Summary | ZeroBOX

Set-up.exe

Themida Anti_VM PE32 PE File
Category Machine Started Completed
FILE s1_win7_x6403_us Nov. 8, 2024, 4:54 p.m. Nov. 8, 2024, 4:57 p.m.
Size 4.2MB
Type PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
MD5 3513dcf913ca16de1e626827dd76f329
SHA256 46a25aa38e536b2f7f2b950f00269d78ceaa2ae77e9ac3b99b1147628e18d76e
CRC32 334CBEB9
ssdeep 98304:Iem+NfZ/yB042SIoHVqNBVZ+Ct5sc8ndU/aY9bE:IeL/yweVo/Vt5R8ndrQ
Yara
  • themida_packer - themida packer
  • PE_Header_Zero - PE File Signature
  • anti_vm_detect - Possibly employs anti-virtualization techniques
  • IsPE32 - (no description)

IP Address Status Action
164.124.101.2 Active Moloch

Suricata Alerts

Flow SID Signature Category
UDP 192.168.56.103:52762 -> 8.8.8.8:53 2023883 ET DNS Query to a *.top domain - Likely Hostile Potentially Bad Traffic

Suricata TLS

No Suricata TLS

Time & API Arguments Status Return Repeated

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0
section \x00
section .rsrc
section .idata
section
section qdplkqls
section vpjvkggo
section .taggant
Time & API Arguments Status Return Repeated

__exception__

stacktrace:
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x778d9ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x778d9ea5

exception.instruction_r: fb e9 4e 01 00 00 60 8b 74 24 24 8b 7c 24 28 fc
exception.symbol: set-up+0xa240b9
exception.instruction: sti
exception.module: Set-up.exe
exception.exception_code: 0xc0000096
exception.offset: 10633401
exception.address: 0x1b740b9
registers.esp: 5570308
registers.edi: 0
registers.eax: 1
registers.ebp: 5570324
registers.edx: 30572544
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 50 c7 04 24 87 7b 5d 4e ff 34 24 ff 34 24 e9
exception.symbol: set-up+0x6a274a
exception.instruction: sti
exception.module: Set-up.exe
exception.exception_code: 0xc0000096
exception.offset: 6956874
exception.address: 0x17f274a
registers.esp: 5570276
registers.edi: 1971192040
registers.eax: 27154
registers.ebp: 4010475540
registers.edx: 18153472
registers.ebx: 25135122
registers.esi: 3
registers.ecx: 1971388416
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 57 57 e9 44 00 00 00 81 c5 07 4c 08 d5 e9 fb
exception.symbol: set-up+0x6a22e8
exception.instruction: sti
exception.module: Set-up.exe
exception.exception_code: 0xc0000096
exception.offset: 6955752
exception.address: 0x17f22e8
registers.esp: 5570276
registers.edi: 0
registers.eax: 27154
registers.ebp: 4010475540
registers.edx: 18153472
registers.ebx: 25110974
registers.esi: 3
registers.ecx: 604292944
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 81 ec 04 00 00 00 89 1c 24 bb be de 3a 2f 81
exception.symbol: set-up+0x6a3145
exception.instruction: sti
exception.module: Set-up.exe
exception.exception_code: 0xc0000096
exception.offset: 6959429
exception.address: 0x17f3145
registers.esp: 5570272
registers.edi: 25111386
registers.eax: 25767
registers.ebp: 4010475540
registers.edx: 2069475035
registers.ebx: 811366804
registers.esi: 3
registers.ecx: 1868234646
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 55 89 0c 24 c7 04 24 f2 63 ea 10 89 3c 24 50
exception.symbol: set-up+0x6a2ee6
exception.instruction: sti
exception.module: Set-up.exe
exception.exception_code: 0xc0000096
exception.offset: 6958822
exception.address: 0x17f2ee6
registers.esp: 5570276
registers.edi: 25137153
registers.eax: 25767
registers.ebp: 4010475540
registers.edx: 2069475035
registers.ebx: 811366804
registers.esi: 3
registers.ecx: 1868234646
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 68 a1 d9 74 6f 89 0c 24 53 89 34 24 68 c1 b1
exception.symbol: set-up+0x6a35bc
exception.instruction: sti
exception.module: Set-up.exe
exception.exception_code: 0xc0000096
exception.offset: 6960572
exception.address: 0x17f35bc
registers.esp: 5570276
registers.edi: 25114361
registers.eax: 25767
registers.ebp: 4010475540
registers.edx: 0
registers.ebx: 811366804
registers.esi: 3
registers.ecx: 242921
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb ba 74 d4 24 10 57 e9 f3 fb ff ff 5d c1 ea 08
exception.symbol: set-up+0x821050
exception.instruction: sti
exception.module: Set-up.exe
exception.exception_code: 0xc0000096
exception.offset: 8523856
exception.address: 0x1971050
registers.esp: 5570276
registers.edi: 25147018
registers.eax: 26700930
registers.ebp: 4010475540
registers.edx: 4294944700
registers.ebx: 406249
registers.esi: 26659305
registers.ecx: 125
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 52 51 68 d0 81 b5 6b 59 41 81 e9 56 2f b7 0c
exception.symbol: set-up+0x822e8e
exception.instruction: sti
exception.module: Set-up.exe
exception.exception_code: 0xc0000096
exception.offset: 8531598
exception.address: 0x1972e8e
registers.esp: 5570276
registers.edi: 26711998
registers.eax: 28008
registers.ebp: 4010475540
registers.edx: 2377961311
registers.ebx: 4294941764
registers.esi: 1145029544
registers.ecx: 50665
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 50 54 8b 04 24 83 c4 04 05 04 00 00 00 83 e8
exception.symbol: set-up+0x824634
exception.instruction: sti
exception.module: Set-up.exe
exception.exception_code: 0xc0000096
exception.offset: 8537652
exception.address: 0x1974634
registers.esp: 5570276
registers.edi: 8072944
registers.eax: 1259
registers.ebp: 4010475540
registers.edx: 26693615
registers.ebx: 0
registers.esi: 1145029544
registers.ecx: 1971442156
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: ed 64 8f 05 00 00 00 00 e9 be c6 ff ff 05 f2 db
exception.symbol: set-up+0x82fcf2
exception.instruction: in eax, dx
exception.module: Set-up.exe
exception.exception_code: 0xc0000096
exception.offset: 8584434
exception.address: 0x197fcf2
registers.esp: 5570268
registers.edi: 8072944
registers.eax: 1447909480
registers.ebp: 4010475540
registers.edx: 22104
registers.ebx: 1971327157
registers.esi: 26721423
registers.ecx: 20
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: 0f 3f 07 0b 64 8f 05 00 00 00 00 83 c4 04 83 fb
exception.symbol: set-up+0x82d4c3
exception.address: 0x197d4c3
exception.module: Set-up.exe
exception.exception_code: 0xc000001d
exception.offset: 8574147
registers.esp: 5570268
registers.edi: 8072944
registers.eax: 1
registers.ebp: 4010475540
registers.edx: 22104
registers.ebx: 0
registers.esi: 26721423
registers.ecx: 20
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: ed 81 fb 68 58 4d 56 75 0a c7 85 ee 36 74 12 01
exception.symbol: set-up+0x82cd21
exception.instruction: in eax, dx
exception.module: Set-up.exe
exception.exception_code: 0xc0000096
exception.offset: 8572193
exception.address: 0x197cd21
registers.esp: 5570268
registers.edi: 8072944
registers.eax: 1447909480
registers.ebp: 4010475540
registers.edx: 22104
registers.ebx: 2256917605
registers.esi: 26721423
registers.ecx: 10
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 81 ee e5 de ff 4f e9 ab 02 00 00 ff 34 24 ff
exception.symbol: set-up+0x8348dc
exception.instruction: sti
exception.module: Set-up.exe
exception.exception_code: 0xc0000096
exception.offset: 8603868
exception.address: 0x19848dc
registers.esp: 5570272
registers.edi: 8072944
registers.eax: 30062
registers.ebp: 4010475540
registers.edx: 2130566132
registers.ebx: 62516249
registers.esi: 26756878
registers.ecx: 1438777344
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 31 ff ff 34 37 e9 e6 f9 ff ff 8b 34 24 e9 34
exception.symbol: set-up+0x834fba
exception.instruction: sti
exception.module: Set-up.exe
exception.exception_code: 0xc0000096
exception.offset: 8605626
exception.address: 0x1984fba
registers.esp: 5570276
registers.edi: 8072944
registers.eax: 30062
registers.ebp: 4010475540
registers.edx: 2130566132
registers.ebx: 62516249
registers.esi: 26786940
registers.ecx: 1438777344
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 57 c7 04 24 4a aa 2b 00 89 0c 24 c7 04 24 c5
exception.symbol: set-up+0x834c89
exception.instruction: sti
exception.module: Set-up.exe
exception.exception_code: 0xc0000096
exception.offset: 8604809
exception.address: 0x1984c89
registers.esp: 5570276
registers.edi: 4294939900
registers.eax: 30062
registers.ebp: 4010475540
registers.edx: 2130566132
registers.ebx: 4141973856
registers.esi: 26786940
registers.ecx: 1438777344
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: cd 01 eb 00 f9 0f 8d 00 00 00 00 64 8f 05 00 00
exception.symbol: set-up+0x8353c1
exception.instruction: int 1
exception.module: Set-up.exe
exception.exception_code: 0xc0000005
exception.offset: 8606657
exception.address: 0x19853c1
registers.esp: 5570236
registers.edi: 0
registers.eax: 5570236
registers.ebp: 4010475540
registers.edx: 21623
registers.ebx: 26760311
registers.esi: 1029431392
registers.ecx: 26760311
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 68 12 29 44 62 89 3c 24 54 8b 3c 24 83 c4 04
exception.symbol: set-up+0x83c98b
exception.instruction: sti
exception.module: Set-up.exe
exception.exception_code: 0xc0000096
exception.offset: 8636811
exception.address: 0x198c98b
registers.esp: 5570276
registers.edi: 2939906128
registers.eax: 27384
registers.ebp: 4010475540
registers.edx: 26772388
registers.ebx: 26791702
registers.esi: 0
registers.ecx: 26772388
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb e9 29 ff ff ff 81 c2 06 23 fe 06 e9 f7 f7 ff
exception.symbol: set-up+0x845838
exception.instruction: sti
exception.module: Set-up.exe
exception.exception_code: 0xc0000096
exception.offset: 8673336
exception.address: 0x1995838
registers.esp: 5570276
registers.edi: 25101526
registers.eax: 0
registers.ebp: 4010475540
registers.edx: 604277075
registers.ebx: 26827345
registers.esi: 1971262480
registers.ecx: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 53 e9 73 01 00 00 b9 17 4b ef 7f e9 af f9 ff
exception.symbol: set-up+0x84cfbc
exception.instruction: sti
exception.module: Set-up.exe
exception.exception_code: 0xc0000096
exception.offset: 8703932
exception.address: 0x199cfbc
registers.esp: 5570268
registers.edi: 4000580802
registers.eax: 26884418
registers.ebp: 4010475540
registers.edx: 604277075
registers.ebx: 8417914
registers.esi: 1996364006
registers.ecx: 604277075
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 68 91 42 94 1b 89 0c 24 89 04 24 56 89 2c 24
exception.symbol: set-up+0x84ca41
exception.instruction: sti
exception.module: Set-up.exe
exception.exception_code: 0xc0000096
exception.offset: 8702529
exception.address: 0x199ca41
registers.esp: 5570268
registers.edi: 4000580802
registers.eax: 26858402
registers.ebp: 4010475540
registers.edx: 605849943
registers.ebx: 0
registers.esi: 1996364006
registers.ecx: 604277075
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb e9 59 00 00 00 68 8e ca 67 7b e9 20 02 00 00
exception.symbol: set-up+0x851d5d
exception.instruction: sti
exception.module: Set-up.exe
exception.exception_code: 0xc0000096
exception.offset: 8723805
exception.address: 0x19a1d5d
registers.esp: 5570264
registers.edi: 4000580802
registers.eax: 32805
registers.ebp: 4010475540
registers.edx: 2130566132
registers.ebx: 73566011
registers.esi: 26875192
registers.ecx: 1438777344
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb e9 3c f6 ff ff ff 04 24 50 e9 66 f8 ff ff 89
exception.symbol: set-up+0x851f7e
exception.instruction: sti
exception.module: Set-up.exe
exception.exception_code: 0xc0000096
exception.offset: 8724350
exception.address: 0x19a1f7e
registers.esp: 5570268
registers.edi: 4000580802
registers.eax: 32805
registers.ebp: 4010475540
registers.edx: 2130566132
registers.ebx: 73566011
registers.esi: 26907997
registers.ecx: 1438777344
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 55 bd de b6 d8 1e 51 b9 e7 3d 3e 3f 09 cd 59
exception.symbol: set-up+0x851894
exception.instruction: sti
exception.module: Set-up.exe
exception.exception_code: 0xc0000096
exception.offset: 8722580
exception.address: 0x19a1894
registers.esp: 5570268
registers.edi: 4000580802
registers.eax: 32805
registers.ebp: 4010475540
registers.edx: 2130566132
registers.ebx: 30185
registers.esi: 26907997
registers.ecx: 4294937808
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 83 ec 04 89 1c 24 e9 8d 00 00 00 01 d3 5a 50
exception.symbol: set-up+0x85ae90
exception.instruction: sti
exception.module: Set-up.exe
exception.exception_code: 0xc0000096
exception.offset: 8760976
exception.address: 0x19aae90
registers.esp: 5570268
registers.edi: 1438777344
registers.eax: 1342204512
registers.ebp: 4010475540
registers.edx: 26917085
registers.ebx: 0
registers.esi: 0
registers.ecx: 26913755
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 52 89 e2 e9 4b fe ff ff 81 c5 c9 33 7e ed 29
exception.symbol: set-up+0x86f014
exception.instruction: sti
exception.module: Set-up.exe
exception.exception_code: 0xc0000096
exception.offset: 8843284
exception.address: 0x19bf014
registers.esp: 5570232
registers.edi: 26687455
registers.eax: 29605
registers.ebp: 4010475540
registers.edx: 2130566132
registers.ebx: 25146818
registers.esi: 26988419
registers.ecx: 26995585
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 83 ec 04 89 1c 24 89 0c 24 89 e1 81 c1 04 00
exception.symbol: set-up+0x86f277
exception.instruction: sti
exception.module: Set-up.exe
exception.exception_code: 0xc0000096
exception.offset: 8843895
exception.address: 0x19bf277
registers.esp: 5570236
registers.edi: 26687455
registers.eax: 4254034
registers.ebp: 4010475540
registers.edx: 2130566132
registers.ebx: 4294940440
registers.esi: 26988419
registers.ecx: 27025190
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 81 c3 93 e1 cd 5f 52 ba 31 0e bf 5f 01 d3 5a
exception.symbol: set-up+0x86fbbd
exception.instruction: sti
exception.module: Set-up.exe
exception.exception_code: 0xc0000096
exception.offset: 8846269
exception.address: 0x19bfbbd
registers.esp: 5570232
registers.edi: 26687455
registers.eax: 29149
registers.ebp: 4010475540
registers.edx: 2130566132
registers.ebx: 26998753
registers.esi: 26988419
registers.ecx: 771117272
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 31 d2 ff 34 1a ff 34 24 8b 3c 24 83 ec 04 e9
exception.symbol: set-up+0x86fb23
exception.instruction: sti
exception.module: Set-up.exe
exception.exception_code: 0xc0000096
exception.offset: 8846115
exception.address: 0x19bfb23
registers.esp: 5570236
registers.edi: 26687455
registers.eax: 29149
registers.ebp: 4010475540
registers.edx: 2130566132
registers.ebx: 27027902
registers.esi: 26988419
registers.ecx: 771117272
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb e9 be 03 00 00 81 ef c9 0c d7 5b 81 c7 61 b6
exception.symbol: set-up+0x86fd8e
exception.instruction: sti
exception.module: Set-up.exe
exception.exception_code: 0xc0000096
exception.offset: 8846734
exception.address: 0x19bfd8e
registers.esp: 5570236
registers.edi: 1426090592
registers.eax: 29149
registers.ebp: 4010475540
registers.edx: 4294940776
registers.ebx: 27027902
registers.esi: 26988419
registers.ecx: 771117272
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb e9 00 00 00 00 68 c5 b6 08 32 89 1c 24 c7 04
exception.symbol: set-up+0x871149
exception.instruction: sti
exception.module: Set-up.exe
exception.exception_code: 0xc0000096
exception.offset: 8851785
exception.address: 0x19c1149
registers.esp: 5570236
registers.edi: 27002039
registers.eax: 33210
registers.ebp: 4010475540
registers.edx: 1677655998
registers.ebx: 14903701
registers.esi: 27035777
registers.ecx: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb e9 b8 02 00 00 c7 04 24 dc a9 5c 39 e9 d3 01
exception.symbol: set-up+0x870a1e
exception.instruction: sti
exception.module: Set-up.exe
exception.exception_code: 0xc0000096
exception.offset: 8849950
exception.address: 0x19c0a1e
registers.esp: 5570236
registers.edi: 27002039
registers.eax: 0
registers.ebp: 4010475540
registers.edx: 1677655998
registers.ebx: 14903701
registers.esi: 27005869
registers.ecx: 958307725
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 55 bd 34 6d ef 17 81 c5 77 69 d8 1e 89 eb e9
exception.symbol: set-up+0x872111
exception.instruction: sti
exception.module: Set-up.exe
exception.exception_code: 0xc0000096
exception.offset: 8855825
exception.address: 0x19c2111
registers.esp: 5570236
registers.edi: 27002039
registers.eax: 31914
registers.ebp: 4010475540
registers.edx: 1677656062
registers.ebx: 25114930
registers.esi: 27038946
registers.ecx: 1710953394
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb bb 00 10 77 2e 81 e3 b5 5d ff 3f e9 77 04 00
exception.symbol: set-up+0x871950
exception.instruction: sti
exception.module: Set-up.exe
exception.exception_code: 0xc0000096
exception.offset: 8853840
exception.address: 0x19c1950
registers.esp: 5570236
registers.edi: 27002039
registers.eax: 31914
registers.ebp: 4010475540
registers.edx: 2298801283
registers.ebx: 0
registers.esi: 27009994
registers.ecx: 1710953394
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 50 55 68 81 f3 d5 3f 5d 81 e5 4a 55 fc 34 81
exception.symbol: set-up+0x878236
exception.instruction: sti
exception.module: Set-up.exe
exception.exception_code: 0xc0000096
exception.offset: 8880694
exception.address: 0x19c8236
registers.esp: 5570236
registers.edi: 27002039
registers.eax: 0
registers.ebp: 4010475540
registers.edx: 0
registers.ebx: 65804
registers.esi: 27035410
registers.ecx: 350835799
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 81 ec 04 00 00 00 89 2c 24 89 14 24 e9 19 06
exception.symbol: set-up+0x878c7e
exception.instruction: sti
exception.module: Set-up.exe
exception.exception_code: 0xc0000096
exception.offset: 8883326
exception.address: 0x19c8c7e
registers.esp: 5570236
registers.edi: 27002039
registers.eax: 29997
registers.ebp: 4010475540
registers.edx: 27065777
registers.ebx: 65804
registers.esi: 27035410
registers.ecx: 1839862030
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 68 79 97 b5 4e 89 04 24 50 c7 04 24 cb cb fa
exception.symbol: set-up+0x879502
exception.instruction: sti
exception.module: Set-up.exe
exception.exception_code: 0xc0000096
exception.offset: 8885506
exception.address: 0x19c9502
registers.esp: 5570236
registers.edi: 0
registers.eax: 29997
registers.ebp: 4010475540
registers.edx: 27039117
registers.ebx: 65804
registers.esi: 157417
registers.ecx: 1839862030
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 50 b8 ce 16 47 3e e9 40 fd ff ff 81 eb b4 8b
exception.symbol: set-up+0x87a686
exception.instruction: sti
exception.module: Set-up.exe
exception.exception_code: 0xc0000096
exception.offset: 8889990
exception.address: 0x19ca686
registers.esp: 5570232
registers.edi: 1032329000
registers.eax: 26339
registers.ebp: 4010475540
registers.edx: 820215885
registers.ebx: 27042735
registers.esi: 27041817
registers.ecx: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 68 aa 62 ba 13 89 1c 24 e9 a6 f8 ff ff 58 51
exception.symbol: set-up+0x87abf0
exception.instruction: sti
exception.module: Set-up.exe
exception.exception_code: 0xc0000096
exception.offset: 8891376
exception.address: 0x19cabf0
registers.esp: 5570236
registers.edi: 1032329000
registers.eax: 4294943408
registers.ebp: 4010475540
registers.edx: 1659459408
registers.ebx: 27069074
registers.esi: 27041817
registers.ecx: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 81 c2 dc 8e 5c 77 e9 28 00 00 00 5c 57 bf b7
exception.symbol: set-up+0x886277
exception.instruction: sti
exception.module: Set-up.exe
exception.exception_code: 0xc0000096
exception.offset: 8938103
exception.address: 0x19d6277
registers.esp: 5570232
registers.edi: 1032329000
registers.eax: 29724
registers.ebp: 4010475540
registers.edx: 27090619
registers.ebx: 2147483650
registers.esi: 27046743
registers.ecx: 1438777344
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb e9 1c fe ff ff 31 54 24 04 5a 59 81 f1 f9 2e
exception.symbol: set-up+0x886222
exception.instruction: sti
exception.module: Set-up.exe
exception.exception_code: 0xc0000096
exception.offset: 8938018
exception.address: 0x19d6222
registers.esp: 5570236
registers.edi: 1032329000
registers.eax: 4294940252
registers.ebp: 4010475540
registers.edx: 27120343
registers.ebx: 2147483650
registers.esi: 27046743
registers.ecx: 98601296
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 31 d2 ff 34 3a e9 84 00 00 00 bf 3a b1 ec 7f
exception.symbol: set-up+0x894f7d
exception.instruction: sti
exception.module: Set-up.exe
exception.exception_code: 0xc0000096
exception.offset: 8998781
exception.address: 0x19e4f7d
registers.esp: 5570236
registers.edi: 27181613
registers.eax: 30284
registers.ebp: 4010475540
registers.edx: 2130566132
registers.ebx: 8268
registers.esi: 27339559
registers.ecx: 2157715551
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 51 89 1c 24 89 04 24 89 3c 24 e9 b4 fd ff ff
exception.symbol: set-up+0x894f62
exception.instruction: sti
exception.module: Set-up.exe
exception.exception_code: 0xc0000096
exception.offset: 8998754
exception.address: 0x19e4f62
registers.esp: 5570236
registers.edi: 27181613
registers.eax: 30284
registers.ebp: 4010475540
registers.edx: 4294939660
registers.ebx: 8268
registers.esi: 27339559
registers.ecx: 604277077
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 57 e9 3d fd ff ff 83 ec 04 89 2c 24 50 b8 a6
exception.symbol: set-up+0x89ff91
exception.instruction: sti
exception.module: Set-up.exe
exception.exception_code: 0xc0000096
exception.offset: 9043857
exception.address: 0x19eff91
registers.esp: 5570236
registers.edi: 4254039
registers.eax: 4294940476
registers.ebp: 4010475540
registers.edx: 2154056
registers.ebx: 27224740
registers.esi: 2932716
registers.ecx: 1438777344
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 29 db ff 34 0b ff 34 24 8b 3c 24 81 c4 04 00
exception.symbol: set-up+0x8a0e6c
exception.instruction: sti
exception.module: Set-up.exe
exception.exception_code: 0xc0000096
exception.offset: 9047660
exception.address: 0x19f0e6c
registers.esp: 5570236
registers.edi: 4254039
registers.eax: 31790
registers.ebp: 4010475540
registers.edx: 879935459
registers.ebx: 27224740
registers.esi: 2932716
registers.ecx: 27230153
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb e9 ed 01 00 00 81 e9 ba 69 cf 5e 81 c1 ee 2b
exception.symbol: set-up+0x8a09a3
exception.instruction: sti
exception.module: Set-up.exe
exception.exception_code: 0xc0000096
exception.offset: 9046435
exception.address: 0x19f09a3
registers.esp: 5570236
registers.edi: 605325648
registers.eax: 31790
registers.ebp: 4010475540
registers.edx: 879935459
registers.ebx: 4294938532
registers.esi: 2932716
registers.ecx: 27230153
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb e9 d3 04 00 00 be 5f 6d e7 7f 81 ea bc f5 fa
exception.symbol: set-up+0x8addde
exception.instruction: sti
exception.module: Set-up.exe
exception.exception_code: 0xc0000096
exception.offset: 9100766
exception.address: 0x19fddde
registers.esp: 5570236
registers.edi: 3128942557
registers.eax: 29954
registers.ebp: 4010475540
registers.edx: 2130566132
registers.ebx: 27283928
registers.esi: 3804478023
registers.ecx: 1438777344
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 52 89 34 24 e9 87 00 00 00 bd 29 64 22 ce e9
exception.symbol: set-up+0x8adf3a
exception.instruction: sti
exception.module: Set-up.exe
exception.exception_code: 0xc0000096
exception.offset: 9101114
exception.address: 0x19fdf3a
registers.esp: 5570236
registers.edi: 3128942557
registers.eax: 29954
registers.ebp: 4010475540
registers.edx: 2130566132
registers.ebx: 27257852
registers.esi: 11856213
registers.ecx: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 83 ec 04 89 04 24 b8 48 91 6e 7d e9 d5 03 00
exception.symbol: set-up+0x8be852
exception.instruction: sti
exception.module: Set-up.exe
exception.exception_code: 0xc0000096
exception.offset: 9168978
exception.address: 0x1a0e852
registers.esp: 5570232
registers.edi: 3489557853
registers.eax: 29860
registers.ebp: 4010475540
registers.edx: 27322358
registers.ebx: 27259250
registers.esi: 2005598220
registers.ecx: 1438777344
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 51 e9 1e f8 ff ff 89 04 24 54 58 05 04 00 00
exception.symbol: set-up+0x8beff4
exception.instruction: sti
exception.module: Set-up.exe
exception.exception_code: 0xc0000096
exception.offset: 9170932
exception.address: 0x1a0eff4
registers.esp: 5570236
registers.edi: 3489557853
registers.eax: 29860
registers.ebp: 4010475540
registers.edx: 27352218
registers.ebx: 27259250
registers.esi: 2005598220
registers.ecx: 1438777344
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb e9 a5 fd ff ff 33 14 24 e9 5a 00 00 00 81 c4
exception.symbol: set-up+0x8bf0e9
exception.instruction: sti
exception.module: Set-up.exe
exception.exception_code: 0xc0000096
exception.offset: 9171177
exception.address: 0x1a0f0e9
registers.esp: 5570236
registers.edi: 3622090344
registers.eax: 0
registers.ebp: 4010475540
registers.edx: 27325150
registers.ebx: 27259250
registers.esi: 2005598220
registers.ecx: 1438777344
1 0 0
domain home.fivjp5sr.top description Generic top level domain TLD
Time & API Arguments Status Return Repeated

NtProtectVirtualMemory

process_identifier: 840
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 8192
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x7793f000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 840
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 8192
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x778b0000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 840
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 2588672
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x01151000
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 840
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00330000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 840
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00340000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 840
region_size: 8192
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00550000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 840
region_size: 65536
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00560000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 840
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00570000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 840
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x005c0000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 840
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00610000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 840
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00620000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 840
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00570000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 840
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00570000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 840
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00570000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 840
region_size: 8192
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00570000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 840
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00630000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 840
region_size: 8192
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x006c0000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 840
region_size: 8192
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00710000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 840
region_size: 8192
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00720000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 840
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00c50000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 840
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00ca0000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 840
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00cb0000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 840
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00ec0000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 840
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x03130000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 840
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x03140000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 840
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x03150000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 840
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x03460000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 840
region_size: 8192
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00570000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 840
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00570000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 840
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00570000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 840
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00570000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 840
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00570000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 840
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00570000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 840
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00570000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 840
region_size: 8192
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00570000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 840
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00570000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 840
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00570000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 840
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00570000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 840
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00570000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 840
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00570000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 840
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00570000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 840
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00570000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0
description Set-up.exe tried to sleep 199 seconds, actually delayed analysis time by 199 seconds
Time & API Arguments Status Return Repeated

GetAdaptersAddresses

flags: 0
family: 0
1 0 0
section {u'size_of_data': u'0x00277600', u'virtual_address': u'0x00001000', u'entropy': 7.98349620008099, u'name': u' \\x00 ', u'virtual_size': u'0x0069d000'} entropy 7.98349620008 description A section with a high entropy has been found
section {u'size_of_data': u'0x001b2200', u'virtual_address': u'0x00a24000', u'entropy': 7.955467899468283, u'name': u'qdplkqls', u'virtual_size': u'0x001b3000'} entropy 7.95546789947 description A section with a high entropy has been found
entropy 0.997542422469 description Overall entropy of this PE file is high
process system
file \??\SICE
file \??\SIWVID
file \??\NTICE
Time & API Arguments Status Return Repeated

FindWindowA

class_name: OLLYDBG
window_name:
0 0

FindWindowA

class_name: GBDYLLO
window_name:
0 0

FindWindowA

class_name: pediy06
window_name:
0 0

FindWindowA

class_name: FilemonClass
window_name:
0 0

FindWindowA

class_name: FilemonClass
window_name:
0 0

FindWindowA

class_name: #0
window_name: File Monitor - Sysinternals: www.sysinternals.com
0 0

FindWindowA

class_name: PROCMON_WINDOW_CLASS
window_name:
0 0

FindWindowA

class_name: #0
window_name: Process Monitor - Sysinternals: www.sysinternals.com
0 0

FindWindowA

class_name: RegmonClass
window_name:
0 0

FindWindowA

class_name: RegmonClass
window_name:
0 0

FindWindowA

class_name: #0
window_name: Registry Monitor - Sysinternals: www.sysinternals.com
0 0

FindWindowA

class_name: 18467-41
window_name:
0 0

FindWindowA

class_name: FilemonClass
window_name:
0 0

FindWindowA

class_name: FilemonClass
window_name:
0 0

FindWindowA

class_name: #0
window_name: File Monitor - Sysinternals: www.sysinternals.com
0 0

FindWindowA

class_name: PROCMON_WINDOW_CLASS
window_name:
0 0

FindWindowA

class_name: #0
window_name: Process Monitor - Sysinternals: www.sysinternals.com
0 0

FindWindowA

class_name: OLLYDBG
window_name:
0 0

FindWindowA

class_name: GBDYLLO
window_name:
0 0

FindWindowA

class_name: pediy06
window_name:
0 0

FindWindowA

class_name: OLLYDBG
window_name:
0 0

FindWindowA

class_name: GBDYLLO
window_name:
0 0

FindWindowA

class_name: pediy06
window_name:
0 0

FindWindowA

class_name: Regmonclass
window_name:
0 0

FindWindowA

class_name: Regmonclass
window_name:
0 0

FindWindowA

class_name: 18467-41
window_name:
0 0

FindWindowA

class_name: Filemonclass
window_name:
0 0

FindWindowA

class_name: Filemonclass
window_name:
0 0

FindWindowA

class_name: PROCMON_WINDOW_CLASS
window_name:
0 0

FindWindowA

class_name: OLLYDBG
window_name:
0 0

FindWindowA

class_name: GBDYLLO
window_name:
0 0

FindWindowA

class_name: pediy06
window_name:
0 0

FindWindowA

class_name: OLLYDBG
window_name:
0 0

FindWindowA

class_name: GBDYLLO
window_name:
0 0

FindWindowA

class_name: pediy06
window_name:
0 0

FindWindowA

class_name: Regmonclass
window_name:
0 0

FindWindowA

class_name: Regmonclass
window_name:
0 0

FindWindowA

class_name: 18467-41
window_name:
0 0

FindWindowA

class_name: Filemonclass
window_name:
0 0

FindWindowA

class_name: Filemonclass
window_name:
0 0

FindWindowA

class_name: PROCMON_WINDOW_CLASS
window_name:
0 0

FindWindowA

class_name: OLLYDBG
window_name:
0 0

FindWindowA

class_name: GBDYLLO
window_name:
0 0

FindWindowA

class_name: pediy06
window_name:
0 0

FindWindowA

class_name: OLLYDBG
window_name:
0 0

FindWindowA

class_name: GBDYLLO
window_name:
0 0

FindWindowA

class_name: pediy06
window_name:
0 0

FindWindowA

class_name: Regmonclass
window_name:
0 0

FindWindowA

class_name: Regmonclass
window_name:
0 0

FindWindowA

class_name: 18467-41
window_name:
0 0
registry HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\SystemBiosVersion
registry HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\VideoBiosVersion
Time & API Arguments Status Return Repeated

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: ed 64 8f 05 00 00 00 00 e9 be c6 ff ff 05 f2 db
exception.symbol: set-up+0x82fcf2
exception.instruction: in eax, dx
exception.module: Set-up.exe
exception.exception_code: 0xc0000096
exception.offset: 8584434
exception.address: 0x197fcf2
registers.esp: 5570268
registers.edi: 8072944
registers.eax: 1447909480
registers.ebp: 4010475540
registers.edx: 22104
registers.ebx: 1971327157
registers.esi: 26721423
registers.ecx: 20
1 0 0
Bkav W32.AIDetectMalware
Lionic Virus.Generic.AI.1!c
Cynet Malicious (score: 99)
Skyhigh BehavesLike.Win32.Generic.rc
Cylance Unsafe
CrowdStrike win/malicious_confidence_90% (D)
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of Win32/Packed.Themida.HZB
APEX Malicious
Kaspersky HEUR:Trojan.Win32.Generic
Rising Trojan.Kryptik@AI.90 (RDML:Y+3lN8efFfyxmAbuKsp9eg)
F-Secure Trojan.TR/Crypt.TPM.Gen
McAfeeD Real Protect-LS!3513DCF913CA
Trapmine malicious.moderate.ml.score
Sophos Generic ML PUA (PUA)
SentinelOne Static AI - Malicious PE
FireEye Generic.mg.3513dcf913ca16de
Google Detected
Avira TR/Crypt.TPM.Gen
Kingsoft malware.kb.b.992
Gridinsoft Trojan.Heur!.03A120A1
Microsoft Trojan:Win32/Wacatac.B!ml
AhnLab-V3 Trojan/Win.Generic.C5690870
DeepInstinct MALICIOUS
Ikarus Trojan.Win32.Themida
Zoner Probably Heur.ExeHeaderL