Report - Geek.exe

Emotet Generic Malware Malicious Library Malicious Packer Antivirus UPX PE File DllRegisterServer dll PE32 OS Processor Check
ScreenShot
Created 2024.10.18 10:23 Machine s1_win7_x6403
Filename Geek.exe
Type PE32 executable (GUI) Intel 80386, for MS Windows
AI Score
2
Behavior Score
4.0
ZERO API file : mailcious
VT API (file) 51 detected (AIDetectMalware, CryptZ, Malicious, score, Marte, Unsafe, HackTool, Reverse, through, uwccg, confidence, 100%, Rozena, Meterpreter, Windows, Metasploit, Swrort, ccnc, CLASSIC, Gen2, YXEJRZ, EncPk, Static AI, Suspicious PE, Detected, Shelm, aqkw, A@4jwdqr, Eldorado, Artemis, Outbreak)
md5 c0eeaaaae6a849152fe8e826a21b6054
sha256 ba619aed58332f8cf8fb93939e6986f9d8b3d0bae3ffa0348dbad5b43c186b19
ssdeep 98304:1DGNSuNY3icztjLO5UE2Ymg77UQ1mfa/ews4VOp9mD:NGNO3icztfO5UEIg7oQcfa/ewsWOpsD
imphash ad779a1bb2e6ce5ca2839622084e8159
impfuzzy 192:oMWLViFVtD084P5U6JmWYQqlXFYpuracEcacsJHSUGL9OPOc3jYOK:oMM8DD08CS3ra1zGUG8Oc3jYOK
  Network IP location

Signature (7cnts)

Level Description
danger File has been identified by 51 AntiVirus engines on VirusTotal as malicious
danger Connects to an IP address that is no longer responding to requests (legitimate services will remain up-and-running usually)
watch Communicates with host for which no DNS query was performed
notice Allocates read-write-execute memory (usually to unpack itself)
notice The binary likely contains encrypted or compressed data indicative of a packer
info The file contains an unknown PE resource name possibly indicative of a packer
info This executable has a PDB path

Rules (10cnts)

Level Name Description Collection
danger Win32_Trojan_Emotet_2_Zero Win32 Trojan Emotet binaries (upload)
warning Generic_Malware_Zero Generic Malware binaries (upload)
watch Antivirus Contains references to security software binaries (upload)
watch Malicious_Library_Zero Malicious_Library binaries (upload)
watch Malicious_Packer_Zero Malicious Packer binaries (upload)
watch UPX_Zero UPX packed file binaries (upload)
info DllRegisterServer_Zero execute regsvr32.exe binaries (upload)
info IsPE32 (no description) binaries (upload)
info OS_Processor_Check_Zero OS Processor Check binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (1cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
47.236.122.191 Unknown 47.236.122.191 mailcious

Suricata ids

PE API

IAT(Import Address Table) Library

KERNEL32.dll
 0x5ea1f0 FlushFileBuffers
 0x5ea1f4 GetVolumeInformationW
 0x5ea1f8 LockFile
 0x5ea1fc SetEndOfFile
 0x5ea200 UnlockFile
 0x5ea204 DuplicateHandle
 0x5ea208 TlsAlloc
 0x5ea20c TlsGetValue
 0x5ea210 TlsSetValue
 0x5ea214 TlsFree
 0x5ea218 GlobalReAlloc
 0x5ea21c GlobalHandle
 0x5ea220 LocalReAlloc
 0x5ea224 GlobalGetAtomNameW
 0x5ea228 GetFileSizeEx
 0x5ea22c GlobalFlags
 0x5ea230 GetSystemDefaultUILanguage
 0x5ea234 SetErrorMode
 0x5ea238 GetUserDefaultLCID
 0x5ea23c IsProcessorFeaturePresent
 0x5ea240 UnhandledExceptionFilter
 0x5ea244 QueryPerformanceCounter
 0x5ea248 GetSystemTimeAsFileTime
 0x5ea24c InitializeSListHead
 0x5ea250 GetStartupInfoW
 0x5ea254 SetEnvironmentVariableW
 0x5ea258 FreeEnvironmentStringsW
 0x5ea25c GetEnvironmentStringsW
 0x5ea260 FindFirstFileExW
 0x5ea264 GetDriveTypeW
 0x5ea268 ReadConsoleW
 0x5ea26c GetConsoleOutputCP
 0x5ea270 SetFilePointerEx
 0x5ea274 GetTimeZoneInformation
 0x5ea278 GetOEMCP
 0x5ea27c IsValidCodePage
 0x5ea280 EnumSystemLocalesW
 0x5ea284 IsValidLocale
 0x5ea288 GetPrivateProfileIntW
 0x5ea28c HeapQueryInformation
 0x5ea290 VirtualQuery
 0x5ea294 GetSystemInfo
 0x5ea298 GetCommandLineA
 0x5ea29c GetFileType
 0x5ea2a0 SetStdHandle
 0x5ea2a4 FreeLibraryAndExitThread
 0x5ea2a8 ExitThread
 0x5ea2ac RtlUnwind
 0x5ea2b0 GetCPInfo
 0x5ea2b4 CompareStringEx
 0x5ea2b8 LCMapStringEx
 0x5ea2bc GetStringTypeW
 0x5ea2c0 SleepConditionVariableSRW
 0x5ea2c4 SleepConditionVariableCS
 0x5ea2c8 WakeAllConditionVariable
 0x5ea2cc WakeConditionVariable
 0x5ea2d0 InitializeConditionVariable
 0x5ea2d4 TryEnterCriticalSection
 0x5ea2d8 AcquireSRWLockExclusive
 0x5ea2dc ReleaseSRWLockExclusive
 0x5ea2e0 InitializeSRWLock
 0x5ea2e4 SuspendThread
 0x5ea2e8 GlobalFindAtomW
 0x5ea2ec GlobalAddAtomW
 0x5ea2f0 GlobalDeleteAtom
 0x5ea2f4 GetSystemDirectoryW
 0x5ea2f8 EncodePointer
 0x5ea2fc OutputDebugStringA
 0x5ea300 GetACP
 0x5ea304 OpenEventW
 0x5ea308 OpenMutexW
 0x5ea30c CreateMutexW
 0x5ea310 GlobalFree
 0x5ea314 lstrlenA
 0x5ea318 ExitProcess
 0x5ea31c CompareStringW
 0x5ea320 EnumResourceLanguagesW
 0x5ea324 EnumResourceTypesW
 0x5ea328 EnumResourceNamesW
 0x5ea32c GetPrivateProfileSectionNamesW
 0x5ea330 WritePrivateProfileStringW
 0x5ea334 GetPrivateProfileStringW
 0x5ea338 lstrcmpA
 0x5ea33c ResumeThread
 0x5ea340 SetThreadPriority
 0x5ea344 CreateThread
 0x5ea348 CreateDirectoryW
 0x5ea34c GetTimeFormatW
 0x5ea350 GetDateFormatW
 0x5ea354 GetModuleHandleA
 0x5ea358 LocalUnlock
 0x5ea35c LocalLock
 0x5ea360 GetVersionExW
 0x5ea364 VirtualFree
 0x5ea368 VirtualAlloc
 0x5ea36c ExpandEnvironmentStringsW
 0x5ea370 SetFilePointer
 0x5ea374 GlobalLock
 0x5ea378 GlobalUnlock
 0x5ea37c GlobalAlloc
 0x5ea380 lstrcatW
 0x5ea384 lstrcpyW
 0x5ea388 GetNativeSystemInfo
 0x5ea38c GetVersion
 0x5ea390 SetUnhandledExceptionFilter
 0x5ea394 K32GetModuleFileNameExW
 0x5ea398 GetThreadLocale
 0x5ea39c K32EnumProcessModules
 0x5ea3a0 Process32NextW
 0x5ea3a4 Process32FirstW
 0x5ea3a8 CreateToolhelp32Snapshot
 0x5ea3ac QueryFullProcessImageNameW
 0x5ea3b0 FormatMessageW
 0x5ea3b4 GetModuleHandleExW
 0x5ea3b8 GetModuleFileNameW
 0x5ea3bc GetModuleFileNameA
 0x5ea3c0 GetCurrentThread
 0x5ea3c4 GetExitCodeProcess
 0x5ea3c8 GetProcessTimes
 0x5ea3cc CreateSemaphoreExW
 0x5ea3d0 CreateMutexExW
 0x5ea3d4 OpenSemaphoreW
 0x5ea3d8 WaitForSingleObjectEx
 0x5ea3dc ReleaseMutex
 0x5ea3e0 ReleaseSemaphore
 0x5ea3e4 OutputDebugStringW
 0x5ea3e8 DebugBreak
 0x5ea3ec IsDebuggerPresent
 0x5ea3f0 FileTimeToLocalFileTime
 0x5ea3f4 CompareFileTime
 0x5ea3f8 GetTempFileNameW
 0x5ea3fc GetFullPathNameW
 0x5ea400 FindNextFileW
 0x5ea404 FindFirstFileW
 0x5ea408 FindClose
 0x5ea40c SetConsoleTextAttribute
 0x5ea410 GetConsoleScreenBufferInfo
 0x5ea414 WriteConsoleA
 0x5ea418 GetConsoleMode
 0x5ea41c GetStdHandle
 0x5ea420 GetDynamicTimeZoneInformation
 0x5ea424 GetFileAttributesW
 0x5ea428 WriteConsoleW
 0x5ea42c GetWindowsDirectoryW
 0x5ea430 SetFileAttributesW
 0x5ea434 RemoveDirectoryW
 0x5ea438 IsBadWritePtr
 0x5ea43c IsBadReadPtr
 0x5ea440 UnmapViewOfFile
 0x5ea444 MapViewOfFile
 0x5ea448 CreateFileMappingW
 0x5ea44c MoveFileExW
 0x5ea450 SystemTimeToFileTime
 0x5ea454 GetSystemTime
 0x5ea458 CreateProcessW
 0x5ea45c GetComputerNameW
 0x5ea460 FileTimeToSystemTime
 0x5ea464 SystemTimeToTzSpecificLocalTime
 0x5ea468 GetFileTime
 0x5ea46c GetFileAttributesExW
 0x5ea470 InitializeCriticalSectionAndSpinCount
 0x5ea474 LoadLibraryW
 0x5ea478 GetLongPathNameW
 0x5ea47c GetExitCodeThread
 0x5ea480 GetTickCount
 0x5ea484 InitializeCriticalSectionEx
 0x5ea488 GetProcessHeap
 0x5ea48c HeapSize
 0x5ea490 HeapFree
 0x5ea494 HeapReAlloc
 0x5ea498 HeapAlloc
 0x5ea49c RaiseException
 0x5ea4a0 DecodePointer
 0x5ea4a4 lstrcmpW
 0x5ea4a8 SearchPathW
 0x5ea4ac ReadFile
 0x5ea4b0 GetFileSize
 0x5ea4b4 GetCommandLineW
 0x5ea4b8 GetLocalTime
 0x5ea4bc Sleep
 0x5ea4c0 GetCurrentDirectoryW
 0x5ea4c4 lstrcpynW
 0x5ea4c8 LoadLibraryExW
 0x5ea4cc VirtualProtect
 0x5ea4d0 LoadLibraryA
 0x5ea4d4 FreeLibrary
 0x5ea4d8 lstrlenW
 0x5ea4dc OpenProcess
 0x5ea4e0 TerminateProcess
 0x5ea4e4 GetLastError
 0x5ea4e8 MulDiv
 0x5ea4ec GetLocaleInfoW
 0x5ea4f0 VerifyVersionInfoW
 0x5ea4f4 VerSetConditionMask
 0x5ea4f8 LocalFree
 0x5ea4fc LocalAlloc
 0x5ea500 GetProcAddress
 0x5ea504 GetTickCount64
 0x5ea508 WideCharToMultiByte
 0x5ea50c GetCurrentThreadId
 0x5ea510 DeleteCriticalSection
 0x5ea514 CreateFileW
 0x5ea518 LeaveCriticalSection
 0x5ea51c EnterCriticalSection
 0x5ea520 InitializeCriticalSection
 0x5ea524 GetUserDefaultUILanguage
 0x5ea528 GetModuleHandleW
 0x5ea52c GetCurrentProcess
 0x5ea530 GetTempPathW
 0x5ea534 WriteFile
 0x5ea538 DeleteFileW
 0x5ea53c MultiByteToWideChar
 0x5ea540 GetCurrentProcessId
 0x5ea544 FindResourceW
 0x5ea548 SizeofResource
 0x5ea54c LockResource
 0x5ea550 LoadResource
 0x5ea554 TerminateThread
 0x5ea558 WaitForMultipleObjects
 0x5ea55c CreateEventW
 0x5ea560 WaitForSingleObject
 0x5ea564 ResetEvent
 0x5ea568 SetEvent
 0x5ea56c SetLastError
 0x5ea570 CloseHandle
 0x5ea574 LCMapStringW
USER32.dll
 0x5ea678 CopyAcceleratorTableW
 0x5ea67c LoadAcceleratorsW
 0x5ea680 IsWindowEnabled
 0x5ea684 MapVirtualKeyExW
 0x5ea688 GetKeyNameTextW
 0x5ea68c GetKeyboardState
 0x5ea690 IsCharLowerW
 0x5ea694 CharUpperW
 0x5ea698 IsIconic
 0x5ea69c GetKeyboardLayout
 0x5ea6a0 GetKeyboardLayoutList
 0x5ea6a4 ToUnicodeEx
 0x5ea6a8 GetMenuItemCount
 0x5ea6ac GetMenuItemInfoW
 0x5ea6b0 GetMenuItemID
 0x5ea6b4 SetParent
 0x5ea6b8 GetTopWindow
 0x5ea6bc UpdateWindow
 0x5ea6c0 LoadMenuW
 0x5ea6c4 MapVirtualKeyW
 0x5ea6c8 wsprintfW
 0x5ea6cc EndDeferWindowPos
 0x5ea6d0 DeferWindowPos
 0x5ea6d4 BeginDeferWindowPos
 0x5ea6d8 CreateIconIndirect
 0x5ea6dc CreateIconFromResourceEx
 0x5ea6e0 LoadBitmapW
 0x5ea6e4 DrawStateW
 0x5ea6e8 RegisterClipboardFormatW
 0x5ea6ec GetNextDlgTabItem
 0x5ea6f0 GetSysColorBrush
 0x5ea6f4 AdjustWindowRectEx
 0x5ea6f8 CallNextHookEx
 0x5ea6fc UnhookWindowsHookEx
 0x5ea700 SetWindowsHookExW
 0x5ea704 GetDesktopWindow
 0x5ea708 InvertRect
 0x5ea70c LockWindowUpdate
 0x5ea710 GetDCEx
 0x5ea714 TabbedTextOutW
 0x5ea718 GrayStringW
 0x5ea71c DrawTextExW
 0x5ea720 GetSubMenu
 0x5ea724 ReleaseCapture
 0x5ea728 SetCapture
 0x5ea72c GetCapture
 0x5ea730 CheckMenuItem
 0x5ea734 SetMenuItemBitmaps
 0x5ea738 EnableWindow
 0x5ea73c GetWindowTextW
 0x5ea740 EnumWindows
 0x5ea744 WinHelpW
 0x5ea748 IsDialogMessageW
 0x5ea74c GetWindow
 0x5ea750 GetLastActivePopup
 0x5ea754 MessageBeep
 0x5ea758 RedrawWindow
 0x5ea75c IsZoomed
 0x5ea760 EnableMenuItem
 0x5ea764 GetSystemMenu
 0x5ea768 GetAsyncKeyState
 0x5ea76c GetDialogBaseUnits
 0x5ea770 CheckDlgButton
 0x5ea774 CreateDialogIndirectParamW
 0x5ea778 MoveWindow
 0x5ea77c DestroyWindow
 0x5ea780 PostQuitMessage
 0x5ea784 WaitMessage
 0x5ea788 PeekMessageW
 0x5ea78c DispatchMessageW
 0x5ea790 TranslateMessage
 0x5ea794 LoadStringW
 0x5ea798 EnumDisplaySettingsW
 0x5ea79c FindWindowExW
 0x5ea7a0 FindWindowW
 0x5ea7a4 MessageBoxW
 0x5ea7a8 WaitForInputIdle
 0x5ea7ac GetMenuCheckMarkDimensions
 0x5ea7b0 EmptyClipboard
 0x5ea7b4 SetClipboardData
 0x5ea7b8 CloseClipboard
 0x5ea7bc GetDoubleClickTime
 0x5ea7c0 GetMenu
 0x5ea7c4 SetMenu
 0x5ea7c8 GetMenuState
 0x5ea7cc GetClassLongW
 0x5ea7d0 SetCursorPos
 0x5ea7d4 CallWindowProcW
 0x5ea7d8 IsWindowUnicode
 0x5ea7dc GetWindowLongA
 0x5ea7e0 SetWindowLongA
 0x5ea7e4 GetTabbedTextExtentA
 0x5ea7e8 MapDialogRect
 0x5ea7ec GetWindowPlacement
 0x5ea7f0 SetWindowPlacement
 0x5ea7f4 TranslateAcceleratorW
 0x5ea7f8 DrawFocusRect
 0x5ea7fc OpenClipboard
 0x5ea800 BringWindowToTop
 0x5ea804 ShowWindow
 0x5ea808 CreateWindowExW
 0x5ea80c DefWindowProcW
 0x5ea810 GetMessageW
 0x5ea814 CharLowerBuffW
 0x5ea818 CharLowerBuffA
 0x5ea81c FillRect
 0x5ea820 InsertMenuW
 0x5ea824 SetWindowTextW
 0x5ea828 GetDlgItem
 0x5ea82c CharLowerW
 0x5ea830 IsClipboardFormatAvailable
 0x5ea834 MapWindowPoints
 0x5ea838 IsMenu
 0x5ea83c IsChild
 0x5ea840 GetDlgCtrlID
 0x5ea844 GetWindowRgn
 0x5ea848 HideCaret
 0x5ea84c ShowCaret
 0x5ea850 SetActiveWindow
 0x5ea854 SetWindowRgn
 0x5ea858 UnionRect
 0x5ea85c GetMenuStringW
 0x5ea860 LookupIconIdFromDirectoryEx
 0x5ea864 GetCursor
 0x5ea868 WindowFromPoint
 0x5ea86c DrawIcon
 0x5ea870 DrawEdge
 0x5ea874 SendMessageW
 0x5ea878 GetSysColor
 0x5ea87c GetParent
 0x5ea880 EnumChildWindows
 0x5ea884 GetFocus
 0x5ea888 GetSystemMetrics
 0x5ea88c DrawTextW
 0x5ea890 GetDC
 0x5ea894 ReleaseDC
 0x5ea898 BeginPaint
 0x5ea89c EndPaint
 0x5ea8a0 InvalidateRgn
 0x5ea8a4 GetWindowTextLengthW
 0x5ea8a8 GetClientRect
 0x5ea8ac GetWindowRect
 0x5ea8b0 GetCursorPos
 0x5ea8b4 FrameRect
 0x5ea8b8 InflateRect
 0x5ea8bc IntersectRect
 0x5ea8c0 PtInRect
 0x5ea8c4 GetWindowLongW
 0x5ea8c8 GetClassNameW
 0x5ea8cc RegisterWindowMessageW
 0x5ea8d0 PostMessageW
 0x5ea8d4 IsWindow
 0x5ea8d8 GetKeyState
 0x5ea8dc InvalidateRect
 0x5ea8e0 SetCursor
 0x5ea8e4 ScreenToClient
 0x5ea8e8 SetRect
 0x5ea8ec UnpackDDElParam
 0x5ea8f0 OffsetRect
 0x5ea8f4 LoadCursorW
 0x5ea8f8 DestroyIcon
 0x5ea8fc LoadImageW
 0x5ea900 DrawIconEx
 0x5ea904 GetIconInfo
 0x5ea908 LoadIconW
 0x5ea90c SetWindowPos
 0x5ea910 SetWindowLongW
 0x5ea914 SendMessageTimeoutW
 0x5ea918 GetWindowThreadProcessId
 0x5ea91c DrawFrameControl
 0x5ea920 GetMessagePos
 0x5ea924 CreatePopupMenu
 0x5ea928 AppendMenuW
 0x5ea92c CopyRect
 0x5ea930 SetClassLongW
 0x5ea934 SystemParametersInfoW
 0x5ea938 GetForegroundWindow
 0x5ea93c SetRectEmpty
 0x5ea940 IsRectEmpty
 0x5ea944 EqualRect
 0x5ea948 GetActiveWindow
 0x5ea94c UnregisterClassW
 0x5ea950 IsWindowVisible
 0x5ea954 TrackPopupMenu
 0x5ea958 GetMenuDefaultItem
 0x5ea95c SetForegroundWindow
 0x5ea960 SetTimer
 0x5ea964 KillTimer
 0x5ea968 ClientToScreen
 0x5ea96c CopyIcon
 0x5ea970 SetMenuItemInfoW
 0x5ea974 GetMessageTime
 0x5ea978 RegisterClassW
 0x5ea97c GetClassInfoW
 0x5ea980 SendDlgItemMessageA
 0x5ea984 GetClassInfoExW
 0x5ea988 ValidateRect
 0x5ea98c GetScrollPos
 0x5ea990 SetScrollRange
 0x5ea994 SetPropW
 0x5ea998 GetPropW
 0x5ea99c RemovePropW
 0x5ea9a0 MonitorFromWindow
 0x5ea9a4 GetMonitorInfoW
 0x5ea9a8 EndDialog
 0x5ea9ac ShowOwnedPopups
 0x5ea9b0 GetWindowDC
 0x5ea9b4 CharNextW
 0x5ea9b8 DestroyMenu
 0x5ea9bc SetWindowContextHelpId
 0x5ea9c0 DrawMenuBar
 0x5ea9c4 DefFrameProcW
 0x5ea9c8 TranslateMDISysAccel
 0x5ea9cc InsertMenuItemW
 0x5ea9d0 PostThreadMessageW
 0x5ea9d4 GetNextDlgGroupItem
 0x5ea9d8 RealChildWindowFromPoint
 0x5ea9dc DeleteMenu
 0x5ea9e0 ReuseDDElParam
 0x5ea9e4 SetFocus
GDI32.dll
 0x5ea090 GetCharWidthW
 0x5ea094 GetClipBox
 0x5ea098 GetClipRgn
 0x5ea09c GetCurrentPositionEx
 0x5ea0a0 GetTextAlign
 0x5ea0a4 GetTextExtentPoint32A
 0x5ea0a8 GetViewportExtEx
 0x5ea0ac GetWindowExtEx
 0x5ea0b0 IntersectClipRect
 0x5ea0b4 LineTo
 0x5ea0b8 ExtSelectClipRgn
 0x5ea0bc BeginPath
 0x5ea0c0 CloseFigure
 0x5ea0c4 EndPath
 0x5ea0c8 FillPath
 0x5ea0cc StrokeAndFillPath
 0x5ea0d0 StrokePath
 0x5ea0d4 MoveToEx
 0x5ea0d8 PolyBezierTo
 0x5ea0dc OffsetViewportOrgEx
 0x5ea0e0 GetRgnBox
 0x5ea0e4 GetBkColor
 0x5ea0e8 RestoreDC
 0x5ea0ec RealizePalette
 0x5ea0f0 SaveDC
 0x5ea0f4 SetDIBitsToDevice
 0x5ea0f8 ExcludeClipRect
 0x5ea0fc SelectClipRgn
 0x5ea100 Ellipse
 0x5ea104 SetMapMode
 0x5ea108 SetTextAlign
 0x5ea10c SetViewportExtEx
 0x5ea110 SetViewportOrgEx
 0x5ea114 SetWindowExtEx
 0x5ea118 ScaleViewportExtEx
 0x5ea11c ScaleWindowExtEx
 0x5ea120 GetMapMode
 0x5ea124 SetRectRgn
 0x5ea128 DPtoLP
 0x5ea12c StretchDIBits
 0x5ea130 CreatePatternBrush
 0x5ea134 CombineRgn
 0x5ea138 Polyline
 0x5ea13c CreateFontW
 0x5ea140 GetViewportOrgEx
 0x5ea144 GetBitmapBits
 0x5ea148 ExtCreateRegion
 0x5ea14c PtInRegion
 0x5ea150 CreateRectRgn
 0x5ea154 GetTextMetricsW
 0x5ea158 GetCurrentObject
 0x5ea15c CreateDIBSection
 0x5ea160 SetStretchBltMode
 0x5ea164 StretchBlt
 0x5ea168 GetDIBits
 0x5ea16c CreateBitmap
 0x5ea170 Polygon
 0x5ea174 TextOutW
 0x5ea178 SetPixel
 0x5ea17c RectVisible
 0x5ea180 PtVisible
 0x5ea184 Escape
 0x5ea188 EnumFontFamiliesExW
 0x5ea18c CreateRectRgnIndirect
 0x5ea190 BitBlt
 0x5ea194 DeleteDC
 0x5ea198 CreateDCW
 0x5ea19c GetTextColor
 0x5ea1a0 RoundRect
 0x5ea1a4 Rectangle
 0x5ea1a8 GetTextExtentPoint32W
 0x5ea1ac CreateFontIndirectW
 0x5ea1b0 CreateCompatibleDC
 0x5ea1b4 CreateCompatibleBitmap
 0x5ea1b8 GetObjectW
 0x5ea1bc DeleteObject
 0x5ea1c0 CreatePen
 0x5ea1c4 ExtTextOutW
 0x5ea1c8 SetTextColor
 0x5ea1cc SetBkMode
 0x5ea1d0 SetBkColor
 0x5ea1d4 SelectObject
 0x5ea1d8 PatBlt
 0x5ea1dc GetStockObject
 0x5ea1e0 GetDeviceCaps
 0x5ea1e4 GetPixel
 0x5ea1e8 CreateSolidBrush
MSIMG32.dll
 0x5ea57c GradientFill
WINSPOOL.DRV
 0x5eaa78 OpenPrinterW
 0x5eaa7c DocumentPropertiesW
 0x5eaa80 ClosePrinter
ADVAPI32.dll
 0x5ea000 RegEnumValueW
 0x5ea004 RegOpenKeyExW
 0x5ea008 RegCreateKeyExW
 0x5ea00c RegQueryValueExW
 0x5ea010 RegDeleteValueW
 0x5ea014 RegSetValueExW
 0x5ea018 OpenProcessToken
 0x5ea01c AdjustTokenPrivileges
 0x5ea020 LookupPrivilegeValueW
 0x5ea024 RegQueryInfoKeyW
 0x5ea028 RegDeleteKeyW
 0x5ea02c GetTokenInformation
 0x5ea030 IsValidSid
 0x5ea034 RegQueryValueW
 0x5ea038 RegEnumKeyW
 0x5ea03c RegCloseKey
 0x5ea040 RegEnumKeyExW
 0x5ea044 ConvertSidToStringSidW
SHELL32.dll
 0x5ea5fc DragFinish
 0x5ea600 DragQueryFileW
 0x5ea604 SHGetSpecialFolderLocation
 0x5ea608 SHGetMalloc
 0x5ea60c ShellExecuteExW
 0x5ea610 SHGetSpecialFolderPathW
 0x5ea614 SHCreateDirectoryExW
 0x5ea618 SHGetPathFromIDListW
 0x5ea61c SHFileOperationW
 0x5ea620 CommandLineToArgvW
 0x5ea624 SHGetFileInfoW
 0x5ea628 ExtractIconExW
 0x5ea62c ShellExecuteW
COMCTL32.dll
 0x5ea04c ImageList_Draw
 0x5ea050 ImageList_GetIconSize
 0x5ea054 None
 0x5ea058 None
 0x5ea05c None
 0x5ea060 None
 0x5ea064 ImageList_AddMasked
 0x5ea068 _TrackMouseEvent
 0x5ea06c ImageList_ReplaceIcon
 0x5ea070 InitCommonControlsEx
 0x5ea074 ImageList_GetIcon
 0x5ea078 ImageList_Destroy
 0x5ea07c ImageList_GetImageCount
 0x5ea080 ImageList_Add
 0x5ea084 ImageList_DrawEx
 0x5ea088 ImageList_GetImageInfo
SHLWAPI.dll
 0x5ea634 PathStripToRootW
 0x5ea638 PathIsUNCW
 0x5ea63c PathFindFileNameW
 0x5ea640 PathFindExtensionW
 0x5ea644 None
 0x5ea648 PathStripPathW
 0x5ea64c PathMatchSpecW
 0x5ea650 PathRemoveFileSpecW
 0x5ea654 PathAddBackslashW
 0x5ea658 StrFormatByteSizeW
 0x5ea65c PathIsDirectoryW
 0x5ea660 PathParseIconLocationW
 0x5ea664 PathFileExistsW
 0x5ea668 PathUnquoteSpacesW
 0x5ea66c PathRemoveArgsW
 0x5ea670 UrlUnescapeW
UxTheme.dll
 0x5ea9ec GetThemeColor
 0x5ea9f0 GetThemeInt
 0x5ea9f4 SetWindowTheme
 0x5ea9f8 BeginBufferedPaint
 0x5ea9fc EndBufferedPaint
 0x5eaa00 BufferedPaintSetAlpha
 0x5eaa04 GetThemePartSize
 0x5eaa08 IsThemeBackgroundPartiallyTransparent
 0x5eaa0c IsAppThemed
 0x5eaa10 DrawThemeParentBackground
 0x5eaa14 OpenThemeData
 0x5eaa18 CloseThemeData
 0x5eaa1c DrawThemeBackground
 0x5eaa20 GetThemeBackgroundContentRect
ole32.dll
 0x5eaaf0 CoFreeUnusedLibraries
 0x5eaaf4 OleInitialize
 0x5eaaf8 OleUninitialize
 0x5eaafc OleFlushClipboard
 0x5eab00 OleIsCurrentClipboard
 0x5eab04 StgCreateDocfileOnILockBytes
 0x5eab08 CoGetClassObject
 0x5eab0c CreateILockBytesOnHGlobal
 0x5eab10 StgOpenStorageOnILockBytes
 0x5eab14 CLSIDFromProgID
 0x5eab18 CLSIDFromString
 0x5eab1c CoDisconnectObject
 0x5eab20 CoInitialize
 0x5eab24 CoCreateGuid
 0x5eab28 CoTaskMemAlloc
 0x5eab2c PropVariantClear
 0x5eab30 CoTaskMemFree
 0x5eab34 CoCreateInstance
 0x5eab38 CoInitializeEx
 0x5eab3c CoUninitialize
 0x5eab40 CoRevokeClassObject
 0x5eab44 CoRegisterMessageFilter
OLEAUT32.dll
 0x5ea590 VariantInit
 0x5ea594 SafeArrayUnaccessData
 0x5ea598 SafeArrayAccessData
 0x5ea59c SafeArrayGetLBound
 0x5ea5a0 SafeArrayGetUBound
 0x5ea5a4 SafeArrayDestroy
 0x5ea5a8 SysFreeString
 0x5ea5ac SysAllocStringLen
 0x5ea5b0 SysAllocString
 0x5ea5b4 OleLoadPicturePath
 0x5ea5b8 SystemTimeToVariantTime
 0x5ea5bc VariantTimeToSystemTime
 0x5ea5c0 VariantChangeTypeEx
 0x5ea5c4 VarDateFromStr
 0x5ea5c8 VarBstrFromDate
 0x5ea5cc VarUdateFromDate
 0x5ea5d0 VariantClear
 0x5ea5d4 SysStringLen
 0x5ea5d8 SafeArrayGetDim
 0x5ea5dc SafeArrayGetElemsize
 0x5ea5e0 LoadTypeLib
 0x5ea5e4 VariantCopy
 0x5ea5e8 VariantChangeType
 0x5ea5ec SysAllocStringByteLen
 0x5ea5f0 SysStringByteLen
 0x5ea5f4 OleCreateFontIndirect
oledlg.dll
 0x5eab4c OleUIBusyW
 0x5eab50 OleUIAddVerbMenuW
VERSION.dll
 0x5eaa28 VerQueryValueW
 0x5eaa2c GetFileVersionInfoW
 0x5eaa30 GetFileVersionInfoSizeW
gdiplus.dll
 0x5eaa88 GdiplusShutdown
 0x5eaa8c GdipBitmapLockBits
 0x5eaa90 GdipCreateBitmapFromHICON
 0x5eaa94 GdipImageRotateFlip
 0x5eaa98 GdipGetImageHeight
 0x5eaa9c GdipGetImageWidth
 0x5eaaa0 GdipDisposeImage
 0x5eaaa4 GdiplusStartup
 0x5eaaa8 GdipCloneImage
 0x5eaaac GdipDrawRectangleI
 0x5eaab0 GdipDeleteGraphics
 0x5eaab4 GdipCreateFromHDC
 0x5eaab8 GdipSetPenDashStyle
 0x5eaabc GdipDeletePen
 0x5eaac0 GdipCreatePen1
 0x5eaac4 GdipAddPathArcI
 0x5eaac8 GdipClosePathFigure
 0x5eaacc GdipStartPathFigure
 0x5eaad0 GdipResetPath
 0x5eaad4 GdipDeletePath
 0x5eaad8 GdipCreatePath
 0x5eaadc GdipFree
 0x5eaae0 GdipAlloc
 0x5eaae4 GdipBitmapUnlockBits
 0x5eaae8 GdipDrawPath
WINMM.dll
 0x5eaa70 PlaySoundW
OLEACC.dll
 0x5ea584 LresultFromObject
 0x5ea588 CreateStdAccessibleObject
WININET.dll
 0x5eaa38 InternetSetStatusCallbackW
 0x5eaa3c InternetGetLastResponseInfoW
 0x5eaa40 InternetSetOptionW
 0x5eaa44 InternetQueryOptionW
 0x5eaa48 InternetQueryDataAvailable
 0x5eaa4c InternetWriteFile
 0x5eaa50 InternetSetFilePointer
 0x5eaa54 InternetReadFile
 0x5eaa58 InternetOpenUrlW
 0x5eaa5c InternetCloseHandle
 0x5eaa60 InternetOpenW
 0x5eaa64 InternetCanonicalizeUrlW
 0x5eaa68 InternetCrackUrlW

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure