PESCAN.IO - Analysis Report Basic

File Structure
Analysis Image
PE Chart Code
Header PE (light blue)
Executable sections (pink)
Non-executable sections (black)
External injected code (red)
File Structure in red = malformed or corrupted header

Chart Code For Other Files
Printable characters (blue)
Non-printable characters (black)
Information
Icon: Icon
Size: 2,65 MB
SHA-256 Hash: 16133DC85FEC6BD94624219E920FCBD683DFCDFF6389B52E0BB4FC7F17BC37B0
SHA-1 Hash: 0AE01707B408DE530C18509D7DBBA9CCD1DF69AA
MD5 Hash: 40E8C434F290BEECD135AE5EF995F265
Imphash: E036611C05048CE1B230596686EABD36
MajorOSVersion: 6
MinorOSVersion: 0
CheckSum: 002AB5F7
EntryPoint (rva): 1EE9AA
SizeOfHeaders: 400
SizeOfImage: 2AD000
ImageBase: 400000
Architecture: x86
ImportTable: 28001C
IAT: 22C000
Characteristics: 102
TimeDateStamp: 69357B74
Date: 07/12/2025 13:04:52
File Type: EXE
Number Of Sections: 5
ASLR: Enabled
Section Names: .text, .rdata, .data, .rsrc, .reloc
Number Of Executable Sections: 1
Subsystem: Windows GUI
UAC Execution Level Manifest: asInvoker

Sections Info
Section Name Flags ROffset RSize VOffset VSizeEntropyChi2
.text
0x60000020
Code
Executable
Readable
400 22AA00 1000 22A976
6.6376
12418708.39
.rdata
0x40000040
Initialized Data
Readable
22AE00 56200 22C000 561DE
5.4497
10892577.48
.data
0xC0000040
Initialized Data
Readable
Writeable
281000 6600 283000 93A4
4.6965
1072227.61
.rsrc
0x40000040
Initialized Data
Readable
287600 A600 28D000 A455
4.006
2783986.05
.reloc
0x42000040
Initialized Data
GP-Relative
Readable
291C00 14200 298000 14068
6.6686
327209.84
Entry Point
The section number (1) - (.text) have the Entry Point
Information -> EntryPoint (calculated) - 1EDDAA
Code -> E8800B0000E97AFEFFFFCCCCCCCCCCCCCCCCCCCCCCCC57565333FF8B4424140BC07D14478B542410F7D8F7DA83D800894424
Assembler
|CALL 0X5EF52F
|JMP 0X5EE82E
|INT3
|INT3
|INT3
|INT3
|INT3
|INT3
|INT3
|INT3
|INT3
|INT3
|INT3
|INT3
|PUSH EDI
|PUSH ESI
|PUSH EBX
|XOR EDI, EDI
|MOV EAX, DWORD PTR [ESP + 0X14]
|OR EAX, EAX
|JGE 0X5EE9E1
|INC EDI
|MOV EDX, DWORD PTR [ESP + 0X10]
|NEG EAX
|NEG EDX
|SBB EAX, 0
Signatures
Rich Signature Analyzer:
Code -> F9DE845CBDBFEA0FBDBFEA0FBDBFEA0FF6C7E90EB0BFEA0FF6C7EF0E70BFEA0FF6C7EE0EAABFEA0FB4C7790FBFBFEA0FA8C0170FBABFEA0FA8C0EE0EAFBFEA0FA8C0EF0ED5BFEA0FA8C0E90EA6BFEA0FF6C7EC0EBFBFEA0FBDBFEB0F17BEEA0FF6C7EB0E9EBFEA0F843FEE0E1FBFEA0F843FE30EAFBFEA0F843F150FBCBFEA0F843FE80EBCBFEA0F52696368BDBFEA0F
Footprint md5 Hash -> BC974EA001F1C14D025DFD5E29CD2278
• The Rich header apparently has not been modified
Certificate - Digital Signature Not Found:
• The file is not signed

Packer/Compiler
Compiler: Microsoft Visual C ++
Detect It Easy (die)
PE: compiler: EP:Microsoft Visual C/C++(2017 v.15.5-6)[EXE32]
PE: compiler: Microsoft Visual C/C++(-)[-]
PE: linker: Microsoft Linker(14.37**)[-]
Entropy: 6.65749

Suspicious Functions
Library Function Description
Ws2_32.DLL connect | Possible Call API By Name Establish a connection to a specified socket.
KERNEL32.DLL CreateMutexW Create a named or unnamed mutex object for controlling access to a shared resource.
KERNEL32.DLL GetModuleFileNameA Retrieve the fully qualified path for the executable file of a specified module.
KERNEL32.DLL GetModuleHandleA Retrieves a handle to the specified module.
KERNEL32.DLL CopyFileW Copies an existing file to a new file.
KERNEL32.DLL WriteFile Writes data to a specified file or input/output (I/O) device.
KERNEL32.DLL LoadLibraryA Loads the specified module into the address space of the calling process.
KERNEL32.DLL LoadLibraryW Loads the specified module into the address space of the calling process.
KERNEL32.DLL CreateToolhelp32Snapshot Creates a snapshot of the specified processes, heaps, threads, and modules.
KERNEL32.DLL GetProcAddress Retrieves the address of an exported function or variable from the specified dynamic-link library (DLL).
KERNEL32.DLL CreateFileA Creates or opens a file or I/O device.
KERNEL32.DLL DeleteFileA Deletes an existing file.
KERNEL32.DLL IsDebuggerPresent Determines if the calling process is being debugged by a user-mode debugger.
KERNEL32.DLL SleepEx Pauses the execution of the current thread, optionally allowing the thread to be awakened by a kernel object or upon expiration of a timeout.
Ws2_32.DLL socket Create a communication endpoint for networking applications.
Ws2_32.DLL connect Establish a connection to a specified socket.
ADVAPI32.DLL CryptEncrypt Performs a cryptographic operation on data in a data block.
ADVAPI32.DLL CryptDecrypt Performs a cryptographic operation on data in a data block.
SHELL32.DLL ShellExecuteW Performs a run operation on a specific file.
SHELL32.DLL ShellExecuteExW Performs a run operation on a specific file.
Windows REG (UNICODE)
Software\Brave-Browser\Application\brave.exe
Software\Microsoft\Windows\CurrentVersion\Uninstall\{53F49750-6209-4FBF-9CA8-7A333C87D1ED}_is1
SOFTWARE\Microsoft\Windows\CurrentVersion\Run
SOFTWARE\Policies\Google\Chrome
SOFTWARE\Policies\Microsoft\Edge
SOFTWARE\Policies\BraveSoftware\Brave
Software\Brave
Software\Brave-Browser\User Data\Default
Software\Opera GX Stable
Software\Opera GX
Software\Brave-Browser\User Data
Software\Opera Stable
Software\Microsoft\Windows\CurrentVersion\Run
SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\
SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\App Paths\
Software\Brave-Browser\User Data\
Software\Opera Stable\
Software\Opera GX Stable\Local Extension Settings\
Software\Opera GX Stable\Local Extension Settings
SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall
Rebuilt string - SOFTWARE\Microsoft\Windows\CurrentVersion\Run

File Access
opera.exe
browser.exe
brave.exe
msedge.exe
chrome.exe
lsass.exe
WINMM.dll
AVICAP32.dll
gdiplus.dll
ncrypt.dll
bcrypt.dll
SHLWAPI.dll
api-ms-win-shcore-scaling-l1-1-1.dll
OLEAUT32.dll
ole32.dll
SHELL32.dll
GDI32.dll
USER32.dll
KERNEL32.dll
ADVAPI32.dll
CRYPT32.dll
WLDAP32.dll
WS2_32.dll
secur32.dll
security.dll
iphlpapi.dll
.dat
@.dat
CreditCards.txt
BrowserPasswords.txt
BrowserAutoFills.txt
BrowserDownloads.txt
].txt
.txt
.pdf
Temp
AppData
UserProfile

File Access (UNICODE)
\Google\Chrome\Application\chrome.exe
\Microsoft\Edge\Application\msedge.exe
cmd.exe
powershell.exe
brave.exe
msedge.exe
chrome.exe
cain.exe
regmon.exe
filemon.exe
wireshark.exe
tcpview.exe
netmon.exe
netstat.exe
processhacker.exe
testversion.exe
- kill a process by name, must not add .exe
- Show the path to process, must not add .exe
lsass.exe
shutdown.exe
Telegram.exe
ntdll.dll
cmdvrt32.dll
snxhk.dll
Sf2.dll
SxIn.dll
SbieDll.dll
mscoree.dll
kernel32.dll
token_buffer.dat
text.txt
- CreditCards.txt
- BrowserPasswords.txt
- BrowserAutoFills.txt
- BrowserDownloads.txt
tokens.txt
com/attatier/Cloud/main/Mil2.txt
com/attatier/Cloud/main/MilInfo.txt
keylogs.txt
\Users\User\1.txt
\Users\User\Downloads\1.txt
pdf, .txt
*getDesktop - grab useful desktop files (.pdf
tdata.zip
Browser History.zip
Browser data.zip
desktop.zip
Exec - cmd.exe /u /c
Exec - powershell.exe -Command "
Temp
AppData

SQL Queries
SELECT 1 FROM "%w".sqlite_master WHERE name NOT LIKE 'sqliteX_%%' ESCAPE 'X' AND sql NOT LIKE 'create virtual%%' AND sqlite_rename_test(%Q, sql, type, name, %d, %Q, %d)=NULL
SELECT 1 FROM temp.sqlite_master WHERE name NOT LIKE 'sqliteX_%%' ESCAPE 'X' AND sql NOT LIKE 'create virtual%%' AND sqlite_rename_test(%Q, sql, type, name, 1, %Q, %d)=NULL
SELECT raise(ABORT,%Q) FROM "%w"."%w"
SELECT CASE WHEN quick_check GLOB 'CHECK*' THEN raise(ABORT,'CHECK constraint failed') WHEN quick_check GLOB 'non-* value in*' THEN raise(ABORT,'type mismatch on DEFAULT') ELSE raise(ABORT,'NOT NULL constraint failed') END FROM pragma_quick_check(%Q,%Q) WHERE quick_check GLOB 'CHECK*' OR quick_check GLOB 'NULL*' OR quick_check GLOB 'non-* value in*'
SELECT tbl,idx,stat FROM %Q.sqlite_stat1
SELECT sql FROM "%w".sqlite_schema WHERE type='table'AND name<>'sqlite_sequence' AND coalesce(rootpage,1)>0
SELECT sql FROM "%w".sqlite_schema WHERE type='index'
SELECT * FROM Win32_ComputerSystem
SELECT * FROM Win32_VideoController
SELECT host_key, name, path, encrypted_value, expires_utc, is_secure, is_httponly FROM cookies
SELECT name_on_card, expiration_month, expiration_year, card_number_encrypted FROM credit_cards
SELECT action_url, username_value, password_value FROM logins
SELECT tab_url, target_path FROM downloads
SELECT name, value FROM autofill
SELECT company_name, street_address, city, state, zipcode, country_code FROM autofill_profiles
SELECT first_name, middle_name, last_name FROM autofill_profile_names
SELECT email FROM autofill_profile_emails
SELECT number FROM autofill_profile_phones
SELECT url FROM urls
SELECT host, path, name, value, isSecure, isHttpOnly, expiry FROM moz_cookies
SELECT url FROM moz_places WHERE url IS NOT NULL
SELECT * FROM Win32_OperatingSystem
INSERT INTO %Q.sqlite_master VALUES('index',%Q,%Q,%d,%Q);
INSERT into generated column "%s"
INSERT INTO %Q.sqlite_master VALUES('trigger',%Q,%Q,0,'CREATE TRIGGER %q')
INSERT INTO %s.'||quote(name)||' SELECT*FROM"%w".'||quote(name)FROM %s.sqlite_schema WHERE type='table'AND coalesce(rootpage,1)>0
INSERT INTO %s.sqlite_schema SELECT*FROM "%w".sqlite_schema WHERE type IN('view','trigger') OR(type='table'AND rootpage=0)
CREATE TABLE %Q.%s(%s)
CREATE TABLE
CREATE TABLE %Q.sqlite_sequence(name,seq)
CREATE TABLE x
CREATE TABLE x(type text,name text,tbl_name text,rootpage int,sql text)
CREATE TABLE x(key,value,type,atom,id,parent,fullkey,path,json HIDDEN,root HIDDEN)
DROP TABLE to delete table %s
DELETE FROM %Q.%s WHERE %s=%Q
DELETE FROM %Q.sqlite_sequence WHERE name=%Q
DELETE FROM %Q.sqlite_master WHERE tbl_name=%Q and type!='trigger'
DELETE FROM %Q.sqlite_master WHERE name=%Q AND type='index'
DELETE FROM %Q.sqlite_master WHERE name=%Q AND type='trigger'
SELECT Name FROM Win32_Processor
SELECT Name FROM Win32_VideoController
SELECT TotalPhysicalMemory FROM Win32_ComputerSystem
SELECT ProcessorId FROM Win32_Processor
SELECT * FROM AntivirusProduct

Interest's Words
rcpt to:
JFIF
smtp
Encrypt
Decrypt
Encryption
PassWord
exec
attrib
start
pause
cipher
hostname
shutdown
systeminfo
ping
expand
replace

Interest's Words (UNICODE)
Virus
Encrypt
Decrypt
KeyLogger
Encryption
PassWord
exec
powershell
start
shutdown
netstat
systeminfo
at.exe

Anti-VM/Sandbox/Debug Tricks (UNICODE)
LabTools - wireshark
LabTools - filemon
LabTools - regmon
SandBoxie Library - SbieDll.dll

URLs
http://localhost:9222/json
http://ip-api.com/json/
https://curl.se/docs/http-cookies.html
https://curl.se/docs/alt-svc.html
https://curl.se/docs/hsts.html
https://api.telegram.org/
https://upload.gofile.io/uploadfile

URLs (UNICODE)
https://raw.githubusercontent.com/attatier/Cloud/main/MilInfo.txt
https://raw.githubusercontent.com/attatier/Cloud/main/Mil2.txt

AV Services (UNICODE)
securitycenter2.exe - (SecurityCenter2)

IP Addresses
127.0.0.1
2.5.29.17
2.5.4.10
2.5.4.11
2.5.4.12
2.5.4.13
2.5.4.17
2.5.4.41
2.5.4.42
2.5.4.43
2.5.4.44
2.5.4.45
2.5.4.46
2.5.4.65
2.5.4.72
2.5.29.18
2.5.29.19

Strings/Hex Code Found With The File Rules
Rule Type Encoding Matched (Word)
Text Ascii Unicode escape - \u00 - (Common Unicode escape sequences)
Text Ascii WinAPI Sockets (bind)
Text Ascii WinAPI Sockets (listen)
Text Ascii WinAPI Sockets (accept)
Text Ascii WinAPI Sockets (connect)
Text Unicode WinAPI Sockets (connect)
Text Ascii WinAPI Sockets (recv)
Text Ascii WinAPI Sockets (send)
Text Unicode WinAPI Sockets (send)
Text Ascii Registry (RegCreateKeyEx)
Text Ascii Registry (RegOpenKeyEx)
Text Ascii Registry (RegSetValueEx)
Text Ascii File (GetTempPath)
Text Ascii File (CopyFile)
Text Ascii File (CreateFile)
Text Ascii File (WriteFile)
Text Ascii File (ReadFile)
Text Ascii Encryption (Microsoft Unified Security Protocol Provider)
Text Ascii Encryption API (CryptAcquireContext)
Text Ascii Encryption API (CryptDecrypt)
Text Ascii Encryption API (CryptReleaseContext)
Hex Hex Pattern PEB AntiDebug (Flag BeingDebugged)
Text Ascii Anti-Analysis VM (IsDebuggerPresent)
Text Ascii Anti-Analysis VM (GetSystemInfo)
Text Ascii Anti-Analysis VM (GetVersion)
Text Ascii Anti-Analysis VM (CreateToolhelp32Snapshot)
Text Ascii Reconnaissance (FindFirstFileW)
Text Ascii Reconnaissance (FindNextFileW)
Text Ascii Reconnaissance (FindClose)
Text Ascii Stealth (ExitThread)
Text Ascii Stealth (CloseHandle)
Text Ascii Stealth (UnmapViewOfFile)
Text Ascii Stealth (MapViewOfFile)
Text Ascii Stealth (CreateFileMappingA)
Text Ascii Stealth (CreateFileMappingW)
Text Ascii Execution (CreateProcessA)
Text Ascii Execution (CreateProcessW)
Text Ascii Execution (ShellExecute)
Text Ascii Execution (CreateEventA)
Text Ascii Privileges (SeDebugPrivilege)
Text Unicode Keyboard Key ([Tab])
Text Unicode Keyboard Key ([Shift])
Text Unicode Keyboard Key ([WIN])
Text Unicode WMI execution (ROOT\CIMV2)
Text Unicode Malware designed to intercept and exfiltrate credit card details from compromised systems (Credit Card)
Text Ascii Information used for user authentication (Credential)
Text Ascii Unauthorized movement of funds or data (Transfer)
Entry Point Hex Pattern Microsoft Visual C++ 8
Entry Point Hex Pattern Microsoft Visual C++ 8
Entry Point Hex Pattern VC8 - Microsoft Corporation
Resources
Path DataRVA Size FileOffset CodeText
\ICON\1\0 28D164 128 287764 2800000010000000200000000100040000000000C00000000000000000000000100000000000000000000000000080000080(....... .........................................
\ICON\2\0 28D28C 2E8 28788C 2800000020000000400000000100040000000000800200000000000000000000100000000000000000000000000080000080(... ...@.........................................
\RCDATA\11\0 28D574 9D3E 287B74 5800670042007A0041004100450041005A00670042002F004100460030004100620077004100420041004100630041004400X.g.B.z.A.A.E.A.Z.g.B./.A.F.0.A.b.w.A.B.A.A.c.A.D.
\GROUP_ICON\$\0 2972B4 22 2918B4 00000100020010101000010004002801000001002020100001000400E80200000200..............(..... ............
\24\1\1033 2972D8 17D 2918D8 3C3F786D6C2076657273696F6E3D27312E302720656E636F64696E673D275554462D3827207374616E64616C6F6E653D2779<?xml version='1.0' encoding='UTF-8' standalone='y
Intelligent String
• chrome.exe
• .pdf
• .txt
• .png
• .jpg
• .gif
• .svg
• .htm
• application/pdf.xml
• Could not read a file:// file
• Login denied
• Bad login part
• Bad file:// URLUnsupported number of slashes following scheme
• https://curl.se/docs/http-cookies.html
• %s cached session ID for %s://%s:%dPROXY
• Failed to add Session ID to cache for %s://%s:%d [%s]
• Added Session ID to cache for %s://%s:%d [%s]
• %s://%sURL rejected: %s
• iphlpapi.dll
• Your alt-svc cache. https://curl.se/docs/alt-svc.html
• Your HSTS cache. https://curl.se/docs/hsts.html
• %s%s.tmp
• LOGIN %s %sAUTHENTICATE %s %s
• Got unexpected imap-server responseLOGINDISABLED
• AUTH=+LOGINUIDVALIDITYMAILINDEX
• failed to resume file:// transfer
• file://%s%s%s
• machinelogin
• security.dll
• 2.5.29.17
• 1.2.840.10045.4.3.2ecdsa-with-SHA256
• 1.2.840.10045.4.3.3ecdsa-with-SHA384
• 1.2.840.10045.4.3.4ecdsa-with-SHA512
• 2.5.4.10
• 2.5.4.11
• 2.5.4.12
• 2.5.4.13
• 2.5.4.41
• 2.5.4.42
• 2.5.4.43
• 2.5.4.44
• 2.5.4.46
• 2.5.4.72
• 2.5.29.18
• 2.5.29.19
• LOGIN
• kernel32.dll
• IND)ind).cmd
• .bat
• .com
• mscoree.dll
• ws://%[:/]ERROR: Could not parse WebSocket url: %s
• C:\Users\attat\source\repos\Millenium RAT Builder V4.3\Stub\libs\miniz.c
• \u0009
• \u00
• \u0000
• SbieDll.dll
• SxIn.dll
• Sf2.dll
• snxhk.dll
• cmdvrt32.dll
• runas
• cmd.exe
• C:\Program Files\Telegram Desktop\tdata
• Telegram.exe
• dumps
• shutdown.exe
• ntdll.dll
• C:\Users\attat\source\repos\Millenium RAT Builder V4.3\Stub\libs\json.hpp
• Failed to init curlCurl failedhttp://localhost:9222/json
• invalid string: control character U+0000 (NUL) must be escaped to \u0000
• invalid string: control character U+0001 (SOH) must be escaped to \u0001
• invalid string: control character U+0002 (STX) must be escaped to \u0002
• invalid string: control character U+0003 (ETX) must be escaped to \u0003
• invalid string: control character U+0004 (EOT) must be escaped to \u0004
• invalid string: control character U+0005 (ENQ) must be escaped to \u0005
• invalid string: control character U+0006 (ACK) must be escaped to \u0006
• invalid string: control character U+0007 (BEL) must be escaped to \u0007
• invalid string: control character U+0008 (BS) must be escaped to \u0008 or \b
• invalid string: control character U+0009 (HT) must be escaped to \u0009 or \t
• invalid string: control character U+000A (LF) must be escaped to \u000A or \n
• invalid string: control character U+000B (VT) must be escaped to \u000Binvalid string: control character U+000C (FF) must be escaped to \u000C or \f
• invalid string: control character U+000D (CR) must be escaped to \u000D or \r
• invalid string: control character U+000E (SO) must be escaped to \u000Einvalid string: control character U+000F (SI) must be escaped to \u000Finvalid string: control character U+0010 (DLE) must be escaped to \u0010
• invalid string: control character U+0011 (DC1) must be escaped to \u0011
• invalid string: control character U+0012 (DC2) must be escaped to \u0012
• invalid string: control character U+0013 (DC3) must be escaped to \u0013
• invalid string: control character U+0014 (DC4) must be escaped to \u0014
• invalid string: control character U+0015 (NAK) must be escaped to \u0015
• invalid string: control character U+0016 (SYN) must be escaped to \u0016
• invalid string: control character U+0017 (ETB) must be escaped to \u0017
• invalid string: control character U+0018 (CAN) must be escaped to \u0018
• invalid string: control character U+0019 (EM) must be escaped to \u0019invalid string: control character U+001A (SUB) must be escaped to \u001A
• invalid string: control character U+001B (ESC) must be escaped to \u001B
• invalid string: control character U+001C (FS) must be escaped to \u001Cinvalid string: control character U+001D (GS) must be escaped to \u001Dinvalid string: control character U+001E (RS) must be escaped to \u001Einvalid string: control character U+001F (US) must be escaped to \u001Finvalid string: ill-formed UTF-8 byte
• lsass.exe
• lsass.exe not foundDuplicateToken failed
• SELECT action_url, username_value, password_value FROM logins
• *cmd*<command> - run a cmd command on victims PC
• *processpath*<process name, e.g. discord, Telegram etc> - Show the path to process, must not add .exe
• *processkill*<process name, e.g. discord, Telegram etc> - kill a process by name, must not add .exe
• C:\Users
• C:\Users\User\Downloads\1.txt*C:\Users\User\1.txt
• keylogs.txt
• audio.wav
• .zip
• desktop.zip
• testversion.exe
• https://raw.githubusercontent.com/attatier/Cloud/main/MilInfo.txt
• https://raw.githubusercontent.com/attatier/Cloud/main/Mil2.txt
• test.key
• processhacker.exe
• netstat.exe
• netmon.exe
• tcpview.exe
• wireshark.exe
• filemon.exe
• regmon.exe
• cain.exe
• .cpp
• .lnk
• .bmp
• .psd
• .doc
• .xls
• .ppt
• .odt
• .csv
• .sql
• .mdb
• .sln
• .php
• .asp
• .xml
• .jar
• .asm
• .ldb
• tokens.txt
• ].txt
• \Login Data
• msedge.exe
• brave.exe
• cookies/Brave [brave.exe
• opera.exe
• BrowserDownloads.txt
• BrowserAutoFills.txt
• BrowserPasswords.txt
• CreditCards.txt
• Browser data.zip
• Browser History.zip
• tdata.zip
• https://upload.gofile.io/uploadfiledata
• http://ip-api.com/json/undefined
• text.txt
• cmd /c timeout /t 3 /nobreak & rd /s /q "
• cmd /c timeout /t 3 /nobreak & del /f /q "
• C:\Program Files\Google\Chrome\Application\chrome.exe
• C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
• \Google\Chrome\Application\chrome.exe
• C:\Program Files\Microsoft\Edge\Application\msedge.exe
• C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
• \Microsoft\Edge\Application\msedge.exe
• C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe
• C:\Program Files (x86)\BraveSoftware\Brave-Browser\Application\brave.exe
• \BraveSoftware\Brave-Browser\Application\brave.exe
• screenshot.png
• .exe
• .dll
• cmd.exe /u /c
• 'The CMD command was executed successfully
• Unknown error: failed to execute the CMD command
• powershell.exe -Command "
• .tls
• .bss
• WS2_32.dll
• api-ms-win-shcore-scaling-l1-1-1.dll
• @NCryptDecryptncrypt.dll
• gdiplus.dll

Flow Anomalies
Offset FlowVA Section Description
1EDB 62C534 .text CALL [static] | Indirect call to absolute memory address
1F7E 62C534 .text CALL [static] | Indirect call to absolute memory address
1FEE 62C548 .text CALL [static] | Indirect call to absolute memory address
1FFE 62C514 .text CALL [static] | Indirect call to absolute memory address
200B 62C514 .text CALL [static] | Indirect call to absolute memory address
20C1 62C53C .text CALL [static] | Indirect call to absolute memory address
21B8 62C530 .text CALL [static] | Indirect call to absolute memory address
21F2 62C530 .text CALL [static] | Indirect call to absolute memory address
2231 62C530 .text CALL [static] | Indirect call to absolute memory address
2ED2 62C538 .text CALL [static] | Indirect call to absolute memory address
2EF5 62C18C .text CALL [static] | Indirect call to absolute memory address
2F4D 62C540 .text CALL [static] | Indirect call to absolute memory address
2F61 62C544 .text CALL [static] | Indirect call to absolute memory address
2F6D 62C530 .text CALL [static] | Indirect call to absolute memory address
2F82 62C54C .text CALL [static] | Indirect call to absolute memory address
3045 62C53C .text CALL [static] | Indirect call to absolute memory address
310B 62C53C .text CALL [static] | Indirect call to absolute memory address
314A 62C53C .text CALL [static] | Indirect call to absolute memory address
319C 62C53C .text CALL [static] | Indirect call to absolute memory address
31DB 62C53C .text CALL [static] | Indirect call to absolute memory address
321A 62C53C .text CALL [static] | Indirect call to absolute memory address
3259 62C53C .text CALL [static] | Indirect call to absolute memory address
3295 62C548 .text CALL [static] | Indirect call to absolute memory address
3348 62C548 .text CALL [static] | Indirect call to absolute memory address
3388 62C554 .text CALL [static] | Indirect call to absolute memory address
33A1 62C550 .text CALL [static] | Indirect call to absolute memory address
8426 684658 .text CALL [static] | Indirect call to absolute memory address
8467 684660 .text CALL [static] | Indirect call to absolute memory address
8507 684658 .text CALL [static] | Indirect call to absolute memory address
86A2 684684 .text CALL [static] | Indirect call to absolute memory address
86B0 684634 .text CALL [static] | Indirect call to absolute memory address
8778 684638 .text CALL [static] | Indirect call to absolute memory address
879C 684634 .text CALL [static] | Indirect call to absolute memory address
87B5 684634 .text CALL [static] | Indirect call to absolute memory address
87CE 684634 .text CALL [static] | Indirect call to absolute memory address
87E7 684634 .text CALL [static] | Indirect call to absolute memory address
88F1 684660 .text CALL [static] | Indirect call to absolute memory address
C10D 684658 .text CALL [static] | Indirect call to absolute memory address
C117 684634 .text CALL [static] | Indirect call to absolute memory address
C12D 68462C .text CALL [static] | Indirect call to absolute memory address
C140 684660 .text CALL [static] | Indirect call to absolute memory address
C157 68462C .text CALL [static] | Indirect call to absolute memory address
C1AB 684658 .text CALL [static] | Indirect call to absolute memory address
C1B5 684634 .text CALL [static] | Indirect call to absolute memory address
C1C8 68462C .text CALL [static] | Indirect call to absolute memory address
C1DB 684660 .text CALL [static] | Indirect call to absolute memory address
C1E7 68462C .text CALL [static] | Indirect call to absolute memory address
C224 684650 .text CALL [static] | Indirect call to absolute memory address
C234 684658 .text CALL [static] | Indirect call to absolute memory address
C28B 684660 .text CALL [static] | Indirect call to absolute memory address
C2BF 684650 .text CALL [static] | Indirect call to absolute memory address
C2CF 684658 .text CALL [static] | Indirect call to absolute memory address
C340 684660 .text CALL [static] | Indirect call to absolute memory address
C36B 684650 .text CALL [static] | Indirect call to absolute memory address
C37B 684658 .text CALL [static] | Indirect call to absolute memory address
C3CD 684660 .text CALL [static] | Indirect call to absolute memory address
C59D 684648 .text CALL [static] | Indirect call to absolute memory address
C5C3 684650 .text JMP [static] | Indirect jump to absolute memory address
C5EE 684654 .text JMP [static] | Indirect jump to absolute memory address
C60E 684658 .text JMP [static] | Indirect jump to absolute memory address
C62E 68465C .text JMP [static] | Indirect jump to absolute memory address
C64E 684660 .text JMP [static] | Indirect jump to absolute memory address
C6B9 685B58 .text CALL [static] | Indirect call to absolute memory address
C78F 62C1C4 .text CALL [static] | Indirect call to absolute memory address
C7B4 62C268 .text CALL [static] | Indirect call to absolute memory address
C7CD 684658 .text CALL [static] | Indirect call to absolute memory address
C7D7 684634 .text CALL [static] | Indirect call to absolute memory address
C7EA 68462C .text CALL [static] | Indirect call to absolute memory address
C801 684660 .text JMP [static] | Indirect jump to absolute memory address
C808 68462C .text CALL [static] | Indirect call to absolute memory address
C826 62C1A8 .text CALL [static] | Indirect call to absolute memory address
C853 62C19C .text CALL [static] | Indirect call to absolute memory address
C876 62C1C0 .text CALL [static] | Indirect call to absolute memory address
C8AC 684658 .text CALL [static] | Indirect call to absolute memory address
C8E7 684660 .text CALL [static] | Indirect call to absolute memory address
C96A 684660 .text CALL [static] | Indirect call to absolute memory address
C97E 684658 .text CALL [static] | Indirect call to absolute memory address
C985 684660 .text CALL [static] | Indirect call to absolute memory address
C9E6 684658 .text CALL [static] | Indirect call to absolute memory address
CA4D 684660 .text CALL [static] | Indirect call to absolute memory address
CA83 684658 .text CALL [static] | Indirect call to absolute memory address
CA97 684660 .text CALL [static] | Indirect call to absolute memory address
CAC3 684658 .text CALL [static] | Indirect call to absolute memory address
CAE9 684660 .text CALL [static] | Indirect call to absolute memory address
CB44 684658 .text CALL [static] | Indirect call to absolute memory address
CB4E 684638 .text CALL [static] | Indirect call to absolute memory address
CBB8 684660 .text CALL [static] | Indirect call to absolute memory address
CBCC 684658 .text CALL [static] | Indirect call to absolute memory address
CC0C 684628 .text CALL [static] | Indirect call to absolute memory address
CC1C 684634 .text CALL [static] | Indirect call to absolute memory address
CC64 684660 .text CALL [static] | Indirect call to absolute memory address
CC76 684628 .text CALL [static] | Indirect call to absolute memory address
CCFB 684634 .text CALL [static] | Indirect call to absolute memory address
CD2E 684658 .text CALL [static] | Indirect call to absolute memory address
CD38 684634 .text CALL [static] | Indirect call to absolute memory address
CD4B 68462C .text CALL [static] | Indirect call to absolute memory address
CD62 684660 .text JMP [static] | Indirect jump to absolute memory address
CD69 68462C .text CALL [static] | Indirect call to absolute memory address
CDBC 684634 .text CALL [static] | Indirect call to absolute memory address
CE35 684658 .text CALL [static] | Indirect call to absolute memory address
54351-5436F N/A .text Unusual BP Cave, count: 31
7E382-7E39F N/A .text Unusual BP Cave, count: 30
16A082-16A09F N/A .text Unusual BP Cave, count: 30
Extra Analysis
Metric Value Percentage
Ascii Code 1643260 59,183%
Null Byte Code 404799 14,5791%
© 2026 All rights reserved.