PESCAN.IO - Analysis Report Basic |
|||||||
| File Structure |
|
PE Chart Code
Header PE (light blue)
Executable sections (pink)
Non-executable sections (black)
External injected code (red)
File Structure in red = malformed or corrupted header
Chart Code For Other Files
Printable characters (blue)
Non-printable characters (black)
| Information |
Icon: Size: 5,94 MBSHA-256 Hash: 51312177A9C81AE610E7B73A8D3330C54C130BAF901516351D250357D0C3FF6D SHA-1 Hash: 18CFD77094A85BA4DD930CDCFC36FD0CBC01C446 MD5 Hash: 35956356B20F6D37C4FDCAF0D75804F0 Imphash: 40AB50289F7EF5FAE60801F88D4541FC MajorOSVersion: 6 MinorOSVersion: 1 CheckSum: 005FA8CB EntryPoint (rva): A83BC SizeOfHeaders: 400 SizeOfImage: E7000 ImageBase: 400000 Architecture: x86 ExportTable: B7000 ImportTable: B5000 IAT: B52D4 Characteristics: 103 TimeDateStamp: 666711EF Date: 10/06/2024 14:47:11 File Type: EXE Number Of Sections: 10 ASLR: Enabled Section Names: .text, .itext, .data, .bss, .idata, .didata, .edata, .tls, .rdata, .rsrc Number Of Executable Sections: 2 Subsystem: Windows GUI UAC Execution Level Manifest: asInvoker |
| Sections Info |
| Section Name | Flags | ROffset | RSize | VOffset | VSize | Entropy | Chi2 |
|---|---|---|---|---|---|---|---|
| .text | 0x60000020 Code Executable Readable |
400 | A5800 | 1000 | A568C |
|
|
| .itext | 0x60000020 Code Executable Readable |
A5C00 | 1C00 | A7000 | 1B64 |
|
|
| .data | 0xC0000040 Initialized Data Readable Writeable |
A7800 | 3A00 | A9000 | 3838 |
|
|
| .bss | 0xC0000000 Readable Writeable |
0 | 0 | AD000 | 7258 |
|
|
| .idata | 0xC0000040 Initialized Data Readable Writeable |
AB200 | 1000 | B5000 | FEC |
|
|
| .didata | 0xC0000040 Initialized Data Readable Writeable |
AC200 | 200 | B6000 | 1A4 |
|
|
| .edata | 0x40000040 Initialized Data Readable |
AC400 | 200 | B7000 | 71 |
|
|
| .tls | 0xC0000000 Readable Writeable |
0 | 0 | B8000 | 18 |
|
|
| .rdata | 0x40000040 Initialized Data Readable |
AC600 | 200 | B9000 | 5D |
|
|
| .rsrc | 0x40000040 Initialized Data Readable |
AC800 | 2CC00 | BA000 | 2CA90 |
|
|
| Description |
| CompanyName: AppSalt LegalCopyright: AppSalt ProductName: DeskRest FileVersion: 1.0.2.1 FileDescription: DeskRest installer ProductVersion: 1.0.2.1 Comments: This installation was built with Inno Setup. Language: Unknown (ID=0x0) CodePage: Unicode (UTF-16 LE) (0x4B0) |
| Binder/Joiner/Crypter |
| Dropper code detected (EOF) - 5,04 MB |
| Entry Point |
The section number (2) - (.itext) have the Entry Point Information -> EntryPoint (calculated) - A6FBC Code -> 558BEC83C4A453565733C08945C48945C08945A48945D08945C88945CC8945D48945D88945ECB8BC2E4A00E85079F6FF33C0 Assembler |PUSH EBP |MOV EBP, ESP |ADD ESP, -0X5C |PUSH EBX |PUSH ESI |PUSH EDI |XOR EAX, EAX |MOV DWORD PTR [EBP - 0X3C], EAX |MOV DWORD PTR [EBP - 0X40], EAX |MOV DWORD PTR [EBP - 0X5C], EAX |MOV DWORD PTR [EBP - 0X30], EAX |MOV DWORD PTR [EBP - 0X38], EAX |MOV DWORD PTR [EBP - 0X34], EAX |MOV DWORD PTR [EBP - 0X2C], EAX |MOV DWORD PTR [EBP - 0X28], EAX |MOV DWORD PTR [EBP - 0X14], EAX |MOV EAX, 0X4A2EBC |CALL 0X40FD3C |XOR EAX, EAX |
| Signatures |
| Certificate - Digital Signature: • The file is signed and the signature is correct |
| Packer/Compiler |
| Detect It Easy (die) • PE: installer: Inno Setup Module(6.3.0)[-] • PE: compiler: Embarcadero Delphi(XE2-XE6)[-] • PE: linker: Turbo Linker(2.25*,Delphi)[-] • PE: overlay: Inno Setup Installer data(-)[-] • Entropy: 7.89078 |
| Suspicious Functions |
| Library | Function | Description |
|---|---|---|
| KERNEL32.DLL | VirtualAlloc | Reserve, commit, or both, a region of memory within the virtual address space of a process. |
| KERNEL32.DLL | WriteFile | Writes data to a specified file or input/output (I/O) device. |
| KERNEL32.DLL | LoadLibraryA | Loads the specified module into the address space of the calling process. |
| KERNEL32.DLL | LoadLibraryW | Loads the specified module into the address space of the calling process. |
| KERNEL32.DLL | GetModuleHandleW | Retrieves a handle to the specified module. |
| KERNEL32.DLL | GetProcAddress | Retrieves the address of an exported function or variable from the specified dynamic-link library (DLL). |
| KERNEL32.DLL | CreateFileW | Creates or opens a file object. |
| KERNEL32.DLL | ReadFile | Reads data from a file. |
| KERNEL32.DLL | FindFirstFileW | Starts file and directory enumeration. |
| KERNEL32.DLL | FindClose | Closes a file search handle. |
| KERNEL32.DLL | ExitThread | Terminates the current thread. |
| KERNEL32.DLL | CloseHandle | Closes an open object handle. |
| KERNEL32.DLL | VirtualProtect | Changes memory protection attributes. |
| KERNEL32.DLL | CreateProcessW | Creates and starts a new process. |
| KERNEL32.DLL | ResumeThread | Resumes a suspended thread. |
| KERNEL32.DLL | CreateEventW | Creates or opens an event object. |
| KERNEL32.DLL | GetSystemInfo | Retrieves system hardware information. |
| KERNEL32.DLL | GetVersion | Retrieves the operating system version. |
| ADVAPI32.DLL | RegOpenKeyExW | Opens an existing registry key. |
| Windows REG |
| System\D |
| Windows REG (UNICODE) |
| Software\Embarcadero\Locales Software\CodeGear\Locales Software\Borland\Locales Software\Borland\Delphi\Locales SOFTWARE\Microsoft\Windows NT\CurrentVersion |
| File Access |
| winhttp.dll version.dll textshaping.dll netutils.dll netapi32.dll mpr.dll comctl32.dll kernel32.dll user32.dll advapi32.dll oleaut32.dll System.Sys dSystem.Sys PathFuncSystem.SysUtilsSystem.Internal.ExcUtilsSystem.Sys PathFuncSystem.Sys System.Sys ?System.Sys .dat Temp |
| File Access (UNICODE) |
| GetLogicalProcessorInformationkernel32.dll kernel32.dll DeskRest.exe shell32.dll ntmarta.dll clbcatq.dll comres.dll profapi.dll version.dll oleacc.dll cryptbase.dll dwmapi.dll propsys.dll apphelp.dll setupapi.dll userenv.dll uxtheme.dll advapi32.dll oleaut32.dll NTDLL.DLL ntdll.dll Temp UserProfile |
| Interest's Words |
| PADDINGX PassWord exec attrib start shutdown systeminfo ping expand |
| Interest's Words (UNICODE) |
| PassWord exec start shutdown ping expand |
| URLs |
| http://schemas.microsoft.com/SMI/2005/WindowsSettings http://ocsp.digicert.com http://cacerts.digicert.com/DigiCertTrustedRootG4.crt http://crl3.digicert.com/DigiCertTrustedRootG4.crl http://www.digicert.com/CPS0 http://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl http://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt http://cacerts.digicert.com/DigiCertTrustedG4TimeStampingRSA4096SHA2562025CA1.crt http://crl3.digicert.com/DigiCertTrustedG4TimeStampingRSA4096SHA2562025CA1.crl http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl |
| URLs (UNICODE) |
| https://jrsoftware.org/ishelp/index.php?topic=setupcmdline |
| Strings/Hex Code Found With The File Rules |
| Rule Type | Encoding | Matched (Word) |
|---|---|---|
| Text | Unicode | Privileges (SeShutdownPrivilege) |
| Text | Ascii | Process of gathering information about network resources (Enumeration) |
| Text | Unicode | Malicious rerouting of traffic to an attacker-controlled site (Redirect) |
| Text | Ascii | Technique used to capture communications between systems (Intercept) |
| Entry Point | Hex Pattern | Borland Delphi 4.0 |
| Entry Point | Hex Pattern | fasm - Tomasz Grysztar |
| Resources |
| Path | DataRVA | Size | FileOffset | Code | Text |
|---|---|---|---|---|---|
| \ICON\100\1033 | BA5B8 | 468 | ACDB8 | 280000001000000020000000010020000000000000040000C30E0000C30E0000000000000000000000000000000000000000 | (....... ..... ................................... |
| \ICON\101\1033 | BAA20 | 988 | AD220 | 280000001800000030000000010020000000000000090000C30E0000C30E0000000000000000000000000000000000000000 | (.......0..... ................................... |
| \ICON\102\1033 | BB3A8 | 10A8 | ADBA8 | 280000002000000040000000010020000000000000100000C30E0000C30E0000000000000000000000000000000000000000 | (... ...@..... ................................... |
| \ICON\103\1033 | BC450 | 25A8 | AEC50 | 280000003000000060000000010020000000000000240000C30E0000C30E0000000000000000000000000000000000000000 | (...0........ ......$............................ |
| \ICON\104\1033 | BE9F8 | 4228 | B11F8 | 280000004000000080000000010020000000000000400000C30E0000C30E0000000000000000000000000000000000000000 | (...@......... ......@............................ |
| \ICON\105\1033 | C2C20 | 5488 | B5420 | 280000004800000090000000010020000000000000510000C30E0000C30E0000000000000000000000000000000000000000 | (...H......... ......Q............................ |
| \ICON\106\1033 | C80A8 | 94A8 | BA8A8 | 2800000060000000C0000000010020000000000000900000C30E0000C30E0000000000000000000000000000000000000000 | (............ ................................... |
| \ICON\107\1033 | D1550 | 10828 | C3D50 | 280000008000000000010000010020000000000000000100C30E0000C30E0000000000000000000000000000000000000000 | (............. ................................... |
| \ICON\108\1033 | E1D78 | 1B8B | D4578 | 89504E470D0A1A0A0000000D49484452000001000000010008060000005C72A866000000016F724E5401CFA2779A00001B45 | .PNG........IHDR.............\r.f....orNT...w....E |
| \STRING\4086\0 | E3904 | 3F8 | D6104 | 1300570069006E0064006F00770073002000530065007200760065007200200032003000310036001300570069006E006400 | ..W.i.n.d.o.w.s. .S.e.r.v.e.r. .2.0.1.6...W.i.n.d. |
| \STRING\4087\0 | E3CFC | 2DC | D64FC | 3700560041005200200061006E00640020004F0055005400200061007200670075006D0065006E007400730020006D007500 | 7.V.A.R. .a.n.d. .O.U.T. .a.r.g.u.m.e.n.t.s. .m.u. |
| \STRING\4088\0 | E3FD8 | 430 | D67D8 | 1500500072006F0070006500720074007900200069007300200072006500610064002D006F006E006C007900170025007300 | ..P.r.o.p.e.r.t.y. .i.s. .r.e.a.d.-.o.n.l.y...%.s. |
| \STRING\4089\0 | E4408 | 44C | D6C08 | 1A00430061006E006E006F0074002000610073007300690067006E0020006100200025007300200074006F00200061002000 | ..C.a.n.n.o.t. .a.s.s.i.g.n. .a. .%.s. .t.o. .a. . |
| \STRING\4090\0 | E4854 | 2D4 | D7054 | 06004D006F006E006400610079000700540075006500730064006100790009005700650064006E0065007300640061007900 | ..M.o.n.d.a.y...T.u.e.s.d.a.y...W.e.d.n.e.s.d.a.y. |
| \STRING\4091\0 | E4B28 | B8 | D7328 | 03004D006100790004004A0075006E00650004004A0075006C00790006004100750067007500730074000900530065007000 | ..M.a.y...J.u.n.e...J.u.l.y...A.u.g.u.s.t...S.e.p. |
| \STRING\4092\0 | E4BE0 | 9C | D73E0 | 03004A0061006E00030046006500620003004D0061007200030041007000720003004D006100790003004A0075006E000300 | ..J.a.n...F.e.b...M.a.r...A.p.r...M.a.y...J.u.n... |
| \STRING\4093\0 | E4C7C | 374 | D747C | 140049006E00760061006C00690064002000760061007200690061006E0074002000740079007000650017004F0070006500 | ..I.n.v.a.l.i.d. .v.a.r.i.a.n.t. .t.y.p.e...O.p.e. |
| \STRING\4094\0 | E4FF0 | 398 | D77F0 | 2200560061007200690061006E00740020006D006500740068006F0064002000630061006C006C00730020006E006F007400 | ".V.a.r.i.a.n.t. .m.e.t.h.o.d. .c.a.l.l.s. .n.o.t. |
| \STRING\4095\0 | E5388 | 368 | D7B88 | 200049006E00760061006C0069006400200066006C006F006100740069006E006700200070006F0069006E00740020006F00 | .I.n.v.a.l.i.d. .f.l.o.a.t.i.n.g. .p.o.i.n.t. .o. |
| \STRING\4096\0 | E56F0 | 2A4 | D7EF0 | 2100270025007300270020006900730020006E006F007400200061002000760061006C0069006400200069006E0074006500 | !.’.%.s.’. .i.s. .n.o.t. .a. .v.a.l.i.d. .i.n.t.e. |
| \RCDATA\DVCLAL\0 | E5994 | 10 | D8194 | 23785D23B6A5F31943F3400226D111C7 | x]....C.@.&... |
| \RCDATA\PACKAGEINFO\0 | E59A4 | 310 | D81A4 | 000010CC0000000033000000010A53657475704C6472001C0F57696E6170692E516F73000CC457696E6170692E57696E646F | ........3.....SetupLdr...Winapi.Qos...Winapi.Windo |
| \RCDATA\11111\0 | E5CB4 | 2C | D84B4 | 72446C507453CDE6D77B0B2A0100000062DE5E0045F6510098FC30005EA7248AC484510000940D00A762B74C | rDlPtS...{.*....b..E.Q...0..$...Q......b.L |
| \GROUP_ICON\MAINICON\1033 | E5CE0 | 84 | D84E0 | 000001000900101000000100200068040000640018180000010020008809000065002020000001002000A810000066003030 | ............ .h...d....... .....e. .... .....f.00 |
| \VERSION\1\1033 | E5D64 | 584 | D8564 | 840534000000560053005F00560045005200530049004F004E005F0049004E0046004F0000000000BD04EFFE000001000000 | ..4...V.S._.V.E.R.S.I.O.N._.I.N.F.O............... |
| \24\1\1033 | E62E8 | 7A8 | D8AE8 | 3C3F786D6C2076657273696F6E3D22312E302220656E636F64696E673D225554462D3822207374616E64616C6F6E653D2279 | <?xml version="1.0" encoding="UTF-8" standalone="y |
| Intelligent String |
| • user32.dll • kernel32.dll • .tmp • oleaut32.dll • .bss • @.tls • ntdll.dll • NTDLL.DLL • advapi32.dll • x:\dirname" • For more detailed information, please visit https://jrsoftware.org/ishelp/index.php?topic=setupcmdline • uxtheme.dll • userenv.dll • setupapi.dll • apphelp.dll • propsys.dll • dwmapi.dll • cryptbase.dll • oleacc.dll • version.dll • profapi.dll • comres.dll • clbcatq.dll • ntmarta.dll • shell32.dll • GetThreadLocalecomctl32.dll • SafeArrayCreateadvapi32.dll • MessageBoxAkernel32.dll • <dpiAware xmlns="http://schemas.microsoft.com/SMI/2005/WindowsSettings">true</dpiAware> • :060U00Uq]dL.g?O0U0E1-Q!m0U0y+m0k0$+0http://ocsp.digicert.com0C+07http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0EU>0<0:864http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0U |
| Flow Anomalies |
| Offset | FlowVA | Section | Description |
|---|---|---|---|
| 4590 | 4B52DC | .text | JMP [static] | Indirect jump to absolute memory address |
| 4598 | 4B5310 | .text | JMP [static] | Indirect jump to absolute memory address |
| 45A0 | 4B5434 | .text | JMP [static] | Indirect jump to absolute memory address |
| 45A8 | 4B5408 | .text | JMP [static] | Indirect jump to absolute memory address |
| 45B0 | 4B53EC | .text | JMP [static] | Indirect jump to absolute memory address |
| 45B8 | 4B53A4 | .text | JMP [static] | Indirect jump to absolute memory address |
| 45C0 | 4B5384 | .text | JMP [static] | Indirect jump to absolute memory address |
| 45C8 | 4B53C4 | .text | JMP [static] | Indirect jump to absolute memory address |
| 45D0 | 4B543C | .text | JMP [static] | Indirect jump to absolute memory address |
| 45D8 | 4B5338 | .text | JMP [static] | Indirect jump to absolute memory address |
| 45E0 | 4B5370 | .text | JMP [static] | Indirect jump to absolute memory address |
| 45E8 | 4B535C | .text | JMP [static] | Indirect jump to absolute memory address |
| 45F0 | 4B5438 | .text | JMP [static] | Indirect jump to absolute memory address |
| 45F8 | 4B52FC | .text | JMP [static] | Indirect jump to absolute memory address |
| 4600 | 4B5354 | .text | JMP [static] | Indirect jump to absolute memory address |
| 4608 | 4B5308 | .text | JMP [static] | Indirect jump to absolute memory address |
| 4610 | 4B5374 | .text | JMP [static] | Indirect jump to absolute memory address |
| 4618 | 4B5328 | .text | JMP [static] | Indirect jump to absolute memory address |
| 4620 | 4B5318 | .text | JMP [static] | Indirect jump to absolute memory address |
| 4628 | 4B54B8 | .text | JMP [static] | Indirect jump to absolute memory address |
| 4630 | 4B53BC | .text | JMP [static] | Indirect jump to absolute memory address |
| 4638 | 4B532C | .text | JMP [static] | Indirect jump to absolute memory address |
| 4640 | 4B5314 | .text | JMP [static] | Indirect jump to absolute memory address |
| 4648 | 4B53C8 | .text | JMP [static] | Indirect jump to absolute memory address |
| 4650 | 4B539C | .text | JMP [static] | Indirect jump to absolute memory address |
| 4658 | 4B5368 | .text | JMP [static] | Indirect jump to absolute memory address |
| 4660 | 4B52D4 | .text | JMP [static] | Indirect jump to absolute memory address |
| 4668 | 4B540C | .text | JMP [static] | Indirect jump to absolute memory address |
| 4670 | 4B5404 | .text | JMP [static] | Indirect jump to absolute memory address |
| 4678 | 4B541C | .text | JMP [static] | Indirect jump to absolute memory address |
| 4680 | 4B53F0 | .text | JMP [static] | Indirect jump to absolute memory address |
| 4688 | 4B5458 | .text | JMP [static] | Indirect jump to absolute memory address |
| 4690 | 4B5470 | .text | JMP [static] | Indirect jump to absolute memory address |
| 4698 | 4B544C | .text | JMP [static] | Indirect jump to absolute memory address |
| 46A0 | 4B54B0 | .text | JMP [static] | Indirect jump to absolute memory address |
| 46A8 | 4B533C | .text | JMP [static] | Indirect jump to absolute memory address |
| 46D0 | 4B6094 | .text | JMP [static] | Indirect jump to absolute memory address |
| 46D8 | 4B5528 | .text | JMP [static] | Indirect jump to absolute memory address |
| 46E0 | 4B5508 | .text | JMP [static] | Indirect jump to absolute memory address |
| 46E8 | 4B551C | .text | JMP [static] | Indirect jump to absolute memory address |
| 46F0 | 4B534C | .text | JMP [static] | Indirect jump to absolute memory address |
| 46F8 | 4B53C0 | .text | JMP [static] | Indirect jump to absolute memory address |
| 4700 | 4B5394 | .text | JMP [static] | Indirect jump to absolute memory address |
| 4708 | 4B53F8 | .text | JMP [static] | Indirect jump to absolute memory address |
| 4710 | 4B5378 | .text | JMP [static] | Indirect jump to absolute memory address |
| 4718 | 4B54C8 | .text | JMP [static] | Indirect jump to absolute memory address |
| 4720 | 4B54E8 | .text | JMP [static] | Indirect jump to absolute memory address |
| 4728 | 4B54E4 | .text | JMP [static] | Indirect jump to absolute memory address |
| 4730 | 4B53F4 | .text | JMP [static] | Indirect jump to absolute memory address |
| 4758 | 4B6090 | .text | JMP [static] | Indirect jump to absolute memory address |
| 4760 | 4B52F8 | .text | JMP [static] | Indirect jump to absolute memory address |
| 4768 | 4B5300 | .text | JMP [static] | Indirect jump to absolute memory address |
| 4770 | 4B5400 | .text | JMP [static] | Indirect jump to absolute memory address |
| 4778 | 4B53E4 | .text | JMP [static] | Indirect jump to absolute memory address |
| 4780 | 4B53D4 | .text | JMP [static] | Indirect jump to absolute memory address |
| 47B4 | 4B53B8 | .text | JMP [static] | Indirect jump to absolute memory address |
| 47BC | 4B52F0 | .text | JMP [static] | Indirect jump to absolute memory address |
| 47C4 | 4B5380 | .text | JMP [static] | Indirect jump to absolute memory address |
| 47CC | 4B5434 | .text | JMP [static] | Indirect jump to absolute memory address |
| 6354 | 4A9774 | .text | CALL [static] | Indirect call to absolute memory address |
| 636C | 4A9768 | .text | CALL [static] | Indirect call to absolute memory address |
| 6388 | 4A976C | .text | CALL [static] | Indirect call to absolute memory address |
| 63A9 | 4A9770 | .text | CALL [static] | Indirect call to absolute memory address |
| 63C2 | 4A976C | .text | CALL [static] | Indirect call to absolute memory address |
| 63DB | 4A9768 | .text | CALL [static] | Indirect call to absolute memory address |
| 642F | 4AD028 | .text | CALL [static] | Indirect call to absolute memory address |
| 646E | 4AD010 | .text | CALL [static] | Indirect call to absolute memory address |
| 69E7 | 4A9044 | .text | CALL [static] | Indirect call to absolute memory address |
| 6A05 | 4A9040 | .text | CALL [static] | Indirect call to absolute memory address |
| 6AE8 | 4AD03C | .text | CALL [static] | Indirect call to absolute memory address |
| 6F3E | FFC0 | .text | JMP [static] | Indirect jump to absolute memory address |
| 80B0 | 4AD01C | .text | CALL [static] | Indirect call to absolute memory address |
| 80CE | 4AD01C | .text | CALL [static] | Indirect call to absolute memory address |
| 80E6 | 4AD01C | .text | CALL [static] | Indirect call to absolute memory address |
| 8158 | 4AD01C | .text | CALL [static] | Indirect call to absolute memory address |
| 8178 | 4AD01C | .text | CALL [static] | Indirect call to absolute memory address |
| 8195 | 4AD01C | .text | CALL [static] | Indirect call to absolute memory address |
| 8272 | 4AD020 | .text | CALL [static] | Indirect call to absolute memory address |
| 8377 | 4AD018 | .text | CALL [static] | Indirect call to absolute memory address |
| 83FA | 4AD020 | .text | CALL [static] | Indirect call to absolute memory address |
| 859A | 4AD01C | .text | JMP [static] | Indirect jump to absolute memory address |
| 8720 | 4AD020 | .text | CALL [static] | Indirect call to absolute memory address |
| 8AF7 | 4AD35C | .text | CALL [static] | Indirect call to absolute memory address |
| 8C74 | 4AD038 | .text | CALL [static] | Indirect call to absolute memory address |
| 8D1D | 4A9038 | .text | CALL [static] | Indirect call to absolute memory address |
| 8D82 | 4A903C | .text | CALL [static] | Indirect call to absolute memory address |
| A291 | 4A9010 | .text | CALL [static] | Indirect call to absolute memory address |
| A949 | 4A9014 | .text | CALL [static] | Indirect call to absolute memory address |
| AA30 | 4A9018 | .text | CALL [static] | Indirect call to absolute memory address |
| C26F | FF | .text | JMP [static] | Indirect jump to absolute memory address |
| C6AB | 4AFC04 | .text | CALL [static] | Indirect call to absolute memory address |
| C6C8 | 4AFC04 | .text | CALL [static] | Indirect call to absolute memory address |
| C6E9 | 4AFC0C | .text | CALL [static] | Indirect call to absolute memory address |
| C747 | 4AFC08 | .text | CALL [static] | Indirect call to absolute memory address |
| C7A4 | 4AFC08 | .text | CALL [static] | Indirect call to absolute memory address |
| C7D7 | 4AFC08 | .text | CALL [static] | Indirect call to absolute memory address |
| E8D9 | 4A9050 | .text | CALL [static] | Indirect call to absolute memory address |
| EADC | 4B5318 | .text | JMP [static] | Indirect jump to absolute memory address |
| EAE4 | 4B5314 | .text | JMP [static] | Indirect jump to absolute memory address |
| EAEC | 4B5460 | .text | JMP [static] | Indirect jump to absolute memory address |
| D9400 | N/A | *Overlay* | 7A6C621A16E694B7E00C5D0026968E700017F7EC | zlb.......].&..p.... |
| Extra Analysis |
| Metric | Value | Percentage |
|---|---|---|
| Ascii Code | 4138239 | 66,4488% |
| Null Byte Code | 263424 | 4,2299% |
© 2026 All rights reserved.