File 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785.exe

Size 4.2MB
Type PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
MD5 17830e6496a4fa2d4dc73ba36ce61725
SHA1 b5bd42c48ba9fde8db5c37a9e11518f3f909eaed
SHA256 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785
SHA512
79fd3bba3b5e30f6e864cbf5c9e9385b7b0c39a724f68975875a7add0f67c3eddcfa3251ef127a2fe3f0fce80992caea858a774999184ab9f22ebfee6672ef1f
CRC32 15E00AEE
ssdeep None
Yara None matched

Score

This file is very suspicious, with a score of 10 out of 10!

Please notice: The scoring system is currently still in development and should be considered an alpha feature.


Feedback

Expecting different results? Send us this analysis and we will inspect it. Click here

Information on Execution

Analysis
Category Started Completed Duration Routing Logs
FILE Aug. 11, 2025, 11:41 a.m. Aug. 11, 2025, 11:42 a.m. 68 seconds internet Show Analyzer Log
Show Cuckoo Log

Analyzer Log

2025-08-11 10:52:06,000 [analyzer] DEBUG: Starting analyzer from: C:\tmp2zg5xi
2025-08-11 10:52:06,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\rNfgTfiEzGBbaYbmmpVx
2025-08-11 10:52:06,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\YGXnFVtnUPjxZlCRT
2025-08-11 10:52:06,296 [analyzer] DEBUG: Started auxiliary module Curtain
2025-08-11 10:52:06,296 [analyzer] DEBUG: Started auxiliary module DbgView
2025-08-11 10:52:06,640 [analyzer] DEBUG: Started auxiliary module Disguise
2025-08-11 10:52:06,828 [analyzer] DEBUG: Loaded monitor into process with pid 512
2025-08-11 10:52:06,828 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2025-08-11 10:52:06,828 [analyzer] DEBUG: Started auxiliary module Human
2025-08-11 10:52:06,828 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2025-08-11 10:52:06,828 [analyzer] DEBUG: Started auxiliary module Reboot
2025-08-11 10:52:06,953 [analyzer] DEBUG: Started auxiliary module RecentFiles
2025-08-11 10:52:06,953 [analyzer] DEBUG: Started auxiliary module Screenshots
2025-08-11 10:52:06,953 [analyzer] DEBUG: Started auxiliary module Sysmon
2025-08-11 10:52:06,953 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2025-08-11 10:52:07,171 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785.exe' with arguments '' and pid 2456
2025-08-11 10:52:07,328 [analyzer] DEBUG: Loaded monitor into process with pid 2456
2025-08-11 10:42:14,118 [analyzer] INFO: Analysis timeout hit, terminating analysis.
2025-08-11 10:42:14,338 [lib.api.process] ERROR: Failed to dump memory of 32-bit process with pid 2456.
2025-08-11 10:42:14,618 [analyzer] INFO: Terminating remaining processes before shutdown.
2025-08-11 10:42:14,618 [lib.api.process] INFO: Successfully terminated process with pid 2456.
2025-08-11 10:42:14,618 [analyzer] INFO: Analysis completed.

Cuckoo Log

2025-08-11 11:41:20,256 [cuckoo.core.scheduler] INFO: Task #6829374: acquired machine win7x6410 (label=win7x6410)
2025-08-11 11:41:20,257 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.210 for task #6829374
2025-08-11 11:41:21,113 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 1795917 (interface=vboxnet0, host=192.168.168.210)
2025-08-11 11:41:22,525 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6410
2025-08-11 11:41:23,589 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6410 to vmcloak
2025-08-11 11:41:35,330 [cuckoo.core.guest] INFO: Starting analysis #6829374 on guest (id=win7x6410, ip=192.168.168.210)
2025-08-11 11:41:36,337 [cuckoo.core.guest] DEBUG: win7x6410: not ready yet
2025-08-11 11:41:41,664 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6410, ip=192.168.168.210)
2025-08-11 11:41:42,181 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6410, ip=192.168.168.210, monitor=latest, size=6660546)
2025-08-11 11:41:44,188 [cuckoo.core.resultserver] DEBUG: Task #6829374: live log analysis.log initialized.
2025-08-11 11:41:44,709 [cuckoo.core.resultserver] DEBUG: Task #6829374 is sending a BSON stream
2025-08-11 11:41:45,195 [cuckoo.core.resultserver] DEBUG: Task #6829374 is sending a BSON stream
2025-08-11 11:41:46,000 [cuckoo.core.resultserver] DEBUG: Task #6829374: File upload for 'shots/0001.jpg'
2025-08-11 11:41:46,015 [cuckoo.core.resultserver] DEBUG: Task #6829374 uploaded file length: 135361
2025-08-11 11:41:58,646 [cuckoo.core.guest] DEBUG: win7x6410: analysis #6829374 still processing
2025-08-11 11:42:13,817 [cuckoo.core.guest] DEBUG: win7x6410: analysis #6829374 still processing
2025-08-11 11:42:14,504 [cuckoo.core.resultserver] DEBUG: Task #6829374: File upload for 'curtain/1754901734.49.curtain.log'
2025-08-11 11:42:14,508 [cuckoo.core.resultserver] DEBUG: Task #6829374 uploaded file length: 36
2025-08-11 11:42:14,615 [cuckoo.core.resultserver] DEBUG: Task #6829374: File upload for 'sysmon/1754901734.62.sysmon.xml'
2025-08-11 11:42:14,623 [cuckoo.core.resultserver] DEBUG: Task #6829374 uploaded file length: 316012
2025-08-11 11:42:14,964 [cuckoo.core.resultserver] DEBUG: Task #6829374: File upload for 'shots/0002.jpg'
2025-08-11 11:42:14,996 [cuckoo.core.resultserver] DEBUG: Task #6829374 uploaded file length: 133508
2025-08-11 11:42:15,009 [cuckoo.core.resultserver] DEBUG: Task #6829374 had connection reset for <Context for LOG>
2025-08-11 11:42:16,838 [cuckoo.core.guest] INFO: win7x6410: analysis completed successfully
2025-08-11 11:42:16,852 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2025-08-11 11:42:16,881 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2025-08-11 11:42:18,750 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6410 to path /srv/cuckoo/cwd/storage/analyses/6829374/memory.dmp
2025-08-11 11:42:18,751 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6410
2025-08-11 11:42:28,105 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.210 for task #6829374
2025-08-11 11:42:28,447 [cuckoo.core.scheduler] DEBUG: Released database task #6829374
2025-08-11 11:42:28,468 [cuckoo.core.scheduler] INFO: Task #6829374: analysis procedure completed

Signatures

Allocates read-write-execute memory (usually to unpack itself) (2 events)
Time & API Arguments Status Return Repeated

NtProtectVirtualMemory

process_identifier: 2456
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 8192
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x7778f000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2456
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 8192
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x77700000
process_handle: 0xffffffff
1 0 0
Checks if process is being debugged by a debugger (1 event)
Time & API Arguments Status Return Repeated

IsDebuggerPresent

0 0
The executable contains unknown PE section names indicative of a packer (could be a false positive) (6 events)
section \x00
section .idata
section
section wasfhoet
section ygjteyur
section .taggant
One or more processes crashed (50 out of 57 events)
Time & API Arguments Status Return Repeated

__exception__

stacktrace:
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa5 ntdll+0x39f72 @ 0x77729f72
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xd2 ntdll+0x39f45 @ 0x77729f45

exception.instruction_r: fb e9 4e 01 00 00 60 8b 74 24 24 8b 7c 24 28 fc
exception.symbol: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785+0xaa80b9
exception.instruction: sti
exception.module: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785.exe
exception.exception_code: 0xc0000096
exception.offset: 11174073
exception.address: 0x1e180b9
registers.esp: 4782776
registers.edi: 0
registers.eax: 1
registers.ebp: 4782792
registers.edx: 33345536
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb e9 70 06 00 00 52 ba 69 23 ff 5b e9 7e 06 00
exception.symbol: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785+0x72df82
exception.instruction: sti
exception.module: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785.exe
exception.exception_code: 0xc0000096
exception.offset: 7528322
exception.address: 0x1a9df82
registers.esp: 4782740
registers.edi: 1966211304
registers.eax: 32825
registers.ebp: 4017930260
registers.edx: 27909629
registers.ebx: 1233043712
registers.esi: 3
registers.ecx: 1966407680
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 57 89 34 24 e9 c9 ff ff ff bb 7d 61 7f 57 09
exception.symbol: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785+0x72e7c3
exception.instruction: sti
exception.module: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785.exe
exception.exception_code: 0xc0000096
exception.offset: 7530435
exception.address: 0x1a9e7c3
registers.esp: 4782744
registers.edi: 1966211304
registers.eax: 32825
registers.ebp: 4017930260
registers.edx: 27912886
registers.ebx: 1233043712
registers.esi: 0
registers.ecx: 3636418386
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 51 89 e1 81 c1 04 00 00 00 e9 61 03 00 00 c7
exception.symbol: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785+0x72f024
exception.instruction: sti
exception.module: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785.exe
exception.exception_code: 0xc0000096
exception.offset: 7532580
exception.address: 0x1a9f024
registers.esp: 4782744
registers.edi: 4294943672
registers.eax: 27939811
registers.ebp: 4017930260
registers.edx: 1623957858
registers.ebx: 651353268
registers.esi: 0
registers.ecx: 234729
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 68 77 06 f8 39 89 34 24 be 1d 09 be 37 c1 ee
exception.symbol: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785+0x8925dc
exception.instruction: sti
exception.module: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785.exe
exception.exception_code: 0xc0000096
exception.offset: 8988124
exception.address: 0x1c025dc
registers.esp: 4782740
registers.edi: 27949809
registers.eax: 26521
registers.ebp: 4017930260
registers.edx: 2345
registers.ebx: 29369582
registers.esi: 29369109
registers.ecx: 1705574400
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb e9 90 01 00 00 5a 81 ed 2f 0d d3 5f 4d c1 e5
exception.symbol: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785+0x89269f
exception.instruction: sti
exception.module: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785.exe
exception.exception_code: 0xc0000096
exception.offset: 8988319
exception.address: 0x1c0269f
registers.esp: 4782744
registers.edi: 27949809
registers.eax: 26521
registers.ebp: 4017930260
registers.edx: 2345
registers.ebx: 29396103
registers.esi: 29369109
registers.ecx: 1705574400
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 50 52 c7 04 24 f7 a4 76 67 58 68 a8 55 ab 70
exception.symbol: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785+0x892643
exception.instruction: sti
exception.module: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785.exe
exception.exception_code: 0xc0000096
exception.offset: 8988227
exception.address: 0x1c02643
registers.esp: 4782744
registers.edi: 27949809
registers.eax: 605325654
registers.ebp: 4017930260
registers.edx: 4294943220
registers.ebx: 29396103
registers.esi: 29369109
registers.ecx: 1705574400
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb e9 ac f6 ff ff 81 34 24 8b 88 7b 13 81 34 24
exception.symbol: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785+0x898eda
exception.instruction: sti
exception.module: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785.exe
exception.exception_code: 0xc0000096
exception.offset: 9015002
exception.address: 0x1c08eda
registers.esp: 4782740
registers.edi: 27949809
registers.eax: 31453
registers.ebp: 4017930260
registers.edx: 2130566132
registers.ebx: 29393987
registers.esi: 29369109
registers.ecx: 421
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 83 ec 04 89 04 24 c7 04 24 20 71 ef 0c 53 89
exception.symbol: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785+0x8987d6
exception.instruction: sti
exception.module: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785.exe
exception.exception_code: 0xc0000096
exception.offset: 9013206
exception.address: 0x1c087d6
registers.esp: 4782744
registers.edi: 1549541099
registers.eax: 31453
registers.ebp: 4017930260
registers.edx: 2130566132
registers.ebx: 29425440
registers.esi: 29369109
registers.ecx: 4294938888
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 81 eb 9e 9d ae 7f 81 c3 4e 60 de 7f 81 c3 f2
exception.symbol: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785+0x89e417
exception.instruction: sti
exception.module: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785.exe
exception.exception_code: 0xc0000096
exception.offset: 9036823
exception.address: 0x1c0e417
registers.esp: 4782740
registers.edi: 8466433
registers.eax: 30819
registers.ebp: 4017930260
registers.edx: 36930
registers.ebx: 29417025
registers.esi: 86919469
registers.ecx: 14288
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb e9 4f fb ff ff 49 81 f1 7c 8e 10 47 89 cf e9
exception.symbol: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785+0x89e4b0
exception.instruction: sti
exception.module: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785.exe
exception.exception_code: 0xc0000096
exception.offset: 9036976
exception.address: 0x1c0e4b0
registers.esp: 4782744
registers.edi: 8466433
registers.eax: 30819
registers.ebp: 4017930260
registers.edx: 36930
registers.ebx: 29447844
registers.esi: 86919469
registers.ecx: 14288
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb e9 19 ff ff ff 89 da e9 44 f7 ff ff 2d 61 21
exception.symbol: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785+0x89e79d
exception.instruction: sti
exception.module: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785.exe
exception.exception_code: 0xc0000096
exception.offset: 9037725
exception.address: 0x1c0e79d
registers.esp: 4782744
registers.edi: 8466433
registers.eax: 1259
registers.ebp: 4017930260
registers.edx: 36930
registers.ebx: 29419984
registers.esi: 86919469
registers.ecx: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: ed 64 8f 05 00 00 00 00 56 89 2c 24 e9 90 09 00
exception.symbol: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785+0x8a2649
exception.instruction: in eax, dx
exception.module: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785.exe
exception.exception_code: 0xc0000096
exception.offset: 9053769
exception.address: 0x1c12649
registers.esp: 4782736
registers.edi: 8466433
registers.eax: 1447909480
registers.ebp: 4017930260
registers.edx: 22104
registers.ebx: 1966346397
registers.esi: 29432159
registers.ecx: 20
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: 0f 3f 07 0b 64 8f 05 00 00 00 00 83 c4 04 83 fb
exception.symbol: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785+0x8a1caa
exception.address: 0x1c11caa
exception.module: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785.exe
exception.exception_code: 0xc000001d
exception.offset: 9051306
registers.esp: 4782736
registers.edi: 8466433
registers.eax: 1
registers.ebp: 4017930260
registers.edx: 22104
registers.ebx: 0
registers.esi: 29432159
registers.ecx: 20
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: ed 81 fb 68 58 4d 56 75 0a c7 85 44 38 2d 12 01
exception.symbol: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785+0x8a7299
exception.instruction: in eax, dx
exception.module: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785.exe
exception.exception_code: 0xc0000096
exception.offset: 9073305
exception.address: 0x1c17299
registers.esp: 4782736
registers.edi: 8466433
registers.eax: 1447909480
registers.ebp: 4017930260
registers.edx: 22104
registers.ebx: 2256917605
registers.esi: 29432159
registers.ecx: 10
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: cd 01 eb 00 6a 00 52 e8 03 00 00 00 20 5a c3 5a
exception.symbol: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785+0x8aa1dd
exception.instruction: int 1
exception.module: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785.exe
exception.exception_code: 0xc0000005
exception.offset: 9085405
exception.address: 0x1c1a1dd
registers.esp: 4782704
registers.edi: 0
registers.eax: 4782704
registers.ebp: 4017930260
registers.edx: 2147316480
registers.ebx: 29467307
registers.esi: 29467307
registers.ecx: 41587
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 68 8b 2e f5 25 89 1c 24 bb 3b bd ff 77 81 e3
exception.symbol: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785+0x8ab11c
exception.instruction: sti
exception.module: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785.exe
exception.exception_code: 0xc0000096
exception.offset: 9089308
exception.address: 0x1c1b11c
registers.esp: 4782740
registers.edi: 8466433
registers.eax: 29467978
registers.ebp: 4017930260
registers.edx: 8454144
registers.ebx: 65387343
registers.esi: 14336
registers.ecx: 167521114
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 53 51 e9 b2 08 00 00 81 04 24 81 16 ed 7d 5e
exception.symbol: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785+0x8aa73c
exception.instruction: sti
exception.module: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785.exe
exception.exception_code: 0xc0000096
exception.offset: 9086780
exception.address: 0x1c1a73c
registers.esp: 4782744
registers.edi: 8466433
registers.eax: 29496044
registers.ebp: 4017930260
registers.edx: 6379
registers.ebx: 65387343
registers.esi: 14336
registers.ecx: 4294942428
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 50 89 e0 05 04 00 00 00 83 e8 04 87 04 24 e9
exception.symbol: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785+0x8b9e69
exception.instruction: sti
exception.module: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785.exe
exception.exception_code: 0xc0000096
exception.offset: 9150057
exception.address: 0x1c29e69
registers.esp: 4782740
registers.edi: 29530622
registers.eax: 29632
registers.ebp: 4017930260
registers.edx: 6
registers.ebx: 65387565
registers.esi: 1966281744
registers.ecx: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 83 ec 04 89 3c 24 89 34 24 89 2c 24 e9 70 fe
exception.symbol: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785+0x8b9ca1
exception.instruction: sti
exception.module: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785.exe
exception.exception_code: 0xc0000096
exception.offset: 9149601
exception.address: 0x1c29ca1
registers.esp: 4782744
registers.edi: 29560254
registers.eax: 29632
registers.ebp: 4017930260
registers.edx: 6
registers.ebx: 65387565
registers.esi: 1966281744
registers.ecx: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 52 ba 0e b8 77 6f e9 ae 01 00 00 89 fa e9 54
exception.symbol: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785+0x8b9c22
exception.instruction: sti
exception.module: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785.exe
exception.exception_code: 0xc0000096
exception.offset: 9149474
exception.address: 0x1c29c22
registers.esp: 4782744
registers.edi: 29560254
registers.eax: 4294940368
registers.ebp: 4017930260
registers.edx: 565055848
registers.ebx: 65387565
registers.esi: 1966281744
registers.ecx: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 81 ec 04 00 00 00 89 14 24 e9 3c fd ff ff 89
exception.symbol: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785+0x8bb1aa
exception.instruction: sti
exception.module: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785.exe
exception.exception_code: 0xc0000096
exception.offset: 9154986
exception.address: 0x1c2b1aa
registers.esp: 4782744
registers.edi: 29560254
registers.eax: 29562692
registers.ebp: 4017930260
registers.edx: 565055848
registers.ebx: 65387565
registers.esi: 1966281744
registers.ecx: 1864239526
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 57 53 e9 00 05 00 00 51 b9 ff ff ff ff e9 07
exception.symbol: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785+0x8ba7cc
exception.instruction: sti
exception.module: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785.exe
exception.exception_code: 0xc0000096
exception.offset: 9152460
exception.address: 0x1c2a7cc
registers.esp: 4782744
registers.edi: 29560254
registers.eax: 29536900
registers.ebp: 4017930260
registers.edx: 565055848
registers.ebx: 0
registers.esi: 1179202795
registers.ecx: 1864239526
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb e9 80 f9 ff ff 29 cd 81 ed 00 c3 5f 5d 59 45
exception.symbol: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785+0x8c290d
exception.instruction: sti
exception.module: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785.exe
exception.exception_code: 0xc0000096
exception.offset: 9185549
exception.address: 0x1c3290d
registers.esp: 4782736
registers.edi: 29595150
registers.eax: 30468
registers.ebp: 4017930260
registers.edx: 565055848
registers.ebx: 556794628
registers.esi: 1208763049
registers.ecx: 594609063
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 57 68 c9 a0 2a 61 89 0c 24 c7 04 24 46 78 b6
exception.symbol: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785+0x8c2483
exception.instruction: sti
exception.module: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785.exe
exception.exception_code: 0xc0000096
exception.offset: 9184387
exception.address: 0x1c32483
registers.esp: 4782736
registers.edi: 29567618
registers.eax: 30468
registers.ebp: 4017930260
registers.edx: 0
registers.ebx: 607422802
registers.esi: 1208763049
registers.ecx: 594609063
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 50 e9 81 fe ff ff c7 04 24 42 8b 7e 67 e9 cd
exception.symbol: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785+0x8c31c9
exception.instruction: sti
exception.module: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785.exe
exception.exception_code: 0xc0000096
exception.offset: 9187785
exception.address: 0x1c331c9
registers.esp: 4782732
registers.edi: 29567618
registers.eax: 29568103
registers.ebp: 4017930260
registers.edx: 1090063660
registers.ebx: 1307907410
registers.esi: 1208763049
registers.ecx: 594609063
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 55 89 04 24 e9 3d 03 00 00 29 5c 24 04 e9 40
exception.symbol: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785+0x8c2e89
exception.instruction: sti
exception.module: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785.exe
exception.exception_code: 0xc0000096
exception.offset: 9186953
exception.address: 0x1c32e89
registers.esp: 4782736
registers.edi: 29567618
registers.eax: 29600032
registers.ebp: 4017930260
registers.edx: 1090063660
registers.ebx: 1307907410
registers.esi: 1208763049
registers.ecx: 594609063
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 68 c0 99 b5 09 e9 f2 fd ff ff 29 fa e9 ff 06
exception.symbol: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785+0x8c2fe2
exception.instruction: sti
exception.module: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785.exe
exception.exception_code: 0xc0000096
exception.offset: 9187298
exception.address: 0x1c32fe2
registers.esp: 4782736
registers.edi: 29567618
registers.eax: 29600032
registers.ebp: 4017930260
registers.edx: 4294938260
registers.ebx: 1307907410
registers.esi: 1208763049
registers.ecx: 84201
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 56 68 5a ae 87 7e ff 34 24 e9 68 f8 ff ff 01
exception.symbol: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785+0x8d3d08
exception.instruction: sti
exception.module: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785.exe
exception.exception_code: 0xc0000096
exception.offset: 9256200
exception.address: 0x1c43d08
registers.esp: 4782732
registers.edi: 29635682
registers.eax: 32892
registers.ebp: 4017930260
registers.edx: 1965639197
registers.ebx: 29631767
registers.esi: 832742815
registers.ecx: 148
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 83 ec 04 89 34 24 57 89 1c 24 57 e9 e1 f7 ff
exception.symbol: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785+0x8d3e4d
exception.instruction: sti
exception.module: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785.exe
exception.exception_code: 0xc0000096
exception.offset: 9256525
exception.address: 0x1c43e4d
registers.esp: 4782736
registers.edi: 29668574
registers.eax: 32892
registers.ebp: 4017930260
registers.edx: 1965639197
registers.ebx: 29631767
registers.esi: 832742815
registers.ecx: 148
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb e9 4a f6 ff ff 89 da 5b e9 04 01 00 00 87 04
exception.symbol: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785+0x8d3efc
exception.instruction: sti
exception.module: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785.exe
exception.exception_code: 0xc0000096
exception.offset: 9256700
exception.address: 0x1c43efc
registers.esp: 4782736
registers.edi: 29639170
registers.eax: 0
registers.ebp: 4017930260
registers.edx: 1965639197
registers.ebx: 29631767
registers.esi: 116969
registers.ecx: 148
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 51 89 04 24 e9 95 07 00 00 29 d7 e9 ef 02 00
exception.symbol: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785+0x8e8501
exception.instruction: sti
exception.module: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785.exe
exception.exception_code: 0xc0000096
exception.offset: 9340161
exception.address: 0x1c58501
registers.esp: 4782704
registers.edi: 0
registers.eax: 29961
registers.ebp: 4017930260
registers.edx: 2130566132
registers.ebx: 29724855
registers.esi: 29717426
registers.ecx: 2646409568
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 55 89 14 24 51 e9 4d 00 00 00 81 ed ac 61 ff
exception.symbol: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785+0x8ebb94
exception.instruction: sti
exception.module: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785.exe
exception.exception_code: 0xc0000096
exception.offset: 9354132
exception.address: 0x1c5bb94
registers.esp: 4782700
registers.edi: 0
registers.eax: 32411
registers.ebp: 4017930260
registers.edx: 643606720
registers.ebx: 29731176
registers.esi: 59448602
registers.ecx: 29733012
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 51 89 e1 81 c1 04 00 00 00 83 e9 04 e9 60 f6
exception.symbol: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785+0x8ebbda
exception.instruction: sti
exception.module: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785.exe
exception.exception_code: 0xc0000096
exception.offset: 9354202
exception.address: 0x1c5bbda
registers.esp: 4782704
registers.edi: 0
registers.eax: 32411
registers.ebp: 4017930260
registers.edx: 643606720
registers.ebx: 29731176
registers.esi: 59448602
registers.ecx: 29765423
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 68 01 aa d7 79 e9 f1 01 00 00 5b 01 c1 58 83
exception.symbol: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785+0x8eba73
exception.instruction: sti
exception.module: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785.exe
exception.exception_code: 0xc0000096
exception.offset: 9353843
exception.address: 0x1c5ba73
registers.esp: 4782704
registers.edi: 0
registers.eax: 0
registers.ebp: 4017930260
registers.edx: 643606720
registers.ebx: 1342204512
registers.esi: 59448602
registers.ecx: 29736255
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 53 68 9b 0f f5 7f 5b 01 d9 e9 af fc ff ff 89
exception.symbol: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785+0x8ec67c
exception.instruction: sti
exception.module: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785.exe
exception.exception_code: 0xc0000096
exception.offset: 9356924
exception.address: 0x1c5c67c
registers.esp: 4782700
registers.edi: 29737030
registers.eax: 31637
registers.ebp: 4017930260
registers.edx: 1151410703
registers.ebx: 1342204512
registers.esi: 29736286
registers.ecx: 29737471
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 51 89 e1 81 c1 04 00 00 00 e9 db 01 00 00 81
exception.symbol: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785+0x8ec90e
exception.instruction: sti
exception.module: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785.exe
exception.exception_code: 0xc0000096
exception.offset: 9357582
exception.address: 0x1c5c90e
registers.esp: 4782704
registers.edi: 29737030
registers.eax: 31637
registers.ebp: 4017930260
registers.edx: 1151410703
registers.ebx: 1342204512
registers.esi: 29736286
registers.ecx: 29769108
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 52 89 e2 51 e9 8b fa ff ff b8 00 da a7 5a 09
exception.symbol: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785+0x8ec92c
exception.instruction: sti
exception.module: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785.exe
exception.exception_code: 0xc0000096
exception.offset: 9357612
exception.address: 0x1c5c92c
registers.esp: 4782704
registers.edi: 972856717
registers.eax: 0
registers.ebp: 4017930260
registers.edx: 1151410703
registers.ebx: 1342204512
registers.esi: 29736286
registers.ecx: 29740144
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 53 bb a2 fc af 64 e9 f4 fd ff ff 89 34 24 89
exception.symbol: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785+0x8f3cea
exception.instruction: sti
exception.module: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785.exe
exception.exception_code: 0xc0000096
exception.offset: 9387242
exception.address: 0x1c63cea
registers.esp: 4782700
registers.edi: 972856717
registers.eax: 25081
registers.ebp: 4017930260
registers.edx: 0
registers.ebx: 12293
registers.esi: 29767430
registers.ecx: 29765701
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 81 ec 04 00 00 00 89 14 24 57 81 ec 04 00 00
exception.symbol: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785+0x8f37fa
exception.instruction: sti
exception.module: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785.exe
exception.exception_code: 0xc0000096
exception.offset: 9385978
exception.address: 0x1c637fa
registers.esp: 4782704
registers.edi: 972856717
registers.eax: 24811
registers.ebp: 4017930260
registers.edx: 0
registers.ebx: 12293
registers.esi: 29792511
registers.ecx: 4294944516
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 68 18 a0 ce 38 89 14 24 ba db c1 f7 75 50 e9
exception.symbol: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785+0x8f630b
exception.instruction: sti
exception.module: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785.exe
exception.exception_code: 0xc0000096
exception.offset: 9397003
exception.address: 0x1c6630b
registers.esp: 4782704
registers.edi: 972856717
registers.eax: 30556
registers.ebp: 4017930260
registers.edx: 0
registers.ebx: 29780251
registers.esi: 29792511
registers.ecx: 82153
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb e9 83 f7 ff ff 5d 87 3c 24 83 c7 ff 87 3c 24
exception.symbol: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785+0x8f7760
exception.instruction: sti
exception.module: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785.exe
exception.exception_code: 0xc0000096
exception.offset: 9402208
exception.address: 0x1c67760
registers.esp: 4782704
registers.edi: 29807518
registers.eax: 3939837675
registers.ebp: 4017930260
registers.edx: 466023873
registers.ebx: 29780251
registers.esi: 29792511
registers.ecx: 4294944376
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 56 89 e6 e9 56 02 00 00 f7 d5 68 02 05 6b 7d
exception.symbol: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785+0x8f8512
exception.instruction: sti
exception.module: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785.exe
exception.exception_code: 0xc0000096
exception.offset: 9405714
exception.address: 0x1c68512
registers.esp: 4782704
registers.edi: 29814092
registers.eax: 28871
registers.ebp: 4017930260
registers.edx: 29785526
registers.ebx: 1931950080
registers.esi: 29814939
registers.ecx: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 50 c7 04 24 09 cd ff 75 e9 49 00 00 00 87 0c
exception.symbol: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785+0x8f8874
exception.instruction: sti
exception.module: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785.exe
exception.exception_code: 0xc0000096
exception.offset: 9406580
exception.address: 0x1c68874
registers.esp: 4782704
registers.edi: 0
registers.eax: 28871
registers.ebp: 4017930260
registers.edx: 29785526
registers.ebx: 81129
registers.esi: 29789187
registers.ecx: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb e9 5a f8 ff ff 5f 8f 04 24 8b 24 24 89 3c 24
exception.symbol: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785+0x90c3c9
exception.instruction: sti
exception.module: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785.exe
exception.exception_code: 0xc0000096
exception.offset: 9487305
exception.address: 0x1c7c3c9
registers.esp: 4782700
registers.edi: 29819815
registers.eax: 29866778
registers.ebp: 4017930260
registers.edx: 2130566132
registers.ebx: 1964638182
registers.esi: 29799241
registers.ecx: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 29 d2 ff 34 02 ff 34 24 8b 34 24 81 c4 04 00
exception.symbol: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785+0x90bce2
exception.instruction: sti
exception.module: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785.exe
exception.exception_code: 0xc0000096
exception.offset: 9485538
exception.address: 0x1c7bce2
registers.esp: 4782704
registers.edi: 29819815
registers.eax: 29894049
registers.ebp: 4017930260
registers.edx: 2130566132
registers.ebx: 1964638182
registers.esi: 29799241
registers.ecx: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 68 e5 89 c0 2c 89 3c 24 e9 2c fd ff ff b9 01
exception.symbol: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785+0x90c2fb
exception.instruction: sti
exception.module: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785.exe
exception.exception_code: 0xc0000096
exception.offset: 9487099
exception.address: 0x1c7c2fb
registers.esp: 4782704
registers.edi: 29819815
registers.eax: 29894049
registers.ebp: 4017930260
registers.edx: 4294942648
registers.ebx: 1964638182
registers.esi: 402713192
registers.ecx: 0
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 50 b8 46 47 68 7f e9 4f f9 ff ff be 63 ea e7
exception.symbol: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785+0x90cebc
exception.instruction: sti
exception.module: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785.exe
exception.exception_code: 0xc0000096
exception.offset: 9490108
exception.address: 0x1c7cebc
registers.esp: 4782700
registers.edi: 29819815
registers.eax: 30661
registers.ebp: 4017930260
registers.edx: 727664257
registers.ebx: 1964638182
registers.esi: 29869765
registers.ecx: 233646284
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb 56 e9 d8 01 00 00 68 21 2e 4d 40 e9 d7 f9 ff
exception.symbol: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785+0x90cd01
exception.instruction: sti
exception.module: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785.exe
exception.exception_code: 0xc0000096
exception.offset: 9489665
exception.address: 0x1c7cd01
registers.esp: 4782704
registers.edi: 29819815
registers.eax: 30661
registers.ebp: 4017930260
registers.edx: 68703080
registers.ebx: 1964638182
registers.esi: 29900426
registers.ecx: 4294939260
1 0 0

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: fb e9 a2 01 00 00 01 d0 8b 14 24 83 c4 04 05 61
exception.symbol: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785+0x91d834
exception.instruction: sti
exception.module: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785.exe
exception.exception_code: 0xc0000096
exception.offset: 9558068
exception.address: 0x1c8d834
registers.esp: 4782704
registers.edi: 29916699
registers.eax: 29967152
registers.ebp: 4017930260
registers.edx: 2613112
registers.ebx: 29892434
registers.esi: 29892430
registers.ecx: 1705574400
1 0 0
A process attempted to delay the analysis task. (1 event)
description 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785.exe tried to sleep 224 seconds, actually delayed analysis time by 224 seconds
The binary likely contains encrypted or compressed data indicative of a packer (3 events)
section {u'size_of_data': u'0x00283400', u'virtual_address': u'0x00001000', u'entropy': 7.989232402371349, u'name': u' \\x00 ', u'virtual_size': u'0x00729000'} entropy 7.98923240237 description A section with a high entropy has been found
section {u'size_of_data': u'0x001b3600', u'virtual_address': u'0x00aa8000', u'entropy': 7.954660871223599, u'name': u'wasfhoet', u'virtual_size': u'0x001b4000'} entropy 7.95466087122 description A section with a high entropy has been found
entropy 0.997456941394 description Overall entropy of this PE file is high
Expresses interest in specific running processes (1 event)
process system
Checks for the presence of known devices from debuggers and forensic tools (3 events)
file \??\SICE
file \??\SIWVID
file \??\NTICE
Checks for the presence of known windows from debuggers and forensic tools (12 events)
Time & API Arguments Status Return Repeated

FindWindowA

class_name: OLLYDBG
window_name:
0 0

FindWindowA

class_name: GBDYLLO
window_name:
0 0

FindWindowA

class_name: pediy06
window_name:
0 0

FindWindowA

class_name: FilemonClass
window_name:
0 0

FindWindowA

class_name: FilemonClass
window_name:
0 0

FindWindowA

class_name: #0
window_name: File Monitor - Sysinternals: www.sysinternals.com
0 0

FindWindowA

class_name: PROCMON_WINDOW_CLASS
window_name:
0 0

FindWindowA

class_name: #0
window_name: Process Monitor - Sysinternals: www.sysinternals.com
0 0

FindWindowA

class_name: RegmonClass
window_name:
0 0

FindWindowA

class_name: RegmonClass
window_name:
0 0

FindWindowA

class_name: #0
window_name: Registry Monitor - Sysinternals: www.sysinternals.com
0 0

FindWindowA

class_name: 18467-41
window_name:
0 0
Checks the version of Bios, possibly for anti-virtualization (2 events)
registry HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\SystemBiosVersion
registry HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\VideoBiosVersion
Detects VMWare through the in instruction feature (1 event)
Time & API Arguments Status Return Repeated

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: ed 64 8f 05 00 00 00 00 56 89 2c 24 e9 90 09 00
exception.symbol: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785+0x8a2649
exception.instruction: in eax, dx
exception.module: 6ee8b2cf092df2b52451c4b328d93d7abcb48f5ebc7dc3a5ab328ea633bd1785.exe
exception.exception_code: 0xc0000096
exception.offset: 9053769
exception.address: 0x1c12649
registers.esp: 4782736
registers.edi: 8466433
registers.eax: 1447909480
registers.ebp: 4017930260
registers.edx: 22104
registers.ebx: 1966346397
registers.esi: 29432159
registers.ecx: 20
1 0 0
File has been identified by 12 AntiVirus engine on IRMA as malicious (12 events)
G Data Antivirus (Windows) Virus: Gen:Variant.Zusy.568294 (Engine A)
Avast Core Security (Linux) Win32:Evo-gen [Trj]
C4S ClamAV (Linux) Win.Packed.Zusy-10040002-0
WithSecure (Linux) Trojan.TR/Crypt.TPM.Gen
eScan Antivirus (Linux) Gen:Variant.Zusy.568294(DB)
ESET Security (Windows) a variant of Win32/Packed.Themida.HZB trojan
Sophos Anti-Virus (Linux) Mal/Generic-S
DrWeb Antivirus (Linux) Trojan.PWS.Amadey.227
ClamAV (Linux) Win.Packed.Zusy-10040002-0
Bitdefender Antivirus (Linux) Gen:Variant.Zusy.568294
Kaspersky Standard (Windows) HEUR:Trojan-Spy.MSIL.Generic
Emsisoft Commandline Scanner (Windows) Gen:Variant.Zusy.568294 (B)
File has been identified by 62 AntiVirus engines on VirusTotal as malicious (50 out of 62 events)
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Themida.l!c
Cynet Malicious (score: 99)
CAT-QuickHeal Trojan.Ghanarava.1734884564e61725
Skyhigh BehavesLike.Win32.Generic.rc
ALYac Gen:Variant.Zusy.568294
Cylance Unsafe
VIPRE Gen:Variant.Zusy.568294
Sangfor Spyware.Win32.Themida.V0fs
CrowdStrike win/malicious_confidence_100% (W)
BitDefender Gen:Variant.Zusy.568294
K7GW Trojan ( 00587f0f1 )
K7AntiVirus Trojan ( 00587f0f1 )
Arcabit Trojan.Zusy.D8ABE6
VirIT Trojan.Win32.Genus.XLS
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of Win32/Packed.Themida.HZB
APEX Malicious
Avast Win32:Evo-gen [Trj]
ClamAV Win.Packed.Zusy-10040002-0
Kaspersky Trojan-Spy.MSIL.Phpw.bhs
Alibaba TrojanSpy:MSIL/Themida.58def23f
NANO-Antivirus Trojan.Win32.Phpw.kudzfv
MicroWorld-eScan Gen:Variant.Zusy.568294
Rising Trojan.Agent!1.126F4 (CLASSIC)
Emsisoft Gen:Variant.Zusy.568294 (B)
F-Secure Trojan.TR/Crypt.TPM.Gen
DrWeb Trojan.PWS.Amadey.227
Zillya Trojan.Themida.Win32.125511
TrendMicro TROJ_GEN.R002C0DDG25
McAfeeD Real Protect-LS!17830E6496A4
Trapmine malicious.high.ml.score
CTX exe.trojan.themida
Sophos Mal/Generic-S
SentinelOne Static AI - Malicious PE
Google Detected
Avira TR/Crypt.TPM.Gen
Antiy-AVL Trojan[Packed]/Win32.Themida
Kingsoft Win32.HeurC.KVMH008.a
Gridinsoft Trojan.Heur!.038120A1
Xcitium Malware@#likbmv8vig3z
Microsoft Trojan:Win32/StealC.BN!MTB
GData Gen:Variant.Zusy.568294
Varist W32/ABTrojan.GQCW-8531
AhnLab-V3 Trojan/Win.Generic.C5700273
VBA32 TScope.Malware-Cryptor.SB
DeepInstinct MALICIOUS
Malwarebytes Trojan.MalPack
Ikarus Trojan.Win32.LummaStealer
Screenshots
Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action VT Location
No hosts contacted.
Cuckoo

We're processing your submission... This could take a few seconds.