Summary | ZeroBOX

lv.exe

PE64 PE File
Category Machine Started Completed
FILE s1_win7_x6402 Oct. 18, 2021, 9:44 a.m. Oct. 18, 2021, 9:51 a.m.
Size 3.3MB
Type PE32+ executable (GUI) x86-64, for MS Windows
MD5 e8719fad9816c40755e1c4821650e14b
SHA256 0d6c6aa72b119b2bc82d377602bfbcebf9f71393c31d2d6b34643adf50f6e82f
CRC32 4595BB04
ssdeep 98304:aSyqHFt/qr04owuG4ZCSmT+wVzl/HKhO:aSvn/twuG4ZCShwtl/H
Yara
  • IsPE64 - (no description)
  • PE_Header_Zero - PE File Signature
  • themida_packer - themida packer

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
164.124.101.2 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

section
section .themida
section .boot
Time & API Arguments Status Return Repeated

__exception__

stacktrace:
RaiseException+0x3d FreeEnvironmentStringsW-0x373 kernelbase+0xa49d @ 0x7fefde3a49d
lv+0x52707a @ 0x13fb1707a
lv+0x53fede @ 0x13fb2fede
HeapWalk-0x1ce0 kernel32+0x0 @ 0x77200000
0x13fd98
0x13fd98
0x13fd98

exception.instruction_r: 48 81 c4 c8 00 00 00 c3 48 85 f6 74 08 83 3b 00
exception.symbol: RaiseException+0x3d FreeEnvironmentStringsW-0x373 kernelbase+0xa49d
exception.instruction: add rsp, 0xc8
exception.module: KERNELBASE.dll
exception.exception_code: 0xc000008e
exception.offset: 42141
exception.address: 0x7fefde3a49d
registers.r14: 0
registers.r15: 0
registers.rcx: 1308304
registers.rsi: 2006858448
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310112
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310136
registers.rdi: 5358354432
registers.rax: 2008556784
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308304
registers.rsi: 2006858448
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310112
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310136
registers.rdi: 5358354432
registers.rax: 2008556784
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308304
registers.rsi: 2006858448
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310112
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310136
registers.rdi: 5358354432
registers.rax: 2008556784
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308304
registers.rsi: 2006858448
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310112
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310136
registers.rdi: 5358354432
registers.rax: 2008556784
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308304
registers.rsi: 2006858448
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310112
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310136
registers.rdi: 5358354432
registers.rax: 2008556784
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308304
registers.rsi: 2006858448
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310112
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310136
registers.rdi: 5358354432
registers.rax: 2008556784
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308304
registers.rsi: 2006858448
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310112
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310136
registers.rdi: 5358354432
registers.rax: 2008556784
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308304
registers.rsi: 2006858448
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310112
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310136
registers.rdi: 5358354432
registers.rax: 2008556784
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308304
registers.rsi: 2006858448
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310112
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310136
registers.rdi: 5358354432
registers.rax: 2008556784
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308304
registers.rsi: 2006858448
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310112
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310136
registers.rdi: 5358354432
registers.rax: 2008556784
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308304
registers.rsi: 2006858448
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310112
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310136
registers.rdi: 5358354432
registers.rax: 2008556784
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308304
registers.rsi: 2006858448
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310112
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310136
registers.rdi: 5358354432
registers.rax: 2008556784
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308304
registers.rsi: 2006858448
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310112
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310136
registers.rdi: 5358354432
registers.rax: 2008556784
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308304
registers.rsi: 2006858448
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310112
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310136
registers.rdi: 5358354432
registers.rax: 2008556784
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308304
registers.rsi: 2006858448
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310112
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310136
registers.rdi: 5358354432
registers.rax: 2008556784
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308304
registers.rsi: 2006858448
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310112
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310136
registers.rdi: 5358354432
registers.rax: 2008556784
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308304
registers.rsi: 2006858448
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310112
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310136
registers.rdi: 5358354432
registers.rax: 2008556784
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308304
registers.rsi: 2006858448
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310112
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310136
registers.rdi: 5358354432
registers.rax: 2008556784
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308304
registers.rsi: 2006858448
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310112
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310136
registers.rdi: 5358354432
registers.rax: 2008556784
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308304
registers.rsi: 2006858448
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310112
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310136
registers.rdi: 5358354432
registers.rax: 2008556784
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308304
registers.rsi: 2006858448
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310112
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310136
registers.rdi: 5358354432
registers.rax: 2008556784
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308304
registers.rsi: 2006858448
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310112
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310136
registers.rdi: 5358354432
registers.rax: 2008556784
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308304
registers.rsi: 2006858448
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310112
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310136
registers.rdi: 5358354432
registers.rax: 2008556784
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308304
registers.rsi: 2006858448
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310112
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310136
registers.rdi: 5358354432
registers.rax: 2008556784
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308304
registers.rsi: 2006858448
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310112
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310136
registers.rdi: 5358354432
registers.rax: 2008556784
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308304
registers.rsi: 2006858448
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310112
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310136
registers.rdi: 5358354432
registers.rax: 2008556784
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308304
registers.rsi: 2006858448
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310112
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310136
registers.rdi: 5358354432
registers.rax: 2008556784
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308304
registers.rsi: 2006858448
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310112
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310136
registers.rdi: 5358354432
registers.rax: 2008556784
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308304
registers.rsi: 2006858448
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310112
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310136
registers.rdi: 5358354432
registers.rax: 2008556784
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308304
registers.rsi: 2006858448
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310112
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310136
registers.rdi: 5358354432
registers.rax: 2008556784
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308304
registers.rsi: 2006858448
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310112
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310136
registers.rdi: 5358354432
registers.rax: 2008556784
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308304
registers.rsi: 2006858448
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310112
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310136
registers.rdi: 5358354432
registers.rax: 2008556784
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308304
registers.rsi: 2006858448
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310112
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310136
registers.rdi: 5358354432
registers.rax: 2008556784
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308304
registers.rsi: 2006858448
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310112
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310136
registers.rdi: 5358354432
registers.rax: 2008556784
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308304
registers.rsi: 2006858448
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310112
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310136
registers.rdi: 5358354432
registers.rax: 2008556784
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308304
registers.rsi: 2006858448
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310112
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310136
registers.rdi: 5358354432
registers.rax: 2008556784
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308304
registers.rsi: 2006858448
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310112
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310136
registers.rdi: 5358354432
registers.rax: 2008556784
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308304
registers.rsi: 2006858448
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310112
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310136
registers.rdi: 5358354432
registers.rax: 2008556784
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308304
registers.rsi: 2006858448
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310112
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310136
registers.rdi: 5358354432
registers.rax: 2008556784
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308304
registers.rsi: 2006858448
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310112
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310136
registers.rdi: 5358354432
registers.rax: 2008556784
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308304
registers.rsi: 2006858448
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310112
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310136
registers.rdi: 5358354432
registers.rax: 2008556784
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308304
registers.rsi: 2006858448
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310112
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310136
registers.rdi: 5358354432
registers.rax: 2008556784
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308304
registers.rsi: 2006858448
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310112
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310136
registers.rdi: 5358354432
registers.rax: 2008556784
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308304
registers.rsi: 2006858448
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310112
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310136
registers.rdi: 5358354432
registers.rax: 2008556784
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308304
registers.rsi: 2006858448
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310112
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310136
registers.rdi: 5358354432
registers.rax: 2008556784
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308304
registers.rsi: 2006858448
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310112
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310136
registers.rdi: 5358354432
registers.rax: 2008556784
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308304
registers.rsi: 2006858448
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310112
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310136
registers.rdi: 5358354432
registers.rax: 2008556784
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308304
registers.rsi: 2006858448
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310112
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310136
registers.rdi: 5358354432
registers.rax: 2008556784
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308304
registers.rsi: 2006858448
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310112
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310136
registers.rdi: 5358354432
registers.rax: 2008556784
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308304
registers.rsi: 2006858448
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310112
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310136
registers.rdi: 5358354432
registers.rax: 2008556784
registers.r13: 0
1 0 0
Time & API Arguments Status Return Repeated

NtProtectVirtualMemory

process_identifier: 2232
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 8192
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00000000779f7000
process_handle: 0xffffffffffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2232
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 8192
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0000000077950000
process_handle: 0xffffffffffffffff
1 0 0
section {u'size_of_data': u'0x0000b000', u'virtual_address': u'0x00001000', u'entropy': 7.979524772223324, u'name': u' ', u'virtual_size': u'0x00014fd0'} entropy 7.97952477222 description A section with a high entropy has been found
section {u'size_of_data': u'0x00005400', u'virtual_address': u'0x00016000', u'entropy': 7.923827313944584, u'name': u' ', u'virtual_size': u'0x0000f51c'} entropy 7.92382731394 description A section with a high entropy has been found
section {u'size_of_data': u'0x00001400', u'virtual_address': u'0x00026000', u'entropy': 7.7545209843504255, u'name': u' ', u'virtual_size': u'0x00003778'} entropy 7.75452098435 description A section with a high entropy has been found
section {u'size_of_data': u'0x00000e00', u'virtual_address': u'0x0002a000', u'entropy': 7.638831178686811, u'name': u' ', u'virtual_size': u'0x0000189c'} entropy 7.63883117869 description A section with a high entropy has been found
section {u'size_of_data': u'0x00000800', u'virtual_address': u'0x0002e000', u'entropy': 7.652484841322989, u'name': u' ', u'virtual_size': u'0x00000a7c'} entropy 7.65248484132 description A section with a high entropy has been found
section {u'size_of_data': u'0x0033ae00', u'virtual_address': u'0x005da000', u'entropy': 7.963398745107405, u'name': u'.boot', u'virtual_size': u'0x0033ae00'} entropy 7.96339874511 description A section with a high entropy has been found
entropy 0.99940915805 description Overall entropy of this PE file is high
Time & API Arguments Status Return Repeated

__anomaly__

tid: 180
message: Encountered 65537 exceptions, quitting.
subcategory: exception
function_name:
1 0 0
Elastic malicious (high confidence)
MicroWorld-eScan Gen:Variant.Razy.921612
FireEye Generic.mg.e8719fad9816c407
CAT-QuickHeal Trojan.GenericRI.S22849637
McAfee Artemis!E8719FAD9816
Cylance Unsafe
Sangfor Trojan.Win32.Save.a
Cyren W64/ClipBanker.AD.gen!Eldorado
ESET-NOD32 a variant of Win64/Packed.Themida.L suspicious
APEX Malicious
Paloalto generic.ml
Kaspersky HEUR:Trojan-Dropper.Win32.Scrop.pef
BitDefender Gen:Variant.Razy.921612
Avast Win64:DropperX-gen [Drp]
Ad-Aware Gen:Variant.Razy.921612
Emsisoft Gen:Variant.Razy.921612 (B)
McAfee-GW-Edition BehavesLike.Win64.Dropper.wc
Sophos Generic ML PUA (PUA)
eGambit Unsafe.AI_Score_93%
MAX malware (ai score=85)
Microsoft Trojan:Win32/Sabsik.FL.A!ml
Gridinsoft Trojan.Heur!.032100A3
GData Gen:Variant.Razy.921612
Cynet Malicious (score: 100)
AhnLab-V3 Malware/Win.Generic.C4626406
ALYac Gen:Variant.Razy.921612
Malwarebytes Trojan.ClipBanker
SentinelOne Static AI - Suspicious PE
AVG Win64:DropperX-gen [Drp]
Panda Trj/CI.A