PESCAN.IO - Analysis Report Basic |
|||||||
| File Structure |
|
PE Chart Code
Header PE (light blue)
Executable sections (pink)
Non-executable sections (black)
External injected code (red)
File Structure in red = malformed or corrupted header
Chart Code For Other Files
Printable characters (blue)
Non-printable characters (black)
| Information |
| Size: 1,32 MB SHA-256 Hash: B3059BF31806BBE9362FEB8260379956DA32E99856F7CFEE240B60F823588BC1 SHA-1 Hash: C79FECB9979A3A9D441BD4903D0E6DA4C763E329 MD5 Hash: 626576D1445AF2D5CF45AAFB64439BC2 Imphash: DAE02F32A21E03CE65412F6E56942DAA MajorOSVersion: 4 MinorOSVersion: 0 CheckSum: 001572C1 EntryPoint (rva): 1524DE SizeOfHeaders: 200 SizeOfImage: 158000 ImageBase: 10000000 Architecture: x86 ImportTable: 152488 IAT: 2000 Characteristics: 2022 TimeDateStamp: 6994F0B7 Date: 17/02/2026 22:50:31 File Type: DLL Number Of Sections: 3 ASLR: Disabled Section Names: .text, .rsrc, .reloc Number Of Executable Sections: 1 Subsystem: Windows Console |
| Sections Info |
| Section Name | Flags | ROffset | RSize | VOffset | VSize | Entropy | Chi2 |
|---|---|---|---|---|---|---|---|
| .text | 0x60000020 Code Executable Readable |
200 | 150600 | 2000 | 1504E4 |
|
|
| .rsrc | 0x40000040 Initialized Data Readable |
150800 | 400 | 154000 | 3D8 |
|
|
| .reloc | 0x42000040 Initialized Data GP-Relative Readable |
150C00 | 200 | 156000 | C |
|
|
| Description |
| OriginalFilename: X1.Common.dll CompanyName: X1 Discovery, Inc. LegalCopyright: 2026 X1 Discovery, Inc. All rights reserved. ProductName: X1 Search FileDescription: X1.Common ProductVersion: 10.3.0.9 Language: Unknown (ID=0x0) CodePage: Unicode (UTF-16 LE) (0x4B0) |
| Entry Point |
The section number (1) - (.text) have the Entry Point Information -> EntryPoint (calculated) - 1506DE Code -> FF25002000100000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 Assembler |JMP DWORD PTR [0X10002000] |ADD BYTE PTR [EAX], AL |ADD BYTE PTR [EAX], AL |ADD BYTE PTR [EAX], AL |ADD BYTE PTR [EAX], AL |ADD BYTE PTR [EAX], AL |ADD BYTE PTR [EAX], AL |ADD BYTE PTR [EAX], AL |ADD BYTE PTR [EAX], AL |ADD BYTE PTR [EAX], AL |ADD BYTE PTR [EAX], AL |ADD BYTE PTR [EAX], AL |ADD BYTE PTR [EAX], AL |ADD BYTE PTR [EAX], AL |ADD BYTE PTR [EAX], AL |ADD BYTE PTR [EAX], AL |ADD BYTE PTR [EAX], AL |ADD BYTE PTR [EAX], AL |ADD BYTE PTR [EAX], AL |ADD BYTE PTR [EAX], AL |ADD BYTE PTR [EAX], AL |ADD BYTE PTR [EAX], AL |ADD BYTE PTR [EAX], AL |
| Signatures |
| Certificate - Digital Signature Not Found: • The file is not signed |
| Packer/Compiler |
| Compiler: Microsoft Visual .NET - (You can use a decompiler for this...) • AnyCPU: True • Version: v4.0 --------> Agile .NET Obfuscator Detect It Easy (die) • PE: library: .NET(v4.0.30319)[-] • PE: compiler: VB.NET(-)[-] • PE: linker: Microsoft Linker(48.0)[-] • Entropy: 6.03095 |
| Suspicious Functions |
| Library | Function | Description |
|---|---|---|
| KERNEL32.DLL | GetModuleHandle | Retrieves a handle to the specified module. |
| Windows REG (UNICODE) |
| Software\Microsoft\Office\ SOFTWARE\Microsoft\Internet Explorer SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION SOFTWARE\Microsoft\Windows\shell\Associations\UrlAssociations\http\UserChoice Software\Microsoft\Windows\CurrentVersion\Internet Settings SOFTWARE\Lotus\Notes\ SOFTWARE\WOW6432Node\Lotus\Notes\ Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles Software\Microsoft\Office\{0}.0\Outlook Software\Microsoft\Office\{0}.0\Outlook\Search SOFTWARE\Clients\Mail\Microsoft Outlook Software\Microsoft\Windows\CurrentVersion\App Paths\OUTLOOK.EXE Software\Microsoft\Office\Common Software\Microsoft\Office\aOutlook {0} is installed but has never been run! SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes Software\Internal ExOne Software\Mozilla\Mozilla Firefox SOFTWARE\Microsoft\NET Framework Setup\NDP\ Software\Policies\X1\X1 Search Software\X1 Search SOFTWARE\Lotus\Notes\BSOFTWARE\WOW6432Node\Lotus\Notes\ 0u SOFTWARE\WOW6432Node\Lotus\Notes\ 0u system\Profiles System\CentralProcessor\0 |
| File Access |
| mscoree.dll wininet.dll mpr.dll rstrtmgr.dll X1.Common.dll urlmon.dll msi.dll Shlwapi.dll psapi.dll Crypt32.dll user32.dll shell32.dll kernel32.dll advapi32.dll gdi32.dll System.Web.Scr System.Windows.Dat X1.Common.Log QX1.Common.X1DotNetZip.Zip 2X1.Common.X1DotNetZip.Zip X1.Common.X1DotNetZip.Zip ICSharpCode.SharpZipLib.Zip Xceed.Zip Temp RootDir AppData UserProfile |
| File Access (UNICODE) |
| //ieframe.dll Common.dll X1EnterpriseManagerTomcat.exe ;X1EnterpriseSearchService.exe X1EnterpriseManagerService.exe ;X1EnterpriseManagerTomcat.exe X1SearchVirtualServerSetup.exe EX1SearchVirtualServerSetupEval.exe EX1SearchVirtualServerSetupBeta.exe 1X1SearchVirtualSetup.exe 9X1SearchVirtualSetupEval.exe 9X1SearchVirtualSetupBeta.exe 5X1SocialDiscoverySetup.exe X1SocialDiscoverySetupEval.exe X1SocialDiscoverySetupBeta.exe X1.exe 1X1ServiceHost.exe X1SearchSetup.exe +X1SearchSetupEval.exe +X1SearchSetupBeta.exe X1.exe OUTLOOK.EXE reg.exe %X1.exe ;X1ServiceHost.exe xul.dll 0.dll 5libSyncfusionTesseract.dll .resources.dll exchangemapicdo.msi lfxx1e.datx1cl.dat x1tr.dat keyx1-db-inf.datx1-db-inf1.dat x1-obc.dat x1e.dat x1cl.dat \x1-db-inf1.dat \x1-db-inf.dat .session.dat OFile needs to end with .dat FakeRateLimit.dat x1tr.dat AEnterpriseSearchService.Dat x1info.dat x1license.dat *.dat x1-obc.dat X1Setup.log %QA.Log !X1MAPIEngine.log X1ServiceHost.log X1IndexCore.log X1.log !RegEx.Log regex.log xN+& trasferfiles.txt jsonexport.jsonversion.txt setup_version.txt uri.txt raw.txt ostPaths.txt version.txt build_version.ini QKeyFileName entry not found in .ini notes.ini OError getting Lotus Notes .ini ILotus Notes .ini /Lotus Notes .ini GChecking for Lotus Notes .ini Temp ProgramFiles AppData |
| SQL Queries |
| select DeviceID, MediaType,InterfaceType from Win32_DiskDrive select * from Win32_LogicalDisk where Name='{0}'MediaType Select FreeSpace,Size,Name from Win32_LogicalDisk where DriveType=3 SELECT * FROM Win32_OperatingSystem |
| Interest's Words |
| outlook smtp Encrypt Decrypt Encryption PassWord <html <body <form <title cscript exec unescape netsh tasklist attrib start pause forfiles hostname sdelete shutdown logman systeminfo ping expand replace setx |
| Interest's Words (UNICODE) |
| outlook smtp Encrypt Decrypt Encryption PassWord <html <head <body <script <link <meta <title <iframe <main exec attrib start pause diskpart hostname sdelete shutdown at.exe ping expand replace |
| Anti-VM/Sandbox/Debug Tricks (UNICODE) |
| LabTools - filemon |
| URLs |
| http://unicode.org/reports/tr35/) http://www.unicode.org/copyright.html http://schemas.xmlsoap.org/ws/2005/02/trust/RST/IssueTReplyAction6http://schemas.xmlsoap.org/ws/2005/02/trust/RSTR/IssueT http://schemas.xmlsoap.org/ws/2005/02/trust/RSTR/IssueT http://X1UI2.LotusNotes; https://www.x1.com https://activate.x1.com/customers/ManualRequest.aspx https://activate.x1.com/webservices/XmlActivationService.asmx https://activate.x1.com/webservices/XmlLicenseFileService.asmx https://activate.x1.com |
| URLs (UNICODE) |
| http://7/X1DDCollectorV3WindowsOnly http://{0}/X1DesktopManagerV3WindowsOnly http://the.fault.action http://<A href=" http://schemas.microsoft.com/idfx/requesttype/issue http://schemas.microsoft.com/idfx/keytype/bearer http://schemas.xmlsoap.org/ws/2005/02/trust"><t:Lifetime><wsu:Created xmlns:wsu=" http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd">{0}</wsu:Created><wsu:Expires xmlns:wsu=" http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd">{1}</wsu:Expires></t:Lifetime><wsp:AppliesTo xmlns:wsp=" http://schemas.xmlsoap.org/ws/2004/09/policy"><wsa:EndpointReference xmlns:wsa=" http://schemas.xmlsoap.org/ws/2005/02/trust/Issue</t:RequestType><t:KeyType> http://schemas.xmlsoap.org/ws/2005/05/identity/NoProofKey</t:KeyType></t:RequestSecurityTokenResponse>Ewa=wsignin1.0&wctx={0}&wresult={1} http://schemas.xmlsoap.org/ws/2005/02/trust/Issue http://schemas.xmlsoap.org/ws/2005/05/identity/NoProofKey http://schemas.xmlsoap.org/ws/2005/02/trust/RST/Issue http://dev-wamp.x1dev.com/scripts/getcrashlog.phpWhttps://logs.x1.com/scripts/getcrashlog.php http://dev-wamp.x1dev.com/scripts/getminidump.phpWhttps://logs.x1.com/scripts/getminidump.php http://dev-wamp.x1dev.com/scripts/9https://logs.x1.com/scripts/ http://' target=''></a> http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsdExpires http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd%0 http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsd http://-previewtemp https://{0}/X1DesktopManagerV3WindowsOnly https://t.co/ https://login.microsoftonline.com/login.srf https://login.microsoftonline.com/extSTS.srf https://logs.x1.com/scripts/getcrashlog.php https://logs.x1.com/scripts/getminidump.php https://logs.x1.com/scripts/ https://lavafalls.business.x1.com/x1renewal/mycommerce.php https://logs.x1.com/scripts/bootstrapper_version.php https://logs.x1.com/scripts/product_version.php https://logs.x1.com/scripts/version.php https://login.microsoftonline.com/extSTS.srfV https://login.microsoftonline.com/login.srf ftp://gopher:// |
| Emails |
| support@x1.com |
| IP Addresses |
| 114.0.0.0 127.0.0.1 121.0.0.0 10.0.27.0 12.0.0.0 17.0.0.0 13.0.0.0 10.3.0.9 |
| Known IP/Domains (UNICODE) |
| outlook.com gmail.com hotmail.com yahoo.com |
| Strings/Hex Code Found With The File Rules |
| Rule Type | Encoding | Matched (Word) |
|---|---|---|
| Text | Unicode | Unicode escape - \u00 - (Common Unicode escape sequences) |
| Text | Ascii | WinAPI Sockets (bind) |
| Text | Unicode | WinAPI Sockets (bind) |
| Text | Ascii | WinAPI Sockets (listen) |
| Text | Ascii | WinAPI Sockets (accept) |
| Text | Unicode | WinAPI Sockets (accept) |
| Text | Ascii | WinAPI Sockets (connect) |
| Text | Unicode | WinAPI Sockets (connect) |
| Text | Ascii | WinAPI Sockets (send) |
| Text | Unicode | WinAPI Sockets (send) |
| Text | Ascii | Registry (RegOpenKeyEx) |
| Text | Ascii | File (GetTempPath) |
| Text | Ascii | File (CreateFile) |
| Text | Ascii | File (ReadFile) |
| Text | Ascii | Encryption (CreateDecryptor) |
| Text | Ascii | Encryption (CryptoStream) |
| Text | Ascii | Encryption (CryptoStreamMode) |
| Text | Ascii | Encryption (DESCryptoServiceProvider) |
| Text | Ascii | Encryption (FromBase64String) |
| Text | Ascii | Encryption (ICryptoTransform) |
| Text | Ascii | Encryption (RNGCryptoServiceProvider) |
| Text | Ascii | Encryption (Rijndael) |
| Text | Unicode | Encryption (Rijndael) |
| Text | Ascii | Encryption (RijndaelManaged) |
| Text | Ascii | Encryption (ToBase64String) |
| Text | Ascii | Encryption (TripleDESCryptoServiceProvider) |
| Text | Ascii | Anti-Analysis VM (GlobalMemoryStatusEx) |
| Text | Unicode | Anti-Analysis VM (GlobalMemoryStatusEx) |
| Text | Ascii | Anti-Analysis VM (GetVersion) |
| Text | Ascii | Stealth (CloseHandle) |
| Text | Ascii | Execution (ShellExecute) |
| Text | Unicode | Privileges (SeAssignPrimaryTokenPrivilege) |
| Text | Unicode | Privileges (SeAuditPrivilege) |
| Text | Unicode | Privileges (SeBackupPrivilege) |
| Text | Unicode | Privileges (SeChangeNotifyPrivilege) |
| Text | Unicode | Privileges (SeCreateGlobalPrivilege) |
| Text | Unicode | Privileges (SeCreatePagefilePrivilege) |
| Text | Unicode | Privileges (SeCreatePermanentPrivilege) |
| Text | Unicode | Privileges (SeCreateSymbolicLinkPrivilege) |
| Text | Unicode | Privileges (SeCreateTokenPrivilege) |
| Text | Unicode | Privileges (SeDebugPrivilege) |
| Text | Unicode | Privileges (SeEnableDelegationPrivilege) |
| Text | Unicode | Privileges (SeImpersonatePrivilege) |
| Text | Unicode | Privileges (SeIncreaseBasePriorityPrivilege) |
| Text | Unicode | Privileges (SeIncreaseQuotaPrivilege) |
| Text | Unicode | Privileges (SeIncreaseWorkingSetPrivilege) |
| Text | Unicode | Privileges (SeLoadDriverPrivilege) |
| Text | Unicode | Privileges (SeLockMemoryPrivilege) |
| Text | Unicode | Privileges (SeMachineAccountPrivilege) |
| Text | Unicode | Privileges (SeManageVolumePrivilege) |
| Text | Unicode | Privileges (SeProfileSingleProcessPrivilege) |
| Text | Unicode | Privileges (SeRelabelPrivilege) |
| Text | Unicode | Privileges (SeRemoteShutdownPrivilege) |
| Text | Unicode | Privileges (SeRestorePrivilege) |
| Text | Unicode | Privileges (SeSecurityPrivilege) |
| Text | Unicode | Privileges (SeShutdownPrivilege) |
| Text | Unicode | Privileges (SeSyncAgentPrivilege) |
| Text | Unicode | Privileges (SeSystemEnvironmentPrivilege) |
| Text | Unicode | Privileges (SeSystemProfilePrivilege) |
| Text | Unicode | Privileges (SeSystemtimePrivilege) |
| Text | Unicode | Privileges (SeTakeOwnershipPrivilege) |
| Text | Unicode | Privileges (SeTcbPrivilege) |
| Text | Unicode | Privileges (SeTimeZonePrivilege) |
| Text | Unicode | Privileges (SeTrustedCredManAccessPrivilege) |
| Text | Unicode | Privileges (SeUndockPrivilege) |
| Text | Ascii | Privileges (SE_BACKUP_NAME) |
| Text | Ascii | Privileges (SE_PRIVILEGE_ENABLED) |
| Text | Ascii | Keyboard Key (LBUTTON) |
| Text | Ascii | Keyboard Key (MBUTTON) |
| Text | Ascii | Keyboard Key (RBUTTON) |
| Text | Ascii | Keyboard Key (Scroll) |
| Text | Ascii | Technique used to make malicious code harder to analyze (Obfuscation) |
| Text | Ascii | Software that records user activity (Logger) |
| Text | Unicode | Software that records user activity (Logger) |
| Text | Ascii | Information used for user authentication (Credential) |
| Text | Unicode | Information used for user authentication (Credential) |
| Text | Ascii | Unauthorized movement of funds or data (Transfer) |
| Text | Unicode | Unauthorized movement of funds or data (Transfer) |
| Text | Ascii | Malicious rerouting of traffic to an attacker-controlled site (Redirect) |
| Text | Unicode | Malicious rerouting of traffic to an attacker-controlled site (Redirect) |
| Text | Ascii | Technique used to capture communications between systems (Intercept) |
| Text | Ascii | Technique used to circumvent security measures (Bypass) |
| Entry Point | Hex Pattern | Microsoft Visual C / Basic .NET |
| Entry Point | Hex Pattern | Microsoft Visual C++ 8 |
| Entry Point | Hex Pattern | Microsoft Visual C++ 8.0 |
| Entry Point | Hex Pattern | TrueVision Targa Graphics format |
| Resources |
| Path | DataRVA | Size | FileOffset | Code | Text |
|---|---|---|---|---|---|
| \VERSION\1\0 | 154058 | 380 | 150858 | 800334000000560053005F00560045005200530049004F004E005F0049004E0046004F0000000000BD04EFFE000001000300 | ..4...V.S._.V.E.R.S.I.O.N._.I.N.F.O............... |
| Intelligent String |
| • X1.Common.dll • For terms of use, see http://www.unicode.org/copyright.html • CLDR data files are interpreted according to the LDML specification (http://unicode.org/reports/tr35/) • x1-obc.dat • 7ReconfigureQuickCollect.xml • .dat • version.txt • x1e.pfx • *.dat • ;X1ServiceHost.exe.*.crash.xml • %X1.exe.*.crash.xml • X1EConfig.xml • x1license.dat • x1info.dat • C:\ProgramData\X1E Virtual Config Root • x1tr.dat • sharedcache.xml • regex.log • RegEx.xml • http://{0}/X1DesktopManagerV3WindowsOnly • https://{0}/X1DesktopManagerV3WindowsOnly • http://the.fault.action • ?net.tcp://{0}:{2}/X1Service_{1} • 7net.tcp://{0}/X1Service_{1} • Cnet.tcp://{0}/X1SearchManager_{1} • Inet.tcp://{0}/X1EnterpriseSearch/{1} • -Global\X1E_startup_{0} • -Global\{0}_startup_{1} • /Global\{0}_shutdown_{1} • Enet.tcp://localhost:{2}/X1/{0}_{1} • ?net.pipe://localhost/X1/{0}_{1} • .exe • =res://ieframe.dll • 1Writing dump html file: • .htm • <script • www. • .css • Mozilla/5.0 (Windows NT 6.3; WOW64; Trident/7.0; rv:11.0) like Gecko • FakeRateLimit.dat • .dll • .resources.dll • .txt • .mht • !image/vnd-ms.dds • .xml • .csv • .rtf • .abw • .odp • .ods • .odt • .doc • .ppt • .xls • .vsd • .azw • .zip • .rar • .tar • .jar • .avi • .wav • .oga • .ogv • .ogx • .aac • .swf • .mid • .mov • .gif • .jpg • .jpm • .jpx • .png • .ico • .tif • .svg • .jxr • .bmp • .wmf • .emf • .dng • .dds • .psd • .eot • .otf • .ttf • .bin • .nsf • URLRewrite.xml • 7Error dumping registry keys • res://ieframe.dll • http://schemas.microsoft.com/idfx/requesttype/issue • http://schemas.microsoft.com/idfx/keytype/bearer • <t:RequestSecurityTokenResponse xmlns:t="http://schemas.xmlsoap.org/ws/2005/02/trust"><t:Lifetime><wsu:Created xmlns:wsu="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd">{0}</wsu:Created><wsu:Expires xmlns:wsu="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd">{1}</wsu:Expires></t:Lifetime><wsp:AppliesTo xmlns:wsp="http://schemas.xmlsoap.org/ws/2004/09/policy"><wsa:EndpointReference xmlns:wsa="http://www.w3.org/2005/08/addressing"><wsa:Address>{2}</wsa:Address></wsa:EndpointReference></wsp:AppliesTo><t:RequestedSecurityToken>{3}</t:RequestedSecurityToken><t:TokenType>urn:oasis:names:tc:SAML:1.0:assertion</t:TokenType><t:RequestType>http://schemas.xmlsoap.org/ws/2005/02/trust/Issue</t:RequestType><t:KeyType>http://schemas.xmlsoap.org/ws/2005/05/identity/NoProofKey</t:KeyType></t:RequestSecurityTokenResponse> • https://login.microsoftonline.com/login.srf • https://login.microsoftonline.com/extSTS.srf • http://schemas.xmlsoap.org/ws/2005/02/trust/Issue • http://schemas.xmlsoap.org/ws/2005/05/identity/NoProofKey • http://schemas.xmlsoap.org/ws/2005/02/trust/RST/Issue • notes.ini • C:\Users\Public\Lotus\Notes\Data • C:\Users\Public\IBM\Notes\Data • 5libSyncfusionTesseract.dll • )leptonica-1.80.0.dll • .pst • Mapi-Profiles.reg • reg.exe • ostPaths.txt • Software\Microsoft\Windows\CurrentVersion\App Paths\OUTLOOK.EXE • OUTLOOK.EXE • .bak • raw.txt • uri.txt • 1PreconfiguredSources.xml • 9PreconfiguredSources-{0}.xml • !time.windows.com • IX1.Common.Resources.windowsZones.xml • .lnk • \u003c • userwhitelist.xml • Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko • whitelist.xml • 9ContentIndexingOverrides.xml • http://dev-wamp.x1dev.com/scripts/getcrashlog.php • https://logs.x1.com/scripts/getcrashlog.php • http://dev-wamp.x1dev.com/scripts/getminidump.php • https://logs.x1.com/scripts/getminidump.php • )DiagnosticData\dumps • .session.dat • !MiniDumpFileName • xul.dll • .crash.xml • X1.log • X1IndexCore.log • X1ServiceHost.log • !X1MAPIEngine.log • .log • flags.xml • getusagelog.php • getcrashlog.php • https://lavafalls.business.x1.com/x1renewal/mycommerce.php • time.nist.gov • {0}.php • x1l.key • \x1-db-inf.dat • \x1-db-inf1.dat • x1cl.dat • x1license.lfx • x1e.dat • imap.gmail.com • smtp.gmail.com • @gmail.com • 'imap.mail.yahoo.com • 'smtp.mail.yahoo.com • @yahoo.com • m.hotmail.com • @hotmail.com • imap.aol.com • smtp.aol.com • @aol.com • Outlook.com • +imap-mail.outlook.com • +smtp-mail.outlook.com • @outlook.com • )ExtractionConfig.xml • 'LigaturesConfig.xml • X1.exe • +X1SearchSetupBeta.exe • build_version.ini • %UIPluginConfig.xml • !PluginConfig.xml • +X1SearchSetupEval.exe • setup_version.txt • X1SearchSetup.exe • =X1SocialDiscoverySetupBeta.exe • =X1SocialDiscoverySetupEval.exe • 'exchangemapicdo.msi • 5X1SocialDiscoverySetup.exe • 9X1SearchVirtualSetupBeta.exe • 9X1SearchVirtualSetupEval.exe • 1X1SearchVirtualSetup.exe • EX1SearchVirtualServerSetupBeta.exe • EX1SearchVirtualServerSetupEval.exe • =X1SearchVirtualServerSetup.exe • ;EnterpriseManager.GraphQL.Url • YEnterpriseSearch.RelativityServer.WebAPI.URL • HidePlugin.Aol • HidePlugin.PST • -HidePlugin.Outlook.com • https://logs.x1.com/scripts/bootstrapper_version.php • https://logs.x1.com/scripts/product_version.php • https://logs.x1.com/scripts/version.php • X1Service.Mac • ;X1EnterpriseManagerTomcat.exe • =X1EnterpriseManagerService.exe • ;X1EnterpriseSearchService.exe • http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsd • http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd • Xhttps://login.microsoftonline.com/extSTS.srfVhttps://login.microsoftonline.com/login.srfhttps://nexus.microsoftonline-p.com/federationmetadata/2007-06/federationmetadata.xmlhttp://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsdhttp://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsdMozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)*SOFTWARE\Lotus\Notes\BSOFTWARE\WOW6432Node\Lotus\Notes\ 0u • YahooAOLHotmailOutlook.com • X1Setup.log • .X1.Common.Utils.X1List1+<DeDupeWithOrder>d__1 • 6Server: {Server}, FilePath: {FilePath}, Title: {Title} • _CorDllMainmscoree.dll • 10.3.0.9 • 1.0.0.0 |
| Flow Anomalies |
| Offset | FlowVA | Section | Description |
|---|---|---|---|
| 2D85 | 154058 | .text | CALL [static] | Indirect call to absolute memory address |
| 2827D | 11080413 | .text | CALL [static] | Indirect call to absolute memory address |
| C4D92 | B430001 | .text | CALL [static] | Indirect call to absolute memory address |
| C4DC4 | B630001 | .text | CALL [static] | Indirect call to absolute memory address |
| C4DF6 | B830001 | .text | CALL [static] | Indirect call to absolute memory address |
| C4E1E | BA30001 | .text | CALL [static] | Indirect call to absolute memory address |
| C4E5A | BC30001 | .text | CALL [static] | Indirect call to absolute memory address |
| C4E78 | BE30001 | .text | CALL [static] | Indirect call to absolute memory address |
| C4EB4 | C030001 | .text | CALL [static] | Indirect call to absolute memory address |
| C4EFA | C230001 | .text | CALL [static] | Indirect call to absolute memory address |
| C4F4A | C430001 | .text | CALL [static] | Indirect call to absolute memory address |
| C5C10 | 1EC30001 | .text | CALL [static] | Indirect call to absolute memory address |
| C5C38 | 1EE30001 | .text | CALL [static] | Indirect call to absolute memory address |
| C5F1C | 23830001 | .text | CALL [static] | Indirect call to absolute memory address |
| C62DC | 2C430001 | .text | CALL [static] | Indirect call to absolute memory address |
| C6304 | 2C630001 | .text | CALL [static] | Indirect call to absolute memory address |
| C632C | 2C830001 | .text | CALL [static] | Indirect call to absolute memory address |
| C634A | 2CA30001 | .text | CALL [static] | Indirect call to absolute memory address |
| C6368 | 2CC30001 | .text | CALL [static] | Indirect call to absolute memory address |
| CC6C0 | 260B0000 | .text | JMP [static] | Indirect jump to absolute memory address |
| D3DB4 | 20AC1 | .text | CALL [static] | Indirect call to absolute memory address |
| 1506DE | 10002000 | .text | JMP [static] | Indirect jump to absolute memory address |
| Extra Analysis |
| Metric | Value | Percentage |
|---|---|---|
| Ascii Code | 856746 | 62,0902% |
| Null Byte Code | 340680 | 24,6898% |
© 2026 All rights reserved.