PESCAN.IO - Analysis Report Basic |
|||||||
| File Structure |
|
PE Chart Code
Header PE (light blue)
Executable sections (pink)
Non-executable sections (black)
External injected code (red)
File Structure in red = malformed or corrupted header
Chart Code For Other Files
Printable characters (blue)
Non-printable characters (black)
| Information |
Icon: Size: 1,01 MBSHA-256 Hash: 606CAC62E510927BE32527EDE5587135CEF6AC366689ECD5CE927ADD4A1F7F7C SHA-1 Hash: 7EFF430CD03D465FFB10A4106DB416D9BFE38D41 MD5 Hash: 6B481AC94109D7630AE52B7A43BDD5BB Imphash: 0E90466E69EF9F142C32141C3762135A MajorOSVersion: 6 MinorOSVersion: 0 CheckSum: 00101C0D EntryPoint (rva): 149F0 SizeOfHeaders: 400 SizeOfImage: 107000 ImageBase: 0000000140000000 Architecture: x64 ImportTable: B7A00 IAT: B7DE0 Characteristics: 22 TimeDateStamp: 6AA2FB42 Date: 10/09/2026 18:47:30 File Type: EXE Number Of Sections: 8 ASLR: Disabled Section Names (Optional Header): .text, .rdata, .data, .pdata, .tls, _RDATA, .rsrc, .reloc Number Of Executable Sections: 1 Subsystem: Windows GUI UAC Execution Level Manifest: asInvoker |
| Sections Info |
| Section Name | Flags | ROffset | RSize | VOffset | VSize | Entropy | Chi2 |
|---|---|---|---|---|---|---|---|
| .text | 0x60000020 Code Executable Readable |
400 | 22C00 | 1000 | 22BF1 |
|
|
| .rdata | 0x40000040 Initialized Data Readable |
23000 | 95E00 | 24000 | 95C5C |
|
|
| .data | 0xC0000040 Initialized Data Readable Writeable |
B8E00 | 2200 | BA000 | 2BC0 |
|
|
| .pdata | 0x40000040 Initialized Data Readable |
BB000 | 1400 | BD000 | 1398 |
|
|
| .tls | 0xC0000040 Initialized Data Readable Writeable |
BC400 | 200 | BF000 | B9 |
|
|
| _RDATA | 0x40000040 Initialized Data Readable |
BC600 | 600 | C0000 | 444 |
|
|
| .rsrc | 0x40000040 Initialized Data Readable |
BCC00 | 44400 | C1000 | 443F0 |
|
|
| .reloc | 0x42000040 Initialized Data GP-Relative Readable |
101000 | 800 | 106000 | 6F8 |
|
|
| Description |
| OriginalFilename: wevomia.exe CompanyName: Egrawoasia GmbH LegalCopyright: Copyright 2021 Egrawoasia GmbH ProductName: Wevomia FileVersion: 4.9.5.479 FileDescription: Wevomia Agent ProductVersion: 4.9.5.479 Language: English (United States) (ID=0x409) CodePage: Unicode (UTF-16 LE) (0x4B0) |
| Entry Point |
The section number (1) have the Entry Point Information -> EntryPoint (calculated) - 13DF0 Code -> 4883EC28E8170000004883C428E96EFEFFFFCCCCCCCCCCCCCCCCCCCCCCCCCCCC40534883EC30488B05A36B0A0048BB32A2DF Assembler |SUB RSP, 0X28 |CALL 0X140014A10 |ADD RSP, 0X28 |JMP 0X140014870 |INT3 |INT3 |INT3 |INT3 |INT3 |INT3 |INT3 |INT3 |INT3 |INT3 |INT3 |INT3 |INT3 |INT3 |PUSH RBX |SUB RSP, 0X30 |MOV RAX, QWORD PTR [RIP + 0XA6BA3] |
| Signatures |
| CheckSum Integrity Problem: • Header: 1055757 • Calculated: 1069921 Certificate - Digital Signature Not Found: • The file is not signed |
| Packer/Compiler |
| Detect It Easy (die) • PE+(64): compiler: Microsoft Visual C/C++(2015 v.14.0)[-] • PE+(64): linker: Microsoft Linker(14.0)[-] • Entropy: 6.1361 |
| Suspicious Functions |
| Library | Function | Description |
|---|---|---|
| KERNEL32.DLL | WriteFile | Writes data to a specified file or input/output (I/O) device. |
| KERNEL32.DLL | LoadLibraryA | Loads the specified module into the address space of the calling process. |
| KERNEL32.DLL | GetModuleHandleA | Retrieves a handle to the specified module. |
| KERNEL32.DLL | GetModuleHandleW | Retrieves a handle to the specified module. |
| KERNEL32.DLL | GetProcAddress | Retrieves the address of an exported function or variable from the specified dynamic-link library (DLL). |
| KERNEL32.DLL | IsDebuggerPresent | Determines if the calling process is being debugged by a user-mode debugger. |
| KERNEL32.DLL | CreateFileW | Creates or opens a file object. |
| KERNEL32.DLL | ReadFile | Reads data from a file. |
| KERNEL32.DLL | FindNextFileW | Continues file and directory enumeration. |
| KERNEL32.DLL | FindClose | Closes a file search handle. |
| KERNEL32.DLL | CloseHandle | Closes an open object handle. |
| KERNEL32.DLL | VirtualProtect | Changes memory protection attributes. |
| File Access |
| ntdll.dll gdi32.dll kernel32.dll user32.dll P.SCr @.dat \ProgramData\compere\schlualyaiantly.txt |L0rZZ.WSH To}o&bcGEj7Yr$.ZIP PcoZZ5FjC.rAr |
| File Access (UNICODE) |
| wevomia.exe mscoree.dll $.dll |
| Interest's Words |
| fuck - }:) Encrypt Decrypt Encryption exec start |
| URLs |
| http://schemas.microsoft.com/SMI/2005/WindowsSettings |
| Emails |
| J@mZr7.Fd 5@CdZA.KS hmG5Px8A@J.C0r jU@JOxhW.ITPP ECO@rz.LZ ZT3uk@3Dk4mLN.zxr5 C@AUu.ZFZFm 0@ZZFYT9.KC |
| Strings/Hex Code Found With The File Rules |
| Rule Type | Encoding | Matched (Word) |
|---|---|---|
| Entry Point | Hex Pattern | Microsoft Visual C++ 8.0 (DLL) |
| Entry Point | Hex Pattern | Microsoft Visual C++ 8.0 |
| Resources |
| Path | DataRVA | Size | FileOffset | Code | Text |
|---|---|---|---|---|---|
| \RT_MANIFEST\1\1033 | C14C0 | 459 | BD0C0 | 3C3F786D6C2076657273696F6E3D22312E302220656E636F64696E673D225554462D3822207374616E64616C6F6E653D2279 | <?xml version="1.0" encoding="UTF-8" standalone="y |
| \ICON\1\1033 | C1920 | 40158 | BD520 | 89504E470D0A1A0A0000000D49484452000001000000010008060000005C72A8660004011F49444154780100FFFF000000B7 | .PNG........IHDR.............\r.f....IDATx........ |
| \ICON\2\1033 | 101A78 | 2474 | FD678 | 89504E470D0A1A0A0000000D49484452000000300000003008060000005702F9870000243B494441547801013024CFDB00B7 | .PNG........IHDR...0...0.....W.....$;IDATx..0$.... |
| \ICON\3\1033 | 103EF0 | 1064 | FFAF0 | 89504E470D0A1A0A0000000D4948445200000020000000200806000000737A7AF40000102B494441547801012010DFEF00B7 | .PNG........IHDR... ... .....szz....+IDATx.. ..... |
| \ICON\4\1033 | 104F58 | 454 | 100B58 | 89504E470D0A1A0A0000000D49484452000000100000001008060000001FF3FF610000041B494441547801011004EFFB00B7 | .PNG........IHDR................a....IDATx........ |
| \GROUP_ICON\1\1033 | 1053B0 | 3E | 100FB0 | 0000010004000000000001002000580104000100303000000100200074240000020020200000010020006410000003001010000001002000540400000400 | ............ .X.....00.... .t$.... .... .d........... .T..... |
| \VERSION\1\1033 | C11E0 | 2DC | BCDE0 | DC0234000000560053005F00560045005200530049004F004E005F0049004E0046004F0000000000BD04EFFE000001000900 | ..4...V.S._.V.E.R.S.I.O.N._.I.N.F.O............... |
| Intelligent String |
| • 4.9.5.479 • wevomia.exe • @.tls • C:\Program Files\soundest\irryuiabs.cfg;@ • $.dll • mscoree.dll • ntwritefileuser32.dll • kernel32.dll • gdi32.dll • ntdll.dll • <dpiAware xmlns="http://schemas.microsoft.com/SMI/2005/WindowsSettings">true</dpiAware> |
| Flow Anomalies |
| Offset | FlowVA | Section | Description |
|---|---|---|---|
| 581 | N/A | .text | CALL QWORD PTR [RIP+0xB6E01] |
| 589 | N/A | .text | CALL QWORD PTR [RIP+0xB6DB1] |
| 592 | N/A | .text | CALL QWORD PTR [RIP+0xB6E30] |
| 5A4 | N/A | .text | CALL QWORD PTR [RIP+0xB6F1E] |
| 5E7 | N/A | .text | CALL QWORD PTR [RIP+0xB6D9B] |
| 5EF | N/A | .text | CALL QWORD PTR [RIP+0xB6D0B] |
| 600 | N/A | .text | CALL QWORD PTR [RIP+0xB6CF2] |
| 612 | N/A | .text | CALL QWORD PTR [RIP+0xB6EB0] |
| BB8 | N/A | .text | CALL QWORD PTR [RIP+0xB67DA] |
| BD6 | N/A | .text | CALL QWORD PTR [RIP+0xB67DC] |
| 124D | N/A | .text | CALL QWORD PTR [RIP+0xB616D] |
| 1271 | N/A | .text | JMP QWORD PTR [RIP+0xB6181] |
| 14E1 | N/A | .text | CALL QWORD PTR [RIP+0xB5D49] |
| 1504 | N/A | .text | CALL QWORD PTR [RIP+0xB5D36] |
| 1607 | N/A | .text | CALL QWORD PTR [RIP+0xB5DB3] |
| 1615 | N/A | .text | CALL QWORD PTR [RIP+0xB5DDD] |
| 163E | N/A | .text | CALL QWORD PTR [RIP+0xB5D7C] |
| 164C | N/A | .text | CALL QWORD PTR [RIP+0xB5DA6] |
| 1797 | N/A | .text | CALL QWORD PTR [RIP+0xB5C23] |
| 17A5 | N/A | .text | CALL QWORD PTR [RIP+0xB5C4D] |
| 18DD | N/A | .text | CALL QWORD PTR [RIP+0xB5ADD] |
| 18EB | N/A | .text | CALL QWORD PTR [RIP+0xB5B07] |
| 195C | N/A | .text | CALL QWORD PTR [RIP+0xB5A5E] |
| 196A | N/A | .text | CALL QWORD PTR [RIP+0xB5A88] |
| 197D | N/A | .text | CALL QWORD PTR [RIP+0xB5A3D] |
| 198B | N/A | .text | CALL QWORD PTR [RIP+0xB5A67] |
| 1B09 | N/A | .text | CALL QWORD PTR [RIP+0xB58B1] |
| 1B17 | N/A | .text | CALL QWORD PTR [RIP+0xB58DB] |
| 1C49 | N/A | .text | CALL QWORD PTR [RIP+0xB5771] |
| 1C57 | N/A | .text | CALL QWORD PTR [RIP+0xB579B] |
| 1C62 | N/A | .text | CALL QWORD PTR [RIP+0xB5758] |
| 1C70 | N/A | .text | CALL QWORD PTR [RIP+0xB5782] |
| 1CDD | N/A | .text | CALL QWORD PTR [RIP+0xB56DD] |
| 1CEB | N/A | .text | CALL QWORD PTR [RIP+0xB5707] |
| 1D87 | N/A | .text | CALL QWORD PTR [RIP+0xB5633] |
| 1D95 | N/A | .text | CALL QWORD PTR [RIP+0xB565D] |
| 1E15 | N/A | .text | CALL QWORD PTR [RIP+0xB55A5] |
| 1E28 | N/A | .text | CALL QWORD PTR [RIP+0xB55CA] |
| 1ED6 | N/A | .text | CALL QWORD PTR [RIP+0xB54E4] |
| 1EE4 | N/A | .text | CALL QWORD PTR [RIP+0xB550E] |
| 2459 | N/A | .text | CALL QWORD PTR [RIP+0xB4F61] |
| 2467 | N/A | .text | CALL QWORD PTR [RIP+0xB4F8B] |
| 2519 | N/A | .text | CALL QWORD PTR [RIP+0xB4EA1] |
| 2527 | N/A | .text | CALL QWORD PTR [RIP+0xB4ECB] |
| 2649 | N/A | .text | CALL QWORD PTR [RIP+0xB4D71] |
| 2657 | N/A | .text | CALL QWORD PTR [RIP+0xB4D9B] |
| 285D | N/A | .text | CALL QWORD PTR [RIP+0xB497D] |
| 2BB2 | N/A | .text | CALL QWORD PTR [RIP+0xB4680] |
| 2BFC | N/A | .text | CALL QWORD PTR [RIP+0xB47BE] |
| 2C0A | N/A | .text | CALL QWORD PTR [RIP+0xB47E8] |
| 2D9E | N/A | .text | CALL QWORD PTR [RIP+0xB461C] |
| 2DAC | N/A | .text | CALL QWORD PTR [RIP+0xB4646] |
| 30E8 | N/A | .text | CALL QWORD PTR [RIP+0xB42D2] |
| 30F6 | N/A | .text | CALL QWORD PTR [RIP+0xB42FC] |
| 3109 | N/A | .text | CALL QWORD PTR [RIP+0xB42B1] |
| 3117 | N/A | .text | CALL QWORD PTR [RIP+0xB42DB] |
| 317C | N/A | .text | CALL QWORD PTR [RIP+0xB423E] |
| 318A | N/A | .text | CALL QWORD PTR [RIP+0xB4268] |
| 33DC | N/A | .text | CALL QWORD PTR [RIP+0xB3FDE] |
| 33EA | N/A | .text | CALL QWORD PTR [RIP+0xB4008] |
| 34ED | N/A | .text | CALL QWORD PTR [RIP+0xB3ECD] |
| 34FB | N/A | .text | CALL QWORD PTR [RIP+0xB3EF7] |
| 354C | N/A | .text | CALL QWORD PTR [RIP+0xB3C96] |
| 35F2 | N/A | .text | CALL QWORD PTR [RIP+0xB3DC8] |
| 3600 | N/A | .text | CALL QWORD PTR [RIP+0xB3DF2] |
| 3754 | N/A | .text | CALL QWORD PTR [RIP+0xB3C66] |
| 3762 | N/A | .text | CALL QWORD PTR [RIP+0xB3C90] |
| 3798 | N/A | .text | CALL QWORD PTR [RIP+0xB3C22] |
| 37A6 | N/A | .text | CALL QWORD PTR [RIP+0xB3C4C] |
| 385D | N/A | .text | CALL QWORD PTR [RIP+0xB3B5D] |
| 386B | N/A | .text | CALL QWORD PTR [RIP+0xB3B87] |
| 387E | N/A | .text | CALL QWORD PTR [RIP+0xB3B3C] |
| 388C | N/A | .text | CALL QWORD PTR [RIP+0xB3B66] |
| 38DC | N/A | .text | CALL QWORD PTR [RIP+0xB3ADE] |
| 38EA | N/A | .text | CALL QWORD PTR [RIP+0xB3B08] |
| 3AC3 | N/A | .text | CALL QWORD PTR [RIP+0xB38F7] |
| 3AD6 | N/A | .text | CALL QWORD PTR [RIP+0xB391C] |
| 3B05 | N/A | .text | CALL QWORD PTR [RIP+0xB38B5] |
| 3B13 | N/A | .text | CALL QWORD PTR [RIP+0xB38DF] |
| 3DD2 | N/A | .text | CALL QWORD PTR [RIP+0xB35E8] |
| 3DE0 | N/A | .text | CALL QWORD PTR [RIP+0xB3612] |
| 3E32 | N/A | .text | CALL QWORD PTR [RIP+0xB3588] |
| 3E40 | N/A | .text | CALL QWORD PTR [RIP+0xB35B2] |
| 3F84 | N/A | .text | CALL QWORD PTR [RIP+0xB3436] |
| 3F92 | N/A | .text | CALL QWORD PTR [RIP+0xB3460] |
| 4000 | N/A | .text | CALL QWORD PTR [RIP+0xB33BA] |
| 400E | N/A | .text | CALL QWORD PTR [RIP+0xB33E4] |
| 4043 | N/A | .text | CALL QWORD PTR [RIP+0xB3377] |
| 4051 | N/A | .text | CALL QWORD PTR [RIP+0xB33A1] |
| 408E | N/A | .text | CALL QWORD PTR [RIP+0xB332C] |
| 409C | N/A | .text | CALL QWORD PTR [RIP+0xB3356] |
| 40AF | N/A | .text | CALL QWORD PTR [RIP+0xB330B] |
| 40BD | N/A | .text | CALL QWORD PTR [RIP+0xB3335] |
| 40C8 | N/A | .text | CALL QWORD PTR [RIP+0xB32F2] |
| 40D6 | N/A | .text | CALL QWORD PTR [RIP+0xB331C] |
| 40E9 | N/A | .text | CALL QWORD PTR [RIP+0xB32D1] |
| 40F7 | N/A | .text | CALL QWORD PTR [RIP+0xB32FB] |
| 41C5 | N/A | .text | CALL QWORD PTR [RIP+0xB31F5] |
| 41D3 | N/A | .text | CALL QWORD PTR [RIP+0xB321F] |
| 41E6 | N/A | .text | CALL QWORD PTR [RIP+0xB31D4] |
| BB000 | 140001000 | .pdata | ExceptionHook | Pointer to 1000 - 0x400 .text + UnwindInfo: .rdata |
| BB00C | 140001086 | .pdata | ExceptionHook | Pointer to 1086 - 0x486 .text + UnwindInfo: .rdata |
| BB018 | 140001294 | .pdata | ExceptionHook | Pointer to 1294 - 0x694 .text + UnwindInfo: .rdata |
| BB024 | 140001605 | .pdata | ExceptionHook | Pointer to 1605 - 0xA05 .text + UnwindInfo: .rdata |
| BB030 | 14000179D | .pdata | ExceptionHook | Pointer to 179D - 0xB9D .text + UnwindInfo: .rdata |
| BB03C | 140001800 | .pdata | ExceptionHook | Pointer to 1800 - 0xC00 .text + UnwindInfo: .rdata |
| BB048 | 14000184C | .pdata | ExceptionHook | Pointer to 184C - 0xC4C .text + UnwindInfo: .rdata |
| BB054 | 140001A5C | .pdata | ExceptionHook | Pointer to 1A5C - 0xE5C .text + UnwindInfo: .rdata |
| BB060 | 140002169 | .pdata | ExceptionHook | Pointer to 2169 - 0x1569 .text + UnwindInfo: .rdata |
| BB06C | 140006358 | .pdata | ExceptionHook | Pointer to 6358 - 0x5758 .text + UnwindInfo: .rdata |
| BB078 | 1400063BC | .pdata | ExceptionHook | Pointer to 63BC - 0x57BC .text + UnwindInfo: .rdata |
| BB084 | 14000644D | .pdata | ExceptionHook | Pointer to 644D - 0x584D .text + UnwindInfo: .rdata |
| BB090 | 140006495 | .pdata | ExceptionHook | Pointer to 6495 - 0x5895 .text + UnwindInfo: .rdata |
| BB09C | 1400065A2 | .pdata | ExceptionHook | Pointer to 65A2 - 0x59A2 .text + UnwindInfo: .rdata |
| BB0A8 | 1400065EC | .pdata | ExceptionHook | Pointer to 65EC - 0x59EC .text + UnwindInfo: .rdata |
| BB0B4 | 140006ADE | .pdata | ExceptionHook | Pointer to 6ADE - 0x5EDE .text + UnwindInfo: .rdata |
| BB0C0 | 140006BEE | .pdata | ExceptionHook | Pointer to 6BEE - 0x5FEE .text + UnwindInfo: .rdata |
| BB0CC | 140006C33 | .pdata | ExceptionHook | Pointer to 6C33 - 0x6033 .text + UnwindInfo: .rdata |
| BB0D8 | 140006C62 | .pdata | ExceptionHook | Pointer to 6C62 - 0x6062 .text + UnwindInfo: .rdata |
| BB0E4 | 140006D9C | .pdata | ExceptionHook | Pointer to 6D9C - 0x619C .text + UnwindInfo: .rdata |
| BB0F0 | 140006E04 | .pdata | ExceptionHook | Pointer to 6E04 - 0x6204 .text + UnwindInfo: .rdata |
| BB0FC | 140006E4F | .pdata | ExceptionHook | Pointer to 6E4F - 0x624F .text + UnwindInfo: .rdata |
| BB108 | 1400072CD | .pdata | ExceptionHook | Pointer to 72CD - 0x66CD .text + UnwindInfo: .rdata |
| BB114 | 140007F62 | .pdata | ExceptionHook | Pointer to 7F62 - 0x7362 .text + UnwindInfo: .rdata |
| BB120 | 140007F9D | .pdata | ExceptionHook | Pointer to 7F9D - 0x739D .text + UnwindInfo: .rdata |
| BB12C | 140008077 | .pdata | ExceptionHook | Pointer to 8077 - 0x7477 .text + UnwindInfo: .rdata |
| BB138 | 1400080A5 | .pdata | ExceptionHook | Pointer to 80A5 - 0x74A5 .text + UnwindInfo: .rdata |
| BB144 | 140008128 | .pdata | ExceptionHook | Pointer to 8128 - 0x7528 .text + UnwindInfo: .rdata |
| BB150 | 140008187 | .pdata | ExceptionHook | Pointer to 8187 - 0x7587 .text + UnwindInfo: .rdata |
| BB15C | 140008943 | .pdata | ExceptionHook | Pointer to 8943 - 0x7D43 .text + UnwindInfo: .rdata |
| BB168 | 14000898D | .pdata | ExceptionHook | Pointer to 898D - 0x7D8D .text + UnwindInfo: .rdata |
| BB174 | 140008A1C | .pdata | ExceptionHook | Pointer to 8A1C - 0x7E1C .text + UnwindInfo: .rdata |
| BB180 | 140008B22 | .pdata | ExceptionHook | Pointer to 8B22 - 0x7F22 .text + UnwindInfo: .rdata |
| BB18C | 140008D74 | .pdata | ExceptionHook | Pointer to 8D74 - 0x8174 .text + UnwindInfo: .rdata |
| BB198 | 140008DE3 | .pdata | ExceptionHook | Pointer to 8DE3 - 0x81E3 .text + UnwindInfo: .rdata |
| BB1A4 | 140008E8B | .pdata | ExceptionHook | Pointer to 8E8B - 0x828B .text + UnwindInfo: .rdata |
| BB1B0 | 140008F0F | .pdata | ExceptionHook | Pointer to 8F0F - 0x830F .text + UnwindInfo: .rdata |
| BB1BC | 1400092FE | .pdata | ExceptionHook | Pointer to 92FE - 0x86FE .text + UnwindInfo: .rdata |
| BB1C8 | 140009508 | .pdata | ExceptionHook | Pointer to 9508 - 0x8908 .text + UnwindInfo: .rdata |
| BB1D4 | 14000955F | .pdata | ExceptionHook | Pointer to 955F - 0x895F .text + UnwindInfo: .rdata |
| BB1E0 | 14000958F | .pdata | ExceptionHook | Pointer to 958F - 0x898F .text + UnwindInfo: .rdata |
| BB1EC | 14000A762 | .pdata | ExceptionHook | Pointer to A762 - 0x9B62 .text + UnwindInfo: .rdata |
| BB1F8 | 14000AA9B | .pdata | ExceptionHook | Pointer to AA9B - 0x9E9B .text + UnwindInfo: .rdata |
| BB204 | 14000B0D3 | .pdata | ExceptionHook | Pointer to B0D3 - 0xA4D3 .text + UnwindInfo: .rdata |
| BB210 | 14000B234 | .pdata | ExceptionHook | Pointer to B234 - 0xA634 .text + UnwindInfo: .rdata |
| BB21C | 14000B2A9 | .pdata | ExceptionHook | Pointer to B2A9 - 0xA6A9 .text + UnwindInfo: .rdata |
| BB228 | 14000B557 | .pdata | ExceptionHook | Pointer to B557 - 0xA957 .text + UnwindInfo: .rdata |
| BB234 | 14000B8F9 | .pdata | ExceptionHook | Pointer to B8F9 - 0xACF9 .text + UnwindInfo: .rdata |
| BB240 | 14000C75B | .pdata | ExceptionHook | Pointer to C75B - 0xBB5B .text + UnwindInfo: .rdata |
| BB24C | 14000C9A6 | .pdata | ExceptionHook | Pointer to C9A6 - 0xBDA6 .text + UnwindInfo: .rdata |
| BB258 | 14000C9DD | .pdata | ExceptionHook | Pointer to C9DD - 0xBDDD .text + UnwindInfo: .rdata |
| BB264 | 14000CE4D | .pdata | ExceptionHook | Pointer to CE4D - 0xC24D .text + UnwindInfo: .rdata |
| BB270 | 14000D672 | .pdata | ExceptionHook | Pointer to D672 - 0xCA72 .text + UnwindInfo: .rdata |
| BB27C | 14000D888 | .pdata | ExceptionHook | Pointer to D888 - 0xCC88 .text + UnwindInfo: .rdata |
| BB288 | 14000D909 | .pdata | ExceptionHook | Pointer to D909 - 0xCD09 .text + UnwindInfo: .rdata |
| BB294 | 14001366B | .pdata | ExceptionHook | Pointer to 1366B - 0x12A6B .text + UnwindInfo: .rdata |
| BB2A0 | 1400136E1 | .pdata | ExceptionHook | Pointer to 136E1 - 0x12AE1 .text + UnwindInfo: .rdata |
| BB2AC | 1400138E5 | .pdata | ExceptionHook | Pointer to 138E5 - 0x12CE5 .text + UnwindInfo: .rdata |
| BB2B8 | 140013913 | .pdata | ExceptionHook | Pointer to 13913 - 0x12D13 .text + UnwindInfo: .rdata |
| BB2C4 | 140013940 | .pdata | ExceptionHook | Pointer to 13940 - 0x12D40 .text + UnwindInfo: .rdata |
| BB2D0 | 1400139A4 | .pdata | ExceptionHook | Pointer to 139A4 - 0x12DA4 .text + UnwindInfo: .rdata |
| BB2DC | 140013C01 | .pdata | ExceptionHook | Pointer to 13C01 - 0x13001 .text + UnwindInfo: .rdata |
| BB2E8 | 140013ED0 | .pdata | ExceptionHook | Pointer to 13ED0 - 0x132D0 .text + UnwindInfo: .rdata |
| BB2F4 | 140013F05 | .pdata | ExceptionHook | Pointer to 13F05 - 0x13305 .text + UnwindInfo: .rdata |
| BB300 | 140013FDB | .pdata | ExceptionHook | Pointer to 13FDB - 0x133DB .text + UnwindInfo: .rdata |
| BB30C | 140014038 | .pdata | ExceptionHook | Pointer to 14038 - 0x13438 .text + UnwindInfo: .rdata |
| BB318 | 1400140D0 | .pdata | ExceptionHook | Pointer to 140D0 - 0x134D0 .text + UnwindInfo: .rdata |
| BB324 | 140014120 | .pdata | ExceptionHook | Pointer to 14120 - 0x13520 .text + UnwindInfo: .rdata |
| BB330 | 140014160 | .pdata | ExceptionHook | Pointer to 14160 - 0x13560 .text + UnwindInfo: .rdata |
| BB33C | 140014200 | .pdata | ExceptionHook | Pointer to 14200 - 0x13600 .text + UnwindInfo: .rdata |
| BB348 | 140014250 | .pdata | ExceptionHook | Pointer to 14250 - 0x13650 .text + UnwindInfo: .rdata |
| BB354 | 140014280 | .pdata | ExceptionHook | Pointer to 14280 - 0x13680 .text + UnwindInfo: .rdata |
| BB360 | 1400142C0 | .pdata | ExceptionHook | Pointer to 142C0 - 0x136C0 .text + UnwindInfo: .rdata |
| BB36C | 1400142F0 | .pdata | ExceptionHook | Pointer to 142F0 - 0x136F0 .text + UnwindInfo: .rdata |
| BB378 | 140014390 | .pdata | ExceptionHook | Pointer to 14390 - 0x13790 .text + UnwindInfo: .rdata |
| BB384 | 14001439B | .pdata | ExceptionHook | Pointer to 1439B - 0x1379B .text + UnwindInfo: .rdata |
| BB390 | 1400144D3 | .pdata | ExceptionHook | Pointer to 144D3 - 0x138D3 .text + UnwindInfo: .rdata |
| BB39C | 140014670 | .pdata | ExceptionHook | Pointer to 14670 - 0x13A70 .text + UnwindInfo: .rdata |
| BB3A8 | 140014710 | .pdata | ExceptionHook | Pointer to 14710 - 0x13B10 .text + UnwindInfo: .rdata |
| BB3B4 | 140014780 | .pdata | ExceptionHook | Pointer to 14780 - 0x13B80 .text + UnwindInfo: .rdata |
| BB3C0 | 140014840 | .pdata | ExceptionHook | Pointer to 14840 - 0x13C40 .text + UnwindInfo: .rdata |
| BB3CC | 140014850 | .pdata | ExceptionHook | Pointer to 14850 - 0x13C50 .text + UnwindInfo: .rdata |
| BB3D8 | 140014870 | .pdata | ExceptionHook | Pointer to 14870 - 0x13C70 .text + UnwindInfo: .rdata |
| BB3E4 | 1400149F0 | .pdata | ExceptionHook | Pointer to 149F0 - 0x13DF0 .text + UnwindInfo: .rdata |
| BB3F0 | 140014A10 | .pdata | ExceptionHook | Pointer to 14A10 - 0x13E10 .text + UnwindInfo: .rdata |
| BB3FC | 140014B00 | .pdata | ExceptionHook | Pointer to 14B00 - 0x13F00 .text + UnwindInfo: .rdata |
| BB408 | 140014B70 | .pdata | ExceptionHook | Pointer to 14B70 - 0x13F70 .text + UnwindInfo: .rdata |
| BB414 | 140014BC0 | .pdata | ExceptionHook | Pointer to 14BC0 - 0x13FC0 .text + UnwindInfo: .rdata |
| BB420 | 140014C10 | .pdata | ExceptionHook | Pointer to 14C10 - 0x14010 .text + UnwindInfo: .rdata |
| BB42C | 140014E30 | .pdata | ExceptionHook | Pointer to 14E30 - 0x14230 .text + UnwindInfo: .rdata |
| BB438 | 140014EA0 | .pdata | ExceptionHook | Pointer to 14EA0 - 0x142A0 .text + UnwindInfo: .rdata |
| BB444 | 140014EC0 | .pdata | ExceptionHook | Pointer to 14EC0 - 0x142C0 .text + UnwindInfo: .rdata |
| BB450 | 140014F00 | .pdata | ExceptionHook | Pointer to 14F00 - 0x14300 .text + UnwindInfo: .rdata |
| BB45C | 140014F20 | .pdata | ExceptionHook | Pointer to 14F20 - 0x14320 .text + UnwindInfo: .rdata |
| BB468 | 140014F70 | .pdata | ExceptionHook | Pointer to 14F70 - 0x14370 .text + UnwindInfo: .rdata |
| BB474 | 140015010 | .pdata | ExceptionHook | Pointer to 15010 - 0x14410 .text + UnwindInfo: .rdata |
| BB480 | 140015040 | .pdata | ExceptionHook | Pointer to 15040 - 0x14440 .text + UnwindInfo: .rdata |
| BB48C | 140015074 | .pdata | ExceptionHook | Pointer to 15074 - 0x14474 .text + UnwindInfo: .rdata |
| BB498 | 140015098 | .pdata | ExceptionHook | Pointer to 15098 - 0x14498 .text + UnwindInfo: .rdata |
| BB4A4 | 1400150A8 | .pdata | ExceptionHook | Pointer to 150A8 - 0x144A8 .text + UnwindInfo: .rdata |
| 101800 | N/A | *Overlay* | F1A51EA67817622C5C45E79884F22841F2D68DFD | ....x.b,\E....(A....) |
| Extra Analysis |
| Metric | Value | Percentage |
|---|---|---|
| Ascii Code | 816119 | 77,2804% |
| Null Byte Code | 51525 | 4,879% |
© 2026 All rights reserved.