Report - tt2.exe

Malicious Library Antivirus UPX Anti_VM PE File PE64 OS Processor Check
ScreenShot
Created 2024.08.11 15:01 Machine s1_win7_x6403
Filename tt2.exe
Type PE32+ executable (GUI) x86-64, for MS Windows
AI Score
4
Behavior Score
1.2
ZERO API file : malware
VT API (file) 41 detected (AIDetectMalware, malicious, high confidence, score, Zusy, Unsafe, Vtw4, Attribute, HighConfidence, GameHack, JJ potentially unsafe, Artemis, TrojanX, AGEN, Generic Reputation PUA, Static AI, Suspicious PE, Detected, ai score=80, Wacapew, R639555, Chgt, R002H09H924, susgen)
md5 ae136ee998229f2898b20cc44cf2bc99
sha256 4f464533c92ec3544e089e2675243b809d21358d3e00964a409458ae3913073e
ssdeep 49152:RjfTJ/oCSH68lv7kwLyuKV6KZPlI1XGjwgTnVTAbY4Rxkcm5j:RjfTPSKZFhTAkYxkV5j
imphash 7a9121c1bce825374af94f5121aa08bf
impfuzzy 192:GpbWpuBE3+wh2dvCRUII8aJrc+FyaBcP82u7TD1GHy2+m:Gpb8uAWER3CyaBcP8hTwSPm
  Network IP location

Signature (1cnts)

Level Description
danger File has been identified by 41 AntiVirus engines on VirusTotal as malicious

Rules (7cnts)

Level Name Description Collection
watch Antivirus Contains references to security software binaries (upload)
watch Malicious_Library_Zero Malicious_Library binaries (upload)
watch UPX_Zero UPX packed file binaries (upload)
notice anti_vm_detect Possibly employs anti-virtualization techniques binaries (upload)
info IsPE64 (no description) binaries (upload)
info OS_Processor_Check_Zero OS Processor Check binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids

PE API

IAT(Import Address Table) Library

KERNEL32.dll
 0x1400c60e8 GetFirmwareType
 0x1400c60f0 InitializeCriticalSectionEx
 0x1400c60f8 DeleteCriticalSection
 0x1400c6100 FormatMessageA
 0x1400c6108 LocalFree
 0x1400c6110 GetCurrentThread
 0x1400c6118 Sleep
 0x1400c6120 VerifyVersionInfoW
 0x1400c6128 SetFileCompletionNotificationModes
 0x1400c6130 CloseThreadpoolIo
 0x1400c6138 CancelThreadpoolIo
 0x1400c6140 StartThreadpoolIo
 0x1400c6148 CreateThreadpoolIo
 0x1400c6150 GetOverlappedResult
 0x1400c6158 WriteFile
 0x1400c6160 ReadFile
 0x1400c6168 CreateFileW
 0x1400c6170 FormatMessageW
 0x1400c6178 OutputDebugStringW
 0x1400c6180 InitializeSListHead
 0x1400c6188 GetSystemTimeAsFileTime
 0x1400c6190 GetCurrentThreadId
 0x1400c6198 ExpandEnvironmentStringsA
 0x1400c61a0 GetModuleHandleW
 0x1400c61a8 IsProcessorFeaturePresent
 0x1400c61b0 GetStartupInfoW
 0x1400c61b8 SetUnhandledExceptionFilter
 0x1400c61c0 UnhandledExceptionFilter
 0x1400c61c8 IsDebuggerPresent
 0x1400c61d0 RtlVirtualUnwind
 0x1400c61d8 RtlLookupFunctionEntry
 0x1400c61e0 RtlCaptureContext
 0x1400c61e8 SleepConditionVariableSRW
 0x1400c61f0 WakeAllConditionVariable
 0x1400c61f8 AcquireSRWLockExclusive
 0x1400c6200 ReleaseSRWLockExclusive
 0x1400c6208 InitOnceComplete
 0x1400c6210 InitOnceBeginInitialize
 0x1400c6218 QueryPerformanceFrequency
 0x1400c6220 GetUserDefaultLocaleName
 0x1400c6228 FindClose
 0x1400c6230 LoadLibraryA
 0x1400c6238 GetProcAddress
 0x1400c6240 GetModuleHandleA
 0x1400c6248 GetModuleFileNameA
 0x1400c6250 QueryPerformanceCounter
 0x1400c6258 VerSetConditionMask
 0x1400c6260 WideCharToMultiByte
 0x1400c6268 MultiByteToWideChar
 0x1400c6270 FreeLibrary
 0x1400c6278 TerminateProcess
 0x1400c6280 ExitProcess
 0x1400c6288 GetCurrentProcess
 0x1400c6290 WaitForSingleObject
 0x1400c6298 GetLastError
 0x1400c62a0 CloseHandle
 0x1400c62a8 GlobalFree
 0x1400c62b0 GlobalLock
 0x1400c62b8 GetFirmwareEnvironmentVariableA
 0x1400c62c0 GlobalUnlock
 0x1400c62c8 GlobalAlloc
 0x1400c62d0 GetCurrentProcessId
 0x1400c62d8 GetTickCount64
 0x1400c62e0 FindNextFileA
 0x1400c62e8 FindFirstFileA
 0x1400c62f0 GetFileSizeEx
 0x1400c62f8 GetLocaleInfoEx
USER32.dll
 0x1400c67f8 GetWindowRect
 0x1400c6800 OpenClipboard
 0x1400c6808 LoadIconA
 0x1400c6810 MoveWindow
 0x1400c6818 ShowWindow
 0x1400c6820 RegisterClassExA
 0x1400c6828 DestroyWindow
 0x1400c6830 CreateWindowExW
 0x1400c6838 RegisterClassExW
 0x1400c6840 UnregisterClassW
 0x1400c6848 UnregisterClassA
 0x1400c6850 PostQuitMessage
 0x1400c6858 DefWindowProcA
 0x1400c6860 PeekMessageA
 0x1400c6868 CreateWindowExA
 0x1400c6870 UpdateWindow
 0x1400c6878 SetWindowPos
 0x1400c6880 TranslateMessage
 0x1400c6888 LoadCursorA
 0x1400c6890 CloseClipboard
 0x1400c6898 SetClipboardData
 0x1400c68a0 GetClipboardData
 0x1400c68a8 EmptyClipboard
 0x1400c68b0 TrackMouseEvent
 0x1400c68b8 ScreenToClient
 0x1400c68c0 GetMessageExtraInfo
 0x1400c68c8 GetKeyState
 0x1400c68d0 GetCapture
 0x1400c68d8 SetCapture
 0x1400c68e0 ReleaseCapture
 0x1400c68e8 GetSystemMetrics
 0x1400c68f0 DispatchMessageA
 0x1400c68f8 IsWindowUnicode
 0x1400c6900 GetForegroundWindow
 0x1400c6908 GetClientRect
 0x1400c6910 SetCursorPos
 0x1400c6918 SetCursor
 0x1400c6920 GetCursorPos
 0x1400c6928 ClientToScreen
ADVAPI32.dll
 0x1400c6000 GetUserNameW
 0x1400c6008 AdjustTokenPrivileges
 0x1400c6010 LookupPrivilegeValueA
 0x1400c6018 RegCloseKey
 0x1400c6020 RegGetValueA
 0x1400c6028 RegCreateKeyExA
 0x1400c6030 RegSetValueExA
 0x1400c6038 RegQueryValueExA
 0x1400c6040 RegOpenKeyExA
 0x1400c6048 OpenProcessToken
SHELL32.dll
 0x1400c67e8 ShellExecuteExA
MSVCP140.dll
 0x1400c6308 ?_New_Locimp@_Locimp@locale@std@@CAPEAV123@AEBV123@@Z
 0x1400c6310 ?_Locimp_Addfac@_Locimp@locale@std@@CAXPEAV123@PEAVfacet@23@_K@Z
 0x1400c6318 ?_Init@locale@std@@CAPEAV_Locimp@12@_N@Z
 0x1400c6320 ?out@?$codecvt@_WDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEB_W1AEAPEB_WPEAD3AEAPEAD@Z
 0x1400c6328 ??0?$codecvt@_WDU_Mbstatet@@@std@@QEAA@_K@Z
 0x1400c6330 ??1?$codecvt@_WDU_Mbstatet@@@std@@MEAA@XZ
 0x1400c6338 ??Bios_base@std@@QEBA_NXZ
 0x1400c6340 ?setf@ios_base@std@@QEAAHHH@Z
 0x1400c6348 ??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA@XZ
 0x1400c6350 ??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAA@XZ
 0x1400c6358 ?sbumpc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
 0x1400c6360 ?sgetc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
 0x1400c6368 ?snextc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
 0x1400c6370 ?eback@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ
 0x1400c6378 ?gptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ
 0x1400c6380 ?pptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ
 0x1400c6388 ?egptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ
 0x1400c6390 ?gbump@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXH@Z
 0x1400c6398 ?setg@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXPEAD00@Z
 0x1400c63a0 ?epptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ
 0x1400c63a8 ?setp@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXPEAD0@Z
 0x1400c63b0 ?setp@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXPEAD00@Z
 0x1400c63b8 ?_Pninc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAPEADXZ
 0x1400c63c0 ??1?$basic_ios@DU?$char_traits@D@std@@@std@@UEAA@XZ
 0x1400c63c8 ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z
 0x1400c63d0 ?rdbuf@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBAPEAV?$basic_streambuf@DU?$char_traits@D@std@@@2@XZ
 0x1400c63d8 ??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA@XZ
 0x1400c63e0 ??0?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z
 0x1400c63e8 ??1?$basic_istream@DU?$char_traits@D@std@@@std@@UEAA@XZ
 0x1400c63f0 ?_Ipfx@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA_N_N@Z
 0x1400c63f8 ??5?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAVios_base@1@AEAV21@@Z@Z
 0x1400c6400 ??5?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@AEAH@Z
 0x1400c6408 ?_Random_device@std@@YAIXZ
 0x1400c6410 ?_Incref@facet@locale@std@@UEAAXXZ
 0x1400c6418 ?_Decref@facet@locale@std@@UEAAPEAV_Facet_base@3@XZ
 0x1400c6420 ?imbue@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAXAEBVlocale@2@@Z
 0x1400c6428 ?sync@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ
 0x1400c6430 ?setbuf@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAPEAV12@PEAD_J@Z
 0x1400c6438 ?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEBD_J@Z
 0x1400c6440 ?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEAD_J@Z
 0x1400c6448 ?uflow@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ
 0x1400c6450 ?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JXZ
 0x1400c6458 ?_Unlock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ
 0x1400c6460 ?_Lock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ
 0x1400c6468 ?id@?$codecvt@_WDU_Mbstatet@@@std@@2V0locale@2@A
 0x1400c6470 _Mtx_init_in_situ
 0x1400c6478 _Mtx_destroy_in_situ
 0x1400c6480 ??0_Lockit@std@@QEAA@H@Z
 0x1400c6488 ??1_Lockit@std@@QEAA@XZ
 0x1400c6490 ?uncaught_exception@std@@YA_NXZ
 0x1400c6498 ?_Getgloballocale@locale@std@@CAPEAV_Locimp@12@XZ
 0x1400c64a0 ?always_noconv@codecvt_base@std@@QEBA_NXZ
 0x1400c64a8 ?in@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z
 0x1400c64b0 ?out@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z
 0x1400c64b8 ?unshift@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEAD1AEAPEAD@Z
 0x1400c64c0 ?_Getcat@?$codecvt@DDU_Mbstatet@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z
 0x1400c64c8 ?good@ios_base@std@@QEBA_NXZ
 0x1400c64d0 ?flags@ios_base@std@@QEBAHXZ
 0x1400c64d8 ?width@ios_base@std@@QEBA_JXZ
 0x1400c64e0 ??Bid@locale@std@@QEAA_KXZ
 0x1400c64e8 ?getloc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEBA?AVlocale@2@XZ
 0x1400c64f0 ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z
 0x1400c64f8 ?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z
 0x1400c6500 ?_Gndec@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAPEADXZ
 0x1400c6508 ?_Gninc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAPEADXZ
 0x1400c6510 ?_Gnavail@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBA_JXZ
 0x1400c6518 ?pbump@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXH@Z
 0x1400c6520 ?_Pnavail@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBA_JXZ
 0x1400c6528 ?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXXZ
 0x1400c6530 ?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXPEAPEAD0PEAH001@Z
 0x1400c6538 ?_Fiopen@std@@YAPEAU_iobuf@@PEBDHH@Z
 0x1400c6540 ?tie@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBAPEAV?$basic_ostream@DU?$char_traits@D@std@@@2@XZ
 0x1400c6548 ?fill@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADXZ
 0x1400c6550 ?widen@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADD@Z
 0x1400c6558 ??0?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z
 0x1400c6560 ??1?$basic_ostream@DU?$char_traits@D@std@@@std@@UEAA@XZ
 0x1400c6568 ?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ
 0x1400c6570 ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z
 0x1400c6578 ?put@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@D@Z
 0x1400c6580 ?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ
 0x1400c6588 ?id@?$codecvt@DDU_Mbstatet@@@std@@2V0locale@2@A
 0x1400c6590 _Thrd_detach
 0x1400c6598 _Cnd_do_broadcast_at_thread_exit
 0x1400c65a0 ?_Throw_Cpp_error@std@@YAXH@Z
 0x1400c65a8 ?_Xinvalid_argument@std@@YAXPEBD@Z
 0x1400c65b0 ?fail@ios_base@std@@QEBA_NXZ
 0x1400c65b8 ?__ExceptionPtrCreate@@YAXPEAX@Z
 0x1400c65c0 ?__ExceptionPtrDestroy@@YAXPEAX@Z
 0x1400c65c8 ?__ExceptionPtrCopy@@YAXPEAXPEBX@Z
 0x1400c65d0 ?__ExceptionPtrAssign@@YAXPEAXPEBX@Z
 0x1400c65d8 ?__ExceptionPtrToBool@@YA_NPEBX@Z
 0x1400c65e0 ?__ExceptionPtrCurrentException@@YAXPEAX@Z
 0x1400c65e8 ?__ExceptionPtrRethrow@@YAXPEBX@Z
 0x1400c65f0 ?__ExceptionPtrCopyException@@YAXPEAXPEBX1@Z
 0x1400c65f8 _Mtx_lock
 0x1400c6600 _Mtx_unlock
 0x1400c6608 _Cnd_init_in_situ
 0x1400c6610 _Cnd_destroy_in_situ
 0x1400c6618 _Cnd_wait
 0x1400c6620 _Cnd_broadcast
 0x1400c6628 ?_Schedule_chore@details@Concurrency@@YAHPEAU_Threadpool_chore@12@@Z
 0x1400c6630 ?_Release_chore@details@Concurrency@@YAXPEAU_Threadpool_chore@12@@Z
 0x1400c6638 ?_ReportUnobservedException@details@Concurrency@@YAXXZ
 0x1400c6640 ?GetCurrentThreadId@platform@details@Concurrency@@YAJXZ
 0x1400c6648 ?_Xbad_function_call@std@@YAXXZ
 0x1400c6650 ?_CallInContext@_ContextCallback@details@Concurrency@@QEBAXV?$function@$$A6AXXZ@std@@_N@Z
 0x1400c6658 ?_Reset@_ContextCallback@details@Concurrency@@AEAAXXZ
 0x1400c6660 ?_Assign@_ContextCallback@details@Concurrency@@AEAAXPEAX@Z
 0x1400c6668 ?_IsCurrentOriginSTA@_ContextCallback@details@Concurrency@@CA_NXZ
 0x1400c6670 ?_Capture@_ContextCallback@details@Concurrency@@AEAAXXZ
 0x1400c6678 ?ReportUnhandledError@_ExceptionHolder@details@Concurrency@@AEAAXXZ
 0x1400c6680 ??0task_continuation_context@Concurrency@@AEAA@XZ
 0x1400c6688 ?_LogScheduleTask@_TaskEventLogger@details@Concurrency@@QEAAX_N@Z
 0x1400c6690 ?_LogCancelTask@_TaskEventLogger@details@Concurrency@@QEAAXXZ
 0x1400c6698 ?_LogTaskCompleted@_TaskEventLogger@details@Concurrency@@QEAAXXZ
 0x1400c66a0 ?_LogTaskExecutionCompleted@_TaskEventLogger@details@Concurrency@@QEAAXXZ
 0x1400c66a8 ?_LogWorkItemStarted@_TaskEventLogger@details@Concurrency@@QEAAXXZ
 0x1400c66b0 ?_LogWorkItemCompleted@_TaskEventLogger@details@Concurrency@@QEAAXXZ
 0x1400c66b8 ?width@ios_base@std@@QEAA_J_J@Z
 0x1400c66c0 ?_Xout_of_range@std@@YAXPEBD@Z
 0x1400c66c8 ?_Xlength_error@std@@YAXPEBD@Z
 0x1400c66d0 ?_Xbad_alloc@std@@YAXXZ
 0x1400c66d8 ??5?$basic_istream@_WU?$char_traits@_W@std@@@std@@QEAAAEAV01@AEA_K@Z
 0x1400c66e0 ??6?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAAAEAV01@_K@Z
 0x1400c66e8 ??1?$basic_ostream@_WU?$char_traits@_W@std@@@std@@UEAA@XZ
 0x1400c66f0 ??0?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAA@PEAV?$basic_streambuf@_WU?$char_traits@_W@std@@@1@_N@Z
 0x1400c66f8 ?_Throw_C_error@std@@YAXH@Z
 0x1400c6700 ?__ExceptionPtrCompare@@YA_NPEBX0@Z
 0x1400c6708 ?flush@?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAAAEAV12@XZ
 0x1400c6710 ?_Osfx@?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAAXXZ
 0x1400c6718 ?sputn@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@QEAA_JPEB_W_J@Z
 0x1400c6720 ?sputc@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@QEAAG_W@Z
 0x1400c6728 ?xsputn@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@MEAA_JPEB_W_J@Z
 0x1400c6730 ?xsgetn@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@MEAA_JPEA_W_J@Z
 0x1400c6738 ?uflow@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@MEAAGXZ
 0x1400c6740 ?sync@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@MEAAHXZ
 0x1400c6748 ?showmanyc@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@MEAA_JXZ
 0x1400c6750 ?setbuf@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@MEAAPEAV12@PEA_W_J@Z
 0x1400c6758 ?imbue@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@MEAAXAEBVlocale@2@@Z
 0x1400c6760 ?_Unlock@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@UEAAXXZ
 0x1400c6768 ?_Lock@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@UEAAXXZ
 0x1400c6770 ??5?$basic_istream@_WU?$char_traits@_W@std@@@std@@QEAAAEAV01@AEAH@Z
 0x1400c6778 ??1?$basic_istream@_WU?$char_traits@_W@std@@@std@@UEAA@XZ
 0x1400c6780 ??0?$basic_istream@_WU?$char_traits@_W@std@@@std@@QEAA@PEAV?$basic_streambuf@_WU?$char_traits@_W@std@@@1@_N@Z
 0x1400c6788 ??0?$basic_ios@_WU?$char_traits@_W@std@@@std@@IEAA@XZ
 0x1400c6790 ?imbue@?$basic_ios@_WU?$char_traits@_W@std@@@std@@QEAA?AVlocale@2@AEBV32@@Z
 0x1400c6798 ?setstate@?$basic_ios@_WU?$char_traits@_W@std@@@std@@QEAAXH_N@Z
 0x1400c67a0 ??1?$basic_ios@_WU?$char_traits@_W@std@@@std@@UEAA@XZ
 0x1400c67a8 ?_Pninc@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@IEAAPEA_WXZ
 0x1400c67b0 ??1?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@UEAA@XZ
 0x1400c67b8 ??0?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@IEAA@XZ
 0x1400c67c0 ?classic@locale@std@@SAAEBV12@XZ
 0x1400c67c8 ?_Winerror_map@std@@YAHH@Z
 0x1400c67d0 ?_Syserror_map@std@@YAPEBDH@Z
 0x1400c67d8 ??4?$_Yarn@D@std@@QEAAAEAV01@PEBD@Z
CONCRT140.dll
 0x1400c6058 ?_Release@_ReentrantBlockingLock@details@Concurrency@@QEAAXXZ
 0x1400c6060 ??0_ReentrantBlockingLock@details@Concurrency@@QEAA@XZ
 0x1400c6068 ?_Acquire@_ReentrantBlockingLock@details@Concurrency@@QEAAXXZ
 0x1400c6070 ??1_ReentrantBlockingLock@details@Concurrency@@QEAA@XZ
IMM32.dll
 0x1400c60c0 ImmSetCompositionWindow
 0x1400c60c8 ImmGetContext
 0x1400c60d0 ImmSetCandidateWindow
 0x1400c60d8 ImmReleaseContext
D3DCOMPILER_47.dll
 0x1400c60b0 D3DCompile
CRYPT32.dll
 0x1400c6080 CertGetCertificateChain
 0x1400c6088 CertVerifyCertificateChainPolicy
 0x1400c6090 CertFreeCertificateChain
 0x1400c6098 CertFreeCertificateContext
 0x1400c60a0 CryptUnprotectMemory
crypt.dll
 0x1400c6d28 BCryptGetProperty
 0x1400c6d30 BCryptCloseAlgorithmProvider
 0x1400c6d38 BCryptDestroyHash
 0x1400c6d40 BCryptFinishHash
 0x1400c6d48 BCryptHashData
 0x1400c6d50 BCryptCreateHash
 0x1400c6d58 BCryptOpenAlgorithmProvider
WINHTTP.dll
 0x1400c69c0 WinHttpQueryAuthSchemes
 0x1400c69c8 WinHttpReceiveResponse
 0x1400c69d0 WinHttpSetCredentials
 0x1400c69d8 WinHttpGetIEProxyConfigForCurrentUser
 0x1400c69e0 WinHttpGetProxyForUrl
 0x1400c69e8 WinHttpQueryHeaders
 0x1400c69f0 WinHttpAddRequestHeaders
 0x1400c69f8 WinHttpOpenRequest
 0x1400c6a00 WinHttpSetTimeouts
 0x1400c6a08 WinHttpSetOption
 0x1400c6a10 WinHttpQueryOption
 0x1400c6a18 WinHttpQueryDataAvailable
 0x1400c6a20 WinHttpWriteData
 0x1400c6a28 WinHttpReadData
 0x1400c6a30 WinHttpConnect
 0x1400c6a38 WinHttpCloseHandle
 0x1400c6a40 WinHttpSendRequest
 0x1400c6a48 WinHttpOpen
 0x1400c6a50 WinHttpGetDefaultProxyConfiguration
 0x1400c6a58 WinHttpSetStatusCallback
d3d11.dll
 0x1400c6d68 D3D11CreateDeviceAndSwapChain
VCRUNTIME140.dll
 0x1400c6938 __std_exception_destroy
 0x1400c6940 _CxxThrowException
 0x1400c6948 __current_exception_context
 0x1400c6950 __std_exception_copy
 0x1400c6958 memmove
 0x1400c6960 __current_exception
 0x1400c6968 __C_specific_handler
 0x1400c6970 _purecall
 0x1400c6978 strstr
 0x1400c6980 memset
 0x1400c6988 memchr
 0x1400c6990 memcpy
 0x1400c6998 memcmp
 0x1400c69a0 __std_terminate
VCRUNTIME140_1.dll
 0x1400c69b0 __CxxFrameHandler4
api-ms-win-crt-runtime-l1-1-0.dll
 0x1400c6b38 _cexit
 0x1400c6b40 _crt_atexit
 0x1400c6b48 _seh_filter_exe
 0x1400c6b50 _register_onexit_function
 0x1400c6b58 _initialize_onexit_table
 0x1400c6b60 _initialize_narrow_environment
 0x1400c6b68 _set_app_type
 0x1400c6b70 _configure_narrow_argv
 0x1400c6b78 abort
 0x1400c6b80 _invalid_parameter_noinfo_noreturn
 0x1400c6b88 _get_narrow_winmain_command_line
 0x1400c6b90 _initterm
 0x1400c6b98 _initterm_e
 0x1400c6ba0 exit
 0x1400c6ba8 _exit
 0x1400c6bb0 _c_exit
 0x1400c6bb8 _register_thread_local_exe_atexit_callback
 0x1400c6bc0 _beginthreadex
 0x1400c6bc8 terminate
 0x1400c6bd0 _errno
api-ms-win-crt-string-l1-1-0.dll
 0x1400c6ca8 strcmp
 0x1400c6cb0 strncmp
 0x1400c6cb8 isdigit
 0x1400c6cc0 isalpha
 0x1400c6cc8 isxdigit
 0x1400c6cd0 strcpy_s
 0x1400c6cd8 strcat_s
 0x1400c6ce0 strncpy
api-ms-win-crt-stdio-l1-1-0.dll
 0x1400c6be0 fseek
 0x1400c6be8 _wfopen
 0x1400c6bf0 __stdio_common_vsprintf
 0x1400c6bf8 __stdio_common_vsprintf_s
 0x1400c6c00 __stdio_common_vsscanf
 0x1400c6c08 ftell
 0x1400c6c10 __stdio_common_vfprintf
 0x1400c6c18 ungetc
 0x1400c6c20 setvbuf
 0x1400c6c28 _fseeki64
 0x1400c6c30 fsetpos
 0x1400c6c38 fread
 0x1400c6c40 fputc
 0x1400c6c48 fgetpos
 0x1400c6c50 fgetc
 0x1400c6c58 fflush
 0x1400c6c60 _get_stream_buffer_pointers
 0x1400c6c68 __p__commode
 0x1400c6c70 _set_fmode
 0x1400c6c78 fwrite
 0x1400c6c80 __acrt_iob_func
 0x1400c6c88 feof
 0x1400c6c90 ferror
 0x1400c6c98 fclose
api-ms-win-crt-heap-l1-1-0.dll
 0x1400c6ab8 malloc
 0x1400c6ac0 free
 0x1400c6ac8 realloc
 0x1400c6ad0 _callnewh
 0x1400c6ad8 _set_new_mode
api-ms-win-crt-convert-l1-1-0.dll
 0x1400c6a68 atoi
 0x1400c6a70 wcstol
 0x1400c6a78 wcstombs_s
api-ms-win-crt-filesystem-l1-1-0.dll
 0x1400c6a88 _mkdir
 0x1400c6a90 _access_s
 0x1400c6a98 remove
 0x1400c6aa0 _lock_file
 0x1400c6aa8 _unlock_file
api-ms-win-crt-time-l1-1-0.dll
 0x1400c6cf0 _time64
 0x1400c6cf8 strftime
 0x1400c6d00 _localtime64
 0x1400c6d08 _localtime64_s
api-ms-win-crt-math-l1-1-0.dll
 0x1400c6af8 sqrtf
 0x1400c6b00 cosf
 0x1400c6b08 fmodf
 0x1400c6b10 ceilf
 0x1400c6b18 sinf
 0x1400c6b20 acosf
 0x1400c6b28 __setusermatherr
api-ms-win-crt-utility-l1-1-0.dll
 0x1400c6d18 qsort
api-ms-win-crt-locale-l1-1-0.dll
 0x1400c6ae8 _configthreadlocale

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure