Report - sqlite3.dll

UPX PE File DLL PE32
ScreenShot
Created 2023.08.18 15:53 Machine s1_win7_x6401
Filename sqlite3.dll
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
AI Score
2
Behavior Score
0.0
ZERO API file : clean
VT API (file)
md5 1f44d4d3087c2b202cf9c90ee9d04b0f
sha256 4841020c8bd06b08fde6e44cbe2e2ab33439e1c8368e936ec5b00dc0584f7260
ssdeep 12288:dxylSMUMifofI9ayCvcZMBiMjCodEMdo8R66tCWko5+jsbFcoYuprzpGSgGSrz:d4AMB3caSZMijBI1CWkoj5auF5gGSrz
imphash e727d00364cd87d72f56e7ba919d1d40
impfuzzy 48:0YH0XOwOsa989FK1eTX/cw7Y5j9qG/JAOgoqttSRd3:PH0X7daSrK1eTvcw7Y5j9qG/JAOVqttQ
  Network IP location

Signature (0cnts)

Level Description

Rules (4cnts)

Level Name Description Collection
watch UPX_Zero UPX packed file binaries (upload)
info IsDLL (no description) binaries (upload)
info IsPE32 (no description) binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids

PE API

IAT(Import Address Table) Library

KERNEL32.dll
 0x61ed020c AreFileApisANSI
 0x61ed0210 CloseHandle
 0x61ed0214 CreateFileA
 0x61ed0218 CreateFileMappingA
 0x61ed021c CreateFileMappingW
 0x61ed0220 CreateFileW
 0x61ed0224 CreateMutexW
 0x61ed0228 DeleteCriticalSection
 0x61ed022c DeleteFileA
 0x61ed0230 DeleteFileW
 0x61ed0234 EnterCriticalSection
 0x61ed0238 FlushFileBuffers
 0x61ed023c FlushViewOfFile
 0x61ed0240 FormatMessageA
 0x61ed0244 FormatMessageW
 0x61ed0248 FreeLibrary
 0x61ed024c GetCurrentProcess
 0x61ed0250 GetCurrentProcessId
 0x61ed0254 GetCurrentThreadId
 0x61ed0258 GetDiskFreeSpaceA
 0x61ed025c GetDiskFreeSpaceW
 0x61ed0260 GetFileAttributesA
 0x61ed0264 GetFileAttributesExW
 0x61ed0268 GetFileAttributesW
 0x61ed026c GetFileSize
 0x61ed0270 GetFullPathNameA
 0x61ed0274 GetFullPathNameW
 0x61ed0278 GetLastError
 0x61ed027c GetModuleHandleA
 0x61ed0280 GetProcAddress
 0x61ed0284 GetProcessHeap
 0x61ed0288 GetSystemInfo
 0x61ed028c GetSystemTime
 0x61ed0290 GetSystemTimeAsFileTime
 0x61ed0294 GetTempPathA
 0x61ed0298 GetTempPathW
 0x61ed029c GetTickCount
 0x61ed02a0 GetVersionExA
 0x61ed02a4 GetVersionExW
 0x61ed02a8 HeapAlloc
 0x61ed02ac HeapCompact
 0x61ed02b0 HeapCreate
 0x61ed02b4 HeapDestroy
 0x61ed02b8 HeapFree
 0x61ed02bc HeapReAlloc
 0x61ed02c0 HeapSize
 0x61ed02c4 HeapValidate
 0x61ed02c8 InitializeCriticalSection
 0x61ed02cc InterlockedCompareExchange
 0x61ed02d0 LeaveCriticalSection
 0x61ed02d4 LoadLibraryA
 0x61ed02d8 LoadLibraryW
 0x61ed02dc LocalFree
 0x61ed02e0 LockFile
 0x61ed02e4 LockFileEx
 0x61ed02e8 MapViewOfFile
 0x61ed02ec MultiByteToWideChar
 0x61ed02f0 OutputDebugStringA
 0x61ed02f4 OutputDebugStringW
 0x61ed02f8 QueryPerformanceCounter
 0x61ed02fc ReadFile
 0x61ed0300 SetEndOfFile
 0x61ed0304 SetFilePointer
 0x61ed0308 SetUnhandledExceptionFilter
 0x61ed030c Sleep
 0x61ed0310 SystemTimeToFileTime
 0x61ed0314 TerminateProcess
 0x61ed0318 TlsGetValue
 0x61ed031c TryEnterCriticalSection
 0x61ed0320 UnhandledExceptionFilter
 0x61ed0324 UnlockFile
 0x61ed0328 UnlockFileEx
 0x61ed032c UnmapViewOfFile
 0x61ed0330 VirtualProtect
 0x61ed0334 VirtualQuery
 0x61ed0338 WaitForSingleObject
 0x61ed033c WaitForSingleObjectEx
 0x61ed0340 WideCharToMultiByte
 0x61ed0344 WriteFile
msvcrt.dll
 0x61ed034c __dllonexit
 0x61ed0350 __setusermatherr
 0x61ed0354 _amsg_exit
 0x61ed0358 _beginthreadex
 0x61ed035c _endthreadex
 0x61ed0360 _errno
 0x61ed0364 _initterm
 0x61ed0368 _iob
 0x61ed036c _lock
 0x61ed0370 _onexit
 0x61ed0374 localtime
 0x61ed0378 calloc
 0x61ed037c cosh
 0x61ed0380 fprintf
 0x61ed0384 free
 0x61ed0388 fwrite
 0x61ed038c malloc
 0x61ed0390 memcmp
 0x61ed0394 memmove
 0x61ed0398 qsort
 0x61ed039c realloc
 0x61ed03a0 sinh
 0x61ed03a4 strcmp
 0x61ed03a8 strcspn
 0x61ed03ac strlen
 0x61ed03b0 strncmp
 0x61ed03b4 strrchr
 0x61ed03b8 _unlock
 0x61ed03bc abort
 0x61ed03c0 acos
 0x61ed03c4 asin
 0x61ed03c8 atan
 0x61ed03cc tan
 0x61ed03d0 tanh
 0x61ed03d4 vfprintf

EAT(Export Address Table) Library

0x61e1d756 sqlite3_aggregate_context
0x61e0388c sqlite3_aggregate_count
0x61ead0a4 sqlite3_auto_extension
0x61e05df1 sqlite3_autovacuum_pages
0x61e555d0 sqlite3_backup_finish
0x61e5501e sqlite3_backup_init
0x61e03451 sqlite3_backup_pagecount
0x61e03446 sqlite3_backup_remaining
0x61e52f80 sqlite3_backup_step
0x61e2d8b8 sqlite3_bind_blob
0x61e2d8e7 sqlite3_bind_blob64
0x61e2d595 sqlite3_bind_double
0x61e2d635 sqlite3_bind_int
0x61e2d5e6 sqlite3_bind_int64
0x61e2d65b sqlite3_bind_null
0x61e038ca sqlite3_bind_parameter_count
0x61e158ca sqlite3_bind_parameter_index
0x61e038dc sqlite3_bind_parameter_name
0x61e2d68c sqlite3_bind_pointer
0x61e2d916 sqlite3_bind_text
0x61e2d981 sqlite3_bind_text16
0x61e2d945 sqlite3_bind_text64
0x61e2d9b0 sqlite3_bind_value
0x61e2d714 sqlite3_bind_zeroblob
0x61e2d781 sqlite3_bind_zeroblob64
0x61e039a7 sqlite3_blob_bytes
0x61e5664b sqlite3_blob_close
0x61e97fc1 sqlite3_blob_open
0x61e58238 sqlite3_blob_read
0x61e9875b sqlite3_blob_reopen
0x61e58f9a sqlite3_blob_write
0x61e05b72 sqlite3_busy_handler
0x61e0e714 sqlite3_busy_timeout
0x61e0468c sqlite3_cancel_auto_extension
0x61e05a26 sqlite3_changes
0x61e05a18 sqlite3_changes64
0x61e0b431 sqlite3_clear_bindings
0x61e557c7 sqlite3_close
0x61e557d5 sqlite3_close_v2
0x61e05ee1 sqlite3_collation_needed
0x61e05f25 sqlite3_collation_needed16
0x61e1f9b5 sqlite3_column_blob
0x61e1f7dc sqlite3_column_bytes
0x61e1f819 sqlite3_column_bytes16
0x61e0389a sqlite3_column_count
0x61e1fedf sqlite3_column_database_name
0x61e1fef7 sqlite3_column_database_name16
0x61e1feac sqlite3_column_decltype
0x61e1fec4 sqlite3_column_decltype16
0x61e2e46f sqlite3_column_double
0x61e11884 sqlite3_column_int
0x61e118b0 sqlite3_column_int64
0x61e1fe79 sqlite3_column_name
0x61e1fe91 sqlite3_column_name16
0x61e1ff45 sqlite3_column_origin_name
0x61e1ff5d sqlite3_column_origin_name16
0x61e1ff12 sqlite3_column_table_name
0x61e1ff2a sqlite3_column_table_name16
0x61e1f9e1 sqlite3_column_text
0x61e1ff78 sqlite3_column_text16
0x61e11954 sqlite3_column_type
0x61e118d9 sqlite3_column_value
0x61e05d2b sqlite3_commit_hook
0x61e06049 sqlite3_compileoption_get
0x61e09c1c sqlite3_compileoption_used
0x61e056f2 sqlite3_complete
0x61ead24a sqlite3_complete16
0x61e34e2e sqlite3_config
0x61e03829 sqlite3_context_db_handle
0x61e2d162 sqlite3_create_collation
0x61e2d199 sqlite3_create_collation16
0x61e2d10b sqlite3_create_collation_v2
0x61e39e09 sqlite3_create_filename
0x61e2cc50 sqlite3_create_function
0x61e2cf25 sqlite3_create_function16
0x61e2ce9a sqlite3_create_function_v2
0x61e23d2a sqlite3_create_module
0x61e23e36 sqlite3_create_module_v2
0x61e2cee0 sqlite3_create_window_function
0x61e038af sqlite3_data_count
0x61ecc020 sqlite3_data_directory
0x61e02a47 sqlite3_database_file_object
0x61e5291b sqlite3_db_cacheflush
0x61e14651 sqlite3_db_config
0x61e13884 sqlite3_db_filename
0x61e038f9 sqlite3_db_handle
0x61e05991 sqlite3_db_mutex
0x61e06009 sqlite3_db_name
0x61e06027 sqlite3_db_readonly
0x61e154d5 sqlite3_db_release_memory
0x61e17032 sqlite3_db_status
0x61e8b02b sqlite3_declare_vtab
0x61e8de6c sqlite3_deserialize
0x61e23e54 sqlite3_drop_modules
0x61e34de8 sqlite3_enable_load_extension
0x61e02ce4 sqlite3_enable_shared_cache
0x61e2d2eb sqlite3_errcode
0x61e2d35e sqlite3_errmsg
0x61e2d3e1 sqlite3_errmsg16
0x61e2d2a4 sqlite3_error_offset
0x61e0e70b sqlite3_errstr
0x61e75015 sqlite3_exec
0x61e1f629 sqlite3_expanded_sql
0x61e03794 sqlite3_expired
0x61e2d326 sqlite3_extended_errcode
0x61e05f7a sqlite3_extended_result_codes
0x61e16076 sqlite3_file_control
0x61e05fd1 sqlite3_filename_database
0x61e09bc1 sqlite3_filename_journal
0x61e09bfa sqlite3_filename_wal
0x61e5655a sqlite3_finalize
0x61e0ae03 sqlite3_free
0x61e0b7cb sqlite3_free_filename
0x61e0b77e sqlite3_free_table
0x61e05f69 sqlite3_get_autocommit
0x61e03851 sqlite3_get_auxdata
0x61e8d680 sqlite3_get_table
0x61ead8fc sqlite3_global_recover
0x61e35893 sqlite3_hard_heap_limit64
0x61e3502f sqlite3_initialize
0x61e08918 sqlite3_interrupt
0x61e13473 sqlite3_keyword_check
0x61e051e8 sqlite3_keyword_count
0x61e051b3 sqlite3_keyword_name
0x61e059d5 sqlite3_last_insert_rowid
0x61e05973 sqlite3_libversion
0x61e0597d sqlite3_libversion_number
0x61e05e9c sqlite3_limit
0x61e44dbd sqlite3_load_extension
0x61e2a4ce sqlite3_log
0x61e35921 sqlite3_malloc
0x61e369df sqlite3_malloc64
0x61e3343b sqlite3_memory_alarm
0x61e2c855 sqlite3_memory_highwater
0x61e2c825 sqlite3_memory_used
0x61e42ea8 sqlite3_mprintf
0x61e017b6 sqlite3_msize
0x61e35598 sqlite3_mutex_alloc
0x61e01759 sqlite3_mutex_enter
0x61e01746 sqlite3_mutex_free
0x61e01781 sqlite3_mutex_leave
0x61e0176c sqlite3_mutex_try
0x61e0395a sqlite3_next_stmt
0x61ead7e7 sqlite3_open
0x61ead81a sqlite3_open16
0x61ead802 sqlite3_open_v2
0x61e34c0e sqlite3_os_end
0x61e354d1 sqlite3_os_init
0x61e4681d sqlite3_overload_function
0x61e84e6a sqlite3_prepare
0x61e8854f sqlite3_prepare16
0x61e88576 sqlite3_prepare16_v2
0x61e8859d sqlite3_prepare16_v3
0x61e878f8 sqlite3_prepare_v2
0x61e87e29 sqlite3_prepare_v3
0x61e34c5f sqlite3_preupdate_blobwrite
0x61e34c1f sqlite3_preupdate_count
0x61e34c3d sqlite3_preupdate_depth
0x61ead8ba sqlite3_preupdate_hook
0x61e34c77 sqlite3_preupdate_new
0x61e504d9 sqlite3_preupdate_old
0x61e05cd7 sqlite3_profile
0x61e05bc0 sqlite3_progress_handler
0x61e48a85 sqlite3_randomness
0x61e3a0ff sqlite3_realloc
0x61e3b57b sqlite3_realloc64
0x61e0179e sqlite3_release_memory
0x61e59035 sqlite3_reset
0x61ead136 sqlite3_reset_auto_extension
0x61e20dcf sqlite3_result_blob
0x61e21706 sqlite3_result_blob64
0x61e138f6 sqlite3_result_double
0x61e1e8c1 sqlite3_result_error
0x61e1ebf0 sqlite3_result_error16
0x61e2149a sqlite3_result_error_code
0x61e20cbe sqlite3_result_error_nomem
0x61e1ec29 sqlite3_result_error_toobig
0x61e0b32d sqlite3_result_int
0x61e0b35f sqlite3_result_int64
0x61e0b3be sqlite3_result_null
0x61e13a5e sqlite3_result_pointer
0x61e03805 sqlite3_result_subtype
0x61e20dee sqlite3_result_text
0x61e21494 sqlite3_result_text16
0x61e21456 sqlite3_result_text16be
0x61e21475 sqlite3_result_text16le
0x61e2175a sqlite3_result_text64
0x61e1ec66 sqlite3_result_value
0x61e1ee7c sqlite3_result_zeroblob
0x61e1ee15 sqlite3_result_zeroblob64
0x61e05daf sqlite3_rollback_hook
0x61ead903 sqlite3_rtree_geometry_callback
0x61ead981 sqlite3_rtree_query_callback
0x61e8dc63 sqlite3_serialize
0x61e040ac sqlite3_set_authorizer
0x61e1acc9 sqlite3_set_auxdata
0x61e059e3 sqlite3_set_last_insert_rowid
0x61ead189 sqlite3_shutdown
0x61e35437 sqlite3_sleep
0x61e2a1be sqlite3_snprintf
0x61e3586f sqlite3_soft_heap_limit
0x61e3579a sqlite3_soft_heap_limit64
0x61e0890e sqlite3_sourceid
0x61e03993 sqlite3_sql
0x61e2c7cd sqlite3_status
0x61e2c73d sqlite3_status64
0x61e7485a sqlite3_step
0x61e03940 sqlite3_stmt_busy
0x61e03926 sqlite3_stmt_isexplain
0x61e03909 sqlite3_stmt_readonly
0x61e11748 sqlite3_stmt_status
0x61e1d3a8 sqlite3_str_append
0x61e1d3dd sqlite3_str_appendall
0x61e1d54e sqlite3_str_appendchar
0x61e1a734 sqlite3_str_appendf
0x61e017f3 sqlite3_str_errcode
0x61e1aa6f sqlite3_str_finish
0x61e01808 sqlite3_str_length
0x61e36a05 sqlite3_str_new
0x61e0aef2 sqlite3_str_reset
0x61e01819 sqlite3_str_value
0x61e19208 sqlite3_str_vappendf
0x61e0a9df sqlite3_strglob
0x61e01998 sqlite3_stricmp
0x61e0a9fa sqlite3_strlike
0x61e019be sqlite3_strnicmp
0x61e05e8b sqlite3_system_errno
0x61e8d0b6 sqlite3_table_column_metadata
0x61ecc024 sqlite3_temp_directory
0x61eaca78 sqlite3_test_control
0x61e05f75 sqlite3_thread_cleanup
0x61e05987 sqlite3_threadsafe
0x61e05a3f sqlite3_total_changes
0x61e05a31 sqlite3_total_changes64
0x61e05c2e sqlite3_trace
0x61e05c7f sqlite3_trace_v2
0x61e1307a sqlite3_transfer_bindings
0x61e05a4a sqlite3_txn_state
0x61e05d6d sqlite3_update_hook
0x61e09b35 sqlite3_uri_boolean
0x61e11fa7 sqlite3_uri_int64
0x61e09b68 sqlite3_uri_key
0x61e09ada sqlite3_uri_parameter
0x61e0381b sqlite3_user_data
0x61e1f8b8 sqlite3_value_blob
0x61e1f7ce sqlite3_value_bytes
0x61e1f808 sqlite3_value_bytes16
0x61e191fc sqlite3_value_double
0x61e35bfa sqlite3_value_dup
0x61e0b4d0 sqlite3_value_free
0x61e037f3 sqlite3_value_frombind
0x61e0c999 sqlite3_value_int
0x61e0c9a6 sqlite3_value_int64
0x61e037da sqlite3_value_nochange
0x61e32d74 sqlite3_value_numeric_type
0x61e11df1 sqlite3_value_pointer
0x61e037b1 sqlite3_value_subtype
0x61e1f87f sqlite3_value_text
0x61e1ffa4 sqlite3_value_text16
0x61e1fdd0 sqlite3_value_text16be
0x61e1fde1 sqlite3_value_text16le
0x61e037c5 sqlite3_value_type
0x61eca8a0 sqlite3_version
0x61e353d4 sqlite3_vfs_find
0x61e3546e sqlite3_vfs_register
0x61e35558 sqlite3_vfs_unregister
0x61e42bdb sqlite3_vmprintf
0x61e2a162 sqlite3_vsnprintf
0x61e28a5e sqlite3_vtab_collation
0x61e2c884 sqlite3_vtab_config
0x61e04f40 sqlite3_vtab_distinct
0x61e04f02 sqlite3_vtab_in
0x61e51258 sqlite3_vtab_in_first
0x61e51269 sqlite3_vtab_in_next
0x61e03836 sqlite3_vtab_nochange
0x61e04ad3 sqlite3_vtab_on_conflict
0x61e2ef89 sqlite3_vtab_rhs_value
0x61e0e763 sqlite3_wal_autocheckpoint
0x61e8d633 sqlite3_wal_checkpoint
0x61e8d5ef sqlite3_wal_checkpoint_v2
0x61e05e49 sqlite3_wal_hook
0x61e335bf sqlite3_win32_is_nt
0x61eacf1a sqlite3_win32_mbcs_to_utf8
0x61eacf43 sqlite3_win32_mbcs_to_utf8_v2
0x61ead09e sqlite3_win32_set_directory
0x61ead052 sqlite3_win32_set_directory16
0x61eacfb8 sqlite3_win32_set_directory8
0x61e334a4 sqlite3_win32_sleep
0x61eacef9 sqlite3_win32_unicode_to_utf8
0x61eacf69 sqlite3_win32_utf8_to_mbcs
0x61eacf92 sqlite3_win32_utf8_to_mbcs_v2
0x61eaced8 sqlite3_win32_utf8_to_unicode
0x61e33442 sqlite3_win32_write_debug
0x61eaf33a sqlite3changegroup_add
0x61eaf39c sqlite3changegroup_add_strm
0x61eaf402 sqlite3changegroup_delete
0x61eaf551 sqlite3changegroup_new
0x61eaf380 sqlite3changegroup_output
0x61eaf3e2 sqlite3changegroup_output_strm
0x61eaf22d sqlite3changeset_apply
0x61eaf2ec sqlite3changeset_apply_strm
0x61eaf1c0 sqlite3changeset_apply_v2
0x61eaf27b sqlite3changeset_apply_v2_strm
0x61eaf4d6 sqlite3changeset_concat
0x61eaf45b sqlite3changeset_concat_strm
0x61eae4bf sqlite3changeset_conflict
0x61eae522 sqlite3changeset_finalize
0x61eae4ff sqlite3changeset_fk_conflicts
0x61eaf12b sqlite3changeset_invert
0x61eaf16a sqlite3changeset_invert_strm
0x61e0f49a sqlite3changeset_new
0x61eae458 sqlite3changeset_next
0x61e0f460 sqlite3changeset_old
0x61eae46f sqlite3changeset_op
0x61eae49f sqlite3changeset_pk
0x61eae390 sqlite3changeset_start
0x61eae3ef sqlite3changeset_start_strm
0x61eae3c1 sqlite3changeset_start_v2
0x61eae424 sqlite3changeset_start_v2_strm
0x61eaf55a sqlite3rebaser_configure
0x61eaf427 sqlite3rebaser_create
0x61eaf67a sqlite3rebaser_delete
0x61eaf5aa sqlite3rebaser_rebase
0x61eaf611 sqlite3rebaser_rebase_strm
0x61eadb8d sqlite3session_attach
0x61eae1b9 sqlite3session_changeset
0x61eae382 sqlite3session_changeset_size
0x61eae1e5 sqlite3session_changeset_strm
0x61eaf69f sqlite3session_config
0x61eada13 sqlite3session_create
0x61eadadf sqlite3session_delete
0x61eadce1 sqlite3session_diff
0x61eae277 sqlite3session_enable
0x61eae2b2 sqlite3session_indirect
0x61eae2ed sqlite3session_isempty
0x61eae338 sqlite3session_memory_used
0x61eae346 sqlite3session_object_config
0x61eae248 sqlite3session_patchset
0x61eae215 sqlite3session_patchset_strm
0x61eadb72 sqlite3session_table_filter


Similarity measure (PE file only) - Checking for service failure