Report - 0beU0RimJUAeIPysjPIQLhgYSowUv3.exe

Gen2 Gen1
ScreenShot
Created 2021.04.22 17:15 Machine s1_win7_x6401
Filename 0beU0RimJUAeIPysjPIQLhgYSowUv3.exe
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
AI Score
6
Behavior Score
1.4
ZERO API file : malware
VT API (file) 52 detected (AIDetect, malware1, malicious, high confidence, Mint, Zamg, Qshell, PinkSbot, Unsafe, Save, confidence, 100%, Kryptik, Eldorado, HIUI, ihrzye, Hacktool, Krap, lKMc, Malware@#2zq7bfdl0l3sh, Chanitor, 0NA103AD21, Static AI, Malicious PE, ZDlder, akxqr, KVMH008, kcloud, Hancitor, score, ZedlaF, IG8@am315Oni, Wacatac, Gencirc, 9fP8wkYFOl0, ai score=85, susgen, GenKryptik, EZVZ, HygBEpsA)
md5 80a193b93598109aea05d7a9008358bb
sha256 0941090d3eb785dbf88fbfafffad34c4ab42877b279129616a455347883e5738
ssdeep 12288:/dVY7kNHvbyVfbWWbyHjaSabybbybvkbleb:/k7kNHvbyVfbWWbyHjaSabybbybvkbl2
imphash 20d61189831e10f6d3b3ce368e9cd764
impfuzzy 384:WzmLS4PlnuKN+SXv9Z6oyqElKSpFIWAw+JcGpN:FL7luKN+SVZ6vqE5IN
  Network IP location

Signature (2cnts)

Level Description
danger File has been identified by 52 AntiVirus engines on VirusTotal as malicious
info The executable contains unknown PE section names indicative of a packer (could be a false positive)

Rules (15cnts)

Level Name Description Collection
danger Win32_Trojan_Gen_1_0904B0_Zero Win32 Trojan Emotet binaries (upload)
info IsDLL (no description) binaries (upload)
info IsPE32 (no description) binaries (upload)
info OS_Processor_Check_Zero OS Processor Check Signature Zero binaries (upload)
info PE_Header_Zero PE File Signature Zero binaries (upload)
info inject_thread Code injection with CreateRemoteThread in a remote process binaries (upload)
info IsWindowsGUI (no description) binaries (upload)
info keylogger Run a keylogger binaries (upload)
info screenshot Take screenshot binaries (upload)
info Win32_Trojan_Gen_2_0904B0_Zero Win32 Trojan Gen binaries (upload)
info win_files_operation Affect private profile binaries (upload)
info win_mutex Create or check mutex binaries (upload)
info win_private_profile Affect private profile binaries (upload)
info win_registry Affect system registries binaries (upload)
info win_token Affect system token binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids

PE API

IAT(Import Address Table) Library

KERNEL32.dll
 0x1005f370 MapViewOfFile
 0x1005f374 CreateFileMappingA
 0x1005f378 GetVolumeInformationW
 0x1005f37c GetFullPathNameW
 0x1005f380 MoveFileW
 0x1005f384 SetErrorMode
 0x1005f388 GetFileSizeEx
 0x1005f38c GetFileAttributesW
 0x1005f390 GetDriveTypeA
 0x1005f394 GetLogicalDriveStringsA
 0x1005f398 CreateDirectoryW
 0x1005f39c IsDBCSLeadByte
 0x1005f3a0 LocalLock
 0x1005f3a4 LocalUnlock
 0x1005f3a8 LocalAlloc
 0x1005f3ac FlushFileBuffers
 0x1005f3b0 GetTempPathA
 0x1005f3b4 GetTimeFormatW
 0x1005f3b8 GetDateFormatW
 0x1005f3bc GetLocalTime
 0x1005f3c0 IsBadWritePtr
 0x1005f3c4 IsBadReadPtr
 0x1005f3c8 lstrcatA
 0x1005f3cc TerminateProcess
 0x1005f3d0 GetDateFormatA
 0x1005f3d4 GetShortPathNameW
 0x1005f3d8 GetCurrentProcess
 0x1005f3dc IsBadStringPtrA
 0x1005f3e0 WriteProcessMemory
 0x1005f3e4 SetUnhandledExceptionFilter
 0x1005f3e8 SetProcessWorkingSetSize
 0x1005f3ec SetFileTime
 0x1005f3f0 CompareStringA
 0x1005f3f4 InterlockedExchange
 0x1005f3f8 GetModuleHandleW
 0x1005f3fc lstrcmpA
 0x1005f400 LoadLibraryExA
 0x1005f404 GetSystemDefaultUILanguage
 0x1005f408 ConvertDefaultLocale
 0x1005f40c GetUserDefaultUILanguage
 0x1005f410 GetCurrentThread
 0x1005f414 ExpandEnvironmentStringsW
 0x1005f418 GetLongPathNameA
 0x1005f41c EnumResourceLanguagesA
 0x1005f420 GetFileAttributesExA
 0x1005f424 LoadLibraryW
 0x1005f428 GetSystemDirectoryW
 0x1005f42c lstrcmpiA
 0x1005f430 SystemTimeToFileTime
 0x1005f434 CompareFileTime
 0x1005f438 DuplicateHandle
 0x1005f43c GlobalMemoryStatus
 0x1005f440 GetDiskFreeSpaceA
 0x1005f444 VirtualFree
 0x1005f448 VirtualAlloc
 0x1005f44c HeapFree
 0x1005f450 GetProcessHeap
 0x1005f454 HeapAlloc
 0x1005f458 GlobalMemoryStatusEx
 0x1005f45c GetCPInfoExA
 0x1005f460 QueryPerformanceCounter
 0x1005f464 QueryPerformanceFrequency
 0x1005f468 GetThreadTimes
 0x1005f46c lstrcmpW
 0x1005f470 GlobalFindAtomA
 0x1005f474 CreateActCtxW
 0x1005f478 ReleaseActCtx
 0x1005f47c SuspendThread
 0x1005f480 VirtualProtect
 0x1005f484 GetAtomNameA
 0x1005f488 GetStringTypeExA
 0x1005f48c GetThreadLocale
 0x1005f490 LockFile
 0x1005f494 UnlockFile
 0x1005f498 LocalFileTimeToFileTime
 0x1005f49c RaiseException
 0x1005f4a0 GlobalFlags
 0x1005f4a4 GetUserDefaultLCID
 0x1005f4a8 ReplaceFileA
 0x1005f4ac SearchPathA
 0x1005f4b0 TlsGetValue
 0x1005f4b4 GlobalHandle
 0x1005f4b8 TlsAlloc
 0x1005f4bc TlsSetValue
 0x1005f4c0 LocalReAlloc
 0x1005f4c4 TlsFree
 0x1005f4c8 FindResourceExW
 0x1005f4cc GetNumberFormatA
 0x1005f4d0 RtlUnwind
 0x1005f4d4 DecodePointer
 0x1005f4d8 EncodePointer
 0x1005f4dc GetSystemTimeAsFileTime
 0x1005f4e0 PeekNamedPipe
 0x1005f4e4 GetFileType
 0x1005f4e8 GetDriveTypeW
 0x1005f4ec FindFirstFileExW
 0x1005f4f0 FindFirstFileExA
 0x1005f4f4 HeapReAlloc
 0x1005f4f8 GetSystemInfo
 0x1005f4fc VirtualQuery
 0x1005f500 HeapSize
 0x1005f504 GetCommandLineA
 0x1005f508 HeapSetInformation
 0x1005f50c GetStartupInfoW
 0x1005f510 SetStdHandle
 0x1005f514 HeapQueryInformation
 0x1005f518 IsProcessorFeaturePresent
 0x1005f51c UnhandledExceptionFilter
 0x1005f520 IsDebuggerPresent
 0x1005f524 GetStdHandle
 0x1005f528 GetLocaleInfoW
 0x1005f52c IsValidCodePage
 0x1005f530 HeapCreate
 0x1005f534 HeapDestroy
 0x1005f538 GetStringTypeW
 0x1005f53c LCMapStringW
 0x1005f540 GetTimeZoneInformation
 0x1005f544 SetHandleCount
 0x1005f548 GetConsoleCP
 0x1005f54c GetConsoleMode
 0x1005f550 FatalAppExitA
 0x1005f554 IsValidLocale
 0x1005f558 SetConsoleCtrlHandler
 0x1005f55c CompareStringW
 0x1005f560 FreeEnvironmentStringsW
 0x1005f564 GetEnvironmentStringsW
 0x1005f568 UnmapViewOfFile
 0x1005f56c GlobalGetAtomNameW
 0x1005f570 InitializeCriticalSection
 0x1005f574 CreatePipe
 0x1005f578 ExitThread
 0x1005f57c SetEndOfFile
 0x1005f580 SetFilePointer
 0x1005f584 GetDiskFreeSpaceExA
 0x1005f588 _lclose
 0x1005f58c GetFileSize
 0x1005f590 DeleteFileW
 0x1005f594 OpenFile
 0x1005f598 LocalSize
 0x1005f59c GetOEMCP
 0x1005f5a0 IsDBCSLeadByteEx
 0x1005f5a4 FindNextFileW
 0x1005f5a8 CreateSemaphoreA
 0x1005f5ac LocalFree
 0x1005f5b0 RemoveDirectoryA
 0x1005f5b4 GetVersion
 0x1005f5b8 GetFileAttributesA
 0x1005f5bc GetExitCodeProcess
 0x1005f5c0 CreateThread
 0x1005f5c4 SetThreadPriority
 0x1005f5c8 GetModuleFileNameW
 0x1005f5cc GlobalAddAtomW
 0x1005f5d0 SystemTimeToTzSpecificLocalTime
 0x1005f5d4 GetShortPathNameA
 0x1005f5d8 GetComputerNameA
 0x1005f5dc ExpandEnvironmentStringsA
 0x1005f5e0 GetTempFileNameA
 0x1005f5e4 CreateProcessA
 0x1005f5e8 GetPrivateProfileSectionA
 0x1005f5ec CopyFileA
 0x1005f5f0 GetProfileStringA
 0x1005f5f4 GetProfileIntA
 0x1005f5f8 GetCommandLineW
 0x1005f5fc EnumSystemCodePagesW
 0x1005f600 GetCPInfoExW
 0x1005f604 WritePrivateProfileSectionA
 0x1005f608 GetFullPathNameA
 0x1005f60c lstrcpynA
 0x1005f610 GetVolumeInformationA
 0x1005f614 lstrcpyA
 0x1005f618 GlobalDeleteAtom
 0x1005f61c GlobalAddAtomA
 0x1005f620 FindResourceA
 0x1005f624 FreeResource
 0x1005f628 GetCPInfo
 0x1005f62c GetFileInformationByHandle
 0x1005f630 CreateFileW
 0x1005f634 SetCurrentDirectoryW
 0x1005f638 GetCurrentDirectoryW
 0x1005f63c GetVersionExA
 0x1005f640 SetEnvironmentVariableA
 0x1005f644 FindFirstFileW
 0x1005f648 GetCurrentProcessId
 0x1005f64c InterlockedDecrement
 0x1005f650 InterlockedIncrement
 0x1005f654 FileTimeToLocalFileTime
 0x1005f658 FileTimeToSystemTime
 0x1005f65c FindFirstFileA
 0x1005f660 FindNextFileA
 0x1005f664 FindClose
 0x1005f668 SetFileAttributesA
 0x1005f66c GetWindowsDirectoryA
 0x1005f670 GetSystemTime
 0x1005f674 ExitProcess
 0x1005f678 EnumSystemCodePagesA
 0x1005f67c EnumSystemLocalesA
 0x1005f680 GetCurrentThreadId
 0x1005f684 SetEvent
 0x1005f688 Sleep
 0x1005f68c GetTickCount
 0x1005f690 ResetEvent
 0x1005f694 CreateEventA
 0x1005f698 GlobalReAlloc
 0x1005f69c WaitForMultipleObjects
 0x1005f6a0 lstrlenW
 0x1005f6a4 TerminateThread
 0x1005f6a8 ReleaseMutex
 0x1005f6ac InitializeCriticalSectionAndSpinCount
 0x1005f6b0 ResumeThread
 0x1005f6b4 WaitForSingleObject
 0x1005f6b8 GetACP
 0x1005f6bc GlobalSize
 0x1005f6c0 GlobalAlloc
 0x1005f6c4 ActivateActCtx
 0x1005f6c8 DeactivateActCtx
 0x1005f6cc GetModuleHandleA
 0x1005f6d0 GetEnvironmentVariableA
 0x1005f6d4 ReadFile
 0x1005f6d8 WriteFile
 0x1005f6dc CreateFileA
 0x1005f6e0 GetFileTime
 0x1005f6e4 GetLocaleInfoA
 0x1005f6e8 SetLastError
 0x1005f6ec FreeLibrary
 0x1005f6f0 GetModuleFileNameA
 0x1005f6f4 CreateDirectoryA
 0x1005f6f8 DeleteFileA
 0x1005f6fc GetCurrentDirectoryA
 0x1005f700 LeaveCriticalSection
 0x1005f704 EnterCriticalSection
 0x1005f708 DeleteCriticalSection
 0x1005f70c MultiByteToWideChar
 0x1005f710 MulDiv
 0x1005f714 GetPrivateProfileStringA
 0x1005f718 lstrlenA
 0x1005f71c WritePrivateProfileStringA
 0x1005f720 GetPrivateProfileIntA
 0x1005f724 GlobalLock
 0x1005f728 GlobalUnlock
 0x1005f72c SetCurrentDirectoryA
 0x1005f730 GetLastError
 0x1005f734 GetSystemDirectoryA
 0x1005f738 LoadLibraryA
 0x1005f73c GetProcAddress
 0x1005f740 FormatMessageA
 0x1005f744 WideCharToMultiByte
 0x1005f748 FindResourceW
 0x1005f74c LoadResource
 0x1005f750 LockResource
 0x1005f754 SizeofResource
 0x1005f758 GlobalFree
 0x1005f75c CloseHandle
 0x1005f760 CreateMutexA
 0x1005f764 InterlockedCompareExchange
 0x1005f768 MoveFileA
 0x1005f76c ReleaseSemaphore
 0x1005f770 WriteConsoleW
 0x1005f774 GlobalGetAtomNameA
 0x1005f778 GetStringTypeExW
 0x1005f77c LCMapStringA
 0x1005f780 VerifyVersionInfoA
 0x1005f784 VerSetConditionMask
 0x1005f788 SleepEx
 0x1005f78c FlushConsoleInputBuffer
 0x1005f790 GetProcessTimes
 0x1005f794 GetSystemTimeAdjustment
 0x1005f798 GetWindowsDirectoryW
 0x1005f79c GetEnvironmentVariableW
 0x1005f7a0 GetVersionExW
 0x1005f7a4 FlushInstructionCache
 0x1005f7a8 SetThreadContext
 0x1005f7ac GetThreadContext
 0x1005f7b0 ReadConsoleInputA
 0x1005f7b4 SetConsoleMode
 0x1005f7b8 PeekConsoleInputA
 0x1005f7bc GetNumberOfConsoleInputEvents
 0x1005f7c0 GetTimeFormatA
 0x1005f7c4 WritePrivateProfileStructA
 0x1005f7c8 GetBinaryTypeA
 0x1005f7cc DisableThreadLibraryCalls
 0x1005f7d0 FreeUserPhysicalPages
 0x1005f7d4 GetStringTypeA
 0x1005f7d8 CreateHardLinkW
 0x1005f7dc EnumUILanguagesW
 0x1005f7e0 OutputDebugStringW
 0x1005f7e4 CopyFileW
 0x1005f7e8 GetPrivateProfileStructA
 0x1005f7ec FindNextVolumeMountPointA
 0x1005f7f0 CreateDirectoryExA
 0x1005f7f4 GetPrivateProfileStringW
 0x1005f7f8 CancelDeviceWakeupRequest
 0x1005f7fc BeginUpdateResourceA
 0x1005f800 _hread
 0x1005f804 GetCommState
 0x1005f808 GetConsoleScreenBufferInfo
 0x1005f80c GetSystemWindowsDirectoryW
 0x1005f810 EnumResourceTypesA
 0x1005f814 EnumSystemLocalesW
 0x1005f818 CreateMutexW
 0x1005f81c SetDefaultCommConfigA
 0x1005f820 GlobalUnfix
 0x1005f824 GetCurrencyFormatW
 0x1005f828 CreateFileMappingW
 0x1005f82c GetConsoleFontSize
 0x1005f830 GetOverlappedResult
 0x1005f834 VirtualAllocEx
USER32.dll
 0x1005f83c GetMenuBarInfo
 0x1005f840 ReuseDDElParam
 0x1005f844 UnpackDDElParam
 0x1005f848 DefFrameProcA
 0x1005f84c DefMDIChildProcA
 0x1005f850 TranslateMDISysAccel
 0x1005f854 MsgWaitForMultipleObjectsEx
 0x1005f858 GetNextDlgGroupItem
 0x1005f85c DrawIconEx
 0x1005f860 CopyImage
 0x1005f864 GetIconInfo
 0x1005f868 MonitorFromPoint
 0x1005f86c RealChildWindowFromPoint
 0x1005f870 LoadAcceleratorsW
 0x1005f874 ShowOwnedPopups
 0x1005f878 NotifyWinEvent
 0x1005f87c CopyIcon
 0x1005f880 IsClipboardFormatAvailable
 0x1005f884 SetWindowContextHelpId
 0x1005f888 UpdateLayeredWindow
 0x1005f88c EnumDisplayMonitors
 0x1005f890 SetLayeredWindowAttributes
 0x1005f894 InSendMessage
 0x1005f898 CopyAcceleratorTableA
 0x1005f89c InvalidateRgn
 0x1005f8a0 LoadImageW
 0x1005f8a4 ToAsciiEx
 0x1005f8a8 CreateAcceleratorTableA
 0x1005f8ac SubtractRect
 0x1005f8b0 GetWindowRgn
 0x1005f8b4 GetDCEx
 0x1005f8b8 CharUpperBuffA
 0x1005f8bc SendNotifyMessageA
 0x1005f8c0 MapVirtualKeyExA
 0x1005f8c4 InvertRect
 0x1005f8c8 SetPropA
 0x1005f8cc GetPropA
 0x1005f8d0 GetClassInfoExA
 0x1005f8d4 RegisterClassExA
 0x1005f8d8 GetComboBoxInfo
 0x1005f8dc SetDlgItemTextA
 0x1005f8e0 MessageBeep
 0x1005f8e4 EnumClipboardFormats
 0x1005f8e8 CreateMenu
 0x1005f8ec SetWindowTextW
 0x1005f8f0 GetDlgItemTextA
 0x1005f8f4 GetSystemMenu
 0x1005f8f8 FindWindowExA
 0x1005f8fc TrackPopupMenuEx
 0x1005f900 MessageBoxW
 0x1005f904 LoadIconA
 0x1005f908 DrawTextW
 0x1005f90c GetTabbedTextExtentW
 0x1005f910 GetScrollPos
 0x1005f914 ShowScrollBar
 0x1005f918 EnableScrollBar
 0x1005f91c SetWindowRgn
 0x1005f920 WindowFromDC
 0x1005f924 GetAsyncKeyState
 0x1005f928 LoadMenuW
 0x1005f92c CreateWindowExW
 0x1005f930 PostQuitMessage
 0x1005f934 TrackPopupMenu
 0x1005f938 GetMenuStringA
 0x1005f93c SetKeyboardState
 0x1005f940 CheckMenuItem
 0x1005f944 SetWindowTextA
 0x1005f948 DestroyAcceleratorTable
 0x1005f94c ModifyMenuW
 0x1005f950 AppendMenuW
 0x1005f954 GetMenuStringW
 0x1005f958 WinHelpA
 0x1005f95c GetAncestor
 0x1005f960 CallWindowProcA
 0x1005f964 MapVirtualKeyA
 0x1005f968 keybd_event
 0x1005f96c SetMenu
 0x1005f970 AdjustWindowRectEx
 0x1005f974 SystemParametersInfoA
 0x1005f978 GetKeyboardState
 0x1005f97c ToAscii
 0x1005f980 GetTopWindow
 0x1005f984 ChildWindowFromPointEx
 0x1005f988 IsZoomed
 0x1005f98c DrawMenuBar
 0x1005f990 SetMenuDefaultItem
 0x1005f994 SendMessageW
 0x1005f998 DrawStateA
 0x1005f99c FlashWindowEx
 0x1005f9a0 CharUpperW
 0x1005f9a4 CharLowerW
 0x1005f9a8 IsCharLowerW
 0x1005f9ac IsCharUpperW
 0x1005f9b0 CharUpperA
 0x1005f9b4 CharLowerA
 0x1005f9b8 IsCharLowerA
 0x1005f9bc IsCharUpperA
 0x1005f9c0 RemoveMenu
 0x1005f9c4 GetMenuItemID
 0x1005f9c8 IsCharAlphaW
 0x1005f9cc IsCharAlphaNumericW
 0x1005f9d0 IsCharAlphaA
 0x1005f9d4 IsCharAlphaNumericA
 0x1005f9d8 OemToCharBuffA
 0x1005f9dc DefWindowProcW
 0x1005f9e0 GetUpdateRect
 0x1005f9e4 BeginPaint
 0x1005f9e8 EndPaint
 0x1005f9ec GetKeyboardLayout
 0x1005f9f0 GetCursor
 0x1005f9f4 GetClipboardData
 0x1005f9f8 GetTabbedTextExtentA
 0x1005f9fc CharToOemBuffA
 0x1005fa00 GetScrollInfo
 0x1005fa04 GetScrollRange
 0x1005fa08 SetScrollPos
 0x1005fa0c ScrollWindow
 0x1005fa10 GetClassLongA
 0x1005fa14 SetCaretPos
 0x1005fa18 CreateCaret
 0x1005fa1c ShowCaret
 0x1005fa20 FrameRect
 0x1005fa24 DestroyCaret
 0x1005fa28 HideCaret
 0x1005fa2c GrayStringA
 0x1005fa30 LoadCursorA
 0x1005fa34 CharNextA
 0x1005fa38 SetClassLongA
 0x1005fa3c SetWindowLongW
 0x1005fa40 GetWindowLongW
 0x1005fa44 SetWindowsHookExA
 0x1005fa48 RegisterClassA
 0x1005fa4c UnregisterClassA
 0x1005fa50 FindWindowA
 0x1005fa54 RegisterClipboardFormatA
 0x1005fa58 TileWindows
 0x1005fa5c GetDoubleClickTime
 0x1005fa60 ShowWindow
 0x1005fa64 InsertMenuItemA
 0x1005fa68 DispatchMessageW
 0x1005fa6c GetMessageW
 0x1005fa70 GetForegroundWindow
 0x1005fa74 SetClipboardData
 0x1005fa78 GetActiveWindow
 0x1005fa7c UnhookWindowsHookEx
 0x1005fa80 SetForegroundWindow
 0x1005fa84 SetActiveWindow
 0x1005fa88 LockWindowUpdate
 0x1005fa8c ModifyMenuA
 0x1005fa90 GetMenuItemCount
 0x1005fa94 EnableMenuItem
 0x1005fa98 DeleteMenu
 0x1005fa9c GetWindowThreadProcessId
 0x1005faa0 CallNextHookEx
 0x1005faa4 IsRectEmpty
 0x1005faa8 OffsetRect
 0x1005faac BeginDeferWindowPos
 0x1005fab0 EndDeferWindowPos
 0x1005fab4 IsIconic
 0x1005fab8 DrawIcon
 0x1005fabc GetDlgCtrlID
 0x1005fac0 GetSysColorBrush
 0x1005fac4 IntersectRect
 0x1005fac8 SetRect
 0x1005facc SetRectEmpty
 0x1005fad0 IsWindowEnabled
 0x1005fad4 RegisterWindowMessageA
 0x1005fad8 DestroyIcon
 0x1005fadc LoadImageA
 0x1005fae0 GetSystemMetrics
 0x1005fae4 DestroyMenu
 0x1005fae8 SetMenuInfo
 0x1005faec GetSubMenu
 0x1005faf0 DefWindowProcA
 0x1005faf4 ValidateRect
 0x1005faf8 SetCursorPos
 0x1005fafc ReleaseCapture
 0x1005fb00 DrawFrameControl
 0x1005fb04 FillRect
 0x1005fb08 DestroyCursor
 0x1005fb0c SetCursor
 0x1005fb10 ShowCursor
 0x1005fb14 LoadCursorW
 0x1005fb18 SetCapture
 0x1005fb1c GetCapture
 0x1005fb20 KillTimer
 0x1005fb24 SetTimer
 0x1005fb28 BringWindowToTop
 0x1005fb2c MessageBoxA
 0x1005fb30 GetMessageA
 0x1005fb34 SetScrollRange
 0x1005fb38 SetScrollInfo
 0x1005fb3c PostThreadMessageA
 0x1005fb40 ScreenToClient
 0x1005fb44 GetMenu
 0x1005fb48 GetWindow
 0x1005fb4c SetWindowPos
 0x1005fb50 EmptyClipboard
 0x1005fb54 CloseClipboard
 0x1005fb58 DrawTextExA
 0x1005fb5c SetFocus
 0x1005fb60 IsWindowUnicode
 0x1005fb64 DestroyWindow
 0x1005fb68 DrawTextA
 0x1005fb6c OpenClipboard
 0x1005fb70 GetDesktopWindow
 0x1005fb74 PostMessageA
 0x1005fb78 InsertMenuA
 0x1005fb7c LoadBitmapW
 0x1005fb80 InflateRect
 0x1005fb84 GetWindowLongA
 0x1005fb88 GetCursorPos
 0x1005fb8c WindowFromPoint
 0x1005fb90 IsWindowVisible
 0x1005fb94 InvalidateRect
 0x1005fb98 ClientToScreen
 0x1005fb9c AppendMenuA
 0x1005fba0 CreatePopupMenu
 0x1005fba4 EqualRect
 0x1005fba8 PtInRect
 0x1005fbac GetDlgItem
 0x1005fbb0 UpdateWindow
 0x1005fbb4 PeekMessageA
 0x1005fbb8 TranslateMessage
 0x1005fbbc DispatchMessageA
 0x1005fbc0 WaitMessage
 0x1005fbc4 LoadIconW
 0x1005fbc8 IsChild
 0x1005fbcc GetFocus
 0x1005fbd0 GetSysColor
 0x1005fbd4 MapDialogRect
 0x1005fbd8 GetDialogBaseUnits
 0x1005fbdc GetClientRect
 0x1005fbe0 CreateWindowExA
 0x1005fbe4 SetWindowLongA
 0x1005fbe8 GetWindowRect
 0x1005fbec MoveWindow
 0x1005fbf0 SetParent
 0x1005fbf4 RedrawWindow
 0x1005fbf8 ReleaseDC
 0x1005fbfc GetDC
 0x1005fc00 DrawFocusRect
 0x1005fc04 TabbedTextOutA
 0x1005fc08 CreateDialogIndirectParamA
 0x1005fc0c EndDialog
 0x1005fc10 ScrollWindowEx
 0x1005fc14 IsDlgButtonChecked
 0x1005fc18 SetDlgItemInt
 0x1005fc1c GetDlgItemInt
 0x1005fc20 CheckRadioButton
 0x1005fc24 CheckDlgButton
 0x1005fc28 SetMenuItemBitmaps
 0x1005fc2c GetMenuCheckMarkDimensions
 0x1005fc30 SendDlgItemMessageA
 0x1005fc34 GetWindowTextLengthA
 0x1005fc38 GetLastActivePopup
 0x1005fc3c GetMessageTime
 0x1005fc40 GetMonitorInfoA
 0x1005fc44 SetWindowPlacement
 0x1005fc48 GetWindowPlacement
 0x1005fc4c GetKeyNameTextA
 0x1005fc50 SetPropW
 0x1005fc54 RemovePropW
 0x1005fc58 GetPropW
 0x1005fc5c CharLowerBuffW
 0x1005fc60 CharLowerBuffA
 0x1005fc64 RemovePropA
 0x1005fc68 AttachThreadInput
 0x1005fc6c TrackMouseEvent
 0x1005fc70 CopyRect
 0x1005fc74 GetParent
 0x1005fc78 IsWindow
 0x1005fc7c GetClassNameA
 0x1005fc80 wsprintfA
 0x1005fc84 GetKeyState
 0x1005fc88 SendMessageA
 0x1005fc8c EnableWindow
 0x1005fc90 CheckMenuRadioItem
 0x1005fc94 EnumChildWindows
 0x1005fc98 LoadAcceleratorsA
 0x1005fc9c TranslateAcceleratorA
 0x1005fca0 LoadStringA
 0x1005fca4 LoadStringW
 0x1005fca8 GetUserObjectInformationW
 0x1005fcac GetClassNameW
 0x1005fcb0 LoadMenuIndirectA
 0x1005fcb4 GetNextDlgTabItem
 0x1005fcb8 GetClassInfoW
 0x1005fcbc RegisterClassW
 0x1005fcc0 GetMenuDefaultItem
 0x1005fcc4 IsMenu
 0x1005fcc8 GetMenuInfo
 0x1005fccc IsDialogMessageA
 0x1005fcd0 UnionRect
 0x1005fcd4 GetMessagePos
 0x1005fcd8 GetMenuState
 0x1005fcdc GetMenuItemInfoA
 0x1005fce0 GetWindowTextA
 0x1005fce4 GetWindowDC
 0x1005fce8 MonitorFromWindow
 0x1005fcec MapWindowPoints
 0x1005fcf0 DrawEdge
 0x1005fcf4 DeferWindowPos
 0x1005fcf8 GetClassInfoA
 0x1005fcfc GetCaretPos
 0x1005fd00 LoadBitmapA
 0x1005fd04 GetProcessWindowStation
 0x1005fd08 GetClipboardOwner
 0x1005fd0c GetQueueStatus
 0x1005fd10 LoadMenuA
 0x1005fd14 CallWindowProcW
 0x1005fd18 GetTitleBarInfo
 0x1005fd1c EditWndProc
 0x1005fd20 OemKeyScan
 0x1005fd24 SwitchDesktop
 0x1005fd28 DdeCreateStringHandleA
 0x1005fd2c OemToCharA
 0x1005fd30 AdjustWindowRect
 0x1005fd34 DialogBoxIndirectParamA
 0x1005fd38 UnloadKeyboardLayout
 0x1005fd3c WaitForInputIdle
 0x1005fd40 VkKeyScanExW
 0x1005fd44 GetMouseMovePointsEx
 0x1005fd48 OpenDesktopW
 0x1005fd4c GetMenuItemInfoW
 0x1005fd50 GetGUIThreadInfo
 0x1005fd54 SendMessageTimeoutW
 0x1005fd58 GetWindowModuleFileNameW
 0x1005fd5c SetDlgItemTextW
 0x1005fd60 GetInputState
 0x1005fd64 OpenIcon
 0x1005fd68 GetKBCodePage
 0x1005fd6c CloseWindowStation
 0x1005fd70 LoadCursorFromFileW
GDI32.dll
 0x1005fd78 DeleteDC
 0x1005fd7c CreateRectRgn
 0x1005fd80 Polyline
 0x1005fd84 Rectangle
 0x1005fd88 TextOutA
 0x1005fd8c ExtTextOutA
 0x1005fd90 SelectClipRgn
 0x1005fd94 LineTo
 0x1005fd98 MoveToEx
 0x1005fd9c ExtTextOutW
 0x1005fda0 GetCharWidthA
 0x1005fda4 GetClipBox
 0x1005fda8 SetLayout
 0x1005fdac GetLayout
 0x1005fdb0 CreateRectRgnIndirect
 0x1005fdb4 CombineRgn
 0x1005fdb8 PatBlt
 0x1005fdbc EnumFontFamiliesExA
 0x1005fdc0 DPtoLP
 0x1005fdc4 ExtCreateRegion
 0x1005fdc8 CreateDIBSection
 0x1005fdcc CreateDCA
 0x1005fdd0 StretchBlt
 0x1005fdd4 GetNearestColor
 0x1005fdd8 SetPixel
 0x1005fddc CreateBrushIndirect
 0x1005fde0 CreateBitmap
 0x1005fde4 GetCharacterPlacementW
 0x1005fde8 ExtCreatePen
 0x1005fdec GetViewportExtEx
 0x1005fdf0 GetWindowExtEx
 0x1005fdf4 StartDocA
 0x1005fdf8 PtVisible
 0x1005fdfc RectVisible
 0x1005fe00 Escape
 0x1005fe04 SetViewportOrgEx
 0x1005fe08 OffsetViewportOrgEx
 0x1005fe0c SetViewportExtEx
 0x1005fe10 ScaleViewportExtEx
 0x1005fe14 OffsetWindowOrgEx
 0x1005fe18 SetWindowExtEx
 0x1005fe1c ScaleWindowExtEx
 0x1005fe20 CreatePenIndirect
 0x1005fe24 UnrealizeObject
 0x1005fe28 ArcTo
 0x1005fe2c PolyDraw
 0x1005fe30 PolylineTo
 0x1005fe34 PolyBezierTo
 0x1005fe38 ExtSelectClipRgn
 0x1005fe3c GetCharWidth32W
 0x1005fe40 SelectPalette
 0x1005fe44 PlayMetaFileRecord
 0x1005fe48 GetObjectType
 0x1005fe4c EnumMetaFile
 0x1005fe50 PlayMetaFile
 0x1005fe54 CreateHatchBrush
 0x1005fe58 SetRectRgn
 0x1005fe5c GetMapMode
 0x1005fe60 CreateDIBitmap
 0x1005fe64 EnumFontFamiliesA
 0x1005fe68 CreateEllipticRgn
 0x1005fe6c Ellipse
 0x1005fe70 GetViewportOrgEx
 0x1005fe74 StartPage
 0x1005fe78 EndPage
 0x1005fe7c SetAbortProc
 0x1005fe80 AbortDoc
 0x1005fe84 EndDoc
 0x1005fe88 LPtoDP
 0x1005fe8c CreateFontA
 0x1005fe90 StretchDIBits
 0x1005fe94 GetRgnBox
 0x1005fe98 SetDIBColorTable
 0x1005fe9c GetDIBits
 0x1005fea0 RealizePalette
 0x1005fea4 CreatePalette
 0x1005fea8 GetPaletteEntries
 0x1005feac OffsetRgn
 0x1005feb0 PtInRegion
 0x1005feb4 FrameRgn
 0x1005feb8 GetBoundsRect
 0x1005febc GetPolyFillMode
 0x1005fec0 GetROP2
 0x1005fec4 GetStretchBltMode
 0x1005fec8 GetTextAlign
 0x1005fecc GetTextFaceA
 0x1005fed0 GetWindowOrgEx
 0x1005fed4 CreateMetaFileA
 0x1005fed8 CloseMetaFile
 0x1005fedc DeleteMetaFile
 0x1005fee0 GetNearestPaletteIndex
 0x1005fee4 GetSystemPaletteEntries
 0x1005fee8 ExtFloodFill
 0x1005feec SetPaletteEntries
 0x1005fef0 SetPixelV
 0x1005fef4 GetTextCharsetInfo
 0x1005fef8 ExcludeClipRect
 0x1005fefc GetClipRgn
 0x1005ff00 FillRgn
 0x1005ff04 GetTextExtentPoint32W
 0x1005ff08 SelectClipPath
 0x1005ff0c SetColorAdjustment
 0x1005ff10 CreateDIBPatternBrushPt
 0x1005ff14 SetArcDirection
 0x1005ff18 CreateRoundRectRgn
 0x1005ff1c CreatePolygonRgn
 0x1005ff20 Polygon
 0x1005ff24 SetBrushOrgEx
 0x1005ff28 GetTextExtentPointA
 0x1005ff2c CreatePen
 0x1005ff30 GetCharWidth32A
 0x1005ff34 GetFontLanguageInfo
 0x1005ff38 GetCharacterPlacementA
 0x1005ff3c BitBlt
 0x1005ff40 CreateCompatibleDC
 0x1005ff44 CreateCompatibleBitmap
 0x1005ff48 GetPixel
 0x1005ff4c GetBkMode
 0x1005ff50 SetBkMode
 0x1005ff54 CreateSolidBrush
 0x1005ff58 SelectObject
 0x1005ff5c DeleteObject
 0x1005ff60 GetCurrentObject
 0x1005ff64 RoundRect
 0x1005ff68 SetTextColor
 0x1005ff6c SetBkColor
 0x1005ff70 GetStockObject
 0x1005ff74 SetMapperFlags
 0x1005ff78 SetTextCharacterExtra
 0x1005ff7c SetTextJustification
 0x1005ff80 SetTextAlign
 0x1005ff84 OffsetClipRgn
 0x1005ff88 SetMapMode
 0x1005ff8c ModifyWorldTransform
 0x1005ff90 SetWorldTransform
 0x1005ff94 SetGraphicsMode
 0x1005ff98 SetStretchBltMode
 0x1005ff9c SetROP2
 0x1005ffa0 SetPolyFillMode
 0x1005ffa4 RestoreDC
 0x1005ffa8 SaveDC
 0x1005ffac CopyMetaFileA
 0x1005ffb0 IntersectClipRect
 0x1005ffb4 SetWindowOrgEx
 0x1005ffb8 PlayEnhMetaFile
 0x1005ffbc GetTextMetricsA
 0x1005ffc0 GetTextExtentPoint32A
 0x1005ffc4 GetTextColor
 0x1005ffc8 GetBitmapBits
 0x1005ffcc GetBkColor
 0x1005ffd0 GetDeviceCaps
 0x1005ffd4 GetObjectA
 0x1005ffd8 GetCurrentPositionEx
 0x1005ffdc CreateFontIndirectA
 0x1005ffe0 CreatePatternBrush
 0x1005ffe4 CloseEnhMetaFile
 0x1005ffe8 CreateEnhMetaFileA
 0x1005ffec SwapBuffers
 0x1005fff0 GdiCleanCacheDC
 0x1005fff4 CancelDC
 0x1005fff8 GdiArtificialDecrementDriver
 0x1005fffc EngLineTo
 0x10060000 GdiRealizationInfo
 0x10060004 GdiCreateLocalEnhMetaFile
 0x10060008 GetAspectRatioFilterEx
 0x1006000c GetCharWidthInfo
 0x10060010 GdiAddGlsBounds
 0x10060014 EngAlphaBlend
 0x10060018 GetColorSpace
 0x1006001c GetDCBrushColor
 0x10060020 AddFontResourceW
 0x10060024 GetEnhMetaFileA
 0x10060028 GdiFlush
 0x1006002c GetEnhMetaFileBits
 0x10060030 GetEnhMetaFileW
COMDLG32.dll
 0x10060038 GetSaveFileNameA
 0x1006003c GetOpenFileNameA
 0x10060040 CommDlgExtendedError
 0x10060044 GetFileTitleA
ADVAPI32.dll
 0x1006004c CryptAcquireContextA
 0x10060050 RegQueryValueExA
 0x10060054 RegSetValueExA
 0x10060058 RegDeleteValueA
 0x1006005c GetUserNameW
 0x10060060 RegSetValueExW
 0x10060064 RegDeleteValueW
 0x10060068 RegDeleteKeyW
 0x1006006c RegOpenKeyW
 0x10060070 RegQueryValueExW
 0x10060074 RegCreateKeyExW
 0x10060078 RegEnumKeyW
 0x1006007c RegCreateKeyW
 0x10060080 RegisterEventSourceA
 0x10060084 ReportEventA
 0x10060088 DeregisterEventSource
 0x1006008c RegDeleteKeyA
 0x10060090 RegOpenKeyExA
 0x10060094 GetUserNameA
 0x10060098 IsTextUnicode
 0x1006009c RegCreateKeyExA
 0x100600a0 InitializeSecurityDescriptor
 0x100600a4 RegEnumValueA
 0x100600a8 RegQueryValueA
 0x100600ac RegEnumKeyA
 0x100600b0 SetFileSecurityA
 0x100600b4 RegOpenKeyExW
 0x100600b8 RegSetValueA
 0x100600bc CryptGenRandom
 0x100600c0 RegCloseKey
 0x100600c4 CryptReleaseContext
 0x100600c8 LookupAccountNameA
 0x100600cc GetFileSecurityA
 0x100600d0 GetSecurityInfo
 0x100600d4 OpenProcessToken
 0x100600d8 GetTokenInformation
 0x100600dc CopySid
 0x100600e0 BuildTrusteeWithSidA
 0x100600e4 GetEffectiveRightsFromAclA
 0x100600e8 RegGetKeySecurity
 0x100600ec GetSecurityDescriptorDacl
 0x100600f0 GetSecurityDescriptorOwner
 0x100600f4 GetAclInformation
 0x100600f8 GetLengthSid
 0x100600fc InitializeAcl
 0x10060100 AddAccessAllowedAce
 0x10060104 SetSecurityDescriptorDacl
 0x10060108 RegSetKeySecurity
 0x1006010c RegEnumKeyExA
 0x10060110 RegOpenKeyA
SHELL32.dll
 0x10060118 ShellExecuteA
 0x1006011c DragAcceptFiles
 0x10060120 ShellExecuteExA
 0x10060124 SHGetFolderPathA
 0x10060128 SHGetPathFromIDListW
 0x1006012c SHGetDesktopFolder
 0x10060130 SHAddToRecentDocs
 0x10060134 SHBrowseForFolderA
 0x10060138 CommandLineToArgvW
 0x1006013c Shell_NotifyIconA
 0x10060140 DragFinish
 0x10060144 DragQueryFileW
 0x10060148 DragQueryFileA
 0x1006014c SHGetFileInfoA
 0x10060150 SHFileOperationA
 0x10060154 SHGetFileInfoW
 0x10060158 SHGetPathFromIDListA
 0x1006015c SHGetMalloc
 0x10060160 ShellExecuteW
 0x10060164 ExtractIconA
 0x10060168 SHGetSpecialFolderLocation
 0x1006016c SHAppBarMessage
 0x10060170 SHChangeNotify
 0x10060174 SHBindToParent
 0x10060178 SHCreateDirectoryExW
 0x1006017c SHCreateDirectoryExA
 0x10060180 ShellExecuteEx
 0x10060184 FindExecutableW
 0x10060188 SHGetDiskFreeSpaceA
 0x1006018c ExtractAssociatedIconW
 0x10060190 SHInvokePrinterCommandA
 0x10060194 SHGetFolderLocation
 0x10060198 DoEnvironmentSubstA
 0x1006019c SHBrowseForFolderW
 0x100601a0 ExtractIconEx
 0x100601a4 ShellExecuteExW
 0x100601a8 CheckEscapesW
 0x100601ac SHPathPrepareForWriteA
 0x100601b0 SHGetFolderPathW
 0x100601b4 DuplicateIcon
 0x100601b8 FindExecutableA
ole32.dll
 0x100601c0 StgIsStorageFile
 0x100601c4 CoRegisterClassObject
 0x100601c8 CoRevokeClassObject
 0x100601cc CoRegisterMessageFilter
 0x100601d0 OleLockRunning
 0x100601d4 OleSetMenuDescriptor
 0x100601d8 OleSave
 0x100601dc WriteClassStm
 0x100601e0 OleSaveToStream
 0x100601e4 OleCreateFromData
 0x100601e8 OleCreateLinkFromData
 0x100601ec OleCreateStaticFromData
 0x100601f0 OleCreate
 0x100601f4 OleLoad
 0x100601f8 GetHGlobalFromILockBytes
 0x100601fc OleSetContainedObject
 0x10060200 OleCreateFromFile
 0x10060204 OleCreateLinkToFile
 0x10060208 OleGetIconOfClass
 0x1006020c CreateItemMoniker
 0x10060210 CreateGenericComposite
 0x10060214 OleIsRunning
 0x10060218 GetRunningObjectTable
 0x1006021c CoGetMalloc
 0x10060220 CreateOleAdviseHolder
 0x10060224 CoDisconnectObject
 0x10060228 StgOpenStorage
 0x1006022c OleRegEnumVerbs
 0x10060230 CoFreeUnusedLibraries
 0x10060234 CLSIDFromProgID
 0x10060238 PropVariantCopy
 0x1006023c CLSIDFromString
 0x10060240 StringFromGUID2
 0x10060244 OleDuplicateData
 0x10060248 CoTaskMemAlloc
 0x1006024c ReleaseStgMedium
 0x10060250 CreateBindCtx
 0x10060254 CoTreatAsClass
 0x10060258 StringFromCLSID
 0x1006025c ReadClassStg
 0x10060260 ReadFmtUserTypeStg
 0x10060264 OleRegGetUserType
 0x10060268 WriteClassStg
 0x1006026c WriteFmtUserTypeStg
 0x10060270 SetConvertStg
 0x10060274 OleUninitialize
 0x10060278 OleInitialize
 0x1006027c CoInitializeEx
 0x10060280 CoInitializeSecurity
 0x10060284 CoCreateInstance
 0x10060288 CoTaskMemFree
 0x1006028c CoCreateGuid
 0x10060290 CoInitialize
 0x10060294 CoUninitialize
 0x10060298 CreateStreamOnHGlobal
 0x1006029c CreateFileMoniker
 0x100602a0 StgCreateDocfile
 0x100602a4 OleRun
 0x100602a8 OleGetClipboard
 0x100602ac RevokeDragDrop
 0x100602b0 CoLockObjectExternal
 0x100602b4 RegisterDragDrop
 0x100602b8 DoDragDrop
 0x100602bc OleFlushClipboard
 0x100602c0 OleIsCurrentClipboard
 0x100602c4 OleSetClipboard
 0x100602c8 OleRegGetMiscStatus
 0x100602cc CreateILockBytesOnHGlobal
 0x100602d0 OleTranslateAccelerator
 0x100602d4 IsAccelerator
 0x100602d8 OleCreateMenuDescriptor
 0x100602dc OleDestroyMenuDescriptor
 0x100602e0 CoGetClassObject
 0x100602e4 StgOpenStorageOnILockBytes
 0x100602e8 OleQueryLinkFromData
 0x100602ec StgCreateDocfileOnILockBytes
 0x100602f0 OleQueryCreateFromData
 0x100602f4 CreateDataAdviseHolder
SHLWAPI.dll
 0x100602fc SHDeleteKeyA
 0x10060300 PathIsNetworkPathA
 0x10060304 PathRelativePathToA
 0x10060308 PathMatchSpecA
 0x1006030c StrStrIA
 0x10060310 StrChrIA
 0x10060314 StrStrIW
 0x10060318 StrChrIW
 0x1006031c PathCompactPathExW
 0x10060320 PathRelativePathToW
 0x10060324 PathIsRelativeA
 0x10060328 SHDeleteValueA
 0x1006032c PathFindExtensionA
 0x10060330 ColorAdjustLuma
 0x10060334 PathIsNetworkPathW
 0x10060338 SHAutoComplete
 0x1006033c PathRemoveFileSpecW
 0x10060340 PathRemoveExtensionA
 0x10060344 PathFindFileNameA
 0x10060348 PathStripToRootA
 0x1006034c PathIsUNCA
 0x10060350 StrChrW
COMCTL32.dll
 0x10060358 ImageList_Remove
 0x1006035c ImageList_DrawEx
 0x10060360 InitCommonControlsEx
 0x10060364 ImageList_Duplicate
 0x10060368 _TrackMouseEvent
 0x1006036c ImageList_GetIconSize
 0x10060370 ImageList_Draw
 0x10060374 ImageList_GetImageInfo
 0x10060378 ImageList_ReplaceIcon
 0x1006037c ImageList_GetImageCount
 0x10060380 ImageList_GetIcon
 0x10060384 ImageList_Create
 0x10060388 ImageList_Destroy
 0x1006038c ImageList_AddMasked
IMM32.dll
 0x10060394 ImmReleaseContext
 0x10060398 ImmGetOpenStatus
 0x1006039c ImmGetContext
 0x100603a0 ImmSetCompositionWindow

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure