Report - r6.exe

Malicious Library Antivirus UPX PE File PE64 OS Processor Check
ScreenShot
Created 2024.08.12 10:04 Machine s1_win7_x6403
Filename r6.exe
Type PE32+ executable (GUI) x86-64, for MS Windows
AI Score
4
Behavior Score
1.8
ZERO API file : malware
VT API (file) 36 detected (AIDetectMalware, Gamehack, malicious, high confidence, Mikey, Unsafe, V2hl, Attribute, HighConfidence, AGen, OZ potentially unsafe, CLOUD, Detected, ai score=83, ApplicUnwnt@#3thfb32i0fcl0, Casdet, Whisperer, Chgt, R002H09ET24, IiKmFt34G9M, susgen, PossibleThreat, PALLAS, confidence)
md5 9506cd00f985244da45f70bbcf1f2518
sha256 a032488812df1bba3922c2dc6bbc5574aba27fbf3c7e3e244e8cf7c52116c38e
ssdeep 49152:Y944Hm8Vo+O5MLvxvlU/A7o7RXNjwjlnivzLxs9AtWvLQ1XkpP1T7vXmbNzXV8q:Y9jYwinxJtWTQ1UnPk8q
imphash b071717308393751e0beeb59457f22d2
impfuzzy 192:s6XWJ7C4ftpTWmLzxvq8NhoRaxgNQgqJi2h2AiDxjFNJ:s6XI7PTDL9t0NQTJiAhKxXJ
  Network IP location

Signature (3cnts)

Level Description
danger File has been identified by 36 AntiVirus engines on VirusTotal as malicious
watch Communicates with host for which no DNS query was performed
info This executable has a PDB path

Rules (6cnts)

Level Name Description Collection
watch Antivirus Contains references to security software binaries (upload)
watch Malicious_Library_Zero Malicious_Library binaries (upload)
watch UPX_Zero UPX packed file binaries (upload)
info IsPE64 (no description) binaries (upload)
info OS_Processor_Check_Zero OS Processor Check binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (2cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
194.58.114.223 RU Domain names registrar REG.RU, Ltd 194.58.114.223 mailcious
152.195.38.76 US EDGECAST 152.195.38.76 clean

Suricata ids

PE API

IAT(Import Address Table) Library

KERNEL32.dll
 0x1400ce0f8 InitializeCriticalSectionEx
 0x1400ce100 DeleteCriticalSection
 0x1400ce108 GetLocaleInfoEx
 0x1400ce110 FormatMessageA
 0x1400ce118 LocalFree
 0x1400ce120 GetFirmwareEnvironmentVariableA
 0x1400ce128 GetTickCount64
 0x1400ce130 VerifyVersionInfoW
 0x1400ce138 FormatMessageW
 0x1400ce140 SetFileCompletionNotificationModes
 0x1400ce148 CloseThreadpoolIo
 0x1400ce150 CancelThreadpoolIo
 0x1400ce158 StartThreadpoolIo
 0x1400ce160 CreateThreadpoolIo
 0x1400ce168 GetOverlappedResult
 0x1400ce170 WriteFile
 0x1400ce178 GetCurrentThread
 0x1400ce180 GetFileSizeEx
 0x1400ce188 CreateFileW
 0x1400ce190 OutputDebugStringW
 0x1400ce198 InitOnceBeginInitialize
 0x1400ce1a0 InitOnceComplete
 0x1400ce1a8 InitializeSListHead
 0x1400ce1b0 GetSystemTimeAsFileTime
 0x1400ce1b8 GetCurrentThreadId
 0x1400ce1c0 GetCurrentProcessId
 0x1400ce1c8 GetModuleHandleW
 0x1400ce1d0 GetStartupInfoW
 0x1400ce1d8 IsDebuggerPresent
 0x1400ce1e0 IsProcessorFeaturePresent
 0x1400ce1e8 SetUnhandledExceptionFilter
 0x1400ce1f0 UnhandledExceptionFilter
 0x1400ce1f8 RtlVirtualUnwind
 0x1400ce200 RtlLookupFunctionEntry
 0x1400ce208 RtlCaptureContext
 0x1400ce210 SleepConditionVariableSRW
 0x1400ce218 WakeAllConditionVariable
 0x1400ce220 AcquireSRWLockExclusive
 0x1400ce228 ReleaseSRWLockExclusive
 0x1400ce230 Sleep
 0x1400ce238 ExitProcess
 0x1400ce240 CloseHandle
 0x1400ce248 GetLastError
 0x1400ce250 WaitForSingleObject
 0x1400ce258 FindClose
 0x1400ce260 FindNextFileA
 0x1400ce268 GetUserDefaultLocaleName
 0x1400ce270 TerminateProcess
 0x1400ce278 GetCurrentProcess
 0x1400ce280 FindFirstFileA
 0x1400ce288 GetModuleFileNameA
 0x1400ce290 GlobalUnlock
 0x1400ce298 WideCharToMultiByte
 0x1400ce2a0 GlobalLock
 0x1400ce2a8 GlobalFree
 0x1400ce2b0 GlobalAlloc
 0x1400ce2b8 QueryPerformanceCounter
 0x1400ce2c0 FreeLibrary
 0x1400ce2c8 VerSetConditionMask
 0x1400ce2d0 GetProcAddress
 0x1400ce2d8 QueryPerformanceFrequency
 0x1400ce2e0 LoadLibraryA
 0x1400ce2e8 GetFirmwareType
 0x1400ce2f0 MultiByteToWideChar
 0x1400ce2f8 GetModuleHandleA
 0x1400ce300 GetLocaleInfoA
 0x1400ce308 ReadFile
USER32.dll
 0x1400ce750 LoadIconA
 0x1400ce758 CreateWindowExA
 0x1400ce760 RegisterClassExA
 0x1400ce768 SetCursorPos
 0x1400ce770 DispatchMessageA
 0x1400ce778 GetWindowRect
 0x1400ce780 ReleaseCapture
 0x1400ce788 DestroyWindow
 0x1400ce790 GetCursorPos
 0x1400ce798 CreateWindowExW
 0x1400ce7a0 GetSystemMetrics
 0x1400ce7a8 UnregisterClassW
 0x1400ce7b0 RegisterClassExW
 0x1400ce7b8 ShowWindow
 0x1400ce7c0 MoveWindow
 0x1400ce7c8 DefWindowProcA
 0x1400ce7d0 TranslateMessage
 0x1400ce7d8 PeekMessageA
 0x1400ce7e0 PostQuitMessage
 0x1400ce7e8 UpdateWindow
 0x1400ce7f0 OpenClipboard
 0x1400ce7f8 SetWindowRgn
 0x1400ce800 IsWindowUnicode
 0x1400ce808 GetClientRect
 0x1400ce810 CloseClipboard
 0x1400ce818 EmptyClipboard
 0x1400ce820 SetCursor
 0x1400ce828 SetCapture
 0x1400ce830 GetForegroundWindow
 0x1400ce838 GetKeyboardLayout
 0x1400ce840 TrackMouseEvent
 0x1400ce848 ClientToScreen
 0x1400ce850 GetCapture
 0x1400ce858 ScreenToClient
 0x1400ce860 GetClipboardData
 0x1400ce868 SetClipboardData
 0x1400ce870 LoadCursorA
 0x1400ce878 GetKeyState
 0x1400ce880 GetMessageExtraInfo
GDI32.dll
 0x1400ce0c0 CreateRoundRectRgn
ADVAPI32.dll
 0x1400ce000 LookupPrivilegeValueA
 0x1400ce008 RegSetValueExA
 0x1400ce010 GetUserNameW
 0x1400ce018 OpenProcessToken
 0x1400ce020 RegQueryValueExA
 0x1400ce028 RegCloseKey
 0x1400ce030 AdjustTokenPrivileges
 0x1400ce038 RegOpenKeyExA
 0x1400ce040 RegGetValueA
 0x1400ce048 RegCreateKeyExA
SHELL32.dll
 0x1400ce740 ShellExecuteExA
D3DCOMPILER_43.dll
 0x1400ce0b0 D3DCompile
MSVCP140.dll
 0x1400ce318 ?_New_Locimp@_Locimp@locale@std@@CAPEAV123@AEBV123@@Z
 0x1400ce320 ?_Init@locale@std@@CAPEAV_Locimp@12@_N@Z
 0x1400ce328 ?_Xbad_alloc@std@@YAXXZ
 0x1400ce330 ?_Xout_of_range@std@@YAXPEBD@Z
 0x1400ce338 ?_Random_device@std@@YAIXZ
 0x1400ce340 ?id@?$codecvt@_WDU_Mbstatet@@@std@@2V0locale@2@A
 0x1400ce348 ?snextc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
 0x1400ce350 ?_Ipfx@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA_N_N@Z
 0x1400ce358 ?sbumpc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
 0x1400ce360 ?sgetc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
 0x1400ce368 ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z
 0x1400ce370 ??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA@XZ
 0x1400ce378 ??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA@XZ
 0x1400ce380 ??0?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z
 0x1400ce388 ??4?$_Yarn@D@std@@QEAAAEAV01@PEBD@Z
 0x1400ce390 ??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAA@XZ
 0x1400ce398 ?_Lock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ
 0x1400ce3a0 ?_Unlock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ
 0x1400ce3a8 ?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JXZ
 0x1400ce3b0 ?uflow@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ
 0x1400ce3b8 ?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEAD_J@Z
 0x1400ce3c0 ?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEBD_J@Z
 0x1400ce3c8 ?setbuf@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAPEAV12@PEAD_J@Z
 0x1400ce3d0 ?sync@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ
 0x1400ce3d8 ?imbue@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAXAEBVlocale@2@@Z
 0x1400ce3e0 ??1?$basic_ios@DU?$char_traits@D@std@@@std@@UEAA@XZ
 0x1400ce3e8 ??1?$basic_istream@DU?$char_traits@D@std@@@std@@UEAA@XZ
 0x1400ce3f0 ??5?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAVios_base@1@AEAV21@@Z@Z
 0x1400ce3f8 ??5?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@AEAH@Z
 0x1400ce400 ??Bios_base@std@@QEBA_NXZ
 0x1400ce408 ??1?$codecvt@_WDU_Mbstatet@@@std@@MEAA@XZ
 0x1400ce410 ??0?$codecvt@_WDU_Mbstatet@@@std@@QEAA@_K@Z
 0x1400ce418 ?out@?$codecvt@_WDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEB_W1AEAPEB_WPEAD3AEAPEAD@Z
 0x1400ce420 ?_Addfac@_Locimp@locale@std@@AEAAXPEAVfacet@23@_K@Z
 0x1400ce428 ?_Decref@facet@locale@std@@UEAAPEAV_Facet_base@3@XZ
 0x1400ce430 ?_Incref@facet@locale@std@@UEAAXXZ
 0x1400ce438 ??Bid@locale@std@@QEAA_KXZ
 0x1400ce440 _Mtx_destroy_in_situ
 0x1400ce448 _Mtx_init_in_situ
 0x1400ce450 ??1_Lockit@std@@QEAA@XZ
 0x1400ce458 ??0_Lockit@std@@QEAA@H@Z
 0x1400ce460 ?_Getgloballocale@locale@std@@CAPEAV_Locimp@12@XZ
 0x1400ce468 ?uncaught_exception@std@@YA_NXZ
 0x1400ce470 ?id@?$codecvt@DDU_Mbstatet@@@std@@2V0locale@2@A
 0x1400ce478 ?_Fiopen@std@@YAPEAU_iobuf@@PEBDHH@Z
 0x1400ce480 ?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ
 0x1400ce488 ?_Getcat@?$codecvt@DDU_Mbstatet@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z
 0x1400ce490 ?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z
 0x1400ce498 ?put@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@D@Z
 0x1400ce4a0 ?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ
 0x1400ce4a8 ?widen@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADD@Z
 0x1400ce4b0 ?getloc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEBA?AVlocale@2@XZ
 0x1400ce4b8 ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z
 0x1400ce4c0 ?unshift@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEAD1AEAPEAD@Z
 0x1400ce4c8 ?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXXZ
 0x1400ce4d0 ??0?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z
 0x1400ce4d8 ?in@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z
 0x1400ce4e0 ?out@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z
 0x1400ce4e8 ??1?$basic_ostream@DU?$char_traits@D@std@@@std@@UEAA@XZ
 0x1400ce4f0 ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z
 0x1400ce4f8 ?good@ios_base@std@@QEBA_NXZ
 0x1400ce500 ?always_noconv@codecvt_base@std@@QEBA_NXZ
 0x1400ce508 ?_Throw_Cpp_error@std@@YAXH@Z
 0x1400ce510 ?_Xbad_function_call@std@@YAXXZ
 0x1400ce518 _Cnd_do_broadcast_at_thread_exit
 0x1400ce520 _Thrd_detach
 0x1400ce528 ?_Xinvalid_argument@std@@YAXPEBD@Z
 0x1400ce530 ?fail@ios_base@std@@QEBA_NXZ
 0x1400ce538 ?__ExceptionPtrAssign@@YAXPEAXPEBX@Z
 0x1400ce540 ?GetCurrentThreadId@platform@details@Concurrency@@YAJXZ
 0x1400ce548 ?_ReportUnobservedException@details@Concurrency@@YAXXZ
 0x1400ce550 ?_Schedule_chore@details@Concurrency@@YAHPEAU_Threadpool_chore@12@@Z
 0x1400ce558 ?_LogWorkItemCompleted@_TaskEventLogger@details@Concurrency@@QEAAXXZ
 0x1400ce560 ?_LogWorkItemStarted@_TaskEventLogger@details@Concurrency@@QEAAXXZ
 0x1400ce568 ?_LogTaskExecutionCompleted@_TaskEventLogger@details@Concurrency@@QEAAXXZ
 0x1400ce570 ?_LogTaskCompleted@_TaskEventLogger@details@Concurrency@@QEAAXXZ
 0x1400ce578 ?_LogCancelTask@_TaskEventLogger@details@Concurrency@@QEAAXXZ
 0x1400ce580 ?_LogScheduleTask@_TaskEventLogger@details@Concurrency@@QEAAX_N@Z
 0x1400ce588 ?_Release_chore@details@Concurrency@@YAXPEAU_Threadpool_chore@12@@Z
 0x1400ce590 ?ReportUnhandledError@_ExceptionHolder@details@Concurrency@@AEAAXXZ
 0x1400ce598 ?_Capture@_ContextCallback@details@Concurrency@@AEAAXXZ
 0x1400ce5a0 ?_IsCurrentOriginSTA@_ContextCallback@details@Concurrency@@CA_NXZ
 0x1400ce5a8 ?_Assign@_ContextCallback@details@Concurrency@@AEAAXPEAX@Z
 0x1400ce5b0 ?_Reset@_ContextCallback@details@Concurrency@@AEAAXXZ
 0x1400ce5b8 ?_CallInContext@_ContextCallback@details@Concurrency@@QEBAXV?$function@$$A6AXXZ@std@@_N@Z
 0x1400ce5c0 ??0task_continuation_context@Concurrency@@AEAA@XZ
 0x1400ce5c8 ?__ExceptionPtrCreate@@YAXPEAX@Z
 0x1400ce5d0 _Cnd_init_in_situ
 0x1400ce5d8 ?__ExceptionPtrCopyException@@YAXPEAXPEBX1@Z
 0x1400ce5e0 ?__ExceptionPtrCopy@@YAXPEAXPEBX@Z
 0x1400ce5e8 ?__ExceptionPtrToBool@@YA_NPEBX@Z
 0x1400ce5f0 ?__ExceptionPtrDestroy@@YAXPEAX@Z
 0x1400ce5f8 _Mtx_lock
 0x1400ce600 ?__ExceptionPtrCurrentException@@YAXPEAX@Z
 0x1400ce608 ?__ExceptionPtrRethrow@@YAXPEBX@Z
 0x1400ce610 _Cnd_wait
 0x1400ce618 _Mtx_unlock
 0x1400ce620 _Cnd_broadcast
 0x1400ce628 _Cnd_destroy_in_situ
 0x1400ce630 ?imbue@?$basic_ios@_WU?$char_traits@_W@std@@@std@@QEAA?AVlocale@2@AEBV32@@Z
 0x1400ce638 ?setstate@?$basic_ios@_WU?$char_traits@_W@std@@@std@@QEAAXH_N@Z
 0x1400ce640 ??1?$basic_ios@_WU?$char_traits@_W@std@@@std@@UEAA@XZ
 0x1400ce648 ?_Pninc@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@IEAAPEA_WXZ
 0x1400ce650 ?_Xlength_error@std@@YAXPEBD@Z
 0x1400ce658 ??1?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@UEAA@XZ
 0x1400ce660 ??0?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@IEAA@XZ
 0x1400ce668 ?classic@locale@std@@SAAEBV12@XZ
 0x1400ce670 ?_Throw_C_error@std@@YAXH@Z
 0x1400ce678 ??0?$basic_istream@_WU?$char_traits@_W@std@@@std@@QEAA@PEAV?$basic_streambuf@_WU?$char_traits@_W@std@@@1@_N@Z
 0x1400ce680 ??1?$basic_istream@_WU?$char_traits@_W@std@@@std@@UEAA@XZ
 0x1400ce688 ??5?$basic_istream@_WU?$char_traits@_W@std@@@std@@QEAAAEAV01@AEAH@Z
 0x1400ce690 ?_Lock@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@UEAAXXZ
 0x1400ce698 ?_Unlock@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@UEAAXXZ
 0x1400ce6a0 ?imbue@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@MEAAXAEBVlocale@2@@Z
 0x1400ce6a8 ?setbuf@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@MEAAPEAV12@PEA_W_J@Z
 0x1400ce6b0 ?showmanyc@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@MEAA_JXZ
 0x1400ce6b8 ?sync@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@MEAAHXZ
 0x1400ce6c0 ?uflow@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@MEAAGXZ
 0x1400ce6c8 ?xsgetn@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@MEAA_JPEA_W_J@Z
 0x1400ce6d0 ??5?$basic_istream@_WU?$char_traits@_W@std@@@std@@QEAAAEAV01@AEA_K@Z
 0x1400ce6d8 ?flush@?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAAAEAV12@XZ
 0x1400ce6e0 ?xsputn@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@MEAA_JPEB_W_J@Z
 0x1400ce6e8 ?__ExceptionPtrCompare@@YA_NPEBX0@Z
 0x1400ce6f0 ?_Syserror_map@std@@YAPEBDH@Z
 0x1400ce6f8 ?_Winerror_map@std@@YAHH@Z
 0x1400ce700 ?sputc@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@QEAAG_W@Z
 0x1400ce708 ?sputn@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@QEAA_JPEB_W_J@Z
 0x1400ce710 ??0?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAA@PEAV?$basic_streambuf@_WU?$char_traits@_W@std@@@1@_N@Z
 0x1400ce718 ??1?$basic_ostream@_WU?$char_traits@_W@std@@@std@@UEAA@XZ
 0x1400ce720 ?_Osfx@?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAAXXZ
 0x1400ce728 ??6?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAAAEAV01@_K@Z
 0x1400ce730 ??0?$basic_ios@_WU?$char_traits@_W@std@@@std@@IEAA@XZ
d3d11.dll
 0x1400ceca8 D3D11CreateDeviceAndSwapChain
d3dx11_43.dll
 0x1400cecb8 D3DX11CreateShaderResourceViewFromMemory
IMM32.dll
 0x1400ce0d0 ImmSetCandidateWindow
 0x1400ce0d8 ImmSetCompositionWindow
 0x1400ce0e0 ImmReleaseContext
 0x1400ce0e8 ImmGetContext
CONCRT140.dll
 0x1400ce058 ??1_ReentrantBlockingLock@details@Concurrency@@QEAA@XZ
 0x1400ce060 ??0_ReentrantBlockingLock@details@Concurrency@@QEAA@XZ
 0x1400ce068 ?_Release@_ReentrantBlockingLock@details@Concurrency@@QEAAXXZ
 0x1400ce070 ?_Acquire@_ReentrantBlockingLock@details@Concurrency@@QEAAXXZ
CRYPT32.dll
 0x1400ce080 CertVerifyCertificateChainPolicy
 0x1400ce088 CertFreeCertificateChain
 0x1400ce090 CertGetCertificateChain
 0x1400ce098 CertFreeCertificateContext
 0x1400ce0a0 CryptUnprotectMemory
crypt.dll
 0x1400cec68 BCryptFinishHash
 0x1400cec70 BCryptHashData
 0x1400cec78 BCryptCreateHash
 0x1400cec80 BCryptDestroyHash
 0x1400cec88 BCryptCloseAlgorithmProvider
 0x1400cec90 BCryptGetProperty
 0x1400cec98 BCryptOpenAlgorithmProvider
WINHTTP.dll
 0x1400ce918 WinHttpWriteData
 0x1400ce920 WinHttpCloseHandle
 0x1400ce928 WinHttpOpen
 0x1400ce930 WinHttpConnect
 0x1400ce938 WinHttpReadData
 0x1400ce940 WinHttpSetStatusCallback
 0x1400ce948 WinHttpSetTimeouts
 0x1400ce950 WinHttpSetOption
 0x1400ce958 WinHttpQueryOption
 0x1400ce960 WinHttpQueryDataAvailable
 0x1400ce968 WinHttpGetDefaultProxyConfiguration
 0x1400ce970 WinHttpOpenRequest
 0x1400ce978 WinHttpGetProxyForUrl
 0x1400ce980 WinHttpQueryHeaders
 0x1400ce988 WinHttpReceiveResponse
 0x1400ce990 WinHttpQueryAuthSchemes
 0x1400ce998 WinHttpSetCredentials
 0x1400ce9a0 WinHttpSendRequest
 0x1400ce9a8 WinHttpAddRequestHeaders
 0x1400ce9b0 WinHttpGetIEProxyConfigForCurrentUser
VCRUNTIME140_1.dll
 0x1400ce908 __CxxFrameHandler4
VCRUNTIME140.dll
 0x1400ce890 __current_exception_context
 0x1400ce898 __std_terminate
 0x1400ce8a0 strstr
 0x1400ce8a8 __std_exception_destroy
 0x1400ce8b0 __std_exception_copy
 0x1400ce8b8 _purecall
 0x1400ce8c0 memchr
 0x1400ce8c8 __C_specific_handler
 0x1400ce8d0 __current_exception
 0x1400ce8d8 memcmp
 0x1400ce8e0 memset
 0x1400ce8e8 memcpy
 0x1400ce8f0 memmove
 0x1400ce8f8 _CxxThrowException
api-ms-win-crt-stdio-l1-1-0.dll
 0x1400ceb30 __stdio_common_vsprintf_s
 0x1400ceb38 fgetc
 0x1400ceb40 fgetpos
 0x1400ceb48 setvbuf
 0x1400ceb50 ungetc
 0x1400ceb58 fsetpos
 0x1400ceb60 __stdio_common_vsscanf
 0x1400ceb68 fread
 0x1400ceb70 fputc
 0x1400ceb78 __stdio_common_vsprintf
 0x1400ceb80 _wfopen
 0x1400ceb88 fwrite
 0x1400ceb90 __stdio_common_vfprintf
 0x1400ceb98 fseek
 0x1400ceba0 fclose
 0x1400ceba8 fflush
 0x1400cebb0 __acrt_iob_func
 0x1400cebb8 ftell
 0x1400cebc0 _get_stream_buffer_pointers
 0x1400cebc8 _fseeki64
 0x1400cebd0 __p__commode
 0x1400cebd8 _set_fmode
api-ms-win-crt-utility-l1-1-0.dll
 0x1400cec58 qsort
api-ms-win-crt-string-l1-1-0.dll
 0x1400cebe8 strcmp
 0x1400cebf0 strncpy
 0x1400cebf8 strncmp
 0x1400cec00 isdigit
 0x1400cec08 isalpha
 0x1400cec10 strcat_s
 0x1400cec18 isxdigit
 0x1400cec20 strcpy_s
api-ms-win-crt-heap-l1-1-0.dll
 0x1400cea08 _callnewh
 0x1400cea10 realloc
 0x1400cea18 _set_new_mode
 0x1400cea20 free
 0x1400cea28 malloc
api-ms-win-crt-runtime-l1-1-0.dll
 0x1400cea88 _initialize_onexit_table
 0x1400cea90 _register_onexit_function
 0x1400cea98 _initialize_narrow_environment
 0x1400ceaa0 abort
 0x1400ceaa8 _crt_atexit
 0x1400ceab0 _register_thread_local_exe_atexit_callback
 0x1400ceab8 _c_exit
 0x1400ceac0 _errno
 0x1400ceac8 terminate
 0x1400cead0 _beginthreadex
 0x1400cead8 _configure_narrow_argv
 0x1400ceae0 _exit
 0x1400ceae8 _invalid_parameter_noinfo_noreturn
 0x1400ceaf0 _initterm_e
 0x1400ceaf8 _initterm
 0x1400ceb00 _get_narrow_winmain_command_line
 0x1400ceb08 _set_app_type
 0x1400ceb10 _cexit
 0x1400ceb18 exit
 0x1400ceb20 _seh_filter_exe
api-ms-win-crt-convert-l1-1-0.dll
 0x1400ce9c0 wcstombs_s
 0x1400ce9c8 wcstol
api-ms-win-crt-filesystem-l1-1-0.dll
 0x1400ce9d8 _access_s
 0x1400ce9e0 remove
 0x1400ce9e8 _unlock_file
 0x1400ce9f0 _lock_file
 0x1400ce9f8 _mkdir
api-ms-win-crt-time-l1-1-0.dll
 0x1400cec30 _time64
 0x1400cec38 _localtime64
 0x1400cec40 _localtime64_s
 0x1400cec48 strftime
api-ms-win-crt-math-l1-1-0.dll
 0x1400cea48 __setusermatherr
 0x1400cea50 sinf
 0x1400cea58 fmodf
 0x1400cea60 acosf
 0x1400cea68 sqrtf
 0x1400cea70 cosf
 0x1400cea78 ceilf
api-ms-win-crt-locale-l1-1-0.dll
 0x1400cea38 _configthreadlocale

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure