PESCAN.IO - Analysis Report Basic

File Structure
Analysis Image
PE Chart Code
Header PE (light blue)
Executable sections (pink)
Non-executable sections (black)
External injected code (red)
File Structure in red = malformed or corrupted header

Chart Code For Other Files
Printable characters (blue)
Non-printable characters (black)
Information
Size: 419,11 KB
SHA-256 Hash: 1FB3D641807C575BEB94D35498BB216B528381D03913B26208D4EF229D2CDABE
SHA-1 Hash: E6C6F3FAF1CA6DF8847B750D5B9637BF2063C38E
MD5 Hash: 459845364EB6247DB59C0EF475695A85
Imphash: 699E2495E7EA451122E4BB62D61370E3
MajorOSVersion: 6
MinorOSVersion: 0
CheckSum: 0006D105
EntryPoint (rva): 26550
SizeOfHeaders: 400
SizeOfImage: 67000
ImageBase: 0000000140000000
Architecture: x64
ImportTable: 5D13C
IAT: 4A000
Characteristics: 22
TimeDateStamp: 656E20B0
Date: 04/12/2023 18:55:44
File Type: EXE
Number Of Sections: 7
ASLR: Disabled
Section Names (Optional Header): .text, .rdata, .data, .pdata, _RDATA, .rsrc, .reloc
Number Of Executable Sections: 1
Subsystem: Windows Console
UAC Execution Level Manifest: asInvoker

Sections Info
Section Name Flags ROffset RSize VOffset VSizeEntropyChi2
.text
0x60000020
Code
Executable
Readable
400 49000 1000 48FE0
6.4372
1969581.97
.rdata
0x40000040
Initialized Data
Readable
49400 13C00 4A000 13ADC
5.1821
3511654.46
.data
0xC0000040
Initialized Data
Readable
Writeable
5D000 1600 5E000 2DC0
2.8042
636533.45
.pdata
0x40000040
Initialized Data
Readable
5E600 3000 61000 2E74
5.4619
362696.42
_RDATA
0x40000040
Initialized Data
Readable
61600 200 64000 15C
3.3085
36263
.rsrc
0x40000040
Initialized Data
Readable
61800 200 65000 1E0
4.7123
9294
.reloc
0x42000040
Initialized Data
GP-Relative
Readable
61A00 C00 66000 A04
5.0492
41738.67
Binder/Joiner/Crypter
Dropper code detected (EOF) - 7,11 KB

Entry Point
The section number (1) have the Entry Point
Information -> EntryPoint (calculated) - 25950
Code -> 4883EC28E8F70800004883C428E972FEFFFFCCCC488BC44C8948204C8940184889501053565741564883EC384D8BF1498BD8
Assembler
|SUB RSP, 0X28
|CALL 0X140026E50
|ADD RSP, 0X28
|JMP 0X1400263D4
|INT3
|INT3
|MOV RAX, RSP
|MOV QWORD PTR [RAX + 0X20], R9
|MOV QWORD PTR [RAX + 0X18], R8
|MOV QWORD PTR [RAX + 0X10], RDX
|PUSH RBX
|PUSH RSI
|PUSH RDI
|PUSH R14
|SUB RSP, 0X38
|MOV R14, R9
|MOV RBX, R8
Signatures
Rich Signature Analyzer:
Code -> AE69C492EA08AAC1EA08AAC1EA08AAC1A170A9C0EF08AAC1A170AFC04308AAC1A170AEC0FA08AAC1FF77AEC0FA08AAC1FF77A9C0E008AAC1FF77AFC0BE08AAC18089AFC0E908AAC1A170ABC0E908AAC1EA08ABC18208AAC1D088A3C0EB08AAC1D08855C1EB08AAC1D088A8C0EB08AAC152696368EA08AAC1
Footprint md5 Hash -> 8CCFCF9D8F01F676DBEADF03E8FDB8BA
• The Rich header apparently has not been modified
Certificate - Digital Signature:
• The file is signed and the signature is correct

Packer/Compiler
Compiler: Microsoft Visual Studio
Detect It Easy (die)
PE+(64): compiler: Microsoft Visual C/C++(-)[-]
PE+(64): linker: Microsoft Linker(14.37**)[-]
PE+(64): Sign tool: Windows Authenticode(2.0)[PKCS 7]
Entropy: 6.48697

Suspicious Functions
Library Function Description
KERNEL32.DLL WriteFile Writes data to a specified file or input/output (I/O) device.
KERNEL32.DLL LoadLibraryA Loads the specified module into the address space of the calling process.
KERNEL32.DLL GetModuleHandleW Retrieves a handle to the specified module.
KERNEL32.DLL GetProcAddress Retrieves the address of an exported function or variable from the specified dynamic-link library (DLL).
KERNEL32.DLL CreateFileA Creates or opens a file or I/O device.
KERNEL32.DLL IsDebuggerPresent Determines if the calling process is being debugged by a user-mode debugger.
KERNEL32.DLL CreateFileW Creates or opens a file object.
KERNEL32.DLL ReadFile Reads data from a file.
KERNEL32.DLL FindNextFileW Continues file and directory enumeration.
KERNEL32.DLL FindClose Closes a file search handle.
KERNEL32.DLL CloseHandle Closes an open object handle.
KERNEL32.DLL UnmapViewOfFile Unmaps a mapped file view.
KERNEL32.DLL MapViewOfFile Maps a file into memory.
KERNEL32.DLL CreateFileMappingA Creates a file mapping object.
File Access
KERNEL32.dll
Failed to load ntdll.dll
ntdll.dll
FWPKCLNT.SYS
.dat
@.dat

File Access (UNICODE)
mscoree.dll

Interest's Words
exec
start
systeminfo
ping

URLs
http://ocsp.globalsign.com/rootr103
http://crl.globalsign.com/root.crl
http://ocsp.digicert.com
http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt
http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl
http://ocsp.globalsign.com/rootr30;
http://secure.globalsign.com/cacert/root-r3.crt
http://crl.globalsign.com/root-r3.crl
http://cacerts.digicert.com/DigiCertTrustedRootG4.crt
http://crl3.digicert.com/DigiCertTrustedRootG4.crl
http://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl
http://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt
http://ocsp.globalsign.com/codesigningrootr450F
http://secure.globalsign.com/cacert/codesigningrootr45.crt
http://crl.globalsign.com/codesigningrootr45.crl
http://secure.globalsign.com/cacert/gsgccr45evcodesignca2020.crt
http://ocsp.globalsign.com/gsgccr45evcodesignca20200U
http://crl.globalsign.com/gsgccr45evcodesignca2020.crl
https://www.globalsign.com/repository/

Strings/Hex Code Found With The File Rules
Rule Type Encoding Matched (Word)
Entry Point Hex Pattern Microsoft Visual C++ 8.0 (DLL)
Entry Point Hex Pattern PE-Exe Executable Image
Resources
Path DataRVA Size FileOffset CodeText
\24\1\1033 65060 17D 61860 3C3F786D6C2076657273696F6E3D27312E302720656E636F64696E673D275554462D3827207374616E64616C6F6E653D2779<?xml version=’1.0’ encoding=’UTF-8’ standalone=’y
Intelligent String
• :060U00Uq]dL.g?O0U0E1-Q!m0U0y+m0k0$+0http://ocsp.digicert.com0C+07http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0EU>0<0:864http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0U
• mscoree.dll
• FWPKCLNT.SYS
• ntdll.dll
• D:\a\WFPCalloutExplorer\WFPCalloutExplorer\x64\Release\WFPCalloutExplorer.pdb
• .bss

Flow Anomalies
Offset FlowVA Section Description
45ED N/A .text CALL QWORD PTR [RIP+0x44E0D]
4A64 N/A .text CALL QWORD PTR [RIP+0x4499E]
4ABF N/A .text CALL QWORD PTR [RIP+0x4494B]
4B0A N/A .text CALL QWORD PTR [RIP+0x44908]
4D6D N/A .text CALL QWORD PTR [RIP+0x446A5]
21401 N/A .text CALL QWORD PTR [RIP+0x28021]
214CE N/A .text CALL QWORD PTR [RIP+0x27F54]
2151B N/A .text CALL QWORD PTR [RIP+0x27F2F]
21529 N/A .text CALL QWORD PTR [RIP+0x27F11]
21536 N/A .text CALL QWORD PTR [RIP+0x27F04]
2261C N/A .text CALL QWORD PTR [RIP+0x26E0E]
22630 N/A .text CALL QWORD PTR [RIP+0x26E02]
22640 N/A .text CALL QWORD PTR [RIP+0x26DFA]
2296B N/A .text CALL QWORD PTR [RIP+0x26AE7]
22980 N/A .text CALL QWORD PTR [RIP+0x26ABA]
22AEA N/A .text CALL QWORD PTR [RIP+0x26958]
2394E N/A .text CALL QWORD PTR [RIP+0x25D9C]
239F9 N/A .text CALL QWORD PTR [RIP+0x25CF1]
23A12 N/A .text CALL QWORD PTR [RIP+0x25CD8]
23A93 N/A .text CALL QWORD PTR [RIP+0x25C57]
23AC5 N/A .text CALL QWORD PTR [RIP+0x25C25]
23DA6 N/A .text CALL QWORD PTR [RIP+0x25944]
2404B N/A .text CALL QWORD PTR [RIP+0x2569F]
243A2 N/A .text CALL QWORD PTR [RIP+0x25348]
24525 N/A .text CALL QWORD PTR [RIP+0x251C5]
2462D N/A .text CALL QWORD PTR [RIP+0x250BD]
24648 N/A .text CALL QWORD PTR [RIP+0x250A2]
24A8D N/A .text CALL QWORD PTR [RIP+0x24C5D]
24AB1 N/A .text CALL QWORD PTR [RIP+0x24C39]
24B12 N/A .text CALL QWORD PTR [RIP+0x24BD8]
24B2E N/A .text CALL QWORD PTR [RIP+0x24BBC]
24C57 N/A .text CALL QWORD PTR [RIP+0x24A93]
24C73 N/A .text CALL QWORD PTR [RIP+0x24A77]
2523B N/A .text CALL QWORD PTR [RIP+0x244AF]
25254 N/A .text CALL QWORD PTR [RIP+0x24496]
25290 N/A .text CALL QWORD PTR [RIP+0x2445A]
252F1 N/A .text JMP QWORD PTR [RIP+0x24181]
25301 N/A .text JMP QWORD PTR [RIP+0x24169]
25309 N/A .text JMP QWORD PTR [RIP+0x24151]
25311 N/A .text JMP QWORD PTR [RIP+0x24151]
25326 N/A .text CALL QWORD PTR [RIP+0x24154]
253C6 N/A .text CALL QWORD PTR [RIP+0x240C4]
2546E N/A .text CALL QWORD PTR [RIP+0x2401C]
254A5 N/A .text CALL QWORD PTR [RIP+0x23FED]
254FE N/A .text CALL QWORD PTR [RIP+0x23F94]
255AB N/A .text CALL QWORD PTR [RIP+0x23EE7]
255ED N/A .text CALL QWORD PTR [RIP+0x23E35]
25896 N/A .text CALL QWORD PTR [RIP+0x23E54]
25A0E N/A .text CALL QWORD PTR [RIP+0x23CDC]
25E60 N/A .text JMP QWORD PTR [RIP+0xFFF3FF0]
25FB7 N/A .text CALL QWORD PTR [RIP+0x23513]
25FC0 N/A .text CALL QWORD PTR [RIP+0x23502]
25FC6 N/A .text CALL QWORD PTR [RIP+0x2350C]
25FDA N/A .text JMP QWORD PTR [RIP+0x23500]
25FEE N/A .text CALL QWORD PTR [RIP+0x234F4]
260D5 N/A .text CALL QWORD PTR [RIP+0x2340D]
26171 N/A .text CALL QWORD PTR [RIP+0x23339]
26189 N/A .text CALL QWORD PTR [RIP+0x23329]
261C0 N/A .text CALL QWORD PTR [RIP+0x232FA]
261DF N/A .text CALL QWORD PTR [RIP+0x232CB]
261F9 N/A .text CALL QWORD PTR [RIP+0x232B9]
26230 N/A .text CALL QWORD PTR [RIP+0x2328A]
2627C N/A .text CALL QWORD PTR [RIP+0x23286]
2628A N/A .text CALL QWORD PTR [RIP+0x23270]
26296 N/A .text CALL QWORD PTR [RIP+0x2325C]
262A6 N/A .text CALL QWORD PTR [RIP+0x23244]
2630C N/A .text JMP QWORD PTR [RIP+0x231FE]
26378 N/A .text CALL QWORD PTR [RIP+0x2316A]
263A5 N/A .text CALL QWORD PTR [RIP+0x23105]
263BF N/A .text CALL QWORD PTR [RIP+0x230F3]
26400 N/A .text CALL QWORD PTR [RIP+0x230BA]
26454 N/A .text CALL QWORD PTR [RIP+0x230BE]
26475 N/A .text CALL QWORD PTR [RIP+0x23055]
26480 N/A .text CALL QWORD PTR [RIP+0x23042]
264B6 N/A .text CALL QWORD PTR [RIP+0x2306C]
2650C N/A .text JMP QWORD PTR [RIP+0x22FBE]
26592 N/A .text CALL QWORD PTR [RIP+0x23158]
265CE N/A .text CALL QWORD PTR [RIP+0x2311C]
26637 N/A .text CALL QWORD PTR [RIP+0x230B3]
2668B N/A .text CALL QWORD PTR [RIP+0x2305F]
26971 N/A .text CALL QWORD PTR [RIP+0x22B41]
26D90 N/A .text CALL QWORD PTR [RIP+0x2279A]
26EB0 N/A .text CALL QWORD PTR [RIP+0x2267A]
27392 N/A .text CALL QWORD PTR [RIP+0x22358]
27402 N/A .text CALL QWORD PTR [RIP+0x222E8]
2753A N/A .text CALL QWORD PTR [RIP+0x221B0]
27554 N/A .text CALL QWORD PTR [RIP+0x21FDE]
27595 N/A .text CALL QWORD PTR [RIP+0x21FA5]
28281 N/A .text CALL QWORD PTR [RIP+0x23CB1]
282BF N/A .text CALL QWORD PTR [RIP+0x2126B]
2846F N/A .text CALL QWORD PTR [RIP+0x210D3]
284F6 N/A .text CALL QWORD PTR [RIP+0x21054]
28527 N/A .text CALL QWORD PTR [RIP+0x2101B]
2853F N/A .text CALL QWORD PTR [RIP+0x2100B]
28870 N/A .text CALL QWORD PTR [RIP+0x20E7A]
28A72 N/A .text CALL QWORD PTR [RIP+0x20C78]
29920 N/A .text CALL QWORD PTR [RIP+0x1FB5A]
29B60 N/A .text CALL QWORD PTR [RIP+0x1F91A]
2A234 N/A .text CALL QWORD PTR [RIP+0x1F4B6]
2A4C7 N/A .text CALL QWORD PTR [RIP+0x1F223]
5E600 140001000 .pdata ExceptionHook | Pointer to 1000 - 0x400 .text + UnwindInfo: .rdata
5E60C 140002640 .pdata ExceptionHook | Pointer to 2640 - 0x1A40 .text + UnwindInfo: .rdata
5E618 14000416C .pdata ExceptionHook | Pointer to 416C - 0x356C .text + UnwindInfo: .rdata
5E624 14000418C .pdata ExceptionHook | Pointer to 418C - 0x358C .text + UnwindInfo: .rdata
5E630 1400041BC .pdata ExceptionHook | Pointer to 41BC - 0x35BC .text + UnwindInfo: .rdata
5E63C 140004254 .pdata ExceptionHook | Pointer to 4254 - 0x3654 .text + UnwindInfo: .rdata
5E648 14000428C .pdata ExceptionHook | Pointer to 428C - 0x368C .text + UnwindInfo: .rdata
5E654 1400042BC .pdata ExceptionHook | Pointer to 42BC - 0x36BC .text + UnwindInfo: .rdata
5E660 140004344 .pdata ExceptionHook | Pointer to 4344 - 0x3744 .text + UnwindInfo: .rdata
5E66C 140004364 .pdata ExceptionHook | Pointer to 4364 - 0x3764 .text + UnwindInfo: .rdata
5E678 1400043A0 .pdata ExceptionHook | Pointer to 43A0 - 0x37A0 .text + UnwindInfo: .rdata
5E684 1400043F0 .pdata ExceptionHook | Pointer to 43F0 - 0x37F0 .text + UnwindInfo: .rdata
5E690 140004450 .pdata ExceptionHook | Pointer to 4450 - 0x3850 .text + UnwindInfo: .rdata
5E69C 1400044F0 .pdata ExceptionHook | Pointer to 44F0 - 0x38F0 .text + UnwindInfo: .rdata
5E6A8 140004510 .pdata ExceptionHook | Pointer to 4510 - 0x3910 .text + UnwindInfo: .rdata
5E6B4 140004550 .pdata ExceptionHook | Pointer to 4550 - 0x3950 .text + UnwindInfo: .rdata
5E6C0 140004590 .pdata ExceptionHook | Pointer to 4590 - 0x3990 .text + UnwindInfo: .rdata
5E6CC 1400045B0 .pdata ExceptionHook | Pointer to 45B0 - 0x39B0 .text + UnwindInfo: .rdata
5E6D8 140004600 .pdata ExceptionHook | Pointer to 4600 - 0x3A00 .text + UnwindInfo: .rdata
5E6E4 140004680 .pdata ExceptionHook | Pointer to 4680 - 0x3A80 .text + UnwindInfo: .rdata
5E6F0 140004860 .pdata ExceptionHook | Pointer to 4860 - 0x3C60 .text + UnwindInfo: .rdata
5E6FC 1400048B0 .pdata ExceptionHook | Pointer to 48B0 - 0x3CB0 .text + UnwindInfo: .rdata
5E708 140004910 .pdata ExceptionHook | Pointer to 4910 - 0x3D10 .text + UnwindInfo: .rdata
5E714 140004970 .pdata ExceptionHook | Pointer to 4970 - 0x3D70 .text + UnwindInfo: .rdata
5E720 1400049F0 .pdata ExceptionHook | Pointer to 49F0 - 0x3DF0 .text + UnwindInfo: .rdata
5E72C 140004A50 .pdata ExceptionHook | Pointer to 4A50 - 0x3E50 .text + UnwindInfo: .rdata
5E738 140004A70 .pdata ExceptionHook | Pointer to 4A70 - 0x3E70 .text + UnwindInfo: .rdata
5E744 140004AB0 .pdata ExceptionHook | Pointer to 4AB0 - 0x3EB0 .text + UnwindInfo: .rdata
5E750 140004AE0 .pdata ExceptionHook | Pointer to 4AE0 - 0x3EE0 .text + UnwindInfo: .rdata
5E75C 140004B60 .pdata ExceptionHook | Pointer to 4B60 - 0x3F60 .text + UnwindInfo: .rdata
5E768 140004C30 .pdata ExceptionHook | Pointer to 4C30 - 0x4030 .text + UnwindInfo: .rdata
5E774 140004C60 .pdata ExceptionHook | Pointer to 4C60 - 0x4060 .text + UnwindInfo: .rdata
5E780 140004E00 .pdata ExceptionHook | Pointer to 4E00 - 0x4200 .text + UnwindInfo: .rdata
5E78C 140004E15 .pdata ExceptionHook | Pointer to 4E15 - 0x4215 .text + UnwindInfo: .rdata
5E798 140004E3A .pdata ExceptionHook | Pointer to 4E3A - 0x423A .text + UnwindInfo: .rdata
5E7A4 140004E60 .pdata ExceptionHook | Pointer to 4E60 - 0x4260 .text + UnwindInfo: .rdata
5E7B0 140004E75 .pdata ExceptionHook | Pointer to 4E75 - 0x4275 .text + UnwindInfo: .rdata
5E7BC 140004E9A .pdata ExceptionHook | Pointer to 4E9A - 0x429A .text + UnwindInfo: .rdata
5E7C8 140004EC0 .pdata ExceptionHook | Pointer to 4EC0 - 0x42C0 .text + UnwindInfo: .rdata
5E7D4 140004EE0 .pdata ExceptionHook | Pointer to 4EE0 - 0x42E0 .text + UnwindInfo: .rdata
5E7E0 140004F00 .pdata ExceptionHook | Pointer to 4F00 - 0x4300 .text + UnwindInfo: .rdata
5E7EC 140004F70 .pdata ExceptionHook | Pointer to 4F70 - 0x4370 .text + UnwindInfo: .rdata
5E7F8 140005030 .pdata ExceptionHook | Pointer to 5030 - 0x4430 .text + UnwindInfo: .rdata
5E804 140005090 .pdata ExceptionHook | Pointer to 5090 - 0x4490 .text + UnwindInfo: .rdata
5E810 140005390 .pdata ExceptionHook | Pointer to 5390 - 0x4790 .text + UnwindInfo: .rdata
5E81C 1400053D4 .pdata ExceptionHook | Pointer to 53D4 - 0x47D4 .text + UnwindInfo: .rdata
5E828 1400053F0 .pdata ExceptionHook | Pointer to 53F0 - 0x47F0 .text + UnwindInfo: .rdata
5E834 140005521 .pdata ExceptionHook | Pointer to 5521 - 0x4921 .text + UnwindInfo: .rdata
5E840 14000552E .pdata ExceptionHook | Pointer to 552E - 0x492E .text + UnwindInfo: .rdata
5E84C 140005540 .pdata ExceptionHook | Pointer to 5540 - 0x4940 .text + UnwindInfo: .rdata
5E858 14000558A .pdata ExceptionHook | Pointer to 558A - 0x498A .text + UnwindInfo: .rdata
5E864 140005610 .pdata ExceptionHook | Pointer to 5610 - 0x4A10 .text + UnwindInfo: .rdata
5E870 14000561D .pdata ExceptionHook | Pointer to 561D - 0x4A1D .text + UnwindInfo: .rdata
5E87C 140005630 .pdata ExceptionHook | Pointer to 5630 - 0x4A30 .text + UnwindInfo: .rdata
5E888 1400059B0 .pdata ExceptionHook | Pointer to 59B0 - 0x4DB0 .text + UnwindInfo: .rdata
5E894 1400059E0 .pdata ExceptionHook | Pointer to 59E0 - 0x4DE0 .text + UnwindInfo: .rdata
5E8A0 140005A40 .pdata ExceptionHook | Pointer to 5A40 - 0x4E40 .text + UnwindInfo: .rdata
5E8AC 140005B80 .pdata ExceptionHook | Pointer to 5B80 - 0x4F80 .text + UnwindInfo: .rdata
5E8B8 140005BA3 .pdata ExceptionHook | Pointer to 5BA3 - 0x4FA3 .text + UnwindInfo: .rdata
5E8C4 140005BE2 .pdata ExceptionHook | Pointer to 5BE2 - 0x4FE2 .text + UnwindInfo: .rdata
5E8D0 140005C10 .pdata ExceptionHook | Pointer to 5C10 - 0x5010 .text + UnwindInfo: .rdata
5E8DC 140005C50 .pdata ExceptionHook | Pointer to 5C50 - 0x5050 .text + UnwindInfo: .rdata
5E8E8 140005C70 .pdata ExceptionHook | Pointer to 5C70 - 0x5070 .text + UnwindInfo: .rdata
5E8F4 140005DB0 .pdata ExceptionHook | Pointer to 5DB0 - 0x51B0 .text + UnwindInfo: .rdata
5E900 140006090 .pdata ExceptionHook | Pointer to 6090 - 0x5490 .text + UnwindInfo: .rdata
5E90C 1400060F9 .pdata ExceptionHook | Pointer to 60F9 - 0x54F9 .text + UnwindInfo: .rdata
5E918 140006177 .pdata ExceptionHook | Pointer to 6177 - 0x5577 .text + UnwindInfo: .rdata
5E924 14000617D .pdata ExceptionHook | Pointer to 617D - 0x557D .text + UnwindInfo: .rdata
5E930 140006183 .pdata ExceptionHook | Pointer to 6183 - 0x5583 .text + UnwindInfo: .rdata
5E93C 140006190 .pdata ExceptionHook | Pointer to 6190 - 0x5590 .text + UnwindInfo: .rdata
5E948 1400061BE .pdata ExceptionHook | Pointer to 61BE - 0x55BE .text + UnwindInfo: .rdata
5E954 14000630A .pdata ExceptionHook | Pointer to 630A - 0x570A .text + UnwindInfo: .rdata
5E960 140006310 .pdata ExceptionHook | Pointer to 6310 - 0x5710 .text + UnwindInfo: .rdata
5E96C 140006316 .pdata ExceptionHook | Pointer to 6316 - 0x5716 .text + UnwindInfo: .rdata
5E978 140006320 .pdata ExceptionHook | Pointer to 6320 - 0x5720 .text + UnwindInfo: .rdata
5E984 140006360 .pdata ExceptionHook | Pointer to 6360 - 0x5760 .text + UnwindInfo: .rdata
5E990 140006400 .pdata ExceptionHook | Pointer to 6400 - 0x5800 .text + UnwindInfo: .rdata
5E99C 140006560 .pdata ExceptionHook | Pointer to 6560 - 0x5960 .text + UnwindInfo: .rdata
5E9A8 140006710 .pdata ExceptionHook | Pointer to 6710 - 0x5B10 .text + UnwindInfo: .rdata
5E9B4 1400068A0 .pdata ExceptionHook | Pointer to 68A0 - 0x5CA0 .text + UnwindInfo: .rdata
5E9C0 140006A90 .pdata ExceptionHook | Pointer to 6A90 - 0x5E90 .text + UnwindInfo: .rdata
5E9CC 140006AC0 .pdata ExceptionHook | Pointer to 6AC0 - 0x5EC0 .text + UnwindInfo: .rdata
5E9D8 140006B70 .pdata ExceptionHook | Pointer to 6B70 - 0x5F70 .text + UnwindInfo: .rdata
5E9E4 140006E80 .pdata ExceptionHook | Pointer to 6E80 - 0x6280 .text + UnwindInfo: .rdata
5E9F0 140006EF0 .pdata ExceptionHook | Pointer to 6EF0 - 0x62F0 .text + UnwindInfo: .rdata
5E9FC 140006F30 .pdata ExceptionHook | Pointer to 6F30 - 0x6330 .text + UnwindInfo: .rdata
5EA08 140006F70 .pdata ExceptionHook | Pointer to 6F70 - 0x6370 .text + UnwindInfo: .rdata
5EA14 140006FB0 .pdata ExceptionHook | Pointer to 6FB0 - 0x63B0 .text + UnwindInfo: .rdata
5EA20 140006FF0 .pdata ExceptionHook | Pointer to 6FF0 - 0x63F0 .text + UnwindInfo: .rdata
5EA2C 140006FFF .pdata ExceptionHook | Pointer to 6FFF - 0x63FF .text + UnwindInfo: .rdata
5EA38 14000706D .pdata ExceptionHook | Pointer to 706D - 0x646D .text + UnwindInfo: .rdata
5EA44 14000706E .pdata ExceptionHook | Pointer to 706E - 0x646E .text + UnwindInfo: .rdata
5EA50 140007080 .pdata ExceptionHook | Pointer to 7080 - 0x6480 .text + UnwindInfo: .rdata
5EA5C 1400070C0 .pdata ExceptionHook | Pointer to 70C0 - 0x64C0 .text + UnwindInfo: .rdata
5EA68 140007270 .pdata ExceptionHook | Pointer to 7270 - 0x6670 .text + UnwindInfo: .rdata
5EA74 140007410 .pdata ExceptionHook | Pointer to 7410 - 0x6810 .text + UnwindInfo: .rdata
5EA80 140007680 .pdata ExceptionHook | Pointer to 7680 - 0x6A80 .text + UnwindInfo: .rdata
5EA8C 140007900 .pdata ExceptionHook | Pointer to 7900 - 0x6D00 .text + UnwindInfo: .rdata
5EA98 140007B90 .pdata ExceptionHook | Pointer to 7B90 - 0x6F90 .text + UnwindInfo: .rdata
5EAA4 140007D90 .pdata ExceptionHook | Pointer to 7D90 - 0x7190 .text + UnwindInfo: .rdata
62600 N/A *Overlay* 70660000000202003082665E06092A864886F70D | pf......0.f..*.H...
Extra Analysis
Metric Value Percentage
Ascii Code 256059 59,664%
Null Byte Code 75568 17,608%
© 2026 All rights reserved.