Report - extension.exe

Generic Malware Malicious Library UPX PE File DllRegisterServer dll PE32 MZP Format OS Processor Check
ScreenShot
Created 2024.05.12 19:11 Machine s1_win7_x6403
Filename extension.exe
Type PE32 executable (GUI) Intel 80386, for MS Windows
AI Score
5
Behavior Score
2.6
ZERO API file : mailcious
VT API (file) 23 detected (GenericKDS, GenericS, Detected, ai score=82, PrivateLoader, ABRisk, OFUS, MALICIOUS, R002H09E924, susgen, PossibleThreat)
md5 e17b09e3a34f25c08e8869c8b5dac01c
sha256 17bbfcb94482982e9b4282c44da52313a1e3862adc5bb48a997a9123b41ebb0b
ssdeep 49152:ZI9+2qYtQ/Rg2ECNUg2I7wUpEroPeeegawQTCIyVM8OoJNz:Og21t0q2ECNURoPblawXIyXOo3
imphash a97600664f6bf22a99cadb2f7fd19144
impfuzzy 192:ocENzRuujUEUhc9bhYoZNBoDX7WcnLpIQJ41GXhWfPbOQMxx9TD7NlUAKo:GNRjn9Zeby+IR1GaPbOQMxnDgAKo
  Network IP location

Signature (7cnts)

Level Description
warning File has been identified by 23 AntiVirus engines on VirusTotal as malicious
notice Allocates read-write-execute memory (usually to unpack itself)
notice Checks for the Locally Unique Identifier on the system for a suspicious privilege
notice The binary likely contains encrypted or compressed data indicative of a packer
info Checks amount of memory in system
info One or more processes crashed
info The executable contains unknown PE section names indicative of a packer (could be a false positive)

Rules (8cnts)

Level Name Description Collection
warning Generic_Malware_Zero Generic Malware binaries (upload)
watch Malicious_Library_Zero Malicious_Library binaries (upload)
watch UPX_Zero UPX packed file binaries (upload)
info DllRegisterServer_Zero execute regsvr32.exe binaries (upload)
info IsPE32 (no description) binaries (upload)
info mzp_file_format MZP(Delphi) file format binaries (upload)
info OS_Processor_Check_Zero OS Processor Check binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (2cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
zenglobalenerji.com TR Netinternet Bilisim Teknolojileri AS 185.106.210.202 mailcious
185.106.210.202 TR Netinternet Bilisim Teknolojileri AS 185.106.210.202 mailcious

Suricata ids

PE API

IAT(Import Address Table) Library

oleaut32.dll
 0x6e6c24 SysFreeString
 0x6e6c28 SysReAllocStringLen
 0x6e6c2c SysAllocStringLen
advapi32.dll
 0x6e6c34 RegQueryValueExW
 0x6e6c38 RegOpenKeyExW
 0x6e6c3c RegCloseKey
user32.dll
 0x6e6c44 GetKeyboardType
 0x6e6c48 LoadStringW
 0x6e6c4c MessageBoxA
 0x6e6c50 CharNextW
kernel32.dll
 0x6e6c58 GetACP
 0x6e6c5c Sleep
 0x6e6c60 VirtualFree
 0x6e6c64 VirtualAlloc
 0x6e6c68 GetSystemInfo
 0x6e6c6c GetTickCount
 0x6e6c70 QueryPerformanceCounter
 0x6e6c74 GetVersion
 0x6e6c78 GetCurrentThreadId
 0x6e6c7c VirtualQuery
 0x6e6c80 WideCharToMultiByte
 0x6e6c84 SetCurrentDirectoryW
 0x6e6c88 MultiByteToWideChar
 0x6e6c8c lstrlenW
 0x6e6c90 lstrlenA
 0x6e6c94 lstrcpynW
 0x6e6c98 LoadLibraryExW
 0x6e6c9c GetThreadLocale
 0x6e6ca0 GetStartupInfoA
 0x6e6ca4 GetProcAddress
 0x6e6ca8 GetModuleHandleW
 0x6e6cac GetModuleFileNameW
 0x6e6cb0 GetLocaleInfoW
 0x6e6cb4 GetLastError
 0x6e6cb8 GetCurrentDirectoryW
 0x6e6cbc GetCommandLineW
 0x6e6cc0 FreeLibrary
 0x6e6cc4 FindFirstFileW
 0x6e6cc8 FindClose
 0x6e6ccc ExitProcess
 0x6e6cd0 ExitThread
 0x6e6cd4 CreateThread
 0x6e6cd8 CompareStringW
 0x6e6cdc WriteFile
 0x6e6ce0 UnhandledExceptionFilter
 0x6e6ce4 SetFilePointer
 0x6e6ce8 SetEndOfFile
 0x6e6cec RtlUnwind
 0x6e6cf0 ReadFile
 0x6e6cf4 RaiseException
 0x6e6cf8 GetStdHandle
 0x6e6cfc GetFileSize
 0x6e6d00 GetFileType
 0x6e6d04 CreateFileW
 0x6e6d08 CloseHandle
kernel32.dll
 0x6e6d10 TlsSetValue
 0x6e6d14 TlsGetValue
 0x6e6d18 LocalAlloc
 0x6e6d1c GetModuleHandleW
user32.dll
 0x6e6d24 CreateWindowExW
 0x6e6d28 WindowFromPoint
 0x6e6d2c WaitMessage
 0x6e6d30 WaitForInputIdle
 0x6e6d34 ValidateRect
 0x6e6d38 UpdateWindow
 0x6e6d3c UnregisterClassW
 0x6e6d40 UnhookWindowsHookEx
 0x6e6d44 TranslateMessage
 0x6e6d48 TranslateMDISysAccel
 0x6e6d4c TrackPopupMenu
 0x6e6d50 SystemParametersInfoW
 0x6e6d54 ShowWindow
 0x6e6d58 ShowScrollBar
 0x6e6d5c ShowOwnedPopups
 0x6e6d60 SetWindowsHookExW
 0x6e6d64 SetWindowTextW
 0x6e6d68 SetWindowPos
 0x6e6d6c SetWindowPlacement
 0x6e6d70 SetWindowLongW
 0x6e6d74 SetTimer
 0x6e6d78 SetScrollRange
 0x6e6d7c SetScrollPos
 0x6e6d80 SetScrollInfo
 0x6e6d84 SetRect
 0x6e6d88 SetPropW
 0x6e6d8c SetParent
 0x6e6d90 SetMenuItemInfoW
 0x6e6d94 SetMenu
 0x6e6d98 SetKeyboardState
 0x6e6d9c SetForegroundWindow
 0x6e6da0 SetFocus
 0x6e6da4 SetCursorPos
 0x6e6da8 SetCursor
 0x6e6dac SetClipboardData
 0x6e6db0 SetClassLongW
 0x6e6db4 SetCaretPos
 0x6e6db8 SetCapture
 0x6e6dbc SetActiveWindow
 0x6e6dc0 SendMessageA
 0x6e6dc4 SendMessageW
 0x6e6dc8 SendDlgItemMessageW
 0x6e6dcc ScrollWindowEx
 0x6e6dd0 ScrollWindow
 0x6e6dd4 ScreenToClient
 0x6e6dd8 RemovePropW
 0x6e6ddc RemoveMenu
 0x6e6de0 ReleaseDC
 0x6e6de4 ReleaseCapture
 0x6e6de8 RegisterWindowMessageW
 0x6e6dec RegisterClipboardFormatW
 0x6e6df0 RegisterClassW
 0x6e6df4 RedrawWindow
 0x6e6df8 PtInRect
 0x6e6dfc PostQuitMessage
 0x6e6e00 PostMessageW
 0x6e6e04 PeekMessageA
 0x6e6e08 PeekMessageW
 0x6e6e0c OpenClipboard
 0x6e6e10 OffsetRect
 0x6e6e14 OemToCharBuffA
 0x6e6e18 OemToCharA
 0x6e6e1c MsgWaitForMultipleObjectsEx
 0x6e6e20 MsgWaitForMultipleObjects
 0x6e6e24 MoveWindow
 0x6e6e28 MessageBoxW
 0x6e6e2c MessageBeep
 0x6e6e30 MapWindowPoints
 0x6e6e34 MapVirtualKeyW
 0x6e6e38 LoadStringW
 0x6e6e3c LoadKeyboardLayoutW
 0x6e6e40 LoadIconW
 0x6e6e44 LoadCursorW
 0x6e6e48 LoadBitmapW
 0x6e6e4c KillTimer
 0x6e6e50 IsZoomed
 0x6e6e54 IsWindowVisible
 0x6e6e58 IsWindowUnicode
 0x6e6e5c IsWindowEnabled
 0x6e6e60 IsWindow
 0x6e6e64 IsIconic
 0x6e6e68 IsDialogMessageA
 0x6e6e6c IsDialogMessageW
 0x6e6e70 IsClipboardFormatAvailable
 0x6e6e74 IsChild
 0x6e6e78 IsCharAlphaNumericW
 0x6e6e7c IsCharAlphaW
 0x6e6e80 InvalidateRect
 0x6e6e84 IntersectRect
 0x6e6e88 InsertMenuItemW
 0x6e6e8c InsertMenuW
 0x6e6e90 InflateRect
 0x6e6e94 GetWindowThreadProcessId
 0x6e6e98 GetWindowTextW
 0x6e6e9c GetWindowRect
 0x6e6ea0 GetWindowPlacement
 0x6e6ea4 GetWindowLongW
 0x6e6ea8 GetWindowDC
 0x6e6eac GetUpdateRect
 0x6e6eb0 GetTopWindow
 0x6e6eb4 GetSystemMetrics
 0x6e6eb8 GetSystemMenu
 0x6e6ebc GetSysColorBrush
 0x6e6ec0 GetSysColor
 0x6e6ec4 GetSubMenu
 0x6e6ec8 GetScrollRange
 0x6e6ecc GetScrollPos
 0x6e6ed0 GetScrollInfo
 0x6e6ed4 GetPropW
 0x6e6ed8 GetParent
 0x6e6edc GetWindow
 0x6e6ee0 GetMessageTime
 0x6e6ee4 GetMessagePos
 0x6e6ee8 GetMenuStringW
 0x6e6eec GetMenuState
 0x6e6ef0 GetMenuItemInfoW
 0x6e6ef4 GetMenuItemID
 0x6e6ef8 GetMenuItemCount
 0x6e6efc GetMenu
 0x6e6f00 GetLastActivePopup
 0x6e6f04 GetKeyboardState
 0x6e6f08 GetKeyboardLayoutNameW
 0x6e6f0c GetKeyboardLayoutList
 0x6e6f10 GetKeyboardLayout
 0x6e6f14 GetKeyState
 0x6e6f18 GetKeyNameTextW
 0x6e6f1c GetIconInfo
 0x6e6f20 GetForegroundWindow
 0x6e6f24 GetFocus
 0x6e6f28 GetDoubleClickTime
 0x6e6f2c GetDlgItem
 0x6e6f30 GetDlgCtrlID
 0x6e6f34 GetDesktopWindow
 0x6e6f38 GetDCEx
 0x6e6f3c GetDC
 0x6e6f40 GetCursorPos
 0x6e6f44 GetCursor
 0x6e6f48 GetClipboardData
 0x6e6f4c GetClientRect
 0x6e6f50 GetClassNameW
 0x6e6f54 GetClassLongW
 0x6e6f58 GetClassInfoW
 0x6e6f5c GetCaretPos
 0x6e6f60 GetCapture
 0x6e6f64 GetActiveWindow
 0x6e6f68 FrameRect
 0x6e6f6c FindWindowExW
 0x6e6f70 FindWindowW
 0x6e6f74 FillRect
 0x6e6f78 EnumWindows
 0x6e6f7c EnumThreadWindows
 0x6e6f80 EnumClipboardFormats
 0x6e6f84 EnumChildWindows
 0x6e6f88 EndPaint
 0x6e6f8c EndDeferWindowPos
 0x6e6f90 EnableWindow
 0x6e6f94 EnableScrollBar
 0x6e6f98 EnableMenuItem
 0x6e6f9c EmptyClipboard
 0x6e6fa0 DrawTextExW
 0x6e6fa4 DrawTextW
 0x6e6fa8 DrawMenuBar
 0x6e6fac DrawIconEx
 0x6e6fb0 DrawIcon
 0x6e6fb4 DrawFrameControl
 0x6e6fb8 DrawFocusRect
 0x6e6fbc DrawEdge
 0x6e6fc0 DispatchMessageA
 0x6e6fc4 DispatchMessageW
 0x6e6fc8 DestroyWindow
 0x6e6fcc DestroyMenu
 0x6e6fd0 DestroyIcon
 0x6e6fd4 DestroyCursor
 0x6e6fd8 DestroyCaret
 0x6e6fdc DeleteMenu
 0x6e6fe0 DeferWindowPos
 0x6e6fe4 DefWindowProcW
 0x6e6fe8 DefMDIChildProcW
 0x6e6fec DefFrameProcW
 0x6e6ff0 CreatePopupMenu
 0x6e6ff4 CreateMenu
 0x6e6ff8 CreateIcon
 0x6e6ffc CreateCaret
 0x6e7000 CreateAcceleratorTableW
 0x6e7004 CountClipboardFormats
 0x6e7008 CopyIcon
 0x6e700c CloseClipboard
 0x6e7010 ClientToScreen
 0x6e7014 ChildWindowFromPoint
 0x6e7018 CheckMenuItem
 0x6e701c CharUpperBuffW
 0x6e7020 CharNextW
 0x6e7024 CharLowerBuffW
 0x6e7028 CharLowerW
 0x6e702c CallWindowProcW
 0x6e7030 CallNextHookEx
 0x6e7034 BeginPaint
 0x6e7038 BeginDeferWindowPos
 0x6e703c CharToOemBuffA
 0x6e7040 AdjustWindowRectEx
 0x6e7044 ActivateKeyboardLayout
msimg32.dll
 0x6e704c AlphaBlend
gdi32.dll
 0x6e7054 UnrealizeObject
 0x6e7058 StretchDIBits
 0x6e705c StretchBlt
 0x6e7060 StartPage
 0x6e7064 StartDocW
 0x6e7068 SetWindowOrgEx
 0x6e706c SetWindowExtEx
 0x6e7070 SetWinMetaFileBits
 0x6e7074 SetViewportOrgEx
 0x6e7078 SetViewportExtEx
 0x6e707c SetTextColor
 0x6e7080 SetStretchBltMode
 0x6e7084 SetROP2
 0x6e7088 SetPixel
 0x6e708c SetMapMode
 0x6e7090 SetEnhMetaFileBits
 0x6e7094 SetDIBColorTable
 0x6e7098 SetBrushOrgEx
 0x6e709c SetBkMode
 0x6e70a0 SetBkColor
 0x6e70a4 SetAbortProc
 0x6e70a8 SelectPalette
 0x6e70ac SelectObject
 0x6e70b0 SelectClipRgn
 0x6e70b4 SaveDC
 0x6e70b8 RoundRect
 0x6e70bc RestoreDC
 0x6e70c0 ResizePalette
 0x6e70c4 Rectangle
 0x6e70c8 RectVisible
 0x6e70cc RealizePalette
 0x6e70d0 Polyline
 0x6e70d4 Polygon
 0x6e70d8 PolyPolyline
 0x6e70dc PlayEnhMetaFile
 0x6e70e0 Pie
 0x6e70e4 PatBlt
 0x6e70e8 MoveToEx
 0x6e70ec MaskBlt
 0x6e70f0 LineTo
 0x6e70f4 IntersectClipRect
 0x6e70f8 GetWindowOrgEx
 0x6e70fc GetWinMetaFileBits
 0x6e7100 GetTextMetricsW
 0x6e7104 GetTextExtentPointW
 0x6e7108 GetTextExtentPoint32W
 0x6e710c GetSystemPaletteEntries
 0x6e7110 GetStockObject
 0x6e7114 GetRgnBox
 0x6e7118 GetPixel
 0x6e711c GetPaletteEntries
 0x6e7120 GetObjectW
 0x6e7124 GetNearestPaletteIndex
 0x6e7128 GetEnhMetaFilePaletteEntries
 0x6e712c GetEnhMetaFileHeader
 0x6e7130 GetEnhMetaFileDescriptionW
 0x6e7134 GetEnhMetaFileBits
 0x6e7138 GetDeviceCaps
 0x6e713c GetDIBits
 0x6e7140 GetDIBColorTable
 0x6e7144 GetDCOrgEx
 0x6e7148 GetCurrentPositionEx
 0x6e714c GetClipBox
 0x6e7150 GetBrushOrgEx
 0x6e7154 GetBitmapBits
 0x6e7158 GdiFlush
 0x6e715c FrameRgn
 0x6e7160 ExtTextOutW
 0x6e7164 ExtFloodFill
 0x6e7168 ExtCreatePen
 0x6e716c ExcludeClipRect
 0x6e7170 EnumFontsW
 0x6e7174 EnumFontFamiliesExW
 0x6e7178 EndPage
 0x6e717c EndDoc
 0x6e7180 Ellipse
 0x6e7184 DeleteObject
 0x6e7188 DeleteEnhMetaFile
 0x6e718c DeleteDC
 0x6e7190 CreateSolidBrush
 0x6e7194 CreateRectRgn
 0x6e7198 CreatePenIndirect
 0x6e719c CreatePalette
 0x6e71a0 CreateICW
 0x6e71a4 CreateHalftonePalette
 0x6e71a8 CreateFontIndirectW
 0x6e71ac CreateEnhMetaFileW
 0x6e71b0 CreateDIBitmap
 0x6e71b4 CreateDIBSection
 0x6e71b8 CreateDCW
 0x6e71bc CreateCompatibleDC
 0x6e71c0 CreateCompatibleBitmap
 0x6e71c4 CreateBrushIndirect
 0x6e71c8 CreateBitmap
 0x6e71cc CopyEnhMetaFileW
 0x6e71d0 CombineRgn
 0x6e71d4 CloseEnhMetaFile
 0x6e71d8 Chord
 0x6e71dc BitBlt
 0x6e71e0 Arc
 0x6e71e4 AbortDoc
version.dll
 0x6e71ec VerQueryValueW
 0x6e71f0 GetFileVersionInfoSizeW
 0x6e71f4 GetFileVersionInfoW
kernel32.dll
 0x6e71fc lstrcpyW
 0x6e7200 lstrcmpW
 0x6e7204 WritePrivateProfileStringW
 0x6e7208 WriteFile
 0x6e720c WideCharToMultiByte
 0x6e7210 WaitForSingleObject
 0x6e7214 WaitForMultipleObjectsEx
 0x6e7218 VirtualQueryEx
 0x6e721c VirtualQuery
 0x6e7220 VirtualAlloc
 0x6e7224 UpdateResourceW
 0x6e7228 SystemTimeToTzSpecificLocalTime
 0x6e722c SystemTimeToFileTime
 0x6e7230 SwitchToThread
 0x6e7234 SleepEx
 0x6e7238 Sleep
 0x6e723c SizeofResource
 0x6e7240 SignalObjectAndWait
 0x6e7244 SetThreadLocale
 0x6e7248 SetLastError
 0x6e724c SetFilePointer
 0x6e7250 SetFileAttributesW
 0x6e7254 SetEvent
 0x6e7258 SetErrorMode
 0x6e725c SetEnvironmentVariableW
 0x6e7260 SetEndOfFile
 0x6e7264 SetCurrentDirectoryW
 0x6e7268 ResumeThread
 0x6e726c ResetEvent
 0x6e7270 RemoveDirectoryW
 0x6e7274 ReadFile
 0x6e7278 QueryPerformanceFrequency
 0x6e727c QueryPerformanceCounter
 0x6e7280 PeekNamedPipe
 0x6e7284 MultiByteToWideChar
 0x6e7288 MulDiv
 0x6e728c MoveFileA
 0x6e7290 MoveFileW
 0x6e7294 LockResource
 0x6e7298 LocalFileTimeToFileTime
 0x6e729c LoadResource
 0x6e72a0 LoadLibraryExW
 0x6e72a4 LoadLibraryA
 0x6e72a8 LoadLibraryW
 0x6e72ac LeaveCriticalSection
 0x6e72b0 InitializeCriticalSection
 0x6e72b4 GlobalUnlock
 0x6e72b8 GlobalSize
 0x6e72bc GlobalLock
 0x6e72c0 GlobalFree
 0x6e72c4 GlobalFindAtomW
 0x6e72c8 GlobalDeleteAtom
 0x6e72cc GlobalAlloc
 0x6e72d0 GlobalAddAtomW
 0x6e72d4 GetWindowsDirectoryW
 0x6e72d8 GetVersionExW
 0x6e72dc GetVersion
 0x6e72e0 GetTimeZoneInformation
 0x6e72e4 GetTickCount
 0x6e72e8 GetThreadLocale
 0x6e72ec GetTempPathW
 0x6e72f0 GetSystemTime
 0x6e72f4 GetStdHandle
 0x6e72f8 GetProcAddress
 0x6e72fc GetPrivateProfileStringW
 0x6e7300 GetOEMCP
 0x6e7304 GetModuleHandleA
 0x6e7308 GetModuleHandleW
 0x6e730c GetModuleFileNameA
 0x6e7310 GetModuleFileNameW
 0x6e7314 GetLocaleInfoW
 0x6e7318 GetLocalTime
 0x6e731c GetLastError
 0x6e7320 GetFullPathNameW
 0x6e7324 GetFileAttributesExW
 0x6e7328 GetFileAttributesW
 0x6e732c GetExitCodeThread
 0x6e7330 GetExitCodeProcess
 0x6e7334 GetEnvironmentVariableW
 0x6e7338 GetDiskFreeSpaceW
 0x6e733c GetDateFormatW
 0x6e7340 GetCurrentThreadId
 0x6e7344 GetCurrentThread
 0x6e7348 GetCurrentProcessId
 0x6e734c GetCurrentProcess
 0x6e7350 GetComputerNameW
 0x6e7354 GetCPInfo
 0x6e7358 GetACP
 0x6e735c FreeResource
 0x6e7360 InterlockedIncrement
 0x6e7364 InterlockedExchangeAdd
 0x6e7368 InterlockedExchange
 0x6e736c InterlockedDecrement
 0x6e7370 InterlockedCompareExchange
 0x6e7374 FreeLibrary
 0x6e7378 FormatMessageW
 0x6e737c FindResourceW
 0x6e7380 FindNextFileW
 0x6e7384 FindFirstFileW
 0x6e7388 FindClose
 0x6e738c FileTimeToSystemTime
 0x6e7390 FileTimeToLocalFileTime
 0x6e7394 FileTimeToDosDateTime
 0x6e7398 ExpandEnvironmentStringsW
 0x6e739c EnumResourceLanguagesW
 0x6e73a0 EnumCalendarInfoW
 0x6e73a4 EnterCriticalSection
 0x6e73a8 EndUpdateResourceW
 0x6e73ac DosDateTimeToFileTime
 0x6e73b0 DeleteFileW
 0x6e73b4 DeleteCriticalSection
 0x6e73b8 CreateThread
 0x6e73bc CreateProcessW
 0x6e73c0 CreatePipe
 0x6e73c4 CreateFileW
 0x6e73c8 CreateEventW
 0x6e73cc CreateDirectoryW
 0x6e73d0 CopyFileA
 0x6e73d4 CopyFileW
 0x6e73d8 CompareStringW
 0x6e73dc CompareFileTime
 0x6e73e0 CloseHandle
 0x6e73e4 BeginUpdateResourceW
 0x6e73e8 Beep
advapi32.dll
 0x6e73f0 RegUnLoadKeyW
 0x6e73f4 RegSetValueExW
 0x6e73f8 RegSaveKeyW
 0x6e73fc RegRestoreKeyW
 0x6e7400 RegReplaceKeyW
 0x6e7404 RegQueryValueExW
 0x6e7408 RegQueryValueW
 0x6e740c RegQueryInfoKeyW
 0x6e7410 RegOpenKeyExW
 0x6e7414 RegOpenKeyW
 0x6e7418 RegLoadKeyW
 0x6e741c RegFlushKey
 0x6e7420 RegEnumValueW
 0x6e7424 RegEnumKeyExW
 0x6e7428 RegDeleteValueW
 0x6e742c RegDeleteKeyW
 0x6e7430 RegCreateKeyExW
 0x6e7434 RegConnectRegistryW
 0x6e7438 RegCloseKey
oleaut32.dll
 0x6e7440 CreateErrorInfo
 0x6e7444 GetErrorInfo
 0x6e7448 SetErrorInfo
 0x6e744c GetActiveObject
 0x6e7450 SafeArrayCopy
 0x6e7454 SafeArrayPutElement
 0x6e7458 SafeArrayGetElement
 0x6e745c SafeArrayUnaccessData
 0x6e7460 SafeArrayAccessData
 0x6e7464 SafeArrayGetUBound
 0x6e7468 SafeArrayGetElemsize
 0x6e746c SafeArrayDestroy
 0x6e7470 SafeArrayCreate
 0x6e7474 SysStringLen
 0x6e7478 SysFreeString
ole32.dll
 0x6e7480 OleUninitialize
 0x6e7484 OleInitialize
 0x6e7488 CoTaskMemFree
 0x6e748c CoTaskMemAlloc
 0x6e7490 CoCreateGuid
 0x6e7494 CLSIDFromProgID
 0x6e7498 ProgIDFromCLSID
 0x6e749c CLSIDFromString
 0x6e74a0 StringFromCLSID
 0x6e74a4 CoCreateInstance
 0x6e74a8 CoGetMalloc
 0x6e74ac CoUninitialize
 0x6e74b0 CoInitialize
 0x6e74b4 IsEqualGUID
kernel32.dll
 0x6e74bc Sleep
ole32.dll
 0x6e74c4 IsEqualGUID
 0x6e74c8 CLSIDFromString
 0x6e74cc CoTaskMemFree
 0x6e74d0 StringFromCLSID
 0x6e74d4 CoCreateGuid
oleaut32.dll
 0x6e74dc SafeArrayPtrOfIndex
 0x6e74e0 SafeArrayPutElement
 0x6e74e4 SafeArrayGetElement
 0x6e74e8 SafeArrayUnaccessData
 0x6e74ec SafeArrayAccessData
 0x6e74f0 SafeArrayGetUBound
 0x6e74f4 SafeArrayGetLBound
 0x6e74f8 SafeArrayRedim
 0x6e74fc SafeArrayCreate
 0x6e7500 VariantChangeType
 0x6e7504 VariantCopyInd
 0x6e7508 VariantCopy
 0x6e750c VariantClear
 0x6e7510 VariantInit
comctl32.dll
 0x6e7518 InitializeFlatSB
 0x6e751c FlatSB_SetScrollProp
 0x6e7520 FlatSB_SetScrollPos
 0x6e7524 FlatSB_SetScrollInfo
 0x6e7528 FlatSB_GetScrollPos
 0x6e752c FlatSB_GetScrollInfo
 0x6e7530 _TrackMouseEvent
 0x6e7534 ImageList_GetImageInfo
 0x6e7538 ImageList_SetIconSize
 0x6e753c ImageList_GetIconSize
 0x6e7540 ImageList_Write
 0x6e7544 ImageList_Read
 0x6e7548 ImageList_GetDragImage
 0x6e754c ImageList_DragShowNolock
 0x6e7550 ImageList_DragMove
 0x6e7554 ImageList_DragLeave
 0x6e7558 ImageList_DragEnter
 0x6e755c ImageList_EndDrag
 0x6e7560 ImageList_BeginDrag
 0x6e7564 ImageList_Copy
 0x6e7568 ImageList_LoadImageW
 0x6e756c ImageList_GetIcon
 0x6e7570 ImageList_Remove
 0x6e7574 ImageList_DrawEx
 0x6e7578 ImageList_Replace
 0x6e757c ImageList_Draw
 0x6e7580 ImageList_SetOverlayImage
 0x6e7584 ImageList_GetBkColor
 0x6e7588 ImageList_SetBkColor
 0x6e758c ImageList_ReplaceIcon
 0x6e7590 ImageList_Add
 0x6e7594 ImageList_SetImageCount
 0x6e7598 ImageList_GetImageCount
 0x6e759c ImageList_Destroy
 0x6e75a0 ImageList_Create
 0x6e75a4 InitCommonControls
winspool.drv
 0x6e75ac OpenPrinterW
 0x6e75b0 EnumPrintersW
 0x6e75b4 DocumentPropertiesW
 0x6e75b8 ClosePrinter
winspool.drv
 0x6e75c0 GetDefaultPrinterW
shell32.dll
 0x6e75c8 ShellExecuteExW
shell32.dll
 0x6e75d0 SHGetSpecialFolderLocation
 0x6e75d4 SHGetPathFromIDListW
 0x6e75d8 SHGetMalloc
 0x6e75dc SHBrowseForFolderW
comdlg32.dll
 0x6e75e4 ChooseFontW
 0x6e75e8 ChooseColorW
 0x6e75ec GetSaveFileNameW
 0x6e75f0 GetOpenFileNameW
kernel32.dll
 0x6e75f8 MulDiv
wsock32.dll
 0x6e7600 WSACleanup
 0x6e7604 WSAStartup
 0x6e7608 WSAGetLastError
 0x6e760c WSACancelAsyncRequest
 0x6e7610 WSAAsyncGetServByName
 0x6e7614 WSAAsyncGetHostByName
 0x6e7618 WSAAsyncSelect
 0x6e761c getservbyname
 0x6e7620 gethostbyname
 0x6e7624 socket
 0x6e7628 send
 0x6e762c recv
 0x6e7630 ntohs
 0x6e7634 listen
 0x6e7638 ioctlsocket
 0x6e763c inet_addr
 0x6e7640 htons
 0x6e7644 connect
 0x6e7648 closesocket
 0x6e764c ind

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure