Summary | ZeroBOX

Zenar_protected.exe

PE64 PE File
Category Machine Started Completed
FILE s1_win7_x6402 Sept. 30, 2021, 9:33 a.m. Sept. 30, 2021, 9:35 a.m.
Size 5.2MB
Type PE32+ executable (console) x86-64, for MS Windows
MD5 ab40d2395f7abeee43552ae6a750044d
SHA256 bcc26c979a4d7b0afec88bdf7c864e965db3041616acea4cda1874ba476e74e0
CRC32 C79F5694
ssdeep 98304:MlVyw8BbPnvCR7znpN+gDn6Vj0mwLCZft9tDaQzLmXo48qBEt3730Z4e+Q:MlVyB7CFHDn6VjP+CZLVAXsq470Zr+
Yara
  • IsPE64 - (no description)
  • PE_Header_Zero - PE File Signature
  • themida_packer - themida packer

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
164.124.101.2 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

section
section .themida
section .boot
Time & API Arguments Status Return Repeated

__exception__

stacktrace:
RaiseException+0x3d FreeEnvironmentStringsW-0x373 kernelbase+0xa49d @ 0x7fefde3a49d
zenar_protected+0x676f43 @ 0x13fdf6f43
zenar_protected+0x6a939e @ 0x13fe2939e
HeapWalk-0x1ce0 kernel32+0x0 @ 0x77200000
0x30fb28
0x30fb28
0x30fb28
0x505344
0x4d30b9
0x4fb76000000000
0x4fb76000000000
0x4fb76000000000
0x4fb76000000000
0x4fb76000000000
0x4fb76000000000
0x4fb76000000000
0x4fb76000000000
0x4fb76000000000
0x4fb76000000000
0x4fb76000000000
0x4fb76000000000
0x4fb76000000000
0x4fb76000000000
0x4fb76000000000
0x4fb76000000000
0x4fb76000000000
0x4fb76000000000
0x4fb76000000000
0x4fb76000000000
0x4fb76000000000
0x4fb76000000000
0x4fb76000000000
0x4fb76000000000
0x4fb76000000000
0x4fb76000000000
0x4fb76000000000
0x4fb76000000000
0x4fb76000000000
0x4fb76000000000
0x4fb76000000000
0x4fb76000000000
0x4fb76000000000
0x4fb76000000000
0x4fb76000000000
0x4fb76000000000
0x4fb76000000000
0x4fb76000000000
0x4fb76000000000
0x4fb76000000000
0x4fb76000000000
0x4fb76000000000
0x4fb76000000000
0x4fb76000000000
0x4fb76000000000
0x4fb76000000000
0x4fb76000000000
0x4fb76000000000
0x4fb76000000000
0x4fb76000000000
0x4fb76000000000
0x4fb76000000000
0x4fb76000000000
0x4fb76000000000
0x4fb76000000000

exception.instruction_r: 48 81 c4 c8 00 00 00 c3 48 85 f6 74 08 83 3b 00
exception.symbol: RaiseException+0x3d FreeEnvironmentStringsW-0x373 kernelbase+0xa49d
exception.instruction: add rsp, 0xc8
exception.module: KERNELBASE.dll
exception.exception_code: 0xc000008e
exception.offset: 42141
exception.address: 0x7fefde3a49d
registers.r14: 0
registers.r15: 0
registers.rcx: 3208224
registers.rsi: 2006858448
registers.r10: 0
registers.rbx: 5363675550
registers.rsp: 3210048
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 3210056
registers.rdi: 5360263168
registers.rax: 2006657020
registers.r13: 0
1 0 0

__exception__

stacktrace:
RtlRestoreContext+0x293 __chkstk-0x1fe ntdll+0x50bd2 @ 0x77950bd2

exception.instruction_r: 48 cf 48 83 ec 30 4c 8b c4 48 81 ec d0 04 00 00
exception.symbol: RtlRestoreContext+0x293 __chkstk-0x1fe ntdll+0x50bd2
exception.instruction: iretq
exception.module: ntdll.dll
exception.exception_code: 0xc0000005
exception.offset: 330706
exception.address: 0x77950bd2
registers.r14: 0
registers.r15: 0
registers.rcx: 3208224
registers.rsi: 0
registers.r10: 0
registers.rbx: 5363675550
registers.rsp: 3210136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2006107425
registers.rdi: 0
registers.rax: 2006657020
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3208224
registers.rsi: 0
registers.r10: 0
registers.rbx: 5363675550
registers.rsp: 3210136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2006107425
registers.rdi: 0
registers.rax: 2006657020
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3208224
registers.rsi: 0
registers.r10: 0
registers.rbx: 5363675550
registers.rsp: 3210136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2006107425
registers.rdi: 0
registers.rax: 2006657020
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3208224
registers.rsi: 0
registers.r10: 0
registers.rbx: 5363675550
registers.rsp: 3210136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2006107425
registers.rdi: 0
registers.rax: 2006657020
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3208224
registers.rsi: 0
registers.r10: 0
registers.rbx: 5363675550
registers.rsp: 3210136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2006107425
registers.rdi: 0
registers.rax: 2006657020
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3208224
registers.rsi: 0
registers.r10: 0
registers.rbx: 5363675550
registers.rsp: 3210136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2006107425
registers.rdi: 0
registers.rax: 2006657020
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3208224
registers.rsi: 0
registers.r10: 0
registers.rbx: 5363675550
registers.rsp: 3210136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2006107425
registers.rdi: 0
registers.rax: 2006657020
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3208224
registers.rsi: 0
registers.r10: 0
registers.rbx: 5363675550
registers.rsp: 3210136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2006107425
registers.rdi: 0
registers.rax: 2006657020
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3208224
registers.rsi: 0
registers.r10: 0
registers.rbx: 5363675550
registers.rsp: 3210136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2006107425
registers.rdi: 0
registers.rax: 2006657020
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3208224
registers.rsi: 0
registers.r10: 0
registers.rbx: 5363675550
registers.rsp: 3210136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2006107425
registers.rdi: 0
registers.rax: 2006657020
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3208224
registers.rsi: 0
registers.r10: 0
registers.rbx: 5363675550
registers.rsp: 3210136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2006107425
registers.rdi: 0
registers.rax: 2006657020
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3208224
registers.rsi: 0
registers.r10: 0
registers.rbx: 5363675550
registers.rsp: 3210136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2006107425
registers.rdi: 0
registers.rax: 2006657020
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3208224
registers.rsi: 0
registers.r10: 0
registers.rbx: 5363675550
registers.rsp: 3210136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2006107425
registers.rdi: 0
registers.rax: 2006657020
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3208224
registers.rsi: 0
registers.r10: 0
registers.rbx: 5363675550
registers.rsp: 3210136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2006107425
registers.rdi: 0
registers.rax: 2006657020
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3208224
registers.rsi: 0
registers.r10: 0
registers.rbx: 5363675550
registers.rsp: 3210136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2006107425
registers.rdi: 0
registers.rax: 2006657020
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3208224
registers.rsi: 0
registers.r10: 0
registers.rbx: 5363675550
registers.rsp: 3210136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2006107425
registers.rdi: 0
registers.rax: 2006657020
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3208224
registers.rsi: 0
registers.r10: 0
registers.rbx: 5363675550
registers.rsp: 3210136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2006107425
registers.rdi: 0
registers.rax: 2006657020
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3208224
registers.rsi: 0
registers.r10: 0
registers.rbx: 5363675550
registers.rsp: 3210136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2006107425
registers.rdi: 0
registers.rax: 2006657020
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3208224
registers.rsi: 0
registers.r10: 0
registers.rbx: 5363675550
registers.rsp: 3210136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2006107425
registers.rdi: 0
registers.rax: 2006657020
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3208224
registers.rsi: 0
registers.r10: 0
registers.rbx: 5363675550
registers.rsp: 3210136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2006107425
registers.rdi: 0
registers.rax: 2006657020
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3208224
registers.rsi: 0
registers.r10: 0
registers.rbx: 5363675550
registers.rsp: 3210136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2006107425
registers.rdi: 0
registers.rax: 2006657020
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3208224
registers.rsi: 0
registers.r10: 0
registers.rbx: 5363675550
registers.rsp: 3210136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2006107425
registers.rdi: 0
registers.rax: 2006657020
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3208224
registers.rsi: 0
registers.r10: 0
registers.rbx: 5363675550
registers.rsp: 3210136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2006107425
registers.rdi: 0
registers.rax: 2006657020
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3208224
registers.rsi: 0
registers.r10: 0
registers.rbx: 5363675550
registers.rsp: 3210136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2006107425
registers.rdi: 0
registers.rax: 2006657020
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3208224
registers.rsi: 0
registers.r10: 0
registers.rbx: 5363675550
registers.rsp: 3210136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2006107425
registers.rdi: 0
registers.rax: 2006657020
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3208224
registers.rsi: 0
registers.r10: 0
registers.rbx: 5363675550
registers.rsp: 3210136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2006107425
registers.rdi: 0
registers.rax: 2006657020
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3208224
registers.rsi: 0
registers.r10: 0
registers.rbx: 5363675550
registers.rsp: 3210136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2006107425
registers.rdi: 0
registers.rax: 2006657020
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3208224
registers.rsi: 0
registers.r10: 0
registers.rbx: 5363675550
registers.rsp: 3210136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2006107425
registers.rdi: 0
registers.rax: 2006657020
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3208224
registers.rsi: 0
registers.r10: 0
registers.rbx: 5363675550
registers.rsp: 3210136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2006107425
registers.rdi: 0
registers.rax: 2006657020
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3208224
registers.rsi: 0
registers.r10: 0
registers.rbx: 5363675550
registers.rsp: 3210136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2006107425
registers.rdi: 0
registers.rax: 2006657020
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3208224
registers.rsi: 0
registers.r10: 0
registers.rbx: 5363675550
registers.rsp: 3210136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2006107425
registers.rdi: 0
registers.rax: 2006657020
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3208224
registers.rsi: 0
registers.r10: 0
registers.rbx: 5363675550
registers.rsp: 3210136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2006107425
registers.rdi: 0
registers.rax: 2006657020
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3208224
registers.rsi: 0
registers.r10: 0
registers.rbx: 5363675550
registers.rsp: 3210136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2006107425
registers.rdi: 0
registers.rax: 2006657020
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3208224
registers.rsi: 0
registers.r10: 0
registers.rbx: 5363675550
registers.rsp: 3210136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2006107425
registers.rdi: 0
registers.rax: 2006657020
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3208224
registers.rsi: 0
registers.r10: 0
registers.rbx: 5363675550
registers.rsp: 3210136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2006107425
registers.rdi: 0
registers.rax: 2006657020
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3208224
registers.rsi: 0
registers.r10: 0
registers.rbx: 5363675550
registers.rsp: 3210136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2006107425
registers.rdi: 0
registers.rax: 2006657020
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3208224
registers.rsi: 0
registers.r10: 0
registers.rbx: 5363675550
registers.rsp: 3210136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2006107425
registers.rdi: 0
registers.rax: 2006657020
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3208224
registers.rsi: 0
registers.r10: 0
registers.rbx: 5363675550
registers.rsp: 3210136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2006107425
registers.rdi: 0
registers.rax: 2006657020
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3208224
registers.rsi: 0
registers.r10: 0
registers.rbx: 5363675550
registers.rsp: 3210136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2006107425
registers.rdi: 0
registers.rax: 2006657020
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3208224
registers.rsi: 0
registers.r10: 0
registers.rbx: 5363675550
registers.rsp: 3210136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2006107425
registers.rdi: 0
registers.rax: 2006657020
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3208224
registers.rsi: 0
registers.r10: 0
registers.rbx: 5363675550
registers.rsp: 3210136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2006107425
registers.rdi: 0
registers.rax: 2006657020
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3208224
registers.rsi: 0
registers.r10: 0
registers.rbx: 5363675550
registers.rsp: 3210136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2006107425
registers.rdi: 0
registers.rax: 2006657020
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3208224
registers.rsi: 0
registers.r10: 0
registers.rbx: 5363675550
registers.rsp: 3210136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2006107425
registers.rdi: 0
registers.rax: 2006657020
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3208224
registers.rsi: 0
registers.r10: 0
registers.rbx: 5363675550
registers.rsp: 3210136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2006107425
registers.rdi: 0
registers.rax: 2006657020
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3208224
registers.rsi: 0
registers.r10: 0
registers.rbx: 5363675550
registers.rsp: 3210136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2006107425
registers.rdi: 0
registers.rax: 2006657020
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3208224
registers.rsi: 0
registers.r10: 0
registers.rbx: 5363675550
registers.rsp: 3210136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2006107425
registers.rdi: 0
registers.rax: 2006657020
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3208224
registers.rsi: 0
registers.r10: 0
registers.rbx: 5363675550
registers.rsp: 3210136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2006107425
registers.rdi: 0
registers.rax: 2006657020
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3208224
registers.rsi: 0
registers.r10: 0
registers.rbx: 5363675550
registers.rsp: 3210136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2006107425
registers.rdi: 0
registers.rax: 2006657020
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3208224
registers.rsi: 0
registers.r10: 0
registers.rbx: 5363675550
registers.rsp: 3210136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2006107425
registers.rdi: 0
registers.rax: 2006657020
registers.r13: 0
1 0 0
Time & API Arguments Status Return Repeated

NtProtectVirtualMemory

process_identifier: 1328
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 8192
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00000000779f7000
process_handle: 0xffffffffffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1328
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 8192
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0000000077950000
process_handle: 0xffffffffffffffff
1 0 0
section {u'size_of_data': u'0x00023200', u'virtual_address': u'0x00001000', u'entropy': 7.978370247017844, u'name': u' ', u'virtual_size': u'0x00044cd0'} entropy 7.97837024702 description A section with a high entropy has been found
section {u'size_of_data': u'0x0000ec00', u'virtual_address': u'0x00046000', u'entropy': 7.947663162626652, u'name': u' ', u'virtual_size': u'0x0001f2ba'} entropy 7.94766316263 description A section with a high entropy has been found
section {u'size_of_data': u'0x00000600', u'virtual_address': u'0x00066000', u'entropy': 7.462964596651532, u'name': u' ', u'virtual_size': u'0x00002f14'} entropy 7.46296459665 description A section with a high entropy has been found
section {u'size_of_data': u'0x00002200', u'virtual_address': u'0x00069000', u'entropy': 7.6491373858019, u'name': u' ', u'virtual_size': u'0x0000387c'} entropy 7.6491373858 description A section with a high entropy has been found
section {u'size_of_data': u'0x00000800', u'virtual_address': u'0x0006f000', u'entropy': 6.868200245795665, u'name': u' ', u'virtual_size': u'0x00000ae0'} entropy 6.8682002458 description A section with a high entropy has been found
section {u'size_of_data': u'0x004fb200', u'virtual_address': u'0x0077a000', u'entropy': 7.946948602881917, u'name': u'.boot', u'virtual_size': u'0x004fb200'} entropy 7.94694860288 description A section with a high entropy has been found
entropy 0.999435559737 description Overall entropy of this PE file is high
Time & API Arguments Status Return Repeated

__anomaly__

tid: 1040
message: Encountered 65537 exceptions, quitting.
subcategory: exception
function_name:
1 0 0
Lionic Trojan.Win64.Agentb.trtl
Elastic malicious (high confidence)
Cynet Malicious (score: 100)
McAfee Artemis!AB40D2395F7A
CrowdStrike win/malicious_confidence_60% (W)
BitDefender Gen:Variant.Razy.638802
Symantec Trojan.Gen.2
ESET-NOD32 a variant of Generik.IWMZXNV
APEX Malicious
Kaspersky UDS:DangerousObject.Multi.Generic
MicroWorld-eScan Gen:Variant.Razy.638802
Ad-Aware Gen:Variant.Razy.638802
Emsisoft Gen:Variant.Razy.638802 (B)
McAfee-GW-Edition BehavesLike.Win64.Generic.tc
FireEye Generic.mg.ab40d2395f7abeee
Sophos Generic Reputation PUA (PUA)
Webroot W32.Trojan.Gen
Avira HEUR/AGEN.1140857
MAX malware (ai score=86)
Kingsoft Win32.Troj.Generic_a.a.(kcloud)
Gridinsoft Trojan.Win64.Sabsik.vb
Microsoft Trojan:Win32/Sabsik.FL.B!ml
GData Gen:Variant.Razy.638802
ALYac Gen:Variant.Razy.638802
TrendMicro-HouseCall TROJ_GEN.R002H0CIT21
SentinelOne Static AI - Malicious PE
Fortinet W32/PossibleThreat