PESCAN.IO - Analysis Report Basic

File Structure
Analysis Image
PE Chart Code
Header PE (light blue)
Executable sections (pink)
Non-executable sections (black)
External injected code (red)
File Structure in red = malformed or corrupted header

Chart Code For Other Files
Printable characters (blue)
Non-printable characters (black)
Information
Icon: Icon
Size: 1,01 MB
SHA-256 Hash: 606CAC62E510927BE32527EDE5587135CEF6AC366689ECD5CE927ADD4A1F7F7C
SHA-1 Hash: 7EFF430CD03D465FFB10A4106DB416D9BFE38D41
MD5 Hash: 6B481AC94109D7630AE52B7A43BDD5BB
Imphash: 0E90466E69EF9F142C32141C3762135A
MajorOSVersion: 6
MinorOSVersion: 0
CheckSum: 00101C0D
EntryPoint (rva): 149F0
SizeOfHeaders: 400
SizeOfImage: 107000
ImageBase: 0000000140000000
Architecture: x64
ImportTable: B7A00
IAT: B7DE0
Characteristics: 22
TimeDateStamp: 6AA2FB42
Date: 10/09/2026 18:47:30
File Type: EXE
Number Of Sections: 8
ASLR: Disabled
Section Names (Optional Header): .text, .rdata, .data, .pdata, .tls, _RDATA, .rsrc, .reloc
Number Of Executable Sections: 1
Subsystem: Windows GUI
UAC Execution Level Manifest: asInvoker

Sections Info
Section Name Flags ROffset RSize VOffset VSizeEntropyChi2
.text
0x60000020
Code
Executable
Readable
400 22C00 1000 22BF1
6.5379
897629
.rdata
0x40000040
Initialized Data
Readable
23000 95E00 24000 95C5C
6.0627
2556026.32
.data
0xC0000040
Initialized Data
Readable
Writeable
B8E00 2200 BA000 2BC0
1.5174
1624378.82
.pdata
0x40000040
Initialized Data
Readable
BB000 1400 BD000 1398
5.3872
135695.6
.tls
0xC0000040
Initialized Data
Readable
Writeable
BC400 200 BF000 B9
2.011
76139
_RDATA
0x40000040
Initialized Data
Readable
BC600 600 C0000 444
2.9339
129354.67
.rsrc
0x40000040
Initialized Data
Readable
BCC00 44400 C1000 443F0
2.3723
15387028.3
.reloc
0x42000040
Initialized Data
GP-Relative
Readable
101000 800 106000 6F8
5.1163
25222
Description
OriginalFilename: wevomia.exe
CompanyName: Egrawoasia GmbH
LegalCopyright: Copyright 2021 Egrawoasia GmbH
ProductName: Wevomia
FileVersion: 4.9.5.479
FileDescription: Wevomia Agent
ProductVersion: 4.9.5.479
Language: English (United States) (ID=0x409)
CodePage: Unicode (UTF-16 LE) (0x4B0)

Entry Point
The section number (1) have the Entry Point
Information -> EntryPoint (calculated) - 13DF0
Code -> 4883EC28E8170000004883C428E96EFEFFFFCCCCCCCCCCCCCCCCCCCCCCCCCCCC40534883EC30488B05A36B0A0048BB32A2DF
Assembler
|SUB RSP, 0X28
|CALL 0X140014A10
|ADD RSP, 0X28
|JMP 0X140014870
|INT3
|INT3
|INT3
|INT3
|INT3
|INT3
|INT3
|INT3
|INT3
|INT3
|INT3
|INT3
|INT3
|INT3
|PUSH RBX
|SUB RSP, 0X30
|MOV RAX, QWORD PTR [RIP + 0XA6BA3]
Signatures
CheckSum Integrity Problem:
• Header: 1055757
• Calculated: 1069921
Certificate - Digital Signature Not Found:
• The file is not signed

Packer/Compiler
Detect It Easy (die)
• PE+(64): compiler: Microsoft Visual C/C++(2015 v.14.0)[-]
• PE+(64): linker: Microsoft Linker(14.0)[-]
• Entropy: 6.1361

Suspicious Functions
Library Function Description
KERNEL32.DLL WriteFile Writes data to a specified file or input/output (I/O) device.
KERNEL32.DLL LoadLibraryA Loads the specified module into the address space of the calling process.
KERNEL32.DLL GetModuleHandleA Retrieves a handle to the specified module.
KERNEL32.DLL GetModuleHandleW Retrieves a handle to the specified module.
KERNEL32.DLL GetProcAddress Retrieves the address of an exported function or variable from the specified dynamic-link library (DLL).
KERNEL32.DLL IsDebuggerPresent Determines if the calling process is being debugged by a user-mode debugger.
KERNEL32.DLL CreateFileW Creates or opens a file object.
KERNEL32.DLL ReadFile Reads data from a file.
KERNEL32.DLL FindNextFileW Continues file and directory enumeration.
KERNEL32.DLL FindClose Closes a file search handle.
KERNEL32.DLL CloseHandle Closes an open object handle.
KERNEL32.DLL VirtualProtect Changes memory protection attributes.
File Access
ntdll.dll
gdi32.dll
kernel32.dll
user32.dll
P.SCr
@.dat
\ProgramData\compere\schlualyaiantly.txt
|L0rZZ.WSH
To}o&bcGEj7Yr$.ZIP
PcoZZ5FjC.rAr

File Access (UNICODE)
wevomia.exe
mscoree.dll
$.dll

Interest's Words
fuck - }:)
Encrypt
Decrypt
Encryption
exec
start

URLs
http://schemas.microsoft.com/SMI/2005/WindowsSettings

Emails
J@mZr7.Fd
5@CdZA.KS
hmG5Px8A@J.C0r
jU@JOxhW.ITPP
ECO@rz.LZ
ZT3uk@3Dk4mLN.zxr5
C@AUu.ZFZFm
0@ZZFYT9.KC

Strings/Hex Code Found With The File Rules
Rule Type Encoding Matched (Word)
Entry Point Hex Pattern Microsoft Visual C++ 8.0 (DLL)
Entry Point Hex Pattern Microsoft Visual C++ 8.0
Resources
Path DataRVA Size FileOffset CodeText
\RT_MANIFEST\1\1033 C14C0 459 BD0C0 3C3F786D6C2076657273696F6E3D22312E302220656E636F64696E673D225554462D3822207374616E64616C6F6E653D2279<?xml version="1.0" encoding="UTF-8" standalone="y
\ICON\1\1033 C1920 40158 BD520 89504E470D0A1A0A0000000D49484452000001000000010008060000005C72A8660004011F49444154780100FFFF000000B7.PNG........IHDR.............\r.f....IDATx........
\ICON\2\1033 101A78 2474 FD678 89504E470D0A1A0A0000000D49484452000000300000003008060000005702F9870000243B494441547801013024CFDB00B7.PNG........IHDR...0...0.....W.....$;IDATx..0$....
\ICON\3\1033 103EF0 1064 FFAF0 89504E470D0A1A0A0000000D4948445200000020000000200806000000737A7AF40000102B494441547801012010DFEF00B7.PNG........IHDR... ... .....szz....+IDATx.. .....
\ICON\4\1033 104F58 454 100B58 89504E470D0A1A0A0000000D49484452000000100000001008060000001FF3FF610000041B494441547801011004EFFB00B7.PNG........IHDR................a....IDATx........
\GROUP_ICON\1\1033 1053B0 3E 100FB0 0000010004000000000001002000580104000100303000000100200074240000020020200000010020006410000003001010000001002000540400000400............ .X.....00.... .t$.... .... .d........... .T.....
\VERSION\1\1033 C11E0 2DC BCDE0 DC0234000000560053005F00560045005200530049004F004E005F0049004E0046004F0000000000BD04EFFE000001000900..4...V.S._.V.E.R.S.I.O.N._.I.N.F.O...............
Intelligent String
• 4.9.5.479
• wevomia.exe
• @.tls
• C:\Program Files\soundest\irryuiabs.cfg;@
• $.dll
• mscoree.dll
• ntwritefileuser32.dll
• kernel32.dll
• gdi32.dll
• ntdll.dll
• <dpiAware xmlns="http://schemas.microsoft.com/SMI/2005/WindowsSettings">true</dpiAware>

Flow Anomalies
Offset FlowVA Section Description
581 N/A .text CALL QWORD PTR [RIP+0xB6E01]
589 N/A .text CALL QWORD PTR [RIP+0xB6DB1]
592 N/A .text CALL QWORD PTR [RIP+0xB6E30]
5A4 N/A .text CALL QWORD PTR [RIP+0xB6F1E]
5E7 N/A .text CALL QWORD PTR [RIP+0xB6D9B]
5EF N/A .text CALL QWORD PTR [RIP+0xB6D0B]
600 N/A .text CALL QWORD PTR [RIP+0xB6CF2]
612 N/A .text CALL QWORD PTR [RIP+0xB6EB0]
BB8 N/A .text CALL QWORD PTR [RIP+0xB67DA]
BD6 N/A .text CALL QWORD PTR [RIP+0xB67DC]
124D N/A .text CALL QWORD PTR [RIP+0xB616D]
1271 N/A .text JMP QWORD PTR [RIP+0xB6181]
14E1 N/A .text CALL QWORD PTR [RIP+0xB5D49]
1504 N/A .text CALL QWORD PTR [RIP+0xB5D36]
1607 N/A .text CALL QWORD PTR [RIP+0xB5DB3]
1615 N/A .text CALL QWORD PTR [RIP+0xB5DDD]
163E N/A .text CALL QWORD PTR [RIP+0xB5D7C]
164C N/A .text CALL QWORD PTR [RIP+0xB5DA6]
1797 N/A .text CALL QWORD PTR [RIP+0xB5C23]
17A5 N/A .text CALL QWORD PTR [RIP+0xB5C4D]
18DD N/A .text CALL QWORD PTR [RIP+0xB5ADD]
18EB N/A .text CALL QWORD PTR [RIP+0xB5B07]
195C N/A .text CALL QWORD PTR [RIP+0xB5A5E]
196A N/A .text CALL QWORD PTR [RIP+0xB5A88]
197D N/A .text CALL QWORD PTR [RIP+0xB5A3D]
198B N/A .text CALL QWORD PTR [RIP+0xB5A67]
1B09 N/A .text CALL QWORD PTR [RIP+0xB58B1]
1B17 N/A .text CALL QWORD PTR [RIP+0xB58DB]
1C49 N/A .text CALL QWORD PTR [RIP+0xB5771]
1C57 N/A .text CALL QWORD PTR [RIP+0xB579B]
1C62 N/A .text CALL QWORD PTR [RIP+0xB5758]
1C70 N/A .text CALL QWORD PTR [RIP+0xB5782]
1CDD N/A .text CALL QWORD PTR [RIP+0xB56DD]
1CEB N/A .text CALL QWORD PTR [RIP+0xB5707]
1D87 N/A .text CALL QWORD PTR [RIP+0xB5633]
1D95 N/A .text CALL QWORD PTR [RIP+0xB565D]
1E15 N/A .text CALL QWORD PTR [RIP+0xB55A5]
1E28 N/A .text CALL QWORD PTR [RIP+0xB55CA]
1ED6 N/A .text CALL QWORD PTR [RIP+0xB54E4]
1EE4 N/A .text CALL QWORD PTR [RIP+0xB550E]
2459 N/A .text CALL QWORD PTR [RIP+0xB4F61]
2467 N/A .text CALL QWORD PTR [RIP+0xB4F8B]
2519 N/A .text CALL QWORD PTR [RIP+0xB4EA1]
2527 N/A .text CALL QWORD PTR [RIP+0xB4ECB]
2649 N/A .text CALL QWORD PTR [RIP+0xB4D71]
2657 N/A .text CALL QWORD PTR [RIP+0xB4D9B]
285D N/A .text CALL QWORD PTR [RIP+0xB497D]
2BB2 N/A .text CALL QWORD PTR [RIP+0xB4680]
2BFC N/A .text CALL QWORD PTR [RIP+0xB47BE]
2C0A N/A .text CALL QWORD PTR [RIP+0xB47E8]
2D9E N/A .text CALL QWORD PTR [RIP+0xB461C]
2DAC N/A .text CALL QWORD PTR [RIP+0xB4646]
30E8 N/A .text CALL QWORD PTR [RIP+0xB42D2]
30F6 N/A .text CALL QWORD PTR [RIP+0xB42FC]
3109 N/A .text CALL QWORD PTR [RIP+0xB42B1]
3117 N/A .text CALL QWORD PTR [RIP+0xB42DB]
317C N/A .text CALL QWORD PTR [RIP+0xB423E]
318A N/A .text CALL QWORD PTR [RIP+0xB4268]
33DC N/A .text CALL QWORD PTR [RIP+0xB3FDE]
33EA N/A .text CALL QWORD PTR [RIP+0xB4008]
34ED N/A .text CALL QWORD PTR [RIP+0xB3ECD]
34FB N/A .text CALL QWORD PTR [RIP+0xB3EF7]
354C N/A .text CALL QWORD PTR [RIP+0xB3C96]
35F2 N/A .text CALL QWORD PTR [RIP+0xB3DC8]
3600 N/A .text CALL QWORD PTR [RIP+0xB3DF2]
3754 N/A .text CALL QWORD PTR [RIP+0xB3C66]
3762 N/A .text CALL QWORD PTR [RIP+0xB3C90]
3798 N/A .text CALL QWORD PTR [RIP+0xB3C22]
37A6 N/A .text CALL QWORD PTR [RIP+0xB3C4C]
385D N/A .text CALL QWORD PTR [RIP+0xB3B5D]
386B N/A .text CALL QWORD PTR [RIP+0xB3B87]
387E N/A .text CALL QWORD PTR [RIP+0xB3B3C]
388C N/A .text CALL QWORD PTR [RIP+0xB3B66]
38DC N/A .text CALL QWORD PTR [RIP+0xB3ADE]
38EA N/A .text CALL QWORD PTR [RIP+0xB3B08]
3AC3 N/A .text CALL QWORD PTR [RIP+0xB38F7]
3AD6 N/A .text CALL QWORD PTR [RIP+0xB391C]
3B05 N/A .text CALL QWORD PTR [RIP+0xB38B5]
3B13 N/A .text CALL QWORD PTR [RIP+0xB38DF]
3DD2 N/A .text CALL QWORD PTR [RIP+0xB35E8]
3DE0 N/A .text CALL QWORD PTR [RIP+0xB3612]
3E32 N/A .text CALL QWORD PTR [RIP+0xB3588]
3E40 N/A .text CALL QWORD PTR [RIP+0xB35B2]
3F84 N/A .text CALL QWORD PTR [RIP+0xB3436]
3F92 N/A .text CALL QWORD PTR [RIP+0xB3460]
4000 N/A .text CALL QWORD PTR [RIP+0xB33BA]
400E N/A .text CALL QWORD PTR [RIP+0xB33E4]
4043 N/A .text CALL QWORD PTR [RIP+0xB3377]
4051 N/A .text CALL QWORD PTR [RIP+0xB33A1]
408E N/A .text CALL QWORD PTR [RIP+0xB332C]
409C N/A .text CALL QWORD PTR [RIP+0xB3356]
40AF N/A .text CALL QWORD PTR [RIP+0xB330B]
40BD N/A .text CALL QWORD PTR [RIP+0xB3335]
40C8 N/A .text CALL QWORD PTR [RIP+0xB32F2]
40D6 N/A .text CALL QWORD PTR [RIP+0xB331C]
40E9 N/A .text CALL QWORD PTR [RIP+0xB32D1]
40F7 N/A .text CALL QWORD PTR [RIP+0xB32FB]
41C5 N/A .text CALL QWORD PTR [RIP+0xB31F5]
41D3 N/A .text CALL QWORD PTR [RIP+0xB321F]
41E6 N/A .text CALL QWORD PTR [RIP+0xB31D4]
BB000 140001000 .pdata ExceptionHook | Pointer to 1000 - 0x400 .text + UnwindInfo: .rdata
BB00C 140001086 .pdata ExceptionHook | Pointer to 1086 - 0x486 .text + UnwindInfo: .rdata
BB018 140001294 .pdata ExceptionHook | Pointer to 1294 - 0x694 .text + UnwindInfo: .rdata
BB024 140001605 .pdata ExceptionHook | Pointer to 1605 - 0xA05 .text + UnwindInfo: .rdata
BB030 14000179D .pdata ExceptionHook | Pointer to 179D - 0xB9D .text + UnwindInfo: .rdata
BB03C 140001800 .pdata ExceptionHook | Pointer to 1800 - 0xC00 .text + UnwindInfo: .rdata
BB048 14000184C .pdata ExceptionHook | Pointer to 184C - 0xC4C .text + UnwindInfo: .rdata
BB054 140001A5C .pdata ExceptionHook | Pointer to 1A5C - 0xE5C .text + UnwindInfo: .rdata
BB060 140002169 .pdata ExceptionHook | Pointer to 2169 - 0x1569 .text + UnwindInfo: .rdata
BB06C 140006358 .pdata ExceptionHook | Pointer to 6358 - 0x5758 .text + UnwindInfo: .rdata
BB078 1400063BC .pdata ExceptionHook | Pointer to 63BC - 0x57BC .text + UnwindInfo: .rdata
BB084 14000644D .pdata ExceptionHook | Pointer to 644D - 0x584D .text + UnwindInfo: .rdata
BB090 140006495 .pdata ExceptionHook | Pointer to 6495 - 0x5895 .text + UnwindInfo: .rdata
BB09C 1400065A2 .pdata ExceptionHook | Pointer to 65A2 - 0x59A2 .text + UnwindInfo: .rdata
BB0A8 1400065EC .pdata ExceptionHook | Pointer to 65EC - 0x59EC .text + UnwindInfo: .rdata
BB0B4 140006ADE .pdata ExceptionHook | Pointer to 6ADE - 0x5EDE .text + UnwindInfo: .rdata
BB0C0 140006BEE .pdata ExceptionHook | Pointer to 6BEE - 0x5FEE .text + UnwindInfo: .rdata
BB0CC 140006C33 .pdata ExceptionHook | Pointer to 6C33 - 0x6033 .text + UnwindInfo: .rdata
BB0D8 140006C62 .pdata ExceptionHook | Pointer to 6C62 - 0x6062 .text + UnwindInfo: .rdata
BB0E4 140006D9C .pdata ExceptionHook | Pointer to 6D9C - 0x619C .text + UnwindInfo: .rdata
BB0F0 140006E04 .pdata ExceptionHook | Pointer to 6E04 - 0x6204 .text + UnwindInfo: .rdata
BB0FC 140006E4F .pdata ExceptionHook | Pointer to 6E4F - 0x624F .text + UnwindInfo: .rdata
BB108 1400072CD .pdata ExceptionHook | Pointer to 72CD - 0x66CD .text + UnwindInfo: .rdata
BB114 140007F62 .pdata ExceptionHook | Pointer to 7F62 - 0x7362 .text + UnwindInfo: .rdata
BB120 140007F9D .pdata ExceptionHook | Pointer to 7F9D - 0x739D .text + UnwindInfo: .rdata
BB12C 140008077 .pdata ExceptionHook | Pointer to 8077 - 0x7477 .text + UnwindInfo: .rdata
BB138 1400080A5 .pdata ExceptionHook | Pointer to 80A5 - 0x74A5 .text + UnwindInfo: .rdata
BB144 140008128 .pdata ExceptionHook | Pointer to 8128 - 0x7528 .text + UnwindInfo: .rdata
BB150 140008187 .pdata ExceptionHook | Pointer to 8187 - 0x7587 .text + UnwindInfo: .rdata
BB15C 140008943 .pdata ExceptionHook | Pointer to 8943 - 0x7D43 .text + UnwindInfo: .rdata
BB168 14000898D .pdata ExceptionHook | Pointer to 898D - 0x7D8D .text + UnwindInfo: .rdata
BB174 140008A1C .pdata ExceptionHook | Pointer to 8A1C - 0x7E1C .text + UnwindInfo: .rdata
BB180 140008B22 .pdata ExceptionHook | Pointer to 8B22 - 0x7F22 .text + UnwindInfo: .rdata
BB18C 140008D74 .pdata ExceptionHook | Pointer to 8D74 - 0x8174 .text + UnwindInfo: .rdata
BB198 140008DE3 .pdata ExceptionHook | Pointer to 8DE3 - 0x81E3 .text + UnwindInfo: .rdata
BB1A4 140008E8B .pdata ExceptionHook | Pointer to 8E8B - 0x828B .text + UnwindInfo: .rdata
BB1B0 140008F0F .pdata ExceptionHook | Pointer to 8F0F - 0x830F .text + UnwindInfo: .rdata
BB1BC 1400092FE .pdata ExceptionHook | Pointer to 92FE - 0x86FE .text + UnwindInfo: .rdata
BB1C8 140009508 .pdata ExceptionHook | Pointer to 9508 - 0x8908 .text + UnwindInfo: .rdata
BB1D4 14000955F .pdata ExceptionHook | Pointer to 955F - 0x895F .text + UnwindInfo: .rdata
BB1E0 14000958F .pdata ExceptionHook | Pointer to 958F - 0x898F .text + UnwindInfo: .rdata
BB1EC 14000A762 .pdata ExceptionHook | Pointer to A762 - 0x9B62 .text + UnwindInfo: .rdata
BB1F8 14000AA9B .pdata ExceptionHook | Pointer to AA9B - 0x9E9B .text + UnwindInfo: .rdata
BB204 14000B0D3 .pdata ExceptionHook | Pointer to B0D3 - 0xA4D3 .text + UnwindInfo: .rdata
BB210 14000B234 .pdata ExceptionHook | Pointer to B234 - 0xA634 .text + UnwindInfo: .rdata
BB21C 14000B2A9 .pdata ExceptionHook | Pointer to B2A9 - 0xA6A9 .text + UnwindInfo: .rdata
BB228 14000B557 .pdata ExceptionHook | Pointer to B557 - 0xA957 .text + UnwindInfo: .rdata
BB234 14000B8F9 .pdata ExceptionHook | Pointer to B8F9 - 0xACF9 .text + UnwindInfo: .rdata
BB240 14000C75B .pdata ExceptionHook | Pointer to C75B - 0xBB5B .text + UnwindInfo: .rdata
BB24C 14000C9A6 .pdata ExceptionHook | Pointer to C9A6 - 0xBDA6 .text + UnwindInfo: .rdata
BB258 14000C9DD .pdata ExceptionHook | Pointer to C9DD - 0xBDDD .text + UnwindInfo: .rdata
BB264 14000CE4D .pdata ExceptionHook | Pointer to CE4D - 0xC24D .text + UnwindInfo: .rdata
BB270 14000D672 .pdata ExceptionHook | Pointer to D672 - 0xCA72 .text + UnwindInfo: .rdata
BB27C 14000D888 .pdata ExceptionHook | Pointer to D888 - 0xCC88 .text + UnwindInfo: .rdata
BB288 14000D909 .pdata ExceptionHook | Pointer to D909 - 0xCD09 .text + UnwindInfo: .rdata
BB294 14001366B .pdata ExceptionHook | Pointer to 1366B - 0x12A6B .text + UnwindInfo: .rdata
BB2A0 1400136E1 .pdata ExceptionHook | Pointer to 136E1 - 0x12AE1 .text + UnwindInfo: .rdata
BB2AC 1400138E5 .pdata ExceptionHook | Pointer to 138E5 - 0x12CE5 .text + UnwindInfo: .rdata
BB2B8 140013913 .pdata ExceptionHook | Pointer to 13913 - 0x12D13 .text + UnwindInfo: .rdata
BB2C4 140013940 .pdata ExceptionHook | Pointer to 13940 - 0x12D40 .text + UnwindInfo: .rdata
BB2D0 1400139A4 .pdata ExceptionHook | Pointer to 139A4 - 0x12DA4 .text + UnwindInfo: .rdata
BB2DC 140013C01 .pdata ExceptionHook | Pointer to 13C01 - 0x13001 .text + UnwindInfo: .rdata
BB2E8 140013ED0 .pdata ExceptionHook | Pointer to 13ED0 - 0x132D0 .text + UnwindInfo: .rdata
BB2F4 140013F05 .pdata ExceptionHook | Pointer to 13F05 - 0x13305 .text + UnwindInfo: .rdata
BB300 140013FDB .pdata ExceptionHook | Pointer to 13FDB - 0x133DB .text + UnwindInfo: .rdata
BB30C 140014038 .pdata ExceptionHook | Pointer to 14038 - 0x13438 .text + UnwindInfo: .rdata
BB318 1400140D0 .pdata ExceptionHook | Pointer to 140D0 - 0x134D0 .text + UnwindInfo: .rdata
BB324 140014120 .pdata ExceptionHook | Pointer to 14120 - 0x13520 .text + UnwindInfo: .rdata
BB330 140014160 .pdata ExceptionHook | Pointer to 14160 - 0x13560 .text + UnwindInfo: .rdata
BB33C 140014200 .pdata ExceptionHook | Pointer to 14200 - 0x13600 .text + UnwindInfo: .rdata
BB348 140014250 .pdata ExceptionHook | Pointer to 14250 - 0x13650 .text + UnwindInfo: .rdata
BB354 140014280 .pdata ExceptionHook | Pointer to 14280 - 0x13680 .text + UnwindInfo: .rdata
BB360 1400142C0 .pdata ExceptionHook | Pointer to 142C0 - 0x136C0 .text + UnwindInfo: .rdata
BB36C 1400142F0 .pdata ExceptionHook | Pointer to 142F0 - 0x136F0 .text + UnwindInfo: .rdata
BB378 140014390 .pdata ExceptionHook | Pointer to 14390 - 0x13790 .text + UnwindInfo: .rdata
BB384 14001439B .pdata ExceptionHook | Pointer to 1439B - 0x1379B .text + UnwindInfo: .rdata
BB390 1400144D3 .pdata ExceptionHook | Pointer to 144D3 - 0x138D3 .text + UnwindInfo: .rdata
BB39C 140014670 .pdata ExceptionHook | Pointer to 14670 - 0x13A70 .text + UnwindInfo: .rdata
BB3A8 140014710 .pdata ExceptionHook | Pointer to 14710 - 0x13B10 .text + UnwindInfo: .rdata
BB3B4 140014780 .pdata ExceptionHook | Pointer to 14780 - 0x13B80 .text + UnwindInfo: .rdata
BB3C0 140014840 .pdata ExceptionHook | Pointer to 14840 - 0x13C40 .text + UnwindInfo: .rdata
BB3CC 140014850 .pdata ExceptionHook | Pointer to 14850 - 0x13C50 .text + UnwindInfo: .rdata
BB3D8 140014870 .pdata ExceptionHook | Pointer to 14870 - 0x13C70 .text + UnwindInfo: .rdata
BB3E4 1400149F0 .pdata ExceptionHook | Pointer to 149F0 - 0x13DF0 .text + UnwindInfo: .rdata
BB3F0 140014A10 .pdata ExceptionHook | Pointer to 14A10 - 0x13E10 .text + UnwindInfo: .rdata
BB3FC 140014B00 .pdata ExceptionHook | Pointer to 14B00 - 0x13F00 .text + UnwindInfo: .rdata
BB408 140014B70 .pdata ExceptionHook | Pointer to 14B70 - 0x13F70 .text + UnwindInfo: .rdata
BB414 140014BC0 .pdata ExceptionHook | Pointer to 14BC0 - 0x13FC0 .text + UnwindInfo: .rdata
BB420 140014C10 .pdata ExceptionHook | Pointer to 14C10 - 0x14010 .text + UnwindInfo: .rdata
BB42C 140014E30 .pdata ExceptionHook | Pointer to 14E30 - 0x14230 .text + UnwindInfo: .rdata
BB438 140014EA0 .pdata ExceptionHook | Pointer to 14EA0 - 0x142A0 .text + UnwindInfo: .rdata
BB444 140014EC0 .pdata ExceptionHook | Pointer to 14EC0 - 0x142C0 .text + UnwindInfo: .rdata
BB450 140014F00 .pdata ExceptionHook | Pointer to 14F00 - 0x14300 .text + UnwindInfo: .rdata
BB45C 140014F20 .pdata ExceptionHook | Pointer to 14F20 - 0x14320 .text + UnwindInfo: .rdata
BB468 140014F70 .pdata ExceptionHook | Pointer to 14F70 - 0x14370 .text + UnwindInfo: .rdata
BB474 140015010 .pdata ExceptionHook | Pointer to 15010 - 0x14410 .text + UnwindInfo: .rdata
BB480 140015040 .pdata ExceptionHook | Pointer to 15040 - 0x14440 .text + UnwindInfo: .rdata
BB48C 140015074 .pdata ExceptionHook | Pointer to 15074 - 0x14474 .text + UnwindInfo: .rdata
BB498 140015098 .pdata ExceptionHook | Pointer to 15098 - 0x14498 .text + UnwindInfo: .rdata
BB4A4 1400150A8 .pdata ExceptionHook | Pointer to 150A8 - 0x144A8 .text + UnwindInfo: .rdata
101800 N/A *Overlay* F1A51EA67817622C5C45E79884F22841F2D68DFD | ....x.b,\E....(A....)
Extra Analysis
Metric Value Percentage
Ascii Code 816119 77,2804%
Null Byte Code 51525 4,879%
© 2026 All rights reserved.