Report - game.exe

Generic Malware Malicious Library ASPack UPX Anti_VM PE File PE32 OS Processor Check
ScreenShot
Created 2024.09.22 15:19 Machine s1_win7_x6401
Filename game.exe
Type MS-DOS executable, MZ for MS-DOS
AI Score
3
Behavior Score
1.8
ZERO API file : mailcious
VT API (file) 11 detected (Sality, Vlek, Attribute, HighConfidence, Malicious, Detected, BScope, Orsam, PossibleThreat)
md5 49a4df6234a85f29ff15b8d58dcb995b
sha256 4b77e49987843ca290926630aa7e1bc0e29b84b094a44495898e490367af658e
ssdeep 98304:YAiqwfDWXjVY1bFWs4TKpG3RyRkRZfs9FT53jUHTJRvwS:Li3fDWXjVY1bFWL2pG3RyRkbfs9FT53q
imphash 6d2c6472274041e62625209f9ed2b31f
impfuzzy 384:y8fYQF6JThwOKAbqphGYPaC8Fx+e2WsrRnrUTknEkfY+58:yQgJThwOwhGYPaC8Fx12WsrRnrUTknED
  Network IP location

Signature (4cnts)

Level Description
watch Communicates with host for which no DNS query was performed
watch File has been identified by 11 AntiVirus engines on VirusTotal as malicious
notice Foreign language identified in PE resource
info This executable has a PDB path

Rules (8cnts)

Level Name Description Collection
warning Generic_Malware_Zero Generic Malware binaries (upload)
watch ASPack_Zero ASPack packed file binaries (upload)
watch Malicious_Library_Zero Malicious_Library binaries (upload)
watch UPX_Zero UPX packed file binaries (upload)
notice anti_vm_detect Possibly employs anti-virtualization techniques binaries (upload)
info IsPE32 (no description) binaries (upload)
info OS_Processor_Check_Zero OS Processor Check binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (1cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
150.158.102.191 CN Shenzhen Tencent Computer Systems Company Limited 150.158.102.191 clean

Suricata ids

PE API

IAT(Import Address Table) Library

SHLWAPI.dll
 0x72a848 PathRemoveFileSpecA
KERNEL32.dll
 0x72a2d8 GetFileSize
 0x72a2dc UnmapViewOfFile
 0x72a2e0 GetComputerNameA
 0x72a2e4 ResumeThread
 0x72a2e8 SuspendThread
 0x72a2ec CreateFileMappingW
 0x72a2f0 OpenProcess
 0x72a2f4 GetProcessHeap
 0x72a2f8 InterlockedExchange
 0x72a2fc GetACP
 0x72a300 GetLocaleInfoA
 0x72a304 GetThreadLocale
 0x72a308 InterlockedCompareExchange
 0x72a30c HeapFree
 0x72a310 HeapAlloc
 0x72a314 IsProcessorFeaturePresent
 0x72a318 TerminateProcess
 0x72a31c UnhandledExceptionFilter
 0x72a320 SetUnhandledExceptionFilter
 0x72a324 IsDebuggerPresent
 0x72a328 QueryPerformanceCounter
 0x72a32c GetCurrentProcessId
 0x72a330 GetSystemTimeAsFileTime
 0x72a334 BindIoCompletionCallback
 0x72a338 MapViewOfFile
 0x72a33c GetTempPathW
 0x72a340 GetVersionExA
 0x72a344 CreateFileA
 0x72a348 DeviceIoControl
 0x72a34c OpenThread
 0x72a350 GetStartupInfoA
 0x72a354 GetSystemTime
 0x72a358 CreateProcessA
 0x72a35c GetModuleHandleA
 0x72a360 CompareStringA
 0x72a364 OpenSemaphoreA
 0x72a368 CreateSemaphoreA
 0x72a36c ReleaseMutex
 0x72a370 OpenMutexA
 0x72a374 CreateMutexA
 0x72a378 LoadLibraryW
 0x72a37c CopyFileA
 0x72a380 SetEvent
 0x72a384 CreateEventW
 0x72a388 ResetEvent
 0x72a38c GetTickCount
 0x72a390 lstrlenA
 0x72a394 LoadLibraryA
 0x72a398 GetProcAddress
 0x72a39c CreateThread
 0x72a3a0 WideCharToMultiByte
 0x72a3a4 GetExitCodeThread
 0x72a3a8 WaitForSingleObject
 0x72a3ac TerminateThread
 0x72a3b0 CloseHandle
 0x72a3b4 Sleep
 0x72a3b8 GetTempPathA
 0x72a3bc GetTempFileNameA
 0x72a3c0 GetModuleHandleW
 0x72a3c4 LoadLibraryExW
 0x72a3c8 FindResourceW
 0x72a3cc LoadResource
 0x72a3d0 SizeofResource
 0x72a3d4 MultiByteToWideChar
 0x72a3d8 FreeLibrary
 0x72a3dc SetLastError
 0x72a3e0 GetCurrentThreadId
 0x72a3e4 GetModuleFileNameW
 0x72a3e8 MulDiv
 0x72a3ec lstrcmpW
 0x72a3f0 VirtualFree
 0x72a3f4 GetCurrentProcess
 0x72a3f8 FlushInstructionCache
 0x72a3fc lstrcmpiW
 0x72a400 InterlockedDecrement
 0x72a404 InterlockedIncrement
 0x72a408 lstrlenW
 0x72a40c DeleteCriticalSection
 0x72a410 InitializeCriticalSection
 0x72a414 LeaveCriticalSection
 0x72a418 EnterCriticalSection
 0x72a41c RaiseException
 0x72a420 VirtualAlloc
 0x72a424 GetLastError
 0x72a428 GlobalAlloc
 0x72a42c GlobalLock
 0x72a430 GlobalUnlock
 0x72a434 GetLocalTime
 0x72a438 GetPrivateProfileIntA
 0x72a43c GetVersion
 0x72a440 FindFirstFileA
 0x72a444 SetFileAttributesA
 0x72a448 DeleteFileA
 0x72a44c FindNextFileA
 0x72a450 FindClose
 0x72a454 RemoveDirectoryA
 0x72a458 GetDiskFreeSpaceExA
 0x72a45c GetStdHandle
 0x72a460 SetConsoleTitleA
 0x72a464 AllocConsole
 0x72a468 GetModuleFileNameA
USER32.dll
 0x72a850 GetFocus
 0x72a854 MessageBoxA
 0x72a858 SetWindowLongW
 0x72a85c GetWindowLongW
 0x72a860 GetKeyState
 0x72a864 SendMessageW
 0x72a868 CloseClipboard
 0x72a86c SetClipboardData
 0x72a870 GetMenu
 0x72a874 EmptyClipboard
 0x72a878 OpenClipboard
 0x72a87c SetCaretPos
 0x72a880 GetCaretPos
 0x72a884 GetClipboardData
 0x72a888 GetClassNameA
 0x72a88c GetWindow
 0x72a890 ShowWindow
 0x72a894 MoveWindow
 0x72a898 CreateWindowExW
 0x72a89c DestroyWindow
 0x72a8a0 IsWindow
 0x72a8a4 CharNextW
 0x72a8a8 DefWindowProcW
 0x72a8ac SetWindowTextW
 0x72a8b0 GetWindowTextW
 0x72a8b4 GetWindowTextLengthW
 0x72a8b8 RegisterClassExW
 0x72a8bc LoadCursorW
 0x72a8c0 GetClassInfoExW
 0x72a8c4 RegisterWindowMessageW
 0x72a8c8 GetSysColor
 0x72a8cc SetWindowPos
 0x72a8d0 GetClientRect
 0x72a8d4 ClientToScreen
 0x72a8d8 ScreenToClient
 0x72a8dc CopyRect
 0x72a8e0 BringWindowToTop
 0x72a8e4 SendMessageA
 0x72a8e8 CreateWindowExA
 0x72a8ec SetWindowLongA
 0x72a8f0 UnregisterClassA
 0x72a8f4 GetDC
 0x72a8f8 ReleaseDC
 0x72a8fc InvalidateRect
 0x72a900 InvalidateRgn
 0x72a904 RedrawWindow
 0x72a908 SetCapture
 0x72a90c IsChild
 0x72a910 GetParent
 0x72a914 GetDlgItem
 0x72a918 GetClassNameW
 0x72a91c ReleaseCapture
 0x72a920 FillRect
 0x72a924 CallWindowProcW
 0x72a928 EndPaint
 0x72a92c AdjustWindowRectEx
 0x72a930 BeginPaint
 0x72a934 UpdateWindow
 0x72a938 EnumWindows
 0x72a93c InSendMessage
 0x72a940 GetMessagePos
 0x72a944 SetCursorPos
 0x72a948 LoadCursorFromFileA
 0x72a94c ShowCursor
 0x72a950 SetCursor
 0x72a954 MessageBoxW
 0x72a958 GetWindowLongA
 0x72a95c CreateAcceleratorTableW
 0x72a960 SetFocus
 0x72a964 PeekMessageW
 0x72a968 DestroyAcceleratorTable
 0x72a96c GetDesktopWindow
GDI32.dll
 0x72a28c CreatePolygonRgn
 0x72a290 PtInRegion
 0x72a294 GetStockObject
 0x72a298 GetObjectW
 0x72a29c CreateSolidBrush
 0x72a2a0 GetDeviceCaps
 0x72a2a4 BitBlt
 0x72a2a8 CreateCompatibleDC
 0x72a2ac CreateCompatibleBitmap
 0x72a2b0 DeleteDC
 0x72a2b4 SelectObject
 0x72a2b8 DeleteObject
 0x72a2bc CreateHatchBrush
 0x72a2c0 SetROP2
 0x72a2c4 Rectangle
 0x72a2c8 SelectPalette
 0x72a2cc RealizePalette
 0x72a2d0 CreatePalette
comdlg32.dll
 0x72a9cc GetOpenFileNameW
ADVAPI32.dll
 0x72a000 RegSetValueExA
 0x72a004 RegQueryInfoKeyW
 0x72a008 RegSetValueExW
 0x72a00c RegOpenKeyExW
 0x72a010 RegCreateKeyExW
 0x72a014 RegCloseKey
 0x72a018 RegDeleteValueW
 0x72a01c RegDeleteKeyW
 0x72a020 RegCreateKeyA
 0x72a024 RegQueryValueExA
 0x72a028 RegOpenKeyExA
 0x72a02c RegEnumKeyExW
SHELL32.dll
 0x72a83c SHGetSpecialFolderPathA
 0x72a840 ShellExecuteA
ole32.dll
 0x72a9d4 OleUninitialize
 0x72a9d8 StringFromGUID2
 0x72a9dc OleLockRunning
 0x72a9e0 CoSetProxyBlanket
 0x72a9e4 OleSetContainedObject
 0x72a9e8 OleCreate
 0x72a9ec CoGetMalloc
 0x72a9f0 OleDraw
 0x72a9f4 StgCreateDocfile
 0x72a9f8 OleSave
 0x72a9fc CLSIDFromString
 0x72aa00 StringFromCLSID
 0x72aa04 CoInitialize
 0x72aa08 CoUninitialize
 0x72aa0c CoTaskMemRealloc
 0x72aa10 CoTaskMemAlloc
 0x72aa14 CoTaskMemFree
 0x72aa18 CreateStreamOnHGlobal
 0x72aa1c OleInitialize
 0x72aa20 CoGetClassObject
 0x72aa24 CLSIDFromProgID
 0x72aa28 CoCreateInstance
OLEAUT32.dll
 0x72a7ec LoadTypeLib
 0x72a7f0 LoadRegTypeLib
 0x72a7f4 OleCreateFontIndirect
 0x72a7f8 VariantClear
 0x72a7fc VariantInit
 0x72a800 SysStringByteLen
 0x72a804 VarUI4FromStr
 0x72a808 SysAllocStringLen
 0x72a80c SysStringLen
 0x72a810 SysFreeString
 0x72a814 SysAllocString
 0x72a818 GetErrorInfo
 0x72a81c CreateErrorInfo
 0x72a820 SetErrorInfo
 0x72a824 VariantChangeType
MSVCP80.dll
 0x72a470 ?assign@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@PBDI@Z
 0x72a474 ??$?8DU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA_NABV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@0@Z
 0x72a478 ?clear@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEXXZ
 0x72a47c ?length@?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@QBEIXZ
 0x72a480 ?empty@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBE_NXZ
 0x72a484 ?fill@?$basic_ios@DU?$char_traits@D@std@@@std@@QBEDXZ
 0x72a488 ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@PBDABV10@@Z
 0x72a48c ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z
 0x72a490 ??0?$basic_stringstream@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@H@Z
 0x72a494 ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QAEAAV01@H@Z
 0x72a498 ??$?5DU?$char_traits@D@std@@V?$allocator@D@1@@std@@YAAAV?$basic_istream@DU?$char_traits@D@std@@@0@AAV10@AAV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@@Z
 0x72a49c ??_D?$basic_stringstream@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEXXZ
 0x72a4a0 ?append@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@ABV12@@Z
 0x72a4a4 ?append@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@PBD@Z
 0x72a4a8 ?_Myptr@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@IBEPBDXZ
 0x72a4ac ?push_back@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEXD@Z
 0x72a4b0 ?compare@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEHPBD@Z
 0x72a4b4 ?endl@std@@YAAAV?$basic_ostream@DU?$char_traits@D@std@@@1@AAV21@@Z
 0x72a4b8 ?cout@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A
 0x72a4bc ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QAEAAV01@P6AAAV01@AAV01@@Z@Z
 0x72a4c0 ?length@?$char_traits@D@std@@SAIPBD@Z
 0x72a4c4 ?width@ios_base@std@@QBEHXZ
 0x72a4c8 ?flags@ios_base@std@@QBEHXZ
 0x72a4cc ?eof@?$char_traits@D@std@@SAHXZ
 0x72a4d0 ?eq_int_type@?$char_traits@D@std@@SA_NABH0@Z
 0x72a4d4 ?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QAEHPBDH@Z
 0x72a4d8 ?width@ios_base@std@@QAEHH@Z
 0x72a4dc ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QAEXH_N@Z
 0x72a4e0 ?uncaught_exception@std@@YA_NXZ
 0x72a4e4 ?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QAEXXZ
 0x72a4e8 ?good@ios_base@std@@QBE_NXZ
 0x72a4ec ?tie@?$basic_ios@DU?$char_traits@D@std@@@std@@QBEPAV?$basic_ostream@DU?$char_traits@D@std@@@2@XZ
 0x72a4f0 ?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QAEAAV12@XZ
 0x72a4f4 ?_Unlock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QAEXXZ
 0x72a4f8 ?rdbuf@?$basic_ios@DU?$char_traits@D@std@@@std@@QBEPAV?$basic_streambuf@DU?$char_traits@D@std@@@2@XZ
 0x72a4fc ?_Lock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QAEXXZ
 0x72a500 ?swap@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEXAAV12@@Z
 0x72a504 ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIDI@Z
 0x72a508 ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEABDI@Z
 0x72a50c ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@D@Z
 0x72a510 ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@0@Z
 0x72a514 ?begin@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE?AV?$_String_iterator@DU?$char_traits@D@std@@V?$allocator@D@2@@2@XZ
 0x72a518 ?end@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE?AV?$_String_iterator@DU?$char_traits@D@std@@V?$allocator@D@2@@2@XZ
 0x72a51c ?_Myptr@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@IAEPADXZ
 0x72a520 ??0?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@QAE@PB_W@Z
 0x72a524 ?assign@?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@QAEAAV12@PB_WI@Z
 0x72a528 ?resize@?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@QAEXI@Z
 0x72a52c ??0?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@QAE@ABV01@@Z
 0x72a530 ?append@?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@QAEAAV12@I_W@Z
 0x72a534 ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIABV12@I@Z
 0x72a538 ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QAEHD@Z
 0x72a53c ??A?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAADI@Z
 0x72a540 ?compare@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEHIIABV12@@Z
 0x72a544 ?npos@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@2IB
 0x72a548 ?substr@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBE?AV12@II@Z
 0x72a54c ??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@DABV10@@Z
 0x72a550 ?size@?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@QBEIXZ
 0x72a554 ??4?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@QAEAAV01@PB_W@Z
 0x72a558 ??A?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@QAEAA_WI@Z
 0x72a55c ??$?MDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA_NABV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@0@Z
 0x72a560 ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z
 0x72a564 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBDI@Z
 0x72a568 ??$?8DU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA_NABV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@PBD@Z
 0x72a56c ??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z
 0x72a570 ?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDI@Z
 0x72a574 ?length@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIXZ
 0x72a578 ?data@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEPBDXZ
 0x72a57c ?resize@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEXI@Z
 0x72a580 ?replace@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@IIPBD@Z
 0x72a584 ??0?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@QAE@XZ
 0x72a588 ?substr@?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@QBE?AV12@II@Z
 0x72a58c ?c_str@?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@QBEPB_WXZ
 0x72a590 ??1?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@QAE@XZ
 0x72a594 ??4?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@QAEAAV01@ABV01@@Z
 0x72a598 ?append@?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@QAEAAV12@PB_W@Z
 0x72a59c ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z
 0x72a5a0 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ
 0x72a5a4 ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@PBD@Z
 0x72a5a8 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z
 0x72a5ac ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ
 0x72a5b0 ?size@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIXZ
 0x72a5b4 ?c_str@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEPBDXZ
 0x72a5b8 ??Y?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z
MSVCR80.dll
 0x72a5c0 _encode_pointer
 0x72a5c4 _lock
 0x72a5c8 _onexit
 0x72a5cc _decode_pointer
 0x72a5d0 _except_handler4_common
 0x72a5d4 ?terminate@@YAXXZ
 0x72a5d8 _amsg_exit
 0x72a5dc __getmainargs
 0x72a5e0 _cexit
 0x72a5e4 _exit
 0x72a5e8 _XcptFilter
 0x72a5ec _ismbblead
 0x72a5f0 exit
 0x72a5f4 _acmdln
 0x72a5f8 _initterm
 0x72a5fc _initterm_e
 0x72a600 _configthreadlocale
 0x72a604 __setusermatherr
 0x72a608 _adjust_fdiv
 0x72a60c __p__commode
 0x72a610 __p__fmode
 0x72a614 __set_app_type
 0x72a618 _crt_debugger_hook
 0x72a61c ?_type_info_dtor_internal_method@type_info@@QAEXXZ
 0x72a620 _invoke_watson
 0x72a624 _controlfp_s
 0x72a628 __dllonexit
 0x72a62c _unlock
 0x72a630 _mktime32
 0x72a634 _atoi64
 0x72a638 fwrite
 0x72a63c _ctime32
 0x72a640 _mkdir
 0x72a644 wcslen
 0x72a648 ceil
 0x72a64c atof
 0x72a650 sin
 0x72a654 cos
 0x72a658 fabs
 0x72a65c labs
 0x72a660 abs
 0x72a664 sqrt
 0x72a668 _itoa
 0x72a66c puts
 0x72a670 _getcwd
 0x72a674 _chdir
 0x72a678 _strnicmp
 0x72a67c _strlwr
 0x72a680 fputc
 0x72a684 fprintf
 0x72a688 sscanf
 0x72a68c _vsnprintf_s
 0x72a690 isalpha
 0x72a694 strncmp
 0x72a698 _ismbcalpha
 0x72a69c _mbschr
 0x72a6a0 _mbscspn
 0x72a6a4 _mbsnbcpy
 0x72a6a8 _mbsspn
 0x72a6ac _mbsstr
 0x72a6b0 _mbsnbcmp
 0x72a6b4 toupper
 0x72a6b8 _findclose
 0x72a6bc _findnext32
 0x72a6c0 _findfirst32
 0x72a6c4 wcsstr
 0x72a6c8 floor
 0x72a6cc _endthread
 0x72a6d0 _beginthread
 0x72a6d4 strcat
 0x72a6d8 strcmp
 0x72a6dc strcpy
 0x72a6e0 strlen
 0x72a6e4 vsprintf
 0x72a6e8 sscanf_s
 0x72a6ec sprintf_s
 0x72a6f0 isalnum
 0x72a6f4 __RTDynamicCast
 0x72a6f8 islower
 0x72a6fc srand
 0x72a700 setlocale
 0x72a704 _CIsqrt
 0x72a708 printf
 0x72a70c vsprintf_s
 0x72a710 wcsncmp
 0x72a714 _vswprintf
 0x72a718 rand
 0x72a71c strstr
 0x72a720 isspace
 0x72a724 isdigit
 0x72a728 swscanf
 0x72a72c wcsncpy
 0x72a730 strtok
 0x72a734 _purecall
 0x72a738 swprintf_s
 0x72a73c _recalloc
 0x72a740 wcsncpy_s
 0x72a744 malloc
 0x72a748 memcpy_s
 0x72a74c free
 0x72a750 strrchr
 0x72a754 memmove
 0x72a758 ??_V@YAXPAX@Z
 0x72a75c _wtoi
 0x72a760 memmove_s
 0x72a764 strncat
 0x72a768 ??2@YAPAXI@Z
 0x72a76c ??0exception@std@@QAE@ABV01@@Z
 0x72a770 _CxxThrowException
 0x72a774 fclose
 0x72a778 _snprintf
 0x72a77c _errno
 0x72a780 fopen
 0x72a784 fputs
 0x72a788 strftime
 0x72a78c _time32
 0x72a790 _localtime32
 0x72a794 ??0exception@std@@QAE@XZ
 0x72a798 ??1exception@std@@UAE@XZ
 0x72a79c ?what@exception@std@@UBEPBDXZ
 0x72a7a0 ??0exception@std@@QAE@ABQBD@Z
 0x72a7a4 _invalid_parameter_noinfo
 0x72a7a8 strcpy_s
 0x72a7ac atoi
 0x72a7b0 _open_osfhandle
 0x72a7b4 _fdopen
 0x72a7b8 setvbuf
 0x72a7bc __iob_func
 0x72a7c0 sprintf
 0x72a7c4 memcpy
 0x72a7c8 isgraph
 0x72a7cc strchr
 0x72a7d0 _stricmp
 0x72a7d4 strncpy
 0x72a7d8 memset
 0x72a7dc __CxxFrameHandler3
 0x72a7e0 ??3@YAXPAX@Z
 0x72a7e4 tolower
Engine.dll
 0x72a034 ?PushObj@KJxScript@@QAEHPBVKLunaBase@@@Z
 0x72a038 ?PushNull@KJxScript@@QAEHXZ
 0x72a03c ?IsUser@KJxScript@@QAEHH@Z
 0x72a040 ?PopStack@KJxScript@@QAEHH@Z
 0x72a044 g_CreateIniFile
 0x72a048 ?PushListV@KJxScript@@QAEHPBDPAD@Z
 0x72a04c ?SafeCallBegin@KJxScript@@QAEHAAH@Z
 0x72a050 ?PushFromStack@KJxScript@@QAEHH@Z
 0x72a054 ?SafeCallEnd@KJxScript@@QAEHH@Z
 0x72a058 ?MoveStack@KJxScript@@QAEHH@Z
 0x72a05c ?KGLogInit@@YAHABU_KGLOG_PARAM@@PAX@Z
 0x72a060 ?KGLogUnInit@@YAHPAX@Z
 0x72a064 g_ClearPackageFiles
 0x72a068 g_RandomSeed
 0x72a06c g_SetRootPath
 0x72a070 g_SetFilePath
 0x72a074 g_LoadPackageFiles
 0x72a078 ?Start@KTimer@@QAEXXZ
 0x72a07c ?SetMouseHoverTime@KWin32AppW@@QAEXI@Z
 0x72a080 ?SetGlobalName@KJxScript@@QAEHPBD@Z
 0x72a084 ?InitWindow@KWin32AppW@@MAEHPAUHINSTANCE__@@@Z
 0x72a088 ?InitClass@KWin32AppW@@MAEHPAUHINSTANCE__@@@Z
 0x72a08c ?ShowMouse@KWin32AppW@@UAEXH@Z
 0x72a090 ?Run@KWin32AppW@@UAEXXZ
 0x72a094 ?Init@KWin32AppW@@UAEHPAUHINSTANCE__@@PB_WH@Z
 0x72a098 ??0KWin32AppW@@QAE@XZ
 0x72a09c g_StrCat
 0x72a0a0 g_StrCmpLen
 0x72a0a4 EDOneTimePad_Encipher
 0x72a0a8 EDOneTimePad_Decipher
 0x72a0ac ?Terminate@KThread@@QAEHK@Z
 0x72a0b0 ??1KThread@@QAE@XZ
 0x72a0b4 ??1KMutex@@QAE@XZ
 0x72a0b8 ?Create@KThread@@QAEHP6AXPAX@Z0@Z
 0x72a0bc ??0KThread@@QAE@XZ
 0x72a0c0 g_DebugLog
 0x72a0c4 ?ReadList@KJxScript@@QAAHHPBDZZ
 0x72a0c8 ?IsTable@KJxScript@@QAEHH@Z
 0x72a0cc ?GetObjLen@KJxScript@@QAEHH@Z
 0x72a0d0 ?GetType@KJxScript@@QAE?AW4KE_DATA_TYPE@1@H@Z
 0x72a0d4 ?GetTableIndex@KJxScript@@QAEHHH@Z
 0x72a0d8 Misc_CRC32
 0x72a0dc ?PushLString@KJxScript@@QAEHPBDH@Z
 0x72a0e0 ?GetNum@KJxScript@@QAENH@Z
 0x72a0e4 g_SetFindFileMode
 0x72a0e8 ?GetGlobalF@KJxScript@@QAEHPBD@Z
 0x72a0ec ?KG_EDStringToMD5String@@YAHQADQBD@Z
 0x72a0f0 g_StrCmp
 0x72a0f4 g_StrCpyLen
 0x72a0f8 g_OpenTabFile
 0x72a0fc g_CreateFile
 0x72a100 g_FindColorName
 0x72a104 g_StrLen
 0x72a108 _g_GetColorValue
 0x72a10c ??1KImeW@@UAE@XZ
 0x72a110 ??0KImeW@@QAE@XZ
 0x72a114 ?EnableLanguageChange@KImeBase@@QAEXXZ
 0x72a118 ?OpenIME@KImeBase@@QAEXXZ
 0x72a11c ?SetCaretPos@KImeBase@@QAEXHH@Z
 0x72a120 ?GetAllocMemSize@KJxScript@@QBEIXZ
 0x72a124 g_OpenFile
 0x72a128 ??0KTimer@@QAE@XZ
 0x72a12c ?GetElapse@KTimer@@QAEIXZ
 0x72a130 ?GetFPS@KTimer@@QAEHPAH@Z
 0x72a134 ?GetInstance@KImeW@@SAPAV1@XZ
 0x72a138 ?IsIme@KImeBase@@QAEHXZ
 0x72a13c ?DisableLanguageChange@KImeBase@@QAEXXZ
 0x72a140 ?CloseIME@KImeBase@@QAEXXZ
 0x72a144 ??0KScriptGroup@@QAE@PBD@Z
 0x72a148 g_StringHash
 0x72a14c g_GetFullPath
 0x72a150 ?IsString@KJxScript@@QAEHH@Z
 0x72a154 g_CreatePath
 0x72a158 g_OpenIniFile
 0x72a15c ?GetThis@KJxScript@@SAPAV1@PAUlua_State@@@Z
 0x72a160 ?DoBuffer@KJxScript@@QAEHPBD0@Z
 0x72a164 ?RegisterTableFunctions@KJxScript@@QAEHPBDQBUTScriptFunc@@K@Z
 0x72a168 ?GetLStr@KJxScript@@QAEPBDHAAH@Z
 0x72a16c ?SetTableField@KJxScript@@QAEHPBD@Z
 0x72a170 ?PushList@KJxScript@@QAAHPBDZZ
 0x72a174 ?KGLogPrintf@@YAHW4KGLOG_PRIORITY@@QBDZZ
 0x72a178 ?IsNumber@KJxScript@@QAEHH@Z
 0x72a17c g_StrCpy
 0x72a180 g_GetRootPath
 0x72a184 ?GetStr@KJxScript@@QAEPBDH@Z
 0x72a188 ?GetInt@KJxScript@@QAEHH@Z
 0x72a18c ?GetMainWnd@KWin32AppW@@SAPAUHWND__@@XZ
 0x72a190 ?PushNumber@KJxScript@@QAEHN@Z
 0x72a194 ??1KLogFile@@UAE@XZ
 0x72a198 ??0KLogFile@@QAE@XZ
 0x72a19c ?InitialLogFile@KLogFile@@QAEHPBD0I@Z
 0x72a1a0 ?LogRecordVar@KLogFile@@QAAXW4LOG_RECORD_REMIND_LEVEL@@PBDZZ
 0x72a1a4 ?GetGlobal@KJxScript@@QAEHPBD@Z
 0x72a1a8 ?GetTableField@KJxScript@@QAEHHPBD@Z
 0x72a1ac ?PushString@KJxScript@@QAEHPBD@Z
 0x72a1b0 ?PushTable@KJxScript@@QAEHXZ
 0x72a1b4 ?SetTableIndex@KJxScript@@QAEHH@Z
 0x72a1b8 ?DoCall@KJxScript@@QAEHHH@Z
 0x72a1bc ?CallTableFunction@KJxScript@@QAAHPBD0H0ZZ
 0x72a1c0 ?SetTopIndex@KJxScript@@QAEHH@Z
 0x72a1c4 ?GetTopIndex@KJxScript@@QAEHXZ
 0x72a1c8 ?LoadScript@KScriptGroup@@QAEHPBDH@Z
 0x72a1cc ?SetCanUseUnpackFile@KScriptGroup@@QAEHH@Z
 0x72a1d0 ?RegisterTableFunctions@KJxScript@@QAEHPBDPBUKSCRIPT_FUNCTION@@K@Z
 0x72a1d4 ?LoadScriptInDirectory@KScriptGroup@@QAEHPBD@Z
 0x72a1d8 ?SetPackPartnerFile@KScriptGroup@@SAHPBD@Z
 0x72a1dc ?GetCObj@KLunaBase@@SAPAV1@PAUlua_State@@H@Z
 0x72a1e0 ?ClearScriptTempTable@KLunaBase@@KAHPAUlua_State@@PBDH@Z
 0x72a1e4 ?GetScriptTempTable@KLunaBase@@KAHPAUlua_State@@PBDH@Z
 0x72a1e8 ?GetObj@KJxScript@@QAEPAVKLunaBase@@H@Z
 0x72a1ec ?SaveValue2Buffer@KJxScript@@QAEHPAEHH@Z
 0x72a1f0 ??0KLunaBase@@QAE@XZ
 0x72a1f4 ?_PushCObj@KLunaBase@@IBEHPAUlua_State@@PBDH@Z
 0x72a1f8 CreatePackFileShell
 0x72a1fc ?LoadBuffer2Value@KJxScript@@QAEHPBEH@Z
 0x72a200 ?LogRecord@KLogFile@@QAEXW4LOG_RECORD_REMIND_LEVEL@@PBDH@Z
 0x72a204 ?KGThread_Sleep@@YAHI@Z
 0x72a208 ?KG_GetTickCount@@YAKXZ
 0x72a20c ??0KMutex@@QAE@XZ
 0x72a210 ?Unlock@KMutex@@QAEHXZ
 0x72a214 ?Lock@KMutex@@QAEHXZ
 0x72a218 g_Random
 0x72a21c ?LoadBuffer@KJxScript@@QAEHPAEKPBD@Z
 0x72a220 KSG_StringSkipSymbol
 0x72a224 ?GetCenterPos@KPolygon@@QAEXPAH0@Z
 0x72a228 KSG_StringGetInt
 0x72a22c ?Stop@KTimer@@QAEXXZ
 0x72a230 g_UnitePathAndName
 0x72a234 g_FileNameHash
 0x72a238 g_IsFileExist
 0x72a23c g_SetColorTable
 0x72a240 ?CallTableFunctionV@KJxScript@@QAEHPBD0H0PAD@Z
 0x72a244 ?CallGlobalFunctionV@KJxScript@@QAEHPBDH0PAD@Z
 0x72a248 g_GetRandomSeed
 0x72a24c ??1KScriptGroup@@QAE@XZ
 0x72a250 ?_Register@KLunaBase@@KAHPAUlua_State@@PBDPAUKLuaData@1@P6AH0@Z333@Z
 0x72a254 ?GetLuaState@KJxScript@@QAEPAUlua_State@@XZ
 0x72a258 ?Clear@KScriptGroup@@QAEXHH@Z
 0x72a25c ?IsPointInPolygon@KPolygon@@QAEHHH@Z
 0x72a260 ?ReleaseAllFreeMemory@KJxScript@@SAHXZ
 0x72a264 ?GetScript@KScriptGroup@@QAEPAVKJxScript@@XZ
 0x72a268 ?_LuaTostring@KLunaBase@@KAHPAUlua_State@@PBD@Z
 0x72a26c ?_LuaIndex@KLunaBase@@KAHPAUlua_State@@PBDP6AH0@Z@Z
 0x72a270 ?_LuaDispatcher@KLunaBase@@KAHPAUlua_State@@PBD@Z
 0x72a274 ?_LuaNewIndex@KLunaBase@@KAHPAUlua_State@@PBD@Z
 0x72a278 ?_LuaGetDataInfo@KLunaBase@@KAHPAUlua_State@@PBD@Z
 0x72a27c ?GetFreeMemSize@KJxScript@@QBEIXZ
 0x72a280 ?TurnOn@KImeBase@@QAEXXZ
 0x72a284 ?OutPutErrMsgF@KJxScript@@QAAHPBDZZ
text.dll
 0x72aa30 ClearSpecialCtrlInEncodedTextW
 0x72aa34 GetUnicodeRange
 0x72aa38 GetEncodedTextSingleLineLimitPos
 0x72aa3c GetEncodedTextLineCountW
 0x72aa40 ConvertUnicodeToCurLang
 0x72aa44 ConvertCurLangToUnicode
 0x72aa48 EncodeTextW
 0x72aa4c GetLimitLenStringW
 0x72aa50 ConvertEncodeBuffCurLangToUnicode
 0x72aa54 GetTextWidth
 0x72aa58 ConvertEncodeBuffUnicodeToCurLang
 0x72aa5c RemoveCtrlInEncodedTextW
 0x72aa60 FindSpecialCtrlInEncodedTextW
 0x72aa64 SplitEncodedStringW
 0x72aa68 RegisterInlineCtrlW
 0x72aa6c RemoveInlineWndCtrlW
 0x72aa70 InitTextRender
 0x72aa74 GetLimitLenEncodedStringW
 0x72aa78 GetCtrlHandleW
WS2_32.dll
 0x72a97c WSAStartup
 0x72a980 WSACleanup
 0x72a984 htonl
 0x72a988 closesocket
 0x72a98c ioctlsocket
 0x72a990 gethostbyname
 0x72a994 connect
 0x72a998 accept
 0x72a99c WSARecv
 0x72a9a0 socket
 0x72a9a4 inet_addr
 0x72a9a8 htons
 0x72a9ac ind
 0x72a9b0 listen
 0x72a9b4 send
 0x72a9b8 recv
 0x72a9bc select
 0x72a9c0 setsockopt
 0x72a9c4 WSAGetLastError
WINMM.dll
 0x72a974 timeGetTime
PSAPI.DLL
 0x72a82c EnumProcessModules
 0x72a830 EnumProcesses
 0x72a834 GetModuleFileNameExA

EAT(Export Address Table) Library

0x7073cb ??4_Init_locks@std@@QAEAAV01@ABV01@@Z
0x4c1490 CoreGetShell


Similarity measure (PE file only) - Checking for service failure