Report - Final Draft.exe

Emotet Generic Malware Malicious Library UPX PE File .NET EXE PE32 OS Processor Check
ScreenShot
Created 2024.07.19 19:18 Machine s1_win7_x6401
Filename Final Draft.exe
Type PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
AI Score Not founds Behavior Score
1.2
ZERO API file : clean
VT API (file) 7 detected (MSIL@AI, MSIL2, lEgwDlz5SK87EBd9+BXVzg, XPACK, malicious, moderate, score, Vmprotect)
md5 00537f781b10d766813b9d5987edde1a
sha256 7dfe0544bea5dc69c1e697af9362ee4f45ba5b273ffded771a671d8752e4bc22
ssdeep 196608:U4IMm5ygEvAsrXAktWpHD7GVh2wv9c++Pqoi+SWSMD/RNxi6FLOyomFHKnP:hIJREvp1O0l1gPJSWDDbzF
imphash 984b7446bb5063fae34f02302a266628
impfuzzy 768:ql0oqNUF5B1sbTAuQ8lwZOabhli/GrS0sUAwVRLvWtXIvPlW9oK6b26DB:ql0ooUFqbBBabhlgUBDLv0IvJK6b24
  Network IP location

Signature (4cnts)

Level Description
notice File has been identified by 7 AntiVirus engines on VirusTotal as malicious
notice The binary likely contains encrypted or compressed data indicative of a packer
info The executable contains unknown PE section names indicative of a packer (could be a false positive)
info The file contains an unknown PE resource name possibly indicative of a packer

Rules (9cnts)

Level Name Description Collection
danger Win32_Trojan_Emotet_1_Zero Win32 Trojan Emotet binaries (upload)
danger Win32_Trojan_Emotet_2_Zero Win32 Trojan Emotet binaries (upload)
warning Generic_Malware_Zero Generic Malware binaries (upload)
watch Malicious_Library_Zero Malicious_Library binaries (upload)
watch UPX_Zero UPX packed file binaries (upload)
info Is_DotNET_EXE (no description) binaries (upload)
info IsPE32 (no description) binaries (upload)
info OS_Processor_Check_Zero OS Processor Check binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids

PE API

IAT(Import Address Table) Library

api-ms-win-core-winrt-string-l1-1-0.dll
 0x1810000 WindowsIsStringEmpty
 0x1810004 WindowsGetStringRawBuffer
 0x1810008 WindowsDeleteString
 0x181000c WindowsCreateStringReference
 0x1810010 WindowsStringHasEmbeddedNull
 0x1810014 WindowsCreateString
api-ms-win-core-winrt-l1-1-0.dll
 0x181001c RoActivateInstance
 0x1810020 RoRevokeActivationFactories
 0x1810024 RoRegisterActivationFactories
 0x1810028 RoGetActivationFactory
api-ms-win-core-winrt-error-l1-1-0.dll
 0x1810030 RoOriginateErrorW
 0x1810034 RoOriginateError
icuin58.dll
 0x181003c ucsdet_getName_58
 0x1810040 ucsdet_detectAll_58
 0x1810044 ucsdet_setText_58
 0x1810048 ucsdet_close_58
 0x181004c ?getFindProgressCallback@RegexMatcher@icu_58@@UAEXAAP6ACPBX_J@ZAAPBXAAW4UErrorCode@@@Z
 0x1810050 ?createInstance@Transliterator@icu_58@@SAPAV12@ABVUnicodeString@2@W4UTransDirection@@AAW4UErrorCode@@@Z
 0x1810054 ucsdet_open_58
 0x1810058 ?getDynamicClassID@RegexMatcher@icu_58@@UBEPAXXZ
 0x181005c ?find@RegexMatcher@icu_58@@UAEC_JAAW4UErrorCode@@@Z
 0x1810060 ?find@RegexMatcher@icu_58@@UAECXZ
 0x1810064 ?find@RegexMatcher@icu_58@@UAECAAW4UErrorCode@@@Z
 0x1810068 ?end@RegexMatcher@icu_58@@UBEHHAAW4UErrorCode@@@Z
 0x181006c ?end@RegexMatcher@icu_58@@UBEHAAW4UErrorCode@@@Z
 0x1810070 ?pattern@RegexMatcher@icu_58@@UBEABVRegexPattern@2@XZ
 0x1810074 ?matches@RegexMatcher@icu_58@@UAEC_JAAW4UErrorCode@@@Z
 0x1810078 ?end64@RegexMatcher@icu_58@@UBE_JHAAW4UErrorCode@@@Z
 0x181007c ?matches@RegexMatcher@icu_58@@UAECAAW4UErrorCode@@@Z
 0x1810080 ??1StringSearch@icu_58@@UAE@XZ
 0x1810084 ?end64@RegexMatcher@icu_58@@UBE_JAAW4UErrorCode@@@Z
 0x1810088 ?getInput@RegexMatcher@icu_58@@UBEPAUUText@@PAU3@AAW4UErrorCode@@@Z
 0x181008c ?getMatchCallback@RegexMatcher@icu_58@@UAEXAAP6ACPBXH@ZAAPBXAAW4UErrorCode@@@Z
 0x1810090 ?appendTail@RegexMatcher@icu_58@@UAEPAUUText@@PAU3@AAW4UErrorCode@@@Z
 0x1810094 ?appendTail@RegexMatcher@icu_58@@UAEAAVUnicodeString@2@AAV32@@Z
 0x1810098 ?appendReplacement@RegexMatcher@icu_58@@UAEAAV12@PAUUText@@0AAW4UErrorCode@@@Z
 0x181009c ?appendReplacement@RegexMatcher@icu_58@@UAEAAV12@AAVUnicodeString@2@ABV32@AAW4UErrorCode@@@Z
 0x18100a0 ?getStackLimit@RegexMatcher@icu_58@@UBEHXZ
 0x18100a4 ?lookingAt@RegexMatcher@icu_58@@UAEC_JAAW4UErrorCode@@@Z
 0x18100a8 ?first@SearchIterator@icu_58@@QAEHAAW4UErrorCode@@@Z
 0x18100ac ?lookingAt@RegexMatcher@icu_58@@UAECAAW4UErrorCode@@@Z
 0x18100b0 ?getTimeLimit@RegexMatcher@icu_58@@UBEHXZ
 0x18100b4 ?group@RegexMatcher@icu_58@@UBE?AVUnicodeString@2@AAW4UErrorCode@@@Z
 0x18100b8 ?group@RegexMatcher@icu_58@@UBE?AVUnicodeString@2@HAAW4UErrorCode@@@Z
 0x18100bc ?group@RegexMatcher@icu_58@@UBEPAUUText@@HPAU3@AA_JAAW4UErrorCode@@@Z
 0x18100c0 ?group@RegexMatcher@icu_58@@UBEPAUUText@@PAU3@AA_JAAW4UErrorCode@@@Z
 0x18100c4 ?refreshInputText@RegexMatcher@icu_58@@UAEAAV12@PAUUText@@AAW4UErrorCode@@@Z
 0x18100c8 ?region@RegexMatcher@icu_58@@UAEAAV12@_J00AAW4UErrorCode@@@Z
 0x18100cc ?region@RegexMatcher@icu_58@@UAEAAV12@_J0AAW4UErrorCode@@@Z
 0x18100d0 ?regionEnd64@RegexMatcher@icu_58@@UBE_JXZ
 0x18100d4 ?regionEnd@RegexMatcher@icu_58@@UBEHXZ
 0x18100d8 ?regionStart64@RegexMatcher@icu_58@@UBE_JXZ
 0x18100dc ?regionStart@RegexMatcher@icu_58@@UBEHXZ
 0x18100e0 ?replaceAll@RegexMatcher@icu_58@@UAE?AVUnicodeString@2@ABV32@AAW4UErrorCode@@@Z
 0x18100e4 ?replaceAll@RegexMatcher@icu_58@@UAEPAUUText@@PAU3@0AAW4UErrorCode@@@Z
 0x18100e8 ?replaceFirst@RegexMatcher@icu_58@@UAE?AVUnicodeString@2@ABV32@AAW4UErrorCode@@@Z
 0x18100ec ?replaceFirst@RegexMatcher@icu_58@@UAEPAUUText@@PAU3@0AAW4UErrorCode@@@Z
 0x18100f0 ?requireEnd@RegexMatcher@icu_58@@UBECXZ
 0x18100f4 ?reset@RegexMatcher@icu_58@@UAEAAV12@ABVUnicodeString@2@@Z
 0x18100f8 ?reset@RegexMatcher@icu_58@@UAEAAV12@PAUUText@@@Z
 0x18100fc ?reset@RegexMatcher@icu_58@@UAEAAV12@XZ
 0x1810100 ?reset@RegexMatcher@icu_58@@UAEAAV12@_JAAW4UErrorCode@@@Z
 0x1810104 ?setFindProgressCallback@RegexMatcher@icu_58@@UAEXP6ACPBX_J@Z0AAW4UErrorCode@@@Z
 0x1810108 ?setMatchCallback@RegexMatcher@icu_58@@UAEXP6ACPBXH@Z0AAW4UErrorCode@@@Z
 0x181010c ?setStackLimit@RegexMatcher@icu_58@@UAEXHAAW4UErrorCode@@@Z
 0x1810110 ?setTimeLimit@RegexMatcher@icu_58@@UAEXHAAW4UErrorCode@@@Z
 0x1810114 ?split@RegexMatcher@icu_58@@UAEHABVUnicodeString@2@QAV32@HAAW4UErrorCode@@@Z
 0x1810118 ?split@RegexMatcher@icu_58@@UAEHPAUUText@@QAPAU3@HAAW4UErrorCode@@@Z
 0x181011c ?start64@RegexMatcher@icu_58@@UBE_JAAW4UErrorCode@@@Z
 0x1810120 ?start64@RegexMatcher@icu_58@@UBE_JHAAW4UErrorCode@@@Z
 0x1810124 ?start@RegexMatcher@icu_58@@UBEHAAW4UErrorCode@@@Z
 0x1810128 ?start@RegexMatcher@icu_58@@UBEHHAAW4UErrorCode@@@Z
 0x181012c ?useAnchoringBounds@RegexMatcher@icu_58@@UAEAAV12@C@Z
 0x1810130 ?useTransparentBounds@RegexMatcher@icu_58@@UAEAAV12@C@Z
 0x1810134 ?inputText@RegexMatcher@icu_58@@UBEPAUUText@@XZ
 0x1810138 ?groupCount@RegexMatcher@icu_58@@UBEHXZ
 0x181013c ?input@RegexMatcher@icu_58@@UBEABVUnicodeString@2@XZ
 0x1810140 ?hitEnd@RegexMatcher@icu_58@@UBECXZ
 0x1810144 ?hasTransparentBounds@RegexMatcher@icu_58@@UBECXZ
 0x1810148 ??0StringSearch@icu_58@@QAE@ABVUnicodeString@1@0ABVLocale@1@PAVBreakIterator@1@AAW4UErrorCode@@@Z
 0x181014c ?hasAnchoringBounds@RegexMatcher@icu_58@@UBECXZ
 0x1810150 ??0RegexMatcher@icu_58@@QAE@ABVUnicodeString@1@IAAW4UErrorCode@@@Z
 0x1810154 ??1RegexMatcher@icu_58@@UAE@XZ
icuuc58.dll
 0x181015c ?hasNext@UCharCharacterIterator@icu_58@@UAECXZ
 0x1810160 ucnv_countAliases_58
 0x1810164 ucnv_close_58
 0x1810168 ucnv_open_58
 0x181016c ubrk_close_58
 0x1810170 ubrk_open_58
 0x1810174 ??1Locale@icu_58@@UAE@XZ
 0x1810178 ??0Locale@icu_58@@QAE@PBD000@Z
 0x181017c ?getUS@Locale@icu_58@@SAABV12@XZ
 0x1810180 ?doCompare@UnicodeString@icu_58@@ABECHHABV12@HH@Z
 0x1810184 ??0UnicodeString@icu_58@@QAE@PBDHPAUUConverter@@AAW4UErrorCode@@@Z
 0x1810188 ??0UnicodeString@icu_58@@QAE@PBDH0@Z
 0x181018c ??0UnicodeString@icu_58@@QAE@PBD@Z
 0x1810190 ??0UnicodeString@icu_58@@QAE@PB_WH@Z
 0x1810194 ?releaseBuffer@UnicodeString@icu_58@@QAEXH@Z
 0x1810198 ?getBuffer@UnicodeString@icu_58@@QAEPA_WH@Z
 0x181019c ?toTitle@UnicodeString@icu_58@@QAEAAV12@PAVBreakIterator@2@ABVLocale@2@@Z
 0x18101a0 ?toTitle@UnicodeString@icu_58@@QAEAAV12@PAVBreakIterator@2@@Z
 0x18101a4 ?toLower@UnicodeString@icu_58@@QAEAAV12@ABVLocale@2@@Z
 0x18101a8 ?toLower@UnicodeString@icu_58@@QAEAAV12@XZ
 0x18101ac ?toUpper@UnicodeString@icu_58@@QAEAAV12@ABVLocale@2@@Z
 0x18101b0 ?findAndReplace@UnicodeString@icu_58@@QAEAAV12@ABV12@0@Z
 0x18101b4 ?setTo@UnicodeString@icu_58@@QAEAAV12@PB_WH@Z
 0x18101b8 ?countChar32@UnicodeString@icu_58@@QBEHHH@Z
 0x18101bc ?extract@UnicodeString@icu_58@@QBEHHHPADIPBD@Z
 0x18101c0 u_strFromUTF8_58
 0x18101c4 u_strFromWCS_58
 0x18101c8 u_memset_58
 0x18101cc u_ispunct_58
 0x18101d0 u_isspace_58
 0x18101d4 ??0StringPiece@icu_58@@QAE@ABV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z
 0x18101d8 ?getTerminatedBuffer@UnicodeString@icu_58@@QAEPB_WXZ
 0x18101dc ??0UnicodeString@icu_58@@QAE@$$QAV01@@Z
 0x18101e0 ??1UnicodeString@icu_58@@UAE@XZ
 0x18101e4 ?fromUTF8@UnicodeString@icu_58@@SA?AV12@VStringPiece@2@@Z
 0x18101e8 u_islower_58
 0x18101ec u_isalpha_58
 0x18101f0 u_isalnum_58
 0x18101f4 u_tolower_58
 0x18101f8 u_toupper_58
 0x18101fc u_charType_58
 0x1810200 ?current@UCharCharacterIterator@icu_58@@UBE_WXZ
 0x1810204 ?next@UCharCharacterIterator@icu_58@@UAE_WXZ
 0x1810208 ??0StringCharacterIterator@icu_58@@QAE@ABVUnicodeString@1@@Z
 0x181020c ??1StringCharacterIterator@icu_58@@UAE@XZ
 0x1810210 ??3UMemory@icu_58@@SAXPAX@Z
 0x1810214 ??1ByteSink@icu_58@@UAE@XZ
 0x1810218 ?toUTF8@UnicodeString@icu_58@@QBEXAAVByteSink@2@@Z
 0x181021c ?Flush@ByteSink@icu_58@@UAEXXZ
 0x1810220 ?GetAppendBuffer@ByteSink@icu_58@@UAEPADHHPADHPAH@Z
 0x1810224 ??2UMemory@icu_58@@SAPAXI@Z
 0x1810228 ??0StringPiece@icu_58@@QAE@PBD@Z
 0x181022c ?length@UnicodeString@icu_58@@QBEHXZ
 0x1810230 ?append@UnicodeString@icu_58@@QAEAAV12@H@Z
 0x1810234 ??0UnicodeString@icu_58@@QAE@XZ
 0x1810238 ?char32At@UnicodeString@icu_58@@QBEHH@Z
 0x181023c ?toUpper@UnicodeString@icu_58@@QAEAAV12@XZ
 0x1810240 ??0UnicodeString@icu_58@@QAE@H@Z
 0x1810244 ??0UnicodeString@icu_58@@QAE@PB_W@Z
 0x1810248 ?doCaseCompare@UnicodeString@icu_58@@ABECHHABV12@HHI@Z
 0x181024c ?doCharAt@UnicodeString@icu_58@@ABE_WH@Z
 0x1810250 u_isprint_58
 0x1810254 u_isWhitespace_58
 0x1810258 ?getChar32At@UnicodeString@icu_58@@MBEHH@Z
 0x181025c ?getCharAt@UnicodeString@icu_58@@MBE_WH@Z
 0x1810260 ?getLength@UnicodeString@icu_58@@MBEHXZ
 0x1810264 ?clone@UnicodeString@icu_58@@UBEPAVReplaceable@2@XZ
 0x1810268 ?hasMetaData@UnicodeString@icu_58@@UBECXZ
 0x181026c ?copy@UnicodeString@icu_58@@UAEXHHH@Z
 0x1810270 ?handleReplaceBetween@UnicodeString@icu_58@@UAEXHHABV12@@Z
 0x1810274 ?extractBetween@UnicodeString@icu_58@@UBEXHHAAV12@@Z
 0x1810278 ?getDynamicClassID@UnicodeString@icu_58@@UBEPAXXZ
 0x181027c ??8UnicodeString@icu_58@@QBECABV01@@Z
 0x1810280 ?endsWith@UnicodeString@icu_58@@QBECABV12@@Z
 0x1810284 ?tempSubString@UnicodeString@icu_58@@QBE?AV12@HH@Z
 0x1810288 ??4UnicodeString@icu_58@@QAEAAV01@$$QAV01@@Z
 0x181028c ?replace@UnicodeString@icu_58@@QAEAAV12@HHH@Z
 0x1810290 ?trim@UnicodeString@icu_58@@QAEAAV12@XZ
 0x1810294 ??0UnicodeString@icu_58@@QAE@ABV01@@Z
 0x1810298 ??0UnicodeString@icu_58@@QAE@ABV01@H@Z
 0x181029c ??0UnicodeString@icu_58@@QAE@ABV01@HH@Z
 0x18102a0 ?doReplace@UnicodeString@icu_58@@AAEAAV12@HHABV12@HH@Z
 0x18102a4 ?doReplace@UnicodeString@icu_58@@AAEAAV12@HHPB_WHH@Z
 0x18102a8 ?getArrayStart@UnicodeString@icu_58@@ABEPB_WXZ
 0x18102ac u_isupper_58
 0x18102b0 u_isdigit_58
 0x18102b4 ucnv_getAliases_58
WinSparkle.dll
 0x18102bc win_sparkle_check_update_without_ui
 0x18102c0 win_sparkle_check_update_with_ui
 0x18102c4 win_sparkle_get_automatic_check_for_updates
 0x18102c8 win_sparkle_set_automatic_check_for_updates
 0x18102cc win_sparkle_init
 0x18102d0 win_sparkle_cleanup
 0x18102d4 win_sparkle_set_appcast_url
 0x18102d8 win_sparkle_set_dsa_pub_pem
WINHTTP.dll
 0x18102e0 WinHttpQueryDataAvailable
 0x18102e4 WinHttpReadData
 0x18102e8 WinHttpConnect
 0x18102ec WinHttpCloseHandle
 0x18102f0 WinHttpOpen
 0x18102f4 WinHttpSetStatusCallback
 0x18102f8 WinHttpReceiveResponse
 0x18102fc WinHttpSendRequest
 0x1810300 WinHttpAddRequestHeaders
 0x1810304 WinHttpOpenRequest
 0x1810308 WinHttpQueryOption
WININET.dll
 0x1810310 InternetCanonicalizeUrlW
 0x1810314 InternetGetConnectedState
Secur32.dll
 0x181031c GetUserNameExW
WINMM.dll
 0x1810324 PlaySoundW
dbghelp.dll
 0x181032c SymCleanup
 0x1810330 SymGetLineFromAddr64
 0x1810334 SymInitialize
 0x1810338 SymFromAddr
UIAutomationCore.DLL
 0x1810340 UiaRaiseAutomationEvent
 0x1810344 UiaReturnRawElementProvider
 0x1810348 UiaHostProviderFromHwnd
CRYPT32.dll
 0x1810350 CryptUnprotectData
 0x1810354 CryptProtectData
ADVAPI32.dll
 0x181035c DeregisterEventSource
 0x1810360 CredReadA
 0x1810364 CredDeleteA
 0x1810368 CredFree
 0x181036c RegSetKeyValueW
 0x1810370 RegCloseKey
 0x1810374 RegCreateKeyW
 0x1810378 RegCreateKeyExW
 0x181037c RegDeleteKeyW
 0x1810380 RegOpenKeyExW
 0x1810384 RegQueryValueExW
 0x1810388 RegEnumValueW
 0x181038c RegDeleteValueW
 0x1810390 CryptReleaseContext
 0x1810394 RegisterEventSourceA
 0x1810398 ReportEventA
 0x181039c CryptAcquireContextA
 0x18103a0 CryptEnumProvidersA
 0x18103a4 CryptGenRandom
 0x18103a8 CryptAcquireContextW
 0x18103ac RegOpenKeyExA
 0x18103b0 RegEnumValueA
 0x18103b4 RegSetValueExW
 0x18103b8 CredWriteA
ruiSDK_5.6.0.x86.dll
 0x18103c0 ruiFree
 0x18103c4 ruiSetLicenseKey
 0x18103c8 ruiTrackEventText
 0x18103cc ruiTrackEvent
 0x18103d0 ruiTrackException
 0x18103d4 ruiStopSDK
 0x18103d8 ruiStartSDK
 0x18103dc ruiSetCustomProperty
 0x18103e0 ruiSetLicenseData
 0x18103e4 ruiSetProductData
 0x18103e8 ruiSetReachOutOnAutoSync
 0x18103ec ruiCreateConfig
 0x18103f0 ruiCreateInstance
 0x18103f4 ruiDestroyInstance
KERNEL32.dll
 0x18103fc FlushConsoleInputBuffer
 0x1810400 GlobalMemoryStatus
 0x1810404 GetFileType
 0x1810408 GetStdHandle
 0x181040c GetModuleHandleA
 0x1810410 CreateIoCompletionPort
 0x1810414 SleepEx
 0x1810418 VerSetConditionMask
 0x181041c CreateWaitableTimerA
 0x1810420 QueueUserAPC
 0x1810424 TerminateThread
 0x1810428 CreateEventW
 0x181042c GetQueuedCompletionStatus
 0x1810430 WaitForMultipleObjects
 0x1810434 SetLastError
 0x1810438 VerifyVersionInfoA
 0x181043c CreateSemaphoreA
 0x1810440 DuplicateHandle
 0x1810444 VirtualProtect
 0x1810448 VirtualQuery
 0x181044c ReleaseSemaphore
 0x1810450 FindNextFileA
 0x1810454 FindFirstFileA
 0x1810458 QueryPerformanceFrequency
 0x181045c GetLogicalProcessorInformation
 0x1810460 ResumeThread
 0x1810464 OpenEventA
 0x1810468 WaitForMultipleObjectsEx
 0x181046c GetStartupInfoW
 0x1810470 IsDebuggerPresent
 0x1810474 IsProcessorFeaturePresent
 0x1810478 TerminateProcess
 0x181047c UnhandledExceptionFilter
 0x1810480 InitializeSListHead
 0x1810484 ResetEvent
 0x1810488 SetWaitableTimer
 0x181048c GetFileSizeEx
 0x1810490 ExitThread
 0x1810494 LoadLibraryExW
 0x1810498 LoadLibraryExA
 0x181049c CreateThread
 0x18104a0 CreateMutexA
 0x18104a4 _lclose
 0x18104a8 _hwrite
 0x18104ac _hread
 0x18104b0 _lwrite
 0x18104b4 _lcreat
 0x18104b8 _lopen
 0x18104bc GetConsoleOutputCP
 0x18104c0 GetSystemDefaultLangID
 0x18104c4 GetACP
 0x18104c8 GlobalReAlloc
 0x18104cc _llseek
 0x18104d0 FreeResource
 0x18104d4 GetLocaleInfoEx
 0x18104d8 LocalFree
 0x18104dc GetLastError
 0x18104e0 PostQueuedCompletionStatus
 0x18104e4 EnterCriticalSection
 0x18104e8 LeaveCriticalSection
 0x18104ec InitializeCriticalSectionAndSpinCount
 0x18104f0 DeleteCriticalSection
 0x18104f4 TlsAlloc
 0x18104f8 TlsFree
 0x18104fc CreateEventA
 0x1810500 CloseHandle
 0x1810504 SetEvent
 0x1810508 EncodePointer
 0x181050c DecodePointer
 0x1810510 RaiseException
 0x1810514 ReleaseSRWLockExclusive
 0x1810518 ReleaseSRWLockShared
 0x181051c AcquireSRWLockExclusive
 0x1810520 AcquireSRWLockShared
 0x1810524 GetCurrentProcess
 0x1810528 GetModuleFileNameW
 0x181052c GetPackageFamilyName
 0x1810530 GetSystemFirmwareTable
 0x1810534 MulDiv
 0x1810538 RtlCaptureStackBackTrace
 0x181053c SetUnhandledExceptionFilter
 0x1810540 InitializeCriticalSectionEx
 0x1810544 OutputDebugStringW
 0x1810548 LocalAlloc
 0x181054c LocalSize
 0x1810550 FormatMessageW
 0x1810554 lstrlenW
 0x1810558 GlobalLock
 0x181055c GlobalUnlock
 0x1810560 FindClose
 0x1810564 FindFirstFileW
 0x1810568 FindNextFileW
 0x181056c GetWindowsDirectoryW
 0x1810570 GetModuleHandleW
 0x1810574 MultiByteToWideChar
 0x1810578 Sleep
 0x181057c GetCurrentThreadId
 0x1810580 GetTimeFormatEx
 0x1810584 GetDateFormatEx
 0x1810588 EnumDateFormatsExEx
 0x181058c HeapDestroy
 0x1810590 HeapAlloc
 0x1810594 HeapReAlloc
 0x1810598 HeapFree
 0x181059c HeapSize
 0x18105a0 GetProcessHeap
 0x18105a4 SetCurrentDirectoryW
 0x18105a8 LockResource
 0x18105ac GlobalAlloc
 0x18105b0 GlobalSize
 0x18105b4 GlobalFree
 0x18105b8 WideCharToMultiByte
 0x18105bc GetCommandLineW
 0x18105c0 ReleaseMutex
 0x18105c4 CreateMutexW
 0x18105c8 GlobalDeleteAtom
 0x18105cc lstrcmpW
 0x18105d0 lstrcmpiW
 0x18105d4 GlobalAddAtomW
 0x18105d8 GetStringTypeExW
 0x18105dc GetThreadLocale
 0x18105e0 FindResourceW
 0x18105e4 RegisterApplicationRestart
 0x18105e8 CreateDirectoryW
 0x18105ec LoadResource
 0x18105f0 GetVersionExW
 0x18105f4 FreeLibrary
 0x18105f8 GetProcAddress
 0x18105fc LoadLibraryW
 0x1810600 GetUserDefaultUILanguage
 0x1810604 GetModuleFileNameA
 0x1810608 GetCurrentDirectoryA
 0x181060c GetFullPathNameA
 0x1810610 GetTempPathA
 0x1810614 GetCurrentProcessId
 0x1810618 GetVersionExA
 0x181061c InitializeCriticalSection
 0x1810620 TlsGetValue
 0x1810624 TlsSetValue
 0x1810628 GetSystemWindowsDirectoryA
 0x181062c LoadLibraryA
 0x1810630 lstrcpynW
 0x1810634 GetLocaleInfoW
 0x1810638 GetUserDefaultLCID
 0x181063c QueryPerformanceCounter
 0x1810640 GetDateFormatW
 0x1810644 FlushFileBuffers
 0x1810648 GetTickCount
 0x181064c MapViewOfFile
 0x1810650 CreateFileMappingW
 0x1810654 FormatMessageA
 0x1810658 GetSystemTime
 0x181065c GetSystemTimeAsFileTime
 0x1810660 SystemTimeToFileTime
 0x1810664 GetFileSize
 0x1810668 LockFileEx
 0x181066c UnlockFile
 0x1810670 HeapCompact
 0x1810674 GetSystemInfo
 0x1810678 DeleteFileW
 0x181067c DeleteFileA
 0x1810680 WaitForSingleObjectEx
 0x1810684 CreateFileA
 0x1810688 FlushViewOfFile
 0x181068c GetFileAttributesExW
 0x1810690 GetFileAttributesA
 0x1810694 GetDiskFreeSpaceA
 0x1810698 HeapValidate
 0x181069c UnmapViewOfFile
 0x18106a0 GetFileAttributesW
 0x18106a4 CreateFileW
 0x18106a8 WaitForSingleObject
 0x18106ac GetTempPathW
 0x18106b0 UnlockFileEx
 0x18106b4 SetEndOfFile
 0x18106b8 SetFilePointer
 0x18106bc LockFile
 0x18106c0 OutputDebugStringA
 0x18106c4 GetDiskFreeSpaceW
 0x18106c8 WriteFile
 0x18106cc GetFullPathNameW
 0x18106d0 HeapCreate
 0x18106d4 ReadFile
 0x18106d8 AreFileApisANSI
 0x18106dc TryEnterCriticalSection
 0x18106e0 GetTempFileNameW
 0x18106e4 lstrcpyW
 0x18106e8 lstrcatW
 0x18106ec GetCurrentDirectoryW
 0x18106f0 LCIDToLocaleName
 0x18106f4 CopyFileW
 0x18106f8 GetVersion
USER32.dll
 0x1810700 GetMonitorInfoW
 0x1810704 MonitorFromWindow
 0x1810708 LockWindowUpdate
 0x181070c DragDetect
 0x1810710 MessageBeep
 0x1810714 DrawEdge
 0x1810718 EmptyClipboard
 0x181071c GetClipboardData
 0x1810720 SetClipboardData
 0x1810724 CloseClipboard
 0x1810728 SetMenuItemInfoW
 0x181072c GetMenuItemInfoW
 0x1810730 CheckMenuItem
 0x1810734 EnumChildWindows
 0x1810738 CallWindowProcW
 0x181073c PostThreadMessageW
 0x1810740 GetUpdateRect
 0x1810744 ToUnicode
 0x1810748 GetKeyboardState
 0x181074c OpenClipboard
 0x1810750 AppendMenuW
 0x1810754 EnableMenuItem
 0x1810758 MapDialogRect
 0x181075c MessageBoxW
 0x1810760 IsIconic
 0x1810764 DefWindowProcW
 0x1810768 DrawMenuBar
 0x181076c UnregisterClassW
 0x1810770 InvertRect
 0x1810774 WindowFromDC
 0x1810778 SetRect
 0x181077c GetWindowDC
 0x1810780 IsWindowEnabled
 0x1810784 TranslateAcceleratorW
 0x1810788 LoadAcceleratorsW
 0x181078c DeleteMenu
 0x1810790 GetSystemMenu
 0x1810794 RegisterWindowMessageW
 0x1810798 GetMenuItemCount
 0x181079c GetMenuItemID
 0x18107a0 GetSubMenu
 0x18107a4 GetMenu
 0x18107a8 GetNextDlgTabItem
 0x18107ac GetWindow
 0x18107b0 DrawFrameControl
 0x18107b4 InflateRect
 0x18107b8 wsprintfW
 0x18107bc FindWindowW
 0x18107c0 SetFocus
 0x18107c4 GetCapture
 0x18107c8 GetIconInfo
 0x18107cc LoadImageW
 0x18107d0 GetWindowThreadProcessId
 0x18107d4 SetForegroundWindow
 0x18107d8 GetForegroundWindow
 0x18107dc ShowWindow
 0x18107e0 AttachThreadInput
 0x18107e4 TranslateMessage
 0x18107e8 DispatchMessageW
 0x18107ec PeekMessageW
 0x18107f0 ScrollDC
 0x18107f4 CreateCaret
 0x18107f8 SetCaretPos
 0x18107fc FrameRect
 0x1810800 DestroyWindow
 0x1810804 SystemParametersInfoW
 0x1810808 GetScrollInfo
 0x181080c UnregisterClassA
 0x1810810 TrackMouseEvent
 0x1810814 IsRectEmpty
 0x1810818 DestroyMenu
 0x181081c EnumDisplayMonitors
 0x1810820 OffsetRect
 0x1810824 ReleaseDC
 0x1810828 AnimateWindow
 0x181082c GetClassInfoW
 0x1810830 RegisterClassW
 0x1810834 DestroyCaret
 0x1810838 IsWindow
 0x181083c CopyRect
 0x1810840 GetSysColor
 0x1810844 GetDoubleClickTime
 0x1810848 GetWindowInfo
 0x181084c GetLastActivePopup
 0x1810850 SetActiveWindow
 0x1810854 GetDlgItem
 0x1810858 SetParent
 0x181085c UpdateLayeredWindow
 0x1810860 GetKeyboardLayout
 0x1810864 KillTimer
 0x1810868 SetTimer
 0x181086c MapWindowPoints
 0x1810870 LoadBitmapW
 0x1810874 SendMessageTimeoutW
 0x1810878 BringWindowToTop
 0x181087c SetWindowPos
 0x1810880 IsZoomed
 0x1810884 ShowCaret
 0x1810888 HideCaret
 0x181088c IsClipboardFormatAvailable
 0x1810890 PostMessageW
 0x1810894 CreatePopupMenu
 0x1810898 IsChild
 0x181089c RegisterClipboardFormatW
 0x18108a0 LoadCursorW
 0x18108a4 GetParent
 0x18108a8 SetWindowLongW
 0x18108ac GetWindowLongW
 0x18108b0 PtInRect
 0x18108b4 IntersectRect
 0x18108b8 WindowFromPoint
 0x18108bc ScreenToClient
 0x18108c0 ClientToScreen
 0x18108c4 GetCursorPos
 0x18108c8 SetCursor
 0x18108cc MessageBoxA
 0x18108d0 GetClientRect
 0x18108d4 EnableScrollBar
 0x18108d8 ShowScrollBar
 0x18108dc SetWindowRgn
 0x18108e0 UpdateWindow
 0x18108e4 ReleaseCapture
 0x18108e8 SetCapture
 0x18108ec SendInput
 0x18108f0 GetKeyState
 0x18108f4 GetFocus
 0x18108f8 GetActiveWindow
 0x18108fc IsWindowVisible
 0x1810900 EndDeferWindowPos
 0x1810904 DeferWindowPos
 0x1810908 BeginDeferWindowPos
 0x181090c SetLayeredWindowAttributes
 0x1810910 LoadIconW
 0x1810914 DrawIcon
 0x1810918 FillRect
 0x181091c GetWindowRect
 0x1810920 RedrawWindow
 0x1810924 InvalidateRect
 0x1810928 GetDC
 0x181092c EnableWindow
 0x1810930 SendMessageW
 0x1810934 CreateIconIndirect
 0x1810938 DestroyIcon
 0x181093c GetProcessWindowStation
 0x1810940 InvalidateRgn
 0x1810944 DestroyCursor
 0x1810948 ReuseDDElParam
 0x181094c UnpackDDElParam
 0x1810950 LoadMenuW
 0x1810954 EqualRect
 0x1810958 GetUserObjectInformationW
 0x181095c GetAsyncKeyState
 0x1810960 GetSystemMetrics
 0x1810964 InsertMenuW
GDI32.dll
 0x181096c CreatePalette
 0x1810970 RoundRect
 0x1810974 CreatePen
 0x1810978 GetTextMetricsW
 0x181097c GetTextColor
 0x1810980 GetBkColor
 0x1810984 CreateSolidBrush
 0x1810988 CreateFontW
 0x181098c StrokeAndFillPath
 0x1810990 EndPath
 0x1810994 BeginPath
 0x1810998 AngleArc
 0x181099c GetStockObject
 0x18109a0 Ellipse
 0x18109a4 GetFontUnicodeRanges
 0x18109a8 ResetDCW
 0x18109ac PtInRegion
 0x18109b0 GetRgnBox
 0x18109b4 RemoveFontResourceW
 0x18109b8 AddFontResourceW
 0x18109bc SetDIBColorTable
 0x18109c0 CreateDIBSection
 0x18109c4 DeleteObject
 0x18109c8 LPtoDP
 0x18109cc CreateRectRgn
 0x18109d0 CreateCompatibleBitmap
 0x18109d4 CombineRgn
 0x18109d8 BitBlt
 0x18109dc GetObjectW
 0x18109e0 GetDeviceCaps
 0x18109e4 GetDIBColorTable
 0x18109e8 SelectObject
 0x18109ec SetRectRgn
 0x18109f0 GetViewportExtEx
 0x18109f4 DeleteDC
 0x18109f8 CreateCompatibleDC
 0x18109fc DPtoLP
 0x1810a00 EnumFontFamiliesExW
 0x1810a04 CreateFontIndirectW
 0x1810a08 RealizePalette
 0x1810a0c UnrealizeObject
 0x1810a10 GetTextExtentPoint32W
 0x1810a14 CreateDCW
 0x1810a18 GetRegionData
 0x1810a1c OffsetRgn
 0x1810a20 CreatePolygonRgn
 0x1810a24 GetBitmapBits
 0x1810a28 GetCurrentObject
 0x1810a2c CreateBitmap
 0x1810a30 CreateBrushIndirect
 0x1810a34 FillRgn
 0x1810a38 GetWindowExtEx
 0x1810a3c GetROP2
 0x1810a40 GetBrushOrgEx
 0x1810a44 GetStretchBltMode
 0x1810a48 GetViewportOrgEx
 0x1810a4c GetWindowOrgEx
 0x1810a50 InvertRgn
 0x1810a54 PatBlt
 0x1810a58 SetGraphicsMode
 0x1810a5c SetPixelV
 0x1810a60 StretchBlt
 0x1810a64 SetWorldTransform
 0x1810a68 SetBrushOrgEx
 0x1810a6c EnumFontFamiliesW
 0x1810a70 Polyline
 0x1810a74 CreateRectRgnIndirect
 0x1810a78 StartDocW
 0x1810a7c EndDoc
 0x1810a80 StartPage
 0x1810a84 EndPage
 0x1810a88 GetMapMode
 0x1810a8c CopyMetaFileW
 0x1810a90 DeleteMetaFile
 0x1810a94 GetMetaFileBitsEx
 0x1810a98 PlayMetaFile
 0x1810a9c RestoreDC
 0x1810aa0 SaveDC
 0x1810aa4 SetMapMode
 0x1810aa8 SetMetaFileBitsEx
 0x1810aac PlayMetaFileRecord
 0x1810ab0 EnumMetaFile
 0x1810ab4 SetViewportExtEx
 0x1810ab8 SetViewportOrgEx
 0x1810abc SetWindowOrgEx
 0x1810ac0 GetClipBox
 0x1810ac4 GetTextCharset
 0x1810ac8 GetFontLanguageInfo
 0x1810acc LineTo
 0x1810ad0 SelectClipRgn
 0x1810ad4 SetBkColor
 0x1810ad8 SetDCBrushColor
 0x1810adc SetDCPenColor
 0x1810ae0 SetTextColor
 0x1810ae4 SetTextJustification
 0x1810ae8 MoveToEx
 0x1810aec TextOutW
 0x1810af0 SetWindowExtEx
 0x1810af4 GetTextFaceW
 0x1810af8 GetTextExtentExPointW
 0x1810afc SetBkMode
 0x1810b00 SetTextAlign
 0x1810b04 ExtTextOutW
 0x1810b08 GetDIBits
 0x1810b0c GetObjectA
 0x1810b10 SelectPalette
 0x1810b14 SetDIBitsToDevice
 0x1810b18 StretchDIBits
 0x1810b1c SetStretchBltMode
 0x1810b20 RectVisible
 0x1810b24 FrameRgn
 0x1810b28 Rectangle
WINSPOOL.DRV
 0x1810b30 OpenPrinterW
 0x1810b34 ClosePrinter
COMDLG32.dll
 0x1810b3c GetOpenFileNameW
 0x1810b40 GetSaveFileNameW
 0x1810b44 PrintDlgW
SHELL32.dll
 0x1810b4c SHFileOperationW
 0x1810b50 ShellExecuteW
 0x1810b54 SHCreateItemFromParsingName
 0x1810b58 DragAcceptFiles
 0x1810b5c DragQueryFileW
 0x1810b60 SHGetKnownFolderPath
 0x1810b64 CommandLineToArgvW
ole32.dll
 0x1810b6c CoRevokeClassObject
 0x1810b70 CoUninitialize
 0x1810b74 CoTaskMemAlloc
 0x1810b78 CoInitialize
 0x1810b7c OleCreateStaticFromData
 0x1810b80 OleQueryCreateFromData
 0x1810b84 CreateILockBytesOnHGlobal
 0x1810b88 StgCreateDocfileOnILockBytes
 0x1810b8c CoCreateInstance
 0x1810b90 CoTaskMemFree
 0x1810b94 StringFromCLSID
 0x1810b98 CoReleaseServerProcess
 0x1810b9c CoAddRefServerProcess
 0x1810ba0 CoResumeClassObjects
 0x1810ba4 CoRegisterClassObject
OLEAUT32.dll
 0x1810bac SysAllocString
 0x1810bb0 SafeArrayDestroy
 0x1810bb4 SafeArrayPutElement
 0x1810bb8 SafeArrayCreateVector
 0x1810bbc SafeArrayAccessData
 0x1810bc0 SafeArrayUnaccessData
 0x1810bc4 VariantClear
 0x1810bc8 VariantInit
 0x1810bcc VariantChangeType
 0x1810bd0 GetErrorInfo
 0x1810bd4 SysAllocStringByteLen
 0x1810bd8 SysStringByteLen
 0x1810bdc VariantCopy
 0x1810be0 CreateErrorInfo
 0x1810be4 SetErrorInfo
 0x1810be8 SysFreeString
mfc140u.dll
 0x1810bf0 None
 0x1810bf4 None
 0x1810bf8 None
 0x1810bfc None
 0x1810c00 None
 0x1810c04 None
 0x1810c08 None
 0x1810c0c None
 0x1810c10 None
 0x1810c14 None
 0x1810c18 None
 0x1810c1c None
 0x1810c20 None
 0x1810c24 None
 0x1810c28 None
 0x1810c2c None
 0x1810c30 None
 0x1810c34 None
 0x1810c38 None
 0x1810c3c None
 0x1810c40 None
 0x1810c44 None
 0x1810c48 None
 0x1810c4c None
 0x1810c50 None
 0x1810c54 None
 0x1810c58 None
 0x1810c5c None
 0x1810c60 None
 0x1810c64 None
 0x1810c68 None
 0x1810c6c None
 0x1810c70 None
 0x1810c74 None
 0x1810c78 None
 0x1810c7c None
 0x1810c80 None
 0x1810c84 None
 0x1810c88 None
 0x1810c8c None
 0x1810c90 None
 0x1810c94 None
 0x1810c98 None
 0x1810c9c None
 0x1810ca0 None
 0x1810ca4 None
 0x1810ca8 None
 0x1810cac None
 0x1810cb0 None
 0x1810cb4 None
 0x1810cb8 None
 0x1810cbc None
 0x1810cc0 None
 0x1810cc4 None
 0x1810cc8 None
 0x1810ccc None
 0x1810cd0 None
 0x1810cd4 None
 0x1810cd8 None
 0x1810cdc None
 0x1810ce0 None
 0x1810ce4 None
 0x1810ce8 None
 0x1810cec None
 0x1810cf0 None
 0x1810cf4 None
 0x1810cf8 None
 0x1810cfc None
 0x1810d00 None
 0x1810d04 None
 0x1810d08 None
 0x1810d0c None
 0x1810d10 None
 0x1810d14 None
 0x1810d18 None
 0x1810d1c None
 0x1810d20 None
 0x1810d24 None
 0x1810d28 None
 0x1810d2c None
 0x1810d30 None
 0x1810d34 None
 0x1810d38 None
 0x1810d3c None
 0x1810d40 None
 0x1810d44 None
 0x1810d48 None
 0x1810d4c None
 0x1810d50 None
 0x1810d54 None
 0x1810d58 None
 0x1810d5c None
 0x1810d60 None
 0x1810d64 None
 0x1810d68 None
 0x1810d6c None
 0x1810d70 None
 0x1810d74 None
 0x1810d78 None
 0x1810d7c None
 0x1810d80 None
 0x1810d84 None
 0x1810d88 None
 0x1810d8c None
 0x1810d90 None
 0x1810d94 None
 0x1810d98 None
 0x1810d9c None
 0x1810da0 None
 0x1810da4 None
 0x1810da8 None
 0x1810dac None
 0x1810db0 None
 0x1810db4 None
 0x1810db8 None
 0x1810dbc None
 0x1810dc0 None
 0x1810dc4 None
 0x1810dc8 None
 0x1810dcc None
 0x1810dd0 None
 0x1810dd4 None
 0x1810dd8 None
 0x1810ddc None
 0x1810de0 None
 0x1810de4 None
 0x1810de8 None
 0x1810dec None
 0x1810df0 None
 0x1810df4 None
 0x1810df8 None
 0x1810dfc None
 0x1810e00 None
 0x1810e04 None
 0x1810e08 None
 0x1810e0c None
 0x1810e10 None
 0x1810e14 None
 0x1810e18 None
 0x1810e1c None
 0x1810e20 None
 0x1810e24 None
 0x1810e28 None
 0x1810e2c None
 0x1810e30 None
 0x1810e34 None
 0x1810e38 None
 0x1810e3c None
 0x1810e40 None
 0x1810e44 None
 0x1810e48 None
 0x1810e4c None
 0x1810e50 None
 0x1810e54 None
 0x1810e58 None
 0x1810e5c None
 0x1810e60 None
 0x1810e64 None
 0x1810e68 None
 0x1810e6c None
 0x1810e70 None
 0x1810e74 None
 0x1810e78 None
 0x1810e7c None
 0x1810e80 None
 0x1810e84 None
 0x1810e88 None
 0x1810e8c None
 0x1810e90 None
 0x1810e94 None
 0x1810e98 None
 0x1810e9c None
 0x1810ea0 None
 0x1810ea4 None
 0x1810ea8 None
 0x1810eac None
 0x1810eb0 None
 0x1810eb4 None
 0x1810eb8 None
 0x1810ebc None
 0x1810ec0 None
 0x1810ec4 None
 0x1810ec8 None
 0x1810ecc None
 0x1810ed0 None
 0x1810ed4 None
 0x1810ed8 None
 0x1810edc None
 0x1810ee0 None
 0x1810ee4 None
 0x1810ee8 None
 0x1810eec None
 0x1810ef0 None
 0x1810ef4 None
 0x1810ef8 None
 0x1810efc None
 0x1810f00 None
 0x1810f04 None
 0x1810f08 None
 0x1810f0c None
 0x1810f10 None
 0x1810f14 None
 0x1810f18 None
 0x1810f1c None
 0x1810f20 None
 0x1810f24 None
 0x1810f28 None
 0x1810f2c None
 0x1810f30 None
 0x1810f34 None
 0x1810f38 None
 0x1810f3c None
 0x1810f40 None
 0x1810f44 None
 0x1810f48 None
 0x1810f4c None
 0x1810f50 None
 0x1810f54 None
 0x1810f58 None
 0x1810f5c None
 0x1810f60 None
 0x1810f64 None
 0x1810f68 None
 0x1810f6c None
 0x1810f70 None
 0x1810f74 None
 0x1810f78 None
 0x1810f7c None
 0x1810f80 None
 0x1810f84 None
 0x1810f88 None
 0x1810f8c None
 0x1810f90 None
 0x1810f94 None
 0x1810f98 None
 0x1810f9c None
 0x1810fa0 None
 0x1810fa4 None
 0x1810fa8 None
 0x1810fac None
 0x1810fb0 None
 0x1810fb4 None
 0x1810fb8 None
 0x1810fbc None
 0x1810fc0 None
 0x1810fc4 None
 0x1810fc8 None
 0x1810fcc None
 0x1810fd0 None
 0x1810fd4 None
 0x1810fd8 None
 0x1810fdc None
 0x1810fe0 None
 0x1810fe4 None
 0x1810fe8 None
 0x1810fec None
 0x1810ff0 None
 0x1810ff4 None
 0x1810ff8 None
 0x1810ffc None
 0x1811000 None
 0x1811004 None
 0x1811008 None
 0x181100c None
 0x1811010 None
 0x1811014 None
 0x1811018 None
 0x181101c None
 0x1811020 None
 0x1811024 None
 0x1811028 None
 0x181102c None
 0x1811030 None
 0x1811034 None
 0x1811038 None
 0x181103c None
 0x1811040 None
 0x1811044 None
 0x1811048 None
 0x181104c None
 0x1811050 None
 0x1811054 None
 0x1811058 None
 0x181105c None
 0x1811060 None
 0x1811064 None
 0x1811068 None
 0x181106c None
 0x1811070 None
 0x1811074 None
 0x1811078 None
 0x181107c None
 0x1811080 None
 0x1811084 None
 0x1811088 None
 0x181108c None
 0x1811090 None
 0x1811094 None
 0x1811098 None
 0x181109c None
 0x18110a0 None
 0x18110a4 None
 0x18110a8 None
 0x18110ac None
 0x18110b0 None
 0x18110b4 None
 0x18110b8 None
 0x18110bc None
 0x18110c0 None
 0x18110c4 None
 0x18110c8 None
 0x18110cc None
 0x18110d0 None
 0x18110d4 None
 0x18110d8 None
 0x18110dc None
 0x18110e0 None
 0x18110e4 None
 0x18110e8 None
 0x18110ec None
 0x18110f0 None
 0x18110f4 None
 0x18110f8 None
 0x18110fc None
 0x1811100 None
 0x1811104 None
 0x1811108 None
 0x181110c None
 0x1811110 None
 0x1811114 None
 0x1811118 None
 0x181111c None
 0x1811120 None
 0x1811124 None
 0x1811128 None
 0x181112c None
 0x1811130 None
 0x1811134 None
 0x1811138 None
 0x181113c None
 0x1811140 None
 0x1811144 None
 0x1811148 None
 0x181114c None
 0x1811150 None
 0x1811154 None
 0x1811158 None
 0x181115c None
 0x1811160 None
 0x1811164 None
 0x1811168 None
 0x181116c None
 0x1811170 None
 0x1811174 None
 0x1811178 None
 0x181117c None
 0x1811180 None
 0x1811184 None
 0x1811188 None
 0x181118c None
 0x1811190 None
 0x1811194 None
 0x1811198 None
 0x181119c None
 0x18111a0 None
 0x18111a4 None
 0x18111a8 None
 0x18111ac None
 0x18111b0 None
 0x18111b4 None
 0x18111b8 None
 0x18111bc None
 0x18111c0 None
 0x18111c4 None
 0x18111c8 None
 0x18111cc None
 0x18111d0 None
 0x18111d4 None
 0x18111d8 None
 0x18111dc None
 0x18111e0 None
 0x18111e4 None
 0x18111e8 None
 0x18111ec None
 0x18111f0 None
 0x18111f4 None
 0x18111f8 None
 0x18111fc None
 0x1811200 None
 0x1811204 None
 0x1811208 None
 0x181120c None
 0x1811210 None
 0x1811214 None
 0x1811218 None
 0x181121c None
 0x1811220 None
 0x1811224 None
 0x1811228 None
 0x181122c None
 0x1811230 None
 0x1811234 None
 0x1811238 None
 0x181123c None
 0x1811240 None
 0x1811244 None
 0x1811248 None
 0x181124c None
 0x1811250 None
 0x1811254 None
 0x1811258 None
 0x181125c None
 0x1811260 None
 0x1811264 None
 0x1811268 None
 0x181126c None
 0x1811270 None
 0x1811274 None
 0x1811278 None
 0x181127c None
 0x1811280 None
 0x1811284 None
 0x1811288 None
 0x181128c None
 0x1811290 None
 0x1811294 None
 0x1811298 None
 0x181129c None
 0x18112a0 None
 0x18112a4 None
 0x18112a8 None
 0x18112ac None
 0x18112b0 None
 0x18112b4 None
 0x18112b8 None
 0x18112bc None
 0x18112c0 None
 0x18112c4 None
 0x18112c8 None
 0x18112cc None
 0x18112d0 None
 0x18112d4 None
 0x18112d8 None
 0x18112dc None
 0x18112e0 None
 0x18112e4 None
 0x18112e8 None
 0x18112ec None
 0x18112f0 None
 0x18112f4 None
 0x18112f8 None
 0x18112fc None
 0x1811300 None
 0x1811304 None
 0x1811308 None
 0x181130c None
 0x1811310 None
 0x1811314 None
 0x1811318 None
 0x181131c None
 0x1811320 None
 0x1811324 None
 0x1811328 None
 0x181132c None
 0x1811330 None
 0x1811334 None
 0x1811338 None
 0x181133c None
 0x1811340 None
 0x1811344 None
 0x1811348 None
 0x181134c None
 0x1811350 None
 0x1811354 None
 0x1811358 None
 0x181135c None
 0x1811360 None
 0x1811364 None
 0x1811368 None
 0x181136c None
 0x1811370 None
 0x1811374 None
 0x1811378 None
 0x181137c None
 0x1811380 None
 0x1811384 None
 0x1811388 None
 0x181138c None
 0x1811390 None
 0x1811394 None
 0x1811398 None
 0x181139c None
 0x18113a0 None
 0x18113a4 None
 0x18113a8 None
 0x18113ac None
 0x18113b0 None
 0x18113b4 None
 0x18113b8 None
 0x18113bc None
 0x18113c0 None
 0x18113c4 None
 0x18113c8 None
 0x18113cc None
 0x18113d0 None
 0x18113d4 None
 0x18113d8 None
 0x18113dc None
 0x18113e0 None
 0x18113e4 None
 0x18113e8 None
 0x18113ec None
 0x18113f0 None
 0x18113f4 None
 0x18113f8 None
 0x18113fc None
 0x1811400 None
 0x1811404 None
 0x1811408 None
 0x181140c None
 0x1811410 None
 0x1811414 None
 0x1811418 None
 0x181141c None
 0x1811420 None
 0x1811424 None
 0x1811428 None
 0x181142c None
 0x1811430 None
 0x1811434 None
 0x1811438 None
 0x181143c None
 0x1811440 None
 0x1811444 None
 0x1811448 None
 0x181144c None
 0x1811450 None
 0x1811454 None
 0x1811458 None
 0x181145c None
 0x1811460 None
 0x1811464 None
 0x1811468 None
 0x181146c None
 0x1811470 None
 0x1811474 None
 0x1811478 None
 0x181147c None
 0x1811480 None
 0x1811484 None
 0x1811488 None
 0x181148c None
 0x1811490 None
 0x1811494 None
 0x1811498 None
 0x181149c None
 0x18114a0 None
 0x18114a4 None
 0x18114a8 None
 0x18114ac None
 0x18114b0 None
 0x18114b4 None
 0x18114b8 None
 0x18114bc None
 0x18114c0 None
 0x18114c4 None
 0x18114c8 None
 0x18114cc None
 0x18114d0 None
 0x18114d4 None
 0x18114d8 None
 0x18114dc None
 0x18114e0 None
 0x18114e4 None
 0x18114e8 None
 0x18114ec None
 0x18114f0 None
 0x18114f4 None
 0x18114f8 None
 0x18114fc None
 0x1811500 None
 0x1811504 None
 0x1811508 None
 0x181150c None
 0x1811510 None
 0x1811514 None
 0x1811518 None
 0x181151c None
 0x1811520 None
 0x1811524 None
 0x1811528 None
 0x181152c None
 0x1811530 None
 0x1811534 None
 0x1811538 None
 0x181153c None
 0x1811540 None
 0x1811544 None
 0x1811548 None
 0x181154c None
 0x1811550 None
 0x1811554 None
 0x1811558 None
 0x181155c None
 0x1811560 None
 0x1811564 None
 0x1811568 None
 0x181156c None
 0x1811570 None
 0x1811574 None
 0x1811578 None
 0x181157c None
 0x1811580 None
 0x1811584 None
 0x1811588 None
 0x181158c None
 0x1811590 None
 0x1811594 None
 0x1811598 None
 0x181159c None
 0x18115a0 None
 0x18115a4 None
 0x18115a8 None
 0x18115ac None
 0x18115b0 None
 0x18115b4 None
 0x18115b8 None
 0x18115bc None
 0x18115c0 None
 0x18115c4 None
 0x18115c8 None
 0x18115cc None
 0x18115d0 None
 0x18115d4 None
 0x18115d8 None
 0x18115dc None
 0x18115e0 None
 0x18115e4 None
 0x18115e8 None
 0x18115ec None
 0x18115f0 None
 0x18115f4 None
 0x18115f8 None
 0x18115fc None
 0x1811600 None
 0x1811604 None
 0x1811608 None
 0x181160c None
 0x1811610 None
 0x1811614 None
 0x1811618 None
 0x181161c None
 0x1811620 None
 0x1811624 None
 0x1811628 None
 0x181162c None
 0x1811630 None
 0x1811634 None
 0x1811638 None
 0x181163c None
 0x1811640 None
 0x1811644 None
 0x1811648 None
 0x181164c None
 0x1811650 None
 0x1811654 None
 0x1811658 None
 0x181165c None
 0x1811660 None
 0x1811664 None
 0x1811668 None
 0x181166c None
 0x1811670 None
 0x1811674 None
 0x1811678 None
 0x181167c None
 0x1811680 None
 0x1811684 None
 0x1811688 None
 0x181168c None
 0x1811690 None
 0x1811694 None
 0x1811698 None
 0x181169c None
 0x18116a0 None
 0x18116a4 None
 0x18116a8 None
 0x18116ac None
 0x18116b0 None
 0x18116b4 None
 0x18116b8 None
 0x18116bc None
 0x18116c0 None
 0x18116c4 None
 0x18116c8 None
 0x18116cc None
 0x18116d0 None
 0x18116d4 None
 0x18116d8 None
 0x18116dc None
 0x18116e0 None
 0x18116e4 None
 0x18116e8 None
 0x18116ec None
 0x18116f0 None
 0x18116f4 None
 0x18116f8 None
 0x18116fc None
 0x1811700 None
 0x1811704 None
 0x1811708 None
 0x181170c None
 0x1811710 None
 0x1811714 None
 0x1811718 None
 0x181171c None
 0x1811720 None
 0x1811724 None
 0x1811728 None
 0x181172c None
 0x1811730 None
 0x1811734 None
 0x1811738 None
 0x181173c None
 0x1811740 None
 0x1811744 None
 0x1811748 None
 0x181174c None
 0x1811750 None
 0x1811754 None
 0x1811758 None
 0x181175c None
 0x1811760 None
 0x1811764 None
 0x1811768 None
 0x181176c None
 0x1811770 None
 0x1811774 None
 0x1811778 None
 0x181177c None
 0x1811780 None
 0x1811784 None
 0x1811788 None
 0x181178c None
 0x1811790 None
 0x1811794 None
 0x1811798 None
 0x181179c None
 0x18117a0 None
 0x18117a4 None
 0x18117a8 None
 0x18117ac None
 0x18117b0 None
 0x18117b4 None
 0x18117b8 None
 0x18117bc None
 0x18117c0 None
 0x18117c4 None
 0x18117c8 None
 0x18117cc None
 0x18117d0 None
 0x18117d4 None
 0x18117d8 None
 0x18117dc None
 0x18117e0 None
 0x18117e4 None
 0x18117e8 None
 0x18117ec None
 0x18117f0 None
 0x18117f4 None
 0x18117f8 None
 0x18117fc None
 0x1811800 None
 0x1811804 None
 0x1811808 None
 0x181180c None
 0x1811810 None
 0x1811814 None
 0x1811818 None
 0x181181c None
 0x1811820 None
 0x1811824 None
 0x1811828 None
 0x181182c None
 0x1811830 None
 0x1811834 None
 0x1811838 None
 0x181183c None
 0x1811840 None
 0x1811844 None
 0x1811848 None
 0x181184c None
 0x1811850 None
 0x1811854 None
 0x1811858 None
 0x181185c None
 0x1811860 None
 0x1811864 None
 0x1811868 None
 0x181186c None
 0x1811870 None
 0x1811874 None
 0x1811878 None
 0x181187c None
 0x1811880 None
 0x1811884 None
 0x1811888 None
 0x181188c None
 0x1811890 None
 0x1811894 None
 0x1811898 None
 0x181189c None
 0x18118a0 None
 0x18118a4 None
 0x18118a8 None
 0x18118ac None
 0x18118b0 None
 0x18118b4 None
 0x18118b8 None
 0x18118bc None
 0x18118c0 None
 0x18118c4 None
 0x18118c8 None
 0x18118cc None
 0x18118d0 None
 0x18118d4 None
 0x18118d8 None
 0x18118dc None
 0x18118e0 None
 0x18118e4 None
 0x18118e8 None
 0x18118ec None
 0x18118f0 None
 0x18118f4 None
 0x18118f8 None
 0x18118fc None
 0x1811900 None
 0x1811904 None
 0x1811908 None
 0x181190c None
 0x1811910 None
 0x1811914 None
 0x1811918 None
 0x181191c None
 0x1811920 None
 0x1811924 None
 0x1811928 None
 0x181192c None
 0x1811930 None
 0x1811934 None
 0x1811938 None
 0x181193c None
 0x1811940 None
 0x1811944 None
 0x1811948 None
 0x181194c None
 0x1811950 None
 0x1811954 None
 0x1811958 None
 0x181195c None
 0x1811960 None
 0x1811964 None
 0x1811968 None
 0x181196c None
 0x1811970 None
 0x1811974 None
 0x1811978 None
 0x181197c None
 0x1811980 None
 0x1811984 None
 0x1811988 None
 0x181198c None
 0x1811990 None
 0x1811994 None
 0x1811998 None
 0x181199c None
 0x18119a0 None
 0x18119a4 None
 0x18119a8 None
 0x18119ac None
 0x18119b0 None
 0x18119b4 None
 0x18119b8 None
 0x18119bc None
 0x18119c0 None
 0x18119c4 None
 0x18119c8 None
 0x18119cc None
 0x18119d0 None
 0x18119d4 None
 0x18119d8 None
 0x18119dc None
 0x18119e0 None
 0x18119e4 None
 0x18119e8 None
 0x18119ec None
 0x18119f0 None
 0x18119f4 None
 0x18119f8 None
 0x18119fc None
 0x1811a00 None
 0x1811a04 None
 0x1811a08 None
 0x1811a0c None
 0x1811a10 None
 0x1811a14 None
 0x1811a18 None
 0x1811a1c None
 0x1811a20 None
 0x1811a24 None
 0x1811a28 None
 0x1811a2c None
 0x1811a30 None
 0x1811a34 None
 0x1811a38 None
 0x1811a3c None
 0x1811a40 None
 0x1811a44 None
 0x1811a48 None
 0x1811a4c None
 0x1811a50 None
 0x1811a54 None
 0x1811a58 None
 0x1811a5c None
 0x1811a60 None
 0x1811a64 None
 0x1811a68 None
 0x1811a6c None
 0x1811a70 None
 0x1811a74 None
 0x1811a78 None
 0x1811a7c None
 0x1811a80 None
 0x1811a84 None
 0x1811a88 None
 0x1811a8c None
 0x1811a90 None
 0x1811a94 None
 0x1811a98 None
 0x1811a9c None
 0x1811aa0 None
 0x1811aa4 None
 0x1811aa8 None
 0x1811aac None
 0x1811ab0 None
 0x1811ab4 None
 0x1811ab8 None
 0x181


Similarity measure (PE file only) - Checking for service failure