PESCAN.IO - Analysis Report Basic

File Structure
Analysis Image
PE Chart Code
Header PE (light blue)
Executable sections (pink)
Non-executable sections (black)
External injected code (red)
File Structure in red = malformed or corrupted header

Chart Code For Other Files
Printable characters (blue)
Non-printable characters (black)
Information
Size: 3,68 MB
SHA-256 Hash: D5D5274CACFF7B59F34B059DC716CB0EE6DDB1370BB9010F9A55CECF4DC2958E
SHA-1 Hash: BA2999B3191921DAA8F1BDDD5F0A9329C00971F9
MD5 Hash: 1E99F4E0623F68E72054DD7AC02D6ABB
Imphash: BDDE57058B98B702790F254A48122E95
MajorOSVersion: 10
MinorOSVersion: 0
CheckSum: 003B18C5
EntryPoint (rva): 133AB0
SizeOfHeaders: 400
SizeOfImage: 3D4000
ImageBase: 0000000140000000
Architecture: x64
ExportTable: 359630
ImportTable: 35968C
IAT: 359F30
Characteristics: 22
TimeDateStamp: 6A6C5ECB
Date: 31/07/2026 8:37:31
File Type: EXE
File Type: DLL
Number Of Sections: 11
ASLR: Disabled
Section Names (Optional Header): .text, .rdata, .data, .pdata, .fptable, .tls, LZMADEC, _RDATA, malloc_h, .rsrc, .reloc
Number Of Executable Sections: 3
Subsystem: Windows GUI
UAC Execution Level Manifest: asInvoker

Sections Info
Section Name Flags ROffset RSize VOffset VSizeEntropyChi2
.text
0x60000020
Code
Executable
Readable
400 2F7E00 1000 2F7C57
6.6057
17418380.18
.rdata
0x40000040
Initialized Data
Readable
2F8200 78A00 2F9000 78898
5.6771
14312465.56
.data
0xC0000040
Initialized Data
Readable
Writeable
370C00 11E00 372000 332E0
2.3951
8682515.46
.pdata
0x40000040
Initialized Data
Readable
382A00 21400 3A6000 21234
6.2922
2401888.6
.fptable
0xC0000040
Initialized Data
Readable
Writeable
3A3E00 200 3C8000 100
0
130560
.tls
0xC0000040
Initialized Data
Readable
Writeable
3A4000 400 3C9000 2E1
0.2544
246551.5
LZMADEC
0x60000020
Code
Executable
Readable
3A4400 1200 3CA000 11F1
6.062
27100.56
_RDATA
0x40000040
Initialized Data
Readable
3A5600 200 3CC000 1F4
4.2125
20068
malloc_h
0x60000020
Code
Executable
Readable
3A5800 200 3CD000 DB
3.4019
43227
.rsrc
0x40000040
Initialized Data
Readable
3A5A00 2000 3CE000 1FB8
4.7445
309007.06
.reloc
0x42000040
Initialized Data
GP-Relative
Readable
3A7A00 3600 3D0000 3484
5.4116
82703.67
Description
OriginalFilename: elevation_service.exe
CompanyName: Microsoft Corporation
LegalCopyright: Copyright Microsoft Corporation. All rights reserved.
ProductName: Microsoft Edge
FileVersion: 151.0.4129.59
FileDescription: Microsoft Edge
ProductVersion: 151.0.4129.59
Language: English (United States) (ID=0x409)
CodePage: Unicode (UTF-16 LE) (0x4B0)

Entry Point
The section number (1) have the Entry Point
Information -> EntryPoint (calculated) - 132EB0
Code -> 4883EC28E80B0000004883C428E97AFEFFFFCCCC48895C241855488BEC4883EC30488B0568E5230048BB32A2DF2D992B0000
Assembler
|SUB RSP, 0X28
|CALL 0X140133AC4
|ADD RSP, 0X28
|JMP 0X14013393C
|INT3
|INT3
|MOV QWORD PTR [RSP + 0X18], RBX
|PUSH RBP
|MOV RBP, RSP
|SUB RSP, 0X30
|MOV RAX, QWORD PTR [RIP + 0X23E568]
|MOVABS RBX, 0X2B992DDFA232
Signatures
Certificate - Digital Signature:
• The file is signed and the signature is correct

Packer/Compiler
Compiler: Microsoft Visual Studio
Compiler: Pure Basic 4.x
Detect It Easy (die)
PE+(64): compiler: Microsoft Visual C/C++(2015 v.14.0)[-]
PE+(64): linker: Microsoft Linker(14.0)[-]
PE+(64): Sign tool: Windows Authenticode(2.0)[PKCS 7]
Entropy: 6.61318

Suspicious Functions
Library Function Description
KERNEL32.DLL VirtualAlloc Reserve, commit, or both, a region of memory within the virtual address space of a process.
KERNEL32.DLL GetModuleHandleA Retrieves a handle to the specified module.
KERNEL32.DLL WriteFile Writes data to a specified file or input/output (I/O) device.
KERNEL32.DLL LoadLibraryW Loads the specified module into the address space of the calling process.
KERNEL32.DLL GetProcAddress Retrieves the address of an exported function or variable from the specified dynamic-link library (DLL).
KERNEL32.DLL CreateFileA Creates or opens a file or I/O device.
KERNEL32.DLL IsDebuggerPresent Determines if the calling process is being debugged by a user-mode debugger.
KERNEL32.DLL SleepEx Pauses the execution of the current thread, optionally allowing the thread to be awakened by a kernel object or upon expiration of a timeout.
ADVAPI32.DLL CryptEncrypt Performs a cryptographic operation on data in a data block.
ADVAPI32.DLL CryptDecrypt Performs a cryptographic operation on data in a data block.
SHELL32.DLL ShellExecuteExW Performs a run operation on a specific file.
Windows REG (UNICODE)
SOFTWARE\Microsoft\Windows NT\CurrentVersion
Software\Microsoft\Windows\CurrentVersion\Uninstall
Software\Microsoft\EdgeUpdate\Clients\
Software\Microsoft\EdgeUpdate\ClientState\
SOFTWARE\Classes
SOFTWARE\Microsoft\Shared Tools\MSInfo
Software\Microsoft\EdgeUpdate

File Access
elevation_service.exe
api-ms-win-core-synch-l1-2-0.dll
api-ms-win-core-winrt-l1-1-0.dll
api-ms-win-core-winrt-string-l1-1-0.dll
WTSAPI32.dll
ntdll.dll
ncrypt.dll
RPCRT4.dll
CRYPT32.dll
KERNEL32.dll
OLEAUT32.dll
dbghelp.dll
USERENV.dll
ole32.dll
WINMM.dll
USER32.dll
SHLWAPI.dll
SHELL32.dll
ADVAPI32.dll
user32.dll
viz,input.scr
renderer,benchmark,rail,input.scr
input,input.scr
cc,benchmark,input,input.scr
benchmark,latencyInfo,rail,input.scr
disabled-by-default-devtools.scr
input.scr
.dat
PERFETTO_CHECK(blob.dat
@.dat
Temp

File Access (UNICODE)
msedge.exe
mscopilot.exe
copilotapp.exe
elevation_service.exe
msedgewebview2.exe
copilot_app_browser_tests.exe
copilotapphost.exe
setup.exe
msedgerecovery.exe
.exe
+ (FormatMessageW() returned invalid UTF-16)NTDLL.DLL
\usp10.dll
api-ms-win-downlevel-shell32-l1-1-0.dll
api-ms-win-downlevel-shlwapi-l1-1-0.dll
onecore.dll
bcryptprimitives.dll
Kernel32.dll
user32.dll
api-ms-win-core-wow64-l1-1-1.dll
ntdll.dll
kernel32.dll
dbghelp.dll
mscoree.dll
FKERNEL32.DLL
*.msi
vmoduledebug.log
Temp
ProgramFiles

Interest's Words
Encrypt
Decrypt
Encryption
PassWord
exec
attrib
start
cipher
hostname
sdelete
shutdown
systeminfo
ping
expand
replace
route

Interest's Words (UNICODE)
exec

Anti-VM/Sandbox/Debug Tricks
OllyDbg Libary - dbghelp.dll

Anti-VM/Sandbox/Debug Tricks (UNICODE)
OllyDbg Libary - dbghelp.dll

URLs
http://schemas.microsoft.com/SMI/2020/WindowsSettings
http://www.microsoft.com/pkiops/crl/Microsoft%20Code%20Signing%20PCA%202024.crl
http://www.microsoft.com/pkiops/certs/Microsoft%20Code%20Signing%20PCA%202024.crt
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
http://www.microsoft.com/pki/certs/MicRooCerAut2011_2011_03_22.crt
http://www.microsoft.com/pkiops/crl/Microsoft%20Time-Stamp%20PCA%202010(1).crl
http://www.microsoft.com/pkiops/certs/Microsoft%20Time-Stamp%20PCA%202010(1).crt
http://www.microsoft.com/pkiops/Docs/Repository.htm
http://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl
http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt
https://perfetto.dev/docs/contributing/getting-startedcommunity).
https://www.microsoft.com

Emails
appro@openssl.org

Strings/Hex Code Found With The File Rules
Rule Type Encoding Matched (Word)
Text Ascii Unicode escape - \u00 - (Common Unicode escape sequences)
Text Ascii WinAPI Sockets (bind)
Text Ascii WinAPI Sockets (connect)
Text Ascii WinAPI Sockets (send)
Text Ascii Registry (RegCreateKeyEx)
Text Ascii Registry (RegOpenKeyEx)
Text Ascii Registry (RegSetValueEx)
Text Ascii Registry (RegDeleteKeyEx)
Text Ascii File (GetTempPath)
Text Ascii File (CreateFile)
Text Ascii File (WriteFile)
Text Ascii File (ReadFile)
Text Ascii Service (OpenSCManager)
Text Ascii Service (StartServiceCtrlDispatcher)
Text Ascii Encryption (Base64Encode)
Text Ascii Encryption API (CryptDecrypt)
Text Ascii Anti-Analysis VM (IsDebuggerPresent)
Text Ascii Anti-Analysis VM (GetSystemInfo)
Text Ascii Anti-Analysis VM (GlobalMemoryStatusEx)
Text Ascii Anti-Analysis VM (GetVersion)
Text Ascii Reconnaissance (FindFirstFileW)
Text Ascii Reconnaissance (FindNextFileW)
Text Ascii Reconnaissance (FindClose)
Text Ascii Stealth (GetThreadContext)
Text Ascii Stealth (CloseHandle)
Text Ascii Stealth (UnmapViewOfFile)
Text Ascii Stealth (MapViewOfFile)
Text Ascii Stealth (CreateFileMappingW)
Text Ascii Stealth (VirtualAlloc)
Text Ascii Stealth (VirtualProtect)
Text Ascii Execution (CreateProcessA)
Text Ascii Execution (CreateProcessW)
Text Ascii Execution (ShellExecute)
Text Ascii Execution (ResumeThread)
Text Ascii Execution (CreateEventW)
Text Ascii Privileges (SeTcbPrivilege)
Text Unicode Privileges (SeTcbPrivilege)
Text Ascii Malware that monitors and collects user data (Spy)
Text Ascii Information used for user authentication (Credential)
Text Ascii Unauthorized movement of funds or data (Transfer)
Text Ascii Technique used to capture communications between systems (Intercept)
Text Ascii Abuse of power for personal gain or unethical purposes (Corruption)
Entry Point Hex Pattern Microsoft Visual C++ 8.0 (DLL)
Resources
Path DataRVA Size FileOffset CodeText
\TYPELIB\1\1033 3CE100 15B8 3A5B00 4D534654020001000000000009040000000000004300000001000000000000000E0000000000000000000000000000002D00MSFT................C...........................-.
\VERSION\1\1033 3CF6B8 464 3A70B8 640434000000560053005F00560045005200530049004F004E005F0049004E0046004F0000000000BD04EFFE000001000000d.4...V.S._.V.E.R.S.I.O.N._.I.N.F.O...............
\24\1\1033 3CFB20 497 3A7520 3C3F786D6C2076657273696F6E3D22312E302220656E636F64696E673D225554462D38223F3E0A3C617373656D626C792078<?xml version="1.0" encoding="UTF-8"?>.<assembly x
Intelligent String
• copilotapp.exe
• user32.dll
• dbghelp.dll
• Kernel32.dll
• mscopilot.exe
• msedge.exe
• .tls
• FKERNEL32.DLL
• mscoree.dll
• Failed to authenticate caller process: .exe
• recovery-component-inner.crx
• msedgerecovery.exe
• Interceptors are experimental. If you want to use them, please get in touch with the project maintainers (https://perfetto.dev/docs/contributing/getting-startedcommunity).
• setup.exe
• copilotapphost.exe
• ://ISOLATION
• kernel32.dll
• ntdll.dll
• leveldbloadingloglogin
• disabled-by-default-cc.debug.scheduler.now
• disabled-by-default-gpu.servicedisabled-by-default-gpu.vulkan.vma
• disabled-by-default-skia.gpu
• disabled-by-default-toplevel.ipc
• gpu,login
• login,screenlock_monitor
• api-ms-win-core-wow64-l1-1-1.dll
• bcryptprimitives.dll
• runas
• api-ms-win-downlevel-shlwapi-l1-1-0.dll
• DumpWithoutCrashing
• DialogInView
• vmoduledebug.log
• \u003C
• copilot_app_browser_tests.exe
• Microsoft.DumpWithoutCrashingStatus
• DumpWithoutCrashing-file
• DumpWithoutCrashing-line
• api-ms-win-downlevel-shell32-l1-1-0.dll
• Logging-FATAL_MILESTONELogging-DUMP_WILL_BE_CHECK_MESSAGE
• ..\..\third_party\boringssl\src\crypto\fipsmodule\bn\add.cc.inc..\..\third_party\boringssl\src\crypto\fipsmodule\bn\bn.cc.inc
• ..\..\third_party\boringssl\src\crypto\fipsmodule\bn\ctx.cc.inc..\..\third_party\boringssl\src\crypto\fipsmodule\bn\div.cc.inc..\..\third_party\boringssl\src\crypto\fipsmodule\bn\exponentiation.cc.inc
• ..\..\third_party\boringssl\src\crypto\fipsmodule\bn\gcd_extra.cc.inc
• ..\..\third_party\boringssl\src\crypto\fipsmodule\bn\jacobi.cc.inc
• ..\..\third_party\boringssl\src\crypto\fipsmodule\bn\montgomery.cc.inc
• ..\..\third_party\boringssl\src\crypto\fipsmodule\bn\mul.cc.inc..\..\third_party\boringssl\src\crypto\fipsmodule\bn\prime.cc.inc
• ..\..\third_party\boringssl\src\crypto\fipsmodule\bn\random.cc.inc
• ..\..\third_party\boringssl\src\crypto\fipsmodule\bn\shift.cc.inc
• ..\..\third_party\boringssl\src\crypto\fipsmodule\bn\sqrt.cc.inc
• ..\..\third_party\boringssl\src\crypto\fipsmodule\cipher\aead.cc.inc
• ..\..\third_party\boringssl\src\crypto\fipsmodule\digest\digest.cc.inc
• ..\..\third_party\boringssl\src\crypto\fipsmodule\digestsign\digestsign.cc.inc
• ..\..\third_party\boringssl\src\crypto\fipsmodule\ec\ec.cc.inc
• ..\..\third_party\boringssl\src\crypto\fipsmodule\ec\ec_key.cc.inc
• ..\..\third_party\boringssl\src\crypto\fipsmodule\ec\felem.cc.inc
• ..\..\third_party\boringssl\src\crypto\fipsmodule\ec\oct.cc.inc..\..\third_party\boringssl\src\crypto\fipsmodule\ec\scalar.cc.inc
• ..\..\third_party\boringssl\src\crypto\fipsmodule\ecdsa\ecdsa.cc.inc
• ..\..\third_party\boringssl\src\crypto\fipsmodule\rsa\padding.cc.inc
• ..\..\third_party\boringssl\src\crypto\fipsmodule\rsa\rsa.cc.inc
• ..\..\third_party\boringssl\src\crypto\fipsmodule\rsa\rsa_impl.cc.inc
• ..\..\third_party\boringssl\src\crypto\fipsmodule\cipher\e_aes.cc.inc
• ..\..\third_party\boringssl\src\crypto\fipsmodule\ec\ec_montgomery.cc.inc
• ..\..\third_party\boringssl\src\crypto\fipsmodule\ec\p256.cc.inc
• app-run-on-os-login-mode
• msedgewebview2.exe
• \usp10.dll
• .dat
• elevation_service.exe.pdb
• .bss
• elevation_service.exe

Flow Anomalies
Offset FlowVA Section Description
DF4 N/A .text CALL QWORD PTR [RIP+0x358A1E]
4093 N/A .text CALL QWORD PTR [RIP+0x35577F]
5205 N/A .text CALL QWORD PTR [RIP+0x35460D]
626D N/A .text CALL QWORD PTR [RIP+0x3535A5]
8825 N/A .text CALL QWORD PTR [RIP+0x350FED]
BD9B N/A .text CALL QWORD PTR [RIP+0x34DA77]
10960 N/A .text CALL QWORD PTR [RIP+0x348EB2]
128EA N/A .text CALL QWORD PTR [RIP+0x346F28]
167B2 N/A .text CALL QWORD PTR [RIP+0x343060]
1BAAA N/A .text CALL QWORD PTR [RIP+0x33DD68]
264D4 N/A .text CALL QWORD PTR [RIP+0x3332AE]
2657B N/A .text CALL QWORD PTR [RIP+0x332FE7]
26594 N/A .text CALL QWORD PTR [RIP+0x332FCE]
265E7 N/A .text CALL QWORD PTR [RIP+0x332F7B]
2663C N/A .text CALL QWORD PTR [RIP+0x333146]
272E8 N/A .text CALL QWORD PTR [RIP+0x35BB4A]
27492 N/A .text CALL QWORD PTR [RIP+0x3320D0]
27543 N/A .text CALL QWORD PTR [RIP+0x33200F]
27570 N/A .text CALL QWORD PTR [RIP+0x331FF2]
2775B N/A .text CALL QWORD PTR [RIP+0x331E07]
27784 N/A .text CALL QWORD PTR [RIP+0x331DDE]
2792A N/A .text CALL QWORD PTR [RIP+0x331C38]
27CE1 N/A .text CALL QWORD PTR [RIP+0x331809]
27D81 N/A .text CALL QWORD PTR [RIP+0x331761]
27DA1 N/A .text CALL QWORD PTR [RIP+0x331671]
27DBA N/A .text CALL QWORD PTR [RIP+0x3317A8]
27DE2 N/A .text CALL QWORD PTR [RIP+0x331780]
27F11 N/A .text CALL QWORD PTR [RIP+0x35B209]
2818A N/A .text CALL QWORD PTR [RIP+0x3313D8]
288FB N/A .text CALL QWORD PTR [RIP+0x330BEF]
28FA9 N/A .text CALL QWORD PTR [RIP+0x330541]
29253 N/A .text CALL QWORD PTR [RIP+0x330297]
2938D N/A .text CALL QWORD PTR [RIP+0x3305C5]
293B6 N/A .text CALL QWORD PTR [RIP+0x33016C]
293C0 N/A .text CALL QWORD PTR [RIP+0x3301A2]
294DC N/A .text CALL QWORD PTR [RIP+0x32FE9E]
29901 N/A .text CALL QWORD PTR [RIP+0x32FC61]
2991E N/A .text CALL QWORD PTR [RIP+0x32FE24]
2997B N/A .text CALL QWORD PTR [RIP+0x32F9F7]
299A2 N/A .text CALL QWORD PTR [RIP+0x32FDA0]
29BD7 N/A .text CALL QWORD PTR [RIP+0x32F98B]
29EFE N/A .text CALL QWORD PTR [RIP+0x32F47C]
2A0AE N/A .text CALL QWORD PTR [RIP+0x32F4B4]
2A0CC N/A .text CALL QWORD PTR [RIP+0x32F496]
2A127 N/A .text CALL QWORD PTR [RIP+0x32F61B]
2A2A3 N/A .text CALL QWORD PTR [RIP+0x32F49F]
2A2D5 N/A .text CALL QWORD PTR [RIP+0x32F09D]
2A312 N/A .text CALL QWORD PTR [RIP+0x32F250]
2A31E N/A .text CALL QWORD PTR [RIP+0x32F244]
2A92A N/A .text CALL QWORD PTR [RIP+0x32EC38]
2AB4E N/A .text CALL QWORD PTR [RIP+0x32EA14]
2AB5D N/A .text CALL QWORD PTR [RIP+0x32ED6D]
2AB65 N/A .text CALL QWORD PTR [RIP+0x32ED05]
2B40F N/A .text CALL QWORD PTR [RIP+0x3579E3]
2B465 N/A .text CALL QWORD PTR [RIP+0x32E375]
2B495 N/A .text CALL QWORD PTR [RIP+0x32E04D]
2B4B9 N/A .text CALL QWORD PTR [RIP+0x32DF59]
2B6F7 N/A .text CALL QWORD PTR [RIP+0x32E08B]
2BC3E N/A .text CALL QWORD PTR [RIP+0x32DB44]
2E2BE N/A .text CALL QWORD PTR [RIP+0x354CDC]
2E2C7 N/A .text CALL QWORD PTR [RIP+0x32B0DB]
2E92E N/A .text CALL QWORD PTR [RIP+0x35466C]
2E937 N/A .text CALL QWORD PTR [RIP+0x32AA6B]
2ECFA N/A .text CALL QWORD PTR [RIP+0x32A7F8]
2ED11 N/A .text CALL QWORD PTR [RIP+0x3541E1]
2ED1A N/A .text CALL QWORD PTR [RIP+0x354240]
2ED3F N/A .text CALL QWORD PTR [RIP+0x32A663]
2ED92 N/A .text CALL QWORD PTR [RIP+0x328D70]
2F7CB N/A .text CALL QWORD PTR [RIP+0x3537CF]
2F7D4 N/A .text CALL QWORD PTR [RIP+0x329BCE]
2F81A N/A .text CALL QWORD PTR [RIP+0x353780]
2F823 N/A .text CALL QWORD PTR [RIP+0x329B7F]
3017C N/A .text CALL QWORD PTR [RIP+0x352E1E]
30185 N/A .text CALL QWORD PTR [RIP+0x32921D]
306F6 N/A .text CALL QWORD PTR [RIP+0x352724]
3073A N/A .text CALL QWORD PTR [RIP+0x3526E8]
307C5 N/A .text CALL QWORD PTR [RIP+0x32733D]
307EB N/A .text JMP QWORD PTR [RIP+0x35263F]
30892 N/A .text CALL QWORD PTR [RIP+0x329060]
3094C N/A .text CALL QWORD PTR [RIP+0x328E6E]
30C9D N/A .text CALL QWORD PTR [RIP+0x328B1D]
318B5 N/A .text CALL QWORD PTR [RIP+0x351865]
31D8C N/A .text CALL QWORD PTR [RIP+0x32775E]
322A9 N/A .text CALL QWORD PTR [RIP+0x325859]
322CB N/A .text CALL QWORD PTR [RIP+0x325837]
32305 N/A .text CALL QWORD PTR [RIP+0x3257FD]
3231E N/A .text CALL QWORD PTR [RIP+0x3257E4]
323B9 N/A .text CALL QWORD PTR [RIP+0x325749]
32667 N/A .text CALL QWORD PTR [RIP+0x32549B]
326D3 N/A .text CALL QWORD PTR [RIP+0x32542F]
326F5 N/A .text CALL QWORD PTR [RIP+0x32540D]
3274F N/A .text CALL QWORD PTR [RIP+0x3253B3]
327A7 N/A .text CALL QWORD PTR [RIP+0x32535B]
327B9 N/A .text CALL QWORD PTR [RIP+0x325349]
32880 N/A .text CALL QWORD PTR [RIP+0x325282]
3297E N/A .text CALL QWORD PTR [RIP+0x325184]
32999 N/A .text CALL QWORD PTR [RIP+0x325169]
331DE N/A .text CALL QWORD PTR [RIP+0x324924]
331F0 N/A .text CALL QWORD PTR [RIP+0x324912]
33876 N/A .text JMP QWORD PTR [RIP+0x32428C]
E11-E3F N/A .text Unusual BP Cave, count: 47
18E1-18FF N/A .text Unusual NOPS Space, count: 31
5222-523F N/A .text Unusual BP Cave, count: 30
628A-62BF N/A .text Unusual BP Cave, count: 54
74D1-74FF N/A .text Unusual NOPS Space, count: 47
8842-887F N/A .text Unusual BP Cave, count: 62
9DD1-9DFF N/A .text Unusual NOPS Space, count: 47
AD22-AD3F N/A .text Unusual NOPS Space, count: 30
BE15-BE3F N/A .text Unusual BP Cave, count: 43
115D4-115FF N/A .text Unusual NOPS Space, count: 44
12907-1293F N/A .text Unusual BP Cave, count: 57
13782-1379F N/A .text Unusual NOPS Space, count: 30
13CA0-13CBF N/A .text Unusual BP Cave, count: 32
14111-1413F N/A .text Unusual BP Cave, count: 47
167CF-167FF N/A .text Unusual BP Cave, count: 49
176E1-176FF N/A .text Unusual NOPS Space, count: 31
1BDDC-1BDFF N/A .text Unusual NOPS Space, count: 36
22E0C-22E3F N/A .text Unusual NOPS Space, count: 52
2F8057-2F81FF N/A .text Unusual BP Cave, count: 425
2F860C-2F863F N/A .rdata Unusual NOPS Space, count: 52
2F91C8-2F91FF N/A .rdata Unusual NOPS Space, count: 56
2F9290-2F92BF N/A .rdata Unusual NOPS Space, count: 48
3A58DB-3A59FF N/A malloc_h Unusual BP Cave, count: 293
3579F8 1400D19A0 .rdata TLS Callback | Pointer to D19A0 - 0xD0DA0 .text
357A00 140132CC0 .rdata TLS Callback | Pointer to 132CC0 - 0x1320C0 .text
357A08 1400F9540 .rdata TLS Callback | Pointer to F9540 - 0xF8940 .text
357A10 140132D40 .rdata TLS Callback | Pointer to 132D40 - 0x132140 .text
357A18 1400ABFE0 .rdata TLS Callback | Pointer to ABFE0 - 0xAB3E0 .text
357A20 1400F4FC0 .rdata TLS Callback | Pointer to F4FC0 - 0xF43C0 .text
382A00 14000100D .pdata ExceptionHook | Pointer to 100D - 0x40D .text + UnwindInfo: .rdata
382A0C 140001A4D .pdata ExceptionHook | Pointer to 1A4D - 0xE4D .text + UnwindInfo: .rdata
382A18 1400020AD .pdata ExceptionHook | Pointer to 20AD - 0x14AD .text + UnwindInfo: .rdata
382A24 1400029AD .pdata ExceptionHook | Pointer to 29AD - 0x1DAD .text + UnwindInfo: .rdata
382A30 14000348D .pdata ExceptionHook | Pointer to 348D - 0x288D .text + UnwindInfo: .rdata
382A3C 140003D6D .pdata ExceptionHook | Pointer to 3D6D - 0x316D .text + UnwindInfo: .rdata
382A48 140004900 .pdata ExceptionHook | Pointer to 4900 - 0x3D00 .text + UnwindInfo: .rdata
382A54 140004CCD .pdata ExceptionHook | Pointer to 4CCD - 0x40CD .text + UnwindInfo: .rdata
382A60 140004F5D .pdata ExceptionHook | Pointer to 4F5D - 0x435D .text + UnwindInfo: .rdata
382A6C 1400054CD .pdata ExceptionHook | Pointer to 54CD - 0x48CD .text + UnwindInfo: .rdata
382A78 14000570D .pdata ExceptionHook | Pointer to 570D - 0x4B0D .text + UnwindInfo: .rdata
382A84 14000674D .pdata ExceptionHook | Pointer to 674D - 0x5B4D .text + UnwindInfo: .rdata
382A90 14000682D .pdata ExceptionHook | Pointer to 682D - 0x5C2D .text + UnwindInfo: .rdata
382A9C 14000691D .pdata ExceptionHook | Pointer to 691D - 0x5D1D .text + UnwindInfo: .rdata
382AA8 1400069ED .pdata ExceptionHook | Pointer to 69ED - 0x5DED .text + UnwindInfo: .rdata
382AB4 140006ABD .pdata ExceptionHook | Pointer to 6ABD - 0x5EBD .text + UnwindInfo: .rdata
382AC0 140006BFD .pdata ExceptionHook | Pointer to 6BFD - 0x5FFD .text + UnwindInfo: .rdata
382ACC 140006ECD .pdata ExceptionHook | Pointer to 6ECD - 0x62CD .text + UnwindInfo: .rdata
382AD8 14000810D .pdata ExceptionHook | Pointer to 810D - 0x750D .text + UnwindInfo: .rdata
382AE4 14000948D .pdata ExceptionHook | Pointer to 948D - 0x888D .text + UnwindInfo: .rdata
382AF0 14000A64D .pdata ExceptionHook | Pointer to A64D - 0x9A4D .text + UnwindInfo: .rdata
382AFC 14000AA0D .pdata ExceptionHook | Pointer to AA0D - 0x9E0D .text + UnwindInfo: .rdata
382B08 14000B94D .pdata ExceptionHook | Pointer to B94D - 0xAD4D .text + UnwindInfo: .rdata
382B14 14000CA4D .pdata ExceptionHook | Pointer to CA4D - 0xBE4D .text + UnwindInfo: .rdata
382B20 14000DA8D .pdata ExceptionHook | Pointer to DA8D - 0xCE8D .text + UnwindInfo: .rdata
382B2C 14000DD5D .pdata ExceptionHook | Pointer to DD5D - 0xD15D .text + UnwindInfo: .rdata
382B38 14000EBFD .pdata ExceptionHook | Pointer to EBFD - 0xDFFD .text + UnwindInfo: .rdata
382B44 14000F9FD .pdata ExceptionHook | Pointer to F9FD - 0xEDFD .text + UnwindInfo: .rdata
382B50 14001158D .pdata ExceptionHook | Pointer to 1158D - 0x1098D .text + UnwindInfo: .rdata
382B5C 14001220D .pdata ExceptionHook | Pointer to 1220D - 0x1160D .text + UnwindInfo: .rdata
382B68 14001314E .pdata ExceptionHook | Pointer to 1314E - 0x1254E .text + UnwindInfo: .rdata
382B74 140013580 .pdata ExceptionHook | Pointer to 13580 - 0x12980 .text + UnwindInfo: .rdata
382B80 1400138C0 .pdata ExceptionHook | Pointer to 138C0 - 0x12CC0 .text + UnwindInfo: .rdata
382B8C 140013F80 .pdata ExceptionHook | Pointer to 13F80 - 0x13380 .text + UnwindInfo: .rdata
382B98 140014160 .pdata ExceptionHook | Pointer to 14160 - 0x13560 .text + UnwindInfo: .rdata
382BA4 1400148C0 .pdata ExceptionHook | Pointer to 148C0 - 0x13CC0 .text + UnwindInfo: .rdata
382BB0 140014AD0 .pdata ExceptionHook | Pointer to 14AD0 - 0x13ED0 .text + UnwindInfo: .rdata
382BBC 14001546D .pdata ExceptionHook | Pointer to 1546D - 0x1486D .text + UnwindInfo: .rdata
382BC8 140015A3D .pdata ExceptionHook | Pointer to 15A3D - 0x14E3D .text + UnwindInfo: .rdata
382BD4 14001628D .pdata ExceptionHook | Pointer to 1628D - 0x1568D .text + UnwindInfo: .rdata
382BE0 140016C40 .pdata ExceptionHook | Pointer to 16C40 - 0x16040 .text + UnwindInfo: .rdata
382BEC 140016F20 .pdata ExceptionHook | Pointer to 16F20 - 0x16320 .text + UnwindInfo: .rdata
382BF8 1400179A0 .pdata ExceptionHook | Pointer to 179A0 - 0x16DA0 .text + UnwindInfo: .rdata
382C04 140017D00 .pdata ExceptionHook | Pointer to 17D00 - 0x17100 .text + UnwindInfo: .rdata
382C10 140018300 .pdata ExceptionHook | Pointer to 18300 - 0x17700 .text + UnwindInfo: .rdata
382C1C 140018380 .pdata ExceptionHook | Pointer to 18380 - 0x17780 .text + UnwindInfo: .rdata
382C28 1400186A0 .pdata ExceptionHook | Pointer to 186A0 - 0x17AA0 .text + UnwindInfo: .rdata
382C34 140018F40 .pdata ExceptionHook | Pointer to 18F40 - 0x18340 .text + UnwindInfo: .rdata
382C40 140019600 .pdata ExceptionHook | Pointer to 19600 - 0x18A00 .text + UnwindInfo: .rdata
382C4C 140019780 .pdata ExceptionHook | Pointer to 19780 - 0x18B80 .text + UnwindInfo: .rdata
382C58 140019800 .pdata ExceptionHook | Pointer to 19800 - 0x18C00 .text + UnwindInfo: .rdata
382C64 140019A80 .pdata ExceptionHook | Pointer to 19A80 - 0x18E80 .text + UnwindInfo: .rdata
382C70 14001A2C0 .pdata ExceptionHook | Pointer to 1A2C0 - 0x196C0 .text + UnwindInfo: .rdata
382C7C 14001A94D .pdata ExceptionHook | Pointer to 1A94D - 0x19D4D .text + UnwindInfo: .rdata
382C88 14001AD0D .pdata ExceptionHook | Pointer to 1AD0D - 0x1A10D .text + UnwindInfo: .rdata
382C94 14001AF4D .pdata ExceptionHook | Pointer to 1AF4D - 0x1A34D .text + UnwindInfo: .rdata
382CA0 14001B9CD .pdata ExceptionHook | Pointer to 1B9CD - 0x1ADCD .text + UnwindInfo: .rdata
382CAC 140026BE0 .pdata ExceptionHook | Pointer to 26BE0 - 0x25FE0 .text + UnwindInfo: .rdata
382CB8 140026C70 .pdata ExceptionHook | Pointer to 26C70 - 0x26070 .text + UnwindInfo: .rdata
382CC4 140026CAC .pdata ExceptionHook | Pointer to 26CAC - 0x260AC .text + UnwindInfo: .rdata
382CD0 140026FCE .pdata ExceptionHook | Pointer to 26FCE - 0x263CE .text + UnwindInfo: .rdata
382CDC 14002704B .pdata ExceptionHook | Pointer to 2704B - 0x2644B .text + UnwindInfo: .rdata
382CE8 140027277 .pdata ExceptionHook | Pointer to 27277 - 0x26677 .text + UnwindInfo: .rdata
382CF4 140027393 .pdata ExceptionHook | Pointer to 27393 - 0x26793 .text + UnwindInfo: .rdata
382D00 1400274C0 .pdata ExceptionHook | Pointer to 274C0 - 0x268C0 .text + UnwindInfo: .rdata
382D0C 1400275D1 .pdata ExceptionHook | Pointer to 275D1 - 0x269D1 .text + UnwindInfo: .rdata
382D18 140027776 .pdata ExceptionHook | Pointer to 27776 - 0x26B76 .text + UnwindInfo: .rdata
382D24 140027D1B .pdata ExceptionHook | Pointer to 27D1B - 0x2711B .text + UnwindInfo: .rdata
382D30 140027E44 .pdata ExceptionHook | Pointer to 27E44 - 0x27244 .text + UnwindInfo: .rdata
382D3C 140027F17 .pdata ExceptionHook | Pointer to 27F17 - 0x27317 .text + UnwindInfo: .rdata
382D48 140027FC4 .pdata ExceptionHook | Pointer to 27FC4 - 0x273C4 .text + UnwindInfo: .rdata
382D54 140028027 .pdata ExceptionHook | Pointer to 28027 - 0x27427 .text + UnwindInfo: .rdata
382D60 1400280E4 .pdata ExceptionHook | Pointer to 280E4 - 0x274E4 .text + UnwindInfo: .rdata
382D6C 1400281C4 .pdata ExceptionHook | Pointer to 281C4 - 0x275C4 .text + UnwindInfo: .rdata
382D78 140028421 .pdata ExceptionHook | Pointer to 28421 - 0x27821 .text + UnwindInfo: .rdata
382D84 1400288AD .pdata ExceptionHook | Pointer to 288AD - 0x27CAD .text + UnwindInfo: .rdata
382D90 140028A42 .pdata ExceptionHook | Pointer to 28A42 - 0x27E42 .text + UnwindInfo: .rdata
382D9C 140028B57 .pdata ExceptionHook | Pointer to 28B57 - 0x27F57 .text + UnwindInfo: .rdata
382DA8 140028D38 .pdata ExceptionHook | Pointer to 28D38 - 0x28138 .text + UnwindInfo: .rdata
382DB4 140028E6D .pdata ExceptionHook | Pointer to 28E6D - 0x2826D .text + UnwindInfo: .rdata
382DC0 140028EEC .pdata ExceptionHook | Pointer to 28EEC - 0x282EC .text + UnwindInfo: .rdata
382DCC 1400294A7 .pdata ExceptionHook | Pointer to 294A7 - 0x288A7 .text + UnwindInfo: .rdata
382DD8 140029980 .pdata ExceptionHook | Pointer to 29980 - 0x28D80 .text + UnwindInfo: .rdata
382DE4 140029B50 .pdata ExceptionHook | Pointer to 29B50 - 0x28F50 .text + UnwindInfo: .rdata
382DF0 140029DA0 .pdata ExceptionHook | Pointer to 29DA0 - 0x291A0 .text + UnwindInfo: .rdata
382DFC 14002A020 .pdata ExceptionHook | Pointer to 2A020 - 0x29420 .text + UnwindInfo: .rdata
382E08 14002A8B2 .pdata ExceptionHook | Pointer to 2A8B2 - 0x29CB2 .text + UnwindInfo: .rdata
382E14 14002A91C .pdata ExceptionHook | Pointer to 2A91C - 0x29D1C .text + UnwindInfo: .rdata
382E20 14002A9AD .pdata ExceptionHook | Pointer to 2A9AD - 0x29DAD .text + UnwindInfo: .rdata
382E2C 14002AA60 .pdata ExceptionHook | Pointer to 2AA60 - 0x29E60 .text + UnwindInfo: .rdata
382E38 14002B364 .pdata ExceptionHook | Pointer to 2B364 - 0x2A764 .text + UnwindInfo: .rdata
382E44 14002B470 .pdata ExceptionHook | Pointer to 2B470 - 0x2A870 .text + UnwindInfo: .rdata
382E50 14002C1BC .pdata ExceptionHook | Pointer to 2C1BC - 0x2B5BC .text + UnwindInfo: .rdata
382E5C 14002C24D .pdata ExceptionHook | Pointer to 2C24D - 0x2B64D .text + UnwindInfo: .rdata
382E68 14002C261 .pdata ExceptionHook | Pointer to 2C261 - 0x2B661 .text + UnwindInfo: .rdata
382E74 14002C55D .pdata ExceptionHook | Pointer to 2C55D - 0x2B95D .text + UnwindInfo: .rdata
382E80 14002CB0F .pdata ExceptionHook | Pointer to 2CB0F - 0x2BF0F .text + UnwindInfo: .rdata
382E8C 14002D08A .pdata ExceptionHook | Pointer to 2D08A - 0x2C48A .text + UnwindInfo: .rdata
382E98 14002D10A .pdata ExceptionHook | Pointer to 2D10A - 0x2C50A .text + UnwindInfo: .rdata
382EA4 14002D11C .pdata ExceptionHook | Pointer to 2D11C - 0x2C51C .text + UnwindInfo: .rdata
3A4400-3A55FF 3CA000 LZMADEC Executable section anomaly, first bytes: 5355565741544155
3A5800-3A59FF 3CD000 malloc_h Executable section anomaly, first bytes: 56574883EC384885
3AB000 N/A *Overlay* 48270000000202003082273806092A864886F70D | H’......0.’8..*.H...
Extra Analysis
Metric Value Percentage
Ascii Code 2467791 63,9954%
Null Byte Code 527091 13,6687%
NOP Cave Found 0x9090909090 Block Count: 523 | Total: 0,0339%
© 2026 All rights reserved.