Report - laowu.exe

UPX Malicious Library PE64 PE File
ScreenShot
Created 2023.04.04 07:08 Machine s1_win7_x6401
Filename laowu.exe
Type PE32+ executable (GUI) x86-64, for MS Windows
AI Score Not founds Behavior Score
4.2
ZERO API file : clean
VT API (file) 35 detected (DInvoke, Packed2, GenericKD, Attribute, HighConfidence, Malicious, score, Redcap, ojovq, GenKD, Casdet, Artemis, ai score=81, unsafe, R002H07CV23, wt0Ig2gYoPO, PossibleThreat)
md5 7b97ca6f925df64756ec0bd8ab3c1590
sha256 27c9474b8299b3b07e74c0c0f2fbcabb229e6be771f162d0ad4377282e6563ce
ssdeep 49152:uYlCdR5hVPPM6rbTgfc7e/f9uJoIVnl2RS+GeYMydeIQITIkWrIAMDNt3USnhimJ:uYlOZTt8fiV8gNNSS8m
imphash e6360e9b7a461166f83852282b66eb35
impfuzzy 192:fWJhPRwsFStsYxl669U7vuuDNydSrnvTkCWa0eZ+tcnchcGEif/g4P1ZPWXi45:8hTStjxl6/hkQGaGAinf1ZPWXi45
  Network IP location

Signature (9cnts)

Level Description
danger Connects to an IP address that is no longer responding to requests (legitimate services will remain up-and-running usually)
danger File has been identified by 35 AntiVirus engines on VirusTotal as malicious
watch Communicates with host for which no DNS query was performed
notice Allocates read-write-execute memory (usually to unpack itself)
notice Changes read-write memory protection to read-execute (probably to avoid detection when setting all RWX flags at the same time)
info Checks amount of memory in system
info Checks if process is being debugged by a debugger
info The executable contains unknown PE section names indicative of a packer (could be a false positive)
info This executable has a PDB path

Rules (4cnts)

Level Name Description Collection
watch Malicious_Library_Zero Malicious_Library binaries (upload)
watch UPX_Zero UPX packed file binaries (upload)
info IsPE64 (no description) binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (1cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
45.151.135.235 Unknown 45.151.135.235 clean

Suricata ids

PE API

IAT(Import Address Table) Library

KERNEL32.dll
 0x1401d14a0 GetStringTypeW
 0x1401d14a8 LCMapStringW
 0x1401d14b0 CompareStringW
 0x1401d14b8 GetTimeZoneInformation
 0x1401d14c0 GetConsoleCP
 0x1401d14c8 GetConsoleMode
 0x1401d14d0 IsValidCodePage
 0x1401d14d8 WriteConsoleW
 0x1401d14e0 CreateFileW
 0x1401d14e8 SetEnvironmentVariableA
 0x1401d14f0 FlsAlloc
 0x1401d14f8 FlsFree
 0x1401d1500 QueryPerformanceCounter
 0x1401d1508 SetHandleCount
 0x1401d1510 FreeEnvironmentStringsW
 0x1401d1518 GetEnvironmentStringsW
 0x1401d1520 FlsSetValue
 0x1401d1528 FlsGetValue
 0x1401d1530 HeapCreate
 0x1401d1538 GetVersion
 0x1401d1540 HeapSetInformation
 0x1401d1548 GetStdHandle
 0x1401d1550 RtlCaptureContext
 0x1401d1558 RtlVirtualUnwind
 0x1401d1560 IsDebuggerPresent
 0x1401d1568 SetUnhandledExceptionFilter
 0x1401d1570 FindResourceW
 0x1401d1578 UnhandledExceptionFilter
 0x1401d1580 TerminateProcess
 0x1401d1588 GetFileType
 0x1401d1590 SetStdHandle
 0x1401d1598 HeapSize
 0x1401d15a0 HeapQueryInformation
 0x1401d15a8 CreateThread
 0x1401d15b0 ExitThread
 0x1401d15b8 GetSystemTimeAsFileTime
 0x1401d15c0 VirtualQuery
 0x1401d15c8 GetSystemInfo
 0x1401d15d0 SetThreadStackGuarantee
 0x1401d15d8 RtlPcToFileHeader
 0x1401d15e0 RaiseException
 0x1401d15e8 RtlUnwindEx
 0x1401d15f0 RtlLookupFunctionEntry
 0x1401d15f8 HeapReAlloc
 0x1401d1600 HeapFree
 0x1401d1608 GetStartupInfoW
 0x1401d1610 GetCommandLineA
 0x1401d1618 ExitProcess
 0x1401d1620 HeapAlloc
 0x1401d1628 DecodePointer
 0x1401d1630 EncodePointer
 0x1401d1638 FindResourceExW
 0x1401d1640 SetErrorMode
 0x1401d1648 GetNumberFormatA
 0x1401d1650 GetWindowsDirectoryA
 0x1401d1658 GetFileSizeEx
 0x1401d1660 LocalFileTimeToFileTime
 0x1401d1668 GetFileAttributesExA
 0x1401d1670 FileTimeToLocalFileTime
 0x1401d1678 GetShortPathNameA
 0x1401d1680 GetVolumeInformationA
 0x1401d1688 DuplicateHandle
 0x1401d1690 SetEndOfFile
 0x1401d1698 UnlockFile
 0x1401d16a0 LockFile
 0x1401d16a8 FlushFileBuffers
 0x1401d16b0 WriteFile
 0x1401d16b8 ReadFile
 0x1401d16c0 MoveFileA
 0x1401d16c8 DeleteFileA
 0x1401d16d0 lstrcmpiA
 0x1401d16d8 GetStringTypeExA
 0x1401d16e0 SearchPathA
 0x1401d16e8 GetProfileIntA
 0x1401d16f0 GetTempPathA
 0x1401d16f8 SetFilePointer
 0x1401d1700 Sleep
 0x1401d1708 GetACP
 0x1401d1710 GetOEMCP
 0x1401d1718 GetCPInfo
 0x1401d1720 TlsFree
 0x1401d1728 LocalReAlloc
 0x1401d1730 TlsSetValue
 0x1401d1738 GlobalHandle
 0x1401d1740 TlsAlloc
 0x1401d1748 TlsGetValue
 0x1401d1750 LocalAlloc
 0x1401d1758 GlobalFlags
 0x1401d1760 InitializeCriticalSection
 0x1401d1768 GetDiskFreeSpaceA
 0x1401d1770 GetFullPathNameA
 0x1401d1778 GetTempFileNameA
 0x1401d1780 GetFileTime
 0x1401d1788 SetFileTime
 0x1401d1790 ReplaceFileA
 0x1401d1798 GetTickCount
 0x1401d17a0 GetPrivateProfileStringA
 0x1401d17a8 WritePrivateProfileStringA
 0x1401d17b0 GetPrivateProfileIntA
 0x1401d17b8 GetCurrentThread
 0x1401d17c0 GetUserDefaultUILanguage
 0x1401d17c8 ConvertDefaultLocale
 0x1401d17d0 GetSystemDefaultUILanguage
 0x1401d17d8 GetLocaleInfoA
 0x1401d17e0 SystemTimeToFileTime
 0x1401d17e8 FileTimeToSystemTime
 0x1401d17f0 GetThreadLocale
 0x1401d17f8 lstrcmpA
 0x1401d1800 CreateFileA
 0x1401d1808 GetFileSize
 0x1401d1810 GetFileAttributesA
 0x1401d1818 GlobalReAlloc
 0x1401d1820 WaitForSingleObject
 0x1401d1828 ResumeThread
 0x1401d1830 SetThreadPriority
 0x1401d1838 CloseHandle
 0x1401d1840 GetModuleFileNameW
 0x1401d1848 ReleaseActCtx
 0x1401d1850 CreateActCtxW
 0x1401d1858 GetModuleFileNameA
 0x1401d1860 DeleteCriticalSection
 0x1401d1868 InitializeCriticalSectionAndSpinCount
 0x1401d1870 GetCurrentDirectoryA
 0x1401d1878 GetModuleHandleW
 0x1401d1880 EnterCriticalSection
 0x1401d1888 LeaveCriticalSection
 0x1401d1890 GlobalFree
 0x1401d1898 CopyFileA
 0x1401d18a0 GlobalSize
 0x1401d18a8 GlobalAlloc
 0x1401d18b0 FormatMessageA
 0x1401d18b8 LocalFree
 0x1401d18c0 lstrlenW
 0x1401d18c8 MulDiv
 0x1401d18d0 FindResourceA
 0x1401d18d8 FreeResource
 0x1401d18e0 GetCurrentThreadId
 0x1401d18e8 GlobalFindAtomA
 0x1401d18f0 GlobalDeleteAtom
 0x1401d18f8 GetVersionExA
 0x1401d1900 FreeLibrary
 0x1401d1908 CompareStringA
 0x1401d1910 LoadLibraryW
 0x1401d1918 lstrcmpW
 0x1401d1920 GlobalLock
 0x1401d1928 GlobalUnlock
 0x1401d1930 GetCurrentProcessId
 0x1401d1938 GlobalGetAtomNameA
 0x1401d1940 GlobalAddAtomA
 0x1401d1948 MultiByteToWideChar
 0x1401d1950 VirtualProtect
 0x1401d1958 FindNextFileA
 0x1401d1960 FindClose
 0x1401d1968 VirtualAlloc
 0x1401d1970 EnumUILanguagesW
 0x1401d1978 FindFirstFileA
 0x1401d1980 GetEnvironmentVariableA
 0x1401d1988 lstrcatA
 0x1401d1990 InitOnceExecuteOnce
 0x1401d1998 GetCurrentProcess
 0x1401d19a0 lstrlenA
 0x1401d19a8 lstrcpyA
 0x1401d19b0 GetModuleHandleA
 0x1401d19b8 LoadLibraryA
 0x1401d19c0 GetProcAddress
 0x1401d19c8 SetLastError
 0x1401d19d0 GetLastError
 0x1401d19d8 DeactivateActCtx
 0x1401d19e0 ActivateActCtx
 0x1401d19e8 LockResource
 0x1401d19f0 SizeofResource
 0x1401d19f8 WideCharToMultiByte
 0x1401d1a00 LoadResource
USER32.dll
 0x1401d1b58 CreateAcceleratorTableA
 0x1401d1b60 GetKeyboardState
 0x1401d1b68 GetKeyboardLayout
 0x1401d1b70 ToAsciiEx
 0x1401d1b78 CopyAcceleratorTableA
 0x1401d1b80 CopyIcon
 0x1401d1b88 SetCursorPos
 0x1401d1b90 RealChildWindowFromPoint
 0x1401d1b98 WaitMessage
 0x1401d1ba0 PostThreadMessageA
 0x1401d1ba8 CreateDialogIndirectParamA
 0x1401d1bb0 GetNextDlgTabItem
 0x1401d1bb8 EndDialog
 0x1401d1bc0 SetWindowContextHelpId
 0x1401d1bc8 MapDialogRect
 0x1401d1bd0 ShowOwnedPopups
 0x1401d1bd8 PostQuitMessage
 0x1401d1be0 HideCaret
 0x1401d1be8 InvertRect
 0x1401d1bf0 FrameRect
 0x1401d1bf8 CharUpperBuffA
 0x1401d1c00 GetIconInfo
 0x1401d1c08 GetMenuItemInfoA
 0x1401d1c10 LoadImageW
 0x1401d1c18 EmptyClipboard
 0x1401d1c20 CloseClipboard
 0x1401d1c28 SetClipboardData
 0x1401d1c30 CopyImage
 0x1401d1c38 OpenClipboard
 0x1401d1c40 TranslateMessage
 0x1401d1c48 DestroyAcceleratorTable
 0x1401d1c50 SetLayeredWindowAttributes
 0x1401d1c58 EnumDisplayMonitors
 0x1401d1c60 RegisterClipboardFormatA
 0x1401d1c68 SetMenuDefaultItem
 0x1401d1c70 GetMenuDefaultItem
 0x1401d1c78 EndPaint
 0x1401d1c80 BeginPaint
 0x1401d1c88 GetWindowDC
 0x1401d1c90 GrayStringA
 0x1401d1c98 DrawTextExA
 0x1401d1ca0 DrawTextA
 0x1401d1ca8 TabbedTextOutA
 0x1401d1cb0 SetClassLongPtrA
 0x1401d1cb8 DrawIconEx
 0x1401d1cc0 GetSysColorBrush
 0x1401d1cc8 DrawFocusRect
 0x1401d1cd0 DrawFrameControl
 0x1401d1cd8 DrawEdge
 0x1401d1ce0 FillRect
 0x1401d1ce8 DrawStateA
 0x1401d1cf0 LockWindowUpdate
 0x1401d1cf8 GetUpdateRect
 0x1401d1d00 SetRect
 0x1401d1d08 MapVirtualKeyA
 0x1401d1d10 GetKeyNameTextA
 0x1401d1d18 ReleaseDC
 0x1401d1d20 GetDC
 0x1401d1d28 CharUpperA
 0x1401d1d30 NotifyWinEvent
 0x1401d1d38 MessageBeep
 0x1401d1d40 LoadCursorW
 0x1401d1d48 WindowFromPoint
 0x1401d1d50 GetSystemMenu
 0x1401d1d58 DeleteMenu
 0x1401d1d60 IsMenu
 0x1401d1d68 GetAsyncKeyState
 0x1401d1d70 GetMessageA
 0x1401d1d78 GetCursorPos
 0x1401d1d80 MonitorFromPoint
 0x1401d1d88 SystemParametersInfoA
 0x1401d1d90 UpdateLayeredWindow
 0x1401d1d98 LoadCursorA
 0x1401d1da0 EnableScrollBar
 0x1401d1da8 SetCapture
 0x1401d1db0 KillTimer
 0x1401d1db8 SetTimer
 0x1401d1dc0 ValidateRect
 0x1401d1dc8 UnionRect
 0x1401d1dd0 MoveWindow
 0x1401d1dd8 SetWindowTextA
 0x1401d1de0 IsDialogMessageA
 0x1401d1de8 SetDlgItemTextA
 0x1401d1df0 SubtractRect
 0x1401d1df8 CheckDlgButton
 0x1401d1e00 TranslateMDISysAccel
 0x1401d1e08 DrawMenuBar
 0x1401d1e10 DefMDIChildProcA
 0x1401d1e18 DefFrameProcA
 0x1401d1e20 SetParent
 0x1401d1e28 RedrawWindow
 0x1401d1e30 SetWindowRgn
 0x1401d1e38 IsZoomed
 0x1401d1e40 IsRectEmpty
 0x1401d1e48 GetMenuStringA
 0x1401d1e50 AppendMenuA
 0x1401d1e58 InsertMenuA
 0x1401d1e60 RemoveMenu
 0x1401d1e68 RegisterWindowMessageA
 0x1401d1e70 LoadIconA
 0x1401d1e78 SendDlgItemMessageA
 0x1401d1e80 SetWindowsHookExA
 0x1401d1e88 CallNextHookEx
 0x1401d1e90 GetClassLongA
 0x1401d1e98 GetClassLongPtrA
 0x1401d1ea0 SetPropA
 0x1401d1ea8 GetPropA
 0x1401d1eb0 RemovePropA
 0x1401d1eb8 GetWindowTextLengthA
 0x1401d1ec0 GetWindowTextA
 0x1401d1ec8 GetForegroundWindow
 0x1401d1ed0 DispatchMessageA
 0x1401d1ed8 BeginDeferWindowPos
 0x1401d1ee0 EndDeferWindowPos
 0x1401d1ee8 GetTopWindow
 0x1401d1ef0 DestroyWindow
 0x1401d1ef8 GetWindowLongPtrA
 0x1401d1f00 SetWindowLongPtrA
 0x1401d1f08 UnhookWindowsHookEx
 0x1401d1f10 GetMessageTime
 0x1401d1f18 GetMessagePos
 0x1401d1f20 MonitorFromWindow
 0x1401d1f28 GetMonitorInfoA
 0x1401d1f30 MapWindowPoints
 0x1401d1f38 ScrollWindow
 0x1401d1f40 TrackPopupMenu
 0x1401d1f48 SetScrollRange
 0x1401d1f50 GetScrollRange
 0x1401d1f58 SetScrollPos
 0x1401d1f60 GetScrollPos
 0x1401d1f68 SetForegroundWindow
 0x1401d1f70 ShowScrollBar
 0x1401d1f78 MessageBoxA
 0x1401d1f80 CreateWindowExA
 0x1401d1f88 GetClassInfoExA
 0x1401d1f90 RegisterClassA
 0x1401d1f98 AdjustWindowRectEx
 0x1401d1fa0 EnableWindow
 0x1401d1fa8 UpdateWindow
 0x1401d1fb0 LoadBitmapW
 0x1401d1fb8 GetSysColor
 0x1401d1fc0 LoadMenuW
 0x1401d1fc8 DeferWindowPos
 0x1401d1fd0 GetScrollInfo
 0x1401d1fd8 SetScrollInfo
 0x1401d1fe0 PtInRect
 0x1401d1fe8 SetWindowPlacement
 0x1401d1ff0 GetWindowPlacement
 0x1401d1ff8 DefWindowProcA
 0x1401d2000 CallWindowProcA
 0x1401d2008 GetClassNameA
 0x1401d2010 UnpackDDElParam
 0x1401d2018 ReuseDDElParam
 0x1401d2020 LoadMenuA
 0x1401d2028 DestroyMenu
 0x1401d2030 WinHelpA
 0x1401d2038 SetWindowPos
 0x1401d2040 GetDoubleClickTime
 0x1401d2048 IsClipboardFormatAvailable
 0x1401d2050 GetTabbedTextExtentW
 0x1401d2058 GetWindowRgn
 0x1401d2060 UnregisterClassA
 0x1401d2068 CreateMenu
 0x1401d2070 MapVirtualKeyExA
 0x1401d2078 IsCharLowerA
 0x1401d2080 DrawIcon
 0x1401d2088 DestroyIcon
 0x1401d2090 SetFocus
 0x1401d2098 GetWindowThreadProcessId
 0x1401d20a0 GetActiveWindow
 0x1401d20a8 IsWindowEnabled
 0x1401d20b0 EqualRect
 0x1401d20b8 GetDlgItem
 0x1401d20c0 SetWindowLongA
 0x1401d20c8 GetDlgCtrlID
 0x1401d20d0 GetKeyState
 0x1401d20d8 LoadIconW
 0x1401d20e0 InvalidateRgn
 0x1401d20e8 CharNextA
 0x1401d20f0 DestroyCursor
 0x1401d20f8 GetNextDlgGroupItem
 0x1401d2100 EnumChildWindows
 0x1401d2108 InvalidateRect
 0x1401d2110 InflateRect
 0x1401d2118 SetRectEmpty
 0x1401d2120 SendMessageA
 0x1401d2128 GetClientRect
 0x1401d2130 GetParent
 0x1401d2138 GetFocus
 0x1401d2140 GetSubMenu
 0x1401d2148 IsChild
 0x1401d2150 GetWindowRect
 0x1401d2158 ScreenToClient
 0x1401d2160 LoadImageA
 0x1401d2168 GetSystemMetrics
 0x1401d2170 wsprintfA
 0x1401d2178 ClientToScreen
 0x1401d2180 CheckMenuItem
 0x1401d2188 EnableMenuItem
 0x1401d2190 GetMenuState
 0x1401d2198 ModifyMenuA
 0x1401d21a0 GetMenuCheckMarkDimensions
 0x1401d21a8 SetMenuItemBitmaps
 0x1401d21b0 TranslateAcceleratorA
 0x1401d21b8 IsWindow
 0x1401d21c0 GetWindow
 0x1401d21c8 ShowWindow
 0x1401d21d0 GetWindowLongA
 0x1401d21d8 GetDesktopWindow
 0x1401d21e0 SetMenu
 0x1401d21e8 PostMessageA
 0x1401d21f0 BringWindowToTop
 0x1401d21f8 GetLastActivePopup
 0x1401d2200 GetMenu
 0x1401d2208 CopyRect
 0x1401d2210 OffsetRect
 0x1401d2218 IntersectRect
 0x1401d2220 GetClassInfoA
 0x1401d2228 CreatePopupMenu
 0x1401d2230 GetMenuItemCount
 0x1401d2238 GetMenuItemID
 0x1401d2240 InsertMenuItemA
 0x1401d2248 IsIconic
 0x1401d2250 IsWindowVisible
 0x1401d2258 SetActiveWindow
 0x1401d2260 LoadAcceleratorsA
 0x1401d2268 ReleaseCapture
 0x1401d2270 GetCapture
 0x1401d2278 PeekMessageA
 0x1401d2280 SetCursor
 0x1401d2288 LoadAcceleratorsW
GDI32.dll
 0x1401d10d8 ExtSelectClipRgn
 0x1401d10e0 CreatePatternBrush
 0x1401d10e8 SelectPalette
 0x1401d10f0 GetObjectType
 0x1401d10f8 SetRectRgn
 0x1401d1100 GetMapMode
 0x1401d1108 DPtoLP
 0x1401d1110 GetTextMetricsA
 0x1401d1118 CreateDIBitmap
 0x1401d1120 EnumFontFamiliesA
 0x1401d1128 GetTextCharsetInfo
 0x1401d1130 SetDIBColorTable
 0x1401d1138 GetDIBits
 0x1401d1140 RealizePalette
 0x1401d1148 StretchBlt
 0x1401d1150 SetPixel
 0x1401d1158 StartPage
 0x1401d1160 EndPage
 0x1401d1168 SetAbortProc
 0x1401d1170 AbortDoc
 0x1401d1178 EndDoc
 0x1401d1180 GetCharWidthA
 0x1401d1188 OffsetRgn
 0x1401d1190 GetRgnBox
 0x1401d1198 RoundRect
 0x1401d11a0 CreatePalette
 0x1401d11a8 GetPaletteEntries
 0x1401d11b0 ExtFloodFill
 0x1401d11b8 SetPaletteEntries
 0x1401d11c0 GetViewportOrgEx
 0x1401d11c8 LPtoDP
 0x1401d11d0 GetNearestPaletteIndex
 0x1401d11d8 GetSystemPaletteEntries
 0x1401d11e0 GetWindowOrgEx
 0x1401d11e8 PtInRegion
 0x1401d11f0 FillRgn
 0x1401d11f8 FrameRgn
 0x1401d1200 GetBoundsRect
 0x1401d1208 EnumFontFamiliesExA
 0x1401d1210 GetNearestColor
 0x1401d1218 GetBkMode
 0x1401d1220 GetPolyFillMode
 0x1401d1228 GetROP2
 0x1401d1230 GetStretchBltMode
 0x1401d1238 GetTextAlign
 0x1401d1240 GetTextFaceA
 0x1401d1248 GetTextExtentPointA
 0x1401d1250 GetTextExtentPoint32W
 0x1401d1258 SetPixelV
 0x1401d1260 SetTextAlign
 0x1401d1268 MoveToEx
 0x1401d1270 GetCurrentPositionEx
 0x1401d1278 ScaleWindowExtEx
 0x1401d1280 SetWindowExtEx
 0x1401d1288 OffsetWindowOrgEx
 0x1401d1290 SetWindowOrgEx
 0x1401d1298 ScaleViewportExtEx
 0x1401d12a0 SetViewportExtEx
 0x1401d12a8 OffsetViewportOrgEx
 0x1401d12b0 SetViewportOrgEx
 0x1401d12b8 Escape
 0x1401d12c0 TextOutA
 0x1401d12c8 RectVisible
 0x1401d12d0 PtVisible
 0x1401d12d8 StartDocA
 0x1401d12e0 GetPixel
 0x1401d12e8 GetWindowExtEx
 0x1401d12f0 GetViewportExtEx
 0x1401d12f8 SelectClipRgn
 0x1401d1300 SetLayout
 0x1401d1308 GetLayout
 0x1401d1310 Rectangle
 0x1401d1318 GetObjectA
 0x1401d1320 LineTo
 0x1401d1328 IntersectClipRect
 0x1401d1330 ExcludeClipRect
 0x1401d1338 GetClipBox
 0x1401d1340 SetMapMode
 0x1401d1348 SetStretchBltMode
 0x1401d1350 SetROP2
 0x1401d1358 SetPolyFillMode
 0x1401d1360 SetBkMode
 0x1401d1368 RestoreDC
 0x1401d1370 SaveDC
 0x1401d1378 ExtTextOutA
 0x1401d1380 Polygon
 0x1401d1388 Ellipse
 0x1401d1390 Polyline
 0x1401d1398 GetTextColor
 0x1401d13a0 GetBkColor
 0x1401d13a8 CombineRgn
 0x1401d13b0 CreatePolygonRgn
 0x1401d13b8 CreateEllipticRgn
 0x1401d13c0 CreateRectRgn
 0x1401d13c8 CreateHatchBrush
 0x1401d13d0 CreateSolidBrush
 0x1401d13d8 PatBlt
 0x1401d13e0 CreateRectRgnIndirect
 0x1401d13e8 CreateRoundRectRgn
 0x1401d13f0 CreatePen
 0x1401d13f8 BitBlt
 0x1401d1400 CreateDIBSection
 0x1401d1408 SelectObject
 0x1401d1410 DeleteDC
 0x1401d1418 CreateDCA
 0x1401d1420 CopyMetaFileA
 0x1401d1428 GetDeviceCaps
 0x1401d1430 SetBkColor
 0x1401d1438 SetTextColor
 0x1401d1440 CreateCompatibleDC
 0x1401d1448 CreateCompatibleBitmap
 0x1401d1450 CreateBitmap
 0x1401d1458 CreateFontIndirectA
 0x1401d1460 DeleteObject
 0x1401d1468 GetStockObject
 0x1401d1470 GetTextExtentPoint32A
MSIMG32.dll
 0x1401d1a10 TransparentBlt
 0x1401d1a18 AlphaBlend
COMDLG32.dll
 0x1401d10c8 GetFileTitleA
WINSPOOL.DRV
 0x1401d22e8 OpenPrinterA
 0x1401d22f0 DocumentPropertiesA
 0x1401d22f8 ClosePrinter
 0x1401d2300 GetJobA
ADVAPI32.dll
 0x1401d1000 RegEnumKeyExA
 0x1401d1008 RegSetValueA
 0x1401d1010 RegQueryValueExA
 0x1401d1018 RegOpenKeyExA
 0x1401d1020 RegCreateKeyExA
 0x1401d1028 RegSetValueExA
 0x1401d1030 RegDeleteValueA
 0x1401d1038 RegDeleteKeyA
 0x1401d1040 RegEnumKeyA
 0x1401d1048 RegQueryValueA
 0x1401d1050 RegEnumValueA
 0x1401d1058 RegOpenKeyExW
 0x1401d1060 RegCloseKey
 0x1401d1068 GetFileSecurityA
 0x1401d1070 SetFileSecurityA
SHELL32.dll
 0x1401d1ac0 SHGetPathFromIDListA
 0x1401d1ac8 DragQueryFileA
 0x1401d1ad0 SHAppBarMessage
 0x1401d1ad8 ShellExecuteA
 0x1401d1ae0 SHGetFileInfoA
 0x1401d1ae8 SHGetDesktopFolder
 0x1401d1af0 SHGetSpecialFolderLocation
 0x1401d1af8 ExtractIconA
 0x1401d1b00 SHAddToRecentDocs
 0x1401d1b08 SHBrowseForFolderA
 0x1401d1b10 SHGetMalloc
 0x1401d1b18 DragFinish
COMCTL32.dll
 0x1401d1080 InitCommonControlsEx
 0x1401d1088 ImageList_GetIconSize
 0x1401d1090 ImageList_ReplaceIcon
 0x1401d1098 ImageList_GetIcon
 0x1401d10a0 ImageList_Create
 0x1401d10a8 ImageList_GetImageCount
 0x1401d10b0 ImageList_Destroy
 0x1401d10b8 ImageList_DrawEx
SHLWAPI.dll
 0x1401d1b28 PathFindFileNameA
 0x1401d1b30 PathStripToRootA
 0x1401d1b38 PathIsUNCA
 0x1401d1b40 PathRemoveFileSpecW
 0x1401d1b48 PathFindExtensionA
ole32.dll
 0x1401d23c8 OleFlushClipboard
 0x1401d23d0 OleIsCurrentClipboard
 0x1401d23d8 CreateILockBytesOnHGlobal
 0x1401d23e0 StgOpenStorageOnILockBytes
 0x1401d23e8 OleInitialize
 0x1401d23f0 CoFreeUnusedLibraries
 0x1401d23f8 OleUninitialize
 0x1401d2400 CLSIDFromProgID
 0x1401d2408 DoDragDrop
 0x1401d2410 CLSIDFromString
 0x1401d2418 CreateStreamOnHGlobal
 0x1401d2420 CoInitialize
 0x1401d2428 CoCreateInstance
 0x1401d2430 RegisterDragDrop
 0x1401d2438 OleDuplicateData
 0x1401d2440 CoTaskMemAlloc
 0x1401d2448 ReleaseStgMedium
 0x1401d2450 StringFromCLSID
 0x1401d2458 IsAccelerator
 0x1401d2460 OleTranslateAccelerator
 0x1401d2468 OleGetClipboard
 0x1401d2470 OleLockRunning
 0x1401d2478 CoInitializeEx
 0x1401d2480 CoGetClassObject
 0x1401d2488 StgCreateDocfileOnILockBytes
 0x1401d2490 CoRevokeClassObject
 0x1401d2498 CoRegisterMessageFilter
 0x1401d24a0 RevokeDragDrop
 0x1401d24a8 CoCreateGuid
 0x1401d24b0 CoLockObjectExternal
 0x1401d24b8 CoTaskMemFree
 0x1401d24c0 OleDestroyMenuDescriptor
 0x1401d24c8 CoUninitialize
 0x1401d24d0 OleCreateMenuDescriptor
OLEAUT32.dll
 0x1401d1a48 VariantChangeType
 0x1401d1a50 VariantInit
 0x1401d1a58 SysAllocStringLen
 0x1401d1a60 SysAllocString
 0x1401d1a68 SysStringLen
 0x1401d1a70 VariantCopy
 0x1401d1a78 SafeArrayDestroy
 0x1401d1a80 VariantTimeToSystemTime
 0x1401d1a88 SystemTimeToVariantTime
 0x1401d1a90 VarBstrFromDate
 0x1401d1a98 OleCreateFontIndirect
 0x1401d1aa0 SysAllocStringByteLen
 0x1401d1aa8 SysFreeString
 0x1401d1ab0 VariantClear
oledlg.dll
 0x1401d24e0 None
gdiplus.dll
 0x1401d2310 GdipGetImageGraphicsContext
 0x1401d2318 GdipBitmapUnlockBits
 0x1401d2320 GdipBitmapLockBits
 0x1401d2328 GdipCreateBitmapFromScan0
 0x1401d2330 GdipCreateBitmapFromStream
 0x1401d2338 GdipGetImagePalette
 0x1401d2340 GdipGetImagePaletteSize
 0x1401d2348 GdipGetImagePixelFormat
 0x1401d2350 GdipGetImageHeight
 0x1401d2358 GdipGetImageWidth
 0x1401d2360 GdipCloneImage
 0x1401d2368 GdipDrawImageRectI
 0x1401d2370 GdipSetInterpolationMode
 0x1401d2378 GdipCreateFromHDC
 0x1401d2380 GdiplusShutdown
 0x1401d2388 GdiplusStartup
 0x1401d2390 GdipCreateBitmapFromHBITMAP
 0x1401d2398 GdipDisposeImage
 0x1401d23a0 GdipDeleteGraphics
 0x1401d23a8 GdipAlloc
 0x1401d23b0 GdipFree
 0x1401d23b8 GdipDrawImageI
WININET.dll
 0x1401d2298 FtpOpenFileA
 0x1401d22a0 InternetCloseHandle
 0x1401d22a8 InternetOpenA
 0x1401d22b0 FtpGetFileSize
 0x1401d22b8 InternetReadFile
 0x1401d22c0 InternetCrackUrlA
 0x1401d22c8 InternetConnectA
OLEACC.dll
 0x1401d1a28 LresultFromObject
 0x1401d1a30 AccessibleObjectFromWindow
 0x1401d1a38 CreateStdAccessibleObject
IMM32.dll
 0x1401d1480 ImmReleaseContext
 0x1401d1488 ImmGetContext
 0x1401d1490 ImmGetOpenStatus
WINMM.dll
 0x1401d22d8 PlaySoundA

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure