PESCAN.IO - Analysis Report Basic

File Structure
Analysis Image
PE Chart Code
Header PE (light blue)
Executable sections (pink)
Non-executable sections (black)
External injected code (red)
File Structure in red = malformed or corrupted header

Chart Code For Other Files
Printable characters (blue)
Non-printable characters (black)
Information
Size: 1,32 MB
SHA-256 Hash: B3059BF31806BBE9362FEB8260379956DA32E99856F7CFEE240B60F823588BC1
SHA-1 Hash: C79FECB9979A3A9D441BD4903D0E6DA4C763E329
MD5 Hash: 626576D1445AF2D5CF45AAFB64439BC2
Imphash: DAE02F32A21E03CE65412F6E56942DAA
MajorOSVersion: 4
MinorOSVersion: 0
CheckSum: 001572C1
EntryPoint (rva): 1524DE
SizeOfHeaders: 200
SizeOfImage: 158000
ImageBase: 10000000
Architecture: x86
ImportTable: 152488
IAT: 2000
Characteristics: 2022
TimeDateStamp: 6994F0B7
Date: 17/02/2026 22:50:31
File Type: DLL
Number Of Sections: 3
ASLR: Disabled
Section Names: .text, .rsrc, .reloc
Number Of Executable Sections: 1
Subsystem: Windows Console

Sections Info
Section Name Flags ROffset RSize VOffset VSizeEntropyChi2
.text
0x60000020
Code
Executable
Readable
200 150600 2000 1504E4
6.0347
22656515.11
.rsrc
0x40000040
Initialized Data
Readable
150800 400 154000 3D8
3.2211
93238.5
.reloc
0x42000040
Initialized Data
GP-Relative
Readable
150C00 200 156000 C
0.1019
128015
Description
OriginalFilename: X1.Common.dll
CompanyName: X1 Discovery, Inc.
LegalCopyright: 2026 X1 Discovery, Inc. All rights reserved.
ProductName: X1 Search
FileDescription: X1.Common
ProductVersion: 10.3.0.9
Language: Unknown (ID=0x0)
CodePage: Unicode (UTF-16 LE) (0x4B0)

Entry Point
The section number (1) - (.text) have the Entry Point
Information -> EntryPoint (calculated) - 1506DE
Code -> FF25002000100000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
Assembler
|JMP DWORD PTR [0X10002000]
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
Signatures
Certificate - Digital Signature Not Found:
• The file is not signed

Packer/Compiler
Compiler: Microsoft Visual .NET - (You can use a decompiler for this...)
AnyCPU: True
Version: v4.0
--------> Agile .NET Obfuscator
Detect It Easy (die)
PE: library: .NET(v4.0.30319)[-]
PE: compiler: VB.NET(-)[-]
PE: linker: Microsoft Linker(48.0)[-]
Entropy: 6.03095

Suspicious Functions
Library Function Description
KERNEL32.DLL GetModuleHandle Retrieves a handle to the specified module.
Windows REG (UNICODE)
Software\Microsoft\Office\
SOFTWARE\Microsoft\Internet Explorer
SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION
SOFTWARE\Microsoft\Windows\shell\Associations\UrlAssociations\http\UserChoice
Software\Microsoft\Windows\CurrentVersion\Internet Settings
SOFTWARE\Lotus\Notes\
SOFTWARE\WOW6432Node\Lotus\Notes\
Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles
Software\Microsoft\Office\{0}.0\Outlook
Software\Microsoft\Office\{0}.0\Outlook\Search
SOFTWARE\Clients\Mail\Microsoft Outlook
Software\Microsoft\Windows\CurrentVersion\App Paths\OUTLOOK.EXE
Software\Microsoft\Office\Common
Software\Microsoft\Office\aOutlook {0} is installed but has never been run!
SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes
Software\Internal ExOne
Software\Mozilla\Mozilla Firefox
SOFTWARE\Microsoft\NET Framework Setup\NDP\
Software\Policies\X1\X1 Search
Software\X1 Search
SOFTWARE\Lotus\Notes\BSOFTWARE\WOW6432Node\Lotus\Notes\ 0u
SOFTWARE\WOW6432Node\Lotus\Notes\ 0u
system\Profiles
System\CentralProcessor\0

File Access
mscoree.dll
wininet.dll
mpr.dll
rstrtmgr.dll
X1.Common.dll
urlmon.dll
msi.dll
Shlwapi.dll
psapi.dll
Crypt32.dll
user32.dll
shell32.dll
kernel32.dll
advapi32.dll
gdi32.dll
System.Web.Scr
System.Windows.Dat
X1.Common.Log
QX1.Common.X1DotNetZip.Zip
2X1.Common.X1DotNetZip.Zip
X1.Common.X1DotNetZip.Zip
ICSharpCode.SharpZipLib.Zip
Xceed.Zip
Temp
RootDir
AppData
UserProfile

File Access (UNICODE)
//ieframe.dll
Common.dll
X1EnterpriseManagerTomcat.exe
;X1EnterpriseSearchService.exe
X1EnterpriseManagerService.exe
;X1EnterpriseManagerTomcat.exe
X1SearchVirtualServerSetup.exe
EX1SearchVirtualServerSetupEval.exe
EX1SearchVirtualServerSetupBeta.exe
1X1SearchVirtualSetup.exe
9X1SearchVirtualSetupEval.exe
9X1SearchVirtualSetupBeta.exe
5X1SocialDiscoverySetup.exe
X1SocialDiscoverySetupEval.exe
X1SocialDiscoverySetupBeta.exe
X1.exe
1X1ServiceHost.exe
X1SearchSetup.exe
+X1SearchSetupEval.exe
+X1SearchSetupBeta.exe
X1.exe
OUTLOOK.EXE
reg.exe
%X1.exe
;X1ServiceHost.exe
xul.dll
0.dll
5libSyncfusionTesseract.dll
.resources.dll
exchangemapicdo.msi
lfxx1e.datx1cl.dat
x1tr.dat
keyx1-db-inf.datx1-db-inf1.dat
x1-obc.dat
x1e.dat
x1cl.dat
\x1-db-inf1.dat
\x1-db-inf.dat
.session.dat
OFile needs to end with .dat
FakeRateLimit.dat
x1tr.dat
AEnterpriseSearchService.Dat
x1info.dat
x1license.dat
*.dat
x1-obc.dat
X1Setup.log
%QA.Log
!X1MAPIEngine.log
X1ServiceHost.log
X1IndexCore.log
X1.log
!RegEx.Log
regex.log
xN+& trasferfiles.txt
jsonexport.jsonversion.txt
setup_version.txt
uri.txt
raw.txt
ostPaths.txt
version.txt
build_version.ini
QKeyFileName entry not found in .ini
notes.ini
OError getting Lotus Notes .ini
ILotus Notes .ini
/Lotus Notes .ini
GChecking for Lotus Notes .ini
Temp
ProgramFiles
AppData

SQL Queries
select DeviceID, MediaType,InterfaceType from Win32_DiskDrive
select * from Win32_LogicalDisk where Name='{0}'MediaType
Select FreeSpace,Size,Name from Win32_LogicalDisk where DriveType=3
SELECT * FROM Win32_OperatingSystem

Interest's Words
outlook
smtp
Encrypt
Decrypt
Encryption
PassWord
<html
<body
<form
<title
cscript
exec
unescape
netsh
tasklist
attrib
start
pause
forfiles
hostname
sdelete
shutdown
logman
systeminfo
ping
expand
replace
setx

Interest's Words (UNICODE)
outlook
smtp
Encrypt
Decrypt
Encryption
PassWord
<html
<head
<body
<script
<link
<meta
<title
<iframe
<main
exec
attrib
start
pause
diskpart
hostname
sdelete
shutdown
at.exe
ping
expand
replace

Anti-VM/Sandbox/Debug Tricks (UNICODE)
LabTools - filemon

URLs
http://unicode.org/reports/tr35/)
http://www.unicode.org/copyright.html
http://schemas.xmlsoap.org/ws/2005/02/trust/RST/IssueTReplyAction6http://schemas.xmlsoap.org/ws/2005/02/trust/RSTR/IssueT
http://schemas.xmlsoap.org/ws/2005/02/trust/RSTR/IssueT
http://X1UI2.LotusNotes;
https://www.x1.com
https://activate.x1.com/customers/ManualRequest.aspx
https://activate.x1.com/webservices/XmlActivationService.asmx
https://activate.x1.com/webservices/XmlLicenseFileService.asmx
https://activate.x1.com

URLs (UNICODE)
http://7/X1DDCollectorV3WindowsOnly
http://{0}/X1DesktopManagerV3WindowsOnly
http://the.fault.action
http://<A href="
http://schemas.microsoft.com/idfx/requesttype/issue
http://schemas.microsoft.com/idfx/keytype/bearer
http://schemas.xmlsoap.org/ws/2005/02/trust"><t:Lifetime><wsu:Created xmlns:wsu="
http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd">{0}</wsu:Created><wsu:Expires xmlns:wsu="
http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd">{1}</wsu:Expires></t:Lifetime><wsp:AppliesTo xmlns:wsp="
http://schemas.xmlsoap.org/ws/2004/09/policy"><wsa:EndpointReference xmlns:wsa="
http://schemas.xmlsoap.org/ws/2005/02/trust/Issue</t:RequestType><t:KeyType>
http://schemas.xmlsoap.org/ws/2005/05/identity/NoProofKey</t:KeyType></t:RequestSecurityTokenResponse>Ewa=wsignin1.0&wctx={0}&wresult={1}
http://schemas.xmlsoap.org/ws/2005/02/trust/Issue
http://schemas.xmlsoap.org/ws/2005/05/identity/NoProofKey
http://schemas.xmlsoap.org/ws/2005/02/trust/RST/Issue
http://dev-wamp.x1dev.com/scripts/getcrashlog.phpWhttps://logs.x1.com/scripts/getcrashlog.php
http://dev-wamp.x1dev.com/scripts/getminidump.phpWhttps://logs.x1.com/scripts/getminidump.php
http://dev-wamp.x1dev.com/scripts/9https://logs.x1.com/scripts/
http://' target=''></a>
http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsdExpires
http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd%0
http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsd
http://-previewtemp
https://{0}/X1DesktopManagerV3WindowsOnly
https://t.co/
https://login.microsoftonline.com/login.srf
https://login.microsoftonline.com/extSTS.srf
https://logs.x1.com/scripts/getcrashlog.php
https://logs.x1.com/scripts/getminidump.php
https://logs.x1.com/scripts/
https://lavafalls.business.x1.com/x1renewal/mycommerce.php
https://logs.x1.com/scripts/bootstrapper_version.php
https://logs.x1.com/scripts/product_version.php
https://logs.x1.com/scripts/version.php
https://login.microsoftonline.com/extSTS.srfV
https://login.microsoftonline.com/login.srf
ftp://gopher://

Emails
support@x1.com

IP Addresses
114.0.0.0
127.0.0.1
121.0.0.0
10.0.27.0
12.0.0.0
17.0.0.0
13.0.0.0
10.3.0.9

Known IP/Domains (UNICODE)
outlook.com
gmail.com
hotmail.com
yahoo.com

Strings/Hex Code Found With The File Rules
Rule Type Encoding Matched (Word)
Text Unicode Unicode escape - \u00 - (Common Unicode escape sequences)
Text Ascii WinAPI Sockets (bind)
Text Unicode WinAPI Sockets (bind)
Text Ascii WinAPI Sockets (listen)
Text Ascii WinAPI Sockets (accept)
Text Unicode WinAPI Sockets (accept)
Text Ascii WinAPI Sockets (connect)
Text Unicode WinAPI Sockets (connect)
Text Ascii WinAPI Sockets (send)
Text Unicode WinAPI Sockets (send)
Text Ascii Registry (RegOpenKeyEx)
Text Ascii File (GetTempPath)
Text Ascii File (CreateFile)
Text Ascii File (ReadFile)
Text Ascii Encryption (CreateDecryptor)
Text Ascii Encryption (CryptoStream)
Text Ascii Encryption (CryptoStreamMode)
Text Ascii Encryption (DESCryptoServiceProvider)
Text Ascii Encryption (FromBase64String)
Text Ascii Encryption (ICryptoTransform)
Text Ascii Encryption (RNGCryptoServiceProvider)
Text Ascii Encryption (Rijndael)
Text Unicode Encryption (Rijndael)
Text Ascii Encryption (RijndaelManaged)
Text Ascii Encryption (ToBase64String)
Text Ascii Encryption (TripleDESCryptoServiceProvider)
Text Ascii Anti-Analysis VM (GlobalMemoryStatusEx)
Text Unicode Anti-Analysis VM (GlobalMemoryStatusEx)
Text Ascii Anti-Analysis VM (GetVersion)
Text Ascii Stealth (CloseHandle)
Text Ascii Execution (ShellExecute)
Text Unicode Privileges (SeAssignPrimaryTokenPrivilege)
Text Unicode Privileges (SeAuditPrivilege)
Text Unicode Privileges (SeBackupPrivilege)
Text Unicode Privileges (SeChangeNotifyPrivilege)
Text Unicode Privileges (SeCreateGlobalPrivilege)
Text Unicode Privileges (SeCreatePagefilePrivilege)
Text Unicode Privileges (SeCreatePermanentPrivilege)
Text Unicode Privileges (SeCreateSymbolicLinkPrivilege)
Text Unicode Privileges (SeCreateTokenPrivilege)
Text Unicode Privileges (SeDebugPrivilege)
Text Unicode Privileges (SeEnableDelegationPrivilege)
Text Unicode Privileges (SeImpersonatePrivilege)
Text Unicode Privileges (SeIncreaseBasePriorityPrivilege)
Text Unicode Privileges (SeIncreaseQuotaPrivilege)
Text Unicode Privileges (SeIncreaseWorkingSetPrivilege)
Text Unicode Privileges (SeLoadDriverPrivilege)
Text Unicode Privileges (SeLockMemoryPrivilege)
Text Unicode Privileges (SeMachineAccountPrivilege)
Text Unicode Privileges (SeManageVolumePrivilege)
Text Unicode Privileges (SeProfileSingleProcessPrivilege)
Text Unicode Privileges (SeRelabelPrivilege)
Text Unicode Privileges (SeRemoteShutdownPrivilege)
Text Unicode Privileges (SeRestorePrivilege)
Text Unicode Privileges (SeSecurityPrivilege)
Text Unicode Privileges (SeShutdownPrivilege)
Text Unicode Privileges (SeSyncAgentPrivilege)
Text Unicode Privileges (SeSystemEnvironmentPrivilege)
Text Unicode Privileges (SeSystemProfilePrivilege)
Text Unicode Privileges (SeSystemtimePrivilege)
Text Unicode Privileges (SeTakeOwnershipPrivilege)
Text Unicode Privileges (SeTcbPrivilege)
Text Unicode Privileges (SeTimeZonePrivilege)
Text Unicode Privileges (SeTrustedCredManAccessPrivilege)
Text Unicode Privileges (SeUndockPrivilege)
Text Ascii Privileges (SE_BACKUP_NAME)
Text Ascii Privileges (SE_PRIVILEGE_ENABLED)
Text Ascii Keyboard Key (LBUTTON)
Text Ascii Keyboard Key (MBUTTON)
Text Ascii Keyboard Key (RBUTTON)
Text Ascii Keyboard Key (Scroll)
Text Ascii Technique used to make malicious code harder to analyze (Obfuscation)
Text Ascii Software that records user activity (Logger)
Text Unicode Software that records user activity (Logger)
Text Ascii Information used for user authentication (Credential)
Text Unicode Information used for user authentication (Credential)
Text Ascii Unauthorized movement of funds or data (Transfer)
Text Unicode Unauthorized movement of funds or data (Transfer)
Text Ascii Malicious rerouting of traffic to an attacker-controlled site (Redirect)
Text Unicode Malicious rerouting of traffic to an attacker-controlled site (Redirect)
Text Ascii Technique used to capture communications between systems (Intercept)
Text Ascii Technique used to circumvent security measures (Bypass)
Entry Point Hex Pattern Microsoft Visual C / Basic .NET
Entry Point Hex Pattern Microsoft Visual C++ 8
Entry Point Hex Pattern Microsoft Visual C++ 8.0
Entry Point Hex Pattern TrueVision Targa Graphics format
Resources
Path DataRVA Size FileOffset CodeText
\VERSION\1\0 154058 380 150858 800334000000560053005F00560045005200530049004F004E005F0049004E0046004F0000000000BD04EFFE000001000300..4...V.S._.V.E.R.S.I.O.N._.I.N.F.O...............
Intelligent String
• X1.Common.dll
• For terms of use, see http://www.unicode.org/copyright.html
• CLDR data files are interpreted according to the LDML specification (http://unicode.org/reports/tr35/)
• x1-obc.dat
• 7ReconfigureQuickCollect.xml
• .dat
• version.txt
• x1e.pfx
• *.dat
• ;X1ServiceHost.exe.*.crash.xml
• %X1.exe.*.crash.xml
• X1EConfig.xml
• x1license.dat
• x1info.dat
• C:\ProgramData\X1E Virtual Config Root
• x1tr.dat
• sharedcache.xml
• regex.log
• RegEx.xml
• http://{0}/X1DesktopManagerV3WindowsOnly
• https://{0}/X1DesktopManagerV3WindowsOnly
• http://the.fault.action
• ?net.tcp://{0}:{2}/X1Service_{1}
• 7net.tcp://{0}/X1Service_{1}
• Cnet.tcp://{0}/X1SearchManager_{1}
• Inet.tcp://{0}/X1EnterpriseSearch/{1}
• -Global\X1E_startup_{0}
• -Global\{0}_startup_{1}
• /Global\{0}_shutdown_{1}
• Enet.tcp://localhost:{2}/X1/{0}_{1}
• ?net.pipe://localhost/X1/{0}_{1}
• .exe
• =res://ieframe.dll
• 1Writing dump html file:
• .htm
• <script
• www.
• .css
• Mozilla/5.0 (Windows NT 6.3; WOW64; Trident/7.0; rv:11.0) like Gecko
• FakeRateLimit.dat
• .dll
• .resources.dll
• .txt
• .mht
• !image/vnd-ms.dds
• .xml
• .csv
• .pdf
• .rtf
• .abw
• .odp
• .ods
• .odt
• .doc
• .ppt
• .xls
• .vsd
• .azw
• .zip
• .rar
• .tar
• .jar
• .avi
• .wav
• .oga
• .ogv
• .ogx
• .aac
• .swf
• .mid
• .mov
• .gif
• .jpg
• .jpm
• .jpx
• .png
• .ico
• .tif
• .svg
• .jxr
• .bmp
• .wmf
• .emf
• .dng
• .dds
• .psd
• .eot
• .otf
• .ttf
• .bin
• .nsf
• URLRewrite.xml
• 7Error dumping registry keys
• res://ieframe.dll
• http://schemas.microsoft.com/idfx/requesttype/issue
• http://schemas.microsoft.com/idfx/keytype/bearer
• <t:RequestSecurityTokenResponse xmlns:t="http://schemas.xmlsoap.org/ws/2005/02/trust"><t:Lifetime><wsu:Created xmlns:wsu="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd">{0}</wsu:Created><wsu:Expires xmlns:wsu="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd">{1}</wsu:Expires></t:Lifetime><wsp:AppliesTo xmlns:wsp="http://schemas.xmlsoap.org/ws/2004/09/policy"><wsa:EndpointReference xmlns:wsa="http://www.w3.org/2005/08/addressing"><wsa:Address>{2}</wsa:Address></wsa:EndpointReference></wsp:AppliesTo><t:RequestedSecurityToken>{3}</t:RequestedSecurityToken><t:TokenType>urn:oasis:names:tc:SAML:1.0:assertion</t:TokenType><t:RequestType>http://schemas.xmlsoap.org/ws/2005/02/trust/Issue</t:RequestType><t:KeyType>http://schemas.xmlsoap.org/ws/2005/05/identity/NoProofKey</t:KeyType></t:RequestSecurityTokenResponse>
• https://login.microsoftonline.com/login.srf
• https://login.microsoftonline.com/extSTS.srf
• http://schemas.xmlsoap.org/ws/2005/02/trust/Issue
• http://schemas.xmlsoap.org/ws/2005/05/identity/NoProofKey
• http://schemas.xmlsoap.org/ws/2005/02/trust/RST/Issue
• notes.ini
• C:\Users\Public\Lotus\Notes\Data
• C:\Users\Public\IBM\Notes\Data
• 5libSyncfusionTesseract.dll
• )leptonica-1.80.0.dll
• .pst
• Mapi-Profiles.reg
• reg.exe
• ostPaths.txt
• Software\Microsoft\Windows\CurrentVersion\App Paths\OUTLOOK.EXE
• OUTLOOK.EXE
• .bak
• raw.txt
• uri.txt
• 1PreconfiguredSources.xml
• 9PreconfiguredSources-{0}.xml
• !time.windows.com
• IX1.Common.Resources.windowsZones.xml
• .lnk
• \u003c
• userwhitelist.xml
• Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
• whitelist.xml
• 9ContentIndexingOverrides.xml
• http://dev-wamp.x1dev.com/scripts/getcrashlog.php
• https://logs.x1.com/scripts/getcrashlog.php
• http://dev-wamp.x1dev.com/scripts/getminidump.php
• https://logs.x1.com/scripts/getminidump.php
• )DiagnosticData\dumps
• .session.dat
• !MiniDumpFileName
• xul.dll
• .crash.xml
• X1.log
• X1IndexCore.log
• X1ServiceHost.log
• !X1MAPIEngine.log
• .log
• flags.xml
• getusagelog.php
• getcrashlog.php
• https://lavafalls.business.x1.com/x1renewal/mycommerce.php
• time.nist.gov
• {0}.php
• x1l.key
• \x1-db-inf.dat
• \x1-db-inf1.dat
• x1cl.dat
• x1license.lfx
• x1e.dat
• imap.gmail.com
• smtp.gmail.com
• @gmail.com
• 'imap.mail.yahoo.com
• 'smtp.mail.yahoo.com
• @yahoo.com
• m.hotmail.com
• @hotmail.com
• imap.aol.com
• smtp.aol.com
• @aol.com
• Outlook.com
• +imap-mail.outlook.com
• +smtp-mail.outlook.com
• @outlook.com
• )ExtractionConfig.xml
• 'LigaturesConfig.xml
• X1.exe
• +X1SearchSetupBeta.exe
• build_version.ini
• %UIPluginConfig.xml
• !PluginConfig.xml
• +X1SearchSetupEval.exe
• setup_version.txt
• X1SearchSetup.exe
• =X1SocialDiscoverySetupBeta.exe
• =X1SocialDiscoverySetupEval.exe
• 'exchangemapicdo.msi
• 5X1SocialDiscoverySetup.exe
• 9X1SearchVirtualSetupBeta.exe
• 9X1SearchVirtualSetupEval.exe
• 1X1SearchVirtualSetup.exe
• EX1SearchVirtualServerSetupBeta.exe
• EX1SearchVirtualServerSetupEval.exe
• =X1SearchVirtualServerSetup.exe
• ;EnterpriseManager.GraphQL.Url
• YEnterpriseSearch.RelativityServer.WebAPI.URL
• HidePlugin.Aol
• HidePlugin.PST
• -HidePlugin.Outlook.com
• https://logs.x1.com/scripts/bootstrapper_version.php
• https://logs.x1.com/scripts/product_version.php
• https://logs.x1.com/scripts/version.php
• X1Service.Mac
• ;X1EnterpriseManagerTomcat.exe
• =X1EnterpriseManagerService.exe
• ;X1EnterpriseSearchService.exe
• http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsd
• http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd
• Xhttps://login.microsoftonline.com/extSTS.srfVhttps://login.microsoftonline.com/login.srfhttps://nexus.microsoftonline-p.com/federationmetadata/2007-06/federationmetadata.xmlhttp://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsdhttp://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsdMozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)*SOFTWARE\Lotus\Notes\BSOFTWARE\WOW6432Node\Lotus\Notes\ 0u
• YahooAOLHotmailOutlook.com
• X1Setup.log
• .X1.Common.Utils.X1List1+<DeDupeWithOrder>d__1
• 6Server: {Server}, FilePath: {FilePath}, Title: {Title}
• _CorDllMainmscoree.dll
• 10.3.0.9
• 1.0.0.0

Flow Anomalies
Offset FlowVA Section Description
2D85 154058 .text CALL [static] | Indirect call to absolute memory address
2827D 11080413 .text CALL [static] | Indirect call to absolute memory address
C4D92 B430001 .text CALL [static] | Indirect call to absolute memory address
C4DC4 B630001 .text CALL [static] | Indirect call to absolute memory address
C4DF6 B830001 .text CALL [static] | Indirect call to absolute memory address
C4E1E BA30001 .text CALL [static] | Indirect call to absolute memory address
C4E5A BC30001 .text CALL [static] | Indirect call to absolute memory address
C4E78 BE30001 .text CALL [static] | Indirect call to absolute memory address
C4EB4 C030001 .text CALL [static] | Indirect call to absolute memory address
C4EFA C230001 .text CALL [static] | Indirect call to absolute memory address
C4F4A C430001 .text CALL [static] | Indirect call to absolute memory address
C5C10 1EC30001 .text CALL [static] | Indirect call to absolute memory address
C5C38 1EE30001 .text CALL [static] | Indirect call to absolute memory address
C5F1C 23830001 .text CALL [static] | Indirect call to absolute memory address
C62DC 2C430001 .text CALL [static] | Indirect call to absolute memory address
C6304 2C630001 .text CALL [static] | Indirect call to absolute memory address
C632C 2C830001 .text CALL [static] | Indirect call to absolute memory address
C634A 2CA30001 .text CALL [static] | Indirect call to absolute memory address
C6368 2CC30001 .text CALL [static] | Indirect call to absolute memory address
CC6C0 260B0000 .text JMP [static] | Indirect jump to absolute memory address
D3DB4 20AC1 .text CALL [static] | Indirect call to absolute memory address
1506DE 10002000 .text JMP [static] | Indirect jump to absolute memory address
Extra Analysis
Metric Value Percentage
Ascii Code 856746 62,0902%
Null Byte Code 340680 24,6898%
© 2026 All rights reserved.