Summary | ZeroBOX

chrome_93.exe

Themida PE64 PE File
Category Machine Started Completed
FILE s1_win7_x6403_us Oct. 21, 2024, 1:37 p.m. Oct. 21, 2024, 1:43 p.m.
Size 8.3MB
Type PE32+ executable (GUI) x86-64, for MS Windows
MD5 54645f818b03eea58b28345e88707bd6
SHA256 051baaebf1cf899c16f6e66ca43d441a87cf037c3dd2e30ace10172e93386ae2
CRC32 C2CA6D58
ssdeep 196608:hVb/+OXplxJaRIEwfa6SFGMUQ06SXevqZhpP8arlNayY:hVb/+6XvaTwfWFGMn0tevqhZX
Yara
  • themida_packer - themida packer
  • PE_Header_Zero - PE File Signature
  • IsPE64 - (no description)

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
No hosts contacted.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

section
section .imports
section .themida
section .boot
Time & API Arguments Status Return Repeated

__exception__

stacktrace:
RaiseException+0x3d FreeEnvironmentStringsW-0x373 kernelbase+0xa49d @ 0x7fefdbfa49d
chrome_93+0xac28b2 @ 0x13fe028b2
chrome_93+0xba248f @ 0x13fee248f
HeapWalk-0x1ce0 kernel32+0x0 @ 0x76fc0000
0x13fd28
0x13fd28
0x13fd28

exception.instruction_r: 48 81 c4 c8 00 00 00 c3 48 85 f6 74 08 83 3b 00
exception.symbol: RaiseException+0x3d FreeEnvironmentStringsW-0x373 kernelbase+0xa49d
exception.instruction: add rsp, 0xc8
exception.module: KERNELBASE.dll
exception.exception_code: 0xc000008e
exception.offset: 42141
exception.address: 0x7fefdbfa49d
registers.r14: 0
registers.r15: 0
registers.rcx: 1308192
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310000
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310024
registers.rdi: 5362573312
registers.rax: 2003689736
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308192
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310000
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310024
registers.rdi: 5362573312
registers.rax: 2003689736
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308192
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310000
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310024
registers.rdi: 5362573312
registers.rax: 2003689736
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308192
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310000
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310024
registers.rdi: 5362573312
registers.rax: 2003689736
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308192
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310000
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310024
registers.rdi: 5362573312
registers.rax: 2003689736
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308192
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310000
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310024
registers.rdi: 5362573312
registers.rax: 2003689736
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308192
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310000
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310024
registers.rdi: 5362573312
registers.rax: 2003689736
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308192
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310000
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310024
registers.rdi: 5362573312
registers.rax: 2003689736
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308192
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310000
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310024
registers.rdi: 5362573312
registers.rax: 2003689736
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308192
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310000
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310024
registers.rdi: 5362573312
registers.rax: 2003689736
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308192
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310000
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310024
registers.rdi: 5362573312
registers.rax: 2003689736
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308192
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310000
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310024
registers.rdi: 5362573312
registers.rax: 2003689736
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308192
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310000
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310024
registers.rdi: 5362573312
registers.rax: 2003689736
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308192
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310000
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310024
registers.rdi: 5362573312
registers.rax: 2003689736
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308192
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310000
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310024
registers.rdi: 5362573312
registers.rax: 2003689736
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308192
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310000
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310024
registers.rdi: 5362573312
registers.rax: 2003689736
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308192
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310000
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310024
registers.rdi: 5362573312
registers.rax: 2003689736
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308192
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310000
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310024
registers.rdi: 5362573312
registers.rax: 2003689736
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308192
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310000
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310024
registers.rdi: 5362573312
registers.rax: 2003689736
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308192
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310000
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310024
registers.rdi: 5362573312
registers.rax: 2003689736
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308192
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310000
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310024
registers.rdi: 5362573312
registers.rax: 2003689736
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308192
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310000
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310024
registers.rdi: 5362573312
registers.rax: 2003689736
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308192
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310000
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310024
registers.rdi: 5362573312
registers.rax: 2003689736
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308192
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310000
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310024
registers.rdi: 5362573312
registers.rax: 2003689736
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308192
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310000
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310024
registers.rdi: 5362573312
registers.rax: 2003689736
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308192
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310000
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310024
registers.rdi: 5362573312
registers.rax: 2003689736
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308192
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310000
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310024
registers.rdi: 5362573312
registers.rax: 2003689736
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308192
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310000
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310024
registers.rdi: 5362573312
registers.rax: 2003689736
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308192
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310000
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310024
registers.rdi: 5362573312
registers.rax: 2003689736
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308192
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310000
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310024
registers.rdi: 5362573312
registers.rax: 2003689736
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308192
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310000
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310024
registers.rdi: 5362573312
registers.rax: 2003689736
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308192
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310000
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310024
registers.rdi: 5362573312
registers.rax: 2003689736
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308192
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310000
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310024
registers.rdi: 5362573312
registers.rax: 2003689736
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308192
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310000
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310024
registers.rdi: 5362573312
registers.rax: 2003689736
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308192
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310000
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310024
registers.rdi: 5362573312
registers.rax: 2003689736
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308192
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310000
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310024
registers.rdi: 5362573312
registers.rax: 2003689736
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308192
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310000
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310024
registers.rdi: 5362573312
registers.rax: 2003689736
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308192
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310000
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310024
registers.rdi: 5362573312
registers.rax: 2003689736
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308192
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310000
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310024
registers.rdi: 5362573312
registers.rax: 2003689736
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308192
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310000
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310024
registers.rdi: 5362573312
registers.rax: 2003689736
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308192
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310000
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310024
registers.rdi: 5362573312
registers.rax: 2003689736
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308192
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310000
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310024
registers.rdi: 5362573312
registers.rax: 2003689736
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308192
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310000
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310024
registers.rdi: 5362573312
registers.rax: 2003689736
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308192
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310000
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310024
registers.rdi: 5362573312
registers.rax: 2003689736
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308192
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310000
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310024
registers.rdi: 5362573312
registers.rax: 2003689736
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308192
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310000
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310024
registers.rdi: 5362573312
registers.rax: 2003689736
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308192
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310000
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310024
registers.rdi: 5362573312
registers.rax: 2003689736
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308192
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310000
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310024
registers.rdi: 5362573312
registers.rax: 2003689736
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308192
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310000
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310024
registers.rdi: 5362573312
registers.rax: 2003689736
registers.r13: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 0
registers.r15: 0
registers.rcx: 1308192
registers.rsi: 2004499152
registers.r10: 0
registers.rbx: 0
registers.rsp: 1310000
registers.r11: 514
registers.r8: 0
registers.r9: 0
registers.rdx: 0
registers.r12: 0
registers.rbp: 1310024
registers.rdi: 5362573312
registers.rax: 2003689736
registers.r13: 0
1 0 0
Time & API Arguments Status Return Repeated

NtProtectVirtualMemory

process_identifier: 2084
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 8192
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00000000777b7000
process_handle: 0xffffffffffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2084
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 8192
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0000000077710000
process_handle: 0xffffffffffffffff
1 0 0
section {u'size_of_data': u'0x00006ee9', u'virtual_address': u'0x00001000', u'entropy': 7.9592943130171445, u'name': u' ', u'virtual_size': u'0x00010e16'} entropy 7.95929431302 description A section with a high entropy has been found
section {u'size_of_data': u'0x00001338', u'virtual_address': u'0x00012000', u'entropy': 7.933804596482624, u'name': u' ', u'virtual_size': u'0x00002a84'} entropy 7.93380459648 description A section with a high entropy has been found
section {u'size_of_data': u'0x0051a199', u'virtual_address': u'0x00015000', u'entropy': 7.8099373163868195, u'name': u' ', u'virtual_size': u'0x006c8070'} entropy 7.80993731639 description A section with a high entropy has been found
section {u'size_of_data': u'0x00000109', u'virtual_address': u'0x006de000', u'entropy': 6.908653336684214, u'name': u' ', u'virtual_size': u'0x00000198'} entropy 6.90865333668 description A section with a high entropy has been found
section {u'size_of_data': u'0x0000016e', u'virtual_address': u'0x006e1000', u'entropy': 7.449153032247283, u'name': u' ', u'virtual_size': u'0x00000350'} entropy 7.44915303225 description A section with a high entropy has been found
section {u'size_of_data': u'0x00323e00', u'virtual_address': u'0x00c5e000', u'entropy': 7.961428504470305, u'name': u'.boot', u'virtual_size': u'0x00323e00'} entropy 7.96142850447 description A section with a high entropy has been found
entropy 0.999747539693 description Overall entropy of this PE file is high
Time & API Arguments Status Return Repeated

__anomaly__

tid: 2088
message: Encountered 65537 exceptions, quitting.
subcategory: exception
function_name:
1 0 0
Bkav W64.AIDetectMalware
Lionic Trojan.Win32.Themida.4!c
MicroWorld-eScan Gen:Variant.Cerbu.198195
Skyhigh BehavesLike.Win64.Trojan.rc
ALYac Gen:Variant.Cerbu.198195
Cylance Unsafe
VIPRE Gen:Variant.Cerbu.198195
Sangfor Trojan.Win32.Packed.Vzvp
CrowdStrike win/malicious_confidence_100% (D)
BitDefender Gen:Variant.Cerbu.198195
K7GW Trojan ( 0057a5231 )
K7AntiVirus Trojan ( 0057a5231 )
Arcabit Trojan.Cerbu.D30633
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of Win64/Packed.Themida.L suspicious
APEX Malicious
Avast Win64:Evo-gen [Trj]
Cynet Malicious (score: 99)
Kaspersky Trojan.Win32.Agent.xbtdts
Alibaba Packed:Win64/Themida.5625240d
Rising Trojan.Kryptik@AI.96 (RDML:Jp54qTjeYHQwQ0kF4CuLIw)
Emsisoft Gen:Variant.Cerbu.198195 (B)
F-Secure Heuristic.HEUR/AGEN.1376239
DrWeb Trojan.Siggen29.56198
McAfeeD ti!051BAAEBF1CF
Trapmine malicious.moderate.ml.score
CTX exe.trojan.themida
Sophos Mal/Generic-S
SentinelOne Static AI - Suspicious PE
FireEye Generic.mg.54645f818b03eea5
Webroot W32.AGent.xbtdts
Google Detected
Avira HEUR/AGEN.1376239
Antiy-AVL Trojan/Win32.Wacatac.b
Kingsoft Win32.Trojan.Agent.xbtdts
Gridinsoft Trojan.Win64.XMRig.tr
Microsoft Trojan:Win64/Reflo
ZoneAlarm UDS:Trojan.Win32.Agent.xbtdts
GData Gen:Variant.Cerbu.198195
AhnLab-V3 Trojan/Win.Generic.C5556540
McAfee Artemis!54645F818B03
DeepInstinct MALICIOUS
Malwarebytes Malware.AI.4253639514
Ikarus PUA.Themida
Panda Trj/Chgt.AD
Fortinet Riskware/Application
AVG Win64:Evo-gen [Trj]
Paloalto generic.ml
alibabacloud Trojan:Win/Packed.Themida.L