Report - rWmzULI.exe

PhysicalDrive Generic Malware Malicious Library Admin Tool (Sysinternals etc ...) UPX Anti_VM PE32 PE File MZP Format OS Processor Check
ScreenShot
Created 2024.11.29 13:34 Machine s1_win7_x6403
Filename rWmzULI.exe
Type PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
AI Score Not founds Behavior Score
4.4
ZERO API file : clean
VT API (file) 4 detected (AIDetectMalware, malicious, moderate confidence, Stealerc)
md5 ef4b5e4dbb0c0cd9c261b1ca7a90e1f1
sha256 b84004b60d9ee0ef798bcc43f8344f06bc775198e04b707eb98f79d6260895f2
ssdeep 98304:XpaOTEikjpnQ1Ow/V0vkFVuvRHyqP4whhx7gqk:Xp9IVNR3wwhPO
imphash 841df9baf321574d4449d661fcc4a66a
impfuzzy 192:kDcLqbW/yHx166wIFupUQmnmDRFWGZEPk5APjHRz6DFFwNkLt1inLRwxcr:ScGuG6647DRFWGaP9Rz6D3w+Uwxo
  Network IP location

Signature (11cnts)

Level Description
watch Attempts to create or modify system certificates
watch Communicates with host for which no DNS query was performed
watch Network activity contains more than one unique useragent
notice Allocates read-write-execute memory (usually to unpack itself)
notice File has been identified by 4 AntiVirus engines on VirusTotal as malicious
notice HTTP traffic contains suspicious features which may be indicative of malware related traffic
notice Performs some HTTP requests
notice The binary likely contains encrypted or compressed data indicative of a packer
info Queries for the computername
info The executable contains unknown PE section names indicative of a packer (could be a false positive)
info The file contains an unknown PE resource name possibly indicative of a packer

Rules (10cnts)

Level Name Description Collection
warning Generic_Malware_Zero Generic Malware binaries (upload)
warning PhysicalDrive_20181001 (no description) binaries (upload)
watch Admin_Tool_IN_Zero Admin Tool Sysinternals binaries (upload)
watch Malicious_Library_Zero Malicious_Library binaries (upload)
watch UPX_Zero UPX packed file binaries (upload)
notice anti_vm_detect Possibly employs anti-virtualization techniques binaries (upload)
info IsPE32 (no description) binaries (upload)
info mzp_file_format MZP(Delphi) file format binaries (upload)
info OS_Processor_Check_Zero OS Processor Check binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (6cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
https://steamcommunity.com/profiles/76561199803837316 US Akamai International B.V. 104.76.74.15 clean
t.me GB Telegram Messenger Inc 149.154.167.99 mailcious
steamcommunity.com US Akamai International B.V. 104.76.74.15 mailcious
149.154.167.99 GB Telegram Messenger Inc 149.154.167.99 mailcious
104.76.74.15 US Akamai International B.V. 104.76.74.15 mailcious
95.217.24.53 FI Hetzner Online GmbH 95.217.24.53 clean

Suricata ids

PE API

IAT(Import Address Table) Library

mpr.dll
 0x86db34 WNetGetUniversalNameW
winmm.dll
 0x86db3c timeGetTime
shlwapi.dll
 0x86db44 SHCreateStreamOnFileW
winspool.drv
 0x86db4c DocumentPropertiesW
 0x86db50 ClosePrinter
 0x86db54 OpenPrinterW
 0x86db58 GetDefaultPrinterW
 0x86db5c EnumPrintersW
comctl32.dll
 0x86db64 ImageList_GetImageInfo
 0x86db68 FlatSB_SetScrollInfo
 0x86db6c InitCommonControls
 0x86db70 ImageList_DragMove
 0x86db74 ImageList_Destroy
 0x86db78 _TrackMouseEvent
 0x86db7c ImageList_DragShowNolock
 0x86db80 ImageList_Add
 0x86db84 FlatSB_SetScrollProp
 0x86db88 ImageList_GetDragImage
 0x86db8c ImageList_Create
 0x86db90 ImageList_EndDrag
 0x86db94 ImageList_DrawEx
 0x86db98 ImageList_SetImageCount
 0x86db9c FlatSB_GetScrollPos
 0x86dba0 FlatSB_SetScrollPos
 0x86dba4 InitializeFlatSB
 0x86dba8 ImageList_Copy
 0x86dbac FlatSB_GetScrollInfo
 0x86dbb0 ImageList_Write
 0x86dbb4 ImageList_DrawIndirect
 0x86dbb8 ImageList_SetBkColor
 0x86dbbc ImageList_GetBkColor
 0x86dbc0 ImageList_BeginDrag
 0x86dbc4 ImageList_GetIcon
 0x86dbc8 ImageList_Replace
 0x86dbcc ImageList_GetImageCount
 0x86dbd0 ImageList_DragEnter
 0x86dbd4 ImageList_GetIconSize
 0x86dbd8 ImageList_SetIconSize
 0x86dbdc ImageList_Read
 0x86dbe0 ImageList_DragLeave
 0x86dbe4 ImageList_LoadImageW
 0x86dbe8 ImageList_Draw
 0x86dbec ImageList_Remove
 0x86dbf0 ImageList_ReplaceIcon
 0x86dbf4 ImageList_SetOverlayImage
shell32.dll
 0x86dbfc Shell_NotifyIconW
 0x86dc00 ShellExecuteW
user32.dll
 0x86dc08 CopyImage
 0x86dc0c SetMenuItemInfoW
 0x86dc10 GetMenuItemInfoW
 0x86dc14 SetCaretPos
 0x86dc18 GetCaretPos
 0x86dc1c DefFrameProcW
 0x86dc20 ScrollWindowEx
 0x86dc24 GetDlgCtrlID
 0x86dc28 FrameRect
 0x86dc2c RegisterWindowMessageW
 0x86dc30 GetMenuStringW
 0x86dc34 FillRect
 0x86dc38 SendMessageA
 0x86dc3c IsClipboardFormatAvailable
 0x86dc40 EnumWindows
 0x86dc44 ShowOwnedPopups
 0x86dc48 GetClassInfoW
 0x86dc4c GetScrollRange
 0x86dc50 SetActiveWindow
 0x86dc54 GetActiveWindow
 0x86dc58 DrawEdge
 0x86dc5c GetKeyboardLayoutList
 0x86dc60 LoadBitmapW
 0x86dc64 EnumChildWindows
 0x86dc68 GetScrollBarInfo
 0x86dc6c UnhookWindowsHookEx
 0x86dc70 SetCapture
 0x86dc74 GetCapture
 0x86dc78 ShowCaret
 0x86dc7c CreatePopupMenu
 0x86dc80 GetMenuItemID
 0x86dc84 DestroyCaret
 0x86dc88 CharLowerBuffW
 0x86dc8c PostMessageW
 0x86dc90 SetWindowLongW
 0x86dc94 IsZoomed
 0x86dc98 SetParent
 0x86dc9c DrawMenuBar
 0x86dca0 GetClientRect
 0x86dca4 IsChild
 0x86dca8 IsIconic
 0x86dcac CallNextHookEx
 0x86dcb0 ShowWindow
 0x86dcb4 GetWindowTextW
 0x86dcb8 SetForegroundWindow
 0x86dcbc IsDialogMessageW
 0x86dcc0 DestroyWindow
 0x86dcc4 RegisterClassW
 0x86dcc8 EndMenu
 0x86dccc CharNextW
 0x86dcd0 GetFocus
 0x86dcd4 GetDC
 0x86dcd8 SetFocus
 0x86dcdc ReleaseDC
 0x86dce0 GetClassLongW
 0x86dce4 SetScrollRange
 0x86dce8 DrawTextW
 0x86dcec PeekMessageA
 0x86dcf0 MessageBeep
 0x86dcf4 SetClassLongW
 0x86dcf8 RemovePropW
 0x86dcfc GetSubMenu
 0x86dd00 DestroyIcon
 0x86dd04 IsWindowVisible
 0x86dd08 DispatchMessageA
 0x86dd0c UnregisterClassW
 0x86dd10 GetTopWindow
 0x86dd14 SendMessageW
 0x86dd18 GetMessageTime
 0x86dd1c LoadStringW
 0x86dd20 CreateMenu
 0x86dd24 CharLowerW
 0x86dd28 SetWindowRgn
 0x86dd2c SetWindowPos
 0x86dd30 GetMenuItemCount
 0x86dd34 GetSysColorBrush
 0x86dd38 GetWindowDC
 0x86dd3c DrawTextExW
 0x86dd40 EnumClipboardFormats
 0x86dd44 GetScrollInfo
 0x86dd48 SetWindowTextW
 0x86dd4c GetMessageExtraInfo
 0x86dd50 GetSysColor
 0x86dd54 EnableScrollBar
 0x86dd58 TrackPopupMenu
 0x86dd5c DrawIconEx
 0x86dd60 GetClassNameW
 0x86dd64 GetMessagePos
 0x86dd68 GetIconInfo
 0x86dd6c SetScrollInfo
 0x86dd70 GetKeyNameTextW
 0x86dd74 GetDesktopWindow
 0x86dd78 SetCursorPos
 0x86dd7c GetCursorPos
 0x86dd80 SetMenu
 0x86dd84 GetMenuState
 0x86dd88 GetMenu
 0x86dd8c SetRect
 0x86dd90 GetKeyState
 0x86dd94 ValidateRect
 0x86dd98 IsCharAlphaW
 0x86dd9c GetCursor
 0x86dda0 KillTimer
 0x86dda4 WaitMessage
 0x86dda8 TranslateMDISysAccel
 0x86ddac GetWindowPlacement
 0x86ddb0 CreateIconIndirect
 0x86ddb4 CreateWindowExW
 0x86ddb8 ChildWindowFromPoint
 0x86ddbc GetMessageW
 0x86ddc0 GetDCEx
 0x86ddc4 PeekMessageW
 0x86ddc8 MonitorFromWindow
 0x86ddcc SetTimer
 0x86ddd0 WindowFromPoint
 0x86ddd4 BeginPaint
 0x86ddd8 RegisterClipboardFormatW
 0x86dddc MapVirtualKeyW
 0x86dde0 OffsetRect
 0x86dde4 IsWindowUnicode
 0x86dde8 DispatchMessageW
 0x86ddec CreateAcceleratorTableW
 0x86ddf0 DefMDIChildProcW
 0x86ddf4 GetSystemMenu
 0x86ddf8 SetScrollPos
 0x86ddfc GetScrollPos
 0x86de00 DrawFocusRect
 0x86de04 ReleaseCapture
 0x86de08 LoadCursorW
 0x86de0c ScrollWindow
 0x86de10 GetLastActivePopup
 0x86de14 GetSystemMetrics
 0x86de18 CharUpperBuffW
 0x86de1c SetClipboardData
 0x86de20 GetClipboardData
 0x86de24 ClientToScreen
 0x86de28 SetWindowPlacement
 0x86de2c GetMonitorInfoW
 0x86de30 CheckMenuItem
 0x86de34 CharUpperW
 0x86de38 DefWindowProcW
 0x86de3c GetForegroundWindow
 0x86de40 EnableWindow
 0x86de44 GetWindowThreadProcessId
 0x86de48 RedrawWindow
 0x86de4c EndPaint
 0x86de50 MsgWaitForMultipleObjectsEx
 0x86de54 LoadKeyboardLayoutW
 0x86de58 ActivateKeyboardLayout
 0x86de5c GetParent
 0x86de60 CreateCaret
 0x86de64 MonitorFromRect
 0x86de68 InsertMenuItemW
 0x86de6c GetPropW
 0x86de70 MessageBoxW
 0x86de74 SetPropW
 0x86de78 UpdateWindow
 0x86de7c MsgWaitForMultipleObjects
 0x86de80 DestroyMenu
 0x86de84 SetWindowsHookExW
 0x86de88 GetDoubleClickTime
 0x86de8c EmptyClipboard
 0x86de90 AdjustWindowRectEx
 0x86de94 IsWindow
 0x86de98 DrawIcon
 0x86de9c EnumThreadWindows
 0x86dea0 InvalidateRect
 0x86dea4 SetKeyboardState
 0x86dea8 GetKeyboardState
 0x86deac ScreenToClient
 0x86deb0 DrawFrameControl
 0x86deb4 IsCharAlphaNumericW
 0x86deb8 SetCursor
 0x86debc CreateIcon
 0x86dec0 RemoveMenu
 0x86dec4 GetKeyboardLayoutNameW
 0x86dec8 OpenClipboard
 0x86decc TranslateMessage
 0x86ded0 MapWindowPoints
 0x86ded4 EnumDisplayMonitors
 0x86ded8 CallWindowProcW
 0x86dedc CountClipboardFormats
 0x86dee0 CloseClipboard
 0x86dee4 DestroyCursor
 0x86dee8 CopyIcon
 0x86deec PostQuitMessage
 0x86def0 ShowScrollBar
 0x86def4 EnableMenuItem
 0x86def8 HideCaret
 0x86defc FindWindowExW
 0x86df00 MonitorFromPoint
 0x86df04 LoadIconW
 0x86df08 SystemParametersInfoW
 0x86df0c GetWindow
 0x86df10 GetWindowRect
 0x86df14 GetWindowLongW
 0x86df18 InsertMenuW
 0x86df1c PostThreadMessageW
 0x86df20 IsWindowEnabled
 0x86df24 IsDialogMessageA
 0x86df28 FindWindowW
 0x86df2c GetKeyboardLayout
 0x86df30 DeleteMenu
version.dll
 0x86df38 GetFileVersionInfoSizeW
 0x86df3c VerQueryValueW
 0x86df40 GetFileVersionInfoW
oleaut32.dll
 0x86df48 SafeArrayPutElement
 0x86df4c LoadTypeLib
 0x86df50 VariantClear
 0x86df54 SysReAllocStringLen
 0x86df58 DispGetIDsOfNames
 0x86df5c CreateErrorInfo
 0x86df60 GetActiveObject
 0x86df64 SafeArrayGetLBound
 0x86df68 SafeArrayGetUBound
 0x86df6c VariantCopy
 0x86df70 SafeArrayAccessData
 0x86df74 SysFreeString
 0x86df78 VariantInit
 0x86df7c GetErrorInfo
 0x86df80 SetErrorInfo
 0x86df84 SafeArrayCreate
 0x86df88 SafeArrayGetElement
 0x86df8c SafeArrayUnaccessData
 0x86df90 SysAllocStringLen
 0x86df94 SafeArrayPtrOfIndex
 0x86df98 DispInvoke
 0x86df9c RegisterTypeLib
 0x86dfa0 VariantChangeType
 0x86dfa4 VariantCopyInd
msvcrt.dll
 0x86dfac memcpy
 0x86dfb0 memset
advapi32.dll
 0x86dfb8 CloseServiceHandle
 0x86dfbc RegSetValueExW
 0x86dfc0 RegSetValueExA
 0x86dfc4 ControlService
 0x86dfc8 RegConnectRegistryW
 0x86dfcc CreateServiceW
 0x86dfd0 StartServiceCtrlDispatcherW
 0x86dfd4 DeregisterEventSource
 0x86dfd8 RegQueryInfoKeyW
 0x86dfdc SetServiceStatus
 0x86dfe0 RegUnLoadKeyW
 0x86dfe4 RegSaveKeyW
 0x86dfe8 DeleteService
 0x86dfec StartServiceW
 0x86dff0 RegReplaceKeyW
 0x86dff4 RegisterEventSourceW
 0x86dff8 RegCreateKeyExW
 0x86dffc RegisterServiceCtrlHandlerW
 0x86e000 OpenServiceW
 0x86e004 RevertToSelf
 0x86e008 RegLoadKeyW
 0x86e00c RegEnumKeyExW
 0x86e010 QueryServiceStatus
 0x86e014 AdjustTokenPrivileges
 0x86e018 RegDeleteKeyW
 0x86e01c LookupPrivilegeValueW
 0x86e020 OpenSCManagerW
 0x86e024 RegOpenKeyExW
 0x86e028 OpenProcessToken
 0x86e02c RegDeleteValueW
 0x86e030 ReportEventW
 0x86e034 RegNotifyChangeKeyValue
 0x86e038 RegFlushKey
 0x86e03c RegQueryValueExW
 0x86e040 RegQueryValueExA
 0x86e044 RegEnumValueW
 0x86e048 RegCloseKey
 0x86e04c RegRestoreKeyW
netapi32.dll
 0x86e054 NetWkstaGetInfo
 0x86e058 NetApiBufferFree
kernel32.dll
 0x86e060 GetFileType
 0x86e064 QueryDosDeviceW
 0x86e068 Process32FirstW
 0x86e06c GetACP
 0x86e070 CloseHandle
 0x86e074 LocalFree
 0x86e078 GetCurrentProcessId
 0x86e07c SizeofResource
 0x86e080 VirtualProtect
 0x86e084 CreateSemaphoreW
 0x86e088 SetEnvironmentVariableW
 0x86e08c QueryPerformanceFrequency
 0x86e090 SetProcessWorkingSetSize
 0x86e094 IsDebuggerPresent
 0x86e098 FindNextFileW
 0x86e09c GetFullPathNameW
 0x86e0a0 VirtualFree
 0x86e0a4 HeapAlloc
 0x86e0a8 ExitProcess
 0x86e0ac GetCPInfoExW
 0x86e0b0 GlobalSize
 0x86e0b4 GetSystemTime
 0x86e0b8 RtlUnwind
 0x86e0bc GetCPInfo
 0x86e0c0 EnumSystemLocalesW
 0x86e0c4 CreateWaitableTimerW
 0x86e0c8 GetStdHandle
 0x86e0cc GetTimeZoneInformation
 0x86e0d0 FileTimeToLocalFileTime
 0x86e0d4 GetModuleHandleW
 0x86e0d8 FreeLibrary
 0x86e0dc TryEnterCriticalSection
 0x86e0e0 HeapDestroy
 0x86e0e4 FileTimeToDosDateTime
 0x86e0e8 ReadFile
 0x86e0ec GetUserDefaultLCID
 0x86e0f0 GetLastError
 0x86e0f4 GetModuleFileNameW
 0x86e0f8 SetLastError
 0x86e0fc GlobalAlloc
 0x86e100 GlobalUnlock
 0x86e104 FindResourceW
 0x86e108 OpenMutexW
 0x86e10c CreateThread
 0x86e110 CompareStringW
 0x86e114 MapViewOfFile
 0x86e118 CreateMutexW
 0x86e11c LoadLibraryA
 0x86e120 ResetEvent
 0x86e124 MulDiv
 0x86e128 FreeResource
 0x86e12c GetVersion
 0x86e130 RaiseException
 0x86e134 MoveFileW
 0x86e138 GlobalAddAtomW
 0x86e13c FormatMessageW
 0x86e140 OpenProcess
 0x86e144 SwitchToThread
 0x86e148 GetExitCodeThread
 0x86e14c GetCurrentThread
 0x86e150 ExpandEnvironmentStringsW
 0x86e154 LoadLibraryExW
 0x86e158 TerminateProcess
 0x86e15c LockResource
 0x86e160 GetShortPathNameW
 0x86e164 GetCurrentThreadId
 0x86e168 UnhandledExceptionFilter
 0x86e16c GlobalFindAtomW
 0x86e170 VirtualQuery
 0x86e174 GlobalFree
 0x86e178 VirtualQueryEx
 0x86e17c Sleep
 0x86e180 EnterCriticalSection
 0x86e184 SetFilePointer
 0x86e188 ReleaseMutex
 0x86e18c LoadResource
 0x86e190 SuspendThread
 0x86e194 GetTickCount
 0x86e198 WaitForMultipleObjects
 0x86e19c GetTempFileNameW
 0x86e1a0 GetFileSize
 0x86e1a4 GlobalDeleteAtom
 0x86e1a8 GetStartupInfoW
 0x86e1ac GetFileAttributesW
 0x86e1b0 InitializeCriticalSection
 0x86e1b4 GetThreadPriority
 0x86e1b8 GetCurrentProcess
 0x86e1bc GlobalLock
 0x86e1c0 SetThreadPriority
 0x86e1c4 VirtualAlloc
 0x86e1c8 GetTempPathW
 0x86e1cc GetCommandLineW
 0x86e1d0 GetSystemInfo
 0x86e1d4 DuplicateHandle
 0x86e1d8 LeaveCriticalSection
 0x86e1dc GetProcAddress
 0x86e1e0 ResumeThread
 0x86e1e4 SetWaitableTimer
 0x86e1e8 GetVersionExW
 0x86e1ec GetModuleHandleA
 0x86e1f0 VerifyVersionInfoW
 0x86e1f4 HeapCreate
 0x86e1f8 DeviceIoControl
 0x86e1fc GetDiskFreeSpaceW
 0x86e200 VerSetConditionMask
 0x86e204 FindFirstFileW
 0x86e208 GetUserDefaultUILanguage
 0x86e20c GetConsoleOutputCP
 0x86e210 UnmapViewOfFile
 0x86e214 GetConsoleCP
 0x86e218 GlobalHandle
 0x86e21c Process32NextW
 0x86e220 lstrlenW
 0x86e224 SetEndOfFile
 0x86e228 QueryPerformanceCounter
 0x86e22c lstrcmpW
 0x86e230 HeapFree
 0x86e234 WideCharToMultiByte
 0x86e238 FindClose
 0x86e23c MultiByteToWideChar
 0x86e240 CreateToolhelp32Snapshot
 0x86e244 LoadLibraryW
 0x86e248 SetEvent
 0x86e24c ReleaseSemaphore
 0x86e250 GetLocaleInfoW
 0x86e254 CreateFileW
 0x86e258 EnumResourceNamesW
 0x86e25c DeleteFileW
 0x86e260 IsDBCSLeadByteEx
 0x86e264 GetEnvironmentVariableW
 0x86e268 GetLocalTime
 0x86e26c WaitForSingleObject
 0x86e270 GetSystemPowerStatus
 0x86e274 Module32FirstW
 0x86e278 WriteFile
 0x86e27c CreateFileMappingW
 0x86e280 ExitThread
 0x86e284 DeleteCriticalSection
 0x86e288 GetDateFormatW
 0x86e28c TlsGetValue
 0x86e290 SetErrorMode
 0x86e294 GetComputerNameW
 0x86e298 PulseEvent
 0x86e29c IsValidLocale
 0x86e2a0 TlsSetValue
 0x86e2a4 CreateDirectoryW
 0x86e2a8 GetSystemDefaultUILanguage
 0x86e2ac EnumCalendarInfoW
 0x86e2b0 LocalAlloc
 0x86e2b4 RemoveDirectoryW
 0x86e2b8 SetConsoleCtrlHandler
 0x86e2bc CreateEventW
 0x86e2c0 WaitForMultipleObjectsEx
 0x86e2c4 GetThreadLocale
 0x86e2c8 SetThreadLocale
SHFolder.dll
 0x86e2d0 SHGetFolderPathW
ole32.dll
 0x86e2d8 OleRegEnumVerbs
 0x86e2dc StgCreateDocfile
 0x86e2e0 CoCreateGuid
 0x86e2e4 CoCreateInstance
 0x86e2e8 CLSIDFromString
 0x86e2ec IsEqualGUID
 0x86e2f0 CreateStreamOnHGlobal
 0x86e2f4 CLSIDFromProgID
 0x86e2f8 CoGetClassObject
 0x86e2fc CoInitialize
 0x86e300 OleDraw
 0x86e304 CoTaskMemAlloc
 0x86e308 StringFromCLSID
 0x86e30c CoMarshalInterThreadInterfaceInStream
 0x86e310 CoRevokeClassObject
 0x86e314 IsAccelerator
 0x86e318 CoGetInterfaceAndReleaseStream
 0x86e31c CoRegisterClassObject
 0x86e320 CoUninitialize
 0x86e324 StgOpenStorage
 0x86e328 CoLockObjectExternal
 0x86e32c OleInitialize
 0x86e330 ProgIDFromCLSID
 0x86e334 CoInitializeEx
 0x86e338 OleUninitialize
 0x86e33c CoDisconnectObject
 0x86e340 StgIsStorageFile
 0x86e344 CoImpersonateClient
 0x86e348 CoInitializeSecurity
 0x86e34c CoTaskMemFree
 0x86e350 OleSetMenuDescriptor
gdi32.dll
 0x86e358 Pie
 0x86e35c SetBkMode
 0x86e360 CreateCompatibleBitmap
 0x86e364 GetEnhMetaFileHeader
 0x86e368 CloseEnhMetaFile
 0x86e36c RectVisible
 0x86e370 AngleArc
 0x86e374 ResizePalette
 0x86e378 SetAbortProc
 0x86e37c SetTextColor
 0x86e380 StretchBlt
 0x86e384 RoundRect
 0x86e388 SelectClipRgn
 0x86e38c RestoreDC
 0x86e390 SetRectRgn
 0x86e394 GetTextMetricsW
 0x86e398 GetWindowOrgEx
 0x86e39c CreatePalette
 0x86e3a0 CreateDCW
 0x86e3a4 PolyBezierTo
 0x86e3a8 CreateICW
 0x86e3ac GetStockObject
 0x86e3b0 CreateSolidBrush
 0x86e3b4 Polygon
 0x86e3b8 MoveToEx
 0x86e3bc PlayEnhMetaFile
 0x86e3c0 Ellipse
 0x86e3c4 StartPage
 0x86e3c8 GetBitmapBits
 0x86e3cc StartDocW
 0x86e3d0 AbortDoc
 0x86e3d4 GetSystemPaletteEntries
 0x86e3d8 GetEnhMetaFileBits
 0x86e3dc GetEnhMetaFilePaletteEntries
 0x86e3e0 CreatePenIndirect
 0x86e3e4 SetMapMode
 0x86e3e8 CreateFontIndirectW
 0x86e3ec PolyBezier
 0x86e3f0 ExtCreatePen
 0x86e3f4 LPtoDP
 0x86e3f8 GetNearestColor
 0x86e3fc EndDoc
 0x86e400 GetObjectW
 0x86e404 GetCharWidthW
 0x86e408 GetWinMetaFileBits
 0x86e40c SetROP2
 0x86e410 GetOutlineTextMetricsW
 0x86e414 GetEnhMetaFileDescriptionW
 0x86e418 ArcTo
 0x86e41c CreateEnhMetaFileW
 0x86e420 Arc
 0x86e424 SelectPalette
 0x86e428 ExcludeClipRect
 0x86e42c MaskBlt
 0x86e430 SetWindowOrgEx
 0x86e434 EndPage
 0x86e438 DeleteEnhMetaFile
 0x86e43c Chord
 0x86e440 SetDIBits
 0x86e444 SetViewportOrgEx
 0x86e448 CreateRectRgn
 0x86e44c RealizePalette
 0x86e450 SetDIBColorTable
 0x86e454 GetDIBColorTable
 0x86e458 CreateBrushIndirect
 0x86e45c PatBlt
 0x86e460 SetEnhMetaFileBits
 0x86e464 Rectangle
 0x86e468 SaveDC
 0x86e46c DeleteDC
 0x86e470 BitBlt
 0x86e474 FrameRgn
 0x86e478 GetDeviceCaps
 0x86e47c GetTextExtentPoint32W
 0x86e480 GetClipBox
 0x86e484 IntersectClipRect
 0x86e488 Polyline
 0x86e48c CreateBitmap
 0x86e490 SetWinMetaFileBits
 0x86e494 GetStretchBltMode
 0x86e498 CreateDIBitmap
 0x86e49c CreateDIBSection
 0x86e4a0 SetStretchBltMode
 0x86e4a4 GetDIBits
 0x86e4a8 LineTo
 0x86e4ac GetRgnBox
 0x86e4b0 EnumFontsW
 0x86e4b4 SetWindowExtEx
 0x86e4b8 CreateHalftonePalette
 0x86e4bc SelectObject
 0x86e4c0 DeleteObject
 0x86e4c4 ExtFloodFill
 0x86e4c8 UnrealizeObject
 0x86e4cc CopyEnhMetaFileW
 0x86e4d0 SetBkColor
 0x86e4d4 CreateCompatibleDC
 0x86e4d8 GetBrushOrgEx
 0x86e4dc GetCurrentPositionEx
 0x86e4e0 GetNearestPaletteIndex
 0x86e4e4 GetTextExtentPointW
 0x86e4e8 ExtTextOutW
 0x86e4ec SetBrushOrgEx
 0x86e4f0 GetPixel
 0x86e4f4 GdiFlush
 0x86e4f8 SetViewportExtEx
 0x86e4fc SetPixel
 0x86e500 PolyPolyline
 0x86e504 EnumFontFamiliesExW
 0x86e508 StretchDIBits
 0x86e50c GetPaletteEntries

EAT(Export Address Table) Library

0x4e2d50 TMethodImplementationIntercept
0x412e50 __dbk_fcall_wrapper
0x86763c dbkFCallWrapperAddr


Similarity measure (PE file only) - Checking for service failure