Summary | ZeroBOX

Bt1_soft.exe

Generic Malware UPX PE64 PE File
Category Machine Started Completed
FILE s1_win7_x6401 March 7, 2023, 9:44 a.m. March 7, 2023, 9:46 a.m.
Size 5.2MB
Type PE32+ executable (GUI) x86-64 (stripped to external PDB), for MS Windows
MD5 cc290b4105ef5a94aba6d767c8bbc2de
SHA256 6ad4906b570eaa52a5c78e98f2273daf5c60248615a502e123d5b7d8b53d9fff
CRC32 119D5F53
ssdeep 98304:ggx2R7dmm8wDy4itwxdl8OGhMVvFTmeBLy4h+5YXTtGLW9ejhky6V/lDx3SHSylR:z2huwDktaRvkDYcBL
Yara
  • Generic_Malware_Zero - Generic Malware
  • UPX_Zero - UPX packed file
  • PE_Header_Zero - PE File Signature
  • IsPE64 - (no description)

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
No hosts contacted.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

section
section .themida
resource name CSR1
resource name PNG
resource name SHADER
resource name SVG
Time & API Arguments Status Return Repeated

__exception__

stacktrace:
RaiseException+0x3d FreeEnvironmentStringsW-0x373 kernelbase+0xa49d @ 0x7fefd4fa49d
bt1_soft+0x89a968 @ 0x194a968
bt1_soft+0x89a933 @ 0x194a933
HeapWalk-0x1ce0 kernel32+0x0 @ 0x76c10000
0x25fbb8
0x25fbb8
0x25fbb8
0x35ef04
0x333082
0x35b42000000030
0x35b42000000030
0x35b42000000030
0x35b42000000030
0x35b42000000030
0x35b42000000030
0x35b42000000030
0x35b42000000030
0x35b42000000030
0x35b42000000030
0x35b42000000030
0x35b42000000030
0x35b42000000030
0x35b42000000030
0x35b42000000030
0x35b42000000030
0x35b42000000030
0x35b42000000030
0x35b42000000030
0x35b42000000030
0x35b42000000030
0x35b42000000030
0x35b42000000030
0x35b42000000030
0x35b42000000030
0x35b42000000030
0x35b42000000030
0x35b42000000030
0x35b42000000030
0x35b42000000030
0x35b42000000030
0x35b42000000030
0x35b42000000030
0x35b42000000030
0x35b42000000030
0x35b42000000030
0x35b42000000030
0x35b42000000030
0x35b42000000030
0x35b42000000030
0x35b42000000030
0x35b42000000030
0x35b42000000030
0x35b42000000030
0x35b42000000030
0x35b42000000030
0x35b42000000030
0x35b42000000030
0x35b42000000030
0x35b42000000030
0x35b42000000030
0x35b42000000030
0x35b42000000030
0x35b42000000030
0x35b42000000030

exception.instruction_r: 48 81 c4 c8 00 00 00 c3 48 85 f6 74 08 83 3b 00
exception.symbol: RaiseException+0x3d FreeEnvironmentStringsW-0x373 kernelbase+0xa49d
exception.instruction: add rsp, 0xc8
exception.module: KERNELBASE.dll
exception.exception_code: 0xc000008e
exception.offset: 42141
exception.address: 0x7fefd4fa49d
registers.r14: 0
registers.r15: 0
registers.rcx: 2487472
registers.rsi: 1994472144
registers.r10: 0
registers.rbx: 25296939
registers.rsp: 2489296
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2489304
registers.rdi: 23855104
registers.rax: 1992536092
registers.r13: 0
1 0 0

__exception__

stacktrace:
RtlRestoreContext+0x293 __chkstk-0x1fe ntdll+0x50bd2 @ 0x76d80bd2

exception.instruction_r: 48 cf 48 83 ec 30 4c 8b c4 48 81 ec d0 04 00 00
exception.symbol: RtlRestoreContext+0x293 __chkstk-0x1fe ntdll+0x50bd2
exception.instruction: iretq
exception.module: ntdll.dll
exception.exception_code: 0xc0000005
exception.offset: 330706
exception.address: 0x76d80bd2
registers.r14: 0
registers.r15: 0
registers.rcx: 2487472
registers.rsi: 0
registers.r10: 0
registers.rbx: 25296939
registers.rsp: 2489384
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1992536092
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2487472
registers.rsi: 0
registers.r10: 0
registers.rbx: 25296939
registers.rsp: 2489384
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1992536092
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2487472
registers.rsi: 0
registers.r10: 0
registers.rbx: 25296939
registers.rsp: 2489384
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1992536092
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2487472
registers.rsi: 0
registers.r10: 0
registers.rbx: 25296939
registers.rsp: 2489384
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1992536092
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2487472
registers.rsi: 0
registers.r10: 0
registers.rbx: 25296939
registers.rsp: 2489384
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1992536092
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2487472
registers.rsi: 0
registers.r10: 0
registers.rbx: 25296939
registers.rsp: 2489384
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1992536092
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2487472
registers.rsi: 0
registers.r10: 0
registers.rbx: 25296939
registers.rsp: 2489384
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1992536092
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2487472
registers.rsi: 0
registers.r10: 0
registers.rbx: 25296939
registers.rsp: 2489384
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1992536092
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2487472
registers.rsi: 0
registers.r10: 0
registers.rbx: 25296939
registers.rsp: 2489384
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1992536092
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2487472
registers.rsi: 0
registers.r10: 0
registers.rbx: 25296939
registers.rsp: 2489384
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1992536092
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2487472
registers.rsi: 0
registers.r10: 0
registers.rbx: 25296939
registers.rsp: 2489384
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1992536092
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2487472
registers.rsi: 0
registers.r10: 0
registers.rbx: 25296939
registers.rsp: 2489384
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1992536092
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2487472
registers.rsi: 0
registers.r10: 0
registers.rbx: 25296939
registers.rsp: 2489384
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1992536092
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2487472
registers.rsi: 0
registers.r10: 0
registers.rbx: 25296939
registers.rsp: 2489384
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1992536092
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2487472
registers.rsi: 0
registers.r10: 0
registers.rbx: 25296939
registers.rsp: 2489384
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1992536092
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2487472
registers.rsi: 0
registers.r10: 0
registers.rbx: 25296939
registers.rsp: 2489384
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1992536092
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2487472
registers.rsi: 0
registers.r10: 0
registers.rbx: 25296939
registers.rsp: 2489384
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1992536092
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2487472
registers.rsi: 0
registers.r10: 0
registers.rbx: 25296939
registers.rsp: 2489384
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1992536092
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2487472
registers.rsi: 0
registers.r10: 0
registers.rbx: 25296939
registers.rsp: 2489384
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1992536092
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2487472
registers.rsi: 0
registers.r10: 0
registers.rbx: 25296939
registers.rsp: 2489384
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1992536092
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2487472
registers.rsi: 0
registers.r10: 0
registers.rbx: 25296939
registers.rsp: 2489384
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1992536092
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2487472
registers.rsi: 0
registers.r10: 0
registers.rbx: 25296939
registers.rsp: 2489384
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1992536092
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2487472
registers.rsi: 0
registers.r10: 0
registers.rbx: 25296939
registers.rsp: 2489384
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1992536092
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2487472
registers.rsi: 0
registers.r10: 0
registers.rbx: 25296939
registers.rsp: 2489384
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1992536092
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2487472
registers.rsi: 0
registers.r10: 0
registers.rbx: 25296939
registers.rsp: 2489384
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1992536092
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2487472
registers.rsi: 0
registers.r10: 0
registers.rbx: 25296939
registers.rsp: 2489384
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1992536092
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2487472
registers.rsi: 0
registers.r10: 0
registers.rbx: 25296939
registers.rsp: 2489384
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1992536092
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2487472
registers.rsi: 0
registers.r10: 0
registers.rbx: 25296939
registers.rsp: 2489384
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1992536092
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2487472
registers.rsi: 0
registers.r10: 0
registers.rbx: 25296939
registers.rsp: 2489384
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1992536092
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2487472
registers.rsi: 0
registers.r10: 0
registers.rbx: 25296939
registers.rsp: 2489384
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1992536092
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2487472
registers.rsi: 0
registers.r10: 0
registers.rbx: 25296939
registers.rsp: 2489384
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1992536092
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2487472
registers.rsi: 0
registers.r10: 0
registers.rbx: 25296939
registers.rsp: 2489384
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1992536092
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2487472
registers.rsi: 0
registers.r10: 0
registers.rbx: 25296939
registers.rsp: 2489384
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1992536092
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2487472
registers.rsi: 0
registers.r10: 0
registers.rbx: 25296939
registers.rsp: 2489384
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1992536092
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2487472
registers.rsi: 0
registers.r10: 0
registers.rbx: 25296939
registers.rsp: 2489384
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1992536092
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2487472
registers.rsi: 0
registers.r10: 0
registers.rbx: 25296939
registers.rsp: 2489384
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1992536092
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2487472
registers.rsi: 0
registers.r10: 0
registers.rbx: 25296939
registers.rsp: 2489384
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1992536092
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2487472
registers.rsi: 0
registers.r10: 0
registers.rbx: 25296939
registers.rsp: 2489384
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1992536092
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2487472
registers.rsi: 0
registers.r10: 0
registers.rbx: 25296939
registers.rsp: 2489384
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1992536092
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2487472
registers.rsi: 0
registers.r10: 0
registers.rbx: 25296939
registers.rsp: 2489384
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1992536092
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2487472
registers.rsi: 0
registers.r10: 0
registers.rbx: 25296939
registers.rsp: 2489384
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1992536092
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2487472
registers.rsi: 0
registers.r10: 0
registers.rbx: 25296939
registers.rsp: 2489384
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1992536092
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2487472
registers.rsi: 0
registers.r10: 0
registers.rbx: 25296939
registers.rsp: 2489384
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1992536092
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2487472
registers.rsi: 0
registers.r10: 0
registers.rbx: 25296939
registers.rsp: 2489384
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1992536092
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2487472
registers.rsi: 0
registers.r10: 0
registers.rbx: 25296939
registers.rsp: 2489384
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1992536092
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2487472
registers.rsi: 0
registers.r10: 0
registers.rbx: 25296939
registers.rsp: 2489384
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1992536092
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2487472
registers.rsi: 0
registers.r10: 0
registers.rbx: 25296939
registers.rsp: 2489384
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1992536092
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2487472
registers.rsi: 0
registers.r10: 0
registers.rbx: 25296939
registers.rsp: 2489384
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1992536092
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2487472
registers.rsi: 0
registers.r10: 0
registers.rbx: 25296939
registers.rsp: 2489384
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1992536092
registers.r13: 0
1 0 0
Time & API Arguments Status Return Repeated

NtProtectVirtualMemory

process_identifier: 2548
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 8192
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0000000076e27000
process_handle: 0xffffffffffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2548
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 8192
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0000000076d80000
process_handle: 0xffffffffffffffff
1 0 0
section {u'size_of_data': u'0x000c5000', u'virtual_address': u'0x00001000', u'entropy': 7.999790869210646, u'name': u' ', u'virtual_size': u'0x0027da5b'} entropy 7.99979086921 description A section with a high entropy has been found
section {u'size_of_data': u'0x000b2a00', u'virtual_address': u'0x0027f000', u'entropy': 7.999742626203883, u'name': u' ', u'virtual_size': u'0x002420d8'} entropy 7.9997426262 description A section with a high entropy has been found
section {u'size_of_data': u'0x00015000', u'virtual_address': u'0x004c2000', u'entropy': 7.997641174926343, u'name': u' ', u'virtual_size': u'0x000b5d40'} entropy 7.99764117493 description A section with a high entropy has been found
section {u'size_of_data': u'0x00002a00', u'virtual_address': u'0x00579000', u'entropy': 7.916073881175904, u'name': u' ', u'virtual_size': u'0x0000c07e'} entropy 7.91607388118 description A section with a high entropy has been found
section {u'size_of_data': u'0x00087c00', u'virtual_address': u'0x00587000', u'entropy': 7.216674799619246, u'name': u'.rsrc', u'virtual_size': u'0x00087b97'} entropy 7.21667479962 description A section with a high entropy has been found
entropy 0.400636525321 description Overall entropy of this PE file is high
Time & API Arguments Status Return Repeated

__anomaly__

tid: 2552
message: Encountered 65537 exceptions, quitting.
subcategory: exception
function_name:
1 0 0
Lionic Trojan.Win32.Foreign.1f!c
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.GenericKD.65801960
FireEye Trojan.GenericKD.65801960
Sangfor Trojan.Win32.Agent.Vohu
CrowdStrike win/malicious_confidence_60% (W)
Arcabit Trojan.Generic.D3EC0EE8
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/GenCBL.DQU
Cynet Malicious (score: 99)
Paloalto generic.ml
Kaspersky Trojan-Ransom.Win32.Foreign.ompc
BitDefender Trojan.GenericKD.65801960
Avast Win64:Evo-gen [Trj]
Tencent Win32.Trojan.FalseSign.Bkjl
McAfee-GW-Edition Artemis!Trojan
Trapmine malicious.high.ml.score
Emsisoft Trojan.GenericKD.65801960 (B)
Webroot W32.Trojan.Gen
Avira TR/Foreign.ncsiu
Antiy-AVL Trojan[Ransom]/Win32.Foreign
Gridinsoft Ransom.Win64.Wacatac.sa
Microsoft Trojan:Win32/Casdet!rfn
ZoneAlarm Trojan-Ransom.Win32.Foreign.ompc
GData Trojan.GenericKD.65801960
Google Detected
McAfee Artemis!CC290B4105EF
MAX malware (ai score=82)
Rising Ransom.Foreign!8.292 (CLOUD)
Ikarus Win32.Outbreak
AVG Win64:Evo-gen [Trj]