PESCAN.IO - Analysis Report Basic |
|||||||
| File Structure |
|
PE Chart Code
Header PE (light blue)
Executable sections (pink)
Non-executable sections (black)
External injected code (red)
File Structure in red = malformed or corrupted header
Chart Code For Other Files
Printable characters (blue)
Non-printable characters (black)
| Information |
| Size: 3,68 MB SHA-256 Hash: D5D5274CACFF7B59F34B059DC716CB0EE6DDB1370BB9010F9A55CECF4DC2958E SHA-1 Hash: BA2999B3191921DAA8F1BDDD5F0A9329C00971F9 MD5 Hash: 1E99F4E0623F68E72054DD7AC02D6ABB Imphash: BDDE57058B98B702790F254A48122E95 MajorOSVersion: 10 MinorOSVersion: 0 CheckSum: 003B18C5 EntryPoint (rva): 133AB0 SizeOfHeaders: 400 SizeOfImage: 3D4000 ImageBase: 0000000140000000 Architecture: x64 ExportTable: 359630 ImportTable: 35968C IAT: 359F30 Characteristics: 22 TimeDateStamp: 6A6C5ECB Date: 31/07/2026 8:37:31 File Type: EXE File Type: DLL Number Of Sections: 11 ASLR: Disabled Section Names (Optional Header): .text, .rdata, .data, .pdata, .fptable, .tls, LZMADEC, _RDATA, malloc_h, .rsrc, .reloc Number Of Executable Sections: 3 Subsystem: Windows GUI UAC Execution Level Manifest: asInvoker |
| Sections Info |
| Section Name | Flags | ROffset | RSize | VOffset | VSize | Entropy | Chi2 |
|---|---|---|---|---|---|---|---|
| .text | 0x60000020 Code Executable Readable |
400 | 2F7E00 | 1000 | 2F7C57 |
|
|
| .rdata | 0x40000040 Initialized Data Readable |
2F8200 | 78A00 | 2F9000 | 78898 |
|
|
| .data | 0xC0000040 Initialized Data Readable Writeable |
370C00 | 11E00 | 372000 | 332E0 |
|
|
| .pdata | 0x40000040 Initialized Data Readable |
382A00 | 21400 | 3A6000 | 21234 |
|
|
| .fptable | 0xC0000040 Initialized Data Readable Writeable |
3A3E00 | 200 | 3C8000 | 100 |
|
|
| .tls | 0xC0000040 Initialized Data Readable Writeable |
3A4000 | 400 | 3C9000 | 2E1 |
|
|
| LZMADEC | 0x60000020 Code Executable Readable |
3A4400 | 1200 | 3CA000 | 11F1 |
|
|
| _RDATA | 0x40000040 Initialized Data Readable |
3A5600 | 200 | 3CC000 | 1F4 |
|
|
| malloc_h | 0x60000020 Code Executable Readable |
3A5800 | 200 | 3CD000 | DB |
|
|
| .rsrc | 0x40000040 Initialized Data Readable |
3A5A00 | 2000 | 3CE000 | 1FB8 |
|
|
| .reloc | 0x42000040 Initialized Data GP-Relative Readable |
3A7A00 | 3600 | 3D0000 | 3484 |
|
|
| Description |
| OriginalFilename: elevation_service.exe CompanyName: Microsoft Corporation LegalCopyright: Copyright Microsoft Corporation. All rights reserved. ProductName: Microsoft Edge FileVersion: 151.0.4129.59 FileDescription: Microsoft Edge ProductVersion: 151.0.4129.59 Language: English (United States) (ID=0x409) CodePage: Unicode (UTF-16 LE) (0x4B0) |
| Entry Point |
The section number (1) have the Entry Point Information -> EntryPoint (calculated) - 132EB0 Code -> 4883EC28E80B0000004883C428E97AFEFFFFCCCC48895C241855488BEC4883EC30488B0568E5230048BB32A2DF2D992B0000 Assembler |SUB RSP, 0X28 |CALL 0X140133AC4 |ADD RSP, 0X28 |JMP 0X14013393C |INT3 |INT3 |MOV QWORD PTR [RSP + 0X18], RBX |PUSH RBP |MOV RBP, RSP |SUB RSP, 0X30 |MOV RAX, QWORD PTR [RIP + 0X23E568] |MOVABS RBX, 0X2B992DDFA232 |
| Signatures |
| Certificate - Digital Signature: • The file is signed and the signature is correct |
| Packer/Compiler |
| Compiler: Microsoft Visual Studio Compiler: Pure Basic 4.x Detect It Easy (die) • PE+(64): compiler: Microsoft Visual C/C++(2015 v.14.0)[-] • PE+(64): linker: Microsoft Linker(14.0)[-] • PE+(64): Sign tool: Windows Authenticode(2.0)[PKCS 7] • Entropy: 6.61318 |
| Suspicious Functions |
| Library | Function | Description |
|---|---|---|
| KERNEL32.DLL | VirtualAlloc | Reserve, commit, or both, a region of memory within the virtual address space of a process. |
| KERNEL32.DLL | GetModuleHandleA | Retrieves a handle to the specified module. |
| KERNEL32.DLL | WriteFile | Writes data to a specified file or input/output (I/O) device. |
| KERNEL32.DLL | LoadLibraryW | Loads the specified module into the address space of the calling process. |
| KERNEL32.DLL | GetProcAddress | Retrieves the address of an exported function or variable from the specified dynamic-link library (DLL). |
| KERNEL32.DLL | CreateFileA | Creates or opens a file or I/O device. |
| KERNEL32.DLL | IsDebuggerPresent | Determines if the calling process is being debugged by a user-mode debugger. |
| KERNEL32.DLL | SleepEx | Pauses the execution of the current thread, optionally allowing the thread to be awakened by a kernel object or upon expiration of a timeout. |
| ADVAPI32.DLL | CryptEncrypt | Performs a cryptographic operation on data in a data block. |
| ADVAPI32.DLL | CryptDecrypt | Performs a cryptographic operation on data in a data block. |
| SHELL32.DLL | ShellExecuteExW | Performs a run operation on a specific file. |
| Windows REG (UNICODE) |
| SOFTWARE\Microsoft\Windows NT\CurrentVersion Software\Microsoft\Windows\CurrentVersion\Uninstall Software\Microsoft\EdgeUpdate\Clients\ Software\Microsoft\EdgeUpdate\ClientState\ SOFTWARE\Classes SOFTWARE\Microsoft\Shared Tools\MSInfo Software\Microsoft\EdgeUpdate |
| File Access |
| elevation_service.exe api-ms-win-core-synch-l1-2-0.dll api-ms-win-core-winrt-l1-1-0.dll api-ms-win-core-winrt-string-l1-1-0.dll WTSAPI32.dll ntdll.dll ncrypt.dll RPCRT4.dll CRYPT32.dll KERNEL32.dll OLEAUT32.dll dbghelp.dll USERENV.dll ole32.dll WINMM.dll USER32.dll SHLWAPI.dll SHELL32.dll ADVAPI32.dll user32.dll viz,input.scr renderer,benchmark,rail,input.scr input,input.scr cc,benchmark,input,input.scr benchmark,latencyInfo,rail,input.scr disabled-by-default-devtools.scr input.scr .dat PERFETTO_CHECK(blob.dat @.dat Temp |
| File Access (UNICODE) |
| msedge.exe mscopilot.exe copilotapp.exe elevation_service.exe msedgewebview2.exe copilot_app_browser_tests.exe copilotapphost.exe setup.exe msedgerecovery.exe .exe + (FormatMessageW() returned invalid UTF-16)NTDLL.DLL \usp10.dll api-ms-win-downlevel-shell32-l1-1-0.dll api-ms-win-downlevel-shlwapi-l1-1-0.dll onecore.dll bcryptprimitives.dll Kernel32.dll user32.dll api-ms-win-core-wow64-l1-1-1.dll ntdll.dll kernel32.dll dbghelp.dll mscoree.dll FKERNEL32.DLL *.msi vmoduledebug.log Temp ProgramFiles |
| Interest's Words |
| Encrypt Decrypt Encryption PassWord exec attrib start cipher hostname sdelete shutdown systeminfo ping expand replace route |
| Interest's Words (UNICODE) |
| exec |
| Anti-VM/Sandbox/Debug Tricks |
| OllyDbg Libary - dbghelp.dll |
| Anti-VM/Sandbox/Debug Tricks (UNICODE) |
| OllyDbg Libary - dbghelp.dll |
| URLs |
| http://schemas.microsoft.com/SMI/2020/WindowsSettings http://www.microsoft.com/pkiops/crl/Microsoft%20Code%20Signing%20PCA%202024.crl http://www.microsoft.com/pkiops/certs/Microsoft%20Code%20Signing%20PCA%202024.crt http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl http://www.microsoft.com/pki/certs/MicRooCerAut2011_2011_03_22.crt http://www.microsoft.com/pkiops/crl/Microsoft%20Time-Stamp%20PCA%202010(1).crl http://www.microsoft.com/pkiops/certs/Microsoft%20Time-Stamp%20PCA%202010(1).crt http://www.microsoft.com/pkiops/Docs/Repository.htm http://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt https://perfetto.dev/docs/contributing/getting-startedcommunity). https://www.microsoft.com |
| Emails |
| appro@openssl.org |
| Strings/Hex Code Found With The File Rules |
| Rule Type | Encoding | Matched (Word) |
|---|---|---|
| Text | Ascii | Unicode escape - \u00 - (Common Unicode escape sequences) |
| Text | Ascii | WinAPI Sockets (bind) |
| Text | Ascii | WinAPI Sockets (connect) |
| Text | Ascii | WinAPI Sockets (send) |
| Text | Ascii | Registry (RegCreateKeyEx) |
| Text | Ascii | Registry (RegOpenKeyEx) |
| Text | Ascii | Registry (RegSetValueEx) |
| Text | Ascii | Registry (RegDeleteKeyEx) |
| Text | Ascii | File (GetTempPath) |
| Text | Ascii | File (CreateFile) |
| Text | Ascii | File (WriteFile) |
| Text | Ascii | File (ReadFile) |
| Text | Ascii | Service (OpenSCManager) |
| Text | Ascii | Service (StartServiceCtrlDispatcher) |
| Text | Ascii | Encryption (Base64Encode) |
| Text | Ascii | Encryption API (CryptDecrypt) |
| Text | Ascii | Anti-Analysis VM (IsDebuggerPresent) |
| Text | Ascii | Anti-Analysis VM (GetSystemInfo) |
| Text | Ascii | Anti-Analysis VM (GlobalMemoryStatusEx) |
| Text | Ascii | Anti-Analysis VM (GetVersion) |
| Text | Ascii | Reconnaissance (FindFirstFileW) |
| Text | Ascii | Reconnaissance (FindNextFileW) |
| Text | Ascii | Reconnaissance (FindClose) |
| Text | Ascii | Stealth (GetThreadContext) |
| Text | Ascii | Stealth (CloseHandle) |
| Text | Ascii | Stealth (UnmapViewOfFile) |
| Text | Ascii | Stealth (MapViewOfFile) |
| Text | Ascii | Stealth (CreateFileMappingW) |
| Text | Ascii | Stealth (VirtualAlloc) |
| Text | Ascii | Stealth (VirtualProtect) |
| Text | Ascii | Execution (CreateProcessA) |
| Text | Ascii | Execution (CreateProcessW) |
| Text | Ascii | Execution (ShellExecute) |
| Text | Ascii | Execution (ResumeThread) |
| Text | Ascii | Execution (CreateEventW) |
| Text | Ascii | Privileges (SeTcbPrivilege) |
| Text | Unicode | Privileges (SeTcbPrivilege) |
| Text | Ascii | Malware that monitors and collects user data (Spy) |
| Text | Ascii | Information used for user authentication (Credential) |
| Text | Ascii | Unauthorized movement of funds or data (Transfer) |
| Text | Ascii | Technique used to capture communications between systems (Intercept) |
| Text | Ascii | Abuse of power for personal gain or unethical purposes (Corruption) |
| Entry Point | Hex Pattern | Microsoft Visual C++ 8.0 (DLL) |
| Resources |
| Path | DataRVA | Size | FileOffset | Code | Text |
|---|---|---|---|---|---|
| \TYPELIB\1\1033 | 3CE100 | 15B8 | 3A5B00 | 4D534654020001000000000009040000000000004300000001000000000000000E0000000000000000000000000000002D00 | MSFT................C...........................-. |
| \VERSION\1\1033 | 3CF6B8 | 464 | 3A70B8 | 640434000000560053005F00560045005200530049004F004E005F0049004E0046004F0000000000BD04EFFE000001000000 | d.4...V.S._.V.E.R.S.I.O.N._.I.N.F.O............... |
| \24\1\1033 | 3CFB20 | 497 | 3A7520 | 3C3F786D6C2076657273696F6E3D22312E302220656E636F64696E673D225554462D38223F3E0A3C617373656D626C792078 | <?xml version="1.0" encoding="UTF-8"?>.<assembly x |
| Intelligent String |
| • copilotapp.exe • user32.dll • dbghelp.dll • Kernel32.dll • mscopilot.exe • msedge.exe • .tls • FKERNEL32.DLL • mscoree.dll • Failed to authenticate caller process: .exe • recovery-component-inner.crx • msedgerecovery.exe • Interceptors are experimental. If you want to use them, please get in touch with the project maintainers (https://perfetto.dev/docs/contributing/getting-startedcommunity). • setup.exe • copilotapphost.exe • ://ISOLATION • kernel32.dll • ntdll.dll • leveldbloadingloglogin • disabled-by-default-cc.debug.scheduler.now • disabled-by-default-gpu.servicedisabled-by-default-gpu.vulkan.vma • disabled-by-default-skia.gpu • disabled-by-default-toplevel.ipc • gpu,login • login,screenlock_monitor • api-ms-win-core-wow64-l1-1-1.dll • bcryptprimitives.dll • runas • api-ms-win-downlevel-shlwapi-l1-1-0.dll • DumpWithoutCrashing • DialogInView • vmoduledebug.log • \u003C • copilot_app_browser_tests.exe • Microsoft.DumpWithoutCrashingStatus • DumpWithoutCrashing-file • DumpWithoutCrashing-line • api-ms-win-downlevel-shell32-l1-1-0.dll • Logging-FATAL_MILESTONELogging-DUMP_WILL_BE_CHECK_MESSAGE • ..\..\third_party\boringssl\src\crypto\fipsmodule\bn\add.cc.inc..\..\third_party\boringssl\src\crypto\fipsmodule\bn\bn.cc.inc • ..\..\third_party\boringssl\src\crypto\fipsmodule\bn\ctx.cc.inc..\..\third_party\boringssl\src\crypto\fipsmodule\bn\div.cc.inc..\..\third_party\boringssl\src\crypto\fipsmodule\bn\exponentiation.cc.inc • ..\..\third_party\boringssl\src\crypto\fipsmodule\bn\gcd_extra.cc.inc • ..\..\third_party\boringssl\src\crypto\fipsmodule\bn\jacobi.cc.inc • ..\..\third_party\boringssl\src\crypto\fipsmodule\bn\montgomery.cc.inc • ..\..\third_party\boringssl\src\crypto\fipsmodule\bn\mul.cc.inc..\..\third_party\boringssl\src\crypto\fipsmodule\bn\prime.cc.inc • ..\..\third_party\boringssl\src\crypto\fipsmodule\bn\random.cc.inc • ..\..\third_party\boringssl\src\crypto\fipsmodule\bn\shift.cc.inc • ..\..\third_party\boringssl\src\crypto\fipsmodule\bn\sqrt.cc.inc • ..\..\third_party\boringssl\src\crypto\fipsmodule\cipher\aead.cc.inc • ..\..\third_party\boringssl\src\crypto\fipsmodule\digest\digest.cc.inc • ..\..\third_party\boringssl\src\crypto\fipsmodule\digestsign\digestsign.cc.inc • ..\..\third_party\boringssl\src\crypto\fipsmodule\ec\ec.cc.inc • ..\..\third_party\boringssl\src\crypto\fipsmodule\ec\ec_key.cc.inc • ..\..\third_party\boringssl\src\crypto\fipsmodule\ec\felem.cc.inc • ..\..\third_party\boringssl\src\crypto\fipsmodule\ec\oct.cc.inc..\..\third_party\boringssl\src\crypto\fipsmodule\ec\scalar.cc.inc • ..\..\third_party\boringssl\src\crypto\fipsmodule\ecdsa\ecdsa.cc.inc • ..\..\third_party\boringssl\src\crypto\fipsmodule\rsa\padding.cc.inc • ..\..\third_party\boringssl\src\crypto\fipsmodule\rsa\rsa.cc.inc • ..\..\third_party\boringssl\src\crypto\fipsmodule\rsa\rsa_impl.cc.inc • ..\..\third_party\boringssl\src\crypto\fipsmodule\cipher\e_aes.cc.inc • ..\..\third_party\boringssl\src\crypto\fipsmodule\ec\ec_montgomery.cc.inc • ..\..\third_party\boringssl\src\crypto\fipsmodule\ec\p256.cc.inc • app-run-on-os-login-mode • msedgewebview2.exe • \usp10.dll • .dat • elevation_service.exe.pdb • .bss • elevation_service.exe |
| Flow Anomalies |
| Offset | FlowVA | Section | Description |
|---|---|---|---|
| DF4 | N/A | .text | CALL QWORD PTR [RIP+0x358A1E] |
| 4093 | N/A | .text | CALL QWORD PTR [RIP+0x35577F] |
| 5205 | N/A | .text | CALL QWORD PTR [RIP+0x35460D] |
| 626D | N/A | .text | CALL QWORD PTR [RIP+0x3535A5] |
| 8825 | N/A | .text | CALL QWORD PTR [RIP+0x350FED] |
| BD9B | N/A | .text | CALL QWORD PTR [RIP+0x34DA77] |
| 10960 | N/A | .text | CALL QWORD PTR [RIP+0x348EB2] |
| 128EA | N/A | .text | CALL QWORD PTR [RIP+0x346F28] |
| 167B2 | N/A | .text | CALL QWORD PTR [RIP+0x343060] |
| 1BAAA | N/A | .text | CALL QWORD PTR [RIP+0x33DD68] |
| 264D4 | N/A | .text | CALL QWORD PTR [RIP+0x3332AE] |
| 2657B | N/A | .text | CALL QWORD PTR [RIP+0x332FE7] |
| 26594 | N/A | .text | CALL QWORD PTR [RIP+0x332FCE] |
| 265E7 | N/A | .text | CALL QWORD PTR [RIP+0x332F7B] |
| 2663C | N/A | .text | CALL QWORD PTR [RIP+0x333146] |
| 272E8 | N/A | .text | CALL QWORD PTR [RIP+0x35BB4A] |
| 27492 | N/A | .text | CALL QWORD PTR [RIP+0x3320D0] |
| 27543 | N/A | .text | CALL QWORD PTR [RIP+0x33200F] |
| 27570 | N/A | .text | CALL QWORD PTR [RIP+0x331FF2] |
| 2775B | N/A | .text | CALL QWORD PTR [RIP+0x331E07] |
| 27784 | N/A | .text | CALL QWORD PTR [RIP+0x331DDE] |
| 2792A | N/A | .text | CALL QWORD PTR [RIP+0x331C38] |
| 27CE1 | N/A | .text | CALL QWORD PTR [RIP+0x331809] |
| 27D81 | N/A | .text | CALL QWORD PTR [RIP+0x331761] |
| 27DA1 | N/A | .text | CALL QWORD PTR [RIP+0x331671] |
| 27DBA | N/A | .text | CALL QWORD PTR [RIP+0x3317A8] |
| 27DE2 | N/A | .text | CALL QWORD PTR [RIP+0x331780] |
| 27F11 | N/A | .text | CALL QWORD PTR [RIP+0x35B209] |
| 2818A | N/A | .text | CALL QWORD PTR [RIP+0x3313D8] |
| 288FB | N/A | .text | CALL QWORD PTR [RIP+0x330BEF] |
| 28FA9 | N/A | .text | CALL QWORD PTR [RIP+0x330541] |
| 29253 | N/A | .text | CALL QWORD PTR [RIP+0x330297] |
| 2938D | N/A | .text | CALL QWORD PTR [RIP+0x3305C5] |
| 293B6 | N/A | .text | CALL QWORD PTR [RIP+0x33016C] |
| 293C0 | N/A | .text | CALL QWORD PTR [RIP+0x3301A2] |
| 294DC | N/A | .text | CALL QWORD PTR [RIP+0x32FE9E] |
| 29901 | N/A | .text | CALL QWORD PTR [RIP+0x32FC61] |
| 2991E | N/A | .text | CALL QWORD PTR [RIP+0x32FE24] |
| 2997B | N/A | .text | CALL QWORD PTR [RIP+0x32F9F7] |
| 299A2 | N/A | .text | CALL QWORD PTR [RIP+0x32FDA0] |
| 29BD7 | N/A | .text | CALL QWORD PTR [RIP+0x32F98B] |
| 29EFE | N/A | .text | CALL QWORD PTR [RIP+0x32F47C] |
| 2A0AE | N/A | .text | CALL QWORD PTR [RIP+0x32F4B4] |
| 2A0CC | N/A | .text | CALL QWORD PTR [RIP+0x32F496] |
| 2A127 | N/A | .text | CALL QWORD PTR [RIP+0x32F61B] |
| 2A2A3 | N/A | .text | CALL QWORD PTR [RIP+0x32F49F] |
| 2A2D5 | N/A | .text | CALL QWORD PTR [RIP+0x32F09D] |
| 2A312 | N/A | .text | CALL QWORD PTR [RIP+0x32F250] |
| 2A31E | N/A | .text | CALL QWORD PTR [RIP+0x32F244] |
| 2A92A | N/A | .text | CALL QWORD PTR [RIP+0x32EC38] |
| 2AB4E | N/A | .text | CALL QWORD PTR [RIP+0x32EA14] |
| 2AB5D | N/A | .text | CALL QWORD PTR [RIP+0x32ED6D] |
| 2AB65 | N/A | .text | CALL QWORD PTR [RIP+0x32ED05] |
| 2B40F | N/A | .text | CALL QWORD PTR [RIP+0x3579E3] |
| 2B465 | N/A | .text | CALL QWORD PTR [RIP+0x32E375] |
| 2B495 | N/A | .text | CALL QWORD PTR [RIP+0x32E04D] |
| 2B4B9 | N/A | .text | CALL QWORD PTR [RIP+0x32DF59] |
| 2B6F7 | N/A | .text | CALL QWORD PTR [RIP+0x32E08B] |
| 2BC3E | N/A | .text | CALL QWORD PTR [RIP+0x32DB44] |
| 2E2BE | N/A | .text | CALL QWORD PTR [RIP+0x354CDC] |
| 2E2C7 | N/A | .text | CALL QWORD PTR [RIP+0x32B0DB] |
| 2E92E | N/A | .text | CALL QWORD PTR [RIP+0x35466C] |
| 2E937 | N/A | .text | CALL QWORD PTR [RIP+0x32AA6B] |
| 2ECFA | N/A | .text | CALL QWORD PTR [RIP+0x32A7F8] |
| 2ED11 | N/A | .text | CALL QWORD PTR [RIP+0x3541E1] |
| 2ED1A | N/A | .text | CALL QWORD PTR [RIP+0x354240] |
| 2ED3F | N/A | .text | CALL QWORD PTR [RIP+0x32A663] |
| 2ED92 | N/A | .text | CALL QWORD PTR [RIP+0x328D70] |
| 2F7CB | N/A | .text | CALL QWORD PTR [RIP+0x3537CF] |
| 2F7D4 | N/A | .text | CALL QWORD PTR [RIP+0x329BCE] |
| 2F81A | N/A | .text | CALL QWORD PTR [RIP+0x353780] |
| 2F823 | N/A | .text | CALL QWORD PTR [RIP+0x329B7F] |
| 3017C | N/A | .text | CALL QWORD PTR [RIP+0x352E1E] |
| 30185 | N/A | .text | CALL QWORD PTR [RIP+0x32921D] |
| 306F6 | N/A | .text | CALL QWORD PTR [RIP+0x352724] |
| 3073A | N/A | .text | CALL QWORD PTR [RIP+0x3526E8] |
| 307C5 | N/A | .text | CALL QWORD PTR [RIP+0x32733D] |
| 307EB | N/A | .text | JMP QWORD PTR [RIP+0x35263F] |
| 30892 | N/A | .text | CALL QWORD PTR [RIP+0x329060] |
| 3094C | N/A | .text | CALL QWORD PTR [RIP+0x328E6E] |
| 30C9D | N/A | .text | CALL QWORD PTR [RIP+0x328B1D] |
| 318B5 | N/A | .text | CALL QWORD PTR [RIP+0x351865] |
| 31D8C | N/A | .text | CALL QWORD PTR [RIP+0x32775E] |
| 322A9 | N/A | .text | CALL QWORD PTR [RIP+0x325859] |
| 322CB | N/A | .text | CALL QWORD PTR [RIP+0x325837] |
| 32305 | N/A | .text | CALL QWORD PTR [RIP+0x3257FD] |
| 3231E | N/A | .text | CALL QWORD PTR [RIP+0x3257E4] |
| 323B9 | N/A | .text | CALL QWORD PTR [RIP+0x325749] |
| 32667 | N/A | .text | CALL QWORD PTR [RIP+0x32549B] |
| 326D3 | N/A | .text | CALL QWORD PTR [RIP+0x32542F] |
| 326F5 | N/A | .text | CALL QWORD PTR [RIP+0x32540D] |
| 3274F | N/A | .text | CALL QWORD PTR [RIP+0x3253B3] |
| 327A7 | N/A | .text | CALL QWORD PTR [RIP+0x32535B] |
| 327B9 | N/A | .text | CALL QWORD PTR [RIP+0x325349] |
| 32880 | N/A | .text | CALL QWORD PTR [RIP+0x325282] |
| 3297E | N/A | .text | CALL QWORD PTR [RIP+0x325184] |
| 32999 | N/A | .text | CALL QWORD PTR [RIP+0x325169] |
| 331DE | N/A | .text | CALL QWORD PTR [RIP+0x324924] |
| 331F0 | N/A | .text | CALL QWORD PTR [RIP+0x324912] |
| 33876 | N/A | .text | JMP QWORD PTR [RIP+0x32428C] |
| E11-E3F | N/A | .text | Unusual BP Cave, count: 47 |
| 18E1-18FF | N/A | .text | Unusual NOPS Space, count: 31 |
| 5222-523F | N/A | .text | Unusual BP Cave, count: 30 |
| 628A-62BF | N/A | .text | Unusual BP Cave, count: 54 |
| 74D1-74FF | N/A | .text | Unusual NOPS Space, count: 47 |
| 8842-887F | N/A | .text | Unusual BP Cave, count: 62 |
| 9DD1-9DFF | N/A | .text | Unusual NOPS Space, count: 47 |
| AD22-AD3F | N/A | .text | Unusual NOPS Space, count: 30 |
| BE15-BE3F | N/A | .text | Unusual BP Cave, count: 43 |
| 115D4-115FF | N/A | .text | Unusual NOPS Space, count: 44 |
| 12907-1293F | N/A | .text | Unusual BP Cave, count: 57 |
| 13782-1379F | N/A | .text | Unusual NOPS Space, count: 30 |
| 13CA0-13CBF | N/A | .text | Unusual BP Cave, count: 32 |
| 14111-1413F | N/A | .text | Unusual BP Cave, count: 47 |
| 167CF-167FF | N/A | .text | Unusual BP Cave, count: 49 |
| 176E1-176FF | N/A | .text | Unusual NOPS Space, count: 31 |
| 1BDDC-1BDFF | N/A | .text | Unusual NOPS Space, count: 36 |
| 22E0C-22E3F | N/A | .text | Unusual NOPS Space, count: 52 |
| 2F8057-2F81FF | N/A | .text | Unusual BP Cave, count: 425 |
| 2F860C-2F863F | N/A | .rdata | Unusual NOPS Space, count: 52 |
| 2F91C8-2F91FF | N/A | .rdata | Unusual NOPS Space, count: 56 |
| 2F9290-2F92BF | N/A | .rdata | Unusual NOPS Space, count: 48 |
| 3A58DB-3A59FF | N/A | malloc_h | Unusual BP Cave, count: 293 |
| 3579F8 | 1400D19A0 | .rdata | TLS Callback | Pointer to D19A0 - 0xD0DA0 .text |
| 357A00 | 140132CC0 | .rdata | TLS Callback | Pointer to 132CC0 - 0x1320C0 .text |
| 357A08 | 1400F9540 | .rdata | TLS Callback | Pointer to F9540 - 0xF8940 .text |
| 357A10 | 140132D40 | .rdata | TLS Callback | Pointer to 132D40 - 0x132140 .text |
| 357A18 | 1400ABFE0 | .rdata | TLS Callback | Pointer to ABFE0 - 0xAB3E0 .text |
| 357A20 | 1400F4FC0 | .rdata | TLS Callback | Pointer to F4FC0 - 0xF43C0 .text |
| 382A00 | 14000100D | .pdata | ExceptionHook | Pointer to 100D - 0x40D .text + UnwindInfo: .rdata |
| 382A0C | 140001A4D | .pdata | ExceptionHook | Pointer to 1A4D - 0xE4D .text + UnwindInfo: .rdata |
| 382A18 | 1400020AD | .pdata | ExceptionHook | Pointer to 20AD - 0x14AD .text + UnwindInfo: .rdata |
| 382A24 | 1400029AD | .pdata | ExceptionHook | Pointer to 29AD - 0x1DAD .text + UnwindInfo: .rdata |
| 382A30 | 14000348D | .pdata | ExceptionHook | Pointer to 348D - 0x288D .text + UnwindInfo: .rdata |
| 382A3C | 140003D6D | .pdata | ExceptionHook | Pointer to 3D6D - 0x316D .text + UnwindInfo: .rdata |
| 382A48 | 140004900 | .pdata | ExceptionHook | Pointer to 4900 - 0x3D00 .text + UnwindInfo: .rdata |
| 382A54 | 140004CCD | .pdata | ExceptionHook | Pointer to 4CCD - 0x40CD .text + UnwindInfo: .rdata |
| 382A60 | 140004F5D | .pdata | ExceptionHook | Pointer to 4F5D - 0x435D .text + UnwindInfo: .rdata |
| 382A6C | 1400054CD | .pdata | ExceptionHook | Pointer to 54CD - 0x48CD .text + UnwindInfo: .rdata |
| 382A78 | 14000570D | .pdata | ExceptionHook | Pointer to 570D - 0x4B0D .text + UnwindInfo: .rdata |
| 382A84 | 14000674D | .pdata | ExceptionHook | Pointer to 674D - 0x5B4D .text + UnwindInfo: .rdata |
| 382A90 | 14000682D | .pdata | ExceptionHook | Pointer to 682D - 0x5C2D .text + UnwindInfo: .rdata |
| 382A9C | 14000691D | .pdata | ExceptionHook | Pointer to 691D - 0x5D1D .text + UnwindInfo: .rdata |
| 382AA8 | 1400069ED | .pdata | ExceptionHook | Pointer to 69ED - 0x5DED .text + UnwindInfo: .rdata |
| 382AB4 | 140006ABD | .pdata | ExceptionHook | Pointer to 6ABD - 0x5EBD .text + UnwindInfo: .rdata |
| 382AC0 | 140006BFD | .pdata | ExceptionHook | Pointer to 6BFD - 0x5FFD .text + UnwindInfo: .rdata |
| 382ACC | 140006ECD | .pdata | ExceptionHook | Pointer to 6ECD - 0x62CD .text + UnwindInfo: .rdata |
| 382AD8 | 14000810D | .pdata | ExceptionHook | Pointer to 810D - 0x750D .text + UnwindInfo: .rdata |
| 382AE4 | 14000948D | .pdata | ExceptionHook | Pointer to 948D - 0x888D .text + UnwindInfo: .rdata |
| 382AF0 | 14000A64D | .pdata | ExceptionHook | Pointer to A64D - 0x9A4D .text + UnwindInfo: .rdata |
| 382AFC | 14000AA0D | .pdata | ExceptionHook | Pointer to AA0D - 0x9E0D .text + UnwindInfo: .rdata |
| 382B08 | 14000B94D | .pdata | ExceptionHook | Pointer to B94D - 0xAD4D .text + UnwindInfo: .rdata |
| 382B14 | 14000CA4D | .pdata | ExceptionHook | Pointer to CA4D - 0xBE4D .text + UnwindInfo: .rdata |
| 382B20 | 14000DA8D | .pdata | ExceptionHook | Pointer to DA8D - 0xCE8D .text + UnwindInfo: .rdata |
| 382B2C | 14000DD5D | .pdata | ExceptionHook | Pointer to DD5D - 0xD15D .text + UnwindInfo: .rdata |
| 382B38 | 14000EBFD | .pdata | ExceptionHook | Pointer to EBFD - 0xDFFD .text + UnwindInfo: .rdata |
| 382B44 | 14000F9FD | .pdata | ExceptionHook | Pointer to F9FD - 0xEDFD .text + UnwindInfo: .rdata |
| 382B50 | 14001158D | .pdata | ExceptionHook | Pointer to 1158D - 0x1098D .text + UnwindInfo: .rdata |
| 382B5C | 14001220D | .pdata | ExceptionHook | Pointer to 1220D - 0x1160D .text + UnwindInfo: .rdata |
| 382B68 | 14001314E | .pdata | ExceptionHook | Pointer to 1314E - 0x1254E .text + UnwindInfo: .rdata |
| 382B74 | 140013580 | .pdata | ExceptionHook | Pointer to 13580 - 0x12980 .text + UnwindInfo: .rdata |
| 382B80 | 1400138C0 | .pdata | ExceptionHook | Pointer to 138C0 - 0x12CC0 .text + UnwindInfo: .rdata |
| 382B8C | 140013F80 | .pdata | ExceptionHook | Pointer to 13F80 - 0x13380 .text + UnwindInfo: .rdata |
| 382B98 | 140014160 | .pdata | ExceptionHook | Pointer to 14160 - 0x13560 .text + UnwindInfo: .rdata |
| 382BA4 | 1400148C0 | .pdata | ExceptionHook | Pointer to 148C0 - 0x13CC0 .text + UnwindInfo: .rdata |
| 382BB0 | 140014AD0 | .pdata | ExceptionHook | Pointer to 14AD0 - 0x13ED0 .text + UnwindInfo: .rdata |
| 382BBC | 14001546D | .pdata | ExceptionHook | Pointer to 1546D - 0x1486D .text + UnwindInfo: .rdata |
| 382BC8 | 140015A3D | .pdata | ExceptionHook | Pointer to 15A3D - 0x14E3D .text + UnwindInfo: .rdata |
| 382BD4 | 14001628D | .pdata | ExceptionHook | Pointer to 1628D - 0x1568D .text + UnwindInfo: .rdata |
| 382BE0 | 140016C40 | .pdata | ExceptionHook | Pointer to 16C40 - 0x16040 .text + UnwindInfo: .rdata |
| 382BEC | 140016F20 | .pdata | ExceptionHook | Pointer to 16F20 - 0x16320 .text + UnwindInfo: .rdata |
| 382BF8 | 1400179A0 | .pdata | ExceptionHook | Pointer to 179A0 - 0x16DA0 .text + UnwindInfo: .rdata |
| 382C04 | 140017D00 | .pdata | ExceptionHook | Pointer to 17D00 - 0x17100 .text + UnwindInfo: .rdata |
| 382C10 | 140018300 | .pdata | ExceptionHook | Pointer to 18300 - 0x17700 .text + UnwindInfo: .rdata |
| 382C1C | 140018380 | .pdata | ExceptionHook | Pointer to 18380 - 0x17780 .text + UnwindInfo: .rdata |
| 382C28 | 1400186A0 | .pdata | ExceptionHook | Pointer to 186A0 - 0x17AA0 .text + UnwindInfo: .rdata |
| 382C34 | 140018F40 | .pdata | ExceptionHook | Pointer to 18F40 - 0x18340 .text + UnwindInfo: .rdata |
| 382C40 | 140019600 | .pdata | ExceptionHook | Pointer to 19600 - 0x18A00 .text + UnwindInfo: .rdata |
| 382C4C | 140019780 | .pdata | ExceptionHook | Pointer to 19780 - 0x18B80 .text + UnwindInfo: .rdata |
| 382C58 | 140019800 | .pdata | ExceptionHook | Pointer to 19800 - 0x18C00 .text + UnwindInfo: .rdata |
| 382C64 | 140019A80 | .pdata | ExceptionHook | Pointer to 19A80 - 0x18E80 .text + UnwindInfo: .rdata |
| 382C70 | 14001A2C0 | .pdata | ExceptionHook | Pointer to 1A2C0 - 0x196C0 .text + UnwindInfo: .rdata |
| 382C7C | 14001A94D | .pdata | ExceptionHook | Pointer to 1A94D - 0x19D4D .text + UnwindInfo: .rdata |
| 382C88 | 14001AD0D | .pdata | ExceptionHook | Pointer to 1AD0D - 0x1A10D .text + UnwindInfo: .rdata |
| 382C94 | 14001AF4D | .pdata | ExceptionHook | Pointer to 1AF4D - 0x1A34D .text + UnwindInfo: .rdata |
| 382CA0 | 14001B9CD | .pdata | ExceptionHook | Pointer to 1B9CD - 0x1ADCD .text + UnwindInfo: .rdata |
| 382CAC | 140026BE0 | .pdata | ExceptionHook | Pointer to 26BE0 - 0x25FE0 .text + UnwindInfo: .rdata |
| 382CB8 | 140026C70 | .pdata | ExceptionHook | Pointer to 26C70 - 0x26070 .text + UnwindInfo: .rdata |
| 382CC4 | 140026CAC | .pdata | ExceptionHook | Pointer to 26CAC - 0x260AC .text + UnwindInfo: .rdata |
| 382CD0 | 140026FCE | .pdata | ExceptionHook | Pointer to 26FCE - 0x263CE .text + UnwindInfo: .rdata |
| 382CDC | 14002704B | .pdata | ExceptionHook | Pointer to 2704B - 0x2644B .text + UnwindInfo: .rdata |
| 382CE8 | 140027277 | .pdata | ExceptionHook | Pointer to 27277 - 0x26677 .text + UnwindInfo: .rdata |
| 382CF4 | 140027393 | .pdata | ExceptionHook | Pointer to 27393 - 0x26793 .text + UnwindInfo: .rdata |
| 382D00 | 1400274C0 | .pdata | ExceptionHook | Pointer to 274C0 - 0x268C0 .text + UnwindInfo: .rdata |
| 382D0C | 1400275D1 | .pdata | ExceptionHook | Pointer to 275D1 - 0x269D1 .text + UnwindInfo: .rdata |
| 382D18 | 140027776 | .pdata | ExceptionHook | Pointer to 27776 - 0x26B76 .text + UnwindInfo: .rdata |
| 382D24 | 140027D1B | .pdata | ExceptionHook | Pointer to 27D1B - 0x2711B .text + UnwindInfo: .rdata |
| 382D30 | 140027E44 | .pdata | ExceptionHook | Pointer to 27E44 - 0x27244 .text + UnwindInfo: .rdata |
| 382D3C | 140027F17 | .pdata | ExceptionHook | Pointer to 27F17 - 0x27317 .text + UnwindInfo: .rdata |
| 382D48 | 140027FC4 | .pdata | ExceptionHook | Pointer to 27FC4 - 0x273C4 .text + UnwindInfo: .rdata |
| 382D54 | 140028027 | .pdata | ExceptionHook | Pointer to 28027 - 0x27427 .text + UnwindInfo: .rdata |
| 382D60 | 1400280E4 | .pdata | ExceptionHook | Pointer to 280E4 - 0x274E4 .text + UnwindInfo: .rdata |
| 382D6C | 1400281C4 | .pdata | ExceptionHook | Pointer to 281C4 - 0x275C4 .text + UnwindInfo: .rdata |
| 382D78 | 140028421 | .pdata | ExceptionHook | Pointer to 28421 - 0x27821 .text + UnwindInfo: .rdata |
| 382D84 | 1400288AD | .pdata | ExceptionHook | Pointer to 288AD - 0x27CAD .text + UnwindInfo: .rdata |
| 382D90 | 140028A42 | .pdata | ExceptionHook | Pointer to 28A42 - 0x27E42 .text + UnwindInfo: .rdata |
| 382D9C | 140028B57 | .pdata | ExceptionHook | Pointer to 28B57 - 0x27F57 .text + UnwindInfo: .rdata |
| 382DA8 | 140028D38 | .pdata | ExceptionHook | Pointer to 28D38 - 0x28138 .text + UnwindInfo: .rdata |
| 382DB4 | 140028E6D | .pdata | ExceptionHook | Pointer to 28E6D - 0x2826D .text + UnwindInfo: .rdata |
| 382DC0 | 140028EEC | .pdata | ExceptionHook | Pointer to 28EEC - 0x282EC .text + UnwindInfo: .rdata |
| 382DCC | 1400294A7 | .pdata | ExceptionHook | Pointer to 294A7 - 0x288A7 .text + UnwindInfo: .rdata |
| 382DD8 | 140029980 | .pdata | ExceptionHook | Pointer to 29980 - 0x28D80 .text + UnwindInfo: .rdata |
| 382DE4 | 140029B50 | .pdata | ExceptionHook | Pointer to 29B50 - 0x28F50 .text + UnwindInfo: .rdata |
| 382DF0 | 140029DA0 | .pdata | ExceptionHook | Pointer to 29DA0 - 0x291A0 .text + UnwindInfo: .rdata |
| 382DFC | 14002A020 | .pdata | ExceptionHook | Pointer to 2A020 - 0x29420 .text + UnwindInfo: .rdata |
| 382E08 | 14002A8B2 | .pdata | ExceptionHook | Pointer to 2A8B2 - 0x29CB2 .text + UnwindInfo: .rdata |
| 382E14 | 14002A91C | .pdata | ExceptionHook | Pointer to 2A91C - 0x29D1C .text + UnwindInfo: .rdata |
| 382E20 | 14002A9AD | .pdata | ExceptionHook | Pointer to 2A9AD - 0x29DAD .text + UnwindInfo: .rdata |
| 382E2C | 14002AA60 | .pdata | ExceptionHook | Pointer to 2AA60 - 0x29E60 .text + UnwindInfo: .rdata |
| 382E38 | 14002B364 | .pdata | ExceptionHook | Pointer to 2B364 - 0x2A764 .text + UnwindInfo: .rdata |
| 382E44 | 14002B470 | .pdata | ExceptionHook | Pointer to 2B470 - 0x2A870 .text + UnwindInfo: .rdata |
| 382E50 | 14002C1BC | .pdata | ExceptionHook | Pointer to 2C1BC - 0x2B5BC .text + UnwindInfo: .rdata |
| 382E5C | 14002C24D | .pdata | ExceptionHook | Pointer to 2C24D - 0x2B64D .text + UnwindInfo: .rdata |
| 382E68 | 14002C261 | .pdata | ExceptionHook | Pointer to 2C261 - 0x2B661 .text + UnwindInfo: .rdata |
| 382E74 | 14002C55D | .pdata | ExceptionHook | Pointer to 2C55D - 0x2B95D .text + UnwindInfo: .rdata |
| 382E80 | 14002CB0F | .pdata | ExceptionHook | Pointer to 2CB0F - 0x2BF0F .text + UnwindInfo: .rdata |
| 382E8C | 14002D08A | .pdata | ExceptionHook | Pointer to 2D08A - 0x2C48A .text + UnwindInfo: .rdata |
| 382E98 | 14002D10A | .pdata | ExceptionHook | Pointer to 2D10A - 0x2C50A .text + UnwindInfo: .rdata |
| 382EA4 | 14002D11C | .pdata | ExceptionHook | Pointer to 2D11C - 0x2C51C .text + UnwindInfo: .rdata |
| 3A4400-3A55FF | 3CA000 | LZMADEC | Executable section anomaly, first bytes: 5355565741544155 |
| 3A5800-3A59FF | 3CD000 | malloc_h | Executable section anomaly, first bytes: 56574883EC384885 |
| 3AB000 | N/A | *Overlay* | 48270000000202003082273806092A864886F70D | H’......0.’8..*.H... |
| Extra Analysis |
| Metric | Value | Percentage |
|---|---|---|
| Ascii Code | 2467791 | 63,9954% |
| Null Byte Code | 527091 | 13,6687% |
| NOP Cave Found | 0x9090909090 | Block Count: 523 | Total: 0,0339% |
© 2026 All rights reserved.