Report - ax.exe

Malicious Library Antivirus UPX Anti_VM PE File PE64 OS Processor Check
ScreenShot
Created 2024.08.11 14:52 Machine s1_win7_x6401
Filename ax.exe
Type PE32+ executable (GUI) x86-64, for MS Windows
AI Score
4
Behavior Score
1.2
ZERO API file : malware
VT API (file) 41 detected (AIDetectMalware, GameHack, malicious, high confidence, score, Zusy, Unsafe, Vtze, Attribute, HighConfidence, JJ potentially unsafe, Artemis, TrojanX, AGEN, Generic Reputation PUA, Detected, ai score=87, Wacapew, R639555, Chgt, R002H09G524, susgen)
md5 3697adfd0eaf4b7835607c271843605a
sha256 0f29ae23f23cdb8eb08a0ebbbf9242e36477474ad508a915d2e3c25078dff75d
ssdeep 49152:BH7LVL6XPu4mRG+uS30quL/soyqXNRGfHnBnPkN4RxkcO5:BH7xq//ShnPaYxkN5
imphash 5a11991504a02547b5aae9fe8973da7c
impfuzzy 192:V+0WvuKE3+wh2dvCRUII8aJrc+FyaBc582u7TD1GHy20m:V+0qu5WER3CyaBc58hTwSjm
  Network IP location

Signature (1cnts)

Level Description
danger File has been identified by 41 AntiVirus engines on VirusTotal as malicious

Rules (7cnts)

Level Name Description Collection
watch Antivirus Contains references to security software binaries (upload)
watch Malicious_Library_Zero Malicious_Library binaries (upload)
watch UPX_Zero UPX packed file binaries (upload)
notice anti_vm_detect Possibly employs anti-virtualization techniques binaries (upload)
info IsPE64 (no description) binaries (upload)
info OS_Processor_Check_Zero OS Processor Check binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids

PE API

IAT(Import Address Table) Library

KERNEL32.dll
 0x1400c40e8 InitializeCriticalSectionEx
 0x1400c40f0 DeleteCriticalSection
 0x1400c40f8 FormatMessageA
 0x1400c4100 LocalFree
 0x1400c4108 GetCurrentThread
 0x1400c4110 Sleep
 0x1400c4118 VerifyVersionInfoW
 0x1400c4120 SetFileCompletionNotificationModes
 0x1400c4128 CloseThreadpoolIo
 0x1400c4130 CancelThreadpoolIo
 0x1400c4138 StartThreadpoolIo
 0x1400c4140 CreateThreadpoolIo
 0x1400c4148 GetOverlappedResult
 0x1400c4150 WriteFile
 0x1400c4158 ReadFile
 0x1400c4160 GetFileSizeEx
 0x1400c4168 FormatMessageW
 0x1400c4170 OutputDebugStringW
 0x1400c4178 InitializeSListHead
 0x1400c4180 GetSystemTimeAsFileTime
 0x1400c4188 GetCurrentThreadId
 0x1400c4190 GetFirmwareEnvironmentVariableA
 0x1400c4198 GetModuleHandleW
 0x1400c41a0 IsProcessorFeaturePresent
 0x1400c41a8 GetStartupInfoW
 0x1400c41b0 SetUnhandledExceptionFilter
 0x1400c41b8 UnhandledExceptionFilter
 0x1400c41c0 IsDebuggerPresent
 0x1400c41c8 RtlVirtualUnwind
 0x1400c41d0 RtlLookupFunctionEntry
 0x1400c41d8 RtlCaptureContext
 0x1400c41e0 SleepConditionVariableSRW
 0x1400c41e8 WakeAllConditionVariable
 0x1400c41f0 AcquireSRWLockExclusive
 0x1400c41f8 ReleaseSRWLockExclusive
 0x1400c4200 InitOnceComplete
 0x1400c4208 InitOnceBeginInitialize
 0x1400c4210 QueryPerformanceFrequency
 0x1400c4218 FindClose
 0x1400c4220 GetUserDefaultLocaleName
 0x1400c4228 LoadLibraryA
 0x1400c4230 GetProcAddress
 0x1400c4238 GetModuleHandleA
 0x1400c4240 GetModuleFileNameA
 0x1400c4248 QueryPerformanceCounter
 0x1400c4250 VerSetConditionMask
 0x1400c4258 WideCharToMultiByte
 0x1400c4260 MultiByteToWideChar
 0x1400c4268 FreeLibrary
 0x1400c4270 TerminateProcess
 0x1400c4278 ExitProcess
 0x1400c4280 GetCurrentProcess
 0x1400c4288 WaitForSingleObject
 0x1400c4290 GetLastError
 0x1400c4298 CloseHandle
 0x1400c42a0 GlobalFree
 0x1400c42a8 GlobalLock
 0x1400c42b0 GetFirmwareType
 0x1400c42b8 GlobalUnlock
 0x1400c42c0 GlobalAlloc
 0x1400c42c8 GetCurrentProcessId
 0x1400c42d0 GetTickCount64
 0x1400c42d8 FindNextFileA
 0x1400c42e0 FindFirstFileA
 0x1400c42e8 CreateFileW
 0x1400c42f0 GetLocaleInfoEx
USER32.dll
 0x1400c47f0 GetWindowRect
 0x1400c47f8 OpenClipboard
 0x1400c4800 LoadIconA
 0x1400c4808 MoveWindow
 0x1400c4810 ShowWindow
 0x1400c4818 RegisterClassExA
 0x1400c4820 DestroyWindow
 0x1400c4828 CreateWindowExW
 0x1400c4830 RegisterClassExW
 0x1400c4838 UnregisterClassW
 0x1400c4840 UnregisterClassA
 0x1400c4848 PostQuitMessage
 0x1400c4850 DefWindowProcA
 0x1400c4858 PeekMessageA
 0x1400c4860 CreateWindowExA
 0x1400c4868 UpdateWindow
 0x1400c4870 SetWindowPos
 0x1400c4878 TranslateMessage
 0x1400c4880 LoadCursorA
 0x1400c4888 CloseClipboard
 0x1400c4890 SetClipboardData
 0x1400c4898 GetClipboardData
 0x1400c48a0 EmptyClipboard
 0x1400c48a8 TrackMouseEvent
 0x1400c48b0 ScreenToClient
 0x1400c48b8 GetMessageExtraInfo
 0x1400c48c0 GetKeyState
 0x1400c48c8 GetCapture
 0x1400c48d0 SetCapture
 0x1400c48d8 ReleaseCapture
 0x1400c48e0 GetSystemMetrics
 0x1400c48e8 DispatchMessageA
 0x1400c48f0 IsWindowUnicode
 0x1400c48f8 GetForegroundWindow
 0x1400c4900 GetClientRect
 0x1400c4908 SetCursorPos
 0x1400c4910 SetCursor
 0x1400c4918 GetCursorPos
 0x1400c4920 ClientToScreen
ADVAPI32.dll
 0x1400c4000 GetUserNameW
 0x1400c4008 AdjustTokenPrivileges
 0x1400c4010 LookupPrivilegeValueA
 0x1400c4018 RegCloseKey
 0x1400c4020 RegGetValueA
 0x1400c4028 RegCreateKeyExA
 0x1400c4030 RegSetValueExA
 0x1400c4038 RegQueryValueExA
 0x1400c4040 RegOpenKeyExA
 0x1400c4048 OpenProcessToken
SHELL32.dll
 0x1400c47e0 ShellExecuteExA
MSVCP140.dll
 0x1400c4300 ?_New_Locimp@_Locimp@locale@std@@CAPEAV123@AEBV123@@Z
 0x1400c4308 ?_Locimp_Addfac@_Locimp@locale@std@@CAXPEAV123@PEAVfacet@23@_K@Z
 0x1400c4310 ?_Init@locale@std@@CAPEAV_Locimp@12@_N@Z
 0x1400c4318 ?out@?$codecvt@_WDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEB_W1AEAPEB_WPEAD3AEAPEAD@Z
 0x1400c4320 ??0?$codecvt@_WDU_Mbstatet@@@std@@QEAA@_K@Z
 0x1400c4328 ??1?$codecvt@_WDU_Mbstatet@@@std@@MEAA@XZ
 0x1400c4330 ??Bios_base@std@@QEBA_NXZ
 0x1400c4338 ?setf@ios_base@std@@QEAAHHH@Z
 0x1400c4340 ??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA@XZ
 0x1400c4348 ??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAA@XZ
 0x1400c4350 ?sbumpc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
 0x1400c4358 ?sgetc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
 0x1400c4360 ?snextc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
 0x1400c4368 ?eback@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ
 0x1400c4370 ?gptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ
 0x1400c4378 ?pptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ
 0x1400c4380 ?egptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ
 0x1400c4388 ?gbump@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXH@Z
 0x1400c4390 ?setg@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXPEAD00@Z
 0x1400c4398 ?epptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ
 0x1400c43a0 ?setp@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXPEAD0@Z
 0x1400c43a8 ?setp@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXPEAD00@Z
 0x1400c43b0 ?_Pninc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAPEADXZ
 0x1400c43b8 ??1?$basic_ios@DU?$char_traits@D@std@@@std@@UEAA@XZ
 0x1400c43c0 ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z
 0x1400c43c8 ?rdbuf@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBAPEAV?$basic_streambuf@DU?$char_traits@D@std@@@2@XZ
 0x1400c43d0 ??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA@XZ
 0x1400c43d8 ??0?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z
 0x1400c43e0 ??1?$basic_istream@DU?$char_traits@D@std@@@std@@UEAA@XZ
 0x1400c43e8 ?_Ipfx@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA_N_N@Z
 0x1400c43f0 ??5?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAVios_base@1@AEAV21@@Z@Z
 0x1400c43f8 ??5?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@AEAH@Z
 0x1400c4400 ?_Random_device@std@@YAIXZ
 0x1400c4408 ?_Incref@facet@locale@std@@UEAAXXZ
 0x1400c4410 ?_Decref@facet@locale@std@@UEAAPEAV_Facet_base@3@XZ
 0x1400c4418 ?imbue@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAXAEBVlocale@2@@Z
 0x1400c4420 ?sync@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ
 0x1400c4428 ?setbuf@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAPEAV12@PEAD_J@Z
 0x1400c4430 ?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEBD_J@Z
 0x1400c4438 ?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEAD_J@Z
 0x1400c4440 ?uflow@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ
 0x1400c4448 ?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JXZ
 0x1400c4450 ?_Unlock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ
 0x1400c4458 ?_Lock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ
 0x1400c4460 ?id@?$codecvt@_WDU_Mbstatet@@@std@@2V0locale@2@A
 0x1400c4468 _Mtx_init_in_situ
 0x1400c4470 _Mtx_destroy_in_situ
 0x1400c4478 ??0_Lockit@std@@QEAA@H@Z
 0x1400c4480 ??1_Lockit@std@@QEAA@XZ
 0x1400c4488 ?uncaught_exception@std@@YA_NXZ
 0x1400c4490 ?_Getgloballocale@locale@std@@CAPEAV_Locimp@12@XZ
 0x1400c4498 ?always_noconv@codecvt_base@std@@QEBA_NXZ
 0x1400c44a0 ?in@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z
 0x1400c44a8 ?out@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z
 0x1400c44b0 ?unshift@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEAD1AEAPEAD@Z
 0x1400c44b8 ?_Getcat@?$codecvt@DDU_Mbstatet@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z
 0x1400c44c0 ?good@ios_base@std@@QEBA_NXZ
 0x1400c44c8 ?flags@ios_base@std@@QEBAHXZ
 0x1400c44d0 ?width@ios_base@std@@QEBA_JXZ
 0x1400c44d8 ??Bid@locale@std@@QEAA_KXZ
 0x1400c44e0 ?getloc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEBA?AVlocale@2@XZ
 0x1400c44e8 ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z
 0x1400c44f0 ?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z
 0x1400c44f8 ?_Gndec@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAPEADXZ
 0x1400c4500 ?_Gninc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAPEADXZ
 0x1400c4508 ?_Gnavail@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBA_JXZ
 0x1400c4510 ?pbump@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXH@Z
 0x1400c4518 ?_Pnavail@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBA_JXZ
 0x1400c4520 ?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXXZ
 0x1400c4528 ?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXPEAPEAD0PEAH001@Z
 0x1400c4530 ?_Fiopen@std@@YAPEAU_iobuf@@PEBDHH@Z
 0x1400c4538 ?tie@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBAPEAV?$basic_ostream@DU?$char_traits@D@std@@@2@XZ
 0x1400c4540 ?fill@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADXZ
 0x1400c4548 ?widen@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADD@Z
 0x1400c4550 ??0?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z
 0x1400c4558 ??1?$basic_ostream@DU?$char_traits@D@std@@@std@@UEAA@XZ
 0x1400c4560 ?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ
 0x1400c4568 ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z
 0x1400c4570 ?put@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@D@Z
 0x1400c4578 ?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ
 0x1400c4580 ?id@?$codecvt@DDU_Mbstatet@@@std@@2V0locale@2@A
 0x1400c4588 _Thrd_detach
 0x1400c4590 _Cnd_do_broadcast_at_thread_exit
 0x1400c4598 ?_Throw_Cpp_error@std@@YAXH@Z
 0x1400c45a0 ?_Xinvalid_argument@std@@YAXPEBD@Z
 0x1400c45a8 ?fail@ios_base@std@@QEBA_NXZ
 0x1400c45b0 ?__ExceptionPtrCreate@@YAXPEAX@Z
 0x1400c45b8 ?__ExceptionPtrDestroy@@YAXPEAX@Z
 0x1400c45c0 ?__ExceptionPtrCopy@@YAXPEAXPEBX@Z
 0x1400c45c8 ?__ExceptionPtrAssign@@YAXPEAXPEBX@Z
 0x1400c45d0 ?__ExceptionPtrToBool@@YA_NPEBX@Z
 0x1400c45d8 ?__ExceptionPtrCurrentException@@YAXPEAX@Z
 0x1400c45e0 ?__ExceptionPtrRethrow@@YAXPEBX@Z
 0x1400c45e8 ?__ExceptionPtrCopyException@@YAXPEAXPEBX1@Z
 0x1400c45f0 _Mtx_lock
 0x1400c45f8 _Mtx_unlock
 0x1400c4600 _Cnd_init_in_situ
 0x1400c4608 _Cnd_destroy_in_situ
 0x1400c4610 _Cnd_wait
 0x1400c4618 _Cnd_broadcast
 0x1400c4620 ?_Schedule_chore@details@Concurrency@@YAHPEAU_Threadpool_chore@12@@Z
 0x1400c4628 ?_Release_chore@details@Concurrency@@YAXPEAU_Threadpool_chore@12@@Z
 0x1400c4630 ?_ReportUnobservedException@details@Concurrency@@YAXXZ
 0x1400c4638 ?GetCurrentThreadId@platform@details@Concurrency@@YAJXZ
 0x1400c4640 ?_Xbad_function_call@std@@YAXXZ
 0x1400c4648 ?_CallInContext@_ContextCallback@details@Concurrency@@QEBAXV?$function@$$A6AXXZ@std@@_N@Z
 0x1400c4650 ?_Reset@_ContextCallback@details@Concurrency@@AEAAXXZ
 0x1400c4658 ?_Assign@_ContextCallback@details@Concurrency@@AEAAXPEAX@Z
 0x1400c4660 ?_IsCurrentOriginSTA@_ContextCallback@details@Concurrency@@CA_NXZ
 0x1400c4668 ?_Capture@_ContextCallback@details@Concurrency@@AEAAXXZ
 0x1400c4670 ?ReportUnhandledError@_ExceptionHolder@details@Concurrency@@AEAAXXZ
 0x1400c4678 ??0task_continuation_context@Concurrency@@AEAA@XZ
 0x1400c4680 ?_LogScheduleTask@_TaskEventLogger@details@Concurrency@@QEAAX_N@Z
 0x1400c4688 ?_LogCancelTask@_TaskEventLogger@details@Concurrency@@QEAAXXZ
 0x1400c4690 ?_LogTaskCompleted@_TaskEventLogger@details@Concurrency@@QEAAXXZ
 0x1400c4698 ?_LogTaskExecutionCompleted@_TaskEventLogger@details@Concurrency@@QEAAXXZ
 0x1400c46a0 ?_LogWorkItemStarted@_TaskEventLogger@details@Concurrency@@QEAAXXZ
 0x1400c46a8 ?_LogWorkItemCompleted@_TaskEventLogger@details@Concurrency@@QEAAXXZ
 0x1400c46b0 ?width@ios_base@std@@QEAA_J_J@Z
 0x1400c46b8 ?_Xout_of_range@std@@YAXPEBD@Z
 0x1400c46c0 ?_Xlength_error@std@@YAXPEBD@Z
 0x1400c46c8 ?_Xbad_alloc@std@@YAXXZ
 0x1400c46d0 ??5?$basic_istream@_WU?$char_traits@_W@std@@@std@@QEAAAEAV01@AEA_K@Z
 0x1400c46d8 ??6?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAAAEAV01@_K@Z
 0x1400c46e0 ??1?$basic_ostream@_WU?$char_traits@_W@std@@@std@@UEAA@XZ
 0x1400c46e8 ??0?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAA@PEAV?$basic_streambuf@_WU?$char_traits@_W@std@@@1@_N@Z
 0x1400c46f0 ?_Throw_C_error@std@@YAXH@Z
 0x1400c46f8 ?__ExceptionPtrCompare@@YA_NPEBX0@Z
 0x1400c4700 ?flush@?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAAAEAV12@XZ
 0x1400c4708 ?_Osfx@?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAAXXZ
 0x1400c4710 ?sputn@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@QEAA_JPEB_W_J@Z
 0x1400c4718 ?sputc@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@QEAAG_W@Z
 0x1400c4720 ?xsputn@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@MEAA_JPEB_W_J@Z
 0x1400c4728 ?xsgetn@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@MEAA_JPEA_W_J@Z
 0x1400c4730 ?uflow@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@MEAAGXZ
 0x1400c4738 ?sync@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@MEAAHXZ
 0x1400c4740 ?showmanyc@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@MEAA_JXZ
 0x1400c4748 ?setbuf@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@MEAAPEAV12@PEA_W_J@Z
 0x1400c4750 ?imbue@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@MEAAXAEBVlocale@2@@Z
 0x1400c4758 ?_Unlock@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@UEAAXXZ
 0x1400c4760 ?_Lock@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@UEAAXXZ
 0x1400c4768 ??5?$basic_istream@_WU?$char_traits@_W@std@@@std@@QEAAAEAV01@AEAH@Z
 0x1400c4770 ??1?$basic_istream@_WU?$char_traits@_W@std@@@std@@UEAA@XZ
 0x1400c4778 ??0?$basic_istream@_WU?$char_traits@_W@std@@@std@@QEAA@PEAV?$basic_streambuf@_WU?$char_traits@_W@std@@@1@_N@Z
 0x1400c4780 ??0?$basic_ios@_WU?$char_traits@_W@std@@@std@@IEAA@XZ
 0x1400c4788 ?imbue@?$basic_ios@_WU?$char_traits@_W@std@@@std@@QEAA?AVlocale@2@AEBV32@@Z
 0x1400c4790 ?setstate@?$basic_ios@_WU?$char_traits@_W@std@@@std@@QEAAXH_N@Z
 0x1400c4798 ??1?$basic_ios@_WU?$char_traits@_W@std@@@std@@UEAA@XZ
 0x1400c47a0 ?_Pninc@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@IEAAPEA_WXZ
 0x1400c47a8 ??1?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@UEAA@XZ
 0x1400c47b0 ??0?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@IEAA@XZ
 0x1400c47b8 ?classic@locale@std@@SAAEBV12@XZ
 0x1400c47c0 ?_Winerror_map@std@@YAHH@Z
 0x1400c47c8 ?_Syserror_map@std@@YAPEBDH@Z
 0x1400c47d0 ??4?$_Yarn@D@std@@QEAAAEAV01@PEBD@Z
CONCRT140.dll
 0x1400c4058 ?_Release@_ReentrantBlockingLock@details@Concurrency@@QEAAXXZ
 0x1400c4060 ??0_ReentrantBlockingLock@details@Concurrency@@QEAA@XZ
 0x1400c4068 ?_Acquire@_ReentrantBlockingLock@details@Concurrency@@QEAAXXZ
 0x1400c4070 ??1_ReentrantBlockingLock@details@Concurrency@@QEAA@XZ
IMM32.dll
 0x1400c40c0 ImmSetCompositionWindow
 0x1400c40c8 ImmGetContext
 0x1400c40d0 ImmSetCandidateWindow
 0x1400c40d8 ImmReleaseContext
D3DCOMPILER_47.dll
 0x1400c40b0 D3DCompile
CRYPT32.dll
 0x1400c4080 CertGetCertificateChain
 0x1400c4088 CertFreeCertificateChain
 0x1400c4090 CertVerifyCertificateChainPolicy
 0x1400c4098 CertFreeCertificateContext
 0x1400c40a0 CryptUnprotectMemory
crypt.dll
 0x1400c4d18 BCryptGetProperty
 0x1400c4d20 BCryptCloseAlgorithmProvider
 0x1400c4d28 BCryptDestroyHash
 0x1400c4d30 BCryptFinishHash
 0x1400c4d38 BCryptHashData
 0x1400c4d40 BCryptCreateHash
 0x1400c4d48 BCryptOpenAlgorithmProvider
WINHTTP.dll
 0x1400c49b8 WinHttpQueryAuthSchemes
 0x1400c49c0 WinHttpReceiveResponse
 0x1400c49c8 WinHttpSetCredentials
 0x1400c49d0 WinHttpGetIEProxyConfigForCurrentUser
 0x1400c49d8 WinHttpGetProxyForUrl
 0x1400c49e0 WinHttpQueryHeaders
 0x1400c49e8 WinHttpAddRequestHeaders
 0x1400c49f0 WinHttpOpenRequest
 0x1400c49f8 WinHttpSetTimeouts
 0x1400c4a00 WinHttpSetOption
 0x1400c4a08 WinHttpQueryOption
 0x1400c4a10 WinHttpQueryDataAvailable
 0x1400c4a18 WinHttpWriteData
 0x1400c4a20 WinHttpReadData
 0x1400c4a28 WinHttpConnect
 0x1400c4a30 WinHttpCloseHandle
 0x1400c4a38 WinHttpSendRequest
 0x1400c4a40 WinHttpOpen
 0x1400c4a48 WinHttpGetDefaultProxyConfiguration
 0x1400c4a50 WinHttpSetStatusCallback
d3d11.dll
 0x1400c4d58 D3D11CreateDeviceAndSwapChain
VCRUNTIME140.dll
 0x1400c4930 __std_exception_destroy
 0x1400c4938 _CxxThrowException
 0x1400c4940 __current_exception_context
 0x1400c4948 __std_exception_copy
 0x1400c4950 memmove
 0x1400c4958 __current_exception
 0x1400c4960 __C_specific_handler
 0x1400c4968 _purecall
 0x1400c4970 strstr
 0x1400c4978 memset
 0x1400c4980 memchr
 0x1400c4988 memcpy
 0x1400c4990 memcmp
 0x1400c4998 __std_terminate
VCRUNTIME140_1.dll
 0x1400c49a8 __CxxFrameHandler4
api-ms-win-crt-runtime-l1-1-0.dll
 0x1400c4b28 _cexit
 0x1400c4b30 _crt_atexit
 0x1400c4b38 _seh_filter_exe
 0x1400c4b40 _register_onexit_function
 0x1400c4b48 _initialize_onexit_table
 0x1400c4b50 _initialize_narrow_environment
 0x1400c4b58 _set_app_type
 0x1400c4b60 _configure_narrow_argv
 0x1400c4b68 abort
 0x1400c4b70 _invalid_parameter_noinfo_noreturn
 0x1400c4b78 _get_narrow_winmain_command_line
 0x1400c4b80 _initterm
 0x1400c4b88 _initterm_e
 0x1400c4b90 exit
 0x1400c4b98 _exit
 0x1400c4ba0 _c_exit
 0x1400c4ba8 _register_thread_local_exe_atexit_callback
 0x1400c4bb0 _beginthreadex
 0x1400c4bb8 terminate
 0x1400c4bc0 _errno
api-ms-win-crt-string-l1-1-0.dll
 0x1400c4c98 strcmp
 0x1400c4ca0 strncmp
 0x1400c4ca8 isdigit
 0x1400c4cb0 isalpha
 0x1400c4cb8 isxdigit
 0x1400c4cc0 strcpy_s
 0x1400c4cc8 strcat_s
 0x1400c4cd0 strncpy
api-ms-win-crt-stdio-l1-1-0.dll
 0x1400c4bd0 fseek
 0x1400c4bd8 _wfopen
 0x1400c4be0 __stdio_common_vsprintf
 0x1400c4be8 __stdio_common_vsprintf_s
 0x1400c4bf0 __stdio_common_vsscanf
 0x1400c4bf8 ftell
 0x1400c4c00 __stdio_common_vfprintf
 0x1400c4c08 ungetc
 0x1400c4c10 setvbuf
 0x1400c4c18 _fseeki64
 0x1400c4c20 fsetpos
 0x1400c4c28 fread
 0x1400c4c30 fputc
 0x1400c4c38 fgetpos
 0x1400c4c40 fgetc
 0x1400c4c48 fflush
 0x1400c4c50 _get_stream_buffer_pointers
 0x1400c4c58 __p__commode
 0x1400c4c60 _set_fmode
 0x1400c4c68 fwrite
 0x1400c4c70 __acrt_iob_func
 0x1400c4c78 feof
 0x1400c4c80 ferror
 0x1400c4c88 fclose
api-ms-win-crt-heap-l1-1-0.dll
 0x1400c4aa8 malloc
 0x1400c4ab0 free
 0x1400c4ab8 realloc
 0x1400c4ac0 _callnewh
 0x1400c4ac8 _set_new_mode
api-ms-win-crt-convert-l1-1-0.dll
 0x1400c4a60 wcstol
 0x1400c4a68 wcstombs_s
api-ms-win-crt-filesystem-l1-1-0.dll
 0x1400c4a78 _mkdir
 0x1400c4a80 _access_s
 0x1400c4a88 remove
 0x1400c4a90 _lock_file
 0x1400c4a98 _unlock_file
api-ms-win-crt-time-l1-1-0.dll
 0x1400c4ce0 _time64
 0x1400c4ce8 strftime
 0x1400c4cf0 _localtime64
 0x1400c4cf8 _localtime64_s
api-ms-win-crt-math-l1-1-0.dll
 0x1400c4ae8 sqrtf
 0x1400c4af0 cosf
 0x1400c4af8 fmodf
 0x1400c4b00 ceilf
 0x1400c4b08 sinf
 0x1400c4b10 acosf
 0x1400c4b18 __setusermatherr
api-ms-win-crt-utility-l1-1-0.dll
 0x1400c4d08 qsort
api-ms-win-crt-locale-l1-1-0.dll
 0x1400c4ad8 _configthreadlocale

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure