Summary | ZeroBOX

lenin.exe

UPX PE32 PE File
Category Machine Started Completed
FILE s1_win7_x6403_us May 31, 2024, 7:35 a.m. May 31, 2024, 7:39 a.m.
Size 2.3MB
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 cd1dfa093d37dff12f11f8c1c06d565e
SHA256 438974434c65fe40fac3a8e076a01fa432be38325ab8b455476f5f4a446b88a5
CRC32 06DC719A
ssdeep 49152:srYMA4OLHI3O1jSOHoy5f3XPBUD0ZogyAjXzLT/qpcpa232vJ+I:2Y74OLo3QjSOIy5vXZUOogJFatY
Yara
  • PE_Header_Zero - PE File Signature
  • themida_packer - themida packer
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file

IP Address Status Action
18.64.13.203 Active Moloch
104.26.4.15 Active Moloch
147.45.47.126 Active Moloch
164.124.101.2 Active Moloch
34.117.186.192 Active Moloch

Time & API Arguments Status Return Repeated

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0
Time & API Arguments Status Return Repeated

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0
Time & API Arguments Status Return Repeated

WriteConsoleW

buffer: SUCCESS: The scheduled task "MPGPH131 HR" has successfully been created.
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: SUCCESS: The scheduled task "MPGPH131 LG" has successfully been created.
console_handle: 0x00000007
1 1 0
registry HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid
section \x00
section .idata
section
section hluphhoi
section syapwmsf
section .taggant
Time & API Arguments Status Return Repeated

__exception__

stacktrace:
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x778d9ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x778d9ea5

exception.instruction_r: fb e9 4e 01 00 00 60 8b 74 24 24 8b 7c 24 28 fc
exception.symbol: lenin+0x4500b9
exception.instruction: sti
exception.module: lenin.exe
exception.exception_code: 0xc0000096
exception.offset: 4522169
exception.address: 0x10c00b9
registers.esp: 1375736
registers.edi: 0
registers.eax: 1
registers.ebp: 1375752
registers.edx: 19296256
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb e9 c5 fa ff ff c7 04 24 ef 40 4c 58 e9 f2 f6
exception.symbol: lenin+0x18f90a
exception.instruction: sti
exception.module: lenin.exe
exception.exception_code: 0xc0000096
exception.offset: 1636618
exception.address: 0xdff90a
registers.esp: 1375704
registers.edi: 0
registers.eax: 233705
registers.ebp: 4004696084
registers.edx: 13041664
registers.ebx: 73548280
registers.esi: 14678326
registers.ecx: 1971388416
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 57 50 89 14 24 89 04 24 81 ec 04 00 00 00 89
exception.symbol: lenin+0x19084c
exception.instruction: sti
exception.module: lenin.exe
exception.exception_code: 0xc0000096
exception.offset: 1640524
exception.address: 0xe0084c
registers.esp: 1375704
registers.edi: 0
registers.eax: 4294943792
registers.ebp: 4004696084
registers.edx: 1259
registers.ebx: 1822002473
registers.esi: 14706680
registers.ecx: 1971388416
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 57 52 ba 73 7b de 7e 81 e2 e1 bf bf 4f f7 da
exception.symbol: lenin+0x30a631
exception.instruction: sti
exception.module: lenin.exe
exception.exception_code: 0xc0000096
exception.offset: 3188273
exception.address: 0xf7a631
registers.esp: 1375700
registers.edi: 14715295
registers.eax: 16228043
registers.ebp: 4004696084
registers.edx: 14673213
registers.ebx: 1609728
registers.esi: 16227515
registers.ecx: 1401880576
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 68 cc 44 d5 1d 89 1c 24 bb be 3e b6 3d 81 ec
exception.symbol: lenin+0x309fcb
exception.instruction: sti
exception.module: lenin.exe
exception.exception_code: 0xc0000096
exception.offset: 3186635
exception.address: 0xf79fcb
registers.esp: 1375704
registers.edi: 14715295
registers.eax: 16254295
registers.ebp: 4004696084
registers.edx: 14673213
registers.ebx: 1609728
registers.esi: 16227515
registers.ecx: 1401880576
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 55 50 89 e0 05 04 00 00 00 53 bb 0d 19 fc 5e
exception.symbol: lenin+0x30a432
exception.instruction: sti
exception.module: lenin.exe
exception.exception_code: 0xc0000096
exception.offset: 3187762
exception.address: 0xf7a432
registers.esp: 1375704
registers.edi: 4294943956
registers.eax: 16254295
registers.ebp: 4004696084
registers.edx: 14673213
registers.ebx: 1609728
registers.esi: 16227515
registers.ecx: 2202699880
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 81 ea 77 09 dc 5c 81 ea 40 e5 5f 6f e9 4e 00
exception.symbol: lenin+0x310181
exception.instruction: sti
exception.module: lenin.exe
exception.exception_code: 0xc0000096
exception.offset: 3211649
exception.address: 0xf80181
registers.esp: 1375700
registers.edi: 4294943956
registers.eax: 29124
registers.ebp: 4004696084
registers.edx: 16251064
registers.ebx: 60359577
registers.esi: 16227515
registers.ecx: 921
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 56 68 77 1f d5 5f 5e 83 ec 04 e9 14 05 00 00
exception.symbol: lenin+0x30fa98
exception.instruction: sti
exception.module: lenin.exe
exception.exception_code: 0xc0000096
exception.offset: 3209880
exception.address: 0xf7fa98
registers.esp: 1375704
registers.edi: 4294943956
registers.eax: 29124
registers.ebp: 4004696084
registers.edx: 16254176
registers.ebx: 50665
registers.esi: 0
registers.ecx: 921
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 81 ef 6f ba f6 31 81 c7 00 69 2f 5f e9 37 0b
exception.symbol: lenin+0x313633
exception.instruction: sti
exception.module: lenin.exe
exception.exception_code: 0xc0000096
exception.offset: 3225139
exception.address: 0xf83633
registers.esp: 1375700
registers.edi: 16266739
registers.eax: 31040
registers.ebp: 4004696084
registers.edx: 0
registers.ebx: 16256165
registers.esi: 16258146
registers.ecx: 16256165
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb e9 ec 02 00 00 81 e3 5f 49 fe 1e c1 eb 04 87
exception.symbol: lenin+0x313b24
exception.instruction: sti
exception.module: lenin.exe
exception.exception_code: 0xc0000096
exception.offset: 3226404
exception.address: 0xf83b24
registers.esp: 1375704
registers.edi: 16297779
registers.eax: 31040
registers.ebp: 4004696084
registers.edx: 0
registers.ebx: 16256165
registers.esi: 16258146
registers.ecx: 16256165
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb e9 71 03 00 00 89 0c 24 e9 8e fd ff ff 81 ee
exception.symbol: lenin+0x313a50
exception.instruction: sti
exception.module: lenin.exe
exception.exception_code: 0xc0000096
exception.offset: 3226192
exception.address: 0xf83a50
registers.esp: 1375704
registers.edi: 16297779
registers.eax: 134889
registers.ebp: 4004696084
registers.edx: 0
registers.ebx: 16256165
registers.esi: 4294939300
registers.ecx: 16256165
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: ed 64 8f 05 00 00 00 00 68 c4 36 44 79 89 2c 24
exception.symbol: lenin+0x319a68
exception.instruction: in eax, dx
exception.module: lenin.exe
exception.exception_code: 0xc0000096
exception.offset: 3250792
exception.address: 0xf89a68
registers.esp: 1375696
registers.edi: 7024359
registers.eax: 1447909480
registers.ebp: 4004696084
registers.edx: 22104
registers.ebx: 1971327157
registers.esi: 16291222
registers.ecx: 20
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: 0f 3f 07 0b 64 8f 05 00 00 00 00 83 c4 04 83 fb
exception.symbol: lenin+0x31ad60
exception.address: 0xf8ad60
exception.module: lenin.exe
exception.exception_code: 0xc000001d
exception.offset: 3255648
registers.esp: 1375696
registers.edi: 7024359
registers.eax: 1
registers.ebp: 4004696084
registers.edx: 22104
registers.ebx: 0
registers.esi: 16291222
registers.ecx: 20
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: ed 81 fb 68 58 4d 56 75 0a c7 85 53 2a 2d 12 01
exception.symbol: lenin+0x31f2a2
exception.instruction: in eax, dx
exception.module: lenin.exe
exception.exception_code: 0xc0000096
exception.offset: 3273378
exception.address: 0xf8f2a2
registers.esp: 1375696
registers.edi: 7024359
registers.eax: 1447909480
registers.ebp: 4004696084
registers.edx: 22104
registers.ebx: 2256917605
registers.esi: 16291222
registers.ecx: 10
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb e9 c6 05 00 00 59 29 d0 05 38 62 df 7e ff 34
exception.symbol: lenin+0x321ebd
exception.instruction: sti
exception.module: lenin.exe
exception.exception_code: 0xc0000096
exception.offset: 3284669
exception.address: 0xf91ebd
registers.esp: 1375700
registers.edi: 7024359
registers.eax: 16325857
registers.ebp: 4004696084
registers.edx: 2130566132
registers.ebx: 19315671
registers.esi: 10
registers.ecx: 1401880576
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 57 68 38 a9 cb 74 e9 a4 f9 ff ff 31 de ff 34
exception.symbol: lenin+0x3226a3
exception.instruction: sti
exception.module: lenin.exe
exception.exception_code: 0xc0000096
exception.offset: 3286691
exception.address: 0xf926a3
registers.esp: 1375704
registers.edi: 0
registers.eax: 16328509
registers.ebp: 4004696084
registers.edx: 2130566132
registers.ebx: 19315671
registers.esi: 6379
registers.ecx: 1401880576
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: cd 01 eb 00 8b cb 6a 00 53 e8 03 00 00 00 20 5b
exception.symbol: lenin+0x322c01
exception.instruction: int 1
exception.module: lenin.exe
exception.exception_code: 0xc0000005
exception.offset: 3288065
exception.address: 0xf92c01
registers.esp: 1375664
registers.edi: 0
registers.eax: 1375664
registers.ebp: 4004696084
registers.edx: 11617
registers.ebx: 16330081
registers.esi: 201178557
registers.ecx: 1390292321
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 29 ff ff 34 3e 81 2c 24 00 e7 bd 7f 8b 1c 24
exception.symbol: lenin+0x3324a3
exception.instruction: sti
exception.module: lenin.exe
exception.exception_code: 0xc0000096
exception.offset: 3351715
exception.address: 0xfa24a3
registers.esp: 1375704
registers.edi: 14668762
registers.eax: 25888
registers.ebp: 4004696084
registers.edx: 6
registers.ebx: 19315893
registers.esi: 16417618
registers.ecx: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 51 52 ba 92 a5 77 50 e9 9e f8 ff ff 81 c6 04
exception.symbol: lenin+0x33297a
exception.instruction: sti
exception.module: lenin.exe
exception.exception_code: 0xc0000096
exception.offset: 3352954
exception.address: 0xfa297a
registers.esp: 1375704
registers.edi: 4294944336
registers.eax: 25888
registers.ebp: 4004696084
registers.edx: 6
registers.ebx: 262633
registers.esi: 16417618
registers.ecx: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 56 89 2c 24 89 1c 24 bb 61 cd 75 62 29 da ff
exception.symbol: lenin+0x334fe6
exception.instruction: sti
exception.module: lenin.exe
exception.exception_code: 0xc0000096
exception.offset: 3362790
exception.address: 0xfa4fe6
registers.esp: 1375692
registers.edi: 4294944336
registers.eax: 32528
registers.ebp: 4004696084
registers.edx: 16403589
registers.ebx: 262633
registers.esi: 16417618
registers.ecx: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 83 ec 04 89 34 24 c7 04 24 0c 53 af 63 81 0c
exception.symbol: lenin+0x335195
exception.instruction: sti
exception.module: lenin.exe
exception.exception_code: 0xc0000096
exception.offset: 3363221
exception.address: 0xfa5195
registers.esp: 1375696
registers.edi: 1179202795
registers.eax: 4294937388
registers.ebp: 4004696084
registers.edx: 16436117
registers.ebx: 262633
registers.esi: 16417618
registers.ecx: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 50 57 c7 04 24 53 de 76 6e f7 1c 24 81 24 24
exception.symbol: lenin+0x337ae6
exception.instruction: sti
exception.module: lenin.exe
exception.exception_code: 0xc0000096
exception.offset: 3373798
exception.address: 0xfa7ae6
registers.esp: 1375696
registers.edi: 1179202795
registers.eax: 604277078
registers.ebp: 4004696084
registers.edx: 16416304
registers.ebx: 127746414
registers.esi: 16417618
registers.ecx: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb e9 ce fc ff ff 81 c1 b9 a3 5e 01 81 c2 40 42
exception.symbol: lenin+0x33a15c
exception.instruction: sti
exception.module: lenin.exe
exception.exception_code: 0xc0000096
exception.offset: 3383644
exception.address: 0xfaa15c
registers.esp: 1375692
registers.edi: 1179202795
registers.eax: 27703
registers.ebp: 4004696084
registers.edx: 16416304
registers.ebx: 16424275
registers.esi: 16417618
registers.ecx: 1687547531
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb e9 70 03 00 00 01 d3 8b 14 24 83 c4 04 01 fb
exception.symbol: lenin+0x33a02a
exception.instruction: sti
exception.module: lenin.exe
exception.exception_code: 0xc0000096
exception.offset: 3383338
exception.address: 0xfaa02a
registers.esp: 1375696
registers.edi: 1179202795
registers.eax: 27703
registers.ebp: 4004696084
registers.edx: 16416304
registers.ebx: 16451978
registers.esi: 16417618
registers.ecx: 1687547531
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 57 c7 04 24 31 5d bf 2f 81 34 24 c2 a3 71 67
exception.symbol: lenin+0x339ed8
exception.instruction: sti
exception.module: lenin.exe
exception.exception_code: 0xc0000096
exception.offset: 3383000
exception.address: 0xfa9ed8
registers.esp: 1375696
registers.edi: 0
registers.eax: 27703
registers.ebp: 4004696084
registers.edx: 16416304
registers.ebx: 16427506
registers.esi: 16417618
registers.ecx: 607453008
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 81 ec 04 00 00 00 89 2c 24 e9 cf f7 ff ff 60
exception.symbol: lenin+0x34830d
exception.instruction: sti
exception.module: lenin.exe
exception.exception_code: 0xc0000096
exception.offset: 3441421
exception.address: 0xfb830d
registers.esp: 1375696
registers.edi: 357871229
registers.eax: 16483096
registers.ebp: 4004696084
registers.edx: 0
registers.ebx: 357871229
registers.esi: 1401880576
registers.ecx: 2879193440
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 81 c2 2d eb ff 31 83 ec 04 89 3c 24 e9 78 fd
exception.symbol: lenin+0x35b635
exception.instruction: sti
exception.module: lenin.exe
exception.exception_code: 0xc0000096
exception.offset: 3520053
exception.address: 0xfcb635
registers.esp: 1375660
registers.edi: 9350
registers.eax: 30957
registers.ebp: 4004696084
registers.edx: 16559689
registers.ebx: 16571355
registers.esi: 16554349
registers.ecx: 1401880576
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 29 db ff 34 13 ff 34 24 e9 8e 03 00 00 50 b8
exception.symbol: lenin+0x35b3b1
exception.instruction: sti
exception.module: lenin.exe
exception.exception_code: 0xc0000096
exception.offset: 3519409
exception.address: 0xfcb3b1
registers.esp: 1375664
registers.edi: 9350
registers.eax: 30957
registers.ebp: 4004696084
registers.edx: 16590646
registers.ebx: 16571355
registers.esi: 16554349
registers.ecx: 1401880576
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 53 bb 00 a5 af 5a 83 ec 04 89 0c 24 68 1a 43
exception.symbol: lenin+0x35b33d
exception.instruction: sti
exception.module: lenin.exe
exception.exception_code: 0xc0000096
exception.offset: 3519293
exception.address: 0xfcb33d
registers.esp: 1375664
registers.edi: 9350
registers.eax: 30957
registers.ebp: 4004696084
registers.edx: 16590646
registers.ebx: 4294938880
registers.esi: 16554349
registers.ecx: 6875752
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 81 eb c7 e6 b7 7f 03 1c 24 56 e9 5e 05 00 00
exception.symbol: lenin+0x35b938
exception.instruction: sti
exception.module: lenin.exe
exception.exception_code: 0xc0000096
exception.offset: 3520824
exception.address: 0xfcb938
registers.esp: 1375660
registers.edi: 9350
registers.eax: 26858
registers.ebp: 4004696084
registers.edx: 1262138698
registers.ebx: 16562426
registers.esi: 16554349
registers.ecx: 1273915136
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 68 c5 f8 97 52 89 04 24 c7 04 24 11 b3 91 12
exception.symbol: lenin+0x35bbea
exception.instruction: sti
exception.module: lenin.exe
exception.exception_code: 0xc0000096
exception.offset: 3521514
exception.address: 0xfcbbea
registers.esp: 1375664
registers.edi: 9350
registers.eax: 26858
registers.ebp: 4004696084
registers.edx: 1262138698
registers.ebx: 16589284
registers.esi: 16554349
registers.ecx: 1273915136
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 68 4a d1 ca 4f 89 04 24 50 e9 00 00 00 00 52
exception.symbol: lenin+0x35b90e
exception.instruction: sti
exception.module: lenin.exe
exception.exception_code: 0xc0000096
exception.offset: 3520782
exception.address: 0xfcb90e
registers.esp: 1375664
registers.edi: 9350
registers.eax: 26858
registers.ebp: 4004696084
registers.edx: 0
registers.ebx: 16565248
registers.esi: 4290087264
registers.ecx: 1273915136
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb e9 82 00 00 00 89 0c 24 57 ff 74 24 04 5f 8f
exception.symbol: lenin+0x35d0cf
exception.instruction: sti
exception.module: lenin.exe
exception.exception_code: 0xc0000096
exception.offset: 3526863
exception.address: 0xfcd0cf
registers.esp: 1375664
registers.edi: 1342204512
registers.eax: 4294942188
registers.ebp: 4004696084
registers.edx: 16593860
registers.ebx: 2069477476
registers.esi: 16565278
registers.ecx: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 55 e9 3b 00 00 00 05 a8 c3 6a 69 01 d0 2d a8
exception.symbol: lenin+0x35e368
exception.instruction: sti
exception.module: lenin.exe
exception.exception_code: 0xc0000096
exception.offset: 3531624
exception.address: 0xfce368
registers.esp: 1375664
registers.edi: 1342204512
registers.eax: 26656
registers.ebp: 4004696084
registers.edx: 1224595391
registers.ebx: 16597526
registers.esi: 16565278
registers.ecx: 687896669
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 56 e9 d8 fd ff ff ff 34 24 8b 0c 24 81 c4 04
exception.symbol: lenin+0x35dc97
exception.instruction: sti
exception.module: lenin.exe
exception.exception_code: 0xc0000096
exception.offset: 3529879
exception.address: 0xfcdc97
registers.esp: 1375664
registers.edi: 0
registers.eax: 26656
registers.ebp: 4004696084
registers.edx: 1224595391
registers.ebx: 16573958
registers.esi: 322689
registers.ecx: 687896669
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 53 bb 47 05 f7 3f 53 87 14 24 f7 d2 52 ff 74
exception.symbol: lenin+0x3629bc
exception.instruction: sti
exception.module: lenin.exe
exception.exception_code: 0xc0000096
exception.offset: 3549628
exception.address: 0xfd29bc
registers.esp: 1375664
registers.edi: 16619241
registers.eax: 29976
registers.ebp: 4004696084
registers.edx: 0
registers.ebx: 65804
registers.esi: 322689
registers.ecx: 1969225870
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb b9 f7 ff fa 3f 81 c1 3e af a9 6f 83 ec 04 89
exception.symbol: lenin+0x3625b2
exception.instruction: sti
exception.module: lenin.exe
exception.exception_code: 0xc0000096
exception.offset: 3548594
exception.address: 0xfd25b2
registers.esp: 1375664
registers.edi: 16592341
registers.eax: 0
registers.ebp: 4004696084
registers.edx: 0
registers.ebx: 65804
registers.esi: 24811
registers.ecx: 1969225870
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 57 56 be af ea 39 6d 68 cf 71 4c 0f 89 2c 24
exception.symbol: lenin+0x3666bc
exception.instruction: sti
exception.module: lenin.exe
exception.exception_code: 0xc0000096
exception.offset: 3565244
exception.address: 0xfd66bc
registers.esp: 1375660
registers.edi: 16600887
registers.eax: 16603889
registers.ebp: 4004696084
registers.edx: 26880
registers.ebx: 275524491
registers.esi: 275524491
registers.ecx: 4294937344
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 50 e9 00 00 00 00 55 c7 04 24 19 0b b7 7d 58
exception.symbol: lenin+0x3666fa
exception.instruction: sti
exception.module: lenin.exe
exception.exception_code: 0xc0000096
exception.offset: 3565306
exception.address: 0xfd66fa
registers.esp: 1375664
registers.edi: 16600887
registers.eax: 16607109
registers.ebp: 4004696084
registers.edx: 26880
registers.ebx: 275524491
registers.esi: 0
registers.ecx: 2394882152
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 51 e9 09 04 00 00 51 89 e1 81 c1 04 00 00 00
exception.symbol: lenin+0x366bcd
exception.instruction: sti
exception.module: lenin.exe
exception.exception_code: 0xc0000096
exception.offset: 3566541
exception.address: 0xfd6bcd
registers.esp: 1375664
registers.edi: 607947088
registers.eax: 26921
registers.ebp: 4004696084
registers.edx: 681760400
registers.ebx: 275524491
registers.esi: 4294943212
registers.ecx: 16634483
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 68 70 98 d0 43 89 1c 24 89 04 24 68 5d 9b 19
exception.symbol: lenin+0x36e2cd
exception.instruction: sti
exception.module: lenin.exe
exception.exception_code: 0xc0000096
exception.offset: 3597005
exception.address: 0xfde2cd
registers.esp: 1375664
registers.edi: 607947088
registers.eax: 29407
registers.ebp: 4004696084
registers.edx: 2130566132
registers.ebx: 2147483650
registers.esi: 16617798
registers.ecx: 16667428
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb e9 6a fa ff ff 35 fb fe ef 7f 89 c5 58 05 d6
exception.symbol: lenin+0x36e75f
exception.instruction: sti
exception.module: lenin.exe
exception.exception_code: 0xc0000096
exception.offset: 3598175
exception.address: 0xfde75f
registers.esp: 1375664
registers.edi: 2179172691
registers.eax: 29407
registers.ebp: 4004696084
registers.edx: 2130566132
registers.ebx: 0
registers.esi: 16617798
registers.ecx: 16640864
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 81 ee 0a e0 e2 78 81 c6 76 c0 bb 6f 03 34 24
exception.symbol: lenin+0x3705d2
exception.instruction: sti
exception.module: lenin.exe
exception.exception_code: 0xc0000096
exception.offset: 3605970
exception.address: 0xfe05d2
registers.esp: 1375660
registers.edi: 1867602247
registers.eax: 30803
registers.ebp: 4004696084
registers.edx: 314797082
registers.ebx: 1878916551
registers.esi: 16646792
registers.ecx: 331442334
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 81 ec 04 00 00 00 e9 38 fe ff ff 59 ff 34 24
exception.symbol: lenin+0x370aa7
exception.instruction: sti
exception.module: lenin.exe
exception.exception_code: 0xc0000096
exception.offset: 3607207
exception.address: 0xfe0aa7
registers.esp: 1375664
registers.edi: 607422803
registers.eax: 30803
registers.ebp: 4004696084
registers.edx: 4294939184
registers.ebx: 1878916551
registers.esi: 16677595
registers.ecx: 331442334
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb e9 41 fa ff ff 81 f6 72 15 db 0e 81 ee 36 f2
exception.symbol: lenin+0x38edd0
exception.instruction: sti
exception.module: lenin.exe
exception.exception_code: 0xc0000096
exception.offset: 3730896
exception.address: 0xffedd0
registers.esp: 1375660
registers.edi: 16749596
registers.eax: 25798
registers.ebp: 4004696084
registers.edx: 2547992
registers.ebx: 4009719623
registers.esi: 16770926
registers.ecx: 1401880576
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 68 96 ac 66 29 e9 53 fb ff ff 5f 56 be 61 42
exception.symbol: lenin+0x38f022
exception.instruction: sti
exception.module: lenin.exe
exception.exception_code: 0xc0000096
exception.offset: 3731490
exception.address: 0xfff022
registers.esp: 1375664
registers.edi: 16749596
registers.eax: 25798
registers.ebp: 4004696084
registers.edx: 0
registers.ebx: 607453008
registers.esi: 16773696
registers.ecx: 1401880576
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 81 ec 04 00 00 00 89 3c 24 bf dc 04 75 7d 50
exception.symbol: lenin+0x396f1a
exception.instruction: sti
exception.module: lenin.exe
exception.exception_code: 0xc0000096
exception.offset: 3763994
exception.address: 0x1006f1a
registers.esp: 1375664
registers.edi: 2298801283
registers.eax: 4294939476
registers.ebp: 4004696084
registers.edx: 16834693
registers.ebx: 3726077008
registers.esi: 3802938637
registers.ecx: 10
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 50 b8 a8 81 f9 7b 68 c0 b1 28 78 89 3c 24 e9
exception.symbol: lenin+0x3a56a1
exception.instruction: sti
exception.module: lenin.exe
exception.exception_code: 0xc0000096
exception.offset: 3823265
exception.address: 0x10156a1
registers.esp: 1375660
registers.edi: 2130566132
registers.eax: 31836
registers.ebp: 4004696084
registers.edx: 11
registers.ebx: 16832909
registers.esi: 4505580
registers.ecx: 16863309
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 31 db ff 34 0b ff 34 24 58 52 c7 04 24 3b 73
exception.symbol: lenin+0x3a5977
exception.instruction: sti
exception.module: lenin.exe
exception.exception_code: 0xc0000096
exception.offset: 3823991
exception.address: 0x1015977
registers.esp: 1375664
registers.edi: 2130566132
registers.eax: 31836
registers.ebp: 4004696084
registers.edx: 11
registers.ebx: 16832909
registers.esi: 4505580
registers.ecx: 16895145
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 81 ec 04 00 00 00 89 3c 24 bf 51 c7 f5 6e 83
exception.symbol: lenin+0x3a515c
exception.instruction: sti
exception.module: lenin.exe
exception.exception_code: 0xc0000096
exception.offset: 3821916
exception.address: 0x101515c
registers.esp: 1375664
registers.edi: 2130566132
registers.eax: 604292946
registers.ebp: 4004696084
registers.edx: 11
registers.ebx: 4294938208
registers.esi: 4505580
registers.ecx: 16895145
1 0 0
request GET https://db-ip.com/demo/home.php?s=175.208.134.152
Time & API Arguments Status Return Repeated

NtProtectVirtualMemory

process_identifier: 2032
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 8192
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x7793f000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2032
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 8192
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x778b0000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2032
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 704512
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00c71000
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2032
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x009c0000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2032
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x009d0000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2032
region_size: 8192
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00c60000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2032
region_size: 65536
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02670000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2032
region_size: 8192
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02680000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2032
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x027d0000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2032
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x027e0000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2032
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x027f0000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2032
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02840000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2032
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02890000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2032
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x029a0000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2032
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x029f0000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2032
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02a00000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2032
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02a10000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2032
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02b20000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2032
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02b30000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2032
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02b80000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2032
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02b90000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2032
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02ba0000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2032
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02bb0000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2032
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02bc0000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2032
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02c10000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2032
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02c20000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2032
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02c30000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2032
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02c40000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2032
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02c50000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2032
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02d60000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2032
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02d70000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2032
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02680000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2032
region_size: 8192
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02f00000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2032
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02680000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2032
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02680000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2032
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02f10000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2032
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02f20000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2032
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02f30000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2032
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02680000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2032
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02680000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2032
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02680000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2032
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02680000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2032
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02680000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2032
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02680000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2032
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02680000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2032
region_size: 8192
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02680000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2032
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02680000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0
description lenin.exe tried to sleep 259 seconds, actually delayed analysis time by 259 seconds
domain ipinfo.io
cmdline schtasks /create /f /RU "test22" /tr "C:\ProgramData\MPGPH131\MPGPH131.exe" /tn "MPGPH131 LG" /sc ONLOGON /rl HIGHEST
cmdline schtasks /create /f /RU "test22" /tr "C:\ProgramData\MPGPH131\MPGPH131.exe" /tn "MPGPH131 HR" /sc HOURLY /rl HIGHEST
Time & API Arguments Status Return Repeated

CreateProcessInternalW

thread_identifier: 2616
thread_handle: 0x000001c8
process_identifier: 2612
current_directory:
filepath:
track: 1
command_line: schtasks /create /f /RU "test22" /tr "C:\ProgramData\MPGPH131\MPGPH131.exe" /tn "MPGPH131 HR" /sc HOURLY /rl HIGHEST
filepath_r:
stack_pivoted: 0
creation_flags: 134217728 (CREATE_NO_WINDOW)
inherit_handles: 0
process_handle: 0x000001cc
1 1 0

CreateProcessInternalW

thread_identifier: 2700
thread_handle: 0x000001d4
process_identifier: 2696
current_directory:
filepath:
track: 1
command_line: schtasks /create /f /RU "test22" /tr "C:\ProgramData\MPGPH131\MPGPH131.exe" /tn "MPGPH131 LG" /sc ONLOGON /rl HIGHEST
filepath_r:
stack_pivoted: 0
creation_flags: 134217728 (CREATE_NO_WINDOW)
inherit_handles: 0
process_handle: 0x000001d0
1 1 0
section {u'size_of_data': u'0x000ab400', u'virtual_address': u'0x00001000', u'entropy': 7.984426631645928, u'name': u' \\x00 ', u'virtual_size': u'0x00189000'} entropy 7.98442663165 description A section with a high entropy has been found
section {u'size_of_data': u'0x00001400', u'virtual_address': u'0x0018a000', u'entropy': 7.840211802259577, u'name': u'.rsrc', u'virtual_size': u'0x00001934'} entropy 7.84021180226 description A section with a high entropy has been found
section {u'size_of_data': u'0x001a5200', u'virtual_address': u'0x00450000', u'entropy': 7.953119860948347, u'name': u'hluphhoi', u'virtual_size': u'0x001a6000'} entropy 7.95311986095 description A section with a high entropy has been found
entropy 0.995597484277 description Overall entropy of this PE file is high
process system
cmdline schtasks /create /f /RU "test22" /tr "C:\ProgramData\MPGPH131\MPGPH131.exe" /tn "MPGPH131 LG" /sc ONLOGON /rl HIGHEST
cmdline schtasks /create /f /RU "test22" /tr "C:\ProgramData\MPGPH131\MPGPH131.exe" /tn "MPGPH131 HR" /sc HOURLY /rl HIGHEST
host 18.64.13.203
host 147.45.47.126
file \??\SICE
file \??\SIWVID
file \??\NTICE
Time & API Arguments Status Return Repeated

FindWindowA

class_name: OLLYDBG
window_name:
0 0

FindWindowA

class_name: GBDYLLO
window_name:
0 0

FindWindowA

class_name: pediy06
window_name:
0 0

FindWindowA

class_name: FilemonClass
window_name:
0 0

FindWindowA

class_name: FilemonClass
window_name:
0 0

FindWindowA

class_name: #0
window_name: File Monitor - Sysinternals: www.sysinternals.com
0 0

FindWindowA

class_name: PROCMON_WINDOW_CLASS
window_name:
0 0

FindWindowA

class_name: #0
window_name: Process Monitor - Sysinternals: www.sysinternals.com
0 0

FindWindowA

class_name: RegmonClass
window_name:
0 0

FindWindowA

class_name: RegmonClass
window_name:
0 0

FindWindowA

class_name: #0
window_name: Registry Monitor - Sysinternals: www.sysinternals.com
0 0

FindWindowA

class_name: 18467-41
window_name:
0 0

FindWindowA

class_name: FilemonClass
window_name:
0 0

FindWindowA

class_name: FilemonClass
window_name:
0 0

FindWindowA

class_name: #0
window_name: File Monitor - Sysinternals: www.sysinternals.com
0 0

FindWindowA

class_name: PROCMON_WINDOW_CLASS
window_name:
0 0

FindWindowA

class_name: #0
window_name: Process Monitor - Sysinternals: www.sysinternals.com
0 0

FindWindowA

class_name: OLLYDBG
window_name:
0 0

FindWindowA

class_name: GBDYLLO
window_name:
0 0

FindWindowA

class_name: pediy06
window_name:
0 0

FindWindowA

class_name: OLLYDBG
window_name:
0 0

FindWindowA

class_name: GBDYLLO
window_name:
0 0

FindWindowA

class_name: pediy06
window_name:
0 0

FindWindowA

class_name: Regmonclass
window_name:
0 0

FindWindowA

class_name: Regmonclass
window_name:
0 0

FindWindowA

class_name: 18467-41
window_name:
0 0

FindWindowA

class_name: Filemonclass
window_name:
0 0

FindWindowA

class_name: Filemonclass
window_name:
0 0

FindWindowA

class_name: PROCMON_WINDOW_CLASS
window_name:
0 0

FindWindowA

class_name: OLLYDBG
window_name:
0 0

FindWindowA

class_name: GBDYLLO
window_name:
0 0

FindWindowA

class_name: pediy06
window_name:
0 0

FindWindowA

class_name: OLLYDBG
window_name:
0 0

FindWindowA

class_name: GBDYLLO
window_name:
0 0

FindWindowA

class_name: pediy06
window_name:
0 0

FindWindowA

class_name: Regmonclass
window_name:
0 0

FindWindowA

class_name: Regmonclass
window_name:
0 0

FindWindowA

class_name: 18467-41
window_name:
0 0

FindWindowA

class_name: Filemonclass
window_name:
0 0

FindWindowA

class_name: Filemonclass
window_name:
0 0

FindWindowA

class_name: PROCMON_WINDOW_CLASS
window_name:
0 0

FindWindowA

class_name: OLLYDBG
window_name:
0 0

FindWindowA

class_name: GBDYLLO
window_name:
0 0

FindWindowA

class_name: pediy06
window_name:
0 0

FindWindowA

class_name: OLLYDBG
window_name:
0 0

FindWindowA

class_name: GBDYLLO
window_name:
0 0

FindWindowA

class_name: pediy06
window_name:
0 0

FindWindowA

class_name: Regmonclass
window_name:
0 0

FindWindowA

class_name: Regmonclass
window_name:
0 0

FindWindowA

class_name: 18467-41
window_name:
0 0
registry HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\SystemBiosVersion
registry HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\VideoBiosVersion
reg_key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\RageMP131 reg_value C:\Users\test22\AppData\Local\RageMP131\RageMP131.exe
cmdline schtasks /create /f /RU "test22" /tr "C:\ProgramData\MPGPH131\MPGPH131.exe" /tn "MPGPH131 LG" /sc ONLOGON /rl HIGHEST
cmdline schtasks /create /f /RU "test22" /tr "C:\ProgramData\MPGPH131\MPGPH131.exe" /tn "MPGPH131 HR" /sc HOURLY /rl HIGHEST
registry HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\F81F111D0E5AB58D396F7BF525577FD30FDC95AA\Blob
cmdline schtasks /create /f /RU "test22" /tr "C:\ProgramData\MPGPH131\MPGPH131.exe" /tn "MPGPH131 LG" /sc ONLOGON /rl HIGHEST
cmdline schtasks /create /f /RU "test22" /tr "C:\ProgramData\MPGPH131\MPGPH131.exe" /tn "MPGPH131 HR" /sc HOURLY /rl HIGHEST
Time & API Arguments Status Return Repeated

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: ed 64 8f 05 00 00 00 00 68 c4 36 44 79 89 2c 24
exception.symbol: lenin+0x319a68
exception.instruction: in eax, dx
exception.module: lenin.exe
exception.exception_code: 0xc0000096
exception.offset: 3250792
exception.address: 0xf89a68
registers.esp: 1375696
registers.edi: 7024359
registers.eax: 1447909480
registers.ebp: 4004696084
registers.edx: 22104
registers.ebx: 1971327157
registers.esi: 16291222
registers.ecx: 20
1 0 0