Summary | ZeroBOX

rundrive.exe

Themida UPX Anti_VM PE32 PE File
Category Machine Started Completed
FILE s1_win7_x6401 March 3, 2025, 6:38 p.m. March 3, 2025, 6:40 p.m.
Size 1.7MB
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 9218e5cad03c752f237ed87a9e52def4
SHA256 833610e95cc965e70096620e0adaa8917963df9f9ec56e00af1ff331161a7971
CRC32 16643A5D
ssdeep 49152:NWiPyNzLHax6WxKPQx1GyGe4/xU7VNT1xMJ1NxjnW8EtVO:NhGW4OOCbhGQK
Yara
  • themida_packer - themida packer
  • PE_Header_Zero - PE File Signature
  • anti_vm_detect - Possibly employs anti-virtualization techniques
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file

Name Response Post-Analysis Lookup
towerbingobongoboom.com 213.209.150.137
IP Address Status Action
164.124.101.2 Active Moloch
213.209.150.137 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Time & API Arguments Status Return Repeated

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0
section \x00
section .idata
section
section vonkwwrp
section axkanahc
section .taggant
Time & API Arguments Status Return Repeated

__exception__

stacktrace:
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x76f49ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x76f49ea5

exception.instruction_r: fb e9 4e 01 00 00 60 8b 74 24 24 8b 7c 24 28 fc
exception.symbol: rundrive+0x2a90b9
exception.instruction: sti
exception.module: rundrive.exe
exception.exception_code: 0xc0000096
exception.offset: 2789561
exception.address: 0x6a90b9
registers.esp: 1638276
registers.edi: 0
registers.eax: 1
registers.ebp: 1638292
registers.edx: 8728576
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 68 36 ec a6 4d ff 34 24 ff 34 24 5a 55 e9 67
exception.symbol: rundrive+0xa716
exception.instruction: sti
exception.module: rundrive.exe
exception.exception_code: 0xc0000096
exception.offset: 42774
exception.address: 0x40a716
registers.esp: 1638244
registers.edi: 236777
registers.eax: 4261686
registers.ebp: 3994255380
registers.edx: 4194304
registers.ebx: 4294943900
registers.esi: 3
registers.ecx: 1969094656
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 68 25 73 3b 66 89 2c 24 53 bb b1 1f 39 3f e9
exception.symbol: rundrive+0xb54c
exception.instruction: sti
exception.module: rundrive.exe
exception.exception_code: 0xc0000096
exception.offset: 46412
exception.address: 0x40b54c
registers.esp: 1638244
registers.edi: 1259
registers.eax: 29960
registers.ebp: 3994255380
registers.edx: 1761471702
registers.ebx: 4294940260
registers.esi: 4269527
registers.ecx: 1969094656
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 05 e7 be bf 75 05 be 6f f5 36 57 bf b8 7b fe
exception.symbol: rundrive+0x18af5e
exception.instruction: sti
exception.module: rundrive.exe
exception.exception_code: 0xc0000096
exception.offset: 1617758
exception.address: 0x58af5e
registers.esp: 1638240
registers.edi: 4274254
registers.eax: 5809051
registers.ebp: 3994255380
registers.edx: 20480
registers.ebx: 20480
registers.esi: 5808483
registers.ecx: 112334346
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 81 ec 04 00 00 00 89 0c 24 89 04 24 56 89 e6
exception.symbol: rundrive+0x18a584
exception.instruction: sti
exception.module: rundrive.exe
exception.exception_code: 0xc0000096
exception.offset: 1615236
exception.address: 0x58a584
registers.esp: 1638244
registers.edi: 4274254
registers.eax: 5837746
registers.ebp: 3994255380
registers.edx: 3860821
registers.ebx: 20480
registers.esi: 5808483
registers.ecx: 4294941868
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 57 e9 9b 07 00 00 55 bd 17 e2 ff 7f 81 c5 00
exception.symbol: rundrive+0x18fc3e
exception.instruction: sti
exception.module: rundrive.exe
exception.exception_code: 0xc0000096
exception.offset: 1637438
exception.address: 0x58fc3e
registers.esp: 1638240
registers.edi: 4274254
registers.eax: 26483
registers.ebp: 3994255380
registers.edx: 2130566132
registers.ebx: 50135805
registers.esi: 5808483
registers.ecx: 5831489
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 68 a0 94 af 7f 58 53 bb 61 0c ff 6f e9 d3 00
exception.symbol: rundrive+0x1900c1
exception.instruction: sti
exception.module: rundrive.exe
exception.exception_code: 0xc0000096
exception.offset: 1638593
exception.address: 0x5900c1
registers.esp: 1638244
registers.edi: 4274254
registers.eax: 26483
registers.ebp: 3994255380
registers.edx: 2130566132
registers.ebx: 50135805
registers.esi: 5808483
registers.ecx: 5857972
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb e9 16 05 00 00 5c 51 54 59 81 c1 04 00 00 00
exception.symbol: rundrive+0x190141
exception.instruction: sti
exception.module: rundrive.exe
exception.exception_code: 0xc0000096
exception.offset: 1638721
exception.address: 0x590141
registers.esp: 1638244
registers.edi: 50665
registers.eax: 0
registers.ebp: 3994255380
registers.edx: 2130566132
registers.ebx: 50135805
registers.esi: 5808483
registers.ecx: 5834436
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 52 89 e2 81 c2 04 00 00 00 81 ea 04 00 00 00
exception.symbol: rundrive+0x1920b8
exception.instruction: sti
exception.module: rundrive.exe
exception.exception_code: 0xc0000096
exception.offset: 1646776
exception.address: 0x5920b8
registers.esp: 1638244
registers.edi: 134889
registers.eax: 5842228
registers.ebp: 3994255380
registers.edx: 0
registers.ebx: 5836425
registers.esi: 4294952775
registers.ecx: 5837851
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: ed 64 8f 05 00 00 00 00 e9 2b 0a 00 00 8d 85 55
exception.symbol: rundrive+0x19c01e
exception.instruction: in eax, dx
exception.module: rundrive.exe
exception.exception_code: 0xc0000096
exception.offset: 1687582
exception.address: 0x59c01e
registers.esp: 1638236
registers.edi: 9973170
registers.eax: 1447909480
registers.ebp: 3994255380
registers.edx: 22104
registers.ebx: 1969033397
registers.esi: 5871746
registers.ecx: 20
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: 0f 3f 07 0b 64 8f 05 00 00 00 00 83 c4 04 83 fb
exception.symbol: rundrive+0x19b7f7
exception.address: 0x59b7f7
exception.module: rundrive.exe
exception.exception_code: 0xc000001d
exception.offset: 1685495
registers.esp: 1638236
registers.edi: 9973170
registers.eax: 1
registers.ebp: 3994255380
registers.edx: 22104
registers.ebx: 0
registers.esi: 5871746
registers.ecx: 20
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: ed 81 fb 68 58 4d 56 75 0a c7 85 47 2d 2d 12 01
exception.symbol: rundrive+0x19ee31
exception.instruction: in eax, dx
exception.module: rundrive.exe
exception.exception_code: 0xc0000096
exception.offset: 1699377
exception.address: 0x59ee31
registers.esp: 1638236
registers.edi: 9973170
registers.eax: 1447909480
registers.ebp: 3994255380
registers.edx: 22104
registers.ebx: 2256917605
registers.esi: 5871746
registers.ecx: 10
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 29 f6 ff 34 3e e9 95 03 00 00 45 81 ed 83 2b
exception.symbol: rundrive+0x1a2643
exception.instruction: sti
exception.module: rundrive.exe
exception.exception_code: 0xc0000096
exception.offset: 1713731
exception.address: 0x5a2643
registers.esp: 1638244
registers.edi: 5936996
registers.eax: 30109
registers.ebp: 3994255380
registers.edx: 2130566132
registers.ebx: 2461421
registers.esi: 10
registers.ecx: 2142568448
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 57 e9 3b 00 00 00 5e 81 ee f1 25 f5 7e e9 b1
exception.symbol: rundrive+0x1a252a
exception.instruction: sti
exception.module: rundrive.exe
exception.exception_code: 0xc0000096
exception.offset: 1713450
exception.address: 0x5a252a
registers.esp: 1638244
registers.edi: 5936996
registers.eax: 30109
registers.ebp: 3994255380
registers.edx: 2130566132
registers.ebx: 6379
registers.esi: 4294939376
registers.ecx: 2142568448
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: cd 01 eb 00 0f bf f1 b6 f3 6a 00 55 e8 03 00 00
exception.symbol: rundrive+0x1a2ec9
exception.instruction: int 1
exception.module: rundrive.exe
exception.exception_code: 0xc0000005
exception.offset: 1715913
exception.address: 0x5a2ec9
registers.esp: 1638204
registers.edi: 0
registers.eax: 1638204
registers.ebp: 3994255380
registers.edx: 730333184
registers.ebx: 5910510
registers.esi: 5936996
registers.ecx: 576325266
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 52 ba c3 6d b6 1d 42 81 ea f0 1f 27 77 e9 07
exception.symbol: rundrive+0x1b1deb
exception.instruction: sti
exception.module: rundrive.exe
exception.exception_code: 0xc0000096
exception.offset: 1777131
exception.address: 0x5b1deb
registers.esp: 1638240
registers.edi: 5970983
registers.eax: 30025
registers.ebp: 3994255380
registers.edx: 6
registers.ebx: 2461643
registers.esi: 1968968720
registers.ecx: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 52 52 e9 c0 01 00 00 5d 01 fd 5f 81 ef 89 10
exception.symbol: rundrive+0x1b1f91
exception.instruction: sti
exception.module: rundrive.exe
exception.exception_code: 0xc0000096
exception.offset: 1777553
exception.address: 0x5b1f91
registers.esp: 1638244
registers.edi: 6001008
registers.eax: 30025
registers.ebp: 3994255380
registers.edx: 6
registers.ebx: 2461643
registers.esi: 1968968720
registers.ecx: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb e9 d3 02 00 00 89 3c 24 52 ba 7e 61 e7 3c e9
exception.symbol: rundrive+0x1b23ce
exception.instruction: sti
exception.module: rundrive.exe
exception.exception_code: 0xc0000096
exception.offset: 1778638
exception.address: 0x5b23ce
registers.esp: 1638244
registers.edi: 5973908
registers.eax: 30025
registers.ebp: 3994255380
registers.edx: 6
registers.ebx: 0
registers.esi: 1968968720
registers.ecx: 262633
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb e9 00 00 00 00 31 c0 ff 34 18 ff 34 24 e9 6d
exception.symbol: rundrive+0x1b6088
exception.instruction: sti
exception.module: rundrive.exe
exception.exception_code: 0xc0000096
exception.offset: 1794184
exception.address: 0x5b6088
registers.esp: 1638236
registers.edi: 5973908
registers.eax: 29386
registers.ebp: 3994255380
registers.edx: 403334996
registers.ebx: 6015092
registers.esi: 1968968720
registers.ecx: 86294534
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb bb 42 95 6f 7b e9 19 00 00 00 46 87 ee f7 d5
exception.symbol: rundrive+0x1b5f59
exception.instruction: sti
exception.module: rundrive.exe
exception.exception_code: 0xc0000096
exception.offset: 1793881
exception.address: 0x5b5f59
registers.esp: 1638236
registers.edi: 5973908
registers.eax: 4294940868
registers.ebp: 3994255380
registers.edx: 403334996
registers.ebx: 6015092
registers.esi: 1968968720
registers.ecx: 887017
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 81 ec 04 00 00 00 89 0c 24 b9 2f da a5 75 e9
exception.symbol: rundrive+0x1b7d03
exception.instruction: sti
exception.module: rundrive.exe
exception.exception_code: 0xc0000096
exception.offset: 1801475
exception.address: 0x5b7d03
registers.esp: 1638232
registers.edi: 5993608
registers.eax: 29345
registers.ebp: 3994255380
registers.edx: 403334996
registers.ebx: 1089750272
registers.esi: 1968968720
registers.ecx: 403334996
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb bb 57 0e 3f 10 56 c7 04 24 1e 2b ff 7f 81 34
exception.symbol: rundrive+0x1b7eed
exception.instruction: sti
exception.module: rundrive.exe
exception.exception_code: 0xc0000096
exception.offset: 1801965
exception.address: 0x5b7eed
registers.esp: 1638236
registers.edi: 5996617
registers.eax: 3269602152
registers.ebp: 3994255380
registers.edx: 403334996
registers.ebx: 1089750272
registers.esi: 1968968720
registers.ecx: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb e9 79 f9 ff ff 89 d6 e9 0f fc ff ff 21 cb 8b
exception.symbol: rundrive+0x1ba734
exception.instruction: sti
exception.module: rundrive.exe
exception.exception_code: 0xc0000096
exception.offset: 1812276
exception.address: 0x5ba734
registers.esp: 1638232
registers.edi: 5996617
registers.eax: 31385
registers.ebp: 3994255380
registers.edx: 875075893
registers.ebx: 1571310081
registers.esi: 6004492
registers.ecx: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 56 c7 04 24 27 6b 1f 74 e9 00 00 00 00 89 0c
exception.symbol: rundrive+0x1baabe
exception.instruction: sti
exception.module: rundrive.exe
exception.exception_code: 0xc0000096
exception.offset: 1813182
exception.address: 0x5baabe
registers.esp: 1638236
registers.edi: 5996617
registers.eax: 31385
registers.ebp: 3994255380
registers.edx: 875075893
registers.ebx: 1571310081
registers.esi: 6035877
registers.ecx: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 55 e9 ec fe ff ff 01 c1 58 e9 8b 03 00 00 89
exception.symbol: rundrive+0x1ba07b
exception.instruction: sti
exception.module: rundrive.exe
exception.exception_code: 0xc0000096
exception.offset: 1810555
exception.address: 0x5ba07b
registers.esp: 1638236
registers.edi: 5996617
registers.eax: 2298801283
registers.ebp: 3994255380
registers.edx: 875075893
registers.ebx: 0
registers.esi: 6007797
registers.ecx: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 50 e9 8e 02 00 00 5e 33 0c 24 31 0c 24 33 0c
exception.symbol: rundrive+0x1ca7b7
exception.instruction: sti
exception.module: rundrive.exe
exception.exception_code: 0xc0000096
exception.offset: 1877943
exception.address: 0x5ca7b7
registers.esp: 1638232
registers.edi: 1756002858
registers.eax: 27205
registers.ebp: 3994255380
registers.edx: 4294942543
registers.ebx: 6060586
registers.esi: 6070587
registers.ecx: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 83 ec 04 89 34 24 89 2c 24 54 e9 49 01 00 00
exception.symbol: rundrive+0x1ca9cd
exception.instruction: sti
exception.module: rundrive.exe
exception.exception_code: 0xc0000096
exception.offset: 1878477
exception.address: 0x5ca9cd
registers.esp: 1638236
registers.edi: 1756002858
registers.eax: 27205
registers.ebp: 3994255380
registers.edx: 4294942543
registers.ebx: 6060586
registers.esi: 6097792
registers.ecx: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 68 27 60 49 20 89 34 24 68 35 51 1e 17 89 14
exception.symbol: rundrive+0x1ca19a
exception.instruction: sti
exception.module: rundrive.exe
exception.exception_code: 0xc0000096
exception.offset: 1876378
exception.address: 0x5ca19a
registers.esp: 1638236
registers.edi: 116969
registers.eax: 27205
registers.ebp: 3994255380
registers.edx: 4294942543
registers.ebx: 0
registers.esi: 6073564
registers.ecx: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb e9 00 00 00 00 50 e9 2e fa ff ff 81 ea 55 79
exception.symbol: rundrive+0x1dfc5e
exception.instruction: sti
exception.module: rundrive.exe
exception.exception_code: 0xc0000096
exception.offset: 1965150
exception.address: 0x5dfc5e
registers.esp: 1638200
registers.edi: 4792372
registers.eax: 26991
registers.ebp: 3994255380
registers.edx: 6156365
registers.ebx: 4256793
registers.esi: 208
registers.ecx: 1972907132
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 52 c7 04 24 9c 51 70 67 68 8b 31 c7 27 89 0c
exception.symbol: rundrive+0x1df744
exception.instruction: sti
exception.module: rundrive.exe
exception.exception_code: 0xc0000096
exception.offset: 1963844
exception.address: 0x5df744
registers.esp: 1638204
registers.edi: 4792372
registers.eax: 26991
registers.ebp: 3994255380
registers.edx: 6183356
registers.ebx: 4256793
registers.esi: 208
registers.ecx: 1972907132
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb e9 3a f7 ff ff 83 c4 04 81 c7 c7 b6 b4 77 59
exception.symbol: rundrive+0x1dfad4
exception.instruction: sti
exception.module: rundrive.exe
exception.exception_code: 0xc0000096
exception.offset: 1964756
exception.address: 0x5dfad4
registers.esp: 1638204
registers.edi: 4792372
registers.eax: 0
registers.ebp: 3994255380
registers.edx: 6160004
registers.ebx: 2136837517
registers.esi: 208
registers.ecx: 1972907132
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 53 c7 04 24 61 2e 2c 17 89 2c 24 e9 3c 04 00
exception.symbol: rundrive+0x1e036b
exception.instruction: sti
exception.module: rundrive.exe
exception.exception_code: 0xc0000096
exception.offset: 1966955
exception.address: 0x5e036b
registers.esp: 1638204
registers.edi: 1
registers.eax: 4294940720
registers.ebp: 3994255380
registers.edx: 2130566132
registers.ebx: 1358981728
registers.esi: 208
registers.ecx: 6190360
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 56 c7 04 24 b0 a5 8f 27 e9 29 02 00 00 59 e9
exception.symbol: rundrive+0x1e3264
exception.instruction: sti
exception.module: rundrive.exe
exception.exception_code: 0xc0000096
exception.offset: 1978980
exception.address: 0x5e3264
registers.esp: 1638204
registers.edi: 3998418455
registers.eax: 4294942572
registers.ebp: 3994255380
registers.edx: 6200596
registers.ebx: 1845561360
registers.esi: 3178007949
registers.ecx: 2145492208
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb e9 54 f9 ff ff 50 b8 da c7 79 6f 35 db 23 08
exception.symbol: rundrive+0x1e4676
exception.instruction: sti
exception.module: rundrive.exe
exception.exception_code: 0xc0000096
exception.offset: 1984118
exception.address: 0x5e4676
registers.esp: 1638204
registers.edi: 3998418455
registers.eax: 29780
registers.ebp: 3994255380
registers.edx: 6206406
registers.ebx: 1738545567
registers.esi: 6176003
registers.ecx: 1972907132
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 51 b9 88 fc d7 77 e9 59 03 00 00 31 d0 5a e9
exception.symbol: rundrive+0x1e4016
exception.instruction: sti
exception.module: rundrive.exe
exception.exception_code: 0xc0000096
exception.offset: 1982486
exception.address: 0x5e4016
registers.esp: 1638204
registers.edi: 3998418455
registers.eax: 29780
registers.ebp: 3994255380
registers.edx: 6179826
registers.ebx: 82608465
registers.esi: 0
registers.ecx: 1972907132
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 29 db ff 34 3b ff 34 24 59 51 e9 fb f9 ff ff
exception.symbol: rundrive+0x1e95ce
exception.instruction: sti
exception.module: rundrive.exe
exception.exception_code: 0xc0000096
exception.offset: 2004430
exception.address: 0x5e95ce
registers.esp: 1638204
registers.edi: 6227150
registers.eax: 30748
registers.ebp: 3994255380
registers.edx: 2130566132
registers.ebx: 6195538
registers.esi: 6195477
registers.ecx: 1972907132
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 50 89 1c 24 89 14 24 55 bd 22 ee bf 5f 55 81
exception.symbol: rundrive+0x1e9761
exception.instruction: sti
exception.module: rundrive.exe
exception.exception_code: 0xc0000096
exception.offset: 2004833
exception.address: 0x5e9761
registers.esp: 1638204
registers.edi: 6227150
registers.eax: 30748
registers.ebp: 3994255380
registers.edx: 2130566132
registers.ebx: 4294939568
registers.esi: 6195477
registers.ecx: 24811
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb e9 c4 fe ff ff 81 c3 04 00 00 00 51 b9 04 00
exception.symbol: rundrive+0x1ec17f
exception.instruction: sti
exception.module: rundrive.exe
exception.exception_code: 0xc0000096
exception.offset: 2015615
exception.address: 0x5ec17f
registers.esp: 1638200
registers.edi: 0
registers.eax: 27583
registers.ebp: 3994255380
registers.edx: 2130566132
registers.ebx: 6207464
registers.esi: 1058109779
registers.ecx: 1972907132
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 68 01 e5 61 40 89 2c 24 52 68 03 b8 a6 6f 5a
exception.symbol: rundrive+0x1ebe02
exception.instruction: sti
exception.module: rundrive.exe
exception.exception_code: 0xc0000096
exception.offset: 2014722
exception.address: 0x5ebe02
registers.esp: 1638204
registers.edi: 0
registers.eax: 27583
registers.ebp: 3994255380
registers.edx: 2130566132
registers.ebx: 6235047
registers.esi: 1058109779
registers.ecx: 1972907132
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 50 b8 ab 4e f7 7f e9 10 f8 ff ff 8d 8d 7e 46
exception.symbol: rundrive+0x1ec5b7
exception.instruction: sti
exception.module: rundrive.exe
exception.exception_code: 0xc0000096
exception.offset: 2016695
exception.address: 0x5ec5b7
registers.esp: 1638204
registers.edi: 0
registers.eax: 27583
registers.ebp: 3994255380
registers.edx: 4294943256
registers.ebx: 6235047
registers.esi: 1182698893
registers.ecx: 1972907132
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 68 fc de 91 67 89 34 24 89 04 24 51 e9 ae f6
exception.symbol: rundrive+0x1ed851
exception.instruction: sti
exception.module: rundrive.exe
exception.exception_code: 0xc0000096
exception.offset: 2021457
exception.address: 0x5ed851
registers.esp: 1638204
registers.edi: 3939837675
registers.eax: 6242623
registers.ebp: 3994255380
registers.edx: 2130566132
registers.ebx: 6211181
registers.esi: 4294940948
registers.ecx: 1972907132
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 52 57 bf 07 67 ac 7d 81 ef b6 10 bb 1f 89 fa
exception.symbol: rundrive+0x20423e
exception.instruction: sti
exception.module: rundrive.exe
exception.exception_code: 0xc0000096
exception.offset: 2114110
exception.address: 0x60423e
registers.esp: 1638200
registers.edi: 6259136
registers.eax: 32118
registers.ebp: 3994255380
registers.edx: 582600
registers.ebx: 6259104
registers.esi: 6307434
registers.ecx: 2142568448
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 68 a0 2b cf 74 89 14 24 c7 04 24 ea 0d e0 79
exception.symbol: rundrive+0x20487d
exception.instruction: sti
exception.module: rundrive.exe
exception.exception_code: 0xc0000096
exception.offset: 2115709
exception.address: 0x60487d
registers.esp: 1638204
registers.edi: 6259136
registers.eax: 4294937904
registers.ebp: 3994255380
registers.edx: 582600
registers.ebx: 2298801283
registers.esi: 6339552
registers.ecx: 2142568448
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb e9 1b 00 00 00 81 f1 f7 58 d6 74 e9 c2 fc ff
exception.symbol: rundrive+0x20abbb
exception.instruction: sti
exception.module: rundrive.exe
exception.exception_code: 0xc0000096
exception.offset: 2141115
exception.address: 0x60abbb
registers.esp: 1638204
registers.edi: 6311509
registers.eax: 29020
registers.ebp: 3994255380
registers.edx: 2130566132
registers.ebx: 1971716070
registers.esi: 6362476
registers.ecx: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 50 e9 64 f7 ff ff 81 c6 13 48 7c ba 89 f3 5e
exception.symbol: rundrive+0x20ae4d
exception.instruction: sti
exception.module: rundrive.exe
exception.exception_code: 0xc0000096
exception.offset: 2141773
exception.address: 0x60ae4d
registers.esp: 1638204
registers.edi: 6311509
registers.eax: 29020
registers.ebp: 3994255380
registers.edx: 2130566132
registers.ebx: 814189965
registers.esi: 6362476
registers.ecx: 4294941228
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 83 ec 04 89 0c 24 b9 b6 09 ff 1e e9 47 04 00
exception.symbol: rundrive+0x2108cd
exception.instruction: sti
exception.module: rundrive.exe
exception.exception_code: 0xc0000096
exception.offset: 2164941
exception.address: 0x6108cd
registers.esp: 1638204
registers.edi: 6347248
registers.eax: 32704
registers.ebp: 3994255380
registers.edx: 28305751
registers.ebx: 6391815
registers.esi: 1436
registers.ecx: 4294937912
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb e9 73 01 00 00 52 ba dc 55 eb 33 e9 3f 00 00
exception.symbol: rundrive+0x217937
exception.instruction: sti
exception.module: rundrive.exe
exception.exception_code: 0xc0000096
exception.offset: 2193719
exception.address: 0x617937
registers.esp: 1638204
registers.edi: 5835425
registers.eax: 32651
registers.ebp: 3994255380
registers.edx: 4294936576
registers.ebx: 6418834
registers.esi: 9879816
registers.ecx: 8
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb e9 1d 07 00 00 29 5c 24 04 81 6c 24 04 a1 88
exception.symbol: rundrive+0x217505
exception.instruction: sti
exception.module: rundrive.exe
exception.exception_code: 0xc0000096
exception.offset: 2192645
exception.address: 0x617505
registers.esp: 1638204
registers.edi: 0
registers.eax: 32651
registers.ebp: 3994255380
registers.edx: 4294936576
registers.ebx: 6389138
registers.esi: 604277074
registers.ecx: 8
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 81 ec 04 00 00 00 89 04 24 89 e0 05 04 00 00
exception.symbol: rundrive+0x226d2f
exception.instruction: sti
exception.module: rundrive.exe
exception.exception_code: 0xc0000096
exception.offset: 2256175
exception.address: 0x626d2f
registers.esp: 1638204
registers.edi: 5835425
registers.eax: 30714
registers.ebp: 3994255380
registers.edx: 11
registers.ebx: 6419318
registers.esi: 6478945
registers.ecx: 12
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 68 39 5c 4d 61 89 34 24 50 56 be 60 f5 d2 7d
exception.symbol: rundrive+0x226d8a
exception.instruction: sti
exception.module: rundrive.exe
exception.exception_code: 0xc0000096
exception.offset: 2256266
exception.address: 0x626d8a
registers.esp: 1638204
registers.edi: 5835425
registers.eax: 4294939820
registers.ebp: 3994255380
registers.edx: 11
registers.ebx: 4058418573
registers.esi: 6478945
registers.ecx: 12
1 0 0
Time & API Arguments Status Return Repeated

NtProtectVirtualMemory

process_identifier: 2548
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 8192
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x76faf000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2548
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 8192
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x76f20000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2548
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 8192
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00401000
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2548
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x04420000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2548
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x04430000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2548
region_size: 8192
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x04440000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2548
region_size: 65536
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x04450000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2548
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x04460000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2548
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x04470000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2548
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x04480000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2548
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x04490000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2548
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x044a0000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2548
region_size: 8192
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x04460000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2548
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x044b0000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2548
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x044c0000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2548
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x044d0000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2548
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x734c2000
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1452
region_size: 65536
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0000000004170000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffffffffffff
1 0 0
description rundrive.exe tried to sleep 600 seconds, actually delayed analysis time by 600 seconds
section {u'size_of_data': u'0x00001800', u'virtual_address': u'0x00001000', u'entropy': 7.8105425899418455, u'name': u' \\x00 ', u'virtual_size': u'0x00005000'} entropy 7.81054258994 description A section with a high entropy has been found
section {u'size_of_data': u'0x001a8e00', u'virtual_address': u'0x002a9000', u'entropy': 7.951882985850609, u'name': u'vonkwwrp', u'virtual_size': u'0x001a9000'} entropy 7.95188298585 description A section with a high entropy has been found
entropy 0.993591610836 description Overall entropy of this PE file is high
process system
file \??\SICE
file \??\SIWVID
file \??\NTICE
Time & API Arguments Status Return Repeated

FindWindowA

class_name: OLLYDBG
window_name:
0 0

FindWindowA

class_name: GBDYLLO
window_name:
0 0

FindWindowA

class_name: pediy06
window_name:
0 0

FindWindowA

class_name: FilemonClass
window_name:
0 0

FindWindowA

class_name: FilemonClass
window_name:
0 0

FindWindowA

class_name: #0
window_name: File Monitor - Sysinternals: www.sysinternals.com
0 0

FindWindowA

class_name: PROCMON_WINDOW_CLASS
window_name:
0 0

FindWindowA

class_name: #0
window_name: Process Monitor - Sysinternals: www.sysinternals.com
0 0

FindWindowA

class_name: RegmonClass
window_name:
0 0

FindWindowA

class_name: RegmonClass
window_name:
0 0

FindWindowA

class_name: #0
window_name: Registry Monitor - Sysinternals: www.sysinternals.com
0 0

FindWindowA

class_name: 18467-41
window_name:
0 0

FindWindowA

class_name: FilemonClass
window_name:
0 0

FindWindowA

class_name: FilemonClass
window_name:
0 0

FindWindowA

class_name: #0
window_name: File Monitor - Sysinternals: www.sysinternals.com
0 0

FindWindowA

class_name: PROCMON_WINDOW_CLASS
window_name:
0 0

FindWindowA

class_name: #0
window_name: Process Monitor - Sysinternals: www.sysinternals.com
0 0

FindWindowA

class_name: OLLYDBG
window_name:
0 0

FindWindowA

class_name: GBDYLLO
window_name:
0 0

FindWindowA

class_name: pediy06
window_name:
0 0

FindWindowA

class_name: OLLYDBG
window_name:
0 0

FindWindowA

class_name: GBDYLLO
window_name:
0 0

FindWindowA

class_name: pediy06
window_name:
0 0

FindWindowA

class_name: Regmonclass
window_name:
0 0

FindWindowA

class_name: Regmonclass
window_name:
0 0

FindWindowA

class_name: 18467-41
window_name:
0 0

FindWindowA

class_name: Filemonclass
window_name:
0 0

FindWindowA

class_name: Filemonclass
window_name:
0 0

FindWindowA

class_name: PROCMON_WINDOW_CLASS
window_name:
0 0

FindWindowA

class_name: OLLYDBG
window_name:
0 0

FindWindowA

class_name: GBDYLLO
window_name:
0 0

FindWindowA

class_name: pediy06
window_name:
0 0

FindWindowA

class_name: OLLYDBG
window_name:
0 0

FindWindowA

class_name: GBDYLLO
window_name:
0 0

FindWindowA

class_name: pediy06
window_name:
0 0

FindWindowA

class_name: Regmonclass
window_name:
0 0

FindWindowA

class_name: Regmonclass
window_name:
0 0

FindWindowA

class_name: 18467-41
window_name:
0 0

FindWindowA

class_name: Filemonclass
window_name:
0 0

FindWindowA

class_name: Filemonclass
window_name:
0 0

FindWindowA

class_name: PROCMON_WINDOW_CLASS
window_name:
0 0

FindWindowA

class_name: OLLYDBG
window_name:
0 0

FindWindowA

class_name: GBDYLLO
window_name:
0 0

FindWindowA

class_name: pediy06
window_name:
0 0

FindWindowA

class_name: OLLYDBG
window_name:
0 0

FindWindowA

class_name: GBDYLLO
window_name:
0 0

FindWindowA

class_name: pediy06
window_name:
0 0

FindWindowA

class_name: Regmonclass
window_name:
0 0

FindWindowA

class_name: Regmonclass
window_name:
0 0

FindWindowA

class_name: 18467-41
window_name:
0 0
registry HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\SystemBiosVersion
registry HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\VideoBiosVersion
file C:\Windows\Tasks\Test Task17.job
Time & API Arguments Status Return Repeated

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: ed 64 8f 05 00 00 00 00 e9 2b 0a 00 00 8d 85 55
exception.symbol: rundrive+0x19c01e
exception.instruction: in eax, dx
exception.module: rundrive.exe
exception.exception_code: 0xc0000096
exception.offset: 1687582
exception.address: 0x59c01e
registers.esp: 1638236
registers.edi: 9973170
registers.eax: 1447909480
registers.ebp: 3994255380
registers.edx: 22104
registers.ebx: 1969033397
registers.esi: 5871746
registers.ecx: 20
1 0 0
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Themida.i!c
Cynet Malicious (score: 100)
CAT-QuickHeal Trojan.Ghanarava.174096537052def4
Skyhigh Artemis!Trojan
ALYac Gen:Variant.Zusy.580600
Cylance Unsafe
VIPRE Gen:Variant.Zusy.580600
CrowdStrike win/malicious_confidence_100% (W)
BitDefender Gen:Variant.Zusy.580600
K7GW Trojan ( 00587f0f1 )
K7AntiVirus Trojan ( 00587f0f1 )
Arcabit Trojan.Zusy.D8DBF8
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of Win32/Packed.Themida.HZB
APEX Malicious
Avast Win32:SpywareX-gen [Trj]
Kaspersky Trojan-PSW.Win32.Stealer.cncl
Alibaba TrojanPSW:Win32/Stealer.35ef2edb
MicroWorld-eScan Gen:Variant.Zusy.580600
Rising Trojan.Agent!1.1280F (CLASSIC)
Emsisoft Gen:Variant.Zusy.580600 (B)
TrendMicro Trojan.Win32.AMADEY.YXFCBZ
McAfeeD Real Protect-LS!9218E5CAD03C
Trapmine suspicious.low.ml.score
CTX exe.trojan.stealer
Sophos Mal/Generic-S
SentinelOne Static AI - Malicious PE
FireEye Generic.mg.9218e5cad03c752f
Google Detected
Kingsoft Win32.Trojan-PSW.Stealer.cncl
Gridinsoft Malware.Win32.Gen.tr
Microsoft Trojan:Win32/Coroxy!rfn
GData Gen:Variant.Zusy.580600
Varist W32/ABTrojan.HNZR-0472
AhnLab-V3 Trojan/Win.Generic.R693419
McAfee Artemis!9218E5CAD03C
DeepInstinct MALICIOUS
Malwarebytes Trojan.MalPack.Themida.Generic
Panda Trj/Chgt.AD
TrendMicro-HouseCall Trojan.Win32.AMADEY.YXFCBZ
Tencent Win32.Trojan.FalseSign.Hajl
MaxSecure Trojan.Malware.300983.susgen
Fortinet W32/Themida.HZB!tr
AVG Win32:SpywareX-gen [Trj]
Paloalto generic.ml
alibabacloud Trojan[stealer]:Win/Stealer.cluj