PREMIUM PESCAN.IO - Analysis Report |
|||||||
| File Structure |
|
PE Chart Code
Header PE (light blue)
Executable sections (pink)
Non-executable sections (black)
External injected code (red)
File Structure in red = malformed or corrupted header
Chart Code For Other Files
Printable characters (blue)
Non-printable characters (black)
| Information |
| Size: 1,62 MB SHA-256 Hash: 284CDB6ED51B1FE3A17A1F62B4F36CE83F28935F3FCED506A8C0E6FC3A2CEBC8 SHA-1 Hash: AA48D19D085366B44CFF797D87FAB1DED4EE6C41 MD5 Hash: AF22E6E224031F90C8E295DF4992D376 Imphash: 1F365D4E2C37B47FB208B089B5F61D49 MajorOSVersion: 6 MinorOSVersion: 0 CheckSum: 00000000 EntryPoint (rva): 189594 SizeOfHeaders: 400 SizeOfImage: 1C7000 ImageBase: 400000 Architecture: x86 ExportTable: 19C000 ImportTable: 199000 Characteristics: 2102 TimeDateStamp: 6A677BC5 Date: 27/07/2026 15:39:49 File Type: DLL Number Of Sections: 10 ASLR: Enabled Section Names: .text, .itext, .data, .bss, .idata, .didata, .edata, .rdata, .reloc, .rsrc Number Of Executable Sections: 2 Subsystem: Windows GUI |
| Sections Info |
| Section Name | Flags | ROffset | RSize | VOffset | VSize | Entropy | Chi2 |
|---|---|---|---|---|---|---|---|
| .text | 0x60000020 Code Executable Readable |
600 | 186E00 | 1000 | 187000 |
|
|
| .itext | 0x60000020 Code Executable Readable |
187400 | 1600 | 188000 | 2000 |
|
|
| .data | 0xC0000040 Initialized Data Readable Writeable |
188A00 | 7E00 | 18A000 | 8000 |
|
|
| .bss | 0xC0000000 Readable Writeable |
190800 | 6C00 | 192000 | 7000 |
|
|
| .idata | 0xC0000040 Initialized Data Readable Writeable |
197400 | 1800 | 199000 | 2000 |
|
|
| .didata | 0xC0000040 Initialized Data Readable Writeable |
198C00 | 600 | 19B000 | 1000 |
|
|
| .edata | 0x40000040 Initialized Data Readable |
199200 | 200 | 19C000 | 1000 |
|
|
| .rdata | 0x40000040 Initialized Data Readable |
199400 | 200 | 19D000 | 1000 |
|
|
| .reloc | 0x42000040 Initialized Data GP-Relative Readable |
199600 | 0 | 19E000 | 23000 |
|
|
| .rsrc | 0x40000040 Initialized Data Readable |
199600 | 5200 | 1C1000 | 6000 |
|
|
| Description |
| OriginalFilename: dhlib.dll CompanyName: Microsoft Corporation LegalCopyright: Microsoft Corporation. All rights reserved. LegalTrademarks: Microsoft ProductName: Windows Data Helper FileVersion: 10.0.19041.1 FileDescription: Windows Data Helper Library ProductVersion: 10.0.19041.1 Comments: System component for application data management Language: English (United States) (ID=0x409) CodePage: Western European (Windows 1252) (0x4E4) |
| Entry Point |
The section number (2) - (.itext) have the Entry Point Information -> EntryPoint (calculated) - 188994 Code -> 558BEC83C4C0B8EC265800E84C86E8FF33C05568C295580064FF3064892033C05A595964891068C995580058FFE0E9E502E8 Assembler |PUSH EBP |MOV EBP, ESP |ADD ESP, -0X40 |MOV EAX, 0X5826EC |CALL 0X411BF0 |XOR EAX, EAX |PUSH EBP |PUSH 0X5895C2 |PUSH DWORD PTR FS:[EAX] |MOV DWORD PTR FS:[EAX], ESP |XOR EAX, EAX |POP EDX |POP ECX |POP ECX |MOV DWORD PTR FS:[EAX], EDX |PUSH 0X5895C9 |POP EAX |JMP EAX |
| Signatures |
| Certificate - Digital Signature Not Found: • The file is not signed |
| Packer/Compiler |
| Detect It Easy (die) • PE: compiler: Embarcadero Delphi(XE2-XE6)[-] • PE: linker: Turbo Linker(2.25*,Delphi)[-] • Entropy: 6.37656 |
| Suspicious Functions |
| Library | Function | Description |
|---|---|---|
| KERNEL32.DLL | VirtualAlloc | Reserve, commit, or both, a region of memory within the virtual address space of a process. |
| KERNEL32.DLL | WriteFile | Writes data to a specified file or input/output (I/O) device. |
| KERNEL32.DLL | LoadLibraryA | Loads the specified module into the address space of the calling process. |
| KERNEL32.DLL | LoadLibraryW | Loads the specified module into the address space of the calling process. |
| KERNEL32.DLL | WriteProcessMemory | Writes data to an area of memory in a specified process. |
| KERNEL32.DLL | ReadProcessMemory | Reads data from an area of memory in a specified process. |
| KERNEL32.DLL | GetProcAddress | Retrieves the address of an exported function or variable from the specified dynamic-link library (DLL). |
| KERNEL32.DLL | IsDebuggerPresent | Determines if the calling process is being debugged by a user-mode debugger. |
| ADVAPI32.DLL | CryptDecrypt | Performs a cryptographic operation on data in a data block. |
| Windows REG |
| System\@ System\H System\CR |
| Windows REG (UNICODE) |
| Software\FluxEngine\Desktop Software\HWiNFO32\Sens SOFTWARE\Microsoft\Windows NT\CurrentVersion Software\Embarcadero\Locales Software\CodeGear\Locales Software\Borland\Locales Software\Borland\Delphi\Locales SOFTWARE\Microsoft\Cryptography Software\Microsoft\Windows\CurrentVersion\Run Rebuilt string - SOFTWARE\Microsoft\Windows\CurrentVersion\Run |
| File Access |
| TTask.Exe TTask.Exe Project1.dll Crypt32.dll advapi32.dll kernel32.dll user32.dll winhttp.dll msvcrt.dll oleaut32.dll ole32.dll bcrypt.dll wininet.dll dSystem.Sys System.Sys System.Sys ?System.Sys &System.Dat System.Word,System.Dat System.Dat System.Dat lttInvalidSystem.Dat AddStrings(Strings.dat .dat System.Ini Temp |
| File Access (UNICODE) |
| GetLogicalProcessorInformationkernel32.dll kernel32.dll dhlib.dll %SystemRoot%\System32\attrib.exe winhttp.dll oleaut32.dll NTDLL.DLL opendocument.dat n-gage.dat dece.dat application/vnd.dat dece.zip Temp |
| SQL Queries |
| SELECT Manufacturer, Model FROM Win32_ComputerSystem SELECT Version FROM Win32_BIOS |
| Interest's Words |
| Encrypt Decrypt Encryption PassWord exec attrib start hostname shutdown systeminfo expand replace |
| Interest's Words (UNICODE) |
| Encrypt Encryption PassWord exec attrib start certreq ping expand route |
| URLs (UNICODE) |
| http://direct:80 https://api.cloudflare.com/client/v4/zones?per_page=1000 https://api.cloudflare.com/client/v4/ |
| Strings/Hex Code Found With The File Rules |
| Rule Type | Encoding | Matched (Word) |
|---|---|---|
| Text | Unicode | WinAPI Sockets (bind) |
| Text | Unicode | WinAPI Sockets (accept) |
| Text | Unicode | WinAPI Sockets (connect) |
| Text | Unicode | WinAPI Sockets (send) |
| Text | Ascii | Registry (RegCreateKeyEx) |
| Text | Ascii | Registry (RegOpenKeyEx) |
| Text | Ascii | Registry (RegSetValueEx) |
| Text | Ascii | Registry (RegDeleteKeyEx) |
| Text | Ascii | File (GetTempPath) |
| Text | Ascii | File (CreateFile) |
| Text | Ascii | File (WriteFile) |
| Text | Ascii | File (ReadFile) |
| Text | Ascii | Encryption API (CryptDecrypt) |
| Text | Ascii | Anti-Analysis VM (IsDebuggerPresent) |
| Text | Ascii | Anti-Analysis VM (GetSystemInfo) |
| Text | Ascii | Anti-Analysis VM (GetVersion) |
| Text | Ascii | Reconnaissance (FindFirstFileW) |
| Text | Ascii | Reconnaissance (FindClose) |
| Text | Ascii | Stealth (GetThreadContext) |
| Text | Ascii | Stealth (SetThreadContext) |
| Text | Ascii | Stealth (ExitThread) |
| Text | Ascii | Stealth (CloseHandle) |
| Text | Ascii | Stealth (VirtualAlloc) |
| Text | Ascii | Stealth (ReadProcessMemory) |
| Text | Ascii | Execution (CreateProcessW) |
| Text | Ascii | Execution (ResumeThread) |
| Text | Ascii | Execution (CreateEventW) |
| Text | Unicode | Antivirus Software (etrust) |
| Text | Unicode | WMI execution (WbemScripting.SWbemLocator) |
| Text | Ascii | Ability of malware to remain on a system after a reboot (Persistence) |
| Text | Ascii | Process of gathering information about network resources (Enumeration) |
| Text | Ascii | Information used for user authentication (Credential) |
| Text | Unicode | Information used for user authentication (Credential) |
| Text | Ascii | Malicious rerouting of traffic to an attacker-controlled site (Redirect) |
| Text | Ascii | Technique used to capture communications between systems (Intercept) |
| Entry Point | Hex Pattern | Borland Delphi 4.0 |
| Entry Point | Hex Pattern | Borland Delphi v3.0 |
| Entry Point | Hex Pattern | Borland Delphi v6.0 - v7.0 |
| Resources |
| Path | DataRVA | Size | FileOffset | Code | Text |
|---|---|---|---|---|---|
| \STRING\4078\0 | 1C14F0 | 1D4 | 199AF0 | 1A00560061006C007500650020006E0061006D0065002000630061006E006E006F007400200062006500200065006D007000 | ..V.a.l.u.e. .n.a.m.e. .c.a.n.n.o.t. .b.e. .e.m.p. |
| \STRING\4079\0 | 1C16C4 | 458 | 199CC4 | 1F0043006C00690065006E0074002000720065006A0065006300740065006400200074006800650020006300650072007400 | ..C.l.i.e.n.t. .r.e.j.e.c.t.e.d. .t.h.e. .c.e.r.t. |
| \STRING\4080\0 | 1C1B1C | 420 | 19A11C | 1D0053006300680065006D0065002000220025007300220020006900730020006E006F007400200072006500670069007300 | ..S.c.h.e.m.e. .".%.s.". .i.s. .n.o.t. .r.e.g.i.s. |
| \STRING\4081\0 | 1C1F3C | 53C | 19A53C | 3C0055005400460038003A00200041002000730074006100720074002000620079007400650020006E006F00740020006600 | <.U.T.F.8.:. .A. .s.t.a.r.t. .b.y.t.e. .n.o.t. .f. |
| \STRING\4082\0 | 1C2478 | 584 | 19AA78 | 340054006800650020006F0062006A00650063007400200064006F006500730020006E006F007400200069006D0070006C00 | 4.T.h.e. .o.b.j.e.c.t. .d.o.e.s. .n.o.t. .i.m.p.l. |
| \STRING\4083\0 | 1C29FC | 2A8 | 19AFFC | 1600570069006E0064006F00770073002000530065007200760065007200200032003000300038002000520032000C005700 | ..W.i.n.d.o.w.s. .S.e.r.v.e.r. .2.0.0.8. .R.2...W. |
| \STRING\4084\0 | 1C2CA4 | 400 | 19B2A4 | 16004400750070006C0069006300610074006500730020006E006F007400200061006C006C006F0077006500640035004900 | ..D.u.p.l.i.c.a.t.e.s. .n.o.t. .a.l.l.o.w.e.d.5.I. |
| \STRING\4085\0 | 1C30A4 | 460 | 19B6A4 | 110049006E00760061006C0069006400200043006F0075006E0074003A002000250064001B0049006E00760061006C006900 | ..I.n.v.a.l.i.d. .C.o.u.n.t.:. .%.d...I.n.v.a.l.i. |
| \STRING\4086\0 | 1C3504 | 56C | 19BB04 | 2D00430061006E006E006F00740020007400650072006D0069006E00610074006500200061006E0020006500780074006500 | -.C.a.n.n.o.t. .t.e.r.m.i.n.a.t.e. .a.n. .e.x.t.e. |
| \STRING\4087\0 | 1C3A70 | 36C | 19C070 | 0E002E002000200025007300200069007300200065006D007000740079002B004F007500740020006F00660020006D006500 | .... . .%.s. .i.s. .e.m.p.t.y.+.O.u.t. .o.f. .m.e. |
| \STRING\4088\0 | 1C3DDC | 3A4 | 19C3DC | 25004C00690073007400200064006F006500730020006E006F007400200061006C006C006F00770020006400750070006C00 | %.L.i.s.t. .d.o.e.s. .n.o.t. .a.l.l.o.w. .d.u.p.l. |
| \STRING\4089\0 | 1C4180 | 41C | 19C780 | 190049006E00760061006C00690064002000640065007300740069006E006100740069006F006E0020006100720072006100 | ..I.n.v.a.l.i.d. .d.e.s.t.i.n.a.t.i.o.n. .a.r.r.a. |
| \STRING\4090\0 | 1C459C | E8 | 19CB9C | 080044006500630065006D006200650072000300530075006E0003004D006F006E0003005400750065000300570065006400 | ..D.e.c.e.m.b.e.r...S.u.n...M.o.n...T.u.e...W.e.d. |
| \STRING\4091\0 | 1C4684 | C4 | 19CC84 | 0300410075006700030053006500700003004F006300740003004E006F007600030044006500630007004A0061006E007500 | ..A.u.g...S.e.p...O.c.t...N.o.v...D.e.c...J.a.n.u. |
| \STRING\4092\0 | 1C4748 | 274 | 19CD48 | 28004D006F006E00690074006F007200200073007500700070006F00720074002000660075006E006300740069006F006E00 | (.M.o.n.i.t.o.r. .s.u.p.p.o.r.t. .f.u.n.c.t.i.o.n. |
| \STRING\4093\0 | 1C49BC | 414 | 19CFBC | 2C0043007500730074006F006D002000760061007200690061006E0074002000740079007000650020002800250073002500 | ,.C.u.s.t.o.m. .v.a.r.i.a.n.t. .t.y.p.e. .(.%.s.%. |
| \STRING\4094\0 | 1C4DD0 | 37C | 19D3D0 | 280045007800630065007000740069006F006E00200025007300200069006E0020006D006F00640075006C00650020002500 | (.E.x.c.e.p.t.i.o.n. .%.s. .i.n. .m.o.d.u.l.e. .%. |
| \STRING\4095\0 | 1C514C | 2DC | 19D74C | 09004400690073006B002000660075006C006C00150049006E00760061006C006900640020006E0075006D00650072006900 | ..D.i.s.k. .f.u.l.l...I.n.v.a.l.i.d. .n.u.m.e.r.i. |
| \STRING\4096\0 | 1C5428 | 344 | 19DA28 | 09003C0075006E006B006E006F0077006E003E002100270025007300270020006900730020006E006F007400200061002000 | ..<.u.n.k.n.o.w.n.>.!.'.%.s.'. .i.s. .n.o.t. .a. . |
| \RCDATA\DVCLAL\0 | 1C576C | 10 | 19DD6C | 263D4F38C28237B8F3244203179B3A83 | &=O8..7..$B...:. |
| \RCDATA\PACKAGEINFO\0 | 1C577C | 4FC | 19DD7C | 0000108C0000000044000000013750726F6A65637431001C2A57696E6170692E57696E48545450001CF257696E6170692E57 | ........D....7Project1..*Winapi.WinHTTP...Winapi.W |
| \RCDATA\PLATFORMTARGETS\1033 | 1C5C78 | 4 | 19E278 | 01000000 | .... |
| \VERSION\1\1033 | 1C5C7C | 438 | 19E27C | 380434000000560053005F00560045005200530049004F004E005F0049004E0046004F0000000000BD04EFFE000001000000 | 8.4...V.S._.V.E.R.S.I.O.N._.I.N.F.O............... |
| Intelligent String |
| • dhlib.dll • advapi32.dll • user32.dll • kernel32.dll • winhttp.dll • d3dx9_43.bin • System.Net.HttpClient.Win • .bss • NTDLL.DLL • oleaut32.dll • :\)MLastIndexOf@ • dump • application/prs.cww • application/vnd.accpac.simply.aso • application/vnd.accpac.simply.imp • application/vnd.adobe.fxp • application/vnd.airzip.filesecure.azf • application/vnd.airzip.filesecure.azs • application/vnd.americandynamics.acc • application/vnd.amiga.ami • application/vnd.aristanetworks.swi • application/vnd.bmi • application/vnd.curl.car • application/vnd.data-vision.rdz • application/vnd.dece.zip • application/vnd.dna • application/vnd.dolby.mlp • application/vnd.dvb.ait • application/vnd.epson.esf • application/vnd.epson.msf • application/vnd.epson.ssf • application/vnd.fdf • application/vnd.frogans.fnc • application/vnd.frogans.ltf • application/vnd.fujixerox.ddd • application/vnd.gmx • application/vnd.google-earth.kmz • application/vnd.insors.igm • application/vnd.intu.qbo • application/vnd.intu.qfx • application/vnd.isac.fcs • application/vnd.jam • application/vnd.mcd • application/vnd.micrografx.flo • application/vnd.micrografx.igx • application/vnd.mif • application/vnd.mobius.daf • application/vnd.mobius.dis • application/vnd.mobius.mbk • application/vnd.mobius.mqy • application/vnd.mobius.msl • application/vnd.mobius.plc • application/vnd.mobius.txf • application/vnd.ms-pki.stl • application/vnd.neurolanguage.nlu • application/vnd.novadigm.edm • application/vnd.novadigm.edx • application/vnd.previewsystems.box • application/vnd.realvnc.bed • application/vnd.rim.cod • application/vnd.spotfire.dxp • application/vnd.spotfire.sfs • application/vnd.svd • application/vnd.tcpdump.pcap • application/vnd.trid.tpt • application/vnd.triscape.mxs • application/vnd.vcx • application/vnd.vsf • application/vnd.wqd • application/vnd.wt.stf • application/vnd.zul • audio/vnd.dra • audio/vnd.dts • audio/vnd.ms-playready.media.pya • audio/vnd.rip • image/vnd.dwg • image/vnd.dxf • image/vnd.fpx • image/vnd.fst • image/x-xwindowdump • model/vnd.dwf • model/vnd.gdl • model/vnd.gtw • model/vnd.mts • model/vnd.vtu • text/prs.lines.tag • text/vnd.fly • text/vnd.wap.wml • video/vnd.fvt • video/vnd.ms-playready.media.pyv • :\SLastIndexOf@ • :\SCreate • :\{UCreate • http://direct:80 • .pfx • .pem • :\dWCreate • :\lWLastIndexOf@ • https://api.cloudflare.com/client/v4/zones?per_page=1000 • %SystemRoot%\System32\attrib.exe • ole32.dll • .exe • GetThreadLocalewininet.dll • bcrypt.dll • MessageBoxWoleaut32.dll • VariantChangeTypemsvcrt.dll • MessageBoxAkernel32.dll |
| Flow Anomalies |
| Offset | FlowVA | Section | Description |
|---|---|---|---|
| 482C | 599400 | .text | JMP [static] | Indirect jump to absolute memory address |
| 4834 | 599454 | .text | JMP [static] | Indirect jump to absolute memory address |
| 483C | 599588 | .text | JMP [static] | Indirect jump to absolute memory address |
| 4844 | 5994F0 | .text | JMP [static] | Indirect jump to absolute memory address |
| 484C | 5994F4 | .text | JMP [static] | Indirect jump to absolute memory address |
| 4854 | 599560 | .text | JMP [static] | Indirect jump to absolute memory address |
| 485C | 599540 | .text | JMP [static] | Indirect jump to absolute memory address |
| 4864 | 5994F8 | .text | JMP [static] | Indirect jump to absolute memory address |
| 486C | 5994D4 | .text | JMP [static] | Indirect jump to absolute memory address |
| 4874 | 599518 | .text | JMP [static] | Indirect jump to absolute memory address |
| 487C | 599590 | .text | JMP [static] | Indirect jump to absolute memory address |
| 4884 | 599480 | .text | JMP [static] | Indirect jump to absolute memory address |
| 488C | 5994BC | .text | JMP [static] | Indirect jump to absolute memory address |
| 4894 | 5994A0 | .text | JMP [static] | Indirect jump to absolute memory address |
| 489C | 59958C | .text | JMP [static] | Indirect jump to absolute memory address |
| 48A4 | 599434 | .text | JMP [static] | Indirect jump to absolute memory address |
| 48AC | 599498 | .text | JMP [static] | Indirect jump to absolute memory address |
| 48B4 | 599448 | .text | JMP [static] | Indirect jump to absolute memory address |
| 48BC | 5994C0 | .text | JMP [static] | Indirect jump to absolute memory address |
| 48C4 | 599474 | .text | JMP [static] | Indirect jump to absolute memory address |
| 48CC | 599460 | .text | JMP [static] | Indirect jump to absolute memory address |
| 48D4 | 59962C | .text | JMP [static] | Indirect jump to absolute memory address |
| 48DC | 59950C | .text | JMP [static] | Indirect jump to absolute memory address |
| 48E4 | 599478 | .text | JMP [static] | Indirect jump to absolute memory address |
| 48EC | 59945C | .text | JMP [static] | Indirect jump to absolute memory address |
| 48F4 | 59951C | .text | JMP [static] | Indirect jump to absolute memory address |
| 48FC | 5994E8 | .text | JMP [static] | Indirect jump to absolute memory address |
| 4904 | 5994B0 | .text | JMP [static] | Indirect jump to absolute memory address |
| 490C | 5993F8 | .text | JMP [static] | Indirect jump to absolute memory address |
| 4914 | 599564 | .text | JMP [static] | Indirect jump to absolute memory address |
| 491C | 59955C | .text | JMP [static] | Indirect jump to absolute memory address |
| 4924 | 599574 | .text | JMP [static] | Indirect jump to absolute memory address |
| 492C | 599544 | .text | JMP [static] | Indirect jump to absolute memory address |
| 4934 | 5995A8 | .text | JMP [static] | Indirect jump to absolute memory address |
| 493C | 5995BC | .text | JMP [static] | Indirect jump to absolute memory address |
| 4944 | 5995A0 | .text | JMP [static] | Indirect jump to absolute memory address |
| 494C | 599620 | .text | JMP [static] | Indirect jump to absolute memory address |
| 4954 | 599484 | .text | JMP [static] | Indirect jump to absolute memory address |
| 497C | 59B0DC | .text | JMP [static] | Indirect jump to absolute memory address |
| 4984 | 5996C8 | .text | JMP [static] | Indirect jump to absolute memory address |
| 498C | 5996A4 | .text | JMP [static] | Indirect jump to absolute memory address |
| 4994 | 5996C0 | .text | JMP [static] | Indirect jump to absolute memory address |
| 499C | 599494 | .text | JMP [static] | Indirect jump to absolute memory address |
| 49A4 | 599510 | .text | JMP [static] | Indirect jump to absolute memory address |
| 49AC | 5994E0 | .text | JMP [static] | Indirect jump to absolute memory address |
| 49B4 | 599550 | .text | JMP [static] | Indirect jump to absolute memory address |
| 49BC | 5994C4 | .text | JMP [static] | Indirect jump to absolute memory address |
| 49C4 | 599668 | .text | JMP [static] | Indirect jump to absolute memory address |
| 49CC | 59965C | .text | JMP [static] | Indirect jump to absolute memory address |
| 49D4 | 599654 | .text | JMP [static] | Indirect jump to absolute memory address |
| 49DC | 59954C | .text | JMP [static] | Indirect jump to absolute memory address |
| 4A04 | 59B0D8 | .text | JMP [static] | Indirect jump to absolute memory address |
| 4A0C | 599430 | .text | JMP [static] | Indirect jump to absolute memory address |
| 4A14 | 599438 | .text | JMP [static] | Indirect jump to absolute memory address |
| 4A1C | 599558 | .text | JMP [static] | Indirect jump to absolute memory address |
| 4A24 | 59953C | .text | JMP [static] | Indirect jump to absolute memory address |
| 4A2C | 59952C | .text | JMP [static] | Indirect jump to absolute memory address |
| 4A60 | 599508 | .text | JMP [static] | Indirect jump to absolute memory address |
| 4A68 | 599420 | .text | JMP [static] | Indirect jump to absolute memory address |
| 4A70 | 5994D0 | .text | JMP [static] | Indirect jump to absolute memory address |
| 4A78 | 599588 | .text | JMP [static] | Indirect jump to absolute memory address |
| 6478 | 58A778 | .text | CALL [static] | Indirect call to absolute memory address |
| 6490 | 58A76C | .text | CALL [static] | Indirect call to absolute memory address |
| 64AC | 58A770 | .text | CALL [static] | Indirect call to absolute memory address |
| 64CD | 58A774 | .text | CALL [static] | Indirect call to absolute memory address |
| 64E8 | 58A770 | .text | CALL [static] | Indirect call to absolute memory address |
| 6506 | 58A76C | .text | CALL [static] | Indirect call to absolute memory address |
| 6577 | 592028 | .text | CALL [static] | Indirect call to absolute memory address |
| 65B6 | 592010 | .text | CALL [static] | Indirect call to absolute memory address |
| 6C77 | 58A048 | .text | CALL [static] | Indirect call to absolute memory address |
| 6C95 | 58A044 | .text | CALL [static] | Indirect call to absolute memory address |
| 7218 | 59203C | .text | CALL [static] | Indirect call to absolute memory address |
| 76D2 | FFC0 | .text | JMP [static] | Indirect jump to absolute memory address |
| 8B08 | 59201C | .text | CALL [static] | Indirect call to absolute memory address |
| 8B26 | 59201C | .text | CALL [static] | Indirect call to absolute memory address |
| 8B3E | 59201C | .text | CALL [static] | Indirect call to absolute memory address |
| 8BB0 | 59201C | .text | CALL [static] | Indirect call to absolute memory address |
| 8BD0 | 59201C | .text | CALL [static] | Indirect call to absolute memory address |
| 8BED | 59201C | .text | CALL [static] | Indirect call to absolute memory address |
| 8CCA | 592020 | .text | CALL [static] | Indirect call to absolute memory address |
| 8DCF | 592018 | .text | CALL [static] | Indirect call to absolute memory address |
| 8E52 | 592020 | .text | CALL [static] | Indirect call to absolute memory address |
| 8FF2 | 59201C | .text | JMP [static] | Indirect jump to absolute memory address |
| 9178 | 592020 | .text | CALL [static] | Indirect call to absolute memory address |
| 95DF | 592364 | .text | CALL [static] | Indirect call to absolute memory address |
| 975C | 592038 | .text | CALL [static] | Indirect call to absolute memory address |
| 9805 | 58A03C | .text | CALL [static] | Indirect call to absolute memory address |
| 986A | 58A040 | .text | CALL [static] | Indirect call to absolute memory address |
| AFB9 | 58A010 | .text | CALL [static] | Indirect call to absolute memory address |
| B671 | 58A014 | .text | CALL [static] | Indirect call to absolute memory address |
| B758 | 58A018 | .text | CALL [static] | Indirect call to absolute memory address |
| D563 | FF | .text | JMP [static] | Indirect jump to absolute memory address |
| D99F | 594C08 | .text | CALL [static] | Indirect call to absolute memory address |
| D9BC | 594C08 | .text | CALL [static] | Indirect call to absolute memory address |
| D9DD | 594C10 | .text | CALL [static] | Indirect call to absolute memory address |
| DA3B | 594C0C | .text | CALL [static] | Indirect call to absolute memory address |
| DA98 | 594C0C | .text | CALL [static] | Indirect call to absolute memory address |
| DACB | 594C0C | .text | CALL [static] | Indirect call to absolute memory address |
| FF69 | 58A054 | .text | CALL [static] | Indirect call to absolute memory address |
| 10B44 | 599460 | .text | JMP [static] | Indirect jump to absolute memory address |
| Extra Analysis |
| Metric | Value | Percentage |
|---|---|---|
| Ascii Code | 1023881 | 60,3066% |
| Null Byte Code | 326544 | 19,2335% |
| NOP Cave Found | 0x9090909090 | Block Count: 1 | Total: 0,0001% |
© 2026 All rights reserved.