PREMIUM PESCAN.IO - Analysis Report

File Structure
Analysis Image
PE Chart Code
Header PE (light blue)
Executable sections (pink)
Non-executable sections (black)
External injected code (red)
File Structure in red = malformed or corrupted header

Chart Code For Other Files
Printable characters (blue)
Non-printable characters (black)
Information
Size: 545,50 KB
SHA-256 Hash: 8E4C5D232D6A1D98D88A52565379F1C8E85FE297910FC4D4F526A0F0375932A5
SHA-1 Hash: FE9A45C7562567BA191FF6C79A375C7EE8AF3A65
MD5 Hash: A8F68066B2E990D00AAFC93F7B5F6156
Imphash: 2D3B2F0421CE116511DABC56A9EE3656
MajorOSVersion: 6
MinorOSVersion: 0
CheckSum: 00000000
EntryPoint (rva): C790
SizeOfHeaders: 400
SizeOfImage: 8E000
ImageBase: 0000000140000000
Architecture: x64
ImportTable: 8511C
IAT: 1B000
Characteristics: 22
TimeDateStamp: 6A7EFA20
Date: 14/08/2026 11:21:04
File Type: EXE
Number Of Sections: 6
ASLR: Disabled
Section Names (Optional Header): .text, .rdata, .data, .pdata, .rsrc, .reloc
Number Of Executable Sections: 1
Subsystem: Windows GUI

Sections Info
Section Name Flags ROffset RSize VOffset VSizeEntropyChi2
.text
0x60000020
Code
Executable
Readable
400 19A00 1000 19990
6.4836
647161.48
.rdata
0x40000040
Initialized Data
Readable
19E00 6AE00 1B000 6ACA2
6.1185
1677476.16
.data
0xC0000040
Initialized Data
Readable
Writeable
84C00 1A00 86000 3408
5.129
356862.15
.pdata
0x40000040
Initialized Data
Readable
86600 1400 8A000 12D8
5.0047
189952
.rsrc
0x40000040
Initialized Data
Readable
87A00 400 8C000 2A8
2.284
141653.5
.reloc
0x42000040
Initialized Data
GP-Relative
Readable
87E00 800 8D000 75C
5.231
17632.25
Description
OriginalFilename: slaufoiaw.exe
CompanyName: reekseincy LLC
ProductName: slaufoiaw
FileVersion: 2.0.34.4912
ProductVersion: 2.0.34.4912
Language: English (United States) (ID=0x409)
CodePage: Unicode (UTF-16 LE) (0x4B0)

Entry Point
The section number (1) have the Entry Point
Information -> EntryPoint (calculated) - BB90
Code -> 4883EC28E84F0500004883C428E972FEFFFFCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCC66660F1F8400000000004883
Assembler
|SUB RSP, 0X28
|CALL 0X14000CCE8
|ADD RSP, 0X28
|JMP 0X14000C614
|INT3
|INT3
|INT3
|INT3
|INT3
|INT3
|INT3
|INT3
|INT3
|INT3
|INT3
|INT3
|INT3
|INT3
|INT3
|INT3
|INT3
|INT3
|INT3
|INT3
|NOP WORD PTR [RAX + RAX]
Signatures
Rich Signature Analyzer:
Code -> 5E7303A61A126DF51A126DF51A126DF51A126DF518126DF51A126CF535126DF51A12FAF51B126DF5729490F519126DF5809592F51B126DF572946CF418126DF580956FF41B126DF572946EF401126DF5589768F408126DF5729468F47D126DF5809564F418126DF5526963681A126DF5
Footprint md5 Hash -> EE612C0C8132F9F5B4CB9B397F6B589B
• The Rich header apparently has not been modified
Certificate - Digital Signature Not Found:
• The file is not signed

Packer/Compiler
Compiler: Microsoft Visual Studio
Detect It Easy (die)
PE+(64): compiler: Microsoft Visual C/C++(-)[-]
PE+(64): linker: Microsoft Linker(14.44**)[-]
Entropy: 6.58152

Suspicious Functions
Library Function Description
KERNEL32.DLL WriteFile Writes data to a specified file or input/output (I/O) device.
KERNEL32.DLL LoadLibraryA Loads the specified module into the address space of the calling process.
KERNEL32.DLL GetModuleHandleA Retrieves a handle to the specified module.
KERNEL32.DLL GetModuleHandleW Retrieves a handle to the specified module.
KERNEL32.DLL GetProcAddress Retrieves the address of an exported function or variable from the specified dynamic-link library (DLL).
KERNEL32.DLL IsDebuggerPresent Determines if the calling process is being debugged by a user-mode debugger.
KERNEL32.DLL GetTempPathW Retrieves the temporary directory path.
KERNEL32.DLL CreateFileW Creates or opens a file object.
KERNEL32.DLL ReadFile Reads data from a file.
KERNEL32.DLL FindNextFileW Continues file and directory enumeration.
KERNEL32.DLL FindClose Closes a file search handle.
KERNEL32.DLL CloseHandle Closes an open object handle.
KERNEL32.DLL VirtualProtect Changes memory protection attributes.
KERNEL32.DLL GetVersion Retrieves the operating system version.
File Access
KERNEL32.dll
ntdll.dll
.dat
\Program Files\Go\oiahiehn.dat
\ProgramData\associated\screenkeadly.dat
@.dat
Temp

File Access (UNICODE)
slaufoiaw.exe
mscoree.dll

Interest's Words
start
wmic
setx

Strings/Hex Code Found With The File Rules
Rule Type Encoding Matched (Word)
Text Ascii Threat focused on obtaining CVV codes to conduct unauthorized transactions (CVV)
Text Ascii Software that monitors and collects user data (Spy)
Entry Point Hex Pattern Microsoft Visual C++ 8.0 (DLL)
Entry Point Hex Pattern Microsoft Visual C++ 8.0
Resources
Path DataRVA Size FileOffset CodeText
\VERSION\1\1033 8C060 244 87A60 440234000000560053005F00560045005200530049004F004E005F0049004E0046004F0000000000BD04EFFE000001000000D.4...V.S._.V.E.R.S.I.O.N._.I.N.F.O...............
Intelligent String
• slaufoiaw.exe
• C:\Program Files (x86)\outdid\hydraiartsoll.pdfNtReleaseKeyedEvent
• NtCreateKeyedEventykX7n$alF&moyll55U),1UtGma?nb6k_"Ana6BBKbWWWWWXkzbbLvtr7mmXGuLn-y8r3vWXb0ZeW\\?\UNC\@zZc5.dll
• C:\Program Files (x86)\Mozilla Firefox\thuietsoery.txtC:\Program Files\Python310\uncyuacs
• mscoree.dll
• slaufoiaw.pdb
• .tls
• .bss
• HeapReAllockernel32.dll

Flow Anomalies
Offset FlowVA Section Description
9D2 N/A .text CALL QWORD PTR [RIP+0x19BB0]
9E6 N/A .text JMP QWORD PTR [RIP+0x19A44]
A0B N/A .text CALL QWORD PTR [RIP+0x19A17]
16B9 N/A .text CALL QWORD PTR [RIP+0x18D61]
174B N/A .text CALL QWORD PTR [RIP+0x18E37]
1765 N/A .text JMP QWORD PTR [RIP+0x18CA5]
1904 N/A .text CALL QWORD PTR [RIP+0x18E06]
1919 N/A .text CALL QWORD PTR [RIP+0x18AF9]
1947 N/A .text CALL QWORD PTR [RIP+0x18DD3]
199C N/A .text CALL QWORD PTR [RIP+0x18AC6]
19B1 N/A .text CALL QWORD PTR [RIP+0x18A81]
1E1C N/A .text CALL QWORD PTR [RIP+0x18616]
1F33 N/A .text CALL QWORD PTR [RIP+0x18507]
1FB1 N/A .text CALL QWORD PTR [RIP+0x18491]
2184 N/A .text CALL QWORD PTR [RIP+0x182C6]
22AF N/A .text CALL QWORD PTR [RIP+0x181A3]
22DA N/A .text CALL QWORD PTR [RIP+0x18180]
2634 N/A .text CALL QWORD PTR [RIP+0x17E06]
2956 N/A .text CALL QWORD PTR [RIP+0x17DBC]
44AA N/A .text CALL QWORD PTR [RIP+0x15FC0]
46D3 N/A .text CALL QWORD PTR [RIP+0x15D9F]
487A N/A .text CALL QWORD PTR [RIP+0x15C00]
4888 N/A .text CALL QWORD PTR [RIP+0x15BFA]
48A3 N/A .text CALL QWORD PTR [RIP+0x15BE7]
48F9 N/A .text CALL QWORD PTR [RIP+0x15B99]
5E29 N/A .text CALL QWORD PTR [RIP+0x14671]
5E3A N/A .text CALL QWORD PTR [RIP+0x14668]
64BB N/A .text CALL QWORD PTR [RIP+0x13FEF]
64CE N/A .text CALL QWORD PTR [RIP+0x13F7C]
6524 N/A .text CALL QWORD PTR [RIP+0x141FE]
6539 N/A .text CALL QWORD PTR [RIP+0x13ED9]
6559 N/A .text CALL QWORD PTR [RIP+0x141C1]
6D0E N/A .text CALL QWORD PTR [RIP+0x137A4]
6D64 N/A .text CALL QWORD PTR [RIP+0x13756]
6DDD N/A .text CALL QWORD PTR [RIP+0x136E5]
6E30 N/A .text CALL QWORD PTR [RIP+0x13682]
6ECE N/A .text CALL QWORD PTR [RIP+0x136B4]
6F36 N/A .text CALL QWORD PTR [RIP+0x13594]
6F79 N/A .text CALL QWORD PTR [RIP+0x13559]
6F8E N/A .text CALL QWORD PTR [RIP+0x13534]
74DC N/A .text CALL QWORD PTR [RIP+0x12FFE]
7534 N/A .text CALL QWORD PTR [RIP+0x12FAE]
7549 N/A .text CALL QWORD PTR [RIP+0x12F01]
75C5 N/A .text CALL QWORD PTR [RIP+0x12E75]
76F2 N/A .text CALL QWORD PTR [RIP+0x12D28]
7706 N/A .text CALL QWORD PTR [RIP+0x12DE4]
7713 N/A .text CALL QWORD PTR [RIP+0x12D37]
7725 N/A .text CALL QWORD PTR [RIP+0x12D25]
79E4 N/A .text CALL QWORD PTR [RIP+0x12B0E]
7A9A N/A .text CALL QWORD PTR [RIP+0x12A68]
7DF8 N/A .text CALL QWORD PTR [RIP+0x12712]
84D3 N/A .text CALL QWORD PTR [RIP+0x11F8F]
84E8 N/A .text CALL QWORD PTR [RIP+0x11F4A]
8614 N/A .text CALL QWORD PTR [RIP+0x11E4E]
868D N/A .text CALL QWORD PTR [RIP+0x11E85]
86DC N/A .text CALL QWORD PTR [RIP+0x11D86]
86F1 N/A .text CALL QWORD PTR [RIP+0x11D41]
8805 N/A .text CALL QWORD PTR [RIP+0x11C65]
8985 N/A .text CALL QWORD PTR [RIP+0x11B95]
8991 N/A .text CALL QWORD PTR [RIP+0x11B91]
8A00 N/A .text CALL QWORD PTR [RIP+0x11B2A]
8A54 N/A .text CALL QWORD PTR [RIP+0x11B2E]
8C6D N/A .text CALL QWORD PTR [RIP+0x117CD]
A07B N/A .text CALL QWORD PTR [RIP+0x104B7]
A095 N/A .text CALL QWORD PTR [RIP+0x104A5]
A14C N/A .text CALL QWORD PTR [RIP+0x103F6]
A1D2 N/A .text CALL QWORD PTR [RIP+0x10378]
A22D N/A .text CALL QWORD PTR [RIP+0x102FD]
A239 N/A .text CALL QWORD PTR [RIP+0x10349]
A2E6 N/A .text CALL QWORD PTR [RIP+0x1026C]
A384 N/A .text CALL QWORD PTR [RIP+0x101D6]
A398 N/A .text CALL QWORD PTR [RIP+0x101CA]
A3E0 N/A .text CALL QWORD PTR [RIP+0x1015A]
A47F N/A .text CALL QWORD PTR [RIP+0x100C3]
A4C2 N/A .text CALL QWORD PTR [RIP+0x10088]
A5FF N/A .text CALL QWORD PTR [RIP+0xFF33]
A62B N/A .text CALL QWORD PTR [RIP+0xFF27]
A965 N/A .text CALL QWORD PTR [RIP+0xFC05]
AB0A N/A .text CALL QWORD PTR [RIP+0xFA68]
AC1D N/A .text CALL QWORD PTR [RIP+0xF845]
AC35 N/A .text CALL QWORD PTR [RIP+0xF7FD]
AC4D N/A .text CALL QWORD PTR [RIP+0xF7E5]
ACFB N/A .text CALL QWORD PTR [RIP+0xF767]
AD10 N/A .text CALL QWORD PTR [RIP+0xF722]
B89F N/A .text CALL QWORD PTR [RIP+0xECE3]
B8B0 N/A .text CALL QWORD PTR [RIP+0xECCA]
BAD6 N/A .text CALL QWORD PTR [RIP+0xEC6C]
C117 N/A .text CALL QWORD PTR [RIP+0xE483]
C125 N/A .text CALL QWORD PTR [RIP+0xE35D]
C131 N/A .text CALL QWORD PTR [RIP+0xE341]
C141 N/A .text CALL QWORD PTR [RIP+0xE451]
C1B4 N/A .text JMP QWORD PTR [RIP+0xE3EE]
C234 N/A .text CALL QWORD PTR [RIP+0xE256]
C261 N/A .text CALL QWORD PTR [RIP+0xE349]
C27B N/A .text CALL QWORD PTR [RIP+0xE337]
C2BF N/A .text CALL QWORD PTR [RIP+0xE2FB]
C313 N/A .text CALL QWORD PTR [RIP+0xE2AF]
C330 N/A .text CALL QWORD PTR [RIP+0xE2A2]
C33B N/A .text CALL QWORD PTR [RIP+0xE28F]
C372 N/A .text CALL QWORD PTR [RIP+0xE150]
988-9BF N/A .text Unusual BP Cave, count: 56
170E-173F N/A .text Unusual BP Cave, count: 50
188B-18BF N/A .text Unusual BP Cave, count: 53
19E2-19FF N/A .text Unusual BP Cave, count: 30
2197-21BF N/A .text Unusual BP Cave, count: 41
264F-267F N/A .text Unusual BP Cave, count: 49
6241-625F N/A .text Unusual BP Cave, count: 31
62DA-62FF N/A .text Unusual BP Cave, count: 38
7090-70BF N/A .text Unusual BP Cave, count: 48
8197-81BF N/A .text Unusual BP Cave, count: 41
869C-86BF N/A .text Unusual BP Cave, count: 36
8722-873F N/A .text Unusual BP Cave, count: 30
8B83-8BBF N/A .text Unusual BP Cave, count: 61
8C81-8CBF N/A .text Unusual BP Cave, count: 63
9ED8-9EFF N/A .text Unusual BP Cave, count: 40
A785-A7BF N/A .text Unusual BP Cave, count: 59
AB56-AB7F N/A .text Unusual BP Cave, count: 42
AC91-ACBF N/A .text Unusual BP Cave, count: 47
ACC1-ACDF N/A .text Unusual BP Cave, count: 31
AD51-AD7F N/A .text Unusual BP Cave, count: 47
AD8D-ADBF N/A .text Unusual BP Cave, count: 51
AECE-AEFF N/A .text Unusual BP Cave, count: 50
B34D-B37F N/A .text Unusual BP Cave, count: 51
B3CB-B3FF N/A .text Unusual BP Cave, count: 53
B4CF-B4FF N/A .text Unusual BP Cave, count: 49
1A1D8 14000BE40 .rdata TLS Callback | Pointer to BE40 - 0xB240 .text
1A1E0 1400026E0 .rdata TLS Callback | Pointer to 26E0 - 0x1AE0 .text
1A1E8 140008B00 .rdata TLS Callback | Pointer to 8B00 - 0x7F00 .text
86600 140001000 .pdata ExceptionHook | Pointer to 1000 - 0x400 .text + UnwindInfo: .rdata
8660C 1400011C0 .pdata ExceptionHook | Pointer to 11C0 - 0x5C0 .text + UnwindInfo: .rdata
86618 140001240 .pdata ExceptionHook | Pointer to 1240 - 0x640 .text + UnwindInfo: .rdata
86624 1400015C0 .pdata ExceptionHook | Pointer to 15C0 - 0x9C0 .text + UnwindInfo: .rdata
86630 1400015F0 .pdata ExceptionHook | Pointer to 15F0 - 0x9F0 .text + UnwindInfo: .rdata
8663C 140001C80 .pdata ExceptionHook | Pointer to 1C80 - 0x1080 .text + UnwindInfo: .rdata
86648 140001D00 .pdata ExceptionHook | Pointer to 1D00 - 0x1100 .text + UnwindInfo: .rdata
86654 140001D80 .pdata ExceptionHook | Pointer to 1D80 - 0x1180 .text + UnwindInfo: .rdata
86660 140002220 .pdata ExceptionHook | Pointer to 2220 - 0x1620 .text + UnwindInfo: .rdata
8666C 1400022B0 .pdata ExceptionHook | Pointer to 22B0 - 0x16B0 .text + UnwindInfo: .rdata
86678 140002340 .pdata ExceptionHook | Pointer to 2340 - 0x1740 .text + UnwindInfo: .rdata
86684 140002380 .pdata ExceptionHook | Pointer to 2380 - 0x1780 .text + UnwindInfo: .rdata
86690 140002440 .pdata ExceptionHook | Pointer to 2440 - 0x1840 .text + UnwindInfo: .rdata
8669C 1400024C0 .pdata ExceptionHook | Pointer to 24C0 - 0x18C0 .text + UnwindInfo: .rdata
866A8 140002580 .pdata ExceptionHook | Pointer to 2580 - 0x1980 .text + UnwindInfo: .rdata
866B4 140002600 .pdata ExceptionHook | Pointer to 2600 - 0x1A00 .text + UnwindInfo: .rdata
866C0 140002680 .pdata ExceptionHook | Pointer to 2680 - 0x1A80 .text + UnwindInfo: .rdata
866CC 140002930 .pdata ExceptionHook | Pointer to 2930 - 0x1D30 .text + UnwindInfo: .rdata
866D8 140002A80 .pdata ExceptionHook | Pointer to 2A80 - 0x1E80 .text + UnwindInfo: .rdata
866E4 140002B50 .pdata ExceptionHook | Pointer to 2B50 - 0x1F50 .text + UnwindInfo: .rdata
866F0 140002CD0 .pdata ExceptionHook | Pointer to 2CD0 - 0x20D0 .text + UnwindInfo: .rdata
866FC 140002D00 .pdata ExceptionHook | Pointer to 2D00 - 0x2100 .text + UnwindInfo: .rdata
86708 140002D80 .pdata ExceptionHook | Pointer to 2D80 - 0x2180 .text + UnwindInfo: .rdata
86714 140002E20 .pdata ExceptionHook | Pointer to 2E20 - 0x2220 .text + UnwindInfo: .rdata
86720 140003280 .pdata ExceptionHook | Pointer to 3280 - 0x2680 .text + UnwindInfo: .rdata
8672C 140006E90 .pdata ExceptionHook | Pointer to 6E90 - 0x6290 .text + UnwindInfo: .rdata
86738 1400070B0 .pdata ExceptionHook | Pointer to 70B0 - 0x64B0 .text + UnwindInfo: .rdata
86744 1400070E0 .pdata ExceptionHook | Pointer to 70E0 - 0x64E0 .text + UnwindInfo: .rdata
86750 140007180 .pdata ExceptionHook | Pointer to 7180 - 0x6580 .text + UnwindInfo: .rdata
8675C 140007BE0 .pdata ExceptionHook | Pointer to 7BE0 - 0x6FE0 .text + UnwindInfo: .rdata
86768 140007C20 .pdata ExceptionHook | Pointer to 7C20 - 0x7020 .text + UnwindInfo: .rdata
86774 140007CC0 .pdata ExceptionHook | Pointer to 7CC0 - 0x70C0 .text + UnwindInfo: .rdata
86780 140008570 .pdata ExceptionHook | Pointer to 8570 - 0x7970 .text + UnwindInfo: .rdata
8678C 140008A80 .pdata ExceptionHook | Pointer to 8A80 - 0x7E80 .text + UnwindInfo: .rdata
86798 140008AA0 .pdata ExceptionHook | Pointer to 8AA0 - 0x7EA0 .text + UnwindInfo: .rdata
867A4 140008AE0 .pdata ExceptionHook | Pointer to 8AE0 - 0x7EE0 .text + UnwindInfo: .rdata
867B0 140008D60 .pdata ExceptionHook | Pointer to 8D60 - 0x8160 .text + UnwindInfo: .rdata
867BC 140008DE0 .pdata ExceptionHook | Pointer to 8DE0 - 0x81E0 .text + UnwindInfo: .rdata
867C8 140008FC0 .pdata ExceptionHook | Pointer to 8FC0 - 0x83C0 .text + UnwindInfo: .rdata
867D4 140009090 .pdata ExceptionHook | Pointer to 9090 - 0x8490 .text + UnwindInfo: .rdata
867E0 1400090C0 .pdata ExceptionHook | Pointer to 90C0 - 0x84C0 .text + UnwindInfo: .rdata
867EC 140009120 .pdata ExceptionHook | Pointer to 9120 - 0x8520 .text + UnwindInfo: .rdata
867F8 140009180 .pdata ExceptionHook | Pointer to 9180 - 0x8580 .text + UnwindInfo: .rdata
86804 1400092C0 .pdata ExceptionHook | Pointer to 92C0 - 0x86C0 .text + UnwindInfo: .rdata
86810 140009360 .pdata ExceptionHook | Pointer to 9360 - 0x8760 .text + UnwindInfo: .rdata
8681C 1400096A0 .pdata ExceptionHook | Pointer to 96A0 - 0x8AA0 .text + UnwindInfo: .rdata
86828 1400096E0 .pdata ExceptionHook | Pointer to 96E0 - 0x8AE0 .text + UnwindInfo: .rdata
86834 140009750 .pdata ExceptionHook | Pointer to 9750 - 0x8B50 .text + UnwindInfo: .rdata
86840 1400097C0 .pdata ExceptionHook | Pointer to 97C0 - 0x8BC0 .text + UnwindInfo: .rdata
8684C 140009820 .pdata ExceptionHook | Pointer to 9820 - 0x8C20 .text + UnwindInfo: .rdata
86858 1400098C0 .pdata ExceptionHook | Pointer to 98C0 - 0x8CC0 .text + UnwindInfo: .rdata
86864 14000A800 .pdata ExceptionHook | Pointer to A800 - 0x9C00 .text + UnwindInfo: .rdata
86870 14000AB00 .pdata ExceptionHook | Pointer to AB00 - 0x9F00 .text + UnwindInfo: .rdata
8687C 14000AB40 .pdata ExceptionHook | Pointer to AB40 - 0x9F40 .text + UnwindInfo: .rdata
86888 14000B260 .pdata ExceptionHook | Pointer to B260 - 0xA660 .text + UnwindInfo: .rdata
86894 14000B300 .pdata ExceptionHook | Pointer to B300 - 0xA700 .text + UnwindInfo: .rdata
868A0 14000B470 .pdata ExceptionHook | Pointer to B470 - 0xA870 .text + UnwindInfo: .rdata
868AC 14000B780 .pdata ExceptionHook | Pointer to B780 - 0xAB80 .text + UnwindInfo: .rdata
868B8 14000B810 .pdata ExceptionHook | Pointer to B810 - 0xAC10 .text + UnwindInfo: .rdata
868C4 14000B8E0 .pdata ExceptionHook | Pointer to B8E0 - 0xACE0 .text + UnwindInfo: .rdata
868D0 14000BB10 .pdata ExceptionHook | Pointer to BB10 - 0xAF10 .text + UnwindInfo: .rdata
868DC 14000BCF0 .pdata ExceptionHook | Pointer to BCF0 - 0xB0F0 .text + UnwindInfo: .rdata
868E8 14000BDC0 .pdata ExceptionHook | Pointer to BDC0 - 0xB1C0 .text + UnwindInfo: .rdata
868F4 14000BDF0 .pdata ExceptionHook | Pointer to BDF0 - 0xB1F0 .text + UnwindInfo: .rdata
86900 14000BE40 .pdata ExceptionHook | Pointer to BE40 - 0xB240 .text + UnwindInfo: .rdata
8690C 14000C010 .pdata ExceptionHook | Pointer to C010 - 0xB410 .text + UnwindInfo: .rdata
86918 14000C060 .pdata ExceptionHook | Pointer to C060 - 0xB460 .text + UnwindInfo: .rdata
86924 14000C420 .pdata ExceptionHook | Pointer to C420 - 0xB820 .text + UnwindInfo: .rdata
86930 14000C530 .pdata ExceptionHook | Pointer to C530 - 0xB930 .text + UnwindInfo: .rdata
8693C 14000C5E8 .pdata ExceptionHook | Pointer to C5E8 - 0xB9E8 .text + UnwindInfo: .rdata
86948 14000C5F8 .pdata ExceptionHook | Pointer to C5F8 - 0xB9F8 .text + UnwindInfo: .rdata
86954 14000C614 .pdata ExceptionHook | Pointer to C614 - 0xBA14 .text + UnwindInfo: .rdata
86960 14000C790 .pdata ExceptionHook | Pointer to C790 - 0xBB90 .text + UnwindInfo: .rdata
8696C 14000C7C0 .pdata ExceptionHook | Pointer to C7C0 - 0xBBC0 .text + UnwindInfo: .rdata
86978 14000C810 .pdata ExceptionHook | Pointer to C810 - 0xBC10 .text + UnwindInfo: .rdata
86984 14000CAA8 .pdata ExceptionHook | Pointer to CAA8 - 0xBEA8 .text + UnwindInfo: .rdata
86990 14000CAE4 .pdata ExceptionHook | Pointer to CAE4 - 0xBEE4 .text + UnwindInfo: .rdata
8699C 14000CB20 .pdata ExceptionHook | Pointer to CB20 - 0xBF20 .text + UnwindInfo: .rdata
869A8 14000CBAC .pdata ExceptionHook | Pointer to CBAC - 0xBFAC .text + UnwindInfo: .rdata
869B4 14000CC44 .pdata ExceptionHook | Pointer to CC44 - 0xC044 .text + UnwindInfo: .rdata
869C0 14000CC68 .pdata ExceptionHook | Pointer to CC68 - 0xC068 .text + UnwindInfo: .rdata
869CC 14000CC94 .pdata ExceptionHook | Pointer to CC94 - 0xC094 .text + UnwindInfo: .rdata
869D8 14000CCD0 .pdata ExceptionHook | Pointer to CCD0 - 0xC0D0 .text + UnwindInfo: .rdata
869E4 14000CCE8 .pdata ExceptionHook | Pointer to CCE8 - 0xC0E8 .text + UnwindInfo: .rdata
869F0 14000CDD4 .pdata ExceptionHook | Pointer to CDD4 - 0xC1D4 .text + UnwindInfo: .rdata
869FC 14000CE18 .pdata ExceptionHook | Pointer to CE18 - 0xC218 .text + UnwindInfo: .rdata
86A08 14000CF6C .pdata ExceptionHook | Pointer to CF6C - 0xC36C .text + UnwindInfo: .rdata
86A14 14000CFD0 .pdata ExceptionHook | Pointer to CFD0 - 0xC3D0 .text + UnwindInfo: .rdata
86A20 14000D034 .pdata ExceptionHook | Pointer to D034 - 0xC434 .text + UnwindInfo: .rdata
86A2C 14000D070 .pdata ExceptionHook | Pointer to D070 - 0xC470 .text + UnwindInfo: .rdata
86A38 14000D0C0 .pdata ExceptionHook | Pointer to D0C0 - 0xC4C0 .text + UnwindInfo: .rdata
86A44 14000D2D8 .pdata ExceptionHook | Pointer to D2D8 - 0xC6D8 .text + UnwindInfo: .rdata
86A50 14000D300 .pdata ExceptionHook | Pointer to D300 - 0xC700 .text + UnwindInfo: .rdata
86A5C 14000D334 .pdata ExceptionHook | Pointer to D334 - 0xC734 .text + UnwindInfo: .rdata
86A68 14000D3AC .pdata ExceptionHook | Pointer to D3AC - 0xC7AC .text + UnwindInfo: .rdata
86A74 14000D400 .pdata ExceptionHook | Pointer to D400 - 0xC800 .text + UnwindInfo: .rdata
86A80 14000D468 .pdata ExceptionHook | Pointer to D468 - 0xC868 .text + UnwindInfo: .rdata
86A8C 14000D47C .pdata ExceptionHook | Pointer to D47C - 0xC87C .text + UnwindInfo: .rdata
86A98 14000D490 .pdata ExceptionHook | Pointer to D490 - 0xC890 .text + UnwindInfo: .rdata
86AA4 14000D4D0 .pdata ExceptionHook | Pointer to D4D0 - 0xC8D0 .text + UnwindInfo: .rdata
Extra Analysis
Metric Value Percentage
Ascii Code 484871 86,8024%
Null Byte Code 38650 6,9192%
© 2026 All rights reserved.