Summary | ZeroBOX

Setup1.exe

Generic Malware PE64 PE File
Category Machine Started Completed
FILE s1_win7_x6401 March 28, 2024, 1:23 a.m. March 28, 2024, 1:23 a.m.
Size 3.3MB
Type PE32+ executable (GUI) x86-64, for MS Windows
MD5 b5376e50d2c47b7b6bab9ba1d42e4436
SHA256 a2f42c442abf1df0a82e750c865dc9ccfdf0796ba34b2dc711c08c0e4300c453
CRC32 5230852B
ssdeep 98304:AQsv/7Y9geHbyoOW7TVaKBRfhGxII+TubZ+CWDWM5eY410xC:AQCteH1/7bBbG+KbbWp410
Yara
  • IsPE64 - (no description)
  • PE_Header_Zero - PE File Signature
  • themida_packer - themida packer
  • Generic_Malware_Zero - Generic Malware

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
No hosts contacted.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

section
section .themida
section .boot
Time & API Arguments Status Return Repeated

__exception__

stacktrace:
RaiseException+0x3d FreeEnvironmentStringsW-0x373 kernelbase+0xa49d @ 0x7fefd4fa49d
setup1+0x4e2dee @ 0x140402dee
setup1+0x505b26 @ 0x140425b26
HeapWalk-0x1ce0 kernel32+0x0 @ 0x76c10000
0x1afcd8
0x1afcd8
0x1afcd8
0x372974
0x343060
0x367b1076d814aa
0x367b1076d814aa
0x367b1076d814aa
0x367b1076d814aa
0x367b1076d814aa
0x367b1076d814aa
0x367b1076d814aa
0x367b1076d814aa
0x367b1076d814aa
0x367b1076d814aa
0x367b1076d814aa
0x367b1076d814aa
0x367b1076d814aa
0x367b1076d814aa
0x367b1076d814aa
0x367b1076d814aa
0x367b1076d814aa
0x367b1076d814aa
0x367b1076d814aa
0x367b1076d814aa
0x367b1076d814aa
0x367b1076d814aa
0x367b1076d814aa
0x367b1076d814aa
0x367b1076d814aa
0x367b1076d814aa
0x367b1076d814aa
0x367b1076d814aa
0x367b1076d814aa
0x367b1076d814aa
0x367b1076d814aa
0x367b1076d814aa
0x367b1076d814aa
0x367b1076d814aa
0x367b1076d814aa
0x367b1076d814aa
0x367b1076d814aa
0x367b1076d814aa
0x367b1076d814aa
0x367b1076d814aa
0x367b1076d814aa
0x367b1076d814aa
0x367b1076d814aa
0x367b1076d814aa
0x367b1076d814aa
0x367b1076d814aa
0x367b1076d814aa
0x367b1076d814aa
0x367b1076d814aa
0x367b1076d814aa
0x367b1076d814aa
0x367b1076d814aa
0x367b1076d814aa
0x367b1076d814aa
0x367b1076d814aa

exception.instruction_r: 48 81 c4 c8 00 00 00 c3 48 85 f6 74 08 83 3b 00
exception.symbol: RaiseException+0x3d FreeEnvironmentStringsW-0x373 kernelbase+0xa49d
exception.instruction: add rsp, 0xc8
exception.module: KERNELBASE.dll
exception.exception_code: 0xc000008e
exception.offset: 42141
exception.address: 0x7fefd4fa49d
registers.r14: 0
registers.r15: 0
registers.rcx: 1766864
registers.rsi: 1994472144
registers.r10: 0
registers.rbx: 5368184875
registers.rsp: 1768688
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1768696
registers.rdi: 5367988224
registers.rax: 1996270852
registers.r13: 0
1 0 0

__exception__

stacktrace:
RtlRestoreContext+0x293 __chkstk-0x1fe ntdll+0x50bd2 @ 0x76d80bd2

exception.instruction_r: 48 cf 48 83 ec 30 4c 8b c4 48 81 ec d0 04 00 00
exception.symbol: RtlRestoreContext+0x293 __chkstk-0x1fe ntdll+0x50bd2
exception.instruction: iretq
exception.module: ntdll.dll
exception.exception_code: 0xc0000005
exception.offset: 330706
exception.address: 0x76d80bd2
registers.r14: 0
registers.r15: 0
registers.rcx: 1766864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5368184875
registers.rsp: 1768776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1996270852
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1766864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5368184875
registers.rsp: 1768776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1996270852
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1766864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5368184875
registers.rsp: 1768776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1996270852
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1766864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5368184875
registers.rsp: 1768776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1996270852
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1766864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5368184875
registers.rsp: 1768776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1996270852
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1766864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5368184875
registers.rsp: 1768776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1996270852
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1766864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5368184875
registers.rsp: 1768776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1996270852
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1766864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5368184875
registers.rsp: 1768776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1996270852
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1766864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5368184875
registers.rsp: 1768776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1996270852
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1766864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5368184875
registers.rsp: 1768776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1996270852
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1766864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5368184875
registers.rsp: 1768776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1996270852
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1766864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5368184875
registers.rsp: 1768776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1996270852
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1766864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5368184875
registers.rsp: 1768776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1996270852
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1766864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5368184875
registers.rsp: 1768776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1996270852
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1766864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5368184875
registers.rsp: 1768776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1996270852
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1766864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5368184875
registers.rsp: 1768776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1996270852
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1766864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5368184875
registers.rsp: 1768776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1996270852
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1766864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5368184875
registers.rsp: 1768776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1996270852
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1766864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5368184875
registers.rsp: 1768776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1996270852
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1766864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5368184875
registers.rsp: 1768776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1996270852
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1766864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5368184875
registers.rsp: 1768776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1996270852
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1766864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5368184875
registers.rsp: 1768776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1996270852
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1766864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5368184875
registers.rsp: 1768776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1996270852
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1766864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5368184875
registers.rsp: 1768776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1996270852
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1766864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5368184875
registers.rsp: 1768776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1996270852
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1766864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5368184875
registers.rsp: 1768776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1996270852
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1766864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5368184875
registers.rsp: 1768776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1996270852
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1766864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5368184875
registers.rsp: 1768776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1996270852
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1766864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5368184875
registers.rsp: 1768776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1996270852
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1766864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5368184875
registers.rsp: 1768776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1996270852
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1766864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5368184875
registers.rsp: 1768776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1996270852
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1766864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5368184875
registers.rsp: 1768776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1996270852
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1766864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5368184875
registers.rsp: 1768776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1996270852
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1766864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5368184875
registers.rsp: 1768776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1996270852
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1766864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5368184875
registers.rsp: 1768776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1996270852
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1766864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5368184875
registers.rsp: 1768776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1996270852
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1766864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5368184875
registers.rsp: 1768776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1996270852
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1766864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5368184875
registers.rsp: 1768776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1996270852
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1766864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5368184875
registers.rsp: 1768776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1996270852
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1766864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5368184875
registers.rsp: 1768776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1996270852
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1766864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5368184875
registers.rsp: 1768776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1996270852
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1766864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5368184875
registers.rsp: 1768776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1996270852
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1766864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5368184875
registers.rsp: 1768776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1996270852
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1766864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5368184875
registers.rsp: 1768776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1996270852
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1766864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5368184875
registers.rsp: 1768776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1996270852
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1766864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5368184875
registers.rsp: 1768776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1996270852
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1766864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5368184875
registers.rsp: 1768776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1996270852
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1766864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5368184875
registers.rsp: 1768776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1996270852
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1766864
registers.rsi: 0
registers.r10: 0
registers.rbx: 5368184875
registers.rsp: 1768776
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1993721121
registers.rdi: 0
registers.rax: 1996270852
registers.r13: 0
1 0 0
Time & API Arguments Status Return Repeated

NtProtectVirtualMemory

process_identifier: 2544
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 8192
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0000000076e27000
process_handle: 0xffffffffffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2544
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 8192
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0000000076d80000
process_handle: 0xffffffffffffffff
1 0 0
section {u'size_of_data': u'0x0000b000', u'virtual_address': u'0x00001000', u'entropy': 7.981717078248575, u'name': u' ', u'virtual_size': u'0x00014fd0'} entropy 7.98171707825 description A section with a high entropy has been found
section {u'size_of_data': u'0x00005400', u'virtual_address': u'0x00016000', u'entropy': 7.931274244336927, u'name': u' ', u'virtual_size': u'0x0000f51c'} entropy 7.93127424434 description A section with a high entropy has been found
section {u'size_of_data': u'0x00001400', u'virtual_address': u'0x00026000', u'entropy': 7.761157551016612, u'name': u' ', u'virtual_size': u'0x00003778'} entropy 7.76115755102 description A section with a high entropy has been found
section {u'size_of_data': u'0x00000e00', u'virtual_address': u'0x0002a000', u'entropy': 7.64920562128135, u'name': u' ', u'virtual_size': u'0x0000189c'} entropy 7.64920562128 description A section with a high entropy has been found
section {u'size_of_data': u'0x00000800', u'virtual_address': u'0x0002e000', u'entropy': 7.639898850521337, u'name': u' ', u'virtual_size': u'0x00000a7c'} entropy 7.63989885052 description A section with a high entropy has been found
section {u'size_of_data': u'0x00340800', u'virtual_address': u'0x005da000', u'entropy': 7.964212869167144, u'name': u'.boot', u'virtual_size': u'0x00340800'} entropy 7.96421286917 description A section with a high entropy has been found
entropy 0.999413059428 description Overall entropy of this PE file is high
Time & API Arguments Status Return Repeated

__anomaly__

tid: 2548
message: Encountered 65537 exceptions, quitting.
subcategory: exception
function_name:
1 0 0
Bkav W32.Common.AF338B2C
Lionic Trojan.Win64.Agentb.trtl
tehtris Generic.Malware
MicroWorld-eScan Gen:Variant.Application.Mikey.127686
CAT-QuickHeal Trojan.GenericRI.S22849637
McAfee Artemis!B5376E50D2C4
ALYac Gen:Variant.Application.Mikey.127686
Cylance unsafe
VIPRE Gen:Variant.Application.Mikey.127686
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 0057a4f61 )
Alibaba TrojanDropper:Win32/Scrop.944991fa
K7GW Trojan ( 0057a4f61 )
Cybereason malicious.00f7a8
Arcabit Trojan.Application.Mikey.D1F2C6
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of Win64/Packed.Themida.L suspicious
APEX Malicious
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan-Dropper.Win32.Scrop.pef
BitDefender Gen:Variant.Application.Mikey.127686
Emsisoft Gen:Variant.Application.Mikey.127686 (B)
Zillya Dropper.Scrop.Win32.2008
Trapmine malicious.high.ml.score
FireEye Generic.mg.b5376e50d2c47b7b
Sophos Mal/Generic-S
Ikarus PUA.Themida
Jiangmin TrojanDropper.Scrop.cwb
Avira HEUR/AGEN.1314141
MAX malware (ai score=75)
Antiy-AVL Trojan[Dropper]/Win32.Scrop
Microsoft Trojan:Win32/Wacatac.A!ml
ViRobot Trojan.Win32.Z.Razy.3490304
ZoneAlarm HEUR:Trojan-Dropper.Win32.Scrop.pef
GData Gen:Variant.Application.Mikey.127686
Google Detected
AhnLab-V3 Trojan/Win.ClipBanker.C4626406
Acronis suspicious
DeepInstinct MALICIOUS
VBA32 TrojanDropper.Scrop
Malwarebytes Themida.Trojan.MalPack.DDS
Zoner Probably Heur.ExeHeaderL
TrendMicro-HouseCall TROJ_GEN.R002H0CGV23
Tencent Win32.Trojan-Dropper.Scrop.Eflw
Yandex Riskware.Themida!NI486N1XDk0
SentinelOne Static AI - Suspicious PE
MaxSecure Trojan.Malware.74784373.susgen
Fortinet Riskware/Application
Panda Trj/CI.A