Summary | ZeroBOX

rewend.exe

PE64 PE File
Category Machine Started Completed
FILE s1_win7_x6403_us Nov. 2, 2021, 12:13 p.m. Nov. 2, 2021, 12:16 p.m.
Size 3.3MB
Type PE32+ executable (GUI) x86-64, for MS Windows
MD5 4cff82e973b1d0aa013a8d1fcdce9803
SHA256 31320da1bd5a36a6d6856e06cebbcc07459b9e1354982f33926b491c1beb4864
CRC32 2912B436
ssdeep 98304:rBYR4EvUiaZUOf42G7K64sx0h6keA60HuwWCFy5MCuU7g:f1ZUu96zA60a4
Yara
  • IsPE64 - (no description)
  • PE_Header_Zero - PE File Signature
  • themida_packer - themida packer

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
No hosts contacted.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

section
section .themida
section .boot
Time & API Arguments Status Return Repeated

__exception__

stacktrace:
RaiseException+0x3d FreeEnvironmentStringsW-0x373 kernelbase+0xa49d @ 0x7fefd7da49d
rewend+0x4cc4b5 @ 0x13fdfc4b5
rewend+0x4e3a13 @ 0x13fe13a13
HeapWalk-0x1ce0 kernel32+0x0 @ 0x76d90000
0x1efae8
0x1efae8
0x1efae8
0x3238d4
0x2f3080
0x317b3000000030
0x317b3000000030
0x317b3000000030
0x317b3000000030
0x317b3000000030
0x317b3000000030
0x317b3000000030
0x317b3000000030
0x317b3000000030
0x317b3000000030
0x317b3000000030
0x317b3000000030
0x317b3000000030
0x317b3000000030
0x317b3000000030
0x317b3000000030
0x317b3000000030
0x317b3000000030
0x317b3000000030
0x317b3000000030
0x317b3000000030
0x317b3000000030
0x317b3000000030
0x317b3000000030
0x317b3000000030
0x317b3000000030
0x317b3000000030
0x317b3000000030
0x317b3000000030
0x317b3000000030
0x317b3000000030
0x317b3000000030
0x317b3000000030
0x317b3000000030
0x317b3000000030
0x317b3000000030
0x317b3000000030
0x317b3000000030
0x317b3000000030
0x317b3000000030
0x317b3000000030
0x317b3000000030
0x317b3000000030
0x317b3000000030
0x317b3000000030
0x317b3000000030
0x317b3000000030
0x317b3000000030
0x317b3000000030
0x317b3000000030
0x317b3000000030
0x317b3000000030
0x317b3000000030
0x317b3000000030
0x317b3000000030

exception.instruction_r: 48 81 c4 c8 00 00 00 c3 48 85 f6 74 08 83 3b 00
exception.symbol: RaiseException+0x3d FreeEnvironmentStringsW-0x373 kernelbase+0xa49d
exception.instruction: add rsp, 0xc8
exception.module: KERNELBASE.dll
exception.exception_code: 0xc000008e
exception.offset: 42141
exception.address: 0x7fefd7da49d
registers.r14: 0
registers.r15: 0
registers.rcx: 2028512
registers.rsi: 1998273232
registers.r10: 0
registers.rbx: 5362489334
registers.rsp: 2030336
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2030344
registers.rdi: 5361762304
registers.rax: 2000605882
registers.r13: 0
1 0 0

__exception__

stacktrace:
RtlRestoreContext+0x293 __chkstk-0x1fe ntdll+0x50bd2 @ 0x77120bd2

exception.instruction_r: 48 cf 48 83 ec 30 4c 8b c4 48 81 ec d0 04 00 00
exception.symbol: RtlRestoreContext+0x293 __chkstk-0x1fe ntdll+0x50bd2
exception.instruction: iretq
exception.module: ntdll.dll
exception.exception_code: 0xc0000005
exception.offset: 330706
exception.address: 0x77120bd2
registers.r14: 0
registers.r15: 0
registers.rcx: 2028512
registers.rsi: 0
registers.r10: 0
registers.rbx: 5362489334
registers.rsp: 2030424
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1997522209
registers.rdi: 0
registers.rax: 2000605882
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2028512
registers.rsi: 0
registers.r10: 0
registers.rbx: 5362489334
registers.rsp: 2030424
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1997522209
registers.rdi: 0
registers.rax: 2000605882
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2028512
registers.rsi: 0
registers.r10: 0
registers.rbx: 5362489334
registers.rsp: 2030424
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1997522209
registers.rdi: 0
registers.rax: 2000605882
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2028512
registers.rsi: 0
registers.r10: 0
registers.rbx: 5362489334
registers.rsp: 2030424
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1997522209
registers.rdi: 0
registers.rax: 2000605882
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2028512
registers.rsi: 0
registers.r10: 0
registers.rbx: 5362489334
registers.rsp: 2030424
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1997522209
registers.rdi: 0
registers.rax: 2000605882
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2028512
registers.rsi: 0
registers.r10: 0
registers.rbx: 5362489334
registers.rsp: 2030424
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1997522209
registers.rdi: 0
registers.rax: 2000605882
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2028512
registers.rsi: 0
registers.r10: 0
registers.rbx: 5362489334
registers.rsp: 2030424
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1997522209
registers.rdi: 0
registers.rax: 2000605882
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2028512
registers.rsi: 0
registers.r10: 0
registers.rbx: 5362489334
registers.rsp: 2030424
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1997522209
registers.rdi: 0
registers.rax: 2000605882
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2028512
registers.rsi: 0
registers.r10: 0
registers.rbx: 5362489334
registers.rsp: 2030424
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1997522209
registers.rdi: 0
registers.rax: 2000605882
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2028512
registers.rsi: 0
registers.r10: 0
registers.rbx: 5362489334
registers.rsp: 2030424
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1997522209
registers.rdi: 0
registers.rax: 2000605882
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2028512
registers.rsi: 0
registers.r10: 0
registers.rbx: 5362489334
registers.rsp: 2030424
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1997522209
registers.rdi: 0
registers.rax: 2000605882
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2028512
registers.rsi: 0
registers.r10: 0
registers.rbx: 5362489334
registers.rsp: 2030424
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1997522209
registers.rdi: 0
registers.rax: 2000605882
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2028512
registers.rsi: 0
registers.r10: 0
registers.rbx: 5362489334
registers.rsp: 2030424
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1997522209
registers.rdi: 0
registers.rax: 2000605882
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2028512
registers.rsi: 0
registers.r10: 0
registers.rbx: 5362489334
registers.rsp: 2030424
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1997522209
registers.rdi: 0
registers.rax: 2000605882
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2028512
registers.rsi: 0
registers.r10: 0
registers.rbx: 5362489334
registers.rsp: 2030424
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1997522209
registers.rdi: 0
registers.rax: 2000605882
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2028512
registers.rsi: 0
registers.r10: 0
registers.rbx: 5362489334
registers.rsp: 2030424
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1997522209
registers.rdi: 0
registers.rax: 2000605882
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2028512
registers.rsi: 0
registers.r10: 0
registers.rbx: 5362489334
registers.rsp: 2030424
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1997522209
registers.rdi: 0
registers.rax: 2000605882
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2028512
registers.rsi: 0
registers.r10: 0
registers.rbx: 5362489334
registers.rsp: 2030424
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1997522209
registers.rdi: 0
registers.rax: 2000605882
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2028512
registers.rsi: 0
registers.r10: 0
registers.rbx: 5362489334
registers.rsp: 2030424
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1997522209
registers.rdi: 0
registers.rax: 2000605882
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2028512
registers.rsi: 0
registers.r10: 0
registers.rbx: 5362489334
registers.rsp: 2030424
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1997522209
registers.rdi: 0
registers.rax: 2000605882
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2028512
registers.rsi: 0
registers.r10: 0
registers.rbx: 5362489334
registers.rsp: 2030424
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1997522209
registers.rdi: 0
registers.rax: 2000605882
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2028512
registers.rsi: 0
registers.r10: 0
registers.rbx: 5362489334
registers.rsp: 2030424
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1997522209
registers.rdi: 0
registers.rax: 2000605882
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2028512
registers.rsi: 0
registers.r10: 0
registers.rbx: 5362489334
registers.rsp: 2030424
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1997522209
registers.rdi: 0
registers.rax: 2000605882
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2028512
registers.rsi: 0
registers.r10: 0
registers.rbx: 5362489334
registers.rsp: 2030424
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1997522209
registers.rdi: 0
registers.rax: 2000605882
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2028512
registers.rsi: 0
registers.r10: 0
registers.rbx: 5362489334
registers.rsp: 2030424
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1997522209
registers.rdi: 0
registers.rax: 2000605882
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2028512
registers.rsi: 0
registers.r10: 0
registers.rbx: 5362489334
registers.rsp: 2030424
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1997522209
registers.rdi: 0
registers.rax: 2000605882
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2028512
registers.rsi: 0
registers.r10: 0
registers.rbx: 5362489334
registers.rsp: 2030424
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1997522209
registers.rdi: 0
registers.rax: 2000605882
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2028512
registers.rsi: 0
registers.r10: 0
registers.rbx: 5362489334
registers.rsp: 2030424
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1997522209
registers.rdi: 0
registers.rax: 2000605882
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2028512
registers.rsi: 0
registers.r10: 0
registers.rbx: 5362489334
registers.rsp: 2030424
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1997522209
registers.rdi: 0
registers.rax: 2000605882
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2028512
registers.rsi: 0
registers.r10: 0
registers.rbx: 5362489334
registers.rsp: 2030424
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1997522209
registers.rdi: 0
registers.rax: 2000605882
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2028512
registers.rsi: 0
registers.r10: 0
registers.rbx: 5362489334
registers.rsp: 2030424
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1997522209
registers.rdi: 0
registers.rax: 2000605882
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2028512
registers.rsi: 0
registers.r10: 0
registers.rbx: 5362489334
registers.rsp: 2030424
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1997522209
registers.rdi: 0
registers.rax: 2000605882
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2028512
registers.rsi: 0
registers.r10: 0
registers.rbx: 5362489334
registers.rsp: 2030424
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1997522209
registers.rdi: 0
registers.rax: 2000605882
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2028512
registers.rsi: 0
registers.r10: 0
registers.rbx: 5362489334
registers.rsp: 2030424
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1997522209
registers.rdi: 0
registers.rax: 2000605882
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2028512
registers.rsi: 0
registers.r10: 0
registers.rbx: 5362489334
registers.rsp: 2030424
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1997522209
registers.rdi: 0
registers.rax: 2000605882
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2028512
registers.rsi: 0
registers.r10: 0
registers.rbx: 5362489334
registers.rsp: 2030424
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1997522209
registers.rdi: 0
registers.rax: 2000605882
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2028512
registers.rsi: 0
registers.r10: 0
registers.rbx: 5362489334
registers.rsp: 2030424
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1997522209
registers.rdi: 0
registers.rax: 2000605882
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2028512
registers.rsi: 0
registers.r10: 0
registers.rbx: 5362489334
registers.rsp: 2030424
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1997522209
registers.rdi: 0
registers.rax: 2000605882
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2028512
registers.rsi: 0
registers.r10: 0
registers.rbx: 5362489334
registers.rsp: 2030424
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1997522209
registers.rdi: 0
registers.rax: 2000605882
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2028512
registers.rsi: 0
registers.r10: 0
registers.rbx: 5362489334
registers.rsp: 2030424
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1997522209
registers.rdi: 0
registers.rax: 2000605882
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2028512
registers.rsi: 0
registers.r10: 0
registers.rbx: 5362489334
registers.rsp: 2030424
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1997522209
registers.rdi: 0
registers.rax: 2000605882
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2028512
registers.rsi: 0
registers.r10: 0
registers.rbx: 5362489334
registers.rsp: 2030424
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1997522209
registers.rdi: 0
registers.rax: 2000605882
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2028512
registers.rsi: 0
registers.r10: 0
registers.rbx: 5362489334
registers.rsp: 2030424
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1997522209
registers.rdi: 0
registers.rax: 2000605882
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2028512
registers.rsi: 0
registers.r10: 0
registers.rbx: 5362489334
registers.rsp: 2030424
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1997522209
registers.rdi: 0
registers.rax: 2000605882
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2028512
registers.rsi: 0
registers.r10: 0
registers.rbx: 5362489334
registers.rsp: 2030424
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1997522209
registers.rdi: 0
registers.rax: 2000605882
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2028512
registers.rsi: 0
registers.r10: 0
registers.rbx: 5362489334
registers.rsp: 2030424
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1997522209
registers.rdi: 0
registers.rax: 2000605882
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2028512
registers.rsi: 0
registers.r10: 0
registers.rbx: 5362489334
registers.rsp: 2030424
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1997522209
registers.rdi: 0
registers.rax: 2000605882
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2028512
registers.rsi: 0
registers.r10: 0
registers.rbx: 5362489334
registers.rsp: 2030424
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1997522209
registers.rdi: 0
registers.rax: 2000605882
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2028512
registers.rsi: 0
registers.r10: 0
registers.rbx: 5362489334
registers.rsp: 2030424
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1997522209
registers.rdi: 0
registers.rax: 2000605882
registers.r13: 0
1 0 0
section {u'size_of_data': u'0x0000b000', u'virtual_address': u'0x00001000', u'entropy': 7.973623974456362, u'name': u' ', u'virtual_size': u'0x00014fd0'} entropy 7.97362397446 description A section with a high entropy has been found
section {u'size_of_data': u'0x00005400', u'virtual_address': u'0x00016000', u'entropy': 7.903292727151683, u'name': u' ', u'virtual_size': u'0x0000f51c'} entropy 7.90329272715 description A section with a high entropy has been found
section {u'size_of_data': u'0x00001400', u'virtual_address': u'0x00026000', u'entropy': 7.833517862220187, u'name': u' ', u'virtual_size': u'0x00003778'} entropy 7.83351786222 description A section with a high entropy has been found
section {u'size_of_data': u'0x00000e00', u'virtual_address': u'0x0002a000', u'entropy': 7.593973999934651, u'name': u' ', u'virtual_size': u'0x0000189c'} entropy 7.59397399993 description A section with a high entropy has been found
section {u'size_of_data': u'0x00000800', u'virtual_address': u'0x0002e000', u'entropy': 7.564571648069698, u'name': u' ', u'virtual_size': u'0x00000a7c'} entropy 7.56457164807 description A section with a high entropy has been found
section {u'size_of_data': u'0x00336e00', u'virtual_address': u'0x005da000', u'entropy': 7.964159050975193, u'name': u'.boot', u'virtual_size': u'0x00336e00'} entropy 7.96415905098 description A section with a high entropy has been found
entropy 0.999406352033 description Overall entropy of this PE file is high
Time & API Arguments Status Return Repeated

__anomaly__

tid: 2316
message: Encountered 65537 exceptions, quitting.
subcategory: exception
function_name:
1 0 0
Elastic malicious (high confidence)
MicroWorld-eScan Gen:Variant.Mikey.127686
FireEye Generic.mg.4cff82e973b1d0aa
CAT-QuickHeal Trojan.GenericRI.S22849637
Cylance Unsafe
Sangfor Trojan.Win32.Save.a
Cybereason malicious.a1c3bf
Cyren W64/S-6a34bfca!Eldorado
ESET-NOD32 a variant of Win64/Packed.Themida.L suspicious
APEX Malicious
Kaspersky HEUR:Trojan-Dropper.Win32.Scrop.pef
BitDefender Gen:Variant.Mikey.127686
Avast Win64:CrypterX-gen [Trj]
Ad-Aware Gen:Variant.Mikey.127686
Emsisoft Gen:Variant.Mikey.127686 (B)
McAfee-GW-Edition BehavesLike.Win64.Generic.wc
Sophos Generic ML PUA (PUA)
MAX malware (ai score=86)
Gridinsoft Trojan.Heur!.032100A3
Microsoft Trojan:Win32/Sabsik.FL.B!ml
GData Gen:Variant.Mikey.127686
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win.ClipBanker.C4626406
ALYac Gen:Variant.Mikey.127686
Malwarebytes Trojan.ClipBanker
SentinelOne Static AI - Malicious PE
AVG Win64:CrypterX-gen [Trj]
Panda Trj/CI.A
CrowdStrike win/malicious_confidence_60% (W)
MaxSecure Trojan.Malware.300983.susgen