PESCAN.IO - Analysis Report Basic

File Structure
Analysis Image
PE Chart Code
Header PE (light blue)
Executable sections (pink)
Non-executable sections (black)
External injected code (red)
File Structure in red = malformed or corrupted header

Chart Code For Other Files
Printable characters (blue)
Non-printable characters (black)
Information
Size: 40,50 KB
SHA-256 Hash: 27E634D9562E6D585E2B5F60D18565742F1A703F009DF961A5AEC90BC46E0AA2
SHA-1 Hash: 4CF2DBE110408E8E3A677486CDB3C72E0E9537B4
MD5 Hash: 7E85AD5E20F083EAC7A2F40BA8651563
Imphash: 0EFD52E4592F023E0F5172ECE1EAF0D7
MajorOSVersion: 5
MinorOSVersion: 2
CheckSum: 00019E65
EntryPoint (rva): 1000
SizeOfHeaders: 400
SizeOfImage: F000
ImageBase: 0000000180000000
Architecture: x64
ExportTable: 9BD0
ImportTable: 9E8C
IAT: 7000
Characteristics: 2022
TimeDateStamp: 6A71BC6D
Date: 04/08/2026 10:18:21
File Type: DLL
Number Of Sections: 6
ASLR: Disabled
Section Names (Optional Header): .text, .rdata, .data, .pdata, .rsrc, .reloc
Number Of Executable Sections: 1
Subsystem: Windows GUI
[Incomplete Binary or Compressor Packer - 19,50 KB Missing]

Sections Info
Section Name Flags ROffset RSize VOffset VSizeEntropyChi2
.text
0x60000020
Code
Executable
Readable
400 5A00 1000 5863
6.2118
219336.27
.rdata
0x40000040
Initialized Data
Readable
5E00 3600 7000 35D8
4.3433
714380.74
.data
0xC0000040
Initialized Data
Readable
Writeable
9400 400 B000 948
3.549
78298.5
.pdata
0x40000040
Initialized Data
Readable
9800 400 C000 2DC
3.2181
109081
.rsrc
0x40000040
Initialized Data
Readable
9C00 400 D000 250
1.9882
157776
.reloc
0x42000040
Initialized Data
GP-Relative
Readable
A000 200 E000 1C
0.3472
120567
Description
LegalCopyright: Copyright (C) 2026
FileVersion: 1.0.0.3
FileDescription: Topaz Labs runtime patcher
ProductVersion: 1.0.0.3
Language: Unknown (ID=0x400)
CodePage: Unicode (UTF-16 LE) (0x4B0)

Entry Point
The section number (1) have the Entry Point
Information -> EntryPoint (calculated) - 400
Code -> 48895C2408564883EC30488BD985D20F841901000083FA010F8565010000FF15E4610000E823060000E88E3F000085C0743D
Assembler
|MOV QWORD PTR [RSP + 8], RBX
|PUSH RSI
|SUB RSP, 0X30
|MOV RBX, RCX
|TEST EDX, EDX
|JE 0X18000112E
|CMP EDX, 1
|JNE 0X180001183
|CALL QWORD PTR [RIP + 0X61E4]
|CALL 0X18000164C
|CALL 0X180004FBC
|TEST EAX, EAX
|JE 0X18000106F
Signatures
Rich Signature Analyzer:
Code -> 717F544A351E3A19351E3A19351E3A193C66A919321E3A19351E3B19711E3A199B773E18331E3A199B773A18341E3A199B77C519341E3A199B773818341E3A1952696368351E3A19
Footprint md5 Hash -> 7496195C6C27EF4C262498CE67F6BD60
• The Rich header apparently has not been modified
Certificate - Digital Signature Not Found:
• The file is not signed

Packer/Compiler
Detect It Easy (die)
PE+(64): linker: Microsoft Linker(14.16, Visual Studio 2017 15.9*)[-]
Entropy: 5.66204

Suspicious Functions
Library Function Description
KERNEL32.DLL CreateMutexW Create a named or unnamed mutex object for controlling access to a shared resource.
KERNEL32.DLL VirtualAlloc Reserve, commit, or both, a region of memory within the virtual address space of a process.
KERNEL32.DLL WriteFile Writes data to a specified file or input/output (I/O) device.
KERNEL32.DLL LoadLibraryW Loads the specified module into the address space of the calling process.
KERNEL32.DLL GetModuleHandleW Retrieves a handle to the specified module.
KERNEL32.DLL CreateToolhelp32Snapshot Creates a snapshot of the specified processes, heaps, threads, and modules.
KERNEL32.DLL WriteProcessMemory Writes data to an area of memory in a specified process.
KERNEL32.DLL GetProcAddress Retrieves the address of an exported function or variable from the specified dynamic-link library (DLL).
KERNEL32.DLL CreateFileW Creates or opens a file object.
KERNEL32.DLL GetThreadContext Retrieves a thread execution context.
KERNEL32.DLL SetThreadContext Modifies a thread execution context.
KERNEL32.DLL CloseHandle Closes an open object handle.
KERNEL32.DLL VirtualProtect Changes memory protection attributes.
KERNEL32.DLL ResumeThread Resumes a suspended thread.
KERNEL32.DLL GetSystemInfo Retrieves system hardware information.
KERNEL32.DLL GetVersion Retrieves the operating system version.
KERNEL32.DLL VirtualProtectEx Changes the protection on a region of memory in another process.
ADVAPI32.DLL RegOpenKeyExW Opens an existing registry key.
Windows REG (UNICODE)
Software\%1\%2

File Access
ADVAPI32.dll
SHELL32.dll
KERNEL32.dll
dxgi.dll
@.dat

File Access (UNICODE)
\Topaz Video BETA.exe
\Topaz Video.exe
neuroserver.exe
runner.exe
ffmpeg.exe
Topaz Video AI BETA.exe
Topaz Video BETA.exe
Topaz Video AI.exe
Topaz Video.exe
tpai-beta.exe
Topaz Photo AI BETA.exe
Topaz Photo BETA.exe
tpai.exe
Topaz Photo AI.exe
Topaz Photo.exe
gigapixel-beta.exe
Topaz Gigapixel AI BETA.exe
Topaz Gigapixel BETA.exe
gigapixel.exe
Topaz Gigapixel AI.exe
Topaz Gigapixel.exe
network.dll
tvai_starlight_meteredrlm1611.dll
ntdll.dll
04X!_debug.log

Interest's Words
exec
attrib
systeminfo
replace

Interest's Words (UNICODE)
exec
replace

Strings/Hex Code Found With The File Rules
Rule Type Encoding Matched (Word)
Text Ascii Malicious code executed after exploiting a vulnerability (Payload)
Entry Point Hex Pattern Microsoft Visual C++ 8
Resources
Path DataRVA Size FileOffset CodeText
\VERSION\1\1049 D060 1EC 9C60 EC0134000000560053005F00560045005200530049004F004E005F0049004E0046004F0000000000BD04EFFE000001000000..4...V.S._.V.E.R.S.I.O.N._.I.N.F.O...............
Intelligent String
• 1.0.0.3
• \proxydll_PID_%1!.04X!_debug.log
• ntdll.dll
• Topaz Gigapixel.exe
• Topaz Gigapixel AI.exe
• gigapixel.exe
• Topaz Gigapixel BETA.exe
• Topaz Gigapixel AI BETA.exe
• gigapixel-beta.exe
• Topaz Photo.exe
• Topaz Photo AI.exe
• tpai.exe
• Topaz Photo BETA.exe
• Topaz Photo AI BETA.exe
• tpai-beta.exe
• Topaz Video.exe
• Topaz Video AI.exe
• Topaz Video BETA.exe
• Topaz Video AI BETA.exe
• ffmpeg.exe
• runner.exe
• neuroserver.exe
• topaz.lic
• \topaz.lic
• ..\Topaz Video.exe
• ..\Topaz Video BETA.exe
• rlm1611.dll
• network.dll
• dxgi.dll
• KERNEL32.dll
• ADVAPI32.dll

Flow Anomalies
Offset FlowVA Section Description
41E N/A .text CALL QWORD PTR [RIP+0x61E4]
49A N/A .text CALL QWORD PTR [RIP+0x6040]
4C2 N/A .text CALL QWORD PTR [RIP+0xA168]
575 N/A .text CALL QWORD PTR [RIP+0x5F2D]
59D N/A .text CALL QWORD PTR [RIP+0x5EBD]
5B4 N/A .text JMP QWORD PTR [RIP+0x5E8E]
649 N/A .text CALL QWORD PTR [RIP+0x5EE1]
67C N/A .text CALL QWORD PTR [RIP+0x5EA6]
6E4 N/A .text CALL QWORD PTR [RIP+0x5DC6]
72C N/A .text CALL QWORD PTR [RIP+0x5D7E]
744 N/A .text CALL QWORD PTR [RIP+0x5CDE]
74F N/A .text CALL QWORD PTR [RIP+0x5D9B]
768 N/A .text CALL QWORD PTR [RIP+0x5D5A]
793 N/A .text CALL QWORD PTR [RIP+0x5D7F]
7A7 N/A .text CALL QWORD PTR [RIP+0x5C73]
7BA N/A .text CALL QWORD PTR [RIP+0x5D08]
7DF N/A .text CALL QWORD PTR [RIP+0x5D33]
805 N/A .text CALL QWORD PTR [RIP+0x5C95]
80E N/A .text CALL QWORD PTR [RIP+0x5C14]
81E N/A .text CALL QWORD PTR [RIP+0x5C04]
841 N/A .text CALL QWORD PTR [RIP+0x5C19]
84F N/A .text CALL QWORD PTR [RIP+0x5C03]
8C6 N/A .text CALL QWORD PTR [RIP+0x5B6C]
8F3 N/A .text CALL QWORD PTR [RIP+0x5B6F]
920 N/A .text CALL QWORD PTR [RIP+0x5B1A]
93F N/A .text CALL QWORD PTR [RIP+0x5B4B]
951 N/A .text CALL QWORD PTR [RIP+0x5AD9]
96F N/A .text CALL QWORD PTR [RIP+0x5ACB]
9A2 N/A .text CALL QWORD PTR [RIP+0x5AE8]
9B4 N/A .text CALL QWORD PTR [RIP+0x5A76]
A88 N/A .text CALL QWORD PTR [RIP+0x5A5A]
A98 N/A .text CALL QWORD PTR [RIP+0x59D2]
AD0 N/A .text CALL QWORD PTR [RIP+0x59DA]
B03 N/A .text CALL QWORD PTR [RIP+0x5B07]
C6A N/A .text CALL QWORD PTR [RIP+0x5850]
C7C N/A .text CALL QWORD PTR [RIP+0x583E]
D47 N/A .text CALL QWORD PTR [RIP+0x56EB]
DC1 N/A .text CALL QWORD PTR [RIP+0x5671]
F0B N/A .text CALL QWORD PTR [RIP+0x55C7]
F17 N/A .text CALL QWORD PTR [RIP+0x5563]
F5C N/A .text CALL QWORD PTR [RIP+0x5556]
F91 N/A .text CALL QWORD PTR [RIP+0x5521]
FC9 N/A .text CALL QWORD PTR [RIP+0x5529]
FDA N/A .text CALL QWORD PTR [RIP+0x54B8]
FE3 N/A .text CALL QWORD PTR [RIP+0x562F]
1002 N/A .text CALL QWORD PTR [RIP+0x5478]
111D N/A .text CALL QWORD PTR [RIP+0x54DD]
113B N/A .text CALL QWORD PTR [RIP+0x5347]
1164 N/A .text CALL QWORD PTR [RIP+0x531E]
1178 N/A .text CALL QWORD PTR [RIP+0x5342]
11B2 N/A .text CALL QWORD PTR [RIP+0x5308]
11EC N/A .text CALL QWORD PTR [RIP+0x532E]
122C N/A .text CALL QWORD PTR [RIP+0x5256]
12C6 N/A .text CALL QWORD PTR [RIP+0x51BC]
12FA N/A .text CALL QWORD PTR [RIP+0x5188]
13CE N/A .text CALL QWORD PTR [RIP+0x512C]
13E0 N/A .text CALL QWORD PTR [RIP+0x50E2]
13EF N/A .text CALL QWORD PTR [RIP+0x50D3]
140A N/A .text CALL QWORD PTR [RIP+0x50A8]
141B N/A .text CALL QWORD PTR [RIP+0x5097]
146C N/A .text CALL QWORD PTR [RIP+0x505E]
15CB N/A .text CALL QWORD PTR [RIP+0x4F4F]
17FA N/A .text CALL QWORD PTR [RIP+0x4E00]
1A5B N/A .text CALL QWORD PTR [RIP+0x4A7F]
1A6B N/A .text CALL QWORD PTR [RIP+0x4B8F]
1A8A N/A .text CALL QWORD PTR [RIP+0x4A50]
1A9A N/A .text CALL QWORD PTR [RIP+0x4B60]
1B08 N/A .text CALL QWORD PTR [RIP+0x4A02]
2398 N/A .text CALL QWORD PTR [RIP+0x40DA]
239F N/A .text CALL QWORD PTR [RIP+0x40DB]
2443 N/A .text CALL QWORD PTR [RIP+0x405F]
244E N/A .text CALL QWORD PTR [RIP+0x4054]
245C N/A .text CALL QWORD PTR [RIP+0x81CE]
249D N/A .text CALL QWORD PTR [RIP+0x8865]
24CE N/A .text CALL QWORD PTR [RIP+0x3FEC]
2501 N/A .text CALL QWORD PTR [RIP+0x3FB9]
26EA N/A .text CALL QWORD PTR [RIP+0x3E18]
26FC N/A .text CALL QWORD PTR [RIP+0x3DDE]
270C N/A .text CALL QWORD PTR [RIP+0x3EEE]
2728 N/A .text CALL QWORD PTR [RIP+0x3DB2]
2740 N/A .text CALL QWORD PTR [RIP+0x3EBA]
27B3 N/A .text CALL QWORD PTR [RIP+0x3E47]
2A5B N/A .text CALL QWORD PTR [RIP+0x7BCF]
2A75 N/A .text CALL QWORD PTR [RIP+0x7BB5]
2E22 N/A .text CALL QWORD PTR [RIP+0x36E0]
2E34 N/A .text CALL QWORD PTR [RIP+0x36A6]
2E44 N/A .text CALL QWORD PTR [RIP+0x37B6]
2E68 N/A .text CALL QWORD PTR [RIP+0x3672]
2E78 N/A .text CALL QWORD PTR [RIP+0x3782]
3005 N/A .text CALL QWORD PTR [RIP+0x354D]
3039 N/A .text CALL QWORD PTR [RIP+0x3521]
30BD N/A .text CALL QWORD PTR [RIP+0x3375]
30FD N/A .text CALL QWORD PTR [RIP+0x344D]
3149 N/A .text CALL QWORD PTR [RIP+0x32E9]
3194 N/A .text CALL QWORD PTR [RIP+0x33B6]
3223 N/A .text CALL QWORD PTR [RIP+0x320F]
3275 N/A .text CALL QWORD PTR [RIP+0x32DD]
390B N/A .text CALL QWORD PTR [RIP+0x2B37]
3946 N/A .text CALL QWORD PTR [RIP+0x2B04]
3B28 N/A .text CALL QWORD PTR [RIP+0x2A92]
9800 180001000 .pdata ExceptionHook | Pointer to 1000 - 0x400 .text + UnwindInfo: .rdata
980C 180001194 .pdata ExceptionHook | Pointer to 1194 - 0x594 .text + UnwindInfo: .rdata
9818 1800011BC .pdata ExceptionHook | Pointer to 11BC - 0x5BC .text + UnwindInfo: .rdata
9824 180001434 .pdata ExceptionHook | Pointer to 1434 - 0x834 .text + UnwindInfo: .rdata
9830 180001470 .pdata ExceptionHook | Pointer to 1470 - 0x870 .text + UnwindInfo: .rdata
983C 1800015C0 .pdata ExceptionHook | Pointer to 15C0 - 0x9C0 .text + UnwindInfo: .rdata
9848 18000164C .pdata ExceptionHook | Pointer to 164C - 0xA4C .text + UnwindInfo: .rdata
9854 180001790 .pdata ExceptionHook | Pointer to 1790 - 0xB90 .text + UnwindInfo: .rdata
9860 1800018D0 .pdata ExceptionHook | Pointer to 18D0 - 0xCD0 .text + UnwindInfo: .rdata
986C 180001A90 .pdata ExceptionHook | Pointer to 1A90 - 0xE90 .text + UnwindInfo: .rdata
9878 180001AC8 .pdata ExceptionHook | Pointer to 1AC8 - 0xEC8 .text + UnwindInfo: .rdata
9884 180001C90 .pdata ExceptionHook | Pointer to 1C90 - 0x1090 .text + UnwindInfo: .rdata
9890 180001EB4 .pdata ExceptionHook | Pointer to 1EB4 - 0x12B4 .text + UnwindInfo: .rdata
989C 180001F14 .pdata ExceptionHook | Pointer to 1F14 - 0x1314 .text + UnwindInfo: .rdata
98A8 180001F2C .pdata ExceptionHook | Pointer to 1F2C - 0x132C .text + UnwindInfo: .rdata
98B4 180002618 .pdata ExceptionHook | Pointer to 2618 - 0x1A18 .text + UnwindInfo: .rdata
98C0 18000273C .pdata ExceptionHook | Pointer to 273C - 0x1B3C .text + UnwindInfo: .rdata
98CC 1800028E4 .pdata ExceptionHook | Pointer to 28E4 - 0x1CE4 .text + UnwindInfo: .rdata
98D8 180002B70 .pdata ExceptionHook | Pointer to 2B70 - 0x1F70 .text + UnwindInfo: .rdata
98E4 180002DC8 .pdata ExceptionHook | Pointer to 2DC8 - 0x21C8 .text + UnwindInfo: .rdata
98F0 180002EC8 .pdata ExceptionHook | Pointer to 2EC8 - 0x22C8 .text + UnwindInfo: .rdata
98FC 180002F54 .pdata ExceptionHook | Pointer to 2F54 - 0x2354 .text + UnwindInfo: .rdata
9908 1800030AC .pdata ExceptionHook | Pointer to 30AC - 0x24AC .text + UnwindInfo: .rdata
9914 1800032E0 .pdata ExceptionHook | Pointer to 32E0 - 0x26E0 .text + UnwindInfo: .rdata
9920 180003410 .pdata ExceptionHook | Pointer to 3410 - 0x2810 .text + UnwindInfo: .rdata
992C 1800035F4 .pdata ExceptionHook | Pointer to 35F4 - 0x29F4 .text + UnwindInfo: .rdata
9938 180003A18 .pdata ExceptionHook | Pointer to 3A18 - 0x2E18 .text + UnwindInfo: .rdata
9944 180003B68 .pdata ExceptionHook | Pointer to 3B68 - 0x2F68 .text + UnwindInfo: .rdata
9950 180003B84 .pdata ExceptionHook | Pointer to 3B84 - 0x2F84 .text + UnwindInfo: .rdata
995C 180003BA8 .pdata ExceptionHook | Pointer to 3BA8 - 0x2FA8 .text + UnwindInfo: .rdata
9968 180003C10 .pdata ExceptionHook | Pointer to 3C10 - 0x3010 .text + UnwindInfo: .rdata
9974 180003E14 .pdata ExceptionHook | Pointer to 3E14 - 0x3214 .text + UnwindInfo: .rdata
9980 180003E50 .pdata ExceptionHook | Pointer to 3E50 - 0x3250 .text + UnwindInfo: .rdata
998C 180003E8C .pdata ExceptionHook | Pointer to 3E8C - 0x328C .text + UnwindInfo: .rdata
9998 1800044E4 .pdata ExceptionHook | Pointer to 44E4 - 0x38E4 .text + UnwindInfo: .rdata
99A4 18000458C .pdata ExceptionHook | Pointer to 458C - 0x398C .text + UnwindInfo: .rdata
99B0 180004648 .pdata ExceptionHook | Pointer to 4648 - 0x3A48 .text + UnwindInfo: .rdata
99BC 1800046F4 .pdata ExceptionHook | Pointer to 46F4 - 0x3AF4 .text + UnwindInfo: .rdata
99C8 180004808 .pdata ExceptionHook | Pointer to 4808 - 0x3C08 .text + UnwindInfo: .rdata
99D4 18000497C .pdata ExceptionHook | Pointer to 497C - 0x3D7C .text + UnwindInfo: .rdata
99E0 180004A80 .pdata ExceptionHook | Pointer to 4A80 - 0x3E80 .text + UnwindInfo: .rdata
99EC 180004C5C .pdata ExceptionHook | Pointer to 4C5C - 0x405C .text + UnwindInfo: .rdata
99F8 180004E00 .pdata ExceptionHook | Pointer to 4E00 - 0x4200 .text + UnwindInfo: .rdata
9A04 180004E58 .pdata ExceptionHook | Pointer to 4E58 - 0x4258 .text + UnwindInfo: .rdata
9A10 180004FBC .pdata ExceptionHook | Pointer to 4FBC - 0x43BC .text + UnwindInfo: .rdata
9A1C 1800050C0 .pdata ExceptionHook | Pointer to 50C0 - 0x44C0 .text + UnwindInfo: .rdata
9A28 18000521C .pdata ExceptionHook | Pointer to 521C - 0x461C .text + UnwindInfo: .rdata
9A34 1800052D4 .pdata ExceptionHook | Pointer to 52D4 - 0x46D4 .text + UnwindInfo: .rdata
9A40 180005430 .pdata ExceptionHook | Pointer to 5430 - 0x4830 .text + UnwindInfo: .rdata
9A4C 180005498 .pdata ExceptionHook | Pointer to 5498 - 0x4898 .text + UnwindInfo: .rdata
9A58 1800054CC .pdata ExceptionHook | Pointer to 54CC - 0x48CC .text + UnwindInfo: .rdata
9A64 180005840 .pdata ExceptionHook | Pointer to 5840 - 0x4C40 .text + UnwindInfo: .rdata
9A70 180005AE4 .pdata ExceptionHook | Pointer to 5AE4 - 0x4EE4 .text + UnwindInfo: .rdata
9A7C 180005B6C .pdata ExceptionHook | Pointer to 5B6C - 0x4F6C .text + UnwindInfo: .rdata
9A88 180005BDC .pdata ExceptionHook | Pointer to 5BDC - 0x4FDC .text + UnwindInfo: .rdata
9A94 180005C88 .pdata ExceptionHook | Pointer to 5C88 - 0x5088 .text + UnwindInfo: .rdata
9AA0 180005E50 .pdata ExceptionHook | Pointer to 5E50 - 0x5250 .text + UnwindInfo: .rdata
9AAC 180005EEC .pdata ExceptionHook | Pointer to 5EEC - 0x52EC .text + UnwindInfo: .rdata
9AB8 180005F88 .pdata ExceptionHook | Pointer to 5F88 - 0x5388 .text + UnwindInfo: .rdata
9AC4 18000603C .pdata ExceptionHook | Pointer to 603C - 0x543C .text + UnwindInfo: .rdata
9AD0 18000665C .pdata ExceptionHook | Pointer to 665C - 0x5A5C .text + UnwindInfo: .rdata
Extra Analysis
Metric Value Percentage
Ascii Code 21900 52,8067%
Null Byte Code 13092 31,5683%
NOP Cave Found 0x9090909090 Block Count: 40 | Total: 0,2411%
© 2026 All rights reserved.