers.r10: 0
registers.rbx: 5375006609
registers.rsp: 19004456
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1980117671
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 19002544
registers.rsi: 0
registers.r10: 0
registers.rbx: 5375006609
registers.rsp: 19004456
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1980117671
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 19002544
registers.rsi: 0
registers.r10: 0
registers.rbx: 5375006609
registers.rsp: 19004456
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1980117671
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 19002544
registers.rsi: 0
registers.r10: 0
registers.rbx: 5375006609
registers.rsp: 19004456
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1980117671
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 19002544
registers.rsi: 0
registers.r10: 0
registers.rbx: 5375006609
registers.rsp: 19004456
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1980117671
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 19002544
registers.rsi: 0
registers.r10: 0
registers.rbx: 5375006609
registers.rsp: 19004456
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1980117671
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 19002544
registers.rsi: 0
registers.r10: 0
registers.rbx: 5375006609
registers.rsp: 19004456
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1980117671
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 19002544
registers.rsi: 0
registers.r10: 0
registers.rbx: 5375006609
registers.rsp: 19004456
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1980117671
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 19002544
registers.rsi: 0
registers.r10: 0
registers.rbx: 5375006609
registers.rsp: 19004456
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1980117671
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 19002544
registers.rsi: 0
registers.r10: 0
registers.rbx: 5375006609
registers.rsp: 19004456
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1980117671
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 19002544
registers.rsi: 0
registers.r10: 0
registers.rbx: 5375006609
registers.rsp: 19004456
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1980117671
registers.r13: 0
1 0 0
section {u'size_of_data': u'0x001b753c', u'virtual_address': u'0x00001000', u'entropy': 7.983957332587296, u'name': u' ', u'virtual_size': u'0x0041be9c'} entropy 7.98395733259 description A section with a high entropy has been found
section {u'size_of_data': u'0x002e55ba', u'virtual_address': u'0x0041d000', u'entropy': 7.927783415997059, u'name': u' ', u'virtual_size': u'0x00340b88'} entropy 7.927783416 description A section with a high entropy has been found
section {u'size_of_data': u'0x0001169e', u'virtual_address': u'0x0075e000', u'entropy': 7.955298225168292, u'name': u' ', u'virtual_size': u'0x0005f474'} entropy 7.95529822517 description A section with a high entropy has been found
section {u'size_of_data': u'0x00017207', u'virtual_address': u'0x007be000', u'entropy': 7.682596231803151, u'name': u' ', u'virtual_size': u'0x00028140'} entropy 7.6825962318 description A section with a high entropy has been found
section {u'size_of_data': u'0x0000063c', u'virtual_address': u'0x007e8000', u'entropy': 7.69611681636254, u'name': u' ', u'virtual_size': u'0x00000f3c'} entropy 7.69611681636 description A section with a high entropy has been found
section {u'size_of_data': u'0x0000010b', u'virtual_address': u'0x007e9000', u'entropy': 7.072954581401555, u'name': u' ', u'virtual_size': u'0x000001e0'} entropy 7.0729545814 description A section with a high entropy has been found
section {u'size_of_data': u'0x000022b9', u'virtual_address': u'0x007ea000', u'entropy': 7.900101085292587, u'name': u' ', u'virtual_size': u'0x00007ecc'} entropy 7.90010108529 description A section with a high entropy has been found
section {u'size_of_data': u'0x0039d400', u'virtual_address': u'0x00e04000', u'entropy': 7.957998223794811, u'name': u'.boot', u'virtual_size': u'0x0039d400'} entropy 7.95799822379 description A section with a high entropy has been found
entropy 0.999706313277 description Overall entropy of this PE file is high
Time & API Arguments Status Return Repeated

__anomaly__

tid: 1836
message: Encountered 65537 exceptions, quitting.
subcategory: exception
function_name:
1 0 0
Elastic malicious (high confidence)
MicroWorld-eScan Gen:Variant.Mikey.126019
Sangfor Suspicious.Win32.Save.a
Cybereason malicious.1d1e74
ESET-NOD32 a variant of Win64/CoinMiner.KT potentially unwanted
APEX Malicious
Kaspersky not-a-virus:HEUR:RiskTool.Win64.Miner.gen
BitDefender Gen:Variant.Mikey.126019
Avast Win64:MiscX-gen [PUP]
Ad-Aware Gen:Variant.Mikey.126019
Sophos Generic ML PUA (PUA)
McAfee-GW-Edition BehavesLike.Win64.Trickbot.rc
FireEye Generic.mg.89059c81d1e7400d
Emsisoft Gen:Variant.Mikey.126019 (B)
SentinelOne Static AI - Malicious PE
Avira HEUR/AGEN.1141501
MAX malware (ai score=87)
Microsoft Program:Win32/Wacapew.C!ml
Gridinsoft Trojan.Heur!.032500A3
ZoneAlarm not-a-virus:HEUR:RiskTool.Win64.Miner.gen
GData Gen:Variant.Mikey.126019
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win64.CoinMiner.R266451
ALYac Gen:Variant.Mikey.126019
Malwarebytes Trojan.BitCoinMiner
Fortinet Riskware/CoinMiner
AVG Win64:MiscX-gen [PUP]
MaxSecure Trojan.Malware.300983.susgen