Summary | ZeroBOX

sp.exe

Generic Malware Malicious Library PE64 PE File
Category Machine Started Completed
FILE s1_win7_x6403_us June 2, 2023, 5:31 p.m. June 2, 2023, 5:34 p.m.
Size 4.6MB
Type PE32+ executable (GUI) x86-64, for MS Windows
MD5 45d50af2dab49aa0de4894a1bbff7d62
SHA256 e84531a3eef229dafb604be21d54c4abfd71efdf132ec141a2ca770d436673d4
CRC32 F03D5C1E
ssdeep 98304:5l1JDX/FWuaPGwguuBnDgMyb3egMT/ia0ctMl6bSfsoCRES9Hp:jHT/5aPDgfpYuFjRG0wo
Yara
  • themida_packer - themida packer
  • Malicious_Library_Zero - Malicious_Library
  • IsPE64 - (no description)
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
No hosts contacted.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

section
section .themida
section .boot
Time & API Arguments Status Return Repeated

__exception__

stacktrace:
RaiseException+0x3d FreeEnvironmentStringsW-0x373 kernelbase+0xa49d @ 0x7fefdbfa49d
sp+0x525c35 @ 0x140235c35
sp+0x50f64a @ 0x14021f64a
HeapWalk-0x1ce0 kernel32+0x0 @ 0x76fc0000
0x2bf778
0x2bf778
0x2bf778

exception.instruction_r: 48 81 c4 c8 00 00 00 c3 48 85 f6 74 08 83 3b 00
exception.symbol: RaiseException+0x3d FreeEnvironmentStringsW-0x373 kernelbase+0xa49d
exception.instruction: add rsp, 0xc8
exception.module: KERNELBASE.dll
exception.exception_code: 0xc000008e
exception.offset: 42141
exception.address: 0x7fefdbfa49d
registers.r14: 0
registers.r15: 0
registers.rcx: 2879600
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 2881408
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2881432
registers.rdi: 5368262656
registers.rax: 2002118620
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2879600
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 2881408
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2881432
registers.rdi: 5368262656
registers.rax: 2002118620
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2879600
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 2881408
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2881432
registers.rdi: 5368262656
registers.rax: 2002118620
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2879600
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 2881408
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2881432
registers.rdi: 5368262656
registers.rax: 2002118620
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2879600
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 2881408
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2881432
registers.rdi: 5368262656
registers.rax: 2002118620
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2879600
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 2881408
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2881432
registers.rdi: 5368262656
registers.rax: 2002118620
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2879600
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 2881408
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2881432
registers.rdi: 5368262656
registers.rax: 2002118620
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2879600
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 2881408
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2881432
registers.rdi: 5368262656
registers.rax: 2002118620
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2879600
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 2881408
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2881432
registers.rdi: 5368262656
registers.rax: 2002118620
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2879600
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 2881408
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2881432
registers.rdi: 5368262656
registers.rax: 2002118620
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2879600
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 2881408
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2881432
registers.rdi: 5368262656
registers.rax: 2002118620
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2879600
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 2881408
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2881432
registers.rdi: 5368262656
registers.rax: 2002118620
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2879600
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 2881408
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2881432
registers.rdi: 5368262656
registers.rax: 2002118620
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2879600
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 2881408
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2881432
registers.rdi: 5368262656
registers.rax: 2002118620
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2879600
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 2881408
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2881432
registers.rdi: 5368262656
registers.rax: 2002118620
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2879600
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 2881408
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2881432
registers.rdi: 5368262656
registers.rax: 2002118620
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2879600
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 2881408
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2881432
registers.rdi: 5368262656
registers.rax: 2002118620
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2879600
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 2881408
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2881432
registers.rdi: 5368262656
registers.rax: 2002118620
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2879600
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 2881408
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2881432
registers.rdi: 5368262656
registers.rax: 2002118620
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2879600
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 2881408
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2881432
registers.rdi: 5368262656
registers.rax: 2002118620
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2879600
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 2881408
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2881432
registers.rdi: 5368262656
registers.rax: 2002118620
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2879600
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 2881408
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2881432
registers.rdi: 5368262656
registers.rax: 2002118620
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2879600
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 2881408
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2881432
registers.rdi: 5368262656
registers.rax: 2002118620
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2879600
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 2881408
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2881432
registers.rdi: 5368262656
registers.rax: 2002118620
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2879600
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 2881408
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2881432
registers.rdi: 5368262656
registers.rax: 2002118620
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2879600
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 2881408
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2881432
registers.rdi: 5368262656
registers.rax: 2002118620
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2879600
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 2881408
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2881432
registers.rdi: 5368262656
registers.rax: 2002118620
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2879600
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 2881408
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2881432
registers.rdi: 5368262656
registers.rax: 2002118620
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2879600
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 2881408
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2881432
registers.rdi: 5368262656
registers.rax: 2002118620
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2879600
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 2881408
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2881432
registers.rdi: 5368262656
registers.rax: 2002118620
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2879600
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 2881408
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2881432
registers.rdi: 5368262656
registers.rax: 2002118620
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2879600
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 2881408
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2881432
registers.rdi: 5368262656
registers.rax: 2002118620
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2879600
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 2881408
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2881432
registers.rdi: 5368262656
registers.rax: 2002118620
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2879600
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 2881408
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2881432
registers.rdi: 5368262656
registers.rax: 2002118620
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2879600
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 2881408
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2881432
registers.rdi: 5368262656
registers.rax: 2002118620
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2879600
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 2881408
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2881432
registers.rdi: 5368262656
registers.rax: 2002118620
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2879600
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 2881408
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2881432
registers.rdi: 5368262656
registers.rax: 2002118620
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2879600
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 2881408
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2881432
registers.rdi: 5368262656
registers.rax: 2002118620
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2879600
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 2881408
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2881432
registers.rdi: 5368262656
registers.rax: 2002118620
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2879600
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 2881408
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2881432
registers.rdi: 5368262656
registers.rax: 2002118620
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2879600
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 2881408
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2881432
registers.rdi: 5368262656
registers.rax: 2002118620
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2879600
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 2881408
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2881432
registers.rdi: 5368262656
registers.rax: 2002118620
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2879600
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 2881408
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2881432
registers.rdi: 5368262656
registers.rax: 2002118620
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2879600
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 2881408
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2881432
registers.rdi: 5368262656
registers.rax: 2002118620
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2879600
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 2881408
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2881432
registers.rdi: 5368262656
registers.rax: 2002118620
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2879600
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 2881408
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2881432
registers.rdi: 5368262656
registers.rax: 2002118620
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2879600
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 2881408
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2881432
registers.rdi: 5368262656
registers.rax: 2002118620
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2879600
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 2881408
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2881432
registers.rdi: 5368262656
registers.rax: 2002118620
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2879600
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 2881408
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2881432
registers.rdi: 5368262656
registers.rax: 2002118620
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 2879600
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 2881408
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 2881432
registers.rdi: 5368262656
registers.rax: 2002118620
registers.r13: 0
1 0 0
Time & API Arguments Status Return Repeated

NtProtectVirtualMemory

process_identifier: 1372
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 8192
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00000000777b7000
process_handle: 0xffffffffffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1372
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 8192
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0000000077710000
process_handle: 0xffffffffffffffff
1 0 0
section {u'size_of_data': u'0x00006800', u'virtual_address': u'0x00001000', u'entropy': 7.961754572566071, u'name': u' ', u'virtual_size': u'0x0000b754'} entropy 7.96175457257 description A section with a high entropy has been found
section {u'size_of_data': u'0x00262600', u'virtual_address': u'0x0000d000', u'entropy': 7.999557745095409, u'name': u' ', u'virtual_size': u'0x00263780'} entropy 7.9995577451 description A section with a high entropy has been found
section {u'size_of_data': u'0x00000400', u'virtual_address': u'0x00271000', u'entropy': 7.020226444115248, u'name': u' ', u'virtual_size': u'0x000005f4'} entropy 7.02022644412 description A section with a high entropy has been found
section {u'size_of_data': u'0x00002c00', u'virtual_address': u'0x00272000', u'entropy': 7.937504830616991, u'name': u' ', u'virtual_size': u'0x00007000'} entropy 7.93750483062 description A section with a high entropy has been found
section {u'size_of_data': u'0x0022fc00', u'virtual_address': u'0x005d5000', u'entropy': 7.942371672245095, u'name': u'.boot', u'virtual_size': u'0x0022fc00'} entropy 7.94237167225 description A section with a high entropy has been found
entropy 0.994310399326 description Overall entropy of this PE file is high
Time & API Arguments Status Return Repeated

__anomaly__

tid: 652
message: Encountered 65537 exceptions, quitting.
subcategory: exception
function_name:
1 0 0
Lionic Trojan.Win64.Agentb.trtl
DrWeb Trojan.Inject4.57962
MicroWorld-eScan Application.Generic.3452804
FireEye Generic.mg.45d50af2dab49aa0
ALYac Application.Generic.3452804
VIPRE Application.Generic.3452804
Sangfor Trojan.Win64.Agent.Vg44
Alibaba Trojan:Win64/Zenpak.22bd4fce
CrowdStrike win/malicious_confidence_70% (W)
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of Win64/Packed.Themida.L suspicious
Cynet Malicious (score: 99)
Kaspersky Trojan.Win64.Zenpak.cak
BitDefender Application.Generic.3452804
Avast Win64:Malware-gen
Tencent Win64.Trojan.Zenpak.Usmw
Emsisoft Application.Generic.3452804 (B)
F-Secure Heuristic.HEUR/AGEN.1360791
McAfee-GW-Edition BehavesLike.Win64.Backdoor.rc
Trapmine suspicious.low.ml.score
Sophos Mal/Generic-S
Avira HEUR/AGEN.1360791
Microsoft Trojan:Win32/Woreflint.A!cl
Gridinsoft Trojan.Win64.Packed.cl
Arcabit Application.Generic.D34AF84
ZoneAlarm Trojan.Win64.Zenpak.cak
GData Win64.Trojan.Agent.A5ACWX
McAfee Artemis!45D50AF2DAB4
MAX malware (ai score=74)
Cylance unsafe
Zoner Probably Heur.ExeHeaderL
TrendMicro-HouseCall TROJ_GEN.R002H07EV23
Rising Trojan.Zenpak!8.10372 (CLOUD)
MaxSecure Trojan.Malware.300983.susgen
Fortinet PossibleThreat.MU
AVG Win64:Malware-gen
DeepInstinct MALICIOUS