Summary | ZeroBOX

lv.exe

Emotet Gen1 Generic Malware Malicious Library UPX Malicious Packer Anti_VM PE64 PE File PE32 DLL
Category Machine Started Completed
FILE s1_win7_x6401 Sept. 29, 2021, 10:05 a.m. Sept. 29, 2021, 10:15 a.m.
Size 4.4MB
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 1814662fda4a0aa4816c124a0fa12002
SHA256 92882d39873b86b9febece1c865a245aabdd7d5c44da54931d25a6e3d9e25670
CRC32 C1FBC0E9
ssdeep 98304:9ZKagY6llt6YTg5Wcc9G/CfgEgZEKZd/Xu5lZD6/+hZXkRIPL4gU4l+:94eg6qcPCfgEgiKu5DrXKIPL4gUD
Yara
  • PE_Header_Zero - PE File Signature
  • Malicious_Library_Zero - Malicious_Library
  • IsPE32 - (no description)

Name Response Post-Analysis Lookup
DoZGPUipbFiATyjSqFFatx.DoZGPUipbFiATyjSqFFatx
IP Address Status Action
164.124.101.2 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Time & API Arguments Status Return Repeated

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0
Time & API Arguments Status Return Repeated

WriteConsoleW

buffer: Microsoft Windows [Version 6.1.7601]
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Copyright (c) 2009 Microsoft Corporation. All rights reserved.
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp\IXP000.TMP>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Set WOMRxkUVXoVFDGpLCKv=DESKTOP-
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp\IXP000.TMP>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Set VnzmQGwlhjaiJVA=QO5QU33
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp\IXP000.TMP>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Set QEjEWUraBNWYxsLwUacYJNu=ping 127.0.0.1
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp\IXP000.TMP>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Set NRPSgaVRQojCOxlspnXWFxCwHGuAXDx=MZ
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp\IXP000.TMP>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: <nul set /p = "%NRPSgaVRQojCOxlspnXWFxCwHGuAXDx%" > Levandosi.exe.com
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp\IXP000.TMP>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: findstr /V /R "^IMxIEQVviptfvbyyjEheJSoafNkHkxTjNWUwqCNzCAPvfjElBwgzfaGPDwaQEglMfRCmCryJQUAorMrepwulyAXxdtnYpXOhdeubK$" Avra.potx >> Levandosi.exe.com
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp\IXP000.TMP>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: copy Ape.potx S
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 1 file(s) copied.
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp\IXP000.TMP>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: start Levandosi.exe.com S
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp\IXP000.TMP>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: %QEjEWUraBNWYxsLwUacYJNu%
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp\IXP000.TMP>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp\IXP000.TMP>
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: Pinging 127.0.0.1
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: with 32 bytes of data:
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: Reply from 127.0.0.1:
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: bytes=32
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: time<1ms
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: TTL=128
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: Reply from 127.0.0.1:
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: bytes=32
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: time<1ms
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: TTL=128
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: Reply from 127.0.0.1:
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: bytes=32
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: time<1ms
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: TTL=128
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: Reply from 127.0.0.1:
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: bytes=32
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: time<1ms
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: TTL=128
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: Ping statistics for 127.0.0.1: Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: Approximate round trip times in milli-seconds: Minimum = 0ms, Maximum = 0ms, Average = 0ms
console_handle: 0x00000007
1 1 0
Time & API Arguments Status Return Repeated

GlobalMemoryStatusEx

1 1 0
section .ndata
Time & API Arguments Status Return Repeated

__exception__

stacktrace:
RaiseException+0x3d FreeEnvironmentStringsW-0x373 kernelbase+0xa49d @ 0x7fefd6da49d
parted+0x507b97 @ 0x140277b97
parted+0x4f099e @ 0x14026099e
HeapWalk-0x1ce0 kernel32+0x0 @ 0x76e40000
0x25f738
0x25f738
0x25f738
0x472c32
0x443316
0x467dc000443222
0x467dc000443222
0x467dc000443222
0x467dc000443222
0x467dc000443222
0x467dc000443222
0x467dc000443222
0x467dc000443222
0x467dc000443222
0x467dc000443222
0x467dc000443222
0x467dc000443222
0x467dc000443222
0x467dc000443222
0x467dc000443222
0x467dc000443222
0x467dc000443222
0x467dc000443222
0x467dc000443222
0x467dc000443222
0x467dc000443222
0x467dc000443222
0x467dc000443222
0x467dc000443222
0x467dc000443222
0x467dc000443222
0x467dc000443222
0x467dc000443222
0x467dc000443222
0x467dc000443222
0x467dc000443222
0x467dc000443222
0x467dc000443222
0x467dc000443222
0x467dc000443222
0x467dc000443222
0x467dc000443222
0x467dc000443222
0x467dc000443222
0x467dc000443222
0x467dc000443222
0x467dc000443222
0x467dc000443222
0x467dc000443222
0x467dc000443222
0x467dc000443222
0x467dc000443222
0x467dc000443222
0x467dc000443222
0x467dc000443222
0x467dc000443222
0x467dc000443222
0x467dc000443222
0x467dc000443222
0x467dc000443222

exception.instruction_r: 48 81 c4 c8 00 00 00 c3 48 85 f6 74 08 83 3b 00
exception.symbol: RaiseException+0x3d FreeEnvironmentStringsW-0x373 kernelbase+0xa49d
exception.instruction: add rsp, 0xc8
exception.module: KERNELBASE.dll
exception.exception_code: 0xc000008e
exception.offset: 42141
exception.address: 0x7fefd6da49d
registers.r14: 0
registers.r15: 0
registers.rcx: 2486320
registers.rsi: 1999256272
registers.r10: 0
registers.rbx: 5369364523
registers.rsp: 2488144
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2488152
registers.rdi: 5366218752
registers.rax: 1996635272
registers.r13: 0
1 0 0

__exception__

stacktrace:
RtlRestoreContext+0x293 __chkstk-0x1fe ntdll+0x50bd2 @ 0x77210bd2

exception.instruction_r: 48 cf 48 83 ec 30 4c 8b c4 48 81 ec d0 04 00 00
exception.symbol: RtlRestoreContext+0x293 __chkstk-0x1fe ntdll+0x50bd2
exception.instruction: iretq
exception.module: ntdll.dll
exception.exception_code: 0xc0000005
exception.offset: 330706
exception.address: 0x77210bd2
registers.r14: 0
registers.r15: 0
registers.rcx: 2486320
registers.rsi: 0
registers.r10: 0
registers.rbx: 5369364523
registers.rsp: 2488232
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1996635272
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2486320
registers.rsi: 0
registers.r10: 0
registers.rbx: 5369364523
registers.rsp: 2488232
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1996635272
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2486320
registers.rsi: 0
registers.r10: 0
registers.rbx: 5369364523
registers.rsp: 2488232
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1996635272
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2486320
registers.rsi: 0
registers.r10: 0
registers.rbx: 5369364523
registers.rsp: 2488232
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1996635272
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2486320
registers.rsi: 0
registers.r10: 0
registers.rbx: 5369364523
registers.rsp: 2488232
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1996635272
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2486320
registers.rsi: 0
registers.r10: 0
registers.rbx: 5369364523
registers.rsp: 2488232
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1996635272
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2486320
registers.rsi: 0
registers.r10: 0
registers.rbx: 5369364523
registers.rsp: 2488232
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1996635272
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2486320
registers.rsi: 0
registers.r10: 0
registers.rbx: 5369364523
registers.rsp: 2488232
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1996635272
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2486320
registers.rsi: 0
registers.r10: 0
registers.rbx: 5369364523
registers.rsp: 2488232
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1996635272
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2486320
registers.rsi: 0
registers.r10: 0
registers.rbx: 5369364523
registers.rsp: 2488232
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1996635272
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2486320
registers.rsi: 0
registers.r10: 0
registers.rbx: 5369364523
registers.rsp: 2488232
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1996635272
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2486320
registers.rsi: 0
registers.r10: 0
registers.rbx: 5369364523
registers.rsp: 2488232
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1996635272
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2486320
registers.rsi: 0
registers.r10: 0
registers.rbx: 5369364523
registers.rsp: 2488232
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1996635272
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2486320
registers.rsi: 0
registers.r10: 0
registers.rbx: 5369364523
registers.rsp: 2488232
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1996635272
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2486320
registers.rsi: 0
registers.r10: 0
registers.rbx: 5369364523
registers.rsp: 2488232
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1996635272
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2486320
registers.rsi: 0
registers.r10: 0
registers.rbx: 5369364523
registers.rsp: 2488232
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1996635272
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2486320
registers.rsi: 0
registers.r10: 0
registers.rbx: 5369364523
registers.rsp: 2488232
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1996635272
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2486320
registers.rsi: 0
registers.r10: 0
registers.rbx: 5369364523
registers.rsp: 2488232
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1996635272
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2486320
registers.rsi: 0
registers.r10: 0
registers.rbx: 5369364523
registers.rsp: 2488232
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1996635272
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2486320
registers.rsi: 0
registers.r10: 0
registers.rbx: 5369364523
registers.rsp: 2488232
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1996635272
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2486320
registers.rsi: 0
registers.r10: 0
registers.rbx: 5369364523
registers.rsp: 2488232
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1996635272
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2486320
registers.rsi: 0
registers.r10: 0
registers.rbx: 5369364523
registers.rsp: 2488232
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1996635272
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2486320
registers.rsi: 0
registers.r10: 0
registers.rbx: 5369364523
registers.rsp: 2488232
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1996635272
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2486320
registers.rsi: 0
registers.r10: 0
registers.rbx: 5369364523
registers.rsp: 2488232
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1996635272
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2486320
registers.rsi: 0
registers.r10: 0
registers.rbx: 5369364523
registers.rsp: 2488232
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1996635272
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2486320
registers.rsi: 0
registers.r10: 0
registers.rbx: 5369364523
registers.rsp: 2488232
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1996635272
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2486320
registers.rsi: 0
registers.r10: 0
registers.rbx: 5369364523
registers.rsp: 2488232
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1996635272
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2486320
registers.rsi: 0
registers.r10: 0
registers.rbx: 5369364523
registers.rsp: 2488232
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1996635272
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2486320
registers.rsi: 0
registers.r10: 0
registers.rbx: 5369364523
registers.rsp: 2488232
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1996635272
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2486320
registers.rsi: 0
registers.r10: 0
registers.rbx: 5369364523
registers.rsp: 2488232
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1996635272
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2486320
registers.rsi: 0
registers.r10: 0
registers.rbx: 5369364523
registers.rsp: 2488232
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1996635272
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2486320
registers.rsi: 0
registers.r10: 0
registers.rbx: 5369364523
registers.rsp: 2488232
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1996635272
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2486320
registers.rsi: 0
registers.r10: 0
registers.rbx: 5369364523
registers.rsp: 2488232
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1996635272
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2486320
registers.rsi: 0
registers.r10: 0
registers.rbx: 5369364523
registers.rsp: 2488232
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1996635272
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2486320
registers.rsi: 0
registers.r10: 0
registers.rbx: 5369364523
registers.rsp: 2488232
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1996635272
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2486320
registers.rsi: 0
registers.r10: 0
registers.rbx: 5369364523
registers.rsp: 2488232
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1996635272
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2486320
registers.rsi: 0
registers.r10: 0
registers.rbx: 5369364523
registers.rsp: 2488232
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1996635272
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2486320
registers.rsi: 0
registers.r10: 0
registers.rbx: 5369364523
registers.rsp: 2488232
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1996635272
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2486320
registers.rsi: 0
registers.r10: 0
registers.rbx: 5369364523
registers.rsp: 2488232
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1996635272
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2486320
registers.rsi: 0
registers.r10: 0
registers.rbx: 5369364523
registers.rsp: 2488232
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1996635272
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2486320
registers.rsi: 0
registers.r10: 0
registers.rbx: 5369364523
registers.rsp: 2488232
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1996635272
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2486320
registers.rsi: 0
registers.r10: 0
registers.rbx: 5369364523
registers.rsp: 2488232
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1996635272
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2486320
registers.rsi: 0
registers.r10: 0
registers.rbx: 5369364523
registers.rsp: 2488232
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1996635272
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2486320
registers.rsi: 0
registers.r10: 0
registers.rbx: 5369364523
registers.rsp: 2488232
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1996635272
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2486320
registers.rsi: 0
registers.r10: 0
registers.rbx: 5369364523
registers.rsp: 2488232
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1996635272
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2486320
registers.rsi: 0
registers.r10: 0
registers.rbx: 5369364523
registers.rsp: 2488232
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1996635272
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2486320
registers.rsi: 0
registers.r10: 0
registers.rbx: 5369364523
registers.rsp: 2488232
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1996635272
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2486320
registers.rsi: 0
registers.r10: 0
registers.rbx: 5369364523
registers.rsp: 2488232
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1996635272
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2486320
registers.rsi: 0
registers.r10: 0
registers.rbx: 5369364523
registers.rsp: 2488232
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1998505249
registers.rdi: 0
registers.rax: 1996635272
registers.r13: 0
1 0 0
Time & API Arguments Status Return Repeated

NtProtectVirtualMemory

process_identifier: 2212
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x73721000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2212
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x74e51000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2212
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x10001000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2212
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x73711000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2212
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x727a1000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2212
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x72764000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2212
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x727a2000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2056
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x73751000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2056
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x72b51000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2056
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x72b14000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2056
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x72b52000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2056
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x73721000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1816
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x72b51000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1816
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x72b14000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1816
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x72b52000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 560
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x72b51000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 560
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x72b14000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 560
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x72b52000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 560
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 102400
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x03de1000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 560
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 32768
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x03dfa000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 560
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 8192
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x03e02000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 560
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x03e04000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 560
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 8192
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x03e05000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1116
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x73321000
process_handle: 0xffffffff
1 0 0
Time & API Arguments Status Return Repeated

GetDiskFreeSpaceW

number_of_free_clusters: 3348944
sectors_per_cluster: 8
bytes_per_sector: 512
root_path: \
total_number_of_clusters: 8362495
1 1 0

GetDiskFreeSpaceW

number_of_free_clusters: 3348944
sectors_per_cluster: 8
bytes_per_sector: 512
root_path: \
total_number_of_clusters: 8362495
1 1 0
file C:\Program Files (x86)\foler\olader\acppage.dll
file C:\Users\test22\AppData\Local\Temp\dislip\wheezy.exe
file C:\Users\test22\AppData\Local\Temp\dislip\parted.exe
file C:\Program Files (x86)\foler\olader\acledit.dll
file C:\Program Files (x86)\foler\olader\adprovider.dll
file C:\Users\test22\AppData\Local\Temp\nsc625D.tmp\UAC.dll
file C:\Users\test22\AppData\Local\Temp\IXP000.TMP\Levandosi.exe.com
file C:\Users\test22\AppData\Local\Temp\nsc625D.tmp\UAC.dll
file C:\Users\test22\AppData\Local\Temp\dislip\wheezy.exe
section {u'size_of_data': u'0x0000f000', u'virtual_address': u'0x00160000', u'entropy': 6.977843706240912, u'name': u'.rsrc', u'virtual_size': u'0x0000ef18'} entropy 6.97784370624 description A section with a high entropy has been found
section {u'size_of_data': u'0x00001000', u'virtual_address': u'0x0016f000', u'entropy': 7.913432912219983, u'name': u'.reloc', u'virtual_size': u'0x00000fd6'} entropy 7.91343291222 description A section with a high entropy has been found
entropy 0.612440191388 description Overall entropy of this PE file is high
cmdline ping 127.0.0.1
file C:\ProgramData\AVAST Software
file C:\ProgramData\AVG
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce\wextract_cleanup0 reg_value rundll32.exe C:\Windows\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\test22\AppData\Local\Temp\IXP000.TMP\"
Process injection Process 1808 resumed a thread in remote process 1816
Time & API Arguments Status Return Repeated

NtResumeThread

thread_handle: 0x00000134
suspend_count: 0
process_identifier: 1816
1 0 0
Time & API Arguments Status Return Repeated

__anomaly__

tid: 2240
message: Encountered 65537 exceptions, quitting.
subcategory: exception
function_name:
1 0 0
Elastic malicious (high confidence)
ClamAV Win.Packed.Filerepmalware-9864117-0
K7AntiVirus Trojan ( 0057a5231 )
BitDefender Gen:Variant.Razy.920754
K7GW Trojan ( 0057a5231 )
Arcabit Trojan.Razy.DE0CB2
Symantec ML.Attribute.HighConfidence
ESET-NOD32 multiple detections
APEX Malicious
Cynet Malicious (score: 100)
Kaspersky UDS:Backdoor.Win32.Agent
MicroWorld-eScan Gen:Variant.Razy.920754
Avast Win64:DropperX-gen [Drp]
Emsisoft Gen:Variant.Razy.920754 (B)
FireEye Gen:Variant.Razy.920754
Sophos Generic ML PUA (PUA)
MAX malware (ai score=83)
Microsoft Trojan:Win32/Wacatac.B!ml
GData Win32.Trojan.BSE.HLJWVB
ALYac Gen:Variant.Razy.920754
Malwarebytes Malware.AI.753280343
SentinelOne Static AI - Suspicious PE
AVG Win64:DropperX-gen [Drp]