Summary | ZeroBOX

panmug.exe

PE64 PE File
Category Machine Started Completed
FILE s1_win7_x6403_us Nov. 2, 2021, 11:01 a.m. Nov. 2, 2021, 11:04 a.m.
Size 3.4MB
Type PE32+ executable (GUI) x86-64, for MS Windows
MD5 e917267d185a6a53998fe6abf3eaef49
SHA256 602e290df2ca1016572cd2079ab36205cbc16d61af4fd229ecb4d0eb43af5c34
CRC32 5BEDF07A
ssdeep 49152:xifAhzN4iPnxNIjaGH3Ou3SYNnCZV3GrnxiW2qcwwngaRlM2yKpYr+WMyv:ZqgnxuzX1S+CV2rxnzLmfM2y+YrhMyv
Yara
  • IsPE64 - (no description)
  • PE_Header_Zero - PE File Signature
  • themida_packer - themida packer

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
No hosts contacted.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

section
section .themida
section .boot
Time & API Arguments Status Return Repeated

__exception__

stacktrace:
RaiseException+0x3d FreeEnvironmentStringsW-0x373 kernelbase+0xa49d @ 0x7fefd7da49d
panmug+0x508d30 @ 0x1401f8d30
panmug+0x50d8b0 @ 0x1401fd8b0
HeapWalk-0x1ce0 kernel32+0x0 @ 0x76d90000
0x2ffda8
0x2ffda8
0x2ffda8

exception.instruction_r: 48 81 c4 c8 00 00 00 c3 48 85 f6 74 08 83 3b 00
exception.symbol: RaiseException+0x3d FreeEnvironmentStringsW-0x373 kernelbase+0xa49d
exception.instruction: add rsp, 0xc8
exception.module: KERNELBASE.dll
exception.exception_code: 0xc000008e
exception.offset: 42141
exception.address: 0x7fefd7da49d
registers.r14: 0
registers.r15: 0
registers.rcx: 3143328
registers.rsi: 1998273232
registers.r10: 0
registers.rbx: 0
registers.rsp: 3145136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 3145160
registers.rdi: 5365694464
registers.rax: 1997526037
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3143328
registers.rsi: 1998273232
registers.r10: 0
registers.rbx: 0
registers.rsp: 3145136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 3145160
registers.rdi: 5365694464
registers.rax: 1997526037
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3143328
registers.rsi: 1998273232
registers.r10: 0
registers.rbx: 0
registers.rsp: 3145136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 3145160
registers.rdi: 5365694464
registers.rax: 1997526037
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3143328
registers.rsi: 1998273232
registers.r10: 0
registers.rbx: 0
registers.rsp: 3145136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 3145160
registers.rdi: 5365694464
registers.rax: 1997526037
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3143328
registers.rsi: 1998273232
registers.r10: 0
registers.rbx: 0
registers.rsp: 3145136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 3145160
registers.rdi: 5365694464
registers.rax: 1997526037
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3143328
registers.rsi: 1998273232
registers.r10: 0
registers.rbx: 0
registers.rsp: 3145136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 3145160
registers.rdi: 5365694464
registers.rax: 1997526037
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3143328
registers.rsi: 1998273232
registers.r10: 0
registers.rbx: 0
registers.rsp: 3145136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 3145160
registers.rdi: 5365694464
registers.rax: 1997526037
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3143328
registers.rsi: 1998273232
registers.r10: 0
registers.rbx: 0
registers.rsp: 3145136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 3145160
registers.rdi: 5365694464
registers.rax: 1997526037
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3143328
registers.rsi: 1998273232
registers.r10: 0
registers.rbx: 0
registers.rsp: 3145136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 3145160
registers.rdi: 5365694464
registers.rax: 1997526037
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3143328
registers.rsi: 1998273232
registers.r10: 0
registers.rbx: 0
registers.rsp: 3145136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 3145160
registers.rdi: 5365694464
registers.rax: 1997526037
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3143328
registers.rsi: 1998273232
registers.r10: 0
registers.rbx: 0
registers.rsp: 3145136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 3145160
registers.rdi: 5365694464
registers.rax: 1997526037
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3143328
registers.rsi: 1998273232
registers.r10: 0
registers.rbx: 0
registers.rsp: 3145136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 3145160
registers.rdi: 5365694464
registers.rax: 1997526037
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3143328
registers.rsi: 1998273232
registers.r10: 0
registers.rbx: 0
registers.rsp: 3145136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 3145160
registers.rdi: 5365694464
registers.rax: 1997526037
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3143328
registers.rsi: 1998273232
registers.r10: 0
registers.rbx: 0
registers.rsp: 3145136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 3145160
registers.rdi: 5365694464
registers.rax: 1997526037
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3143328
registers.rsi: 1998273232
registers.r10: 0
registers.rbx: 0
registers.rsp: 3145136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 3145160
registers.rdi: 5365694464
registers.rax: 1997526037
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3143328
registers.rsi: 1998273232
registers.r10: 0
registers.rbx: 0
registers.rsp: 3145136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 3145160
registers.rdi: 5365694464
registers.rax: 1997526037
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3143328
registers.rsi: 1998273232
registers.r10: 0
registers.rbx: 0
registers.rsp: 3145136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 3145160
registers.rdi: 5365694464
registers.rax: 1997526037
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3143328
registers.rsi: 1998273232
registers.r10: 0
registers.rbx: 0
registers.rsp: 3145136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 3145160
registers.rdi: 5365694464
registers.rax: 1997526037
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3143328
registers.rsi: 1998273232
registers.r10: 0
registers.rbx: 0
registers.rsp: 3145136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 3145160
registers.rdi: 5365694464
registers.rax: 1997526037
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3143328
registers.rsi: 1998273232
registers.r10: 0
registers.rbx: 0
registers.rsp: 3145136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 3145160
registers.rdi: 5365694464
registers.rax: 1997526037
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3143328
registers.rsi: 1998273232
registers.r10: 0
registers.rbx: 0
registers.rsp: 3145136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 3145160
registers.rdi: 5365694464
registers.rax: 1997526037
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3143328
registers.rsi: 1998273232
registers.r10: 0
registers.rbx: 0
registers.rsp: 3145136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 3145160
registers.rdi: 5365694464
registers.rax: 1997526037
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3143328
registers.rsi: 1998273232
registers.r10: 0
registers.rbx: 0
registers.rsp: 3145136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 3145160
registers.rdi: 5365694464
registers.rax: 1997526037
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3143328
registers.rsi: 1998273232
registers.r10: 0
registers.rbx: 0
registers.rsp: 3145136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 3145160
registers.rdi: 5365694464
registers.rax: 1997526037
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3143328
registers.rsi: 1998273232
registers.r10: 0
registers.rbx: 0
registers.rsp: 3145136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 3145160
registers.rdi: 5365694464
registers.rax: 1997526037
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3143328
registers.rsi: 1998273232
registers.r10: 0
registers.rbx: 0
registers.rsp: 3145136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 3145160
registers.rdi: 5365694464
registers.rax: 1997526037
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3143328
registers.rsi: 1998273232
registers.r10: 0
registers.rbx: 0
registers.rsp: 3145136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 3145160
registers.rdi: 5365694464
registers.rax: 1997526037
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3143328
registers.rsi: 1998273232
registers.r10: 0
registers.rbx: 0
registers.rsp: 3145136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 3145160
registers.rdi: 5365694464
registers.rax: 1997526037
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3143328
registers.rsi: 1998273232
registers.r10: 0
registers.rbx: 0
registers.rsp: 3145136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 3145160
registers.rdi: 5365694464
registers.rax: 1997526037
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3143328
registers.rsi: 1998273232
registers.r10: 0
registers.rbx: 0
registers.rsp: 3145136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 3145160
registers.rdi: 5365694464
registers.rax: 1997526037
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3143328
registers.rsi: 1998273232
registers.r10: 0
registers.rbx: 0
registers.rsp: 3145136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 3145160
registers.rdi: 5365694464
registers.rax: 1997526037
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3143328
registers.rsi: 1998273232
registers.r10: 0
registers.rbx: 0
registers.rsp: 3145136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 3145160
registers.rdi: 5365694464
registers.rax: 1997526037
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3143328
registers.rsi: 1998273232
registers.r10: 0
registers.rbx: 0
registers.rsp: 3145136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 3145160
registers.rdi: 5365694464
registers.rax: 1997526037
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3143328
registers.rsi: 1998273232
registers.r10: 0
registers.rbx: 0
registers.rsp: 3145136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 3145160
registers.rdi: 5365694464
registers.rax: 1997526037
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3143328
registers.rsi: 1998273232
registers.r10: 0
registers.rbx: 0
registers.rsp: 3145136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 3145160
registers.rdi: 5365694464
registers.rax: 1997526037
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3143328
registers.rsi: 1998273232
registers.r10: 0
registers.rbx: 0
registers.rsp: 3145136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 3145160
registers.rdi: 5365694464
registers.rax: 1997526037
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3143328
registers.rsi: 1998273232
registers.r10: 0
registers.rbx: 0
registers.rsp: 3145136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 3145160
registers.rdi: 5365694464
registers.rax: 1997526037
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3143328
registers.rsi: 1998273232
registers.r10: 0
registers.rbx: 0
registers.rsp: 3145136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 3145160
registers.rdi: 5365694464
registers.rax: 1997526037
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3143328
registers.rsi: 1998273232
registers.r10: 0
registers.rbx: 0
registers.rsp: 3145136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 3145160
registers.rdi: 5365694464
registers.rax: 1997526037
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3143328
registers.rsi: 1998273232
registers.r10: 0
registers.rbx: 0
registers.rsp: 3145136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 3145160
registers.rdi: 5365694464
registers.rax: 1997526037
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3143328
registers.rsi: 1998273232
registers.r10: 0
registers.rbx: 0
registers.rsp: 3145136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 3145160
registers.rdi: 5365694464
registers.rax: 1997526037
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3143328
registers.rsi: 1998273232
registers.r10: 0
registers.rbx: 0
registers.rsp: 3145136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 3145160
registers.rdi: 5365694464
registers.rax: 1997526037
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3143328
registers.rsi: 1998273232
registers.r10: 0
registers.rbx: 0
registers.rsp: 3145136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 3145160
registers.rdi: 5365694464
registers.rax: 1997526037
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3143328
registers.rsi: 1998273232
registers.r10: 0
registers.rbx: 0
registers.rsp: 3145136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 3145160
registers.rdi: 5365694464
registers.rax: 1997526037
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3143328
registers.rsi: 1998273232
registers.r10: 0
registers.rbx: 0
registers.rsp: 3145136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 3145160
registers.rdi: 5365694464
registers.rax: 1997526037
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3143328
registers.rsi: 1998273232
registers.r10: 0
registers.rbx: 0
registers.rsp: 3145136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 3145160
registers.rdi: 5365694464
registers.rax: 1997526037
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3143328
registers.rsi: 1998273232
registers.r10: 0
registers.rbx: 0
registers.rsp: 3145136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 3145160
registers.rdi: 5365694464
registers.rax: 1997526037
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3143328
registers.rsi: 1998273232
registers.r10: 0
registers.rbx: 0
registers.rsp: 3145136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 3145160
registers.rdi: 5365694464
registers.rax: 1997526037
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3143328
registers.rsi: 1998273232
registers.r10: 0
registers.rbx: 0
registers.rsp: 3145136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 3145160
registers.rdi: 5365694464
registers.rax: 1997526037
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 3143328
registers.rsi: 1998273232
registers.r10: 0
registers.rbx: 0
registers.rsp: 3145136
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 3145160
registers.rdi: 5365694464
registers.rax: 1997526037
registers.r13: 0
1 0 0
Time & API Arguments Status Return Repeated

NtProtectVirtualMemory

process_identifier: 2312
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 8192
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00000000771c7000
process_handle: 0xffffffffffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2312
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 8192
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0000000077120000
process_handle: 0xffffffffffffffff
1 0 0
section {u'size_of_data': u'0x0000b000', u'virtual_address': u'0x00001000', u'entropy': 7.985890653756536, u'name': u' ', u'virtual_size': u'0x00014fd0'} entropy 7.98589065376 description A section with a high entropy has been found
section {u'size_of_data': u'0x00005400', u'virtual_address': u'0x00016000', u'entropy': 7.892328948705118, u'name': u' ', u'virtual_size': u'0x0000f51c'} entropy 7.89232894871 description A section with a high entropy has been found
section {u'size_of_data': u'0x00001400', u'virtual_address': u'0x00026000', u'entropy': 7.893424594864925, u'name': u' ', u'virtual_size': u'0x00003778'} entropy 7.89342459486 description A section with a high entropy has been found
section {u'size_of_data': u'0x00000e00', u'virtual_address': u'0x0002a000', u'entropy': 7.633112413719036, u'name': u' ', u'virtual_size': u'0x0000189c'} entropy 7.63311241372 description A section with a high entropy has been found
section {u'size_of_data': u'0x00000800', u'virtual_address': u'0x0002e000', u'entropy': 7.575364223155216, u'name': u' ', u'virtual_size': u'0x00000a7c'} entropy 7.57536422316 description A section with a high entropy has been found
section {u'size_of_data': u'0x00347a00', u'virtual_address': u'0x005da000', u'entropy': 7.961864442907846, u'name': u'.boot', u'virtual_size': u'0x00347a00'} entropy 7.96186444291 description A section with a high entropy has been found
entropy 0.999417927823 description Overall entropy of this PE file is high
Time & API Arguments Status Return Repeated

__anomaly__

tid: 2316
message: Encountered 65537 exceptions, quitting.
subcategory: exception
function_name:
1 0 0
Lionic Trojan.Win64.Agentb.trtl
Elastic malicious (high confidence)
CAT-QuickHeal Trojan.GenericRI.S22849637
McAfee Artemis!E917267D185A
Cylance Unsafe
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 0057a4f61 )
BitDefender Gen:Variant.Mikey.127686
K7GW Trojan ( 0057a4f61 )
CrowdStrike win/malicious_confidence_60% (W)
Arcabit Trojan.Mikey.D1F2C6
Cyren W64/S-6a34bfca!Eldorado
Symantec Trojan.Gen.MBT
ESET-NOD32 Win64/Agent.AWB
APEX Malicious
Avast Win64:CrypterX-gen [Trj]
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan-Dropper.Win32.Scrop.pef
MicroWorld-eScan Gen:Variant.Mikey.127686
Ad-Aware Gen:Variant.Mikey.127686
Emsisoft Gen:Variant.Mikey.127686 (B)
F-Secure Trojan.TR/Drop.Scrop.ecpqt
TrendMicro TROJ_FRS.0NA103K121
McAfee-GW-Edition BehavesLike.Win64.Generic.wc
FireEye Generic.mg.e917267d185a6a53
Sophos Generic ML PUA (PUA)
Ikarus Win32.Outbreak
Webroot W32.Trojan.Gen
Avira TR/Drop.Scrop.ecpqt
MAX malware (ai score=84)
Kingsoft Win32.Troj.Undef.(kcloud)
Gridinsoft Trojan.Win64.Packed.vb
Microsoft TrojanDownloader:O97M/Obfuse.KY!MTB
ZoneAlarm HEUR:Trojan-Dropper.Win32.Scrop.pef
GData Gen:Variant.Mikey.127686
AhnLab-V3 Trojan/Win.ClipBanker.C4626406
ALYac Gen:Variant.Mikey.127686
Malwarebytes Trojan.ClipBanker
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet Riskware/Application
AVG Win64:CrypterX-gen [Trj]
Cybereason malicious.090f9e
Paloalto generic.ml