Report - axs.exe

Malicious Library Antivirus UPX Anti_VM PE File PE64 OS Processor Check
ScreenShot
Created 2024.08.12 09:25 Machine s1_win7_x6403
Filename axs.exe
Type PE32+ executable (GUI) x86-64, for MS Windows
AI Score
4
Behavior Score
1.0
ZERO API file : malware
VT API (file) 38 detected (AIDetectMalware, GameHack, malicious, high confidence, Zusy, Unsafe, Vr9r, Attribute, HighConfidence, JJ potentially unsafe, Artemis, TrojanX, Generic Reputation PUA, Detected, ai score=87, ABApplication, QFYD, R639555, R002H09G424, susgen)
md5 bb870f9c15ae35c42a21784726575208
sha256 c2707866f66085bbcd80fbe5b61431fac009fc744587b4704332a66795935eb2
ssdeep 49152:8d7W629BFe/ydZXSq0q452v5a1XRL6xVbDnmnPOHvN4Rxkc856:8d7n29s2PunPOFYxkD56
imphash 5a11991504a02547b5aae9fe8973da7c
impfuzzy 192:V+0WvuKE3+wh2dvCRUII8aJrc+FyaBc582u7TD1GHy20m:V+0qu5WER3CyaBc58hTwSjm
  Network IP location

Signature (1cnts)

Level Description
danger File has been identified by 38 AntiVirus engines on VirusTotal as malicious

Rules (7cnts)

Level Name Description Collection
watch Antivirus Contains references to security software binaries (upload)
watch Malicious_Library_Zero Malicious_Library binaries (upload)
watch UPX_Zero UPX packed file binaries (upload)
notice anti_vm_detect Possibly employs anti-virtualization techniques binaries (upload)
info IsPE64 (no description) binaries (upload)
info OS_Processor_Check_Zero OS Processor Check binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids

PE API

IAT(Import Address Table) Library

KERNEL32.dll
 0x1400c60e8 InitializeCriticalSectionEx
 0x1400c60f0 DeleteCriticalSection
 0x1400c60f8 FormatMessageA
 0x1400c6100 LocalFree
 0x1400c6108 GetCurrentThread
 0x1400c6110 Sleep
 0x1400c6118 VerifyVersionInfoW
 0x1400c6120 SetFileCompletionNotificationModes
 0x1400c6128 CloseThreadpoolIo
 0x1400c6130 CancelThreadpoolIo
 0x1400c6138 StartThreadpoolIo
 0x1400c6140 CreateThreadpoolIo
 0x1400c6148 GetOverlappedResult
 0x1400c6150 WriteFile
 0x1400c6158 ReadFile
 0x1400c6160 GetFileSizeEx
 0x1400c6168 FormatMessageW
 0x1400c6170 OutputDebugStringW
 0x1400c6178 InitializeSListHead
 0x1400c6180 GetSystemTimeAsFileTime
 0x1400c6188 GetCurrentThreadId
 0x1400c6190 GetFirmwareEnvironmentVariableA
 0x1400c6198 GetModuleHandleW
 0x1400c61a0 IsProcessorFeaturePresent
 0x1400c61a8 GetStartupInfoW
 0x1400c61b0 SetUnhandledExceptionFilter
 0x1400c61b8 UnhandledExceptionFilter
 0x1400c61c0 IsDebuggerPresent
 0x1400c61c8 RtlVirtualUnwind
 0x1400c61d0 RtlLookupFunctionEntry
 0x1400c61d8 RtlCaptureContext
 0x1400c61e0 SleepConditionVariableSRW
 0x1400c61e8 WakeAllConditionVariable
 0x1400c61f0 AcquireSRWLockExclusive
 0x1400c61f8 ReleaseSRWLockExclusive
 0x1400c6200 InitOnceComplete
 0x1400c6208 InitOnceBeginInitialize
 0x1400c6210 QueryPerformanceFrequency
 0x1400c6218 FindClose
 0x1400c6220 GetUserDefaultLocaleName
 0x1400c6228 LoadLibraryA
 0x1400c6230 GetProcAddress
 0x1400c6238 GetModuleHandleA
 0x1400c6240 GetModuleFileNameA
 0x1400c6248 QueryPerformanceCounter
 0x1400c6250 VerSetConditionMask
 0x1400c6258 WideCharToMultiByte
 0x1400c6260 MultiByteToWideChar
 0x1400c6268 FreeLibrary
 0x1400c6270 TerminateProcess
 0x1400c6278 ExitProcess
 0x1400c6280 GetCurrentProcess
 0x1400c6288 WaitForSingleObject
 0x1400c6290 GetLastError
 0x1400c6298 CloseHandle
 0x1400c62a0 GlobalFree
 0x1400c62a8 GlobalLock
 0x1400c62b0 GetFirmwareType
 0x1400c62b8 GlobalUnlock
 0x1400c62c0 GlobalAlloc
 0x1400c62c8 GetCurrentProcessId
 0x1400c62d0 GetTickCount64
 0x1400c62d8 FindNextFileA
 0x1400c62e0 FindFirstFileA
 0x1400c62e8 CreateFileW
 0x1400c62f0 GetLocaleInfoEx
USER32.dll
 0x1400c67f0 GetWindowRect
 0x1400c67f8 OpenClipboard
 0x1400c6800 LoadIconA
 0x1400c6808 MoveWindow
 0x1400c6810 ShowWindow
 0x1400c6818 RegisterClassExA
 0x1400c6820 DestroyWindow
 0x1400c6828 CreateWindowExW
 0x1400c6830 RegisterClassExW
 0x1400c6838 UnregisterClassW
 0x1400c6840 UnregisterClassA
 0x1400c6848 PostQuitMessage
 0x1400c6850 DefWindowProcA
 0x1400c6858 PeekMessageA
 0x1400c6860 CreateWindowExA
 0x1400c6868 UpdateWindow
 0x1400c6870 SetWindowPos
 0x1400c6878 TranslateMessage
 0x1400c6880 LoadCursorA
 0x1400c6888 CloseClipboard
 0x1400c6890 SetClipboardData
 0x1400c6898 GetClipboardData
 0x1400c68a0 EmptyClipboard
 0x1400c68a8 TrackMouseEvent
 0x1400c68b0 ScreenToClient
 0x1400c68b8 GetMessageExtraInfo
 0x1400c68c0 GetKeyState
 0x1400c68c8 GetCapture
 0x1400c68d0 SetCapture
 0x1400c68d8 ReleaseCapture
 0x1400c68e0 GetSystemMetrics
 0x1400c68e8 DispatchMessageA
 0x1400c68f0 IsWindowUnicode
 0x1400c68f8 GetForegroundWindow
 0x1400c6900 GetClientRect
 0x1400c6908 SetCursorPos
 0x1400c6910 SetCursor
 0x1400c6918 GetCursorPos
 0x1400c6920 ClientToScreen
ADVAPI32.dll
 0x1400c6000 GetUserNameW
 0x1400c6008 AdjustTokenPrivileges
 0x1400c6010 LookupPrivilegeValueA
 0x1400c6018 RegCloseKey
 0x1400c6020 RegGetValueA
 0x1400c6028 RegCreateKeyExA
 0x1400c6030 RegSetValueExA
 0x1400c6038 RegQueryValueExA
 0x1400c6040 RegOpenKeyExA
 0x1400c6048 OpenProcessToken
SHELL32.dll
 0x1400c67e0 ShellExecuteExA
MSVCP140.dll
 0x1400c6300 ?_New_Locimp@_Locimp@locale@std@@CAPEAV123@AEBV123@@Z
 0x1400c6308 ?_Locimp_Addfac@_Locimp@locale@std@@CAXPEAV123@PEAVfacet@23@_K@Z
 0x1400c6310 ?_Init@locale@std@@CAPEAV_Locimp@12@_N@Z
 0x1400c6318 ?out@?$codecvt@_WDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEB_W1AEAPEB_WPEAD3AEAPEAD@Z
 0x1400c6320 ??0?$codecvt@_WDU_Mbstatet@@@std@@QEAA@_K@Z
 0x1400c6328 ??1?$codecvt@_WDU_Mbstatet@@@std@@MEAA@XZ
 0x1400c6330 ??Bios_base@std@@QEBA_NXZ
 0x1400c6338 ?setf@ios_base@std@@QEAAHHH@Z
 0x1400c6340 ??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA@XZ
 0x1400c6348 ??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAA@XZ
 0x1400c6350 ?sbumpc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
 0x1400c6358 ?sgetc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
 0x1400c6360 ?snextc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
 0x1400c6368 ?eback@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ
 0x1400c6370 ?gptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ
 0x1400c6378 ?pptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ
 0x1400c6380 ?egptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ
 0x1400c6388 ?gbump@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXH@Z
 0x1400c6390 ?setg@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXPEAD00@Z
 0x1400c6398 ?epptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ
 0x1400c63a0 ?setp@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXPEAD0@Z
 0x1400c63a8 ?setp@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXPEAD00@Z
 0x1400c63b0 ?_Pninc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAPEADXZ
 0x1400c63b8 ??1?$basic_ios@DU?$char_traits@D@std@@@std@@UEAA@XZ
 0x1400c63c0 ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z
 0x1400c63c8 ?rdbuf@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBAPEAV?$basic_streambuf@DU?$char_traits@D@std@@@2@XZ
 0x1400c63d0 ??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA@XZ
 0x1400c63d8 ??0?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z
 0x1400c63e0 ??1?$basic_istream@DU?$char_traits@D@std@@@std@@UEAA@XZ
 0x1400c63e8 ?_Ipfx@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA_N_N@Z
 0x1400c63f0 ??5?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAVios_base@1@AEAV21@@Z@Z
 0x1400c63f8 ??5?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@AEAH@Z
 0x1400c6400 ?_Random_device@std@@YAIXZ
 0x1400c6408 ?_Incref@facet@locale@std@@UEAAXXZ
 0x1400c6410 ?_Decref@facet@locale@std@@UEAAPEAV_Facet_base@3@XZ
 0x1400c6418 ?imbue@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAXAEBVlocale@2@@Z
 0x1400c6420 ?sync@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ
 0x1400c6428 ?setbuf@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAPEAV12@PEAD_J@Z
 0x1400c6430 ?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEBD_J@Z
 0x1400c6438 ?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEAD_J@Z
 0x1400c6440 ?uflow@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ
 0x1400c6448 ?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JXZ
 0x1400c6450 ?_Unlock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ
 0x1400c6458 ?_Lock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ
 0x1400c6460 ?id@?$codecvt@_WDU_Mbstatet@@@std@@2V0locale@2@A
 0x1400c6468 _Mtx_init_in_situ
 0x1400c6470 _Mtx_destroy_in_situ
 0x1400c6478 ??0_Lockit@std@@QEAA@H@Z
 0x1400c6480 ??1_Lockit@std@@QEAA@XZ
 0x1400c6488 ?uncaught_exception@std@@YA_NXZ
 0x1400c6490 ?_Getgloballocale@locale@std@@CAPEAV_Locimp@12@XZ
 0x1400c6498 ?always_noconv@codecvt_base@std@@QEBA_NXZ
 0x1400c64a0 ?in@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z
 0x1400c64a8 ?out@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z
 0x1400c64b0 ?unshift@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEAD1AEAPEAD@Z
 0x1400c64b8 ?_Getcat@?$codecvt@DDU_Mbstatet@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z
 0x1400c64c0 ?good@ios_base@std@@QEBA_NXZ
 0x1400c64c8 ?flags@ios_base@std@@QEBAHXZ
 0x1400c64d0 ?width@ios_base@std@@QEBA_JXZ
 0x1400c64d8 ??Bid@locale@std@@QEAA_KXZ
 0x1400c64e0 ?getloc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEBA?AVlocale@2@XZ
 0x1400c64e8 ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z
 0x1400c64f0 ?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z
 0x1400c64f8 ?_Gndec@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAPEADXZ
 0x1400c6500 ?_Gninc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAPEADXZ
 0x1400c6508 ?_Gnavail@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBA_JXZ
 0x1400c6510 ?pbump@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXH@Z
 0x1400c6518 ?_Pnavail@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBA_JXZ
 0x1400c6520 ?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXXZ
 0x1400c6528 ?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXPEAPEAD0PEAH001@Z
 0x1400c6530 ?_Fiopen@std@@YAPEAU_iobuf@@PEBDHH@Z
 0x1400c6538 ?tie@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBAPEAV?$basic_ostream@DU?$char_traits@D@std@@@2@XZ
 0x1400c6540 ?fill@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADXZ
 0x1400c6548 ?widen@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADD@Z
 0x1400c6550 ??0?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z
 0x1400c6558 ??1?$basic_ostream@DU?$char_traits@D@std@@@std@@UEAA@XZ
 0x1400c6560 ?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ
 0x1400c6568 ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z
 0x1400c6570 ?put@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@D@Z
 0x1400c6578 ?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ
 0x1400c6580 ?id@?$codecvt@DDU_Mbstatet@@@std@@2V0locale@2@A
 0x1400c6588 _Thrd_detach
 0x1400c6590 _Cnd_do_broadcast_at_thread_exit
 0x1400c6598 ?_Throw_Cpp_error@std@@YAXH@Z
 0x1400c65a0 ?_Xinvalid_argument@std@@YAXPEBD@Z
 0x1400c65a8 ?fail@ios_base@std@@QEBA_NXZ
 0x1400c65b0 ?__ExceptionPtrCreate@@YAXPEAX@Z
 0x1400c65b8 ?__ExceptionPtrDestroy@@YAXPEAX@Z
 0x1400c65c0 ?__ExceptionPtrCopy@@YAXPEAXPEBX@Z
 0x1400c65c8 ?__ExceptionPtrAssign@@YAXPEAXPEBX@Z
 0x1400c65d0 ?__ExceptionPtrToBool@@YA_NPEBX@Z
 0x1400c65d8 ?__ExceptionPtrCurrentException@@YAXPEAX@Z
 0x1400c65e0 ?__ExceptionPtrRethrow@@YAXPEBX@Z
 0x1400c65e8 ?__ExceptionPtrCopyException@@YAXPEAXPEBX1@Z
 0x1400c65f0 _Mtx_lock
 0x1400c65f8 _Mtx_unlock
 0x1400c6600 _Cnd_init_in_situ
 0x1400c6608 _Cnd_destroy_in_situ
 0x1400c6610 _Cnd_wait
 0x1400c6618 _Cnd_broadcast
 0x1400c6620 ?_Schedule_chore@details@Concurrency@@YAHPEAU_Threadpool_chore@12@@Z
 0x1400c6628 ?_Release_chore@details@Concurrency@@YAXPEAU_Threadpool_chore@12@@Z
 0x1400c6630 ?_ReportUnobservedException@details@Concurrency@@YAXXZ
 0x1400c6638 ?GetCurrentThreadId@platform@details@Concurrency@@YAJXZ
 0x1400c6640 ?_Xbad_function_call@std@@YAXXZ
 0x1400c6648 ?_CallInContext@_ContextCallback@details@Concurrency@@QEBAXV?$function@$$A6AXXZ@std@@_N@Z
 0x1400c6650 ?_Reset@_ContextCallback@details@Concurrency@@AEAAXXZ
 0x1400c6658 ?_Assign@_ContextCallback@details@Concurrency@@AEAAXPEAX@Z
 0x1400c6660 ?_IsCurrentOriginSTA@_ContextCallback@details@Concurrency@@CA_NXZ
 0x1400c6668 ?_Capture@_ContextCallback@details@Concurrency@@AEAAXXZ
 0x1400c6670 ?ReportUnhandledError@_ExceptionHolder@details@Concurrency@@AEAAXXZ
 0x1400c6678 ??0task_continuation_context@Concurrency@@AEAA@XZ
 0x1400c6680 ?_LogScheduleTask@_TaskEventLogger@details@Concurrency@@QEAAX_N@Z
 0x1400c6688 ?_LogCancelTask@_TaskEventLogger@details@Concurrency@@QEAAXXZ
 0x1400c6690 ?_LogTaskCompleted@_TaskEventLogger@details@Concurrency@@QEAAXXZ
 0x1400c6698 ?_LogTaskExecutionCompleted@_TaskEventLogger@details@Concurrency@@QEAAXXZ
 0x1400c66a0 ?_LogWorkItemStarted@_TaskEventLogger@details@Concurrency@@QEAAXXZ
 0x1400c66a8 ?_LogWorkItemCompleted@_TaskEventLogger@details@Concurrency@@QEAAXXZ
 0x1400c66b0 ?width@ios_base@std@@QEAA_J_J@Z
 0x1400c66b8 ?_Xout_of_range@std@@YAXPEBD@Z
 0x1400c66c0 ?_Xlength_error@std@@YAXPEBD@Z
 0x1400c66c8 ?_Xbad_alloc@std@@YAXXZ
 0x1400c66d0 ??5?$basic_istream@_WU?$char_traits@_W@std@@@std@@QEAAAEAV01@AEA_K@Z
 0x1400c66d8 ??6?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAAAEAV01@_K@Z
 0x1400c66e0 ??1?$basic_ostream@_WU?$char_traits@_W@std@@@std@@UEAA@XZ
 0x1400c66e8 ??0?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAA@PEAV?$basic_streambuf@_WU?$char_traits@_W@std@@@1@_N@Z
 0x1400c66f0 ?_Throw_C_error@std@@YAXH@Z
 0x1400c66f8 ?__ExceptionPtrCompare@@YA_NPEBX0@Z
 0x1400c6700 ?flush@?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAAAEAV12@XZ
 0x1400c6708 ?_Osfx@?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAAXXZ
 0x1400c6710 ?sputn@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@QEAA_JPEB_W_J@Z
 0x1400c6718 ?sputc@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@QEAAG_W@Z
 0x1400c6720 ?xsputn@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@MEAA_JPEB_W_J@Z
 0x1400c6728 ?xsgetn@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@MEAA_JPEA_W_J@Z
 0x1400c6730 ?uflow@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@MEAAGXZ
 0x1400c6738 ?sync@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@MEAAHXZ
 0x1400c6740 ?showmanyc@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@MEAA_JXZ
 0x1400c6748 ?setbuf@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@MEAAPEAV12@PEA_W_J@Z
 0x1400c6750 ?imbue@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@MEAAXAEBVlocale@2@@Z
 0x1400c6758 ?_Unlock@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@UEAAXXZ
 0x1400c6760 ?_Lock@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@UEAAXXZ
 0x1400c6768 ??5?$basic_istream@_WU?$char_traits@_W@std@@@std@@QEAAAEAV01@AEAH@Z
 0x1400c6770 ??1?$basic_istream@_WU?$char_traits@_W@std@@@std@@UEAA@XZ
 0x1400c6778 ??0?$basic_istream@_WU?$char_traits@_W@std@@@std@@QEAA@PEAV?$basic_streambuf@_WU?$char_traits@_W@std@@@1@_N@Z
 0x1400c6780 ??0?$basic_ios@_WU?$char_traits@_W@std@@@std@@IEAA@XZ
 0x1400c6788 ?imbue@?$basic_ios@_WU?$char_traits@_W@std@@@std@@QEAA?AVlocale@2@AEBV32@@Z
 0x1400c6790 ?setstate@?$basic_ios@_WU?$char_traits@_W@std@@@std@@QEAAXH_N@Z
 0x1400c6798 ??1?$basic_ios@_WU?$char_traits@_W@std@@@std@@UEAA@XZ
 0x1400c67a0 ?_Pninc@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@IEAAPEA_WXZ
 0x1400c67a8 ??1?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@UEAA@XZ
 0x1400c67b0 ??0?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@IEAA@XZ
 0x1400c67b8 ?classic@locale@std@@SAAEBV12@XZ
 0x1400c67c0 ?_Winerror_map@std@@YAHH@Z
 0x1400c67c8 ?_Syserror_map@std@@YAPEBDH@Z
 0x1400c67d0 ??4?$_Yarn@D@std@@QEAAAEAV01@PEBD@Z
CONCRT140.dll
 0x1400c6058 ?_Release@_ReentrantBlockingLock@details@Concurrency@@QEAAXXZ
 0x1400c6060 ??0_ReentrantBlockingLock@details@Concurrency@@QEAA@XZ
 0x1400c6068 ?_Acquire@_ReentrantBlockingLock@details@Concurrency@@QEAAXXZ
 0x1400c6070 ??1_ReentrantBlockingLock@details@Concurrency@@QEAA@XZ
IMM32.dll
 0x1400c60c0 ImmSetCompositionWindow
 0x1400c60c8 ImmGetContext
 0x1400c60d0 ImmSetCandidateWindow
 0x1400c60d8 ImmReleaseContext
D3DCOMPILER_47.dll
 0x1400c60b0 D3DCompile
CRYPT32.dll
 0x1400c6080 CertGetCertificateChain
 0x1400c6088 CertFreeCertificateChain
 0x1400c6090 CertVerifyCertificateChainPolicy
 0x1400c6098 CertFreeCertificateContext
 0x1400c60a0 CryptUnprotectMemory
crypt.dll
 0x1400c6d18 BCryptGetProperty
 0x1400c6d20 BCryptCloseAlgorithmProvider
 0x1400c6d28 BCryptDestroyHash
 0x1400c6d30 BCryptFinishHash
 0x1400c6d38 BCryptHashData
 0x1400c6d40 BCryptCreateHash
 0x1400c6d48 BCryptOpenAlgorithmProvider
WINHTTP.dll
 0x1400c69b8 WinHttpQueryAuthSchemes
 0x1400c69c0 WinHttpReceiveResponse
 0x1400c69c8 WinHttpSetCredentials
 0x1400c69d0 WinHttpGetIEProxyConfigForCurrentUser
 0x1400c69d8 WinHttpGetProxyForUrl
 0x1400c69e0 WinHttpQueryHeaders
 0x1400c69e8 WinHttpAddRequestHeaders
 0x1400c69f0 WinHttpOpenRequest
 0x1400c69f8 WinHttpSetTimeouts
 0x1400c6a00 WinHttpSetOption
 0x1400c6a08 WinHttpQueryOption
 0x1400c6a10 WinHttpQueryDataAvailable
 0x1400c6a18 WinHttpWriteData
 0x1400c6a20 WinHttpReadData
 0x1400c6a28 WinHttpConnect
 0x1400c6a30 WinHttpCloseHandle
 0x1400c6a38 WinHttpSendRequest
 0x1400c6a40 WinHttpOpen
 0x1400c6a48 WinHttpGetDefaultProxyConfiguration
 0x1400c6a50 WinHttpSetStatusCallback
d3d11.dll
 0x1400c6d58 D3D11CreateDeviceAndSwapChain
VCRUNTIME140.dll
 0x1400c6930 __std_exception_destroy
 0x1400c6938 _CxxThrowException
 0x1400c6940 __current_exception_context
 0x1400c6948 __std_exception_copy
 0x1400c6950 memmove
 0x1400c6958 __current_exception
 0x1400c6960 __C_specific_handler
 0x1400c6968 _purecall
 0x1400c6970 strstr
 0x1400c6978 memset
 0x1400c6980 memchr
 0x1400c6988 memcpy
 0x1400c6990 memcmp
 0x1400c6998 __std_terminate
VCRUNTIME140_1.dll
 0x1400c69a8 __CxxFrameHandler4
api-ms-win-crt-runtime-l1-1-0.dll
 0x1400c6b28 _cexit
 0x1400c6b30 _crt_atexit
 0x1400c6b38 _seh_filter_exe
 0x1400c6b40 _register_onexit_function
 0x1400c6b48 _initialize_onexit_table
 0x1400c6b50 _initialize_narrow_environment
 0x1400c6b58 _set_app_type
 0x1400c6b60 _configure_narrow_argv
 0x1400c6b68 abort
 0x1400c6b70 _invalid_parameter_noinfo_noreturn
 0x1400c6b78 _get_narrow_winmain_command_line
 0x1400c6b80 _initterm
 0x1400c6b88 _initterm_e
 0x1400c6b90 exit
 0x1400c6b98 _exit
 0x1400c6ba0 _c_exit
 0x1400c6ba8 _register_thread_local_exe_atexit_callback
 0x1400c6bb0 _beginthreadex
 0x1400c6bb8 terminate
 0x1400c6bc0 _errno
api-ms-win-crt-string-l1-1-0.dll
 0x1400c6c98 strcmp
 0x1400c6ca0 strncmp
 0x1400c6ca8 isdigit
 0x1400c6cb0 isalpha
 0x1400c6cb8 isxdigit
 0x1400c6cc0 strcpy_s
 0x1400c6cc8 strcat_s
 0x1400c6cd0 strncpy
api-ms-win-crt-stdio-l1-1-0.dll
 0x1400c6bd0 fseek
 0x1400c6bd8 _wfopen
 0x1400c6be0 __stdio_common_vsprintf
 0x1400c6be8 __stdio_common_vsprintf_s
 0x1400c6bf0 __stdio_common_vsscanf
 0x1400c6bf8 ftell
 0x1400c6c00 __stdio_common_vfprintf
 0x1400c6c08 ungetc
 0x1400c6c10 setvbuf
 0x1400c6c18 _fseeki64
 0x1400c6c20 fsetpos
 0x1400c6c28 fread
 0x1400c6c30 fputc
 0x1400c6c38 fgetpos
 0x1400c6c40 fgetc
 0x1400c6c48 fflush
 0x1400c6c50 _get_stream_buffer_pointers
 0x1400c6c58 __p__commode
 0x1400c6c60 _set_fmode
 0x1400c6c68 fwrite
 0x1400c6c70 __acrt_iob_func
 0x1400c6c78 feof
 0x1400c6c80 ferror
 0x1400c6c88 fclose
api-ms-win-crt-heap-l1-1-0.dll
 0x1400c6aa8 malloc
 0x1400c6ab0 free
 0x1400c6ab8 realloc
 0x1400c6ac0 _callnewh
 0x1400c6ac8 _set_new_mode
api-ms-win-crt-convert-l1-1-0.dll
 0x1400c6a60 wcstol
 0x1400c6a68 wcstombs_s
api-ms-win-crt-filesystem-l1-1-0.dll
 0x1400c6a78 _mkdir
 0x1400c6a80 _access_s
 0x1400c6a88 remove
 0x1400c6a90 _lock_file
 0x1400c6a98 _unlock_file
api-ms-win-crt-time-l1-1-0.dll
 0x1400c6ce0 _time64
 0x1400c6ce8 strftime
 0x1400c6cf0 _localtime64
 0x1400c6cf8 _localtime64_s
api-ms-win-crt-math-l1-1-0.dll
 0x1400c6ae8 sqrtf
 0x1400c6af0 cosf
 0x1400c6af8 fmodf
 0x1400c6b00 ceilf
 0x1400c6b08 sinf
 0x1400c6b10 acosf
 0x1400c6b18 __setusermatherr
api-ms-win-crt-utility-l1-1-0.dll
 0x1400c6d08 qsort
api-ms-win-crt-locale-l1-1-0.dll
 0x1400c6ad8 _configthreadlocale

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure