Summary | ZeroBOX

lv.exe

PE64 PE File
Category Machine Started Completed
FILE s1_win7_x6403_us Oct. 22, 2021, 9:12 a.m. Oct. 22, 2021, 9:15 a.m.
Size 3.5MB
Type PE32+ executable (GUI) x86-64, for MS Windows
MD5 7d4a4b1e6c40323bb0c3c86da4c185d5
SHA256 8725e5ff2dde91cb1a5424ddeea253b3f3e1b59b46ac3142c22ad5ccd4e22914
CRC32 EF61CBC1
ssdeep 98304:LdEr/e+/uk9hPRSfBQIowE5ZllpMdu+GgAri:LCq4QBQIOpaSri
Yara
  • IsPE64 - (no description)
  • PE_Header_Zero - PE File Signature
  • themida_packer - themida packer

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
No hosts contacted.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

section
section .themida
section .boot
Time & API Arguments Status Return Repeated

__exception__

stacktrace:
RaiseException+0x3d FreeEnvironmentStringsW-0x373 kernelbase+0xa49d @ 0x7fefd8ba49d
lv+0x5237f9 @ 0x13fcb37f9
lv+0x53cf6f @ 0x13fcccf6f
HeapWalk-0x1ce0 kernel32+0x0 @ 0x76dc0000
0x2cfe38
0x2cfe38
0x2cfe38
0x402494
0x3d307c
0x3f7b30773b14aa
0x3f7b30773b14aa
0x3f7b30773b14aa
0x3f7b30773b14aa
0x3f7b30773b14aa
0x3f7b30773b14aa
0x3f7b30773b14aa
0x3f7b30773b14aa
0x3f7b30773b14aa
0x3f7b30773b14aa
0x3f7b30773b14aa
0x3f7b30773b14aa
0x3f7b30773b14aa
0x3f7b30773b14aa
0x3f7b30773b14aa
0x3f7b30773b14aa
0x3f7b30773b14aa
0x3f7b30773b14aa
0x3f7b30773b14aa
0x3f7b30773b14aa
0x3f7b30773b14aa
0x3f7b30773b14aa
0x3f7b30773b14aa
0x3f7b30773b14aa
0x3f7b30773b14aa
0x3f7b30773b14aa
0x3f7b30773b14aa
0x3f7b30773b14aa
0x3f7b30773b14aa
0x3f7b30773b14aa
0x3f7b30773b14aa
0x3f7b30773b14aa
0x3f7b30773b14aa
0x3f7b30773b14aa
0x3f7b30773b14aa
0x3f7b30773b14aa
0x3f7b30773b14aa
0x3f7b30773b14aa
0x3f7b30773b14aa
0x3f7b30773b14aa
0x3f7b30773b14aa
0x3f7b30773b14aa
0x3f7b30773b14aa
0x3f7b30773b14aa
0x3f7b30773b14aa
0x3f7b30773b14aa
0x3f7b30773b14aa
0x3f7b30773b14aa
0x3f7b30773b14aa
0x3f7b30773b14aa
0x3f7b30773b14aa
0x3f7b30773b14aa
0x3f7b30773b14aa
0x3f7b30773b14aa
0x3f7b30773b14aa

exception.instruction_r: 48 81 c4 c8 00 00 00 c3 48 85 f6 74 08 83 3b 00
exception.symbol: RaiseException+0x3d FreeEnvironmentStringsW-0x373 kernelbase+0xa49d
exception.instruction: add rsp, 0xc8
exception.module: KERNELBASE.dll
exception.exception_code: 0xc000008e
exception.offset: 42141
exception.address: 0x7fefd8ba49d
registers.r14: 0
registers.r15: 0
registers.rcx: 2946864
registers.rsi: 2000960208
registers.r10: 0
registers.rbx: 5361041451
registers.rsp: 2948688
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2948696
registers.rdi: 5360058368
registers.rax: 2003064769
registers.r13: 0
1 0 0

__exception__

stacktrace:
RtlRestoreContext+0x293 __chkstk-0x1fe ntdll+0x50bd2 @ 0x773b0bd2

exception.instruction_r: 48 cf 48 83 ec 30 4c 8b c4 48 81 ec d0 04 00 00
exception.symbol: RtlRestoreContext+0x293 __chkstk-0x1fe ntdll+0x50bd2
exception.instruction: iretq
exception.module: ntdll.dll
exception.exception_code: 0xc0000005
exception.offset: 330706
exception.address: 0x773b0bd2
registers.r14: 0
registers.r15: 0
registers.rcx: 2946864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5361041451
registers.rsp: 2948776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2000209185
registers.rdi: 0
registers.rax: 2003064769
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2946864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5361041451
registers.rsp: 2948776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2000209185
registers.rdi: 0
registers.rax: 2003064769
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2946864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5361041451
registers.rsp: 2948776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2000209185
registers.rdi: 0
registers.rax: 2003064769
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2946864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5361041451
registers.rsp: 2948776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2000209185
registers.rdi: 0
registers.rax: 2003064769
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2946864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5361041451
registers.rsp: 2948776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2000209185
registers.rdi: 0
registers.rax: 2003064769
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2946864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5361041451
registers.rsp: 2948776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2000209185
registers.rdi: 0
registers.rax: 2003064769
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2946864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5361041451
registers.rsp: 2948776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2000209185
registers.rdi: 0
registers.rax: 2003064769
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2946864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5361041451
registers.rsp: 2948776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2000209185
registers.rdi: 0
registers.rax: 2003064769
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2946864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5361041451
registers.rsp: 2948776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2000209185
registers.rdi: 0
registers.rax: 2003064769
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2946864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5361041451
registers.rsp: 2948776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2000209185
registers.rdi: 0
registers.rax: 2003064769
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2946864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5361041451
registers.rsp: 2948776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2000209185
registers.rdi: 0
registers.rax: 2003064769
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2946864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5361041451
registers.rsp: 2948776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2000209185
registers.rdi: 0
registers.rax: 2003064769
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2946864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5361041451
registers.rsp: 2948776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2000209185
registers.rdi: 0
registers.rax: 2003064769
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2946864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5361041451
registers.rsp: 2948776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2000209185
registers.rdi: 0
registers.rax: 2003064769
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2946864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5361041451
registers.rsp: 2948776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2000209185
registers.rdi: 0
registers.rax: 2003064769
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2946864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5361041451
registers.rsp: 2948776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2000209185
registers.rdi: 0
registers.rax: 2003064769
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2946864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5361041451
registers.rsp: 2948776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2000209185
registers.rdi: 0
registers.rax: 2003064769
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2946864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5361041451
registers.rsp: 2948776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2000209185
registers.rdi: 0
registers.rax: 2003064769
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2946864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5361041451
registers.rsp: 2948776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2000209185
registers.rdi: 0
registers.rax: 2003064769
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2946864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5361041451
registers.rsp: 2948776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2000209185
registers.rdi: 0
registers.rax: 2003064769
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2946864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5361041451
registers.rsp: 2948776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2000209185
registers.rdi: 0
registers.rax: 2003064769
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2946864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5361041451
registers.rsp: 2948776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2000209185
registers.rdi: 0
registers.rax: 2003064769
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2946864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5361041451
registers.rsp: 2948776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2000209185
registers.rdi: 0
registers.rax: 2003064769
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2946864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5361041451
registers.rsp: 2948776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2000209185
registers.rdi: 0
registers.rax: 2003064769
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2946864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5361041451
registers.rsp: 2948776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2000209185
registers.rdi: 0
registers.rax: 2003064769
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2946864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5361041451
registers.rsp: 2948776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2000209185
registers.rdi: 0
registers.rax: 2003064769
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2946864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5361041451
registers.rsp: 2948776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2000209185
registers.rdi: 0
registers.rax: 2003064769
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2946864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5361041451
registers.rsp: 2948776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2000209185
registers.rdi: 0
registers.rax: 2003064769
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2946864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5361041451
registers.rsp: 2948776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2000209185
registers.rdi: 0
registers.rax: 2003064769
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2946864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5361041451
registers.rsp: 2948776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2000209185
registers.rdi: 0
registers.rax: 2003064769
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2946864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5361041451
registers.rsp: 2948776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2000209185
registers.rdi: 0
registers.rax: 2003064769
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2946864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5361041451
registers.rsp: 2948776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2000209185
registers.rdi: 0
registers.rax: 2003064769
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2946864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5361041451
registers.rsp: 2948776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2000209185
registers.rdi: 0
registers.rax: 2003064769
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2946864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5361041451
registers.rsp: 2948776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2000209185
registers.rdi: 0
registers.rax: 2003064769
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2946864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5361041451
registers.rsp: 2948776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2000209185
registers.rdi: 0
registers.rax: 2003064769
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2946864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5361041451
registers.rsp: 2948776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2000209185
registers.rdi: 0
registers.rax: 2003064769
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2946864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5361041451
registers.rsp: 2948776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2000209185
registers.rdi: 0
registers.rax: 2003064769
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2946864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5361041451
registers.rsp: 2948776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2000209185
registers.rdi: 0
registers.rax: 2003064769
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2946864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5361041451
registers.rsp: 2948776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2000209185
registers.rdi: 0
registers.rax: 2003064769
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2946864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5361041451
registers.rsp: 2948776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2000209185
registers.rdi: 0
registers.rax: 2003064769
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2946864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5361041451
registers.rsp: 2948776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2000209185
registers.rdi: 0
registers.rax: 2003064769
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2946864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5361041451
registers.rsp: 2948776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2000209185
registers.rdi: 0
registers.rax: 2003064769
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2946864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5361041451
registers.rsp: 2948776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2000209185
registers.rdi: 0
registers.rax: 2003064769
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2946864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5361041451
registers.rsp: 2948776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2000209185
registers.rdi: 0
registers.rax: 2003064769
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2946864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5361041451
registers.rsp: 2948776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2000209185
registers.rdi: 0
registers.rax: 2003064769
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2946864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5361041451
registers.rsp: 2948776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2000209185
registers.rdi: 0
registers.rax: 2003064769
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2946864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5361041451
registers.rsp: 2948776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2000209185
registers.rdi: 0
registers.rax: 2003064769
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2946864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5361041451
registers.rsp: 2948776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2000209185
registers.rdi: 0
registers.rax: 2003064769
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2946864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5361041451
registers.rsp: 2948776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2000209185
registers.rdi: 0
registers.rax: 2003064769
registers.r13: 0
1 0 0
section {u'size_of_data': u'0x0000b000', u'virtual_address': u'0x00001000', u'entropy': 7.976785930913017, u'name': u' ', u'virtual_size': u'0x00014fd0'} entropy 7.97678593091 description A section with a high entropy has been found
section {u'size_of_data': u'0x00005400', u'virtual_address': u'0x00016000', u'entropy': 7.8937220474196845, u'name': u' ', u'virtual_size': u'0x0000f51c'} entropy 7.89372204742 description A section with a high entropy has been found
section {u'size_of_data': u'0x00001400', u'virtual_address': u'0x00026000', u'entropy': 7.846255381800891, u'name': u' ', u'virtual_size': u'0x00003778'} entropy 7.8462553818 description A section with a high entropy has been found
section {u'size_of_data': u'0x00000e00', u'virtual_address': u'0x0002a000', u'entropy': 7.639180076597236, u'name': u' ', u'virtual_size': u'0x0000189c'} entropy 7.6391800766 description A section with a high entropy has been found
section {u'size_of_data': u'0x00000800', u'virtual_address': u'0x0002e000', u'entropy': 7.559446618701814, u'name': u' ', u'virtual_size': u'0x00000a7c'} entropy 7.5594466187 description A section with a high entropy has been found
section {u'size_of_data': u'0x00362e00', u'virtual_address': u'0x0060c000', u'entropy': 7.963969578801031, u'name': u'.boot', u'virtual_size': u'0x00362e00'} entropy 7.9639695788 description A section with a high entropy has been found
entropy 0.999435825106 description Overall entropy of this PE file is high
Time & API Arguments Status Return Repeated

__anomaly__

tid: 1608
message: Encountered 65537 exceptions, quitting.
subcategory: exception
function_name:
1 0 0
Elastic malicious (high confidence)
MicroWorld-eScan Gen:Variant.Mikey.127686
FireEye Generic.mg.7d4a4b1e6c40323b
CAT-QuickHeal Trojan.GenericRI.S22849637
ALYac Gen:Variant.Mikey.127686
Cylance Unsafe
Sangfor Trojan.Win32.Save.a
Cybereason malicious.0537be
Cyren W64/S-6a34bfca!Eldorado
Symantec Trojan.Gen.MBT
ESET-NOD32 a variant of Win64/Packed.Themida.L suspicious
APEX Malicious
Paloalto generic.ml
Kaspersky HEUR:Trojan-Dropper.Win32.Scrop.pef
BitDefender Gen:Variant.Mikey.127686
Avast Win64:DropperX-gen [Drp]
Ad-Aware Gen:Variant.Mikey.127686
Sophos Mal/Generic-S
McAfee-GW-Edition BehavesLike.Win64.Generic.wc
Emsisoft Gen:Variant.Mikey.127686 (B)
SentinelOne Static AI - Malicious PE
MAX malware (ai score=85)
Microsoft Trojan:Win32/Sabsik.FL.B!ml
Gridinsoft Trojan.Heur!.032100A3
GData Gen:Variant.Mikey.127686
Cynet Malicious (score: 100)
AhnLab-V3 Malware/Win.Generic.C4626406
McAfee Artemis!7D4A4B1E6C40
Malwarebytes Trojan.ClipBanker
MaxSecure Trojan.Malware.300983.susgen
Webroot W32.Malware.Gen
AVG Win64:DropperX-gen [Drp]
Panda Trj/CI.A
CrowdStrike win/malicious_confidence_60% (W)