ScreenShot
Created | 2023.10.06 18:40 | Machine | s1_win7_x6401 |
Filename | Cerber.exe | ||
Type | PE32 executable (GUI) Intel 80386, for MS Windows | ||
AI Score |
|
Behavior Score |
|
ZERO API | file : clean | ||
VT API (file) | 57 detected (malicious, high confidence, Siggen7, Cerber, Ransomware, CBER, Unsafe, Zerber, Save, ali2000010, ZexaF, Eq0@aymjM4dP, Genus, Eldorado, Filecoder, HPCERBER, SMALY5A, epfvib, Gencirc, R + Mal, EW@73u1y1, Static AI, Malicious PE, Krypt, Score, 100%, AGEN, ASMalwS, BScope, Generic@ML, RDML, 74HmFHENQ, +dFqwKEK17+Q, GenAsa, hwUIeNdKBl8, ai score=100, susgen, Kryptik, HGZD, Genetic, confidence) | ||
md5 | 8b3d0bc69064a0155a205a4202417330 | ||
sha256 | 9ef7fe10bbbb58899859d82ba7a698cbfdd546c6e9e4d3b55193e4180682036c | ||
ssdeep | 12288:ww+dKNr2YH7WQx3IjKoa+888888888888W888888888888:wVKMYbWzuBf | ||
imphash | fe586131a824714774b47ac27da9e046 | ||
impfuzzy | 192:ZXPGjRIwZnu1bKmvJ9iucsU8CVcIb/Dl1my9:ZXOIwo13J93HCV1zz9 |
Network IP location
Signature (18cnts)
Level | Description |
---|---|
danger | File has been identified by 57 AntiVirus engines on VirusTotal as malicious |
warning | Generates some ICMP traffic |
watch | Communicates with host for which no DNS query was performed |
watch | Operates on local firewall's policies and settings |
notice | A process created a hidden window |
notice | Allocates read-write-execute memory (usually to unpack itself) |
notice | Communication to multiple IPs on high port numbers possibly indicative of a peer-to-peer (P2P) or non-standard command and control protocol |
notice | Creates a shortcut to an executable file |
notice | Executes one or more WMI queries |
notice | Foreign language identified in PE resource |
notice | One or more potentially interesting buffers were extracted |
notice | Queries the disk size which could be used to detect virtual machine with small fixed size or dynamic allocation |
notice | Uses Windows utilities for basic Windows functionality |
info | Checks amount of memory in system |
info | Collects information to fingerprint the system (MachineGuid |
info | Command line console output was observed |
info | Queries for the computername |
info | The file contains an unknown PE resource name possibly indicative of a packer |
Rules (5cnts)
Level | Name | Description | Collection |
---|---|---|---|
watch | Admin_Tool_IN_Zero | Admin Tool Sysinternals | binaries (upload) |
watch | Malicious_Library_Zero | Malicious_Library | binaries (upload) |
watch | UPX_Zero | UPX packed file | binaries (upload) |
info | IsPE32 | (no description) | binaries (upload) |
info | PE_Header_Zero | PE File Signature | binaries (upload) |
Network (1088cnts) ?
Suricata ids
ET MALWARE Ransomware/Cerber Checkin M3 (2)
PE API
IAT(Import Address Table) Library
KERNEL32.dll
0x45618c CloseHandle
0x456190 DeleteCriticalSection
0x456194 EnterCriticalSection
0x456198 EnumLanguageGroupLocalesA
0x45619c ExitProcess
0x4561a0 FindClose
0x4561a4 FindFirstFileA
0x4561a8 FindNextFileA
0x4561ac FormatMessageA
0x4561b0 FreeEnvironmentStringsA
0x4561b4 FreeEnvironmentStringsW
0x4561b8 GetACP
0x4561bc GetCPInfo
0x4561c0 GetCommMask
0x4561c4 GetCommandLineA
0x4561c8 GetCurrentProcess
0x4561cc GetCurrentProcessId
0x4561d0 GetCurrentThreadId
0x4561d4 GetEnvironmentStrings
0x4561d8 GetEnvironmentStringsW
0x4561dc GetFileType
0x4561e0 GetLastError
0x4561e4 WriteFile
0x4561e8 WideCharToMultiByte
0x4561ec WaitForSingleObject
0x4561f0 VirtualFree
0x4561f4 VirtualAlloc
0x4561f8 VerifyVersionInfoW
0x4561fc UnhandledExceptionFilter
0x456200 TlsSetValue
0x456204 TlsGetValue
0x456208 TlsFree
0x45620c TlsAlloc
0x456210 Thread32Next
0x456214 TerminateProcess
0x456218 Sleep
0x45621c SetUnhandledExceptionFilter
0x456220 SetLocalTime
0x456224 SetLastError
0x456228 SetHandleCount
0x45622c SetConsoleScreenBufferSize
0x456230 RtlUnwind
0x456234 RaiseException
0x456238 QueryPerformanceCounter
0x45623c MultiByteToWideChar
0x456240 LocalFree
0x456244 LoadLibraryA
0x456248 LeaveCriticalSection
0x45624c LCMapStringW
0x456250 LCMapStringA
0x456254 IsValidCodePage
0x456258 IsDebuggerPresent
0x45625c InterlockedIncrement
0x456260 InterlockedDecrement
0x456264 InitializeCriticalSectionAndSpinCount
0x456268 HeapSize
0x45626c HeapReAlloc
0x456270 BeginUpdateResourceA
0x456274 HeapFree
0x456278 HeapCreate
0x45627c HeapAlloc
0x456280 GetVersionExA
0x456284 GetTickCount
0x456288 GetTempPathA
0x45628c GetSystemTimeAsFileTime
0x456290 GetStringTypeW
0x456294 GetStringTypeA
0x456298 GetStdHandle
0x45629c GetStartupInfoA
0x4562a0 GetProcAddress
0x4562a4 GetOEMCP
0x4562a8 GetModuleHandleW
0x4562ac GetModuleHandleA
0x4562b0 GetModuleFileNameA
0x4562b4 GetLocaleInfoA
USER32.dll
0x4562d8 LoadCursorFromFileA
0x4562dc CloseClipboard
0x4562e0 GetLastActivePopup
0x4562e4 GetMenuContextHelpId
0x4562e8 IsMenu
0x4562ec GetInputState
0x4562f0 GetKeyboardLayout
0x4562f4 CloseDesktop
0x4562f8 IsCharAlphaNumericA
0x4562fc GetWindowDC
0x456300 PaintDesktop
0x456304 GetActiveWindow
0x456308 CharUpperA
0x45630c IsWindow
0x456310 GetCaretBlinkTime
0x456314 GetClipboardSequenceNumber
0x456318 GetThreadDesktop
0x45631c CopyIcon
0x456320 GetCursor
0x456324 WindowFromDC
0x456328 LoadCursorFromFileW
0x45632c GetMenu
0x456330 GetProcessWindowStation
0x456334 EndMenu
0x456338 GetOpenClipboardWindow
0x45633c GetWindowTextLengthW
0x456340 IsGUIThread
0x456344 CharLowerA
0x456348 GetDialogBaseUnits
0x45634c IsCharLowerA
0x456350 ShowCaret
0x456354 GetKeyState
0x456358 GetMessageExtraInfo
0x45635c GetTopWindow
0x456360 CharNextA
0x456364 IsCharAlphaA
0x456368 DestroyIcon
0x45636c UserHandleGrantAccess
0x456370 TranslateMessage
0x456374 TranslateMDISysAccel
0x456378 ToAscii
0x45637c SystemParametersInfoW
0x456380 SetWindowTextW
0x456384 SetWindowRgn
0x456388 SetWindowPos
0x45638c SetWindowLongW
0x456390 SetTimer
0x456394 SetScrollInfo
0x456398 SetMenuContextHelpId
0x45639c SetForegroundWindow
0x4563a0 SetDlgItemTextW
0x4563a4 SetClipboardViewer
0x4563a8 SendMessageW
0x4563ac SendMessageTimeoutA
0x4563b0 SendInput
0x4563b4 SendDlgItemMessageW
0x4563b8 ReplyMessage
0x4563bc ReleaseDC
0x4563c0 ReleaseCapture
0x4563c4 RegisterWindowMessageW
0x4563c8 CharLowerW
0x4563cc RegisterClassExA
0x4563d0 PostThreadMessageW
0x4563d4 PostQuitMessage
0x4563d8 PostMessageW
0x4563dc OpenIcon
0x4563e0 OffsetRect
0x4563e4 MonitorFromRect
0x4563e8 MessageBoxW
0x4563ec MessageBoxA
0x4563f0 LoadStringW
0x4563f4 LoadKeyboardLayoutW
0x4563f8 LoadImageW
0x4563fc LoadBitmapW
0x456400 KillTimer
0x456404 IsWindowVisible
0x456408 IsWindowEnabled
0x45640c IsRectEmpty
0x456410 IsIconic
0x456414 IsCharUpperW
0x456418 InflateRect
0x45641c HiliteMenuItem
0x456420 GetWindowThreadProcessId
0x456424 GetWindowTextW
0x456428 GetWindowRect
0x45642c GetWindowLongW
0x456430 GetSystemMetrics
0x456434 GetSysColorBrush
0x456438 GetScrollPos
0x45643c GetMonitorInfoW
0x456440 GetMessageW
0x456444 GetMenuItemRect
0x456448 GetInputDesktop
0x45644c GetDlgItem
0x456450 GetDlgCtrlID
0x456454 GetDesktopWindow
0x456458 GetDC
0x45645c GetCursorPos
0x456460 GetClientRect
0x456464 GetClassNameW
0x456468 GetClassLongW
0x45646c FindWindowW
0x456470 FillRect
0x456474 EnumWindows
0x456478 EnumWindowStationsA
0x45647c EnumThreadWindows
0x456480 EnumDisplaySettingsW
0x456484 EnumDisplayDevicesW
0x456488 EndDialog
0x45648c DispatchMessageW
0x456490 DestroyWindow
0x456494 DefWindowProcW
0x456498 CreateWindowExW
0x45649c CreateMenu
0x4564a0 CreateIconIndirect
0x4564a4 CreateIconFromResourceEx
0x4564a8 CreateIcon
0x4564ac CreateDialogIndirectParamW
0x4564b0 IsCharAlphaNumericW
0x4564b4 DestroyCursor
0x4564b8 VkKeyScanA
0x4564bc VkKeyScanW
0x4564c0 CopyRect
0x4564c4 CloseWindow
0x4564c8 CharNextW
0x4564cc ChangeDisplaySettingsExW
0x4564d0 GetQueueStatus
0x4564d4 RegisterClipboardFormatA
0x4564d8 GetSysColor
0x4564dc CallWindowProcW
0x4564e0 ShowWindow
GDI32.dll
0x45605c CreateMetaFileA
0x456060 AddFontResourceExW
0x456064 AngleArc
0x456068 CloseEnhMetaFile
0x45606c CopyEnhMetaFileA
0x456070 CreateColorSpaceW
0x456074 CreateCompatibleDC
0x456078 CreateFontA
0x45607c CreateFontIndirectW
0x456080 CreateSolidBrush
0x456084 DeleteObject
0x456088 EngCreateDeviceSurface
0x45608c EngCreatePalette
0x456090 EngDeleteSurface
0x456094 EngFillPath
0x456098 EngPaint
0x45609c EngTextOut
0x4560a0 FillRgn
0x4560a4 FlattenPath
0x4560a8 FloodFill
0x4560ac FontIsLinked
0x4560b0 GdiAlphaBlend
0x4560b4 GdiConvertBrush
0x4560b8 GdiDeleteSpoolFileHandle
0x4560bc GdiEntry8
0x4560c0 GdiPlayJournal
0x4560c4 GdiPlayPrivatePageEMF
0x4560c8 GdiSetBatchLimit
0x4560cc GetCharABCWidthsFloatW
0x4560d0 GetCharABCWidthsW
0x4560d4 GetCurrentPositionEx
0x4560d8 GetDeviceCaps
0x4560dc GetEnhMetaFileW
0x4560e0 GetFontData
0x4560e4 GetGlyphIndicesA
0x4560e8 GetObjectW
0x4560ec GetTextExtentExPointWPri
0x4560f0 GetWinMetaFileBits
0x4560f4 ModifyWorldTransform
0x4560f8 NamedEscape
0x4560fc PathToRegion
0x456100 PolyDraw
0x456104 ScaleViewportExtEx
0x456108 SetDIBColorTable
0x45610c SetMetaRgn
0x456110 SetPolyFillMode
0x456114 SetROP2
0x456118 SetTextAlign
0x45611c UpdateColors
0x456120 GetSystemPaletteUse
0x456124 CreateMetaFileW
0x456128 EndDoc
0x45612c DeleteEnhMetaFile
0x456130 BeginPath
0x456134 CreatePatternBrush
0x456138 GetTextCharacterExtra
0x45613c CancelDC
0x456140 GdiGetBatchLimit
0x456144 GetColorSpace
0x456148 EndPath
0x45614c EndPage
0x456150 SaveDC
0x456154 SwapBuffers
0x456158 CloseMetaFile
0x45615c GetDCPenColor
0x456160 AbortDoc
0x456164 GetTextCharset
0x456168 GdiFlush
0x45616c FillPath
0x456170 CloseFigure
0x456174 GetTextAlign
0x456178 GetMapMode
0x45617c GetBkMode
0x456180 GetStretchBltMode
0x456184 AbortPath
ADVAPI32.dll
0x456000 RegOpenKeyExA
0x456004 CryptAcquireContextW
0x456008 CryptCreateHash
0x45600c CryptDestroyHash
0x456010 CryptGetHashParam
0x456014 CryptHashData
0x456018 CryptReleaseContext
0x45601c RegCloseKey
0x456020 RegCreateKeyExW
0x456024 RegDeleteKeyW
0x456028 RegDeleteValueA
0x45602c RegOpenKeyW
0x456030 RegQueryValueExA
0x456034 RegSetValueExA
0x456038 RegSetValueExW
0x45603c RegQueryValueExW
SHELL32.dll
0x4562bc SHGetFolderPathW
0x4562c0 CommandLineToArgvW
0x4562c4 ShellExecuteExA
ole32.dll
0x456550 CoInitialize
0x456554 CoUninitialize
0x456558 CoCreateInstance
SHLWAPI.dll
0x4562cc StrCmpNA
0x4562d0 StrStrA
COMCTL32.dll
0x456044 ImageList_AddMasked
0x456048 InitCommonControlsEx
0x45604c ImageList_Destroy
0x456050 ImageList_Create
0x456054 CreateStatusWindowW
msvcrt.dll
0x4564e8 _except_handler3
0x4564ec wcslen
0x4564f0 wcscpy
0x4564f4 wcscmp
0x4564f8 _XcptFilter
0x4564fc __dllonexit
0x456500 __p__commode
0x456504 __p__fmode
0x456508 __set_app_type
0x45650c __setusermatherr
0x456510 __wgetmainargs
0x456514 _adjust_fdiv
0x456518 _c_exit
0x45651c _cexit
0x456520 _controlfp
0x456524 _exit
0x456528 _initterm
0x45652c _onexit
0x456530 _purecall
0x456534 _snwprintf
0x456538 _wcmdln
0x45653c _wcsicmp
0x456540 _wcsnicmp
0x456544 exit
0x456548 wcscat
EAT(Export Address Table) is none
KERNEL32.dll
0x45618c CloseHandle
0x456190 DeleteCriticalSection
0x456194 EnterCriticalSection
0x456198 EnumLanguageGroupLocalesA
0x45619c ExitProcess
0x4561a0 FindClose
0x4561a4 FindFirstFileA
0x4561a8 FindNextFileA
0x4561ac FormatMessageA
0x4561b0 FreeEnvironmentStringsA
0x4561b4 FreeEnvironmentStringsW
0x4561b8 GetACP
0x4561bc GetCPInfo
0x4561c0 GetCommMask
0x4561c4 GetCommandLineA
0x4561c8 GetCurrentProcess
0x4561cc GetCurrentProcessId
0x4561d0 GetCurrentThreadId
0x4561d4 GetEnvironmentStrings
0x4561d8 GetEnvironmentStringsW
0x4561dc GetFileType
0x4561e0 GetLastError
0x4561e4 WriteFile
0x4561e8 WideCharToMultiByte
0x4561ec WaitForSingleObject
0x4561f0 VirtualFree
0x4561f4 VirtualAlloc
0x4561f8 VerifyVersionInfoW
0x4561fc UnhandledExceptionFilter
0x456200 TlsSetValue
0x456204 TlsGetValue
0x456208 TlsFree
0x45620c TlsAlloc
0x456210 Thread32Next
0x456214 TerminateProcess
0x456218 Sleep
0x45621c SetUnhandledExceptionFilter
0x456220 SetLocalTime
0x456224 SetLastError
0x456228 SetHandleCount
0x45622c SetConsoleScreenBufferSize
0x456230 RtlUnwind
0x456234 RaiseException
0x456238 QueryPerformanceCounter
0x45623c MultiByteToWideChar
0x456240 LocalFree
0x456244 LoadLibraryA
0x456248 LeaveCriticalSection
0x45624c LCMapStringW
0x456250 LCMapStringA
0x456254 IsValidCodePage
0x456258 IsDebuggerPresent
0x45625c InterlockedIncrement
0x456260 InterlockedDecrement
0x456264 InitializeCriticalSectionAndSpinCount
0x456268 HeapSize
0x45626c HeapReAlloc
0x456270 BeginUpdateResourceA
0x456274 HeapFree
0x456278 HeapCreate
0x45627c HeapAlloc
0x456280 GetVersionExA
0x456284 GetTickCount
0x456288 GetTempPathA
0x45628c GetSystemTimeAsFileTime
0x456290 GetStringTypeW
0x456294 GetStringTypeA
0x456298 GetStdHandle
0x45629c GetStartupInfoA
0x4562a0 GetProcAddress
0x4562a4 GetOEMCP
0x4562a8 GetModuleHandleW
0x4562ac GetModuleHandleA
0x4562b0 GetModuleFileNameA
0x4562b4 GetLocaleInfoA
USER32.dll
0x4562d8 LoadCursorFromFileA
0x4562dc CloseClipboard
0x4562e0 GetLastActivePopup
0x4562e4 GetMenuContextHelpId
0x4562e8 IsMenu
0x4562ec GetInputState
0x4562f0 GetKeyboardLayout
0x4562f4 CloseDesktop
0x4562f8 IsCharAlphaNumericA
0x4562fc GetWindowDC
0x456300 PaintDesktop
0x456304 GetActiveWindow
0x456308 CharUpperA
0x45630c IsWindow
0x456310 GetCaretBlinkTime
0x456314 GetClipboardSequenceNumber
0x456318 GetThreadDesktop
0x45631c CopyIcon
0x456320 GetCursor
0x456324 WindowFromDC
0x456328 LoadCursorFromFileW
0x45632c GetMenu
0x456330 GetProcessWindowStation
0x456334 EndMenu
0x456338 GetOpenClipboardWindow
0x45633c GetWindowTextLengthW
0x456340 IsGUIThread
0x456344 CharLowerA
0x456348 GetDialogBaseUnits
0x45634c IsCharLowerA
0x456350 ShowCaret
0x456354 GetKeyState
0x456358 GetMessageExtraInfo
0x45635c GetTopWindow
0x456360 CharNextA
0x456364 IsCharAlphaA
0x456368 DestroyIcon
0x45636c UserHandleGrantAccess
0x456370 TranslateMessage
0x456374 TranslateMDISysAccel
0x456378 ToAscii
0x45637c SystemParametersInfoW
0x456380 SetWindowTextW
0x456384 SetWindowRgn
0x456388 SetWindowPos
0x45638c SetWindowLongW
0x456390 SetTimer
0x456394 SetScrollInfo
0x456398 SetMenuContextHelpId
0x45639c SetForegroundWindow
0x4563a0 SetDlgItemTextW
0x4563a4 SetClipboardViewer
0x4563a8 SendMessageW
0x4563ac SendMessageTimeoutA
0x4563b0 SendInput
0x4563b4 SendDlgItemMessageW
0x4563b8 ReplyMessage
0x4563bc ReleaseDC
0x4563c0 ReleaseCapture
0x4563c4 RegisterWindowMessageW
0x4563c8 CharLowerW
0x4563cc RegisterClassExA
0x4563d0 PostThreadMessageW
0x4563d4 PostQuitMessage
0x4563d8 PostMessageW
0x4563dc OpenIcon
0x4563e0 OffsetRect
0x4563e4 MonitorFromRect
0x4563e8 MessageBoxW
0x4563ec MessageBoxA
0x4563f0 LoadStringW
0x4563f4 LoadKeyboardLayoutW
0x4563f8 LoadImageW
0x4563fc LoadBitmapW
0x456400 KillTimer
0x456404 IsWindowVisible
0x456408 IsWindowEnabled
0x45640c IsRectEmpty
0x456410 IsIconic
0x456414 IsCharUpperW
0x456418 InflateRect
0x45641c HiliteMenuItem
0x456420 GetWindowThreadProcessId
0x456424 GetWindowTextW
0x456428 GetWindowRect
0x45642c GetWindowLongW
0x456430 GetSystemMetrics
0x456434 GetSysColorBrush
0x456438 GetScrollPos
0x45643c GetMonitorInfoW
0x456440 GetMessageW
0x456444 GetMenuItemRect
0x456448 GetInputDesktop
0x45644c GetDlgItem
0x456450 GetDlgCtrlID
0x456454 GetDesktopWindow
0x456458 GetDC
0x45645c GetCursorPos
0x456460 GetClientRect
0x456464 GetClassNameW
0x456468 GetClassLongW
0x45646c FindWindowW
0x456470 FillRect
0x456474 EnumWindows
0x456478 EnumWindowStationsA
0x45647c EnumThreadWindows
0x456480 EnumDisplaySettingsW
0x456484 EnumDisplayDevicesW
0x456488 EndDialog
0x45648c DispatchMessageW
0x456490 DestroyWindow
0x456494 DefWindowProcW
0x456498 CreateWindowExW
0x45649c CreateMenu
0x4564a0 CreateIconIndirect
0x4564a4 CreateIconFromResourceEx
0x4564a8 CreateIcon
0x4564ac CreateDialogIndirectParamW
0x4564b0 IsCharAlphaNumericW
0x4564b4 DestroyCursor
0x4564b8 VkKeyScanA
0x4564bc VkKeyScanW
0x4564c0 CopyRect
0x4564c4 CloseWindow
0x4564c8 CharNextW
0x4564cc ChangeDisplaySettingsExW
0x4564d0 GetQueueStatus
0x4564d4 RegisterClipboardFormatA
0x4564d8 GetSysColor
0x4564dc CallWindowProcW
0x4564e0 ShowWindow
GDI32.dll
0x45605c CreateMetaFileA
0x456060 AddFontResourceExW
0x456064 AngleArc
0x456068 CloseEnhMetaFile
0x45606c CopyEnhMetaFileA
0x456070 CreateColorSpaceW
0x456074 CreateCompatibleDC
0x456078 CreateFontA
0x45607c CreateFontIndirectW
0x456080 CreateSolidBrush
0x456084 DeleteObject
0x456088 EngCreateDeviceSurface
0x45608c EngCreatePalette
0x456090 EngDeleteSurface
0x456094 EngFillPath
0x456098 EngPaint
0x45609c EngTextOut
0x4560a0 FillRgn
0x4560a4 FlattenPath
0x4560a8 FloodFill
0x4560ac FontIsLinked
0x4560b0 GdiAlphaBlend
0x4560b4 GdiConvertBrush
0x4560b8 GdiDeleteSpoolFileHandle
0x4560bc GdiEntry8
0x4560c0 GdiPlayJournal
0x4560c4 GdiPlayPrivatePageEMF
0x4560c8 GdiSetBatchLimit
0x4560cc GetCharABCWidthsFloatW
0x4560d0 GetCharABCWidthsW
0x4560d4 GetCurrentPositionEx
0x4560d8 GetDeviceCaps
0x4560dc GetEnhMetaFileW
0x4560e0 GetFontData
0x4560e4 GetGlyphIndicesA
0x4560e8 GetObjectW
0x4560ec GetTextExtentExPointWPri
0x4560f0 GetWinMetaFileBits
0x4560f4 ModifyWorldTransform
0x4560f8 NamedEscape
0x4560fc PathToRegion
0x456100 PolyDraw
0x456104 ScaleViewportExtEx
0x456108 SetDIBColorTable
0x45610c SetMetaRgn
0x456110 SetPolyFillMode
0x456114 SetROP2
0x456118 SetTextAlign
0x45611c UpdateColors
0x456120 GetSystemPaletteUse
0x456124 CreateMetaFileW
0x456128 EndDoc
0x45612c DeleteEnhMetaFile
0x456130 BeginPath
0x456134 CreatePatternBrush
0x456138 GetTextCharacterExtra
0x45613c CancelDC
0x456140 GdiGetBatchLimit
0x456144 GetColorSpace
0x456148 EndPath
0x45614c EndPage
0x456150 SaveDC
0x456154 SwapBuffers
0x456158 CloseMetaFile
0x45615c GetDCPenColor
0x456160 AbortDoc
0x456164 GetTextCharset
0x456168 GdiFlush
0x45616c FillPath
0x456170 CloseFigure
0x456174 GetTextAlign
0x456178 GetMapMode
0x45617c GetBkMode
0x456180 GetStretchBltMode
0x456184 AbortPath
ADVAPI32.dll
0x456000 RegOpenKeyExA
0x456004 CryptAcquireContextW
0x456008 CryptCreateHash
0x45600c CryptDestroyHash
0x456010 CryptGetHashParam
0x456014 CryptHashData
0x456018 CryptReleaseContext
0x45601c RegCloseKey
0x456020 RegCreateKeyExW
0x456024 RegDeleteKeyW
0x456028 RegDeleteValueA
0x45602c RegOpenKeyW
0x456030 RegQueryValueExA
0x456034 RegSetValueExA
0x456038 RegSetValueExW
0x45603c RegQueryValueExW
SHELL32.dll
0x4562bc SHGetFolderPathW
0x4562c0 CommandLineToArgvW
0x4562c4 ShellExecuteExA
ole32.dll
0x456550 CoInitialize
0x456554 CoUninitialize
0x456558 CoCreateInstance
SHLWAPI.dll
0x4562cc StrCmpNA
0x4562d0 StrStrA
COMCTL32.dll
0x456044 ImageList_AddMasked
0x456048 InitCommonControlsEx
0x45604c ImageList_Destroy
0x456050 ImageList_Create
0x456054 CreateStatusWindowW
msvcrt.dll
0x4564e8 _except_handler3
0x4564ec wcslen
0x4564f0 wcscpy
0x4564f4 wcscmp
0x4564f8 _XcptFilter
0x4564fc __dllonexit
0x456500 __p__commode
0x456504 __p__fmode
0x456508 __set_app_type
0x45650c __setusermatherr
0x456510 __wgetmainargs
0x456514 _adjust_fdiv
0x456518 _c_exit
0x45651c _cexit
0x456520 _controlfp
0x456524 _exit
0x456528 _initterm
0x45652c _onexit
0x456530 _purecall
0x456534 _snwprintf
0x456538 _wcmdln
0x45653c _wcsicmp
0x456540 _wcsnicmp
0x456544 exit
0x456548 wcscat
EAT(Export Address Table) is none