Summary | ZeroBOX

BraveCrashHandler64.exe

Generic Malware EnigmaProtector UPX PE64 PE32 PE File MZP Format
Category Machine Started Completed
FILE s1_win7_x6403_us Dec. 11, 2023, 3:20 p.m. Dec. 11, 2023, 3:26 p.m.
Size 10.0MB
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 80933f1574b52fe27bfc085779bd2552
SHA256 336cfabdf9d36499b40352dbd06b0da24a31bbb7e6e57ac6bf04aa96de305da7
CRC32 E11279D7
ssdeep 196608:KzFTg0HXBfrnm3nioFmRy18VfxZ4QauGo3Pq+vcnBw0G5BGiw:KzFTPNm3icwyiVoQ4Z+UnynQp
Yara
  • IsPE32 - (no description)
  • PE_Header_Zero - PE File Signature
  • UPX_Zero - UPX packed file
  • mzp_file_format - MZP(Delphi) file format
  • EnigmaProtector_IN - EnigmaProtector

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
164.124.101.2 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Time & API Arguments Status Return Repeated

GetComputerNameA

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameA

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameA

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameA

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameA

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0
Time & API Arguments Status Return Repeated

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0
Time & API Arguments Status Return Repeated

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: chcp
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: "RuntimeBrooker.exe"
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: '"C:\Windows\TEMP\RuntimeBrooker.exe"' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: "RuntimeBrooker.exe"
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: '"C:\Windows\TEMP\RuntimeBrooker.exe"' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: "RuntimeBrooker.exe"
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: '"C:\Windows\TEMP\RuntimeBrooker.exe"' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: "RuntimeBrooker.exe"
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: '"C:\Windows\TEMP\RuntimeBrooker.exe"' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: "RuntimeBrooker.exe"
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: '"C:\Windows\TEMP\RuntimeBrooker.exe"' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: Active code page: 1252
console_handle: 0x00000013
1 1 0

WriteConsoleW

buffer: Waiting for 10
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: seconds, press a key to continue ...
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Waiting for 10
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: seconds, press a key to continue ...
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Waiting for 10
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: seconds, press a key to continue ...
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Waiting for 10
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: seconds, press a key to continue ...
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Waiting for 10
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: seconds, press a key to continue ...
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Waiting for 10
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: seconds, press a key to continue ...
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Waiting for 10
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: seconds, press a key to continue ...
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Waiting for 10
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: seconds, press a key to continue ...
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Waiting for 10
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: seconds, press a key to continue ...
console_handle: 0x00000007
1 1 0
section
Time & API Arguments Status Return Repeated

__exception__

stacktrace:
bravecrashhandler64+0x1abab3 @ 0x5abab3
bravecrashhandler64+0x1b5391 @ 0x5b5391
bravecrashhandler64+0x291e61 @ 0x691e61

exception.instruction_r: f7 f0 e8 44 37 01 00 33 c0 5a 59 59 64 89 10 eb
exception.symbol: bravecrashhandler64+0xf96d5
exception.instruction: div eax
exception.module: BraveCrashHandler64.exe
exception.exception_code: 0xc0000094
exception.offset: 1021653
exception.address: 0x4f96d5
registers.esp: 2686684
registers.edi: 6889712
registers.eax: 0
registers.ebp: 2686712
registers.edx: 0
registers.ebx: 2482338606
registers.esi: 4296704
registers.ecx: 37763760
1 0 0

__exception__

stacktrace:
bravecrashhandler64+0x1abab3 @ 0x5abab3
bravecrashhandler64+0x1b5391 @ 0x5b5391
bravecrashhandler64+0x291e61 @ 0x691e61

exception.instruction_r: 0f 0b e8 19 37 01 00 33 c0 5a 59 59 64 89 10 eb
exception.symbol: bravecrashhandler64+0xf9700
exception.instruction: ud2
exception.module: BraveCrashHandler64.exe
exception.exception_code: 0xc000001d
exception.offset: 1021696
exception.address: 0x4f9700
registers.esp: 2686684
registers.edi: 2686684
registers.eax: 0
registers.ebp: 2686712
registers.edx: 2
registers.ebx: 5215979
registers.esi: 0
registers.ecx: 2686720
1 0 0

__exception__

stacktrace:
bravecrashhandler64+0x1abab3 @ 0x5abab3
bravecrashhandler64+0x1b5391 @ 0x5b5391
bravecrashhandler64+0x291e61 @ 0x691e61

exception.instruction_r: f7 f0 e8 44 37 01 00 33 c0 5a 59 59 64 89 10 eb
exception.symbol: bravecrashhandler64+0xf96d5
exception.instruction: div eax
exception.module: BraveCrashHandler64.exe
exception.exception_code: 0xc0000094
exception.offset: 1021653
exception.address: 0x4f96d5
registers.esp: 2686684
registers.edi: 2686684
registers.eax: 0
registers.ebp: 2686712
registers.edx: 0
registers.ebx: 5216022
registers.esi: 0
registers.ecx: 2686720
1 0 0

__exception__

stacktrace:
bravecrashhandler64+0x1b1bae @ 0x5b1bae
bravecrashhandler64+0x1b539e @ 0x5b539e
bravecrashhandler64+0x291e61 @ 0x691e61

exception.instruction_r: f7 f0 e8 44 37 01 00 33 c0 5a 59 59 64 89 10 eb
exception.symbol: bravecrashhandler64+0xf96d5
exception.instruction: div eax
exception.module: BraveCrashHandler64.exe
exception.exception_code: 0xc0000094
exception.offset: 1021653
exception.address: 0x4f96d5
registers.esp: 2686620
registers.edi: 5683876
registers.eax: 0
registers.ebp: 2686648
registers.edx: 0
registers.ebx: 102400
registers.esi: 4296704
registers.ecx: 4296704
1 0 0

__exception__

stacktrace:
bravecrashhandler64+0x1b1bae @ 0x5b1bae
bravecrashhandler64+0x1b539e @ 0x5b539e
bravecrashhandler64+0x291e61 @ 0x691e61

exception.instruction_r: f7 f0 e8 44 37 01 00 33 c0 5a 59 59 64 89 10 eb
exception.symbol: bravecrashhandler64+0xf96d5
exception.instruction: div eax
exception.module: BraveCrashHandler64.exe
exception.exception_code: 0xc0000094
exception.offset: 1021653
exception.address: 0x4f96d5
registers.esp: 2686620
registers.edi: 2686620
registers.eax: 0
registers.ebp: 2686648
registers.edx: 0
registers.ebx: 5215979
registers.esi: 0
registers.ecx: 2686656
1 0 0

__exception__

stacktrace:
bravecrashhandler64+0x1b1bae @ 0x5b1bae
bravecrashhandler64+0x1b539e @ 0x5b539e
bravecrashhandler64+0x291e61 @ 0x691e61

exception.instruction_r: f7 f0 e8 44 37 01 00 33 c0 5a 59 59 64 89 10 eb
exception.symbol: bravecrashhandler64+0xf96d5
exception.instruction: div eax
exception.module: BraveCrashHandler64.exe
exception.exception_code: 0xc0000094
exception.offset: 1021653
exception.address: 0x4f96d5
registers.esp: 2686620
registers.edi: 2686620
registers.eax: 0
registers.ebp: 2686648
registers.edx: 0
registers.ebx: 5215979
registers.esi: 0
registers.ecx: 2686656
1 0 0

__exception__

stacktrace:
bravecrashhandler64+0x1b1bae @ 0x5b1bae
bravecrashhandler64+0x1b539e @ 0x5b539e
bravecrashhandler64+0x291e61 @ 0x691e61

exception.instruction_r: f7 f0 e8 44 37 01 00 33 c0 5a 59 59 64 89 10 eb
exception.symbol: bravecrashhandler64+0xf96d5
exception.instruction: div eax
exception.module: BraveCrashHandler64.exe
exception.exception_code: 0xc0000094
exception.offset: 1021653
exception.address: 0x4f96d5
registers.esp: 2686620
registers.edi: 2686620
registers.eax: 0
registers.ebp: 2686648
registers.edx: 0
registers.ebx: 5215979
registers.esi: 0
registers.ecx: 2686656
1 0 0

__exception__

stacktrace:
bravecrashhandler64+0x1b1bae @ 0x5b1bae
bravecrashhandler64+0x1b539e @ 0x5b539e
bravecrashhandler64+0x291e61 @ 0x691e61

exception.instruction_r: f7 f0 e8 44 37 01 00 33 c0 5a 59 59 64 89 10 eb
exception.symbol: bravecrashhandler64+0xf96d5
exception.instruction: div eax
exception.module: BraveCrashHandler64.exe
exception.exception_code: 0xc0000094
exception.offset: 1021653
exception.address: 0x4f96d5
registers.esp: 2686620
registers.edi: 2686620
registers.eax: 0
registers.ebp: 2686648
registers.edx: 0
registers.ebx: 5215979
registers.esi: 0
registers.ecx: 2686656
1 0 0

__exception__

stacktrace:
bravecrashhandler64+0x1b1bae @ 0x5b1bae
bravecrashhandler64+0x1b539e @ 0x5b539e
bravecrashhandler64+0x291e61 @ 0x691e61

exception.instruction_r: f7 f0 e8 44 37 01 00 33 c0 5a 59 59 64 89 10 eb
exception.symbol: bravecrashhandler64+0xf96d5
exception.instruction: div eax
exception.module: BraveCrashHandler64.exe
exception.exception_code: 0xc0000094
exception.offset: 1021653
exception.address: 0x4f96d5
registers.esp: 2686620
registers.edi: 2686620
registers.eax: 0
registers.ebp: 2686648
registers.edx: 0
registers.ebx: 5215979
registers.esi: 0
registers.ecx: 2686656
1 0 0

__exception__

stacktrace:
bravecrashhandler64+0x1b1bae @ 0x5b1bae
bravecrashhandler64+0x1b539e @ 0x5b539e
bravecrashhandler64+0x291e61 @ 0x691e61

exception.instruction_r: 0f 0b e8 19 37 01 00 33 c0 5a 59 59 64 89 10 eb
exception.symbol: bravecrashhandler64+0xf9700
exception.instruction: ud2
exception.module: BraveCrashHandler64.exe
exception.exception_code: 0xc000001d
exception.offset: 1021696
exception.address: 0x4f9700
registers.esp: 2686620
registers.edi: 2686620
registers.eax: 0
registers.ebp: 2686648
registers.edx: 2
registers.ebx: 5215979
registers.esi: 0
registers.ecx: 2686656
1 0 0

__exception__

stacktrace:
bravecrashhandler64+0x1b1e7c @ 0x5b1e7c
bravecrashhandler64+0x1b539e @ 0x5b539e
bravecrashhandler64+0x291e61 @ 0x691e61

exception.instruction_r: 0f 0b e8 19 37 01 00 33 c0 5a 59 59 64 89 10 eb
exception.symbol: bravecrashhandler64+0xf9700
exception.instruction: ud2
exception.module: BraveCrashHandler64.exe
exception.exception_code: 0xc000001d
exception.offset: 1021696
exception.address: 0x4f9700
registers.esp: 2686620
registers.edi: 5683876
registers.eax: 0
registers.ebp: 2686648
registers.edx: 2
registers.ebx: 4
registers.esi: 4294967295
registers.ecx: 0
1 0 0

__exception__

stacktrace:
bravecrashhandler64+0x1b1e7c @ 0x5b1e7c
bravecrashhandler64+0x1b539e @ 0x5b539e
bravecrashhandler64+0x291e61 @ 0x691e61

exception.instruction_r: f7 f0 e8 44 37 01 00 33 c0 5a 59 59 64 89 10 eb
exception.symbol: bravecrashhandler64+0xf96d5
exception.instruction: div eax
exception.module: BraveCrashHandler64.exe
exception.exception_code: 0xc0000094
exception.offset: 1021653
exception.address: 0x4f96d5
registers.esp: 2686620
registers.edi: 2686620
registers.eax: 0
registers.ebp: 2686648
registers.edx: 0
registers.ebx: 5216022
registers.esi: 0
registers.ecx: 2686656
1 0 0

__exception__

stacktrace:
bravecrashhandler64+0x1b1e7c @ 0x5b1e7c
bravecrashhandler64+0x1b539e @ 0x5b539e
bravecrashhandler64+0x291e61 @ 0x691e61

exception.instruction_r: f7 f0 e8 44 37 01 00 33 c0 5a 59 59 64 89 10 eb
exception.symbol: bravecrashhandler64+0xf96d5
exception.instruction: div eax
exception.module: BraveCrashHandler64.exe
exception.exception_code: 0xc0000094
exception.offset: 1021653
exception.address: 0x4f96d5
registers.esp: 2686620
registers.edi: 2686620
registers.eax: 0
registers.ebp: 2686648
registers.edx: 0
registers.ebx: 5215979
registers.esi: 0
registers.ecx: 2686656
1 0 0

__exception__

stacktrace:
bravecrashhandler64+0x1b1e7c @ 0x5b1e7c
bravecrashhandler64+0x1b539e @ 0x5b539e
bravecrashhandler64+0x291e61 @ 0x691e61

exception.instruction_r: f7 f0 e8 44 37 01 00 33 c0 5a 59 59 64 89 10 eb
exception.symbol: bravecrashhandler64+0xf96d5
exception.instruction: div eax
exception.module: BraveCrashHandler64.exe
exception.exception_code: 0xc0000094
exception.offset: 1021653
exception.address: 0x4f96d5
registers.esp: 2686620
registers.edi: 2686620
registers.eax: 0
registers.ebp: 2686648
registers.edx: 0
registers.ebx: 5215979
registers.esi: 0
registers.ecx: 2686656
1 0 0

__exception__

stacktrace:
bravecrashhandler64+0x1b1ea0 @ 0x5b1ea0
bravecrashhandler64+0x1b539e @ 0x5b539e
bravecrashhandler64+0x291e61 @ 0x691e61

exception.instruction_r: cc 68 fd 57 5a e9 e9 df 59 ff ff 40 63 fc af 47
exception.symbol: bravecrashhandler64+0x1a79fe
exception.instruction: int3
exception.module: BraveCrashHandler64.exe
exception.exception_code: 0x80000003
exception.offset: 1735166
exception.address: 0x5a79fe
registers.esp: 2686620
registers.edi: 5655117
registers.eax: 2324
registers.ebp: 2686648
registers.edx: 2686656
registers.ebx: 4
registers.esi: 4294919751
registers.ecx: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: cc 68 41 71 5a e9 e9 42 a4 ff ff e5 18 b9 43 8f
exception.symbol: bravecrashhandler64+0x1a2f9b
exception.instruction: int3
exception.module: BraveCrashHandler64.exe
exception.exception_code: 0x80000003
exception.offset: 1716123
exception.address: 0x5a2f9b
registers.esp: 2686620
registers.edi: 5683876
registers.eax: 4
registers.ebp: 1111705675
registers.edx: 0
registers.ebx: 4
registers.esi: 4294967295
registers.ecx: 1354039296
1 0 0

__exception__

stacktrace:
bravecrashhandler64+0x1b2023 @ 0x5b2023
bravecrashhandler64+0x1b539e @ 0x5b539e
bravecrashhandler64+0x291e61 @ 0x691e61

exception.instruction_r: 0f 0b e8 19 37 01 00 33 c0 5a 59 59 64 89 10 eb
exception.symbol: bravecrashhandler64+0xf9700
exception.instruction: ud2
exception.module: BraveCrashHandler64.exe
exception.exception_code: 0xc000001d
exception.offset: 1021696
exception.address: 0x4f9700
registers.esp: 2686620
registers.edi: 5683876
registers.eax: 0
registers.ebp: 2686648
registers.edx: 2
registers.ebx: 4
registers.esi: 4294967295
registers.ecx: 0
1 0 0

__exception__

stacktrace:
bravecrashhandler64+0x1b2023 @ 0x5b2023
bravecrashhandler64+0x1b539e @ 0x5b539e
bravecrashhandler64+0x291e61 @ 0x691e61

exception.instruction_r: 0f 0b e8 19 37 01 00 33 c0 5a 59 59 64 89 10 eb
exception.symbol: bravecrashhandler64+0xf9700
exception.instruction: ud2
exception.module: BraveCrashHandler64.exe
exception.exception_code: 0xc000001d
exception.offset: 1021696
exception.address: 0x4f9700
registers.esp: 2686620
registers.edi: 2686620
registers.eax: 0
registers.ebp: 2686648
registers.edx: 2
registers.ebx: 5216022
registers.esi: 0
registers.ecx: 2686656
1 0 0

__exception__

stacktrace:
bravecrashhandler64+0x1b2023 @ 0x5b2023
bravecrashhandler64+0x1b539e @ 0x5b539e
bravecrashhandler64+0x291e61 @ 0x691e61

exception.instruction_r: 0f 0b e8 19 37 01 00 33 c0 5a 59 59 64 89 10 eb
exception.symbol: bravecrashhandler64+0xf9700
exception.instruction: ud2
exception.module: BraveCrashHandler64.exe
exception.exception_code: 0xc000001d
exception.offset: 1021696
exception.address: 0x4f9700
registers.esp: 2686620
registers.edi: 2686620
registers.eax: 0
registers.ebp: 2686648
registers.edx: 2
registers.ebx: 5216022
registers.esi: 0
registers.ecx: 2686656
1 0 0

__exception__

stacktrace:
bravecrashhandler64+0x1b2023 @ 0x5b2023
bravecrashhandler64+0x1b539e @ 0x5b539e
bravecrashhandler64+0x291e61 @ 0x691e61

exception.instruction_r: 0f 0b e8 19 37 01 00 33 c0 5a 59 59 64 89 10 eb
exception.symbol: bravecrashhandler64+0xf9700
exception.instruction: ud2
exception.module: BraveCrashHandler64.exe
exception.exception_code: 0xc000001d
exception.offset: 1021696
exception.address: 0x4f9700
registers.esp: 2686620
registers.edi: 2686620
registers.eax: 0
registers.ebp: 2686648
registers.edx: 2
registers.ebx: 5216022
registers.esi: 0
registers.ecx: 2686656
1 0 0

__exception__

stacktrace:
bravecrashhandler64+0x1a4204 @ 0x5a4204
bravecrashhandler64+0x1b539e @ 0x5b539e
bravecrashhandler64+0x291e61 @ 0x691e61

exception.instruction_r: ed 68 aa 55 5a e9 e9 53 53 ff ff 92 4c f3 40 1d
exception.symbol: bravecrashhandler64+0x1a808a
exception.instruction: in eax, dx
exception.module: BraveCrashHandler64.exe
exception.exception_code: 0xc0000096
exception.offset: 1736842
exception.address: 0x5a808a
registers.esp: 2686608
registers.edi: 5683876
registers.eax: 1447909480
registers.ebp: 2686636
registers.edx: 22104
registers.ebx: 0
registers.esi: 5682560
registers.ecx: 10
1 0 0

__exception__

stacktrace:
bravecrashhandler64+0x1a4229 @ 0x5a4229
bravecrashhandler64+0x1b539e @ 0x5b539e
bravecrashhandler64+0x291e61 @ 0x691e61

exception.instruction_r: 0f 3f 68 21 0b 5a e9 e9 c0 7e fe ff b3 7c 68 29
exception.symbol: bravecrashhandler64+0x1b551c
exception.address: 0x5b551c
exception.module: BraveCrashHandler64.exe
exception.exception_code: 0xc000001d
exception.offset: 1791260
registers.esp: 2686608
registers.edi: 5683876
registers.eax: 1
registers.ebp: 2686636
registers.edx: 0
registers.ebx: 0
registers.esi: 5682560
registers.ecx: 0
1 0 0

__exception__

stacktrace:
bravecrashhandler64+0x1b2207 @ 0x5b2207
bravecrashhandler64+0x1b539e @ 0x5b539e
bravecrashhandler64+0x291e61 @ 0x691e61

exception.instruction_r: f7 f0 e8 44 37 01 00 33 c0 5a 59 59 64 89 10 eb
exception.symbol: bravecrashhandler64+0xf96d5
exception.instruction: div eax
exception.module: BraveCrashHandler64.exe
exception.exception_code: 0xc0000094
exception.offset: 1021653
exception.address: 0x4f96d5
registers.esp: 2686620
registers.edi: 5683876
registers.eax: 0
registers.ebp: 2686648
registers.edx: 0
registers.ebx: 4
registers.esi: 4294967295
registers.ecx: 0
1 0 0

__exception__

stacktrace:
bravecrashhandler64+0x1b2207 @ 0x5b2207
bravecrashhandler64+0x1b539e @ 0x5b539e
bravecrashhandler64+0x291e61 @ 0x691e61

exception.instruction_r: f7 f0 e8 44 37 01 00 33 c0 5a 59 59 64 89 10 eb
exception.symbol: bravecrashhandler64+0xf96d5
exception.instruction: div eax
exception.module: BraveCrashHandler64.exe
exception.exception_code: 0xc0000094
exception.offset: 1021653
exception.address: 0x4f96d5
registers.esp: 2686620
registers.edi: 2686620
registers.eax: 0
registers.ebp: 2686648
registers.edx: 0
registers.ebx: 5215979
registers.esi: 0
registers.ecx: 2686656
1 0 0

__exception__

stacktrace:
bravecrashhandler64+0x1b2207 @ 0x5b2207
bravecrashhandler64+0x1b539e @ 0x5b539e
bravecrashhandler64+0x291e61 @ 0x691e61

exception.instruction_r: f7 f0 e8 44 37 01 00 33 c0 5a 59 59 64 89 10 eb
exception.symbol: bravecrashhandler64+0xf96d5
exception.instruction: div eax
exception.module: BraveCrashHandler64.exe
exception.exception_code: 0xc0000094
exception.offset: 1021653
exception.address: 0x4f96d5
registers.esp: 2686620
registers.edi: 2686620
registers.eax: 0
registers.ebp: 2686648
registers.edx: 0
registers.ebx: 5215979
registers.esi: 0
registers.ecx: 2686656
1 0 0

__exception__

stacktrace:
bravecrashhandler64+0x1b2207 @ 0x5b2207
bravecrashhandler64+0x1b539e @ 0x5b539e
bravecrashhandler64+0x291e61 @ 0x691e61

exception.instruction_r: 0f 0b e8 19 37 01 00 33 c0 5a 59 59 64 89 10 eb
exception.symbol: bravecrashhandler64+0xf9700
exception.instruction: ud2
exception.module: BraveCrashHandler64.exe
exception.exception_code: 0xc000001d
exception.offset: 1021696
exception.address: 0x4f9700
registers.esp: 2686620
registers.edi: 2686620
registers.eax: 0
registers.ebp: 2686648
registers.edx: 2
registers.ebx: 5215979
registers.esi: 0
registers.ecx: 2686656
1 0 0

__exception__

stacktrace:
bravecrashhandler64+0x1b2207 @ 0x5b2207
bravecrashhandler64+0x1b539e @ 0x5b539e
bravecrashhandler64+0x291e61 @ 0x691e61

exception.instruction_r: 0f 0b e8 19 37 01 00 33 c0 5a 59 59 64 89 10 eb
exception.symbol: bravecrashhandler64+0xf9700
exception.instruction: ud2
exception.module: BraveCrashHandler64.exe
exception.exception_code: 0xc000001d
exception.offset: 1021696
exception.address: 0x4f9700
registers.esp: 2686620
registers.edi: 2686620
registers.eax: 0
registers.ebp: 2686648
registers.edx: 2
registers.ebx: 5216022
registers.esi: 0
registers.ecx: 2686656
1 0 0

__exception__

stacktrace:
bravecrashhandler64+0x1b2207 @ 0x5b2207
bravecrashhandler64+0x1b539e @ 0x5b539e
bravecrashhandler64+0x291e61 @ 0x691e61

exception.instruction_r: 0f 0b e8 19 37 01 00 33 c0 5a 59 59 64 89 10 eb
exception.symbol: bravecrashhandler64+0xf9700
exception.instruction: ud2
exception.module: BraveCrashHandler64.exe
exception.exception_code: 0xc000001d
exception.offset: 1021696
exception.address: 0x4f9700
registers.esp: 2686620
registers.edi: 2686620
registers.eax: 0
registers.ebp: 2686648
registers.edx: 2
registers.ebx: 5216022
registers.esi: 0
registers.ecx: 2686656
1 0 0

__exception__

stacktrace:
bravecrashhandler64+0x1b2207 @ 0x5b2207
bravecrashhandler64+0x1b539e @ 0x5b539e
bravecrashhandler64+0x291e61 @ 0x691e61

exception.instruction_r: f7 f0 e8 44 37 01 00 33 c0 5a 59 59 64 89 10 eb
exception.symbol: bravecrashhandler64+0xf96d5
exception.instruction: div eax
exception.module: BraveCrashHandler64.exe
exception.exception_code: 0xc0000094
exception.offset: 1021653
exception.address: 0x4f96d5
registers.esp: 2686620
registers.edi: 2686620
registers.eax: 0
registers.ebp: 2686648
registers.edx: 0
registers.ebx: 5216022
registers.esi: 0
registers.ecx: 2686656
1 0 0

__exception__

stacktrace:
bravecrashhandler64+0x1b2207 @ 0x5b2207
bravecrashhandler64+0x1b539e @ 0x5b539e
bravecrashhandler64+0x291e61 @ 0x691e61

exception.instruction_r: f7 f0 e8 44 37 01 00 33 c0 5a 59 59 64 89 10 eb
exception.symbol: bravecrashhandler64+0xf96d5
exception.instruction: div eax
exception.module: BraveCrashHandler64.exe
exception.exception_code: 0xc0000094
exception.offset: 1021653
exception.address: 0x4f96d5
registers.esp: 2686620
registers.edi: 2686620
registers.eax: 0
registers.ebp: 2686648
registers.edx: 0
registers.ebx: 5215979
registers.esi: 0
registers.ecx: 2686656
1 0 0

__exception__

stacktrace:
bravecrashhandler64+0x1b2207 @ 0x5b2207
bravecrashhandler64+0x1b539e @ 0x5b539e
bravecrashhandler64+0x291e61 @ 0x691e61

exception.instruction_r: 0f 0b e8 19 37 01 00 33 c0 5a 59 59 64 89 10 eb
exception.symbol: bravecrashhandler64+0xf9700
exception.instruction: ud2
exception.module: BraveCrashHandler64.exe
exception.exception_code: 0xc000001d
exception.offset: 1021696
exception.address: 0x4f9700
registers.esp: 2686620
registers.edi: 2686620
registers.eax: 0
registers.ebp: 2686648
registers.edx: 2
registers.ebx: 5215979
registers.esi: 0
registers.ecx: 2686656
1 0 0

__exception__

stacktrace:
bravecrashhandler64+0x1b232a @ 0x5b232a
bravecrashhandler64+0x1b539e @ 0x5b539e
bravecrashhandler64+0x291e61 @ 0x691e61

exception.instruction_r: 0f 0b e8 19 37 01 00 33 c0 5a 59 59 64 89 10 eb
exception.symbol: bravecrashhandler64+0xf9700
exception.instruction: ud2
exception.module: BraveCrashHandler64.exe
exception.exception_code: 0xc000001d
exception.offset: 1021696
exception.address: 0x4f9700
registers.esp: 2686620
registers.edi: 5683876
registers.eax: 0
registers.ebp: 2686648
registers.edx: 2
registers.ebx: 4
registers.esi: 4294967295
registers.ecx: 3280666624
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: cc 68 41 71 5a e9 e9 42 a4 ff ff e5 18 b9 43 8f
exception.symbol: bravecrashhandler64+0x1a2f9b
exception.instruction: int3
exception.module: BraveCrashHandler64.exe
exception.exception_code: 0x80000003
exception.offset: 1716123
exception.address: 0x5a2f9b
registers.esp: 49544980
registers.edi: 37923860
registers.eax: 4
registers.ebp: 1111705675
registers.edx: 0
registers.ebx: 37923944
registers.esi: 5
registers.ecx: 1354039296
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: cc 68 41 71 5a e9 e9 42 a4 ff ff e5 18 b9 43 8f
exception.symbol: bravecrashhandler64+0x1a2f9b
exception.instruction: int3
exception.module: BraveCrashHandler64.exe
exception.exception_code: 0x80000003
exception.offset: 1716123
exception.address: 0x5a2f9b
registers.esp: 49544980
registers.edi: 37923860
registers.eax: 4
registers.ebp: 1111705675
registers.edx: 0
registers.ebx: 37923946
registers.esi: 13
registers.ecx: 1354039296
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: cc 68 41 71 5a e9 e9 42 a4 ff ff e5 18 b9 43 8f
exception.symbol: bravecrashhandler64+0x1a2f9b
exception.instruction: int3
exception.module: BraveCrashHandler64.exe
exception.exception_code: 0x80000003
exception.offset: 1716123
exception.address: 0x5a2f9b
registers.esp: 49544980
registers.edi: 37923860
registers.eax: 4
registers.ebp: 1111705675
registers.edx: 0
registers.ebx: 37923948
registers.esi: 13
registers.ecx: 1354039296
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: cc 68 41 71 5a e9 e9 42 a4 ff ff e5 18 b9 43 8f
exception.symbol: bravecrashhandler64+0x1a2f9b
exception.instruction: int3
exception.module: BraveCrashHandler64.exe
exception.exception_code: 0x80000003
exception.offset: 1716123
exception.address: 0x5a2f9b
registers.esp: 49544980
registers.edi: 37923860
registers.eax: 4
registers.ebp: 1111705675
registers.edx: 0
registers.ebx: 37923950
registers.esi: 13
registers.ecx: 1354039296
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: cc 68 41 71 5a e9 e9 42 a4 ff ff e5 18 b9 43 8f
exception.symbol: bravecrashhandler64+0x1a2f9b
exception.instruction: int3
exception.module: BraveCrashHandler64.exe
exception.exception_code: 0x80000003
exception.offset: 1716123
exception.address: 0x5a2f9b
registers.esp: 49544980
registers.edi: 37923860
registers.eax: 4
registers.ebp: 1111705675
registers.edx: 0
registers.ebx: 37923952
registers.esi: 13
registers.ecx: 1354039296
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: cc 68 41 71 5a e9 e9 42 a4 ff ff e5 18 b9 43 8f
exception.symbol: bravecrashhandler64+0x1a2f9b
exception.instruction: int3
exception.module: BraveCrashHandler64.exe
exception.exception_code: 0x80000003
exception.offset: 1716123
exception.address: 0x5a2f9b
registers.esp: 49544980
registers.edi: 37923860
registers.eax: 4
registers.ebp: 1111705675
registers.edx: 0
registers.ebx: 37923954
registers.esi: 13
registers.ecx: 1354039296
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: cc 68 41 71 5a e9 e9 42 a4 ff ff e5 18 b9 43 8f
exception.symbol: bravecrashhandler64+0x1a2f9b
exception.instruction: int3
exception.module: BraveCrashHandler64.exe
exception.exception_code: 0x80000003
exception.offset: 1716123
exception.address: 0x5a2f9b
registers.esp: 49544980
registers.edi: 37923860
registers.eax: 4
registers.ebp: 1111705675
registers.edx: 0
registers.ebx: 37923956
registers.esi: 13
registers.ecx: 1354039296
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: cc 68 41 71 5a e9 e9 42 a4 ff ff e5 18 b9 43 8f
exception.symbol: bravecrashhandler64+0x1a2f9b
exception.instruction: int3
exception.module: BraveCrashHandler64.exe
exception.exception_code: 0x80000003
exception.offset: 1716123
exception.address: 0x5a2f9b
registers.esp: 49544980
registers.edi: 37923860
registers.eax: 4
registers.ebp: 1111705675
registers.edx: 0
registers.ebx: 37923958
registers.esi: 13
registers.ecx: 1354039296
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: cc 68 41 71 5a e9 e9 42 a4 ff ff e5 18 b9 43 8f
exception.symbol: bravecrashhandler64+0x1a2f9b
exception.instruction: int3
exception.module: BraveCrashHandler64.exe
exception.exception_code: 0x80000003
exception.offset: 1716123
exception.address: 0x5a2f9b
registers.esp: 49544980
registers.edi: 37923860
registers.eax: 4
registers.ebp: 1111705675
registers.edx: 0
registers.ebx: 37923960
registers.esi: 13
registers.ecx: 1354039296
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: cc 68 41 71 5a e9 e9 42 a4 ff ff e5 18 b9 43 8f
exception.symbol: bravecrashhandler64+0x1a2f9b
exception.instruction: int3
exception.module: BraveCrashHandler64.exe
exception.exception_code: 0x80000003
exception.offset: 1716123
exception.address: 0x5a2f9b
registers.esp: 49544980
registers.edi: 37923860
registers.eax: 4
registers.ebp: 1111705675
registers.edx: 0
registers.ebx: 37923962
registers.esi: 13
registers.ecx: 1354039296
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: cc 68 41 71 5a e9 e9 42 a4 ff ff e5 18 b9 43 8f
exception.symbol: bravecrashhandler64+0x1a2f9b
exception.instruction: int3
exception.module: BraveCrashHandler64.exe
exception.exception_code: 0x80000003
exception.offset: 1716123
exception.address: 0x5a2f9b
registers.esp: 49544980
registers.edi: 37923860
registers.eax: 4
registers.ebp: 1111705675
registers.edx: 0
registers.ebx: 37923964
registers.esi: 11
registers.ecx: 1354039296
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: cc 68 41 71 5a e9 e9 42 a4 ff ff e5 18 b9 43 8f
exception.symbol: bravecrashhandler64+0x1a2f9b
exception.instruction: int3
exception.module: BraveCrashHandler64.exe
exception.exception_code: 0x80000003
exception.offset: 1716123
exception.address: 0x5a2f9b
registers.esp: 49544980
registers.edi: 37923860
registers.eax: 4
registers.ebp: 1111705675
registers.edx: 0
registers.ebx: 37923966
registers.esi: 11
registers.ecx: 1354039296
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: cc 68 41 71 5a e9 e9 42 a4 ff ff e5 18 b9 43 8f
exception.symbol: bravecrashhandler64+0x1a2f9b
exception.instruction: int3
exception.module: BraveCrashHandler64.exe
exception.exception_code: 0x80000003
exception.offset: 1716123
exception.address: 0x5a2f9b
registers.esp: 49544980
registers.edi: 37923860
registers.eax: 4
registers.ebp: 1111705675
registers.edx: 0
registers.ebx: 37923968
registers.esi: 11
registers.ecx: 1354039296
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: cc 68 41 71 5a e9 e9 42 a4 ff ff e5 18 b9 43 8f
exception.symbol: bravecrashhandler64+0x1a2f9b
exception.instruction: int3
exception.module: BraveCrashHandler64.exe
exception.exception_code: 0x80000003
exception.offset: 1716123
exception.address: 0x5a2f9b
registers.esp: 49544980
registers.edi: 37923860
registers.eax: 4
registers.ebp: 1111705675
registers.edx: 0
registers.ebx: 37923970
registers.esi: 11
registers.ecx: 1354039296
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: cc 68 41 71 5a e9 e9 42 a4 ff ff e5 18 b9 43 8f
exception.symbol: bravecrashhandler64+0x1a2f9b
exception.instruction: int3
exception.module: BraveCrashHandler64.exe
exception.exception_code: 0x80000003
exception.offset: 1716123
exception.address: 0x5a2f9b
registers.esp: 49544980
registers.edi: 37923860
registers.eax: 4
registers.ebp: 1111705675
registers.edx: 0
registers.ebx: 37923972
registers.esi: 11
registers.ecx: 1354039296
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: cc 68 41 71 5a e9 e9 42 a4 ff ff e5 18 b9 43 8f
exception.symbol: bravecrashhandler64+0x1a2f9b
exception.instruction: int3
exception.module: BraveCrashHandler64.exe
exception.exception_code: 0x80000003
exception.offset: 1716123
exception.address: 0x5a2f9b
registers.esp: 49544980
registers.edi: 37923860
registers.eax: 4
registers.ebp: 1111705675
registers.edx: 0
registers.ebx: 37923974
registers.esi: 13
registers.ecx: 1354039296
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: cc 68 41 71 5a e9 e9 42 a4 ff ff e5 18 b9 43 8f
exception.symbol: bravecrashhandler64+0x1a2f9b
exception.instruction: int3
exception.module: BraveCrashHandler64.exe
exception.exception_code: 0x80000003
exception.offset: 1716123
exception.address: 0x5a2f9b
registers.esp: 49544980
registers.edi: 37923860
registers.eax: 4
registers.ebp: 1111705675
registers.edx: 0
registers.ebx: 37923976
registers.esi: 13
registers.ecx: 1354039296
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: cc 68 41 71 5a e9 e9 42 a4 ff ff e5 18 b9 43 8f
exception.symbol: bravecrashhandler64+0x1a2f9b
exception.instruction: int3
exception.module: BraveCrashHandler64.exe
exception.exception_code: 0x80000003
exception.offset: 1716123
exception.address: 0x5a2f9b
registers.esp: 49544980
registers.edi: 37923860
registers.eax: 4
registers.ebp: 1111705675
registers.edx: 0
registers.ebx: 37923978
registers.esi: 10
registers.ecx: 1354039296
1 0 0
Time & API Arguments Status Return Repeated

NtAllocateVirtualMemory

process_identifier: 2088
region_size: 16384
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x022d0000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2088
region_size: 16384
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x023d0000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2088
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00860000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2088
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00880000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2088
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x008a0000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2088
region_size: 65536
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x023d4000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2088
region_size: 81920
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x023e4000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2088
region_size: 147456
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x023e4000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2088
region_size: 65536
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02404000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2088
region_size: 16384
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02414000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2088
region_size: 65536
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02414000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2088
region_size: 16384
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02414000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2088
region_size: 81920
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02418000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2088
region_size: 81920
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02418000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2088
region_size: 81920
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02418000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2088
region_size: 81920
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02418000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2088
region_size: 81920
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02418000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2088
region_size: 81920
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02418000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2088
region_size: 81920
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02418000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2088
region_size: 81920
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02428000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2088
region_size: 1064960
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02b40000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2088
region_size: 81920
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02428000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2088
region_size: 81920
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0243c000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2088
region_size: 81920
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02428000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2088
region_size: 81920
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0243c000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2088
region_size: 81920
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02428000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2088
region_size: 81920
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0243c000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2088
region_size: 81920
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02428000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2088
region_size: 81920
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0243c000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2088
region_size: 81920
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02428000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2088
region_size: 81920
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0243c000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2088
region_size: 81920
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02428000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2088
region_size: 81920
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0243c000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2088
region_size: 81920
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02428000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2088
region_size: 81920
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0243c000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2088
region_size: 81920
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02428000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2088
region_size: 81920
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0243c000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2088
region_size: 81920
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02428000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2088
region_size: 81920
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0243c000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2088
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x778bf000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2088
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x778c0000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2088
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x778bf000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2088
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x778bf000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2088
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x778bf000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2088
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x778bf000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2088
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x778bf000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2088
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x778bf000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2088
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x778bf000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2088
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x778bf000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2088
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x778c0000
process_handle: 0xffffffff
1 0 0
description BraveCrashHandler64.exe tried to sleep 235 seconds, actually delayed analysis time by 235 seconds
file c:\Users\test22\AppData\Local\Temp\RuntimeBrooker.exe
file C:\Users\test22\AppData\Local\Temp\2088820A.bat
cmdline cmd.exe /c ""C:\Users\test22\AppData\Local\Temp\2088820A.bat" "C:\Users\test22\AppData\Local\Temp\BraveCrashHandler64.exe" "
file C:\Users\test22\AppData\Local\Temp\RuntimeBrooker.exe
wmi SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process
section {u'size_of_data': u'0x00004c00', u'virtual_address': u'0x00001000', u'entropy': 7.9668972347074325, u'name': u'', u'virtual_size': u'0x00009000'} entropy 7.96689723471 description A section with a high entropy has been found
section {u'size_of_data': u'0x00000600', u'virtual_address': u'0x0000a000', u'entropy': 7.2398444564422215, u'name': u'', u'virtual_size': u'0x00001000'} entropy 7.23984445644 description A section with a high entropy has been found
section {u'size_of_data': u'0x00000c00', u'virtual_address': u'0x00014000', u'entropy': 7.721767009223186, u'name': u'', u'virtual_size': u'0x00001000'} entropy 7.72176700922 description A section with a high entropy has been found
section {u'size_of_data': u'0x00000400', u'virtual_address': u'0x00015000', u'entropy': 7.138362900156004, u'name': u'', u'virtual_size': u'0x00002000'} entropy 7.13836290016 description A section with a high entropy has been found
section {u'size_of_data': u'0x00900400', u'virtual_address': u'0x00019000', u'entropy': 7.997453841464318, u'name': u'', u'virtual_size': u'0x00291000'} entropy 7.99745384146 description A section with a high entropy has been found
section {u'size_of_data': u'0x000f1c00', u'virtual_address': u'0x002aa000', u'entropy': 7.973741851409543, u'name': u'.data', u'virtual_size': u'0x000f2000'} entropy 7.97374185141 description A section with a high entropy has been found
entropy 0.999314766776 description Overall entropy of this PE file is high
Time & API Arguments Status Return Repeated

LookupPrivilegeValueW

system_name:
privilege_name: SeDebugPrivilege
1 1 0

LookupPrivilegeValueW

system_name:
privilege_name: SeDebugPrivilege
1 1 0

LookupPrivilegeValueW

system_name:
privilege_name: SeDebugPrivilege
1 1 0

LookupPrivilegeValueW

system_name:
privilege_name: SeDebugPrivilege
1 1 0

LookupPrivilegeValueW

system_name:
privilege_name: SeDebugPrivilege
1 1 0

LookupPrivilegeValueW

system_name:
privilege_name: SeDebugPrivilege
1 1 0

LookupPrivilegeValueW

system_name:
privilege_name: SeDebugPrivilege
1 1 0

LookupPrivilegeValueW

system_name:
privilege_name: SeDebugPrivilege
1 1 0

LookupPrivilegeValueW

system_name:
privilege_name: SeDebugPrivilege
1 1 0
cmdline TASKLIST
cmdline chcp 1252
file \??\SICE
file \??\SIWDEBUG
file \??\NTICE
Time & API Arguments Status Return Repeated

FindWindowA

class_name: OLLYDBG
window_name:
0 0

FindWindowA

class_name: OLLYDBG
window_name:
0 0

FindWindowA

class_name: OLLYDBG
window_name:
0 0

FindWindowA

class_name: OLLYDBG
window_name:
0 0

FindWindowA

class_name: OLLYDBG
window_name:
0 0

FindWindowA

class_name: OLLYDBG
window_name:
0 0

FindWindowA

class_name: OLLYDBG
window_name:
0 0

FindWindowA

class_name: OLLYDBG
window_name:
0 0

FindWindowA

class_name: OLLYDBG
window_name:
0 0

FindWindowA

class_name: OLLYDBG
window_name:
0 0

FindWindowA

class_name: OLLYDBG
window_name:
0 0

FindWindowA

class_name: OLLYDBG
window_name:
0 0

FindWindowA

class_name: OLLYDBG
window_name:
0 0

FindWindowA

class_name: OLLYDBG
window_name:
0 0

FindWindowA

class_name: OLLYDBG
window_name:
0 0

FindWindowA

class_name: OLLYDBG
window_name:
0 0

FindWindowA

class_name: OLLYDBG
window_name:
0 0

FindWindowA

class_name: OLLYDBG
window_name:
0 0

FindWindowA

class_name: OLLYDBG
window_name:
0 0

FindWindowA

class_name: OLLYDBG
window_name:
0 0

FindWindowA

class_name: OLLYDBG
window_name:
0 0

FindWindowA

class_name: OLLYDBG
window_name:
0 0

FindWindowA

class_name: OLLYDBG
window_name:
0 0

FindWindowA

class_name: OLLYDBG
window_name:
0 0

FindWindowA

class_name: OLLYDBG
window_name:
0 0

FindWindowA

class_name: OLLYDBG
window_name:
0 0

FindWindowA

class_name: OLLYDBG
window_name:
0 0

FindWindowA

class_name: OLLYDBG
window_name:
0 0

FindWindowA

class_name: OLLYDBG
window_name:
0 0

FindWindowA

class_name: OLLYDBG
window_name:
0 0

FindWindowA

class_name: OLLYDBG
window_name:
0 0

FindWindowA

class_name: OLLYDBG
window_name:
0 0

FindWindowA

class_name: OLLYDBG
window_name:
0 0

FindWindowA

class_name: OLLYDBG
window_name:
0 0

FindWindowA

class_name: OLLYDBG
window_name:
0 0

FindWindowA

class_name: OLLYDBG
window_name:
0 0

FindWindowA

class_name: OLLYDBG
window_name:
0 0

FindWindowA

class_name: OLLYDBG
window_name:
0 0

FindWindowA

class_name: OLLYDBG
window_name:
0 0

FindWindowA

class_name: OLLYDBG
window_name:
0 0

FindWindowA

class_name: OLLYDBG
window_name:
0 0

FindWindowA

class_name: OLLYDBG
window_name:
0 0

FindWindowA

class_name: OLLYDBG
window_name:
0 0

FindWindowA

class_name: OLLYDBG
window_name:
0 0

FindWindowA

class_name: OLLYDBG
window_name:
0 0

FindWindowA

class_name: OLLYDBG
window_name:
0 0

FindWindowA

class_name: OLLYDBG
window_name:
0 0

FindWindowA

class_name: OLLYDBG
window_name:
0 0

FindWindowA

class_name: OLLYDBG
window_name:
0 0

FindWindowA

class_name: OLLYDBG
window_name:
0 0
Time & API Arguments Status Return Repeated

__anomaly__

tid: 2900
message: Encountered 65537 exceptions, quitting.
subcategory: exception
function_name:
1 0 0
Time & API Arguments Status Return Repeated

__exception__

stacktrace:
bravecrashhandler64+0x1a4204 @ 0x5a4204
bravecrashhandler64+0x1b539e @ 0x5b539e
bravecrashhandler64+0x291e61 @ 0x691e61

exception.instruction_r: ed 68 aa 55 5a e9 e9 53 53 ff ff 92 4c f3 40 1d
exception.symbol: bravecrashhandler64+0x1a808a
exception.instruction: in eax, dx
exception.module: BraveCrashHandler64.exe
exception.exception_code: 0xc0000096
exception.offset: 1736842
exception.address: 0x5a808a
registers.esp: 2686608
registers.edi: 5683876
registers.eax: 1447909480
registers.ebp: 2686636
registers.edx: 22104
registers.ebx: 0
registers.esi: 5682560
registers.ecx: 10
1 0 0
Bkav W32.AIDetectMalware
FireEye Generic.mg.80933f1574b52fe2
Skyhigh BehavesLike.Win32.PWSZbot.tc
Malwarebytes Malware.AI.3001675323
CrowdStrike win/malicious_confidence_90% (W)
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of Win32/Packed.EnigmaProtector.M suspicious
Cynet Malicious (score: 100)
APEX Malicious
Kaspersky not-a-virus:VHO:RiskTool.Win32.BitCoinMiner.gen
Avast Win32:Evo-gen [Trj]
Trapmine malicious.high.ml.score
Sophos Generic ML PUA (PUA)
SentinelOne Static AI - Malicious PE
Microsoft Trojan:Win32/Znyonm
ZoneAlarm not-a-virus:VHO:RiskTool.Win32.BitCoinMiner.gen
Google Detected
VBA32 Trojan.Tiggre
Cylance unsafe
Zoner Probably Heur.ExeHeaderL
Ikarus Trojan.Dropper.Agent
MaxSecure Trojan.Malware.300983.susgen
BitDefenderTheta Gen:NN.ZexaF.36608.@Z0@aG76mUei
AVG Win32:Evo-gen [Trj]
DeepInstinct MALICIOUS