Report - clientPower.exe

Malicious Library UPX Malicious Packer Admin Tool (Sysinternals etc ...) PE File PE32 MZP Format OS Processor Check
ScreenShot
Created 2023.10.12 14:54 Machine s1_win7_x6401
Filename clientPower.exe
Type PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
AI Score
4
Behavior Score
3.0
ZERO API file : clean
VT API (file) 19 detected (Artemis, Rugmi, arpkk, PRIVATELOADER, YXDJKZ, Detected, Wacatac, TScope, Delf, unsafe, CLOUD, MALICIOUS)
md5 96a2d507409c68e291e2d473a2d35ae0
sha256 265122b7fb9dd7b3c4cf0adbcc046d84b33693c2ba49c5bfede1de48f24acbc7
ssdeep 98304:K/9GEgliiRbu0qX0xWAlydfrNxqXiEmNkwq3EZtabizHq:KQlA0xLMNsia3csWHq
imphash d32ac74ff74175a30930b71116dcf55b
impfuzzy 192:ccdqD9KyFx26wI3uEUQimHBQdOGoV2DzDuQTFTfOcAzvIB/pF1OT9:ccEUD660BQdOGPDzDuQpCPIdBo9
  Network IP location

Signature (9cnts)

Level Description
watch File has been identified by 19 AntiVirus engines on VirusTotal as malicious
notice Allocates read-write-execute memory (usually to unpack itself)
notice Expresses interest in specific running processes
notice Searches running processes potentially to identify processes for sandbox evasion
notice The binary likely contains encrypted or compressed data indicative of a packer
info One or more processes crashed
info The executable contains unknown PE section names indicative of a packer (could be a false positive)
info The executable uses a known packer
info The file contains an unknown PE resource name possibly indicative of a packer

Rules (8cnts)

Level Name Description Collection
watch Admin_Tool_IN_Zero Admin Tool Sysinternals binaries (upload)
watch Malicious_Library_Zero Malicious_Library binaries (upload)
watch Malicious_Packer_Zero Malicious Packer binaries (upload)
watch UPX_Zero UPX packed file binaries (upload)
info IsPE32 (no description) binaries (upload)
info mzp_file_format MZP(Delphi) file format binaries (upload)
info OS_Processor_Check_Zero OS Processor Check binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids

PE API

IAT(Import Address Table) Library

winmm.dll
 0x7bdae0 timeGetTime
oleacc.dll
 0x7bdae8 LresultFromObject
shlwapi.dll
 0x7bdaf0 PathCombineW
wininet.dll
 0x7bdaf8 InternetCanonicalizeUrlW
winspool.drv
 0x7bdb00 DocumentPropertiesW
 0x7bdb04 ClosePrinter
 0x7bdb08 OpenPrinterW
 0x7bdb0c GetDefaultPrinterW
 0x7bdb10 EnumPrintersW
comctl32.dll
 0x7bdb18 ImageList_GetImageInfo
 0x7bdb1c FlatSB_SetScrollInfo
 0x7bdb20 ImageList_DragMove
 0x7bdb24 ImageList_Destroy
 0x7bdb28 _TrackMouseEvent
 0x7bdb2c ImageList_DragShowNolock
 0x7bdb30 ImageList_Add
 0x7bdb34 FlatSB_SetScrollProp
 0x7bdb38 ImageList_GetDragImage
 0x7bdb3c ImageList_Create
 0x7bdb40 ImageList_EndDrag
 0x7bdb44 ImageList_DrawEx
 0x7bdb48 ImageList_SetImageCount
 0x7bdb4c FlatSB_GetScrollPos
 0x7bdb50 FlatSB_SetScrollPos
 0x7bdb54 InitializeFlatSB
 0x7bdb58 ImageList_Copy
 0x7bdb5c FlatSB_GetScrollInfo
 0x7bdb60 ImageList_Write
 0x7bdb64 ImageList_DrawIndirect
 0x7bdb68 ImageList_SetBkColor
 0x7bdb6c ImageList_GetBkColor
 0x7bdb70 ImageList_BeginDrag
 0x7bdb74 ImageList_GetIcon
 0x7bdb78 ImageList_Replace
 0x7bdb7c ImageList_GetImageCount
 0x7bdb80 ImageList_DragEnter
 0x7bdb84 ImageList_GetIconSize
 0x7bdb88 ImageList_SetIconSize
 0x7bdb8c ImageList_Read
 0x7bdb90 ImageList_DragLeave
 0x7bdb94 ImageList_LoadImageW
 0x7bdb98 ImageList_Draw
 0x7bdb9c ImageList_Remove
 0x7bdba0 ImageList_ReplaceIcon
 0x7bdba4 ImageList_SetOverlayImage
shell32.dll
 0x7bdbac SHGetFolderPathW
 0x7bdbb0 Shell_NotifyIconW
 0x7bdbb4 ShellExecuteW
user32.dll
 0x7bdbbc CopyImage
 0x7bdbc0 SetMenuItemInfoW
 0x7bdbc4 GetMenuItemInfoW
 0x7bdbc8 DefFrameProcW
 0x7bdbcc GetDlgCtrlID
 0x7bdbd0 FrameRect
 0x7bdbd4 RegisterWindowMessageW
 0x7bdbd8 GetMenuStringW
 0x7bdbdc FillRect
 0x7bdbe0 SendMessageA
 0x7bdbe4 EnumWindows
 0x7bdbe8 ShowOwnedPopups
 0x7bdbec GetClassInfoW
 0x7bdbf0 GetScrollRange
 0x7bdbf4 SetActiveWindow
 0x7bdbf8 GetActiveWindow
 0x7bdbfc DrawEdge
 0x7bdc00 GetKeyboardLayoutList
 0x7bdc04 LoadBitmapW
 0x7bdc08 EnumChildWindows
 0x7bdc0c SendNotifyMessageW
 0x7bdc10 GetScrollBarInfo
 0x7bdc14 UnhookWindowsHookEx
 0x7bdc18 SetCapture
 0x7bdc1c GetCapture
 0x7bdc20 ShowCaret
 0x7bdc24 CreatePopupMenu
 0x7bdc28 GetMenuItemID
 0x7bdc2c CharLowerBuffW
 0x7bdc30 PostMessageW
 0x7bdc34 SetWindowLongW
 0x7bdc38 IsZoomed
 0x7bdc3c SetParent
 0x7bdc40 DrawMenuBar
 0x7bdc44 GetClientRect
 0x7bdc48 IsChild
 0x7bdc4c IsIconic
 0x7bdc50 CallNextHookEx
 0x7bdc54 ShowWindow
 0x7bdc58 GetWindowTextW
 0x7bdc5c SetForegroundWindow
 0x7bdc60 IsDialogMessageW
 0x7bdc64 DestroyWindow
 0x7bdc68 RegisterClassW
 0x7bdc6c EndMenu
 0x7bdc70 CharNextW
 0x7bdc74 GetFocus
 0x7bdc78 GetDC
 0x7bdc7c SetFocus
 0x7bdc80 ReleaseDC
 0x7bdc84 GetClassLongW
 0x7bdc88 SetScrollRange
 0x7bdc8c DrawTextW
 0x7bdc90 PeekMessageA
 0x7bdc94 MessageBeep
 0x7bdc98 SetClassLongW
 0x7bdc9c InSendMessage
 0x7bdca0 LockWindowUpdate
 0x7bdca4 RemovePropW
 0x7bdca8 GetSubMenu
 0x7bdcac EqualRect
 0x7bdcb0 DestroyIcon
 0x7bdcb4 IsWindowVisible
 0x7bdcb8 FlashWindowEx
 0x7bdcbc PtInRect
 0x7bdcc0 DispatchMessageA
 0x7bdcc4 UnregisterClassW
 0x7bdcc8 GetTopWindow
 0x7bdccc SendMessageW
 0x7bdcd0 GetMessageTime
 0x7bdcd4 NotifyWinEvent
 0x7bdcd8 SendMessageTimeoutW
 0x7bdcdc LoadStringW
 0x7bdce0 CreateMenu
 0x7bdce4 CharLowerW
 0x7bdce8 GetWindowRgn
 0x7bdcec SetWindowRgn
 0x7bdcf0 SetWindowPos
 0x7bdcf4 GetMenuItemCount
 0x7bdcf8 GetSysColorBrush
 0x7bdcfc GetWindowDC
 0x7bdd00 DrawTextExW
 0x7bdd04 ScrollDC
 0x7bdd08 GetScrollInfo
 0x7bdd0c SetWindowTextW
 0x7bdd10 GetMessageExtraInfo
 0x7bdd14 GetSysColor
 0x7bdd18 EnableScrollBar
 0x7bdd1c TrackPopupMenu
 0x7bdd20 DrawIconEx
 0x7bdd24 GetClassNameW
 0x7bdd28 GetMessagePos
 0x7bdd2c GetIconInfo
 0x7bdd30 SetScrollInfo
 0x7bdd34 GetKeyNameTextW
 0x7bdd38 GetDesktopWindow
 0x7bdd3c SetCursorPos
 0x7bdd40 GetCursorPos
 0x7bdd44 SetMenu
 0x7bdd48 GetMenuState
 0x7bdd4c GetMenu
 0x7bdd50 SetRect
 0x7bdd54 GetKeyState
 0x7bdd58 GetCursor
 0x7bdd5c KillTimer
 0x7bdd60 BeginDeferWindowPos
 0x7bdd64 WaitMessage
 0x7bdd68 TranslateMDISysAccel
 0x7bdd6c GetWindowPlacement
 0x7bdd70 GetClipboardFormatNameW
 0x7bdd74 CreateIconIndirect
 0x7bdd78 CreateWindowExW
 0x7bdd7c GetDCEx
 0x7bdd80 PeekMessageW
 0x7bdd84 MonitorFromWindow
 0x7bdd88 GetUpdateRect
 0x7bdd8c MessageBoxA
 0x7bdd90 SetTimer
 0x7bdd94 WindowFromPoint
 0x7bdd98 BeginPaint
 0x7bdd9c RegisterClipboardFormatW
 0x7bdda0 MapVirtualKeyW
 0x7bdda4 OffsetRect
 0x7bdda8 IsWindowUnicode
 0x7bddac DispatchMessageW
 0x7bddb0 CreateAcceleratorTableW
 0x7bddb4 DefMDIChildProcW
 0x7bddb8 GetSystemMenu
 0x7bddbc SetScrollPos
 0x7bddc0 GetScrollPos
 0x7bddc4 DrawFocusRect
 0x7bddc8 ReleaseCapture
 0x7bddcc LoadCursorW
 0x7bddd0 ScrollWindow
 0x7bddd4 GetLastActivePopup
 0x7bddd8 GetCursorInfo
 0x7bdddc GetSystemMetrics
 0x7bdde0 CharUpperBuffW
 0x7bdde4 SetClipboardData
 0x7bdde8 GetClipboardData
 0x7bddec ClientToScreen
 0x7bddf0 SetWindowPlacement
 0x7bddf4 GetMonitorInfoW
 0x7bddf8 CheckMenuItem
 0x7bddfc CharUpperW
 0x7bde00 DefWindowProcW
 0x7bde04 GetForegroundWindow
 0x7bde08 ToAscii
 0x7bde0c EnableWindow
 0x7bde10 GetWindowThreadProcessId
 0x7bde14 RedrawWindow
 0x7bde18 EndPaint
 0x7bde1c MsgWaitForMultipleObjectsEx
 0x7bde20 LoadKeyboardLayoutW
 0x7bde24 ActivateKeyboardLayout
 0x7bde28 GetParent
 0x7bde2c MonitorFromRect
 0x7bde30 InsertMenuItemW
 0x7bde34 GetPropW
 0x7bde38 MessageBoxW
 0x7bde3c SetPropW
 0x7bde40 UpdateWindow
 0x7bde44 MsgWaitForMultipleObjects
 0x7bde48 DestroyMenu
 0x7bde4c SetWindowsHookExW
 0x7bde50 GetDoubleClickTime
 0x7bde54 EmptyClipboard
 0x7bde58 AdjustWindowRectEx
 0x7bde5c IsWindow
 0x7bde60 DrawIcon
 0x7bde64 EnumThreadWindows
 0x7bde68 InvalidateRect
 0x7bde6c GetKeyboardState
 0x7bde70 ScreenToClient
 0x7bde74 DrawFrameControl
 0x7bde78 SetCursor
 0x7bde7c CreateIcon
 0x7bde80 RemoveMenu
 0x7bde84 SubtractRect
 0x7bde88 GetKeyboardLayoutNameW
 0x7bde8c OpenClipboard
 0x7bde90 TranslateMessage
 0x7bde94 MapWindowPoints
 0x7bde98 EnumDisplayMonitors
 0x7bde9c CallWindowProcW
 0x7bdea0 CloseClipboard
 0x7bdea4 DestroyCursor
 0x7bdea8 CopyIcon
 0x7bdeac PostQuitMessage
 0x7bdeb0 ShowScrollBar
 0x7bdeb4 EnableMenuItem
 0x7bdeb8 DeferWindowPos
 0x7bdebc HideCaret
 0x7bdec0 EndDeferWindowPos
 0x7bdec4 FindWindowExW
 0x7bdec8 MonitorFromPoint
 0x7bdecc LoadIconW
 0x7bded0 SystemParametersInfoW
 0x7bded4 GetWindow
 0x7bded8 GetWindowLongW
 0x7bdedc GetWindowRect
 0x7bdee0 InsertMenuW
 0x7bdee4 IsWindowEnabled
 0x7bdee8 IsDialogMessageA
 0x7bdeec FindWindowW
 0x7bdef0 GetKeyboardLayout
 0x7bdef4 DeleteMenu
version.dll
 0x7bdefc GetFileVersionInfoSizeW
 0x7bdf00 VerQueryValueW
 0x7bdf04 GetFileVersionInfoW
oleaut32.dll
 0x7bdf0c SysFreeString
 0x7bdf10 VariantClear
 0x7bdf14 VariantInit
 0x7bdf18 GetErrorInfo
 0x7bdf1c SysReAllocStringLen
 0x7bdf20 SafeArrayCreate
 0x7bdf24 GetActiveObject
 0x7bdf28 SysAllocStringLen
 0x7bdf2c SafeArrayPtrOfIndex
 0x7bdf30 SafeArrayGetUBound
 0x7bdf34 SafeArrayGetLBound
 0x7bdf38 VariantCopy
 0x7bdf3c VariantChangeType
advapi32.dll
 0x7bdf44 ConvertStringSecurityDescriptorToSecurityDescriptorW
 0x7bdf48 RegSetValueExW
 0x7bdf4c RegConnectRegistryW
 0x7bdf50 RegEnumKeyExW
 0x7bdf54 RegLoadKeyW
 0x7bdf58 RegDeleteKeyW
 0x7bdf5c GetSecurityDescriptorSacl
 0x7bdf60 RegOpenKeyExW
 0x7bdf64 RegQueryInfoKeyW
 0x7bdf68 RegUnLoadKeyW
 0x7bdf6c RegSaveKeyW
 0x7bdf70 RegDeleteValueW
 0x7bdf74 RegReplaceKeyW
 0x7bdf78 RegFlushKey
 0x7bdf7c RegEnumValueW
 0x7bdf80 RegQueryValueExW
 0x7bdf84 InitializeSecurityDescriptor
 0x7bdf88 RegCloseKey
 0x7bdf8c RegCreateKeyExW
 0x7bdf90 SetSecurityDescriptorDacl
 0x7bdf94 RegRestoreKeyW
netapi32.dll
 0x7bdf9c NetWkstaGetInfo
 0x7bdfa0 NetApiBufferFree
kernel32.dll
 0x7bdfa8 QueryDosDeviceW
 0x7bdfac GetACP
 0x7bdfb0 LocalFree
 0x7bdfb4 CloseHandle
 0x7bdfb8 GetCurrentProcessId
 0x7bdfbc SizeofResource
 0x7bdfc0 VirtualProtect
 0x7bdfc4 lstrcmpiW
 0x7bdfc8 QueryPerformanceFrequency
 0x7bdfcc IsDebuggerPresent
 0x7bdfd0 FlushInstructionCache
 0x7bdfd4 GetFullPathNameW
 0x7bdfd8 VirtualFree
 0x7bdfdc ExitProcess
 0x7bdfe0 HeapAlloc
 0x7bdfe4 GetCPInfoExW
 0x7bdfe8 GlobalSize
 0x7bdfec GetSystemTime
 0x7bdff0 GetLongPathNameW
 0x7bdff4 RtlUnwind
 0x7bdff8 GetCPInfo
 0x7bdffc EnumSystemLocalesW
 0x7be000 GetStdHandle
 0x7be004 GetTimeZoneInformation
 0x7be008 DisconnectNamedPipe
 0x7be00c GetModuleHandleW
 0x7be010 FreeLibrary
 0x7be014 TryEnterCriticalSection
 0x7be018 HeapDestroy
 0x7be01c ReadFile
 0x7be020 GetUserDefaultLCID
 0x7be024 CreateProcessW
 0x7be028 GetLastError
 0x7be02c GetModuleFileNameW
 0x7be030 WaitNamedPipeW
 0x7be034 SetLastError
 0x7be038 GlobalAlloc
 0x7be03c GlobalUnlock
 0x7be040 FindResourceW
 0x7be044 CreateThread
 0x7be048 CompareStringW
 0x7be04c MapViewOfFile
 0x7be050 CreateMutexW
 0x7be054 LoadLibraryA
 0x7be058 ResetEvent
 0x7be05c MulDiv
 0x7be060 FreeResource
 0x7be064 GetDriveTypeW
 0x7be068 GetVersion
 0x7be06c RaiseException
 0x7be070 GlobalAddAtomW
 0x7be074 FormatMessageW
 0x7be078 OpenProcess
 0x7be07c SwitchToThread
 0x7be080 GetExitCodeThread
 0x7be084 GetCurrentThread
 0x7be088 SetNamedPipeHandleState
 0x7be08c LoadLibraryExW
 0x7be090 LockResource
 0x7be094 CancelIo
 0x7be098 GetShortPathNameW
 0x7be09c GetCurrentThreadId
 0x7be0a0 UnhandledExceptionFilter
 0x7be0a4 PeekNamedPipe
 0x7be0a8 VirtualQuery
 0x7be0ac GlobalFindAtomW
 0x7be0b0 VirtualQueryEx
 0x7be0b4 GlobalFree
 0x7be0b8 Sleep
 0x7be0bc EnterCriticalSection
 0x7be0c0 SetFilePointer
 0x7be0c4 ReleaseMutex
 0x7be0c8 FlushFileBuffers
 0x7be0cc LoadResource
 0x7be0d0 SuspendThread
 0x7be0d4 GetTickCount
 0x7be0d8 WaitForMultipleObjects
 0x7be0dc GetFileSize
 0x7be0e0 GetTempFileNameW
 0x7be0e4 GetStartupInfoW
 0x7be0e8 GlobalDeleteAtom
 0x7be0ec GetFileAttributesW
 0x7be0f0 InitializeCriticalSection
 0x7be0f4 VerLanguageNameW
 0x7be0f8 GetThreadPriority
 0x7be0fc GetCurrentProcess
 0x7be100 SetThreadPriority
 0x7be104 GlobalLock
 0x7be108 VirtualAlloc
 0x7be10c GetTempPathW
 0x7be110 GetSystemInfo
 0x7be114 GetCommandLineW
 0x7be118 DuplicateHandle
 0x7be11c LeaveCriticalSection
 0x7be120 GetProcAddress
 0x7be124 ResumeThread
 0x7be128 GetVersionExW
 0x7be12c VerifyVersionInfoW
 0x7be130 HeapCreate
 0x7be134 GetWindowsDirectoryW
 0x7be138 GetDiskFreeSpaceW
 0x7be13c VerSetConditionMask
 0x7be140 FindFirstFileW
 0x7be144 GetUserDefaultUILanguage
 0x7be148 UnmapViewOfFile
 0x7be14c GetModuleFileNameA
 0x7be150 lstrlenW
 0x7be154 CompareStringA
 0x7be158 QueryPerformanceCounter
 0x7be15c SetEndOfFile
 0x7be160 lstrcmpW
 0x7be164 HeapFree
 0x7be168 WideCharToMultiByte
 0x7be16c FindClose
 0x7be170 MultiByteToWideChar
 0x7be174 LoadLibraryW
 0x7be178 SetEvent
 0x7be17c CreateFileW
 0x7be180 GetLocaleInfoW
 0x7be184 EnumResourceNamesW
 0x7be188 DeleteFileW
 0x7be18c GetLocalTime
 0x7be190 WaitForSingleObject
 0x7be194 WriteFile
 0x7be198 CreateFileMappingW
 0x7be19c ExitThread
 0x7be1a0 DeleteCriticalSection
 0x7be1a4 GetDateFormatW
 0x7be1a8 TlsGetValue
 0x7be1ac SetErrorMode
 0x7be1b0 GetComputerNameW
 0x7be1b4 IsValidLocale
 0x7be1b8 TlsSetValue
 0x7be1bc GetOverlappedResult
 0x7be1c0 GetSystemDefaultUILanguage
 0x7be1c4 EnumCalendarInfoW
 0x7be1c8 LocalAlloc
 0x7be1cc RemoveDirectoryW
 0x7be1d0 CreateEventW
 0x7be1d4 WaitForMultipleObjectsEx
 0x7be1d8 GetThreadLocale
 0x7be1dc SetThreadLocale
XmlLite.dll
 0x7be1e4 CreateXmlReader
 0x7be1e8 CreateXmlReaderInputWithEncodingName
 0x7be1ec CreateXmlWriterOutputWithEncodingCodePage
 0x7be1f0 CreateXmlReaderInputWithEncodingCodePage
 0x7be1f4 CreateXmlWriterOutputWithEncodingName
 0x7be1f8 CreateXmlWriter
wsock32.dll
 0x7be200 send
ole32.dll
 0x7be208 CreateDataAdviseHolder
 0x7be20c OleRegEnumVerbs
 0x7be210 CoCreateInstance
 0x7be214 OleGetClipboard
 0x7be218 OleSetClipboard
 0x7be21c IsEqualGUID
 0x7be220 OleFlushClipboard
 0x7be224 CreateStreamOnHGlobal
 0x7be228 CoGetClassObject
 0x7be22c CoInitialize
 0x7be230 OleDraw
 0x7be234 CoTaskMemAlloc
 0x7be238 DoDragDrop
 0x7be23c StringFromCLSID
 0x7be240 RevokeDragDrop
 0x7be244 IsAccelerator
 0x7be248 CoUninitialize
 0x7be24c ReleaseStgMedium
 0x7be250 RegisterDragDrop
 0x7be254 OleInitialize
 0x7be258 ProgIDFromCLSID
 0x7be25c OleUninitialize
 0x7be260 CoDisconnectObject
 0x7be264 CoTaskMemFree
 0x7be268 OleSetMenuDescriptor
gdi32.dll
 0x7be270 Pie
 0x7be274 SetPaletteEntries
 0x7be278 SetBkMode
 0x7be27c GetRandomRgn
 0x7be280 CreateCompatibleBitmap
 0x7be284 CreatePolygonRgn
 0x7be288 GetEnhMetaFileHeader
 0x7be28c CloseEnhMetaFile
 0x7be290 RectVisible
 0x7be294 AngleArc
 0x7be298 ResizePalette
 0x7be29c SetAbortProc
 0x7be2a0 SetTextColor
 0x7be2a4 GetTextColor
 0x7be2a8 StretchBlt
 0x7be2ac RoundRect
 0x7be2b0 SelectClipRgn
 0x7be2b4 RestoreDC
 0x7be2b8 SetRectRgn
 0x7be2bc GetTextMetricsW
 0x7be2c0 GetWindowOrgEx
 0x7be2c4 SetPixelV
 0x7be2c8 CreatePalette
 0x7be2cc CreateDCW
 0x7be2d0 CreateICW
 0x7be2d4 PolyBezierTo
 0x7be2d8 GetStockObject
 0x7be2dc CreateSolidBrush
 0x7be2e0 Polygon
 0x7be2e4 MoveToEx
 0x7be2e8 PlayEnhMetaFile
 0x7be2ec Ellipse
 0x7be2f0 StartPage
 0x7be2f4 GetBitmapBits
 0x7be2f8 StartDocW
 0x7be2fc AbortDoc
 0x7be300 GetSystemPaletteEntries
 0x7be304 GetEnhMetaFileBits
 0x7be308 CreatePenIndirect
 0x7be30c GetEnhMetaFilePaletteEntries
 0x7be310 SetMapMode
 0x7be314 GetMapMode
 0x7be318 CreateFontIndirectW
 0x7be31c PolyBezier
 0x7be320 LPtoDP
 0x7be324 GetNearestColor
 0x7be328 EndDoc
 0x7be32c GetObjectW
 0x7be330 GetCurrentObject
 0x7be334 GetWinMetaFileBits
 0x7be338 SetROP2
 0x7be33c GetEnhMetaFileDescriptionW
 0x7be340 ArcTo
 0x7be344 GetKerningPairs
 0x7be348 CreateEnhMetaFileW
 0x7be34c Arc
 0x7be350 CreateRectRgnIndirect
 0x7be354 SelectPalette
 0x7be358 SetLayout
 0x7be35c ExcludeClipRect
 0x7be360 MaskBlt
 0x7be364 SetWindowOrgEx
 0x7be368 CreatePatternBrush
 0x7be36c EndPage
 0x7be370 DeleteEnhMetaFile
 0x7be374 Chord
 0x7be378 SetDIBits
 0x7be37c SetViewportOrgEx
 0x7be380 CreateRectRgn
 0x7be384 RealizePalette
 0x7be388 SetDIBColorTable
 0x7be38c GetDIBColorTable
 0x7be390 GetGlyphOutlineW
 0x7be394 CreateBrushIndirect
 0x7be398 PatBlt
 0x7be39c SetEnhMetaFileBits
 0x7be3a0 Rectangle
 0x7be3a4 SaveDC
 0x7be3a8 DeleteDC
 0x7be3ac BitBlt
 0x7be3b0 FrameRgn
 0x7be3b4 GetDeviceCaps
 0x7be3b8 GetTextExtentPoint32W
 0x7be3bc GetClipBox
 0x7be3c0 IntersectClipRect
 0x7be3c4 Polyline
 0x7be3c8 CreateBitmap
 0x7be3cc CombineRgn
 0x7be3d0 SetWinMetaFileBits
 0x7be3d4 CreateDIBitmap
 0x7be3d8 GetStretchBltMode
 0x7be3dc CreateDIBSection
 0x7be3e0 SetStretchBltMode
 0x7be3e4 GetDIBits
 0x7be3e8 LineTo
 0x7be3ec GetRgnBox
 0x7be3f0 EnumFontsW
 0x7be3f4 CreateHalftonePalette
 0x7be3f8 SelectObject
 0x7be3fc DeleteObject
 0x7be400 ExtFloodFill
 0x7be404 UnrealizeObject
 0x7be408 CopyEnhMetaFileW
 0x7be40c OffsetRgn
 0x7be410 SetBkColor
 0x7be414 GetBkColor
 0x7be418 CreateCompatibleDC
 0x7be41c GetObjectA
 0x7be420 GetBrushOrgEx
 0x7be424 GetCurrentPositionEx
 0x7be428 GetNearestPaletteIndex
 0x7be42c CreateRoundRectRgn
 0x7be430 GetTextExtentPointW
 0x7be434 ExtTextOutW
 0x7be438 SetBrushOrgEx
 0x7be43c GetPixel
 0x7be440 GdiFlush
 0x7be444 SetPixel
 0x7be448 EnumFontFamiliesExW
 0x7be44c StretchDIBits
 0x7be450 GetPaletteEntries

EAT(Export Address Table) Library

0x470f60 TMethodImplementationIntercept
0x411ee4 __dbk_fcall_wrapper
0x7b663c dbkFCallWrapperAddr


Similarity measure (PE file only) - Checking for service failure