PESCAN.IO - Analysis Report Basic |
|||||||
| File Structure |
|
PE Chart Code
Header PE (light blue)
Executable sections (pink)
Non-executable sections (black)
External injected code (red)
File Structure in red = malformed or corrupted header
Chart Code For Other Files
Printable characters (blue)
Non-printable characters (black)
| Information |
Icon: Size: 2,65 MBSHA-256 Hash: 16133DC85FEC6BD94624219E920FCBD683DFCDFF6389B52E0BB4FC7F17BC37B0 SHA-1 Hash: 0AE01707B408DE530C18509D7DBBA9CCD1DF69AA MD5 Hash: 40E8C434F290BEECD135AE5EF995F265 Imphash: E036611C05048CE1B230596686EABD36 MajorOSVersion: 6 MinorOSVersion: 0 CheckSum: 002AB5F7 EntryPoint (rva): 1EE9AA SizeOfHeaders: 400 SizeOfImage: 2AD000 ImageBase: 400000 Architecture: x86 ImportTable: 28001C IAT: 22C000 Characteristics: 102 TimeDateStamp: 69357B74 Date: 07/12/2025 13:04:52 File Type: EXE Number Of Sections: 5 ASLR: Enabled Section Names: .text, .rdata, .data, .rsrc, .reloc Number Of Executable Sections: 1 Subsystem: Windows GUI UAC Execution Level Manifest: asInvoker |
| Sections Info |
| Section Name | Flags | ROffset | RSize | VOffset | VSize | Entropy | Chi2 |
|---|---|---|---|---|---|---|---|
| .text | 0x60000020 Code Executable Readable |
400 | 22AA00 | 1000 | 22A976 |
|
|
| .rdata | 0x40000040 Initialized Data Readable |
22AE00 | 56200 | 22C000 | 561DE |
|
|
| .data | 0xC0000040 Initialized Data Readable Writeable |
281000 | 6600 | 283000 | 93A4 |
|
|
| .rsrc | 0x40000040 Initialized Data Readable |
287600 | A600 | 28D000 | A455 |
|
|
| .reloc | 0x42000040 Initialized Data GP-Relative Readable |
291C00 | 14200 | 298000 | 14068 |
|
|
| Entry Point |
The section number (1) - (.text) have the Entry Point Information -> EntryPoint (calculated) - 1EDDAA Code -> E8800B0000E97AFEFFFFCCCCCCCCCCCCCCCCCCCCCCCC57565333FF8B4424140BC07D14478B542410F7D8F7DA83D800894424 Assembler |CALL 0X5EF52F |JMP 0X5EE82E |INT3 |INT3 |INT3 |INT3 |INT3 |INT3 |INT3 |INT3 |INT3 |INT3 |INT3 |INT3 |PUSH EDI |PUSH ESI |PUSH EBX |XOR EDI, EDI |MOV EAX, DWORD PTR [ESP + 0X14] |OR EAX, EAX |JGE 0X5EE9E1 |INC EDI |MOV EDX, DWORD PTR [ESP + 0X10] |NEG EAX |NEG EDX |SBB EAX, 0 |
| Signatures |
| Rich Signature Analyzer: Code -> F9DE845CBDBFEA0FBDBFEA0FBDBFEA0FF6C7E90EB0BFEA0FF6C7EF0E70BFEA0FF6C7EE0EAABFEA0FB4C7790FBFBFEA0FA8C0170FBABFEA0FA8C0EE0EAFBFEA0FA8C0EF0ED5BFEA0FA8C0E90EA6BFEA0FF6C7EC0EBFBFEA0FBDBFEB0F17BEEA0FF6C7EB0E9EBFEA0F843FEE0E1FBFEA0F843FE30EAFBFEA0F843F150FBCBFEA0F843FE80EBCBFEA0F52696368BDBFEA0F Footprint md5 Hash -> BC974EA001F1C14D025DFD5E29CD2278 • The Rich header apparently has not been modified Certificate - Digital Signature Not Found: • The file is not signed |
| Packer/Compiler |
| Compiler: Microsoft Visual C ++ Detect It Easy (die) • PE: compiler: EP:Microsoft Visual C/C++(2017 v.15.5-6)[EXE32] • PE: compiler: Microsoft Visual C/C++(-)[-] • PE: linker: Microsoft Linker(14.37**)[-] • Entropy: 6.65749 |
| Suspicious Functions |
| Library | Function | Description |
|---|---|---|
| Ws2_32.DLL | connect | Possible Call API By Name | Establish a connection to a specified socket. |
| KERNEL32.DLL | CreateMutexW | Create a named or unnamed mutex object for controlling access to a shared resource. |
| KERNEL32.DLL | GetModuleFileNameA | Retrieve the fully qualified path for the executable file of a specified module. |
| KERNEL32.DLL | GetModuleHandleA | Retrieves a handle to the specified module. |
| KERNEL32.DLL | CopyFileW | Copies an existing file to a new file. |
| KERNEL32.DLL | WriteFile | Writes data to a specified file or input/output (I/O) device. |
| KERNEL32.DLL | LoadLibraryA | Loads the specified module into the address space of the calling process. |
| KERNEL32.DLL | LoadLibraryW | Loads the specified module into the address space of the calling process. |
| KERNEL32.DLL | CreateToolhelp32Snapshot | Creates a snapshot of the specified processes, heaps, threads, and modules. |
| KERNEL32.DLL | GetProcAddress | Retrieves the address of an exported function or variable from the specified dynamic-link library (DLL). |
| KERNEL32.DLL | CreateFileA | Creates or opens a file or I/O device. |
| KERNEL32.DLL | DeleteFileA | Deletes an existing file. |
| KERNEL32.DLL | IsDebuggerPresent | Determines if the calling process is being debugged by a user-mode debugger. |
| KERNEL32.DLL | SleepEx | Pauses the execution of the current thread, optionally allowing the thread to be awakened by a kernel object or upon expiration of a timeout. |
| Ws2_32.DLL | socket | Create a communication endpoint for networking applications. |
| Ws2_32.DLL | connect | Establish a connection to a specified socket. |
| ADVAPI32.DLL | CryptEncrypt | Performs a cryptographic operation on data in a data block. |
| ADVAPI32.DLL | CryptDecrypt | Performs a cryptographic operation on data in a data block. |
| SHELL32.DLL | ShellExecuteW | Performs a run operation on a specific file. |
| SHELL32.DLL | ShellExecuteExW | Performs a run operation on a specific file. |
| Windows REG (UNICODE) |
| Software\Brave-Browser\Application\brave.exe Software\Microsoft\Windows\CurrentVersion\Uninstall\{53F49750-6209-4FBF-9CA8-7A333C87D1ED}_is1 SOFTWARE\Microsoft\Windows\CurrentVersion\Run SOFTWARE\Policies\Google\Chrome SOFTWARE\Policies\Microsoft\Edge SOFTWARE\Policies\BraveSoftware\Brave Software\Brave Software\Brave-Browser\User Data\Default Software\Opera GX Stable Software\Opera GX Software\Brave-Browser\User Data Software\Opera Stable Software\Microsoft\Windows\CurrentVersion\Run SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\ SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\App Paths\ Software\Brave-Browser\User Data\ Software\Opera Stable\ Software\Opera GX Stable\Local Extension Settings\ Software\Opera GX Stable\Local Extension Settings SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall Rebuilt string - SOFTWARE\Microsoft\Windows\CurrentVersion\Run |
| File Access |
| opera.exe browser.exe brave.exe msedge.exe chrome.exe lsass.exe WINMM.dll AVICAP32.dll gdiplus.dll ncrypt.dll bcrypt.dll SHLWAPI.dll api-ms-win-shcore-scaling-l1-1-1.dll OLEAUT32.dll ole32.dll SHELL32.dll GDI32.dll USER32.dll KERNEL32.dll ADVAPI32.dll CRYPT32.dll WLDAP32.dll WS2_32.dll secur32.dll security.dll iphlpapi.dll .dat @.dat CreditCards.txt BrowserPasswords.txt BrowserAutoFills.txt BrowserDownloads.txt ].txt .txt Temp AppData UserProfile |
| File Access (UNICODE) |
| \Google\Chrome\Application\chrome.exe \Microsoft\Edge\Application\msedge.exe cmd.exe powershell.exe brave.exe msedge.exe chrome.exe cain.exe regmon.exe filemon.exe wireshark.exe tcpview.exe netmon.exe netstat.exe processhacker.exe testversion.exe - kill a process by name, must not add .exe - Show the path to process, must not add .exe lsass.exe shutdown.exe Telegram.exe ntdll.dll cmdvrt32.dll snxhk.dll Sf2.dll SxIn.dll SbieDll.dll mscoree.dll kernel32.dll token_buffer.dat text.txt - CreditCards.txt - BrowserPasswords.txt - BrowserAutoFills.txt - BrowserDownloads.txt tokens.txt com/attatier/Cloud/main/Mil2.txt com/attatier/Cloud/main/MilInfo.txt keylogs.txt \Users\User\1.txt \Users\User\Downloads\1.txt pdf, .txt *getDesktop - grab useful desktop files (.pdf tdata.zip Browser History.zip Browser data.zip desktop.zip Exec - cmd.exe /u /c Exec - powershell.exe -Command " Temp AppData |
| SQL Queries |
| SELECT 1 FROM "%w".sqlite_master WHERE name NOT LIKE 'sqliteX_%%' ESCAPE 'X' AND sql NOT LIKE 'create virtual%%' AND sqlite_rename_test(%Q, sql, type, name, %d, %Q, %d)=NULL SELECT 1 FROM temp.sqlite_master WHERE name NOT LIKE 'sqliteX_%%' ESCAPE 'X' AND sql NOT LIKE 'create virtual%%' AND sqlite_rename_test(%Q, sql, type, name, 1, %Q, %d)=NULL SELECT raise(ABORT,%Q) FROM "%w"."%w" SELECT CASE WHEN quick_check GLOB 'CHECK*' THEN raise(ABORT,'CHECK constraint failed') WHEN quick_check GLOB 'non-* value in*' THEN raise(ABORT,'type mismatch on DEFAULT') ELSE raise(ABORT,'NOT NULL constraint failed') END FROM pragma_quick_check(%Q,%Q) WHERE quick_check GLOB 'CHECK*' OR quick_check GLOB 'NULL*' OR quick_check GLOB 'non-* value in*' SELECT tbl,idx,stat FROM %Q.sqlite_stat1 SELECT sql FROM "%w".sqlite_schema WHERE type='table'AND name<>'sqlite_sequence' AND coalesce(rootpage,1)>0 SELECT sql FROM "%w".sqlite_schema WHERE type='index' SELECT * FROM Win32_ComputerSystem SELECT * FROM Win32_VideoController SELECT host_key, name, path, encrypted_value, expires_utc, is_secure, is_httponly FROM cookies SELECT name_on_card, expiration_month, expiration_year, card_number_encrypted FROM credit_cards SELECT action_url, username_value, password_value FROM logins SELECT tab_url, target_path FROM downloads SELECT name, value FROM autofill SELECT company_name, street_address, city, state, zipcode, country_code FROM autofill_profiles SELECT first_name, middle_name, last_name FROM autofill_profile_names SELECT email FROM autofill_profile_emails SELECT number FROM autofill_profile_phones SELECT url FROM urls SELECT host, path, name, value, isSecure, isHttpOnly, expiry FROM moz_cookies SELECT url FROM moz_places WHERE url IS NOT NULL SELECT * FROM Win32_OperatingSystem INSERT INTO %Q.sqlite_master VALUES('index',%Q,%Q,%d,%Q); INSERT into generated column "%s" INSERT INTO %Q.sqlite_master VALUES('trigger',%Q,%Q,0,'CREATE TRIGGER %q') INSERT INTO %s.'||quote(name)||' SELECT*FROM"%w".'||quote(name)FROM %s.sqlite_schema WHERE type='table'AND coalesce(rootpage,1)>0 INSERT INTO %s.sqlite_schema SELECT*FROM "%w".sqlite_schema WHERE type IN('view','trigger') OR(type='table'AND rootpage=0) CREATE TABLE %Q.%s(%s) CREATE TABLE CREATE TABLE %Q.sqlite_sequence(name,seq) CREATE TABLE x CREATE TABLE x(type text,name text,tbl_name text,rootpage int,sql text) CREATE TABLE x(key,value,type,atom,id,parent,fullkey,path,json HIDDEN,root HIDDEN) DROP TABLE to delete table %s DELETE FROM %Q.%s WHERE %s=%Q DELETE FROM %Q.sqlite_sequence WHERE name=%Q DELETE FROM %Q.sqlite_master WHERE tbl_name=%Q and type!='trigger' DELETE FROM %Q.sqlite_master WHERE name=%Q AND type='index' DELETE FROM %Q.sqlite_master WHERE name=%Q AND type='trigger' SELECT Name FROM Win32_Processor SELECT Name FROM Win32_VideoController SELECT TotalPhysicalMemory FROM Win32_ComputerSystem SELECT ProcessorId FROM Win32_Processor SELECT * FROM AntivirusProduct |
| Interest's Words |
| rcpt to: JFIF smtp Encrypt Decrypt Encryption PassWord exec attrib start pause cipher hostname shutdown systeminfo ping expand replace |
| Interest's Words (UNICODE) |
| Virus Encrypt Decrypt KeyLogger Encryption PassWord exec powershell start shutdown netstat systeminfo at.exe |
| Anti-VM/Sandbox/Debug Tricks (UNICODE) |
| LabTools - wireshark LabTools - filemon LabTools - regmon SandBoxie Library - SbieDll.dll |
| URLs |
| http://localhost:9222/json http://ip-api.com/json/ https://curl.se/docs/http-cookies.html https://curl.se/docs/alt-svc.html https://curl.se/docs/hsts.html https://api.telegram.org/ https://upload.gofile.io/uploadfile |
| URLs (UNICODE) |
| https://raw.githubusercontent.com/attatier/Cloud/main/MilInfo.txt https://raw.githubusercontent.com/attatier/Cloud/main/Mil2.txt |
| AV Services (UNICODE) |
| securitycenter2.exe - (SecurityCenter2) |
| IP Addresses |
| 127.0.0.1 2.5.29.17 2.5.4.10 2.5.4.11 2.5.4.12 2.5.4.13 2.5.4.17 2.5.4.41 2.5.4.42 2.5.4.43 2.5.4.44 2.5.4.45 2.5.4.46 2.5.4.65 2.5.4.72 2.5.29.18 2.5.29.19 |
| Strings/Hex Code Found With The File Rules |
| Rule Type | Encoding | Matched (Word) |
|---|---|---|
| Text | Ascii | Unicode escape - \u00 - (Common Unicode escape sequences) |
| Text | Ascii | WinAPI Sockets (bind) |
| Text | Ascii | WinAPI Sockets (listen) |
| Text | Ascii | WinAPI Sockets (accept) |
| Text | Ascii | WinAPI Sockets (connect) |
| Text | Unicode | WinAPI Sockets (connect) |
| Text | Ascii | WinAPI Sockets (recv) |
| Text | Ascii | WinAPI Sockets (send) |
| Text | Unicode | WinAPI Sockets (send) |
| Text | Ascii | Registry (RegCreateKeyEx) |
| Text | Ascii | Registry (RegOpenKeyEx) |
| Text | Ascii | Registry (RegSetValueEx) |
| Text | Ascii | File (GetTempPath) |
| Text | Ascii | File (CopyFile) |
| Text | Ascii | File (CreateFile) |
| Text | Ascii | File (WriteFile) |
| Text | Ascii | File (ReadFile) |
| Text | Ascii | Encryption (Microsoft Unified Security Protocol Provider) |
| Text | Ascii | Encryption API (CryptAcquireContext) |
| Text | Ascii | Encryption API (CryptDecrypt) |
| Text | Ascii | Encryption API (CryptReleaseContext) |
| Hex | Hex Pattern | PEB AntiDebug (Flag BeingDebugged) |
| Text | Ascii | Anti-Analysis VM (IsDebuggerPresent) |
| Text | Ascii | Anti-Analysis VM (GetSystemInfo) |
| Text | Ascii | Anti-Analysis VM (GetVersion) |
| Text | Ascii | Anti-Analysis VM (CreateToolhelp32Snapshot) |
| Text | Ascii | Reconnaissance (FindFirstFileW) |
| Text | Ascii | Reconnaissance (FindNextFileW) |
| Text | Ascii | Reconnaissance (FindClose) |
| Text | Ascii | Stealth (ExitThread) |
| Text | Ascii | Stealth (CloseHandle) |
| Text | Ascii | Stealth (UnmapViewOfFile) |
| Text | Ascii | Stealth (MapViewOfFile) |
| Text | Ascii | Stealth (CreateFileMappingA) |
| Text | Ascii | Stealth (CreateFileMappingW) |
| Text | Ascii | Execution (CreateProcessA) |
| Text | Ascii | Execution (CreateProcessW) |
| Text | Ascii | Execution (ShellExecute) |
| Text | Ascii | Execution (CreateEventA) |
| Text | Ascii | Privileges (SeDebugPrivilege) |
| Text | Unicode | Keyboard Key ([Tab]) |
| Text | Unicode | Keyboard Key ([Shift]) |
| Text | Unicode | Keyboard Key ([WIN]) |
| Text | Unicode | WMI execution (ROOT\CIMV2) |
| Text | Unicode | Malware designed to intercept and exfiltrate credit card details from compromised systems (Credit Card) |
| Text | Ascii | Information used for user authentication (Credential) |
| Text | Ascii | Unauthorized movement of funds or data (Transfer) |
| Entry Point | Hex Pattern | Microsoft Visual C++ 8 |
| Entry Point | Hex Pattern | Microsoft Visual C++ 8 |
| Entry Point | Hex Pattern | VC8 - Microsoft Corporation |
| Resources |
| Path | DataRVA | Size | FileOffset | Code | Text |
|---|---|---|---|---|---|
| \ICON\1\0 | 28D164 | 128 | 287764 | 2800000010000000200000000100040000000000C00000000000000000000000100000000000000000000000000080000080 | (....... ......................................... |
| \ICON\2\0 | 28D28C | 2E8 | 28788C | 2800000020000000400000000100040000000000800200000000000000000000100000000000000000000000000080000080 | (... ...@......................................... |
| \RCDATA\11\0 | 28D574 | 9D3E | 287B74 | 5800670042007A0041004100450041005A00670042002F004100460030004100620077004100420041004100630041004400 | X.g.B.z.A.A.E.A.Z.g.B./.A.F.0.A.b.w.A.B.A.A.c.A.D. |
| \GROUP_ICON\$\0 | 2972B4 | 22 | 2918B4 | 00000100020010101000010004002801000001002020100001000400E80200000200 | ..............(..... ............ |
| \24\1\1033 | 2972D8 | 17D | 2918D8 | 3C3F786D6C2076657273696F6E3D27312E302720656E636F64696E673D275554462D3827207374616E64616C6F6E653D2779 | <?xml version='1.0' encoding='UTF-8' standalone='y |
| Intelligent String |
| • chrome.exe • .txt • .png • .jpg • .gif • .svg • .htm • application/pdf.xml • Could not read a file:// file • Login denied • Bad login part • Bad file:// URLUnsupported number of slashes following scheme • https://curl.se/docs/http-cookies.html • %s cached session ID for %s://%s:%dPROXY • Failed to add Session ID to cache for %s://%s:%d [%s] • Added Session ID to cache for %s://%s:%d [%s] • %s://%sURL rejected: %s • iphlpapi.dll • Your alt-svc cache. https://curl.se/docs/alt-svc.html • Your HSTS cache. https://curl.se/docs/hsts.html • %s%s.tmp • LOGIN %s %sAUTHENTICATE %s %s • Got unexpected imap-server responseLOGINDISABLED • AUTH=+LOGINUIDVALIDITYMAILINDEX • failed to resume file:// transfer • file://%s%s%s • machinelogin • security.dll • 2.5.29.17 • 1.2.840.10045.4.3.2ecdsa-with-SHA256 • 1.2.840.10045.4.3.3ecdsa-with-SHA384 • 1.2.840.10045.4.3.4ecdsa-with-SHA512 • 2.5.4.10 • 2.5.4.11 • 2.5.4.12 • 2.5.4.13 • 2.5.4.41 • 2.5.4.42 • 2.5.4.43 • 2.5.4.44 • 2.5.4.46 • 2.5.4.72 • 2.5.29.18 • 2.5.29.19 • LOGIN • kernel32.dll • IND)ind).cmd • .bat • .com • mscoree.dll • ws://%[:/]ERROR: Could not parse WebSocket url: %s • C:\Users\attat\source\repos\Millenium RAT Builder V4.3\Stub\libs\miniz.c • \u0009 • \u00 • \u0000 • SbieDll.dll • SxIn.dll • Sf2.dll • snxhk.dll • cmdvrt32.dll • runas • cmd.exe • C:\Program Files\Telegram Desktop\tdata • Telegram.exe • dumps • shutdown.exe • ntdll.dll • C:\Users\attat\source\repos\Millenium RAT Builder V4.3\Stub\libs\json.hpp • Failed to init curlCurl failedhttp://localhost:9222/json • invalid string: control character U+0000 (NUL) must be escaped to \u0000 • invalid string: control character U+0001 (SOH) must be escaped to \u0001 • invalid string: control character U+0002 (STX) must be escaped to \u0002 • invalid string: control character U+0003 (ETX) must be escaped to \u0003 • invalid string: control character U+0004 (EOT) must be escaped to \u0004 • invalid string: control character U+0005 (ENQ) must be escaped to \u0005 • invalid string: control character U+0006 (ACK) must be escaped to \u0006 • invalid string: control character U+0007 (BEL) must be escaped to \u0007 • invalid string: control character U+0008 (BS) must be escaped to \u0008 or \b • invalid string: control character U+0009 (HT) must be escaped to \u0009 or \t • invalid string: control character U+000A (LF) must be escaped to \u000A or \n • invalid string: control character U+000B (VT) must be escaped to \u000Binvalid string: control character U+000C (FF) must be escaped to \u000C or \f • invalid string: control character U+000D (CR) must be escaped to \u000D or \r • invalid string: control character U+000E (SO) must be escaped to \u000Einvalid string: control character U+000F (SI) must be escaped to \u000Finvalid string: control character U+0010 (DLE) must be escaped to \u0010 • invalid string: control character U+0011 (DC1) must be escaped to \u0011 • invalid string: control character U+0012 (DC2) must be escaped to \u0012 • invalid string: control character U+0013 (DC3) must be escaped to \u0013 • invalid string: control character U+0014 (DC4) must be escaped to \u0014 • invalid string: control character U+0015 (NAK) must be escaped to \u0015 • invalid string: control character U+0016 (SYN) must be escaped to \u0016 • invalid string: control character U+0017 (ETB) must be escaped to \u0017 • invalid string: control character U+0018 (CAN) must be escaped to \u0018 • invalid string: control character U+0019 (EM) must be escaped to \u0019invalid string: control character U+001A (SUB) must be escaped to \u001A • invalid string: control character U+001B (ESC) must be escaped to \u001B • invalid string: control character U+001C (FS) must be escaped to \u001Cinvalid string: control character U+001D (GS) must be escaped to \u001Dinvalid string: control character U+001E (RS) must be escaped to \u001Einvalid string: control character U+001F (US) must be escaped to \u001Finvalid string: ill-formed UTF-8 byte • lsass.exe • lsass.exe not foundDuplicateToken failed • SELECT action_url, username_value, password_value FROM logins • *cmd*<command> - run a cmd command on victims PC • *processpath*<process name, e.g. discord, Telegram etc> - Show the path to process, must not add .exe • *processkill*<process name, e.g. discord, Telegram etc> - kill a process by name, must not add .exe • C:\Users • C:\Users\User\Downloads\1.txt*C:\Users\User\1.txt • keylogs.txt • audio.wav • .zip • desktop.zip • testversion.exe • https://raw.githubusercontent.com/attatier/Cloud/main/MilInfo.txt • https://raw.githubusercontent.com/attatier/Cloud/main/Mil2.txt • test.key • processhacker.exe • netstat.exe • netmon.exe • tcpview.exe • wireshark.exe • filemon.exe • regmon.exe • cain.exe • .cpp • .lnk • .bmp • .psd • .doc • .xls • .ppt • .odt • .csv • .sql • .mdb • .sln • .php • .asp • .xml • .jar • .asm • .ldb • tokens.txt • ].txt • \Login Data • msedge.exe • brave.exe • cookies/Brave [brave.exe • opera.exe • BrowserDownloads.txt • BrowserAutoFills.txt • BrowserPasswords.txt • CreditCards.txt • Browser data.zip • Browser History.zip • tdata.zip • https://upload.gofile.io/uploadfiledata • http://ip-api.com/json/undefined • text.txt • cmd /c timeout /t 3 /nobreak & rd /s /q " • cmd /c timeout /t 3 /nobreak & del /f /q " • C:\Program Files\Google\Chrome\Application\chrome.exe • C:\Program Files (x86)\Google\Chrome\Application\chrome.exe • \Google\Chrome\Application\chrome.exe • C:\Program Files\Microsoft\Edge\Application\msedge.exe • C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe • \Microsoft\Edge\Application\msedge.exe • C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe • C:\Program Files (x86)\BraveSoftware\Brave-Browser\Application\brave.exe • \BraveSoftware\Brave-Browser\Application\brave.exe • screenshot.png • .exe • .dll • cmd.exe /u /c • 'The CMD command was executed successfully • Unknown error: failed to execute the CMD command • powershell.exe -Command " • .tls • .bss • WS2_32.dll • api-ms-win-shcore-scaling-l1-1-1.dll • @NCryptDecryptncrypt.dll • gdiplus.dll |
| Flow Anomalies |
| Offset | FlowVA | Section | Description |
|---|---|---|---|
| 1EDB | 62C534 | .text | CALL [static] | Indirect call to absolute memory address |
| 1F7E | 62C534 | .text | CALL [static] | Indirect call to absolute memory address |
| 1FEE | 62C548 | .text | CALL [static] | Indirect call to absolute memory address |
| 1FFE | 62C514 | .text | CALL [static] | Indirect call to absolute memory address |
| 200B | 62C514 | .text | CALL [static] | Indirect call to absolute memory address |
| 20C1 | 62C53C | .text | CALL [static] | Indirect call to absolute memory address |
| 21B8 | 62C530 | .text | CALL [static] | Indirect call to absolute memory address |
| 21F2 | 62C530 | .text | CALL [static] | Indirect call to absolute memory address |
| 2231 | 62C530 | .text | CALL [static] | Indirect call to absolute memory address |
| 2ED2 | 62C538 | .text | CALL [static] | Indirect call to absolute memory address |
| 2EF5 | 62C18C | .text | CALL [static] | Indirect call to absolute memory address |
| 2F4D | 62C540 | .text | CALL [static] | Indirect call to absolute memory address |
| 2F61 | 62C544 | .text | CALL [static] | Indirect call to absolute memory address |
| 2F6D | 62C530 | .text | CALL [static] | Indirect call to absolute memory address |
| 2F82 | 62C54C | .text | CALL [static] | Indirect call to absolute memory address |
| 3045 | 62C53C | .text | CALL [static] | Indirect call to absolute memory address |
| 310B | 62C53C | .text | CALL [static] | Indirect call to absolute memory address |
| 314A | 62C53C | .text | CALL [static] | Indirect call to absolute memory address |
| 319C | 62C53C | .text | CALL [static] | Indirect call to absolute memory address |
| 31DB | 62C53C | .text | CALL [static] | Indirect call to absolute memory address |
| 321A | 62C53C | .text | CALL [static] | Indirect call to absolute memory address |
| 3259 | 62C53C | .text | CALL [static] | Indirect call to absolute memory address |
| 3295 | 62C548 | .text | CALL [static] | Indirect call to absolute memory address |
| 3348 | 62C548 | .text | CALL [static] | Indirect call to absolute memory address |
| 3388 | 62C554 | .text | CALL [static] | Indirect call to absolute memory address |
| 33A1 | 62C550 | .text | CALL [static] | Indirect call to absolute memory address |
| 8426 | 684658 | .text | CALL [static] | Indirect call to absolute memory address |
| 8467 | 684660 | .text | CALL [static] | Indirect call to absolute memory address |
| 8507 | 684658 | .text | CALL [static] | Indirect call to absolute memory address |
| 86A2 | 684684 | .text | CALL [static] | Indirect call to absolute memory address |
| 86B0 | 684634 | .text | CALL [static] | Indirect call to absolute memory address |
| 8778 | 684638 | .text | CALL [static] | Indirect call to absolute memory address |
| 879C | 684634 | .text | CALL [static] | Indirect call to absolute memory address |
| 87B5 | 684634 | .text | CALL [static] | Indirect call to absolute memory address |
| 87CE | 684634 | .text | CALL [static] | Indirect call to absolute memory address |
| 87E7 | 684634 | .text | CALL [static] | Indirect call to absolute memory address |
| 88F1 | 684660 | .text | CALL [static] | Indirect call to absolute memory address |
| C10D | 684658 | .text | CALL [static] | Indirect call to absolute memory address |
| C117 | 684634 | .text | CALL [static] | Indirect call to absolute memory address |
| C12D | 68462C | .text | CALL [static] | Indirect call to absolute memory address |
| C140 | 684660 | .text | CALL [static] | Indirect call to absolute memory address |
| C157 | 68462C | .text | CALL [static] | Indirect call to absolute memory address |
| C1AB | 684658 | .text | CALL [static] | Indirect call to absolute memory address |
| C1B5 | 684634 | .text | CALL [static] | Indirect call to absolute memory address |
| C1C8 | 68462C | .text | CALL [static] | Indirect call to absolute memory address |
| C1DB | 684660 | .text | CALL [static] | Indirect call to absolute memory address |
| C1E7 | 68462C | .text | CALL [static] | Indirect call to absolute memory address |
| C224 | 684650 | .text | CALL [static] | Indirect call to absolute memory address |
| C234 | 684658 | .text | CALL [static] | Indirect call to absolute memory address |
| C28B | 684660 | .text | CALL [static] | Indirect call to absolute memory address |
| C2BF | 684650 | .text | CALL [static] | Indirect call to absolute memory address |
| C2CF | 684658 | .text | CALL [static] | Indirect call to absolute memory address |
| C340 | 684660 | .text | CALL [static] | Indirect call to absolute memory address |
| C36B | 684650 | .text | CALL [static] | Indirect call to absolute memory address |
| C37B | 684658 | .text | CALL [static] | Indirect call to absolute memory address |
| C3CD | 684660 | .text | CALL [static] | Indirect call to absolute memory address |
| C59D | 684648 | .text | CALL [static] | Indirect call to absolute memory address |
| C5C3 | 684650 | .text | JMP [static] | Indirect jump to absolute memory address |
| C5EE | 684654 | .text | JMP [static] | Indirect jump to absolute memory address |
| C60E | 684658 | .text | JMP [static] | Indirect jump to absolute memory address |
| C62E | 68465C | .text | JMP [static] | Indirect jump to absolute memory address |
| C64E | 684660 | .text | JMP [static] | Indirect jump to absolute memory address |
| C6B9 | 685B58 | .text | CALL [static] | Indirect call to absolute memory address |
| C78F | 62C1C4 | .text | CALL [static] | Indirect call to absolute memory address |
| C7B4 | 62C268 | .text | CALL [static] | Indirect call to absolute memory address |
| C7CD | 684658 | .text | CALL [static] | Indirect call to absolute memory address |
| C7D7 | 684634 | .text | CALL [static] | Indirect call to absolute memory address |
| C7EA | 68462C | .text | CALL [static] | Indirect call to absolute memory address |
| C801 | 684660 | .text | JMP [static] | Indirect jump to absolute memory address |
| C808 | 68462C | .text | CALL [static] | Indirect call to absolute memory address |
| C826 | 62C1A8 | .text | CALL [static] | Indirect call to absolute memory address |
| C853 | 62C19C | .text | CALL [static] | Indirect call to absolute memory address |
| C876 | 62C1C0 | .text | CALL [static] | Indirect call to absolute memory address |
| C8AC | 684658 | .text | CALL [static] | Indirect call to absolute memory address |
| C8E7 | 684660 | .text | CALL [static] | Indirect call to absolute memory address |
| C96A | 684660 | .text | CALL [static] | Indirect call to absolute memory address |
| C97E | 684658 | .text | CALL [static] | Indirect call to absolute memory address |
| C985 | 684660 | .text | CALL [static] | Indirect call to absolute memory address |
| C9E6 | 684658 | .text | CALL [static] | Indirect call to absolute memory address |
| CA4D | 684660 | .text | CALL [static] | Indirect call to absolute memory address |
| CA83 | 684658 | .text | CALL [static] | Indirect call to absolute memory address |
| CA97 | 684660 | .text | CALL [static] | Indirect call to absolute memory address |
| CAC3 | 684658 | .text | CALL [static] | Indirect call to absolute memory address |
| CAE9 | 684660 | .text | CALL [static] | Indirect call to absolute memory address |
| CB44 | 684658 | .text | CALL [static] | Indirect call to absolute memory address |
| CB4E | 684638 | .text | CALL [static] | Indirect call to absolute memory address |
| CBB8 | 684660 | .text | CALL [static] | Indirect call to absolute memory address |
| CBCC | 684658 | .text | CALL [static] | Indirect call to absolute memory address |
| CC0C | 684628 | .text | CALL [static] | Indirect call to absolute memory address |
| CC1C | 684634 | .text | CALL [static] | Indirect call to absolute memory address |
| CC64 | 684660 | .text | CALL [static] | Indirect call to absolute memory address |
| CC76 | 684628 | .text | CALL [static] | Indirect call to absolute memory address |
| CCFB | 684634 | .text | CALL [static] | Indirect call to absolute memory address |
| CD2E | 684658 | .text | CALL [static] | Indirect call to absolute memory address |
| CD38 | 684634 | .text | CALL [static] | Indirect call to absolute memory address |
| CD4B | 68462C | .text | CALL [static] | Indirect call to absolute memory address |
| CD62 | 684660 | .text | JMP [static] | Indirect jump to absolute memory address |
| CD69 | 68462C | .text | CALL [static] | Indirect call to absolute memory address |
| CDBC | 684634 | .text | CALL [static] | Indirect call to absolute memory address |
| CE35 | 684658 | .text | CALL [static] | Indirect call to absolute memory address |
| 54351-5436F | N/A | .text | Unusual BP Cave, count: 31 |
| 7E382-7E39F | N/A | .text | Unusual BP Cave, count: 30 |
| 16A082-16A09F | N/A | .text | Unusual BP Cave, count: 30 |
| Extra Analysis |
| Metric | Value | Percentage |
|---|---|---|
| Ascii Code | 1643260 | 59,183% |
| Null Byte Code | 404799 | 14,5791% |
© 2026 All rights reserved.