Report - 5.exe

Emotet Generic Malware UPX Malicious Library OS Processor Check PE File PE32
ScreenShot
Created 2023.08.08 09:17 Machine s1_win7_x6401
Filename 5.exe
Type PE32 executable (GUI) Intel 80386, for MS Windows
AI Score
3
Behavior Score
1.8
ZERO API file : mailcious
VT API (file) 15 detected (AIDetectMalware, V8pc, Malicious, ccmw, FileRepMalware, Misc, Artemis, Autoit, Phonzy, Detected, BScope, Remcos)
md5 82cf051811579ee4f1d9978af52f12db
sha256 2227d5b2e2782a03bdb847a8ebf9ea40cc2c9f10f48385154c66ded1577b1deb
ssdeep 49152:M32RUvjn/TCGDQiMDpU/Sb8HDWSrbmnidPtrmEKhPlGRr4g0aQ7svt/:nyn/+GDhOcSb8HDhrK8rtGlGRr4+
imphash d5385158ebad80896ebc67b40f1bbb77
impfuzzy 384:k/R/RYkwiabBQOfR3yHawvrZwPKJvoV0Ce0:k/R/Rg7y6wvllJvLCt
  Network IP location

Signature (5cnts)

Level Description
watch File has been identified by 15 AntiVirus engines on VirusTotal as malicious
notice Checks adapter addresses which can be used to detect virtual network interfaces
notice Performs some HTTP requests
info Checks amount of memory in system
info This executable has a PDB path

Rules (7cnts)

Level Name Description Collection
danger Win32_Trojan_Emotet_1_Zero Win32 Trojan Emotet binaries (upload)
warning Generic_Malware_Zero Generic Malware binaries (upload)
watch Malicious_Library_Zero Malicious_Library binaries (upload)
watch UPX_Zero UPX packed file binaries (upload)
info IsPE32 (no description) binaries (upload)
info OS_Processor_Check_Zero OS Processor Check binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (4cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
http://apps.identrust.com/roots/dstrootcax3.p7c US Akamai International B.V. 23.67.53.17 clean
doi.org US CLOUDFLARENET 104.26.8.237 clean
104.26.9.237 US CLOUDFLARENET 104.26.9.237 clean
121.254.136.57 KR LG DACOM Corporation 121.254.136.57 clean

Suricata ids

PE API

IAT(Import Address Table) Library

COMCTL32.dll
 0x5b8044 InitCommonControlsEx
 0x5b8048 _TrackMouseEvent
 0x5b804c None
USER32.dll
 0x5b85a4 DrawIcon
 0x5b85a8 GetClientRect
 0x5b85ac wsprintfW
 0x5b85b0 EnableWindow
 0x5b85b4 SendMessageW
 0x5b85b8 GetWindow
 0x5b85bc LoadIconW
 0x5b85c0 GetWindowLongW
 0x5b85c4 EnableMenuItem
 0x5b85c8 KillTimer
 0x5b85cc PostMessageW
 0x5b85d0 LoadImageW
 0x5b85d4 IsIconic
 0x5b85d8 GetWindowRect
 0x5b85dc SetTimer
 0x5b85e0 GetSystemMenu
 0x5b85e4 GetDesktopWindow
 0x5b85e8 ReleaseDC
 0x5b85ec GetDC
 0x5b85f0 IsRectEmpty
 0x5b85f4 DestroyIcon
 0x5b85f8 IsWindowVisible
 0x5b85fc IsWindow
 0x5b8600 InvalidateRect
 0x5b8604 InflateRect
 0x5b8608 GetIconInfo
 0x5b860c SetRectEmpty
 0x5b8610 LoadCursorW
 0x5b8614 GetParent
 0x5b8618 GetFocus
 0x5b861c DrawIconEx
 0x5b8620 FillRect
 0x5b8624 SetCursor
 0x5b8628 CheckMenuItem
 0x5b862c SetMenuItemBitmaps
 0x5b8630 SetWindowLongW
 0x5b8634 UnregisterClassW
 0x5b8638 GetSystemMetrics
 0x5b863c GetMenuCheckMarkDimensions
 0x5b8640 SetMenuItemInfoW
 0x5b8644 LoadBitmapW
 0x5b8648 IsWindowEnabled
 0x5b864c MessageBoxW
 0x5b8650 GetWindowThreadProcessId
 0x5b8654 GetLastActivePopup
 0x5b8658 DestroyWindow
 0x5b865c CreateDialogIndirectParamW
 0x5b8660 EndDialog
 0x5b8664 GetDlgItem
 0x5b8668 GetWindowRgn
 0x5b866c DestroyCursor
 0x5b8670 CreateMenu
 0x5b8674 SubtractRect
 0x5b8678 GetUpdateRect
 0x5b867c IsClipboardFormatAvailable
 0x5b8680 TranslateMDISysAccel
 0x5b8684 DefMDIChildProcW
 0x5b8688 DefFrameProcW
 0x5b868c DrawMenuBar
 0x5b8690 FrameRect
 0x5b8694 CharUpperBuffW
 0x5b8698 ModifyMenuW
 0x5b869c SetMenuDefaultItem
 0x5b86a0 CopyIcon
 0x5b86a4 GetDoubleClickTime
 0x5b86a8 SetClassLongW
 0x5b86ac SetCursorPos
 0x5b86b0 DestroyAcceleratorTable
 0x5b86b4 CreateAcceleratorTableW
 0x5b86b8 GetKeyboardState
 0x5b86bc ToUnicodeEx
 0x5b86c0 LockWindowUpdate
 0x5b86c4 MapVirtualKeyExW
 0x5b86c8 IsCharLowerW
 0x5b86cc GetKeyboardLayout
 0x5b86d0 IsZoomed
 0x5b86d4 GetComboBoxInfo
 0x5b86d8 TrackMouseEvent
 0x5b86dc MonitorFromPoint
 0x5b86e0 UpdateLayeredWindow
 0x5b86e4 IsMenu
 0x5b86e8 SetWindowRgn
 0x5b86ec DrawFrameControl
 0x5b86f0 DrawEdge
 0x5b86f4 DrawStateW
 0x5b86f8 EmptyClipboard
 0x5b86fc SetClipboardData
 0x5b8700 CloseClipboard
 0x5b8704 OpenClipboard
 0x5b8708 EnumDisplayMonitors
 0x5b870c SetLayeredWindowAttributes
 0x5b8710 SetParent
 0x5b8714 UnionRect
 0x5b8718 GetKeyNameTextW
 0x5b871c MapVirtualKeyW
 0x5b8720 NotifyWinEvent
 0x5b8724 InvertRect
 0x5b8728 HideCaret
 0x5b872c EnableScrollBar
 0x5b8730 GetAsyncKeyState
 0x5b8734 DrawFocusRect
 0x5b8738 ReuseDDElParam
 0x5b873c UnpackDDElParam
 0x5b8740 InsertMenuItemW
 0x5b8744 TranslateAcceleratorW
 0x5b8748 LoadAcceleratorsW
 0x5b874c BringWindowToTop
 0x5b8750 GetMenuDefaultItem
 0x5b8754 CreatePopupMenu
 0x5b8758 PostThreadMessageW
 0x5b875c MessageBeep
 0x5b8760 GetNextDlgGroupItem
 0x5b8764 SetRect
 0x5b8768 InvalidateRgn
 0x5b876c CopyAcceleratorTableW
 0x5b8770 OffsetRect
 0x5b8774 CharNextW
 0x5b8778 CharUpperW
 0x5b877c WindowFromPoint
 0x5b8780 ReleaseCapture
 0x5b8784 SetCapture
 0x5b8788 WaitMessage
 0x5b878c DeleteMenu
 0x5b8790 CopyImage
 0x5b8794 IntersectRect
 0x5b8798 GetSysColorBrush
 0x5b879c RealChildWindowFromPoint
 0x5b87a0 LoadMenuW
 0x5b87a4 SystemParametersInfoW
 0x5b87a8 GetMenuItemInfoW
 0x5b87ac DestroyMenu
 0x5b87b0 SendDlgItemMessageA
 0x5b87b4 RegisterClipboardFormatW
 0x5b87b8 GetCursorPos
 0x5b87bc TranslateMessage
 0x5b87c0 GetMessageW
 0x5b87c4 MapDialogRect
 0x5b87c8 SetWindowContextHelpId
 0x5b87cc ShowOwnedPopups
 0x5b87d0 PostQuitMessage
 0x5b87d4 IsDialogMessageW
 0x5b87d8 SetWindowTextW
 0x5b87dc CheckDlgButton
 0x5b87e0 MoveWindow
 0x5b87e4 ShowWindow
 0x5b87e8 GetMonitorInfoW
 0x5b87ec MonitorFromWindow
 0x5b87f0 WinHelpW
 0x5b87f4 GetScrollInfo
 0x5b87f8 SetScrollInfo
 0x5b87fc CallNextHookEx
 0x5b8800 UnhookWindowsHookEx
 0x5b8804 SetWindowsHookExW
 0x5b8808 GetTopWindow
 0x5b880c GetClassNameW
 0x5b8810 GetClassLongW
 0x5b8814 PtInRect
 0x5b8818 EqualRect
 0x5b881c CopyRect
 0x5b8820 MapWindowPoints
 0x5b8824 AdjustWindowRectEx
 0x5b8828 GetWindowTextLengthW
 0x5b882c GetWindowTextW
 0x5b8830 RemovePropW
 0x5b8834 GetPropW
 0x5b8838 SetPropW
 0x5b883c ShowScrollBar
 0x5b8840 GetScrollRange
 0x5b8844 SetScrollRange
 0x5b8848 GetScrollPos
 0x5b884c SetScrollPos
 0x5b8850 ScrollWindow
 0x5b8854 RedrawWindow
 0x5b8858 ValidateRect
 0x5b885c SetForegroundWindow
 0x5b8860 GetForegroundWindow
 0x5b8864 UpdateWindow
 0x5b8868 TrackPopupMenu
 0x5b886c SetMenu
 0x5b8870 GetMenu
 0x5b8874 GetCapture
 0x5b8878 GetKeyState
 0x5b887c SetFocus
 0x5b8880 GetDlgCtrlID
 0x5b8884 EndDeferWindowPos
 0x5b8888 DeferWindowPos
 0x5b888c BeginDeferWindowPos
 0x5b8890 SetWindowPlacement
 0x5b8894 GetWindowPlacement
 0x5b8898 SetWindowPos
 0x5b889c IsChild
 0x5b88a0 CreateWindowExW
 0x5b88a4 GetClassInfoExW
 0x5b88a8 GetClassInfoW
 0x5b88ac RegisterClassW
 0x5b88b0 CallWindowProcW
 0x5b88b4 DefWindowProcW
 0x5b88b8 GetMessageTime
 0x5b88bc GetMessagePos
 0x5b88c0 PeekMessageW
 0x5b88c4 DispatchMessageW
 0x5b88c8 RegisterWindowMessageW
 0x5b88cc RemoveMenu
 0x5b88d0 AppendMenuW
 0x5b88d4 InsertMenuW
 0x5b88d8 GetMenuItemCount
 0x5b88dc GetMenuItemID
 0x5b88e0 GetSubMenu
 0x5b88e4 GetMenuState
 0x5b88e8 GetMenuStringW
 0x5b88ec GetSysColor
 0x5b88f0 ScreenToClient
 0x5b88f4 ClientToScreen
 0x5b88f8 EndPaint
 0x5b88fc BeginPaint
 0x5b8900 GetWindowDC
 0x5b8904 TabbedTextOutW
 0x5b8908 GrayStringW
 0x5b890c DrawTextExW
 0x5b8910 DrawTextW
 0x5b8914 SetActiveWindow
 0x5b8918 GetActiveWindow
 0x5b891c GetNextDlgTabItem
ole32.dll
 0x5b8a08 CLSIDFromString
 0x5b8a0c ReleaseStgMedium
 0x5b8a10 OleDuplicateData
 0x5b8a14 StgOpenStorageOnILockBytes
 0x5b8a18 CoFreeUnusedLibraries
 0x5b8a1c CoGetClassObject
 0x5b8a20 CoDisconnectObject
 0x5b8a24 OleRun
 0x5b8a28 CoUninitialize
 0x5b8a2c RevokeDragDrop
 0x5b8a30 RegisterDragDrop
 0x5b8a34 CoLockObjectExternal
 0x5b8a38 OleGetClipboard
 0x5b8a3c IsAccelerator
 0x5b8a40 OleTranslateAccelerator
 0x5b8a44 OleDestroyMenuDescriptor
 0x5b8a48 OleCreateMenuDescriptor
 0x5b8a4c OleLockRunning
 0x5b8a50 DoDragDrop
 0x5b8a54 CreateStreamOnHGlobal
 0x5b8a58 CoRegisterMessageFilter
 0x5b8a5c OleIsCurrentClipboard
 0x5b8a60 OleFlushClipboard
 0x5b8a64 CoRevokeClassObject
 0x5b8a68 StgCreateDocfileOnILockBytes
 0x5b8a6c OleUninitialize
 0x5b8a70 CreateILockBytesOnHGlobal
 0x5b8a74 OleInitialize
 0x5b8a78 CoTaskMemFree
 0x5b8a7c CoTaskMemAlloc
 0x5b8a80 CoCreateGuid
 0x5b8a84 StringFromGUID2
 0x5b8a88 CoInitialize
 0x5b8a8c CoInitializeEx
 0x5b8a90 CLSIDFromProgID
 0x5b8a94 CoCreateInstance
OLEAUT32.dll
 0x5b84e0 SysAllocString
 0x5b84e4 SysStringLen
 0x5b84e8 VariantClear
 0x5b84ec VariantCopy
 0x5b84f0 VariantInit
 0x5b84f4 SysFreeString
 0x5b84f8 SysAllocStringLen
 0x5b84fc VariantChangeType
 0x5b8500 SystemTimeToVariantTime
 0x5b8504 VariantTimeToSystemTime
 0x5b8508 GetErrorInfo
 0x5b850c OleCreateFontIndirect
 0x5b8510 LoadTypeLib
 0x5b8514 VarBstrFromDate
 0x5b8518 SafeArrayDestroy
SHLWAPI.dll
 0x5b8558 PathIsFileSpecW
 0x5b855c PathAppendW
 0x5b8560 PathRenameExtensionW
 0x5b8564 StrFormatKBSizeW
 0x5b8568 PathStripToRootW
 0x5b856c PathIsUNCW
 0x5b8570 PathRemoveExtensionW
 0x5b8574 PathFindExtensionW
 0x5b8578 PathFindFileNameW
 0x5b857c PathRemoveFileSpecW
 0x5b8580 StrRChrW
 0x5b8584 PathFileExistsW
 0x5b8588 PathRemoveBackslashW
 0x5b858c PathIsNetworkPathW
 0x5b8590 PathGetDriveNumberW
 0x5b8594 PathIsRootW
 0x5b8598 PathIsDirectoryW
 0x5b859c PathAddExtensionW
KERNEL32.dll
 0x5b81f0 WaitForMultipleObjects
 0x5b81f4 lstrlenA
 0x5b81f8 IsDBCSLeadByteEx
 0x5b81fc TerminateThread
 0x5b8200 OpenMutexW
 0x5b8204 GetLocalTime
 0x5b8208 SetEnvironmentVariableA
 0x5b820c WriteConsoleW
 0x5b8210 EnumSystemLocalesW
 0x5b8214 IsValidLocale
 0x5b8218 LCMapStringW
 0x5b821c GetTimeFormatW
 0x5b8220 GetDateFormatW
 0x5b8224 OutputDebugStringW
 0x5b8228 ReadConsoleW
 0x5b822c GetStringTypeW
 0x5b8230 GetTimeZoneInformation
 0x5b8234 GetConsoleMode
 0x5b8238 GetConsoleCP
 0x5b823c SetFilePointerEx
 0x5b8240 GetCPInfo
 0x5b8244 GetOEMCP
 0x5b8248 GetACP
 0x5b824c IsValidCodePage
 0x5b8250 SetUnhandledExceptionFilter
 0x5b8254 UnhandledExceptionFilter
 0x5b8258 FreeEnvironmentStringsW
 0x5b825c GetEnvironmentStringsW
 0x5b8260 QueryPerformanceCounter
 0x5b8264 GetStartupInfoW
 0x5b8268 VirtualQuery
 0x5b826c VirtualAlloc
 0x5b8270 GetSystemInfo
 0x5b8274 IsProcessorFeaturePresent
 0x5b8278 IsDebuggerPresent
 0x5b827c HeapQueryInformation
 0x5b8280 ExitThread
 0x5b8284 GetModuleHandleExW
 0x5b8288 ExitProcess
 0x5b828c RtlUnwind
 0x5b8290 GetSystemTimeAsFileTime
 0x5b8294 GetFileType
 0x5b8298 SetStdHandle
 0x5b829c FindResourceExW
 0x5b82a0 GetUserDefaultLCID
 0x5b82a4 VirtualProtect
 0x5b82a8 SearchPathW
 0x5b82ac GetProfileIntW
 0x5b82b0 GetTempFileNameW
 0x5b82b4 VerifyVersionInfoW
 0x5b82b8 VerSetConditionMask
 0x5b82bc lstrcpyW
 0x5b82c0 GetFileTime
 0x5b82c4 GetFileAttributesExW
 0x5b82c8 SetErrorMode
 0x5b82cc GetWindowsDirectoryW
 0x5b82d0 DuplicateHandle
 0x5b82d4 UnlockFile
 0x5b82d8 SetFilePointer
 0x5b82dc SetEndOfFile
 0x5b82e0 LockFile
 0x5b82e4 GetVolumeInformationW
 0x5b82e8 GetFullPathNameW
 0x5b82ec GetCurrentDirectoryW
 0x5b82f0 GetSystemDefaultUILanguage
 0x5b82f4 GetLocaleInfoW
 0x5b82f8 CompareStringW
 0x5b82fc LocalReAlloc
 0x5b8300 GlobalHandle
 0x5b8304 GlobalReAlloc
 0x5b8308 TlsFree
 0x5b830c TlsSetValue
 0x5b8310 TlsGetValue
 0x5b8314 TlsAlloc
 0x5b8318 GetThreadLocale
 0x5b831c GlobalGetAtomNameW
 0x5b8320 InitializeCriticalSection
 0x5b8324 GlobalFlags
 0x5b8328 GetTickCount
 0x5b832c ResumeThread
 0x5b8330 SetThreadPriority
 0x5b8334 WritePrivateProfileStringW
 0x5b8338 GetPrivateProfileStringW
 0x5b833c GetPrivateProfileIntW
 0x5b8340 lstrcmpA
 0x5b8344 GetCurrentThread
 0x5b8348 FileTimeToSystemTime
 0x5b834c FileTimeToLocalFileTime
 0x5b8350 GlobalFindAtomW
 0x5b8354 GlobalAddAtomW
 0x5b8358 LoadLibraryA
 0x5b835c GlobalDeleteAtom
 0x5b8360 LoadLibraryExW
 0x5b8364 GetSystemDirectoryW
 0x5b8368 GetCurrentThreadId
 0x5b836c LeaveCriticalSection
 0x5b8370 EnterCriticalSection
 0x5b8374 EncodePointer
 0x5b8378 FormatMessageW
 0x5b837c GlobalSize
 0x5b8380 GlobalAlloc
 0x5b8384 MulDiv
 0x5b8388 GlobalFree
 0x5b838c GlobalUnlock
 0x5b8390 GlobalLock
 0x5b8394 GetModuleHandleA
 0x5b8398 FreeResource
 0x5b839c OutputDebugStringA
 0x5b83a0 GetFileSizeEx
 0x5b83a4 CreateToolhelp32Snapshot
 0x5b83a8 FindNextFileW
 0x5b83ac lstrcmpiW
 0x5b83b0 Process32NextW
 0x5b83b4 Process32FirstW
 0x5b83b8 FindClose
 0x5b83bc SetLastError
 0x5b83c0 FlushFileBuffers
 0x5b83c4 lstrcmpW
 0x5b83c8 CreateFileW
 0x5b83cc ReadFile
 0x5b83d0 TerminateProcess
 0x5b83d4 GetFileAttributesW
 0x5b83d8 GetVersionExW
 0x5b83dc OpenProcess
 0x5b83e0 WriteFile
 0x5b83e4 GetCurrentProcess
 0x5b83e8 MoveFileExW
 0x5b83ec FindFirstFileW
 0x5b83f0 GetFileSize
 0x5b83f4 CreateDirectoryW
 0x5b83f8 GetUserDefaultUILanguage
 0x5b83fc GetTempPathW
 0x5b8400 GetExitCodeProcess
 0x5b8404 CopyFileW
 0x5b8408 GetUserDefaultLangID
 0x5b840c CreateProcessW
 0x5b8410 GetDriveTypeW
 0x5b8414 LockResource
 0x5b8418 SizeofResource
 0x5b841c LoadResource
 0x5b8420 FindResourceW
 0x5b8424 CreateThread
 0x5b8428 SetFileAttributesW
 0x5b842c DeleteFileW
 0x5b8430 RemoveDirectoryW
 0x5b8434 SetCurrentDirectoryW
 0x5b8438 CreateEventW
 0x5b843c ResetEvent
 0x5b8440 GetProcAddress
 0x5b8444 GetStdHandle
 0x5b8448 GetModuleFileNameW
 0x5b844c FreeConsole
 0x5b8450 LoadLibraryW
 0x5b8454 GetModuleHandleW
 0x5b8458 SetEvent
 0x5b845c FreeLibrary
 0x5b8460 GetCommandLineW
 0x5b8464 MultiByteToWideChar
 0x5b8468 WideCharToMultiByte
 0x5b846c LocalFree
 0x5b8470 GetCurrentProcessId
 0x5b8474 CloseHandle
 0x5b8478 ReleaseMutex
 0x5b847c OpenSemaphoreW
 0x5b8480 LocalAlloc
 0x5b8484 CreateSemaphoreW
 0x5b8488 ReleaseSemaphore
 0x5b848c Sleep
 0x5b8490 WaitForSingleObject
 0x5b8494 CreateMutexW
 0x5b8498 DeleteCriticalSection
 0x5b849c DecodePointer
 0x5b84a0 HeapSize
 0x5b84a4 GetLastError
 0x5b84a8 RaiseException
 0x5b84ac GetProcessHeap
 0x5b84b0 HeapFree
 0x5b84b4 HeapAlloc
 0x5b84b8 HeapReAlloc
 0x5b84bc InitializeCriticalSectionAndSpinCount
GDI32.dll
 0x5b8054 GetDeviceCaps
 0x5b8058 GetObjectW
 0x5b805c Rectangle
 0x5b8060 CreateCompatibleBitmap
 0x5b8064 CreateCompatibleDC
 0x5b8068 CreateSolidBrush
 0x5b806c CreateRoundRectRgn
 0x5b8070 GetTextFaceW
 0x5b8074 GetViewportOrgEx
 0x5b8078 LPtoDP
 0x5b807c GetWindowOrgEx
 0x5b8080 GetBoundsRect
 0x5b8084 FillRgn
 0x5b8088 SetPaletteEntries
 0x5b808c ExtFloodFill
 0x5b8090 SetPixelV
 0x5b8094 PtInRegion
 0x5b8098 FrameRgn
 0x5b809c RoundRect
 0x5b80a0 OffsetRgn
 0x5b80a4 EnumFontFamiliesExW
 0x5b80a8 Polyline
 0x5b80ac Polygon
 0x5b80b0 CreatePolygonRgn
 0x5b80b4 Ellipse
 0x5b80b8 CreateEllipticRgn
 0x5b80bc SetDIBColorTable
 0x5b80c0 CreateDIBSection
 0x5b80c4 StretchBlt
 0x5b80c8 SetPixel
 0x5b80cc GetTextCharsetInfo
 0x5b80d0 EnumFontFamiliesW
 0x5b80d4 CreateDIBitmap
 0x5b80d8 RealizePalette
 0x5b80dc GetSystemPaletteEntries
 0x5b80e0 GetPaletteEntries
 0x5b80e4 GetNearestPaletteIndex
 0x5b80e8 CreatePalette
 0x5b80ec GetRgnBox
 0x5b80f0 GetTextColor
 0x5b80f4 GetBkColor
 0x5b80f8 DPtoLP
 0x5b80fc SetRectRgn
 0x5b8100 PatBlt
 0x5b8104 GetMapMode
 0x5b8108 CreateRectRgnIndirect
 0x5b810c CombineRgn
 0x5b8110 GetTextMetricsW
 0x5b8114 GetTextExtentPoint32W
 0x5b8118 CreateDCW
 0x5b811c CopyMetaFileW
 0x5b8120 ScaleWindowExtEx
 0x5b8124 ScaleViewportExtEx
 0x5b8128 OffsetWindowOrgEx
 0x5b812c OffsetViewportOrgEx
 0x5b8130 SetWindowOrgEx
 0x5b8134 SetWindowExtEx
 0x5b8138 SetViewportOrgEx
 0x5b813c SetViewportExtEx
 0x5b8140 ExtTextOutW
 0x5b8144 TextOutW
 0x5b8148 MoveToEx
 0x5b814c SetTextAlign
 0x5b8150 SetTextColor
 0x5b8154 SetROP2
 0x5b8158 SetPolyFillMode
 0x5b815c GetLayout
 0x5b8160 SetLayout
 0x5b8164 SetMapMode
 0x5b8168 SetBkMode
 0x5b816c SetBkColor
 0x5b8170 SelectPalette
 0x5b8174 ExtSelectClipRgn
 0x5b8178 SelectClipRgn
 0x5b817c SaveDC
 0x5b8180 RestoreDC
 0x5b8184 RectVisible
 0x5b8188 PtVisible
 0x5b818c LineTo
 0x5b8190 IntersectClipRect
 0x5b8194 GetWindowExtEx
 0x5b8198 GetViewportExtEx
 0x5b819c GetPixel
 0x5b81a0 GetObjectType
 0x5b81a4 GetClipBox
 0x5b81a8 ExcludeClipRect
 0x5b81ac Escape
 0x5b81b0 CreateRectRgn
 0x5b81b4 CreatePatternBrush
 0x5b81b8 CreatePen
 0x5b81bc CreateHatchBrush
 0x5b81c0 BitBlt
 0x5b81c4 DeleteDC
 0x5b81c8 CreateFontIndirectW
 0x5b81cc CreateBitmap
 0x5b81d0 DeleteObject
 0x5b81d4 SelectObject
 0x5b81d8 GetStockObject
MSIMG32.dll
 0x5b84c4 TransparentBlt
 0x5b84c8 AlphaBlend
WINSPOOL.DRV
 0x5b899c DocumentPropertiesW
 0x5b89a0 ClosePrinter
 0x5b89a4 OpenPrinterW
ADVAPI32.dll
 0x5b8000 RegEnumKeyW
 0x5b8004 SetSecurityDescriptorDacl
 0x5b8008 AllocateAndInitializeSid
 0x5b800c SetEntriesInAclW
 0x5b8010 FreeSid
 0x5b8014 RegQueryValueExW
 0x5b8018 RegOpenKeyExW
 0x5b801c RegCloseKey
 0x5b8020 RegEnumKeyExW
 0x5b8024 RegEnumValueW
 0x5b8028 RegQueryValueW
 0x5b802c InitializeSecurityDescriptor
 0x5b8030 RegSetValueExW
 0x5b8034 RegDeleteValueW
 0x5b8038 RegDeleteKeyW
 0x5b803c RegCreateKeyExW
SHELL32.dll
 0x5b8520 SHCreateDirectoryExW
 0x5b8524 SHAppBarMessage
 0x5b8528 SHBrowseForFolderW
 0x5b852c DragFinish
 0x5b8530 DragQueryFileW
 0x5b8534 SHGetDesktopFolder
 0x5b8538 SHGetSpecialFolderLocation
 0x5b853c SHGetPathFromIDListW
 0x5b8540 SHGetFileInfoW
 0x5b8544 SHGetSpecialFolderPathW
 0x5b8548 CommandLineToArgvW
 0x5b854c None
 0x5b8550 ShellExecuteW
UxTheme.dll
 0x5b8924 GetThemePartSize
 0x5b8928 DrawThemeBackground
 0x5b892c IsThemeBackgroundPartiallyTransparent
 0x5b8930 DrawThemeParentBackground
 0x5b8934 OpenThemeData
 0x5b8938 CloseThemeData
 0x5b893c GetThemeColor
 0x5b8940 GetCurrentThemeName
 0x5b8944 IsAppThemed
 0x5b8948 GetThemeSysColor
 0x5b894c GetWindowTheme
 0x5b8950 DrawThemeText
oledlg.dll
 0x5b8a9c OleUIBusyW
OLEACC.dll
 0x5b84d0 CreateStdAccessibleObject
 0x5b84d4 AccessibleObjectFromWindow
 0x5b84d8 LresultFromObject
gdiplus.dll
 0x5b89ac GdipDeleteGraphics
 0x5b89b0 GdipBitmapUnlockBits
 0x5b89b4 GdipBitmapLockBits
 0x5b89b8 GdipCreateBitmapFromScan0
 0x5b89bc GdipCreateBitmapFromStream
 0x5b89c0 GdipGetImagePaletteSize
 0x5b89c4 GdipDrawImageI
 0x5b89c8 GdipGetImagePixelFormat
 0x5b89cc GdipGetImageHeight
 0x5b89d0 GdipGetImageWidth
 0x5b89d4 GdipGetImageGraphicsContext
 0x5b89d8 GdipDisposeImage
 0x5b89dc GdipCloneImage
 0x5b89e0 GdiplusStartup
 0x5b89e4 GdipFree
 0x5b89e8 GdipAlloc
 0x5b89ec GdiplusShutdown
 0x5b89f0 GdipCreateBitmapFromHBITMAP
 0x5b89f4 GdipCreateFromHDC
 0x5b89f8 GdipSetInterpolationMode
 0x5b89fc GdipDrawImageRectI
 0x5b8a00 GdipGetImagePalette
IMM32.dll
 0x5b81e0 ImmGetOpenStatus
 0x5b81e4 ImmReleaseContext
 0x5b81e8 ImmGetContext
WINMM.dll
 0x5b8994 PlaySoundW
WINHTTP.dll
 0x5b8958 WinHttpGetIEProxyConfigForCurrentUser
 0x5b895c WinHttpSendRequest
 0x5b8960 WinHttpConnect
 0x5b8964 WinHttpCloseHandle
 0x5b8968 WinHttpQueryHeaders
 0x5b896c WinHttpSetStatusCallback
 0x5b8970 WinHttpQueryDataAvailable
 0x5b8974 WinHttpOpen
 0x5b8978 WinHttpOpenRequest
 0x5b897c WinHttpGetProxyForUrl
 0x5b8980 WinHttpReadData
 0x5b8984 WinHttpSetCredentials
 0x5b8988 WinHttpAddRequestHeaders
 0x5b898c WinHttpReceiveResponse

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure