Report - tt1.exe

Malicious Library Antivirus UPX Anti_VM PE File PE64 OS Processor Check
ScreenShot
Created 2024.08.11 15:32 Machine s1_win7_x6403
Filename tt1.exe
Type PE32+ executable (GUI) x86-64, for MS Windows
AI Score
4
Behavior Score
1.0
ZERO API file : malware
VT API (file) 39 detected (AIDetectMalware, GameHack, malicious, high confidence, score, Zusy, Unsafe, V2xb, Attribute, HighConfidence, JJ potentially unsafe, Artemis, TrojanX, AGEN, Detected, ai score=88, ABApplication, UHXT, R639555, Chgt, R002H09H924, confidence)
md5 7dff94df36e6e229ee7d60702dccf9a7
sha256 16ab80de994e7725b290c75ba04cd1c573f4ff27dceeddac383feef68e8619d6
ssdeep 49152:41TPH4hrPGi6B5LLxZKVnF1/eZ5XGgGGsQnDXvY4Rxkck5:41T/y71gGYxkL5
imphash 7a9121c1bce825374af94f5121aa08bf
impfuzzy 192:GpbWpuBE3+wh2dvCRUII8aJrc+FyaBcP82u7TD1GHy2+m:Gpb8uAWER3CyaBcP8hTwSPm
  Network IP location

Signature (1cnts)

Level Description
danger File has been identified by 39 AntiVirus engines on VirusTotal as malicious

Rules (7cnts)

Level Name Description Collection
watch Antivirus Contains references to security software binaries (upload)
watch Malicious_Library_Zero Malicious_Library binaries (upload)
watch UPX_Zero UPX packed file binaries (upload)
notice anti_vm_detect Possibly employs anti-virtualization techniques binaries (upload)
info IsPE64 (no description) binaries (upload)
info OS_Processor_Check_Zero OS Processor Check binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids

PE API

IAT(Import Address Table) Library

KERNEL32.dll
 0x1400c80e8 GetFirmwareType
 0x1400c80f0 InitializeCriticalSectionEx
 0x1400c80f8 DeleteCriticalSection
 0x1400c8100 FormatMessageA
 0x1400c8108 LocalFree
 0x1400c8110 GetCurrentThread
 0x1400c8118 Sleep
 0x1400c8120 VerifyVersionInfoW
 0x1400c8128 SetFileCompletionNotificationModes
 0x1400c8130 CloseThreadpoolIo
 0x1400c8138 CancelThreadpoolIo
 0x1400c8140 StartThreadpoolIo
 0x1400c8148 CreateThreadpoolIo
 0x1400c8150 GetOverlappedResult
 0x1400c8158 WriteFile
 0x1400c8160 ReadFile
 0x1400c8168 CreateFileW
 0x1400c8170 FormatMessageW
 0x1400c8178 OutputDebugStringW
 0x1400c8180 InitializeSListHead
 0x1400c8188 GetSystemTimeAsFileTime
 0x1400c8190 GetCurrentThreadId
 0x1400c8198 ExpandEnvironmentStringsA
 0x1400c81a0 GetModuleHandleW
 0x1400c81a8 IsProcessorFeaturePresent
 0x1400c81b0 GetStartupInfoW
 0x1400c81b8 SetUnhandledExceptionFilter
 0x1400c81c0 UnhandledExceptionFilter
 0x1400c81c8 IsDebuggerPresent
 0x1400c81d0 RtlVirtualUnwind
 0x1400c81d8 RtlLookupFunctionEntry
 0x1400c81e0 RtlCaptureContext
 0x1400c81e8 SleepConditionVariableSRW
 0x1400c81f0 WakeAllConditionVariable
 0x1400c81f8 AcquireSRWLockExclusive
 0x1400c8200 ReleaseSRWLockExclusive
 0x1400c8208 InitOnceComplete
 0x1400c8210 InitOnceBeginInitialize
 0x1400c8218 QueryPerformanceFrequency
 0x1400c8220 GetUserDefaultLocaleName
 0x1400c8228 FindClose
 0x1400c8230 LoadLibraryA
 0x1400c8238 GetProcAddress
 0x1400c8240 GetModuleHandleA
 0x1400c8248 GetModuleFileNameA
 0x1400c8250 QueryPerformanceCounter
 0x1400c8258 VerSetConditionMask
 0x1400c8260 WideCharToMultiByte
 0x1400c8268 MultiByteToWideChar
 0x1400c8270 FreeLibrary
 0x1400c8278 TerminateProcess
 0x1400c8280 ExitProcess
 0x1400c8288 GetCurrentProcess
 0x1400c8290 WaitForSingleObject
 0x1400c8298 GetLastError
 0x1400c82a0 CloseHandle
 0x1400c82a8 GlobalFree
 0x1400c82b0 GlobalLock
 0x1400c82b8 GetFirmwareEnvironmentVariableA
 0x1400c82c0 GlobalUnlock
 0x1400c82c8 GlobalAlloc
 0x1400c82d0 GetCurrentProcessId
 0x1400c82d8 GetTickCount64
 0x1400c82e0 FindNextFileA
 0x1400c82e8 FindFirstFileA
 0x1400c82f0 GetFileSizeEx
 0x1400c82f8 GetLocaleInfoEx
USER32.dll
 0x1400c87f8 GetWindowRect
 0x1400c8800 OpenClipboard
 0x1400c8808 LoadIconA
 0x1400c8810 MoveWindow
 0x1400c8818 ShowWindow
 0x1400c8820 RegisterClassExA
 0x1400c8828 DestroyWindow
 0x1400c8830 CreateWindowExW
 0x1400c8838 RegisterClassExW
 0x1400c8840 UnregisterClassW
 0x1400c8848 UnregisterClassA
 0x1400c8850 PostQuitMessage
 0x1400c8858 DefWindowProcA
 0x1400c8860 PeekMessageA
 0x1400c8868 CreateWindowExA
 0x1400c8870 UpdateWindow
 0x1400c8878 SetWindowPos
 0x1400c8880 TranslateMessage
 0x1400c8888 LoadCursorA
 0x1400c8890 CloseClipboard
 0x1400c8898 SetClipboardData
 0x1400c88a0 GetClipboardData
 0x1400c88a8 EmptyClipboard
 0x1400c88b0 TrackMouseEvent
 0x1400c88b8 ScreenToClient
 0x1400c88c0 GetMessageExtraInfo
 0x1400c88c8 GetKeyState
 0x1400c88d0 GetCapture
 0x1400c88d8 SetCapture
 0x1400c88e0 ReleaseCapture
 0x1400c88e8 GetSystemMetrics
 0x1400c88f0 DispatchMessageA
 0x1400c88f8 IsWindowUnicode
 0x1400c8900 GetForegroundWindow
 0x1400c8908 GetClientRect
 0x1400c8910 SetCursorPos
 0x1400c8918 SetCursor
 0x1400c8920 GetCursorPos
 0x1400c8928 ClientToScreen
ADVAPI32.dll
 0x1400c8000 GetUserNameW
 0x1400c8008 AdjustTokenPrivileges
 0x1400c8010 LookupPrivilegeValueA
 0x1400c8018 RegCloseKey
 0x1400c8020 RegGetValueA
 0x1400c8028 RegCreateKeyExA
 0x1400c8030 RegSetValueExA
 0x1400c8038 RegQueryValueExA
 0x1400c8040 RegOpenKeyExA
 0x1400c8048 OpenProcessToken
SHELL32.dll
 0x1400c87e8 ShellExecuteExA
MSVCP140.dll
 0x1400c8308 ?_New_Locimp@_Locimp@locale@std@@CAPEAV123@AEBV123@@Z
 0x1400c8310 ?_Locimp_Addfac@_Locimp@locale@std@@CAXPEAV123@PEAVfacet@23@_K@Z
 0x1400c8318 ?_Init@locale@std@@CAPEAV_Locimp@12@_N@Z
 0x1400c8320 ?out@?$codecvt@_WDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEB_W1AEAPEB_WPEAD3AEAPEAD@Z
 0x1400c8328 ??0?$codecvt@_WDU_Mbstatet@@@std@@QEAA@_K@Z
 0x1400c8330 ??1?$codecvt@_WDU_Mbstatet@@@std@@MEAA@XZ
 0x1400c8338 ??Bios_base@std@@QEBA_NXZ
 0x1400c8340 ?setf@ios_base@std@@QEAAHHH@Z
 0x1400c8348 ??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA@XZ
 0x1400c8350 ??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAA@XZ
 0x1400c8358 ?sbumpc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
 0x1400c8360 ?sgetc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
 0x1400c8368 ?snextc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
 0x1400c8370 ?eback@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ
 0x1400c8378 ?gptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ
 0x1400c8380 ?pptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ
 0x1400c8388 ?egptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ
 0x1400c8390 ?gbump@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXH@Z
 0x1400c8398 ?setg@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXPEAD00@Z
 0x1400c83a0 ?epptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ
 0x1400c83a8 ?setp@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXPEAD0@Z
 0x1400c83b0 ?setp@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXPEAD00@Z
 0x1400c83b8 ?_Pninc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAPEADXZ
 0x1400c83c0 ??1?$basic_ios@DU?$char_traits@D@std@@@std@@UEAA@XZ
 0x1400c83c8 ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z
 0x1400c83d0 ?rdbuf@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBAPEAV?$basic_streambuf@DU?$char_traits@D@std@@@2@XZ
 0x1400c83d8 ??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA@XZ
 0x1400c83e0 ??0?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z
 0x1400c83e8 ??1?$basic_istream@DU?$char_traits@D@std@@@std@@UEAA@XZ
 0x1400c83f0 ?_Ipfx@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA_N_N@Z
 0x1400c83f8 ??5?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAVios_base@1@AEAV21@@Z@Z
 0x1400c8400 ??5?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@AEAH@Z
 0x1400c8408 ?_Random_device@std@@YAIXZ
 0x1400c8410 ?_Incref@facet@locale@std@@UEAAXXZ
 0x1400c8418 ?_Decref@facet@locale@std@@UEAAPEAV_Facet_base@3@XZ
 0x1400c8420 ?imbue@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAXAEBVlocale@2@@Z
 0x1400c8428 ?sync@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ
 0x1400c8430 ?setbuf@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAPEAV12@PEAD_J@Z
 0x1400c8438 ?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEBD_J@Z
 0x1400c8440 ?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEAD_J@Z
 0x1400c8448 ?uflow@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ
 0x1400c8450 ?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JXZ
 0x1400c8458 ?_Unlock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ
 0x1400c8460 ?_Lock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ
 0x1400c8468 ?id@?$codecvt@_WDU_Mbstatet@@@std@@2V0locale@2@A
 0x1400c8470 _Mtx_init_in_situ
 0x1400c8478 _Mtx_destroy_in_situ
 0x1400c8480 ??0_Lockit@std@@QEAA@H@Z
 0x1400c8488 ??1_Lockit@std@@QEAA@XZ
 0x1400c8490 ?uncaught_exception@std@@YA_NXZ
 0x1400c8498 ?_Getgloballocale@locale@std@@CAPEAV_Locimp@12@XZ
 0x1400c84a0 ?always_noconv@codecvt_base@std@@QEBA_NXZ
 0x1400c84a8 ?in@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z
 0x1400c84b0 ?out@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z
 0x1400c84b8 ?unshift@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEAD1AEAPEAD@Z
 0x1400c84c0 ?_Getcat@?$codecvt@DDU_Mbstatet@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z
 0x1400c84c8 ?good@ios_base@std@@QEBA_NXZ
 0x1400c84d0 ?flags@ios_base@std@@QEBAHXZ
 0x1400c84d8 ?width@ios_base@std@@QEBA_JXZ
 0x1400c84e0 ??Bid@locale@std@@QEAA_KXZ
 0x1400c84e8 ?getloc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEBA?AVlocale@2@XZ
 0x1400c84f0 ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z
 0x1400c84f8 ?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z
 0x1400c8500 ?_Gndec@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAPEADXZ
 0x1400c8508 ?_Gninc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAPEADXZ
 0x1400c8510 ?_Gnavail@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBA_JXZ
 0x1400c8518 ?pbump@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXH@Z
 0x1400c8520 ?_Pnavail@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBA_JXZ
 0x1400c8528 ?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXXZ
 0x1400c8530 ?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXPEAPEAD0PEAH001@Z
 0x1400c8538 ?_Fiopen@std@@YAPEAU_iobuf@@PEBDHH@Z
 0x1400c8540 ?tie@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBAPEAV?$basic_ostream@DU?$char_traits@D@std@@@2@XZ
 0x1400c8548 ?fill@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADXZ
 0x1400c8550 ?widen@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADD@Z
 0x1400c8558 ??0?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z
 0x1400c8560 ??1?$basic_ostream@DU?$char_traits@D@std@@@std@@UEAA@XZ
 0x1400c8568 ?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ
 0x1400c8570 ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z
 0x1400c8578 ?put@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@D@Z
 0x1400c8580 ?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ
 0x1400c8588 ?id@?$codecvt@DDU_Mbstatet@@@std@@2V0locale@2@A
 0x1400c8590 _Thrd_detach
 0x1400c8598 _Cnd_do_broadcast_at_thread_exit
 0x1400c85a0 ?_Throw_Cpp_error@std@@YAXH@Z
 0x1400c85a8 ?_Xinvalid_argument@std@@YAXPEBD@Z
 0x1400c85b0 ?fail@ios_base@std@@QEBA_NXZ
 0x1400c85b8 ?__ExceptionPtrCreate@@YAXPEAX@Z
 0x1400c85c0 ?__ExceptionPtrDestroy@@YAXPEAX@Z
 0x1400c85c8 ?__ExceptionPtrCopy@@YAXPEAXPEBX@Z
 0x1400c85d0 ?__ExceptionPtrAssign@@YAXPEAXPEBX@Z
 0x1400c85d8 ?__ExceptionPtrToBool@@YA_NPEBX@Z
 0x1400c85e0 ?__ExceptionPtrCurrentException@@YAXPEAX@Z
 0x1400c85e8 ?__ExceptionPtrRethrow@@YAXPEBX@Z
 0x1400c85f0 ?__ExceptionPtrCopyException@@YAXPEAXPEBX1@Z
 0x1400c85f8 _Mtx_lock
 0x1400c8600 _Mtx_unlock
 0x1400c8608 _Cnd_init_in_situ
 0x1400c8610 _Cnd_destroy_in_situ
 0x1400c8618 _Cnd_wait
 0x1400c8620 _Cnd_broadcast
 0x1400c8628 ?_Schedule_chore@details@Concurrency@@YAHPEAU_Threadpool_chore@12@@Z
 0x1400c8630 ?_Release_chore@details@Concurrency@@YAXPEAU_Threadpool_chore@12@@Z
 0x1400c8638 ?_ReportUnobservedException@details@Concurrency@@YAXXZ
 0x1400c8640 ?GetCurrentThreadId@platform@details@Concurrency@@YAJXZ
 0x1400c8648 ?_Xbad_function_call@std@@YAXXZ
 0x1400c8650 ?_CallInContext@_ContextCallback@details@Concurrency@@QEBAXV?$function@$$A6AXXZ@std@@_N@Z
 0x1400c8658 ?_Reset@_ContextCallback@details@Concurrency@@AEAAXXZ
 0x1400c8660 ?_Assign@_ContextCallback@details@Concurrency@@AEAAXPEAX@Z
 0x1400c8668 ?_IsCurrentOriginSTA@_ContextCallback@details@Concurrency@@CA_NXZ
 0x1400c8670 ?_Capture@_ContextCallback@details@Concurrency@@AEAAXXZ
 0x1400c8678 ?ReportUnhandledError@_ExceptionHolder@details@Concurrency@@AEAAXXZ
 0x1400c8680 ??0task_continuation_context@Concurrency@@AEAA@XZ
 0x1400c8688 ?_LogScheduleTask@_TaskEventLogger@details@Concurrency@@QEAAX_N@Z
 0x1400c8690 ?_LogCancelTask@_TaskEventLogger@details@Concurrency@@QEAAXXZ
 0x1400c8698 ?_LogTaskCompleted@_TaskEventLogger@details@Concurrency@@QEAAXXZ
 0x1400c86a0 ?_LogTaskExecutionCompleted@_TaskEventLogger@details@Concurrency@@QEAAXXZ
 0x1400c86a8 ?_LogWorkItemStarted@_TaskEventLogger@details@Concurrency@@QEAAXXZ
 0x1400c86b0 ?_LogWorkItemCompleted@_TaskEventLogger@details@Concurrency@@QEAAXXZ
 0x1400c86b8 ?width@ios_base@std@@QEAA_J_J@Z
 0x1400c86c0 ?_Xout_of_range@std@@YAXPEBD@Z
 0x1400c86c8 ?_Xlength_error@std@@YAXPEBD@Z
 0x1400c86d0 ?_Xbad_alloc@std@@YAXXZ
 0x1400c86d8 ??5?$basic_istream@_WU?$char_traits@_W@std@@@std@@QEAAAEAV01@AEA_K@Z
 0x1400c86e0 ??6?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAAAEAV01@_K@Z
 0x1400c86e8 ??1?$basic_ostream@_WU?$char_traits@_W@std@@@std@@UEAA@XZ
 0x1400c86f0 ??0?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAA@PEAV?$basic_streambuf@_WU?$char_traits@_W@std@@@1@_N@Z
 0x1400c86f8 ?_Throw_C_error@std@@YAXH@Z
 0x1400c8700 ?__ExceptionPtrCompare@@YA_NPEBX0@Z
 0x1400c8708 ?flush@?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAAAEAV12@XZ
 0x1400c8710 ?_Osfx@?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAAXXZ
 0x1400c8718 ?sputn@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@QEAA_JPEB_W_J@Z
 0x1400c8720 ?sputc@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@QEAAG_W@Z
 0x1400c8728 ?xsputn@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@MEAA_JPEB_W_J@Z
 0x1400c8730 ?xsgetn@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@MEAA_JPEA_W_J@Z
 0x1400c8738 ?uflow@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@MEAAGXZ
 0x1400c8740 ?sync@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@MEAAHXZ
 0x1400c8748 ?showmanyc@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@MEAA_JXZ
 0x1400c8750 ?setbuf@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@MEAAPEAV12@PEA_W_J@Z
 0x1400c8758 ?imbue@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@MEAAXAEBVlocale@2@@Z
 0x1400c8760 ?_Unlock@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@UEAAXXZ
 0x1400c8768 ?_Lock@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@UEAAXXZ
 0x1400c8770 ??5?$basic_istream@_WU?$char_traits@_W@std@@@std@@QEAAAEAV01@AEAH@Z
 0x1400c8778 ??1?$basic_istream@_WU?$char_traits@_W@std@@@std@@UEAA@XZ
 0x1400c8780 ??0?$basic_istream@_WU?$char_traits@_W@std@@@std@@QEAA@PEAV?$basic_streambuf@_WU?$char_traits@_W@std@@@1@_N@Z
 0x1400c8788 ??0?$basic_ios@_WU?$char_traits@_W@std@@@std@@IEAA@XZ
 0x1400c8790 ?imbue@?$basic_ios@_WU?$char_traits@_W@std@@@std@@QEAA?AVlocale@2@AEBV32@@Z
 0x1400c8798 ?setstate@?$basic_ios@_WU?$char_traits@_W@std@@@std@@QEAAXH_N@Z
 0x1400c87a0 ??1?$basic_ios@_WU?$char_traits@_W@std@@@std@@UEAA@XZ
 0x1400c87a8 ?_Pninc@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@IEAAPEA_WXZ
 0x1400c87b0 ??1?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@UEAA@XZ
 0x1400c87b8 ??0?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@IEAA@XZ
 0x1400c87c0 ?classic@locale@std@@SAAEBV12@XZ
 0x1400c87c8 ?_Winerror_map@std@@YAHH@Z
 0x1400c87d0 ?_Syserror_map@std@@YAPEBDH@Z
 0x1400c87d8 ??4?$_Yarn@D@std@@QEAAAEAV01@PEBD@Z
CONCRT140.dll
 0x1400c8058 ?_Release@_ReentrantBlockingLock@details@Concurrency@@QEAAXXZ
 0x1400c8060 ??0_ReentrantBlockingLock@details@Concurrency@@QEAA@XZ
 0x1400c8068 ?_Acquire@_ReentrantBlockingLock@details@Concurrency@@QEAAXXZ
 0x1400c8070 ??1_ReentrantBlockingLock@details@Concurrency@@QEAA@XZ
IMM32.dll
 0x1400c80c0 ImmSetCompositionWindow
 0x1400c80c8 ImmGetContext
 0x1400c80d0 ImmSetCandidateWindow
 0x1400c80d8 ImmReleaseContext
D3DCOMPILER_47.dll
 0x1400c80b0 D3DCompile
CRYPT32.dll
 0x1400c8080 CertGetCertificateChain
 0x1400c8088 CertVerifyCertificateChainPolicy
 0x1400c8090 CertFreeCertificateChain
 0x1400c8098 CertFreeCertificateContext
 0x1400c80a0 CryptUnprotectMemory
crypt.dll
 0x1400c8d28 BCryptGetProperty
 0x1400c8d30 BCryptCloseAlgorithmProvider
 0x1400c8d38 BCryptDestroyHash
 0x1400c8d40 BCryptFinishHash
 0x1400c8d48 BCryptHashData
 0x1400c8d50 BCryptCreateHash
 0x1400c8d58 BCryptOpenAlgorithmProvider
WINHTTP.dll
 0x1400c89c0 WinHttpQueryAuthSchemes
 0x1400c89c8 WinHttpReceiveResponse
 0x1400c89d0 WinHttpSetCredentials
 0x1400c89d8 WinHttpGetIEProxyConfigForCurrentUser
 0x1400c89e0 WinHttpGetProxyForUrl
 0x1400c89e8 WinHttpQueryHeaders
 0x1400c89f0 WinHttpAddRequestHeaders
 0x1400c89f8 WinHttpOpenRequest
 0x1400c8a00 WinHttpSetTimeouts
 0x1400c8a08 WinHttpSetOption
 0x1400c8a10 WinHttpQueryOption
 0x1400c8a18 WinHttpQueryDataAvailable
 0x1400c8a20 WinHttpWriteData
 0x1400c8a28 WinHttpReadData
 0x1400c8a30 WinHttpConnect
 0x1400c8a38 WinHttpCloseHandle
 0x1400c8a40 WinHttpSendRequest
 0x1400c8a48 WinHttpOpen
 0x1400c8a50 WinHttpGetDefaultProxyConfiguration
 0x1400c8a58 WinHttpSetStatusCallback
d3d11.dll
 0x1400c8d68 D3D11CreateDeviceAndSwapChain
VCRUNTIME140.dll
 0x1400c8938 __std_exception_destroy
 0x1400c8940 _CxxThrowException
 0x1400c8948 __current_exception_context
 0x1400c8950 __std_exception_copy
 0x1400c8958 memmove
 0x1400c8960 __current_exception
 0x1400c8968 __C_specific_handler
 0x1400c8970 _purecall
 0x1400c8978 strstr
 0x1400c8980 memset
 0x1400c8988 memchr
 0x1400c8990 memcpy
 0x1400c8998 memcmp
 0x1400c89a0 __std_terminate
VCRUNTIME140_1.dll
 0x1400c89b0 __CxxFrameHandler4
api-ms-win-crt-runtime-l1-1-0.dll
 0x1400c8b38 _cexit
 0x1400c8b40 _crt_atexit
 0x1400c8b48 _seh_filter_exe
 0x1400c8b50 _register_onexit_function
 0x1400c8b58 _initialize_onexit_table
 0x1400c8b60 _initialize_narrow_environment
 0x1400c8b68 _set_app_type
 0x1400c8b70 _configure_narrow_argv
 0x1400c8b78 abort
 0x1400c8b80 _invalid_parameter_noinfo_noreturn
 0x1400c8b88 _get_narrow_winmain_command_line
 0x1400c8b90 _initterm
 0x1400c8b98 _initterm_e
 0x1400c8ba0 exit
 0x1400c8ba8 _exit
 0x1400c8bb0 _c_exit
 0x1400c8bb8 _register_thread_local_exe_atexit_callback
 0x1400c8bc0 _beginthreadex
 0x1400c8bc8 terminate
 0x1400c8bd0 _errno
api-ms-win-crt-string-l1-1-0.dll
 0x1400c8ca8 strcmp
 0x1400c8cb0 strncmp
 0x1400c8cb8 isdigit
 0x1400c8cc0 isalpha
 0x1400c8cc8 isxdigit
 0x1400c8cd0 strcpy_s
 0x1400c8cd8 strcat_s
 0x1400c8ce0 strncpy
api-ms-win-crt-stdio-l1-1-0.dll
 0x1400c8be0 fseek
 0x1400c8be8 _wfopen
 0x1400c8bf0 __stdio_common_vsprintf
 0x1400c8bf8 __stdio_common_vsprintf_s
 0x1400c8c00 __stdio_common_vsscanf
 0x1400c8c08 ftell
 0x1400c8c10 __stdio_common_vfprintf
 0x1400c8c18 ungetc
 0x1400c8c20 setvbuf
 0x1400c8c28 _fseeki64
 0x1400c8c30 fsetpos
 0x1400c8c38 fread
 0x1400c8c40 fputc
 0x1400c8c48 fgetpos
 0x1400c8c50 fgetc
 0x1400c8c58 fflush
 0x1400c8c60 _get_stream_buffer_pointers
 0x1400c8c68 __p__commode
 0x1400c8c70 _set_fmode
 0x1400c8c78 fwrite
 0x1400c8c80 __acrt_iob_func
 0x1400c8c88 feof
 0x1400c8c90 ferror
 0x1400c8c98 fclose
api-ms-win-crt-heap-l1-1-0.dll
 0x1400c8ab8 malloc
 0x1400c8ac0 free
 0x1400c8ac8 realloc
 0x1400c8ad0 _callnewh
 0x1400c8ad8 _set_new_mode
api-ms-win-crt-convert-l1-1-0.dll
 0x1400c8a68 atoi
 0x1400c8a70 wcstol
 0x1400c8a78 wcstombs_s
api-ms-win-crt-filesystem-l1-1-0.dll
 0x1400c8a88 _mkdir
 0x1400c8a90 _access_s
 0x1400c8a98 remove
 0x1400c8aa0 _lock_file
 0x1400c8aa8 _unlock_file
api-ms-win-crt-time-l1-1-0.dll
 0x1400c8cf0 _time64
 0x1400c8cf8 strftime
 0x1400c8d00 _localtime64
 0x1400c8d08 _localtime64_s
api-ms-win-crt-math-l1-1-0.dll
 0x1400c8af8 sqrtf
 0x1400c8b00 cosf
 0x1400c8b08 fmodf
 0x1400c8b10 ceilf
 0x1400c8b18 sinf
 0x1400c8b20 acosf
 0x1400c8b28 __setusermatherr
api-ms-win-crt-utility-l1-1-0.dll
 0x1400c8d18 qsort
api-ms-win-crt-locale-l1-1-0.dll
 0x1400c8ae8 _configthreadlocale

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure