Crash in unknown_bluewhale, Analyzed 10 dumps, total processed 5805, rate equals 0.17%



Top 1: Version = 1.6624.1180.1121, Total count = 4


dump count = 1

ChildEBP RetAddr  
00b7e524 00b7e580 KERNELBASE!RaiseException+0x62
WARNING: Frame IP not in any known module. Following frames may be wrong.
00b7e538 00b7e570 0xb7e580
00b7e53c 00b7e614 0xb7e570
00b7e570 00000000 0xb7e614
bluewhale/2025-06-10_04-05-14/dump/86fa2691ccf06001bd3abd5e239a6e3b_000.dmp

dump count = 1

03cdf624 753104e6 ws2_32!socket+0x73
03cdf7fc 75310375 wininet!WxGetLocalIpAddresses+0x82
03cdf840 75321fd1 wininet!WxGetCurrentNetworkKeys+0x55
03cdf86c 753be81c wininet!WxCompareNetworkKeysToCurrent+0x55
03cdf984 77770f0b wininet!IpAddressWpad+0x10f
03cdf9a8 777709b1 ntdll!TppTimerpExecuteCallback+0x10f
03cdfaf8 7637344d ntdll!TppWorkerThread+0x562
03cdfb04 77759802 kernel32!BaseThreadInitThunk+0xe
03cdfb44 777597d5 ntdll!__RtlUserThreadStart+0x70
03cdfb5c 00000000 ntdll!_RtlUserThreadStart+0x1b
bluewhale/2025-06-10_04-05-14/dump/29e4d99c3e892a1092a2f0bd0792dc5a_000.dmp

dump count = 1

ChildEBP RetAddr  
06a9f648 778ce0c3 ntdll!RtlpLowFragHeapFree+0x31
06a9f660 753c1918 ntdll!RtlFreeHeap+0x105
06a9f680 739577db nsi!NsiFreeTable+0x24
06a9f6a8 73957749 IPHLPAPI!AddMulticastAddresses+0x60
06a9f738 73956a89 IPHLPAPI!AllocateAndGetAdaptersAddresses+0x563
06a9f770 73a847fb IPHLPAPI!GetAdaptersAddresses+0x44
06a9f7b0 73a82d24 winhttp!LoadAdapterTables+0x47
06a9f870 73a8452e winhttp!LoadGatewayMacsByAdapter+0x75
06a9f8a0 73a82b6e winhttp!WinHttpReadGuidsForConnectedNetworks+0xe9
06a9f8c4 73a8394e winhttp!NETWORK_MANAGER::Init+0x4a
06a9f8fc 73a8467e winhttp!NETWORK_MANAGER::GetWpadInformationForConnectedNetworks+0x60
06a9f924 73a7620f winhttp!SWpadAsyncCall::OnWorkItem+0x5b
06a9f964 73a7618d winhttp!HTTP_THREAD_POOL::_WorkItemCallback+0xc1
06a9f96c 7790fa5f winhttp!HTTP_THREAD_POOL::_StaticWorkItemCallback+0x16
06a9f990 778f09b1 ntdll!TppWorkpExecuteCallback+0x10f
06a9fae0 7504343d ntdll!TppWorkerThread+0x562
06a9faec 778d9802 kernel32!BaseThreadInitThunk+0xe
06a9fb2c 778d97d5 ntdll!__RtlUserThreadStart+0x70
06a9fb44 00000000 ntdll!_RtlUserThreadStart+0x1b
bluewhale/2025-06-10_04-05-14/dump/a341533be791e0c6a6ce3ca1eda59a1e_000.dmp

dump count = 1

0017d0bf 77732d6b 0x72614d20
0017d0c3 20706565 iertutil!IsStringProperty+0x1546b
0017d0c7 352e3031 0x20706565
0017d0cb 32312820 0x352e3031
0017d0cf 2029332e 0x32312820
0017d0d3 31203e2d 0x2029332e
0017d0d7 20322e30 0x31203e2d
0017d0db 2e323128 0x20322e30
0017d0df 4d202933 0x2e323128
0017d0e3 38202c42 0x4d202933
0017d0e7 2f20372e 0x38202c42
0017d0eb 302e3020 0x2f20372e
0017d0ef 20736d20 0x302e3020
0017d0f3 76612820 0x20736d20
0017d0ff 31203d20 wintrust!_CatAdminCreatePath+0x9d
0017d10f 756d2074 0x31203d20
0017d12b 63696669 shell32!CGetVerbStateTask::InternalResumeRT+0x6b
0017d133 4347206e dbghelp!MemStream::Seek+0x61
0017d14b 0a646574 0x4347206e
0017d14f 3130335b 0xa646574
0017d153 30303a36 0x3130335b
0017d157 39443743 0x30303a36
0017d15b 205d3045 0x39443743
0017d15f 31383120 0x205d3045
0017d163 39373536 0x31383120
0017d167 3a736d20 0x39373536
0017d16b 72614d20 0x3a736d20
0017d16f 77732d6b 0x72614d20
0017d173 20706565 iertutil!IsStringProperty+0x1546b
0017d177 322e3031 0x20706565
0017d17b 32312820 0x322e3031
0017d17f 2029332e 0x32312820
0017d183 31203e2d 0x2029332e
0017d187 20322e30 0x31203e2d
0017d18b 2e323128 0x20322e30
0017d18f 4d202933 0x2e323128
0017d193 33202c42 0x4d202933
0017d197 20372e30 0x33202c42
0017d19b 2e30202f 0x20372e30
0017d19f 736d2030 0x2e30202f
0017d1a3 61282020 0x736d2030
0017d1a7 61726576 0x61282020
0017d1ab 6d206567 0x61726576
0017d1af 203d2075 0x6d206567
0017d1b3 39392e30 0x203d2075
0017d1b7 63202c39 0x39392e30
0017d1bb 65727275 0x63202c39
0017d1bf 6d20746e 0x65727275
0017d1c3 203d2075 0x6d20746e
0017d1c7 30302e30 0x203d2075
0017d1cb 6c202931 0x30302e30
0017d1cf 6d20776f 0x6c202931
0017d1d3 726f6d65 0x6d20776f
0017d1d7 6f6e2079 0x726f6d65
0017d1db 69666974 0x6f6e2079
0017d1df 69746163 0x69666974
0017d1e3 47206e6f 0x69746163
0017d1e7 6e692043 0x47206e6f
0017d1eb 646c6f20 0x6e692043
0017d1ef 61707320 0x646c6f20
0017d1f3 72206563 0x61707320
0017d1f7 65757165 0x72206563
0017d1fb 64657473 0x65757165
0017d1ff 30335b0a 0x64657473
0017d203 303a3631 0x30335b0a
0017d207 44374330 0x303a3631
0017d20b 5d304539 0x44374330
0017d20f 38312020 0x5d304539
0017d213 36323936 0x38312020
0017d217 736d2032 0x36323936
0017d21b 6353203a 0x736d2032
0017d21f 6e657661 0x6353203a
0017d223 31206567 0x6e657661
0017d227 20332e31 0x31206567
0017d22b 2e323128 0x20332e31
0017d22f 2d202933 0x2e323128
0017d233 3031203e 0x2d202933
0017d237 2820342e 0x3031203e
0017d23b 332e3231 0x2820342e
0017d23f 424d2029 0x332e3231
0017d243 3031202c 0x424d2029
0017d247 352e3738 0x3031202c
0017d24b 30202f20 0x352e3738
0017d24f 6d20312e 0x30202f20
0017d253 28202073 0x6d20312e
0017d257 72657661 0x28202073
0017d25b 20656761 0x72657661
0017d25f 3d20756d 0x20656761
0017d263 392e3020 0x3d20756d
0017d267 202c3939 0x392e3020
0017d26b 72727563 0x202c3939
0017d26f 20746e65 0x72727563
0017d273 3d20756d 0x20746e65
0017d277 302e3020 0x3d20756d
0017d27b 20293130 0x302e3020
0017d27f 6f6c6c61 0x20293130
0017d283 69746163 0x6f6c6c61
0017d287 66206e6f 0x69746163
0017d28b 756c6961 0x66206e6f
0017d28f 0a206572 shell32!`string'+0x35
0017d293 00000000 0xa206572
bluewhale/2025-06-10_04-05-14/dump/a421a3d905c5be0c561fbbc3802e371c_000.dmp


Top 2: Version = 1.6623.1065.714, Total count = 1


dump count = 1

ChildEBP RetAddr  
001992f8 00000000 KERNELBASE!RaiseException+0x62
bluewhale/2025-06-10_04-05-14/dump/79b3362d057dcd16ec69f2e182face63_000.dmp


Top 3: Version = 1.6623.1080.802, Total count = 1


dump count = 1

ChildEBP RetAddr  
001992f8 00000000 KERNELBASE!RaiseException+0x62
bluewhale/2025-06-10_04-05-14/dump/008259671f9a803849a4576e78f5f0cb_000.dmp


Top 4: Version = 1.6623.1090.907, Total count = 1


dump count = 1

ChildEBP RetAddr  
001992f8 00000000 KERNELBASE!RaiseException+0x62
bluewhale/2025-06-10_04-05-14/dump/424de82e35c0d2210a8650e82996fdfc_000.dmp


Top 5: Version = 1.6624.1135.321, Total count = 1


dump count = 1

ChildEBP RetAddr  
001992f8 00000000 KERNELBASE!RaiseException+0x62
bluewhale/2025-06-10_04-05-14/dump/a09816552dc578ef772cbe710b99b26c_000.dmp


Top 6: Version = 1.6624.1155.527, Total count = 1


dump count = 1

ChildEBP RetAddr  
001992f8 00000000 KERNELBASE!RaiseException+0x62
bluewhale/2025-06-10_04-05-14/dump/55ef805e49b1558a238cd24dc2498520_000.dmp


Top 7: Version = 1.6624.1185.1202, Total count = 1


dump count = 1

ChildEBP RetAddr  
00deef54 75d643d1 KERNELBASE!RaiseException+0x62
00deef84 00000000 bcryptPrimitives!ProcessPrng+0x51
bluewhale/2025-06-10_04-05-14/dump/36b8594b18e812ec76fc23dd69437e34_000.dmp