Skip to content

Instantly share code, notes, and snippets.

@adeii
Created September 12, 2024 20:54
Show Gist options
  • Save adeii/199792b9869b27af0294d672eff344f0 to your computer and use it in GitHub Desktop.
Save adeii/199792b9869b27af0294d672eff344f0 to your computer and use it in GitHub Desktop.
Chrome 128.0.6613.132 x86 Win 7
Chrome 128.0.6613.132 32bit
--------------------------
chrome.exe
===========
b8: 06
C0: 06
110-Security Directory RVA / Size --> 00000000
55 89 E5 53 57 56 83 EC 38 89 CB 8B 7D 1C 0F 10 -> 55 89 E5 53 57 56 83 EC 78 89 CB 8B 7D 1C 0F 10
0F 7F 45 D0 C7 45 EC FF FF FF FF 8D 45 EC 8D 4D -> 0F 7F 45 90 C7 45 EC FF FF FF FF 8D 45 EC 8D 4D
D0 50 6A 10 51 FF 73 04 FF 73 10 FF 15 60 54 5A -- 90 50 6A 20 51 FF 73 04 FF 73 10 FF 15 60 54 5A
00 85 C0 0F 84 7C 01 00 00 83 7D EC 10 0F 85 72 -- 00 85 C0 0F 84 7C 01 00 00 83 7D EC 20 0F 85 72
01 00 00 80 7D D0 E9 8B 7D 1C 75 17 8B 45 D1 8B -- 01 00 00 80 7D 90 E9 8B 7D 1C 75 17 8B 45 91 8B
4B 04 29 F8 01 C8 89 45 D1 89 F8 29 C8 83 C0 13 -- 4B 04 29 F8 01 C8 89 45 91 89 F8 29 C8 83 C0 13
89 43 18 0F 10 45 D0 0F 11 06 0F 10 06 0F 11 45 -- 89 43 18 E9 8F 84 14 00 90 90 0F 10 06 0F 11 45
D0 C6 45 D0 B8 8B 46 01 89 45 D1 C6 45 D5 BA 8D -- 90 C6 45 90 B8 8B 46 01 89 45 91 C6 45 95 BA 8D
47 18 89 45 D6 66 C7 45 DA FF E2 8B 43 18 85 C0 -- 47 18 89 45 96 66 C7 45 9A FF E2 8B 43 18 85 C0
74 10 C6 45 D0 E9 89 45 D1 C7 45 C8 05 00 00 00 -- 74 10 C6 45 90 E9 89 45 91 C7 45 C8 05 00 00 00
00 89 F8 83 C4
38 5E 5F 5B 5D C2 20 00 68 44 E2 5A 00 E8 BF A0 -> 78 5E 5F 5B 5D C2 20 00 68 44 E2 5A 00 E8 BF A0
03 00 84 C0 74 53 0F B6 9D 49 FF FF FF 8B 85 4C -> 03 00 90 90 90 90 0F B6 9D 49 FF FF FF 8B 85 4C
59 FF E0 CC CC CC CC CC CC CC CC CC CC CC CC CC -> 59 FF E0 CC CC CC CC 0F 10 45 90 0F 11 06 0F 10
CC CC CC CC CC CC CC CC CC CC CC CC CC CC CC CC -- 45 A0 0F 11 46 10 E9 66 7B EB FF CC CC CC CC CC
b.c.r.y.p.t... -> x.c.r.y.p.t... (hidden) 62 00 63 00 72 00 79 00 70 00 74 00 70 00 -> 78 00 63 00 72 00 79 00 70 00 74 00 70 00 (62->78)
USERENV.dll -> USERENX.dll (hidden)
KERNEL32.dll -> KERNEL64.dll (CFF explorer-Import directory)
-------------------------------------------------------------------------
chrome_proxy.exe
================
b8: 06
C0: 06
110-Security Directory RVA / Size --> 00000000
b.c.r.y.p.t... -> x.c.r.y.p.t... (hidden) 62 00 63 00 72 00 79 00 70 00 74 00 70 00 -> 78 00 63 00 72 00 79 00 70 00 74 00 70 00 (62->78) 620063007200790070
KERNEL32.dll -> KERNEL64.dll
-------------------------------------------------------------------------
chrome_elf.dll
==============
b8: 06
C0: 06
110-Security Directory RVA / Size --> 00000000
b.c.r.y.p.t... -> x.c.r.y.p.t... (hidden) 62 00 63 00 72 00 79 00 70 00 74 00 70 00 -> 78 00 63 00 72 00 79 00 70 00 74 00 70 00 (62->78) x2
KERNEL32.dll -> KERNEL64.dll
-------------------------------------------------------------------------
chrome.dll
==========
b8: 06
C0: 06
110-Security Directory RVA / Size --> 00000000
45 A0 0F 11 46 10 E9 66 7B EB FF CC CC CC CC CC -> 90 90 90 90 90 90 90 90 89 65 D8 89 70 04 8B 07
E9 92 FD FF FF CC CC CC CC CC CC CC CC CC CC CC
55 89 E5 57 56 83 EC 28 A1 40 10 4E 1D 31 E8 89 -- B8 10 00 00 00 C3 90 90 A1 40 10 4E 1D 31 E8 89
00 00 10 6A 01 53 FF 15 00 C3 56 1D 85 C0 74 25 -> 00 00 00 6A 01 53 FF 15 00 C3 56 1D 85 C0 74 25
4D 1D 83 F8 FF 7C 19 40 83 F8 10 77 4F B9 CF 00 -> 4D 1D 83 F8 FF 7C 19 90 90 90 90 90 90 90 90 90
01 00 0F A3 C1 73 45 6A FE 56 FF 15 0C 70 4D 1D -- 90 90 90 90 90 90 90 6A FE 56 FF 15 0C 70 4D 1D
85 C0 74 09 FF 76 10 FF 15 44 6B 4D 1D 85 DB 0F -> 85 C0 74 09 FF 76 10 FF 15 44 6B 4D 1D 90 90 90
94 C0 83 3E 00 0F 95 C1 30 C1 0F 84 E1 00 00 00 -- 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90
58 01 84 C0 74 53 0F B6 9D 49 FF FF FF 8B 85 4C -> 58 01 90 90 90 90 0F B6 9D 49 FF FF FF 8B 85 4C
00 00 B9 00
09 00 00 0F 49 C8 89 8D 48 FF FF FF 8D 75 08 0F -> 00 00 00 0F 49 C8 89 8D 48 FF FF FF 8D 75 08 0F
1D 31 E8 89 45 F0 8B 45 08 F7 45 28 40 00 20 00 -> 1D 31 E8 89 45 F0 8B 45 08 90 90 90 90 90 90 90
74 0A 83 7F 34 00 0F 84 77 01 00 00 8D 75 38 89 -- 90 90 90 90 90 90 90 90 90 90 90 90 8D 75 38 89
C3 41 1B 9A BB D3 6A 46 87 FC FE 67 55 6A 3B 65 -> 5A EE 59 B8 38 D8 5B 4B A2 E8 1A DC 7D 93 DB 48
b.c.r.y.p.t... -> x.c.r.y.p.t... (hidden) 62 00 63 00 72 00 79 00 70 00 74 00 -> 78 00 63 00 72 00 79 00 70 00 74 00 (62->78)
b.c.r.y.p.t... -> x.c.r.y.p.t... (hidden)
user32.dll -> user64.dll (hidden)
mfplat.dll -> xfplat.dll (hidden)
netapi32.dll -> netapi64.dll (hidden)
bcryptprimitives.dll -> xcryptprimitives.dll (hidden)
kernel32.dll -> kernel64.dll
userenv.dll -> userenx.dll
winhttp.dll -> winxttp.dll
-------------------------------------------------------------------------
notification_helper.exe
=======================
b8: 06
C0: 06
110-Security Directory RVA / Size --> 00000000
b.c.r.y.p.t... -> x.c.r.y.p.t... (hidden) 62 00 63 00 72 00 79 00 70 00 74 00 70 00 -> 78 00 63 00 72 00 79 00 70 00 74 00 70 00 (62->78) x2
KERNEL32.dll -> KERNEL64.dll
-------------------------------------------------------------------------
mojo_core.dll
=============
b8: 06
C0: 06
110-Security Directory RVA / Size --> 00000000
b.c.r.y.p.t... -> x.c.r.y.p.t... (hidden) 62 00 63 00 72 00 79 00 70 00 74 00 70 00 -> 78 00 63 00 72 00 79 00 70 00 74 00 70 00 (62->78) x2
KERNEL32.dll -> KERNEL64.dll
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment