Skip to content

Instantly share code, notes, and snippets.

@adeii
Last active April 1, 2025 20:32
Show Gist options
  • Save adeii/b2d1015ab08a14e2fb75beafc3616ff5 to your computer and use it in GitHub Desktop.
Save adeii/b2d1015ab08a14e2fb75beafc3616ff5 to your computer and use it in GitHub Desktop.
Chrome 134 x86
THROME 134.0.6998.178 x86 (trom = sluggish)
-------------------------
chrome.exe
===========
b8: 06
C0: 06
110-Security Directory RVA / Size --> 00000000
55 89 E5 53 57 56 83 EC 18 89 D6 89 CF A1 40 E0 -- 55 89 E5 53 57 56 83 EC 78 89 D6 89 CF A1 40 E0
5C 00 31 E8 89 45 F0 66 0F 76 C0 8D 45 E0 F3 0F -- 5C 00 31 E8 89 45 F0 66 0F 76 C0 8D 45 A0 F3 0F
7F 00 8D 5D DC C7 03 FF FF FF FF 53 6A 10 50 FF -- 7F 00 8D 5D DC C7 03 FF FF FF FF 53 6A 20 50 FF
..
83 3B 10 0F 94 C3 20 C3 80 FB 01 75 27 80 7D E0 -- 83 3B 20 0F 94 C3 20 C3 80 FB 01 75 27 80 7D A0
..
89 4D E1 29 D0 83 C0 13 89 47 18 F3 0F 6F 45 E0 -- 89 4D E1 29 D0 83 C0 13 89 47 18 E9 67 F9 06 00
..
83 C4 18 5E 5F 5B 5D C3 CC CC CC CC CC CC CC CC -- 83 C4 78 5E 5F 5B 5D C3 CC CC CC CC CC CC CC CC
F9 E8 0A 2A 01 00 8D 8D 44 FF FF FF 84 C0 74 0A -- F9 E8 0A 2A 01 00 8D 8D 44 FF FF FF 90 90 90 90
5C 00 E8 4B FF F5 FF 5A 59 FF E0 CC CC CC CC CC
CC CC CC CC CC CC CC CC CC CC CC CC CC CC CC CC
CC CC CC CC CC CC CC CC CC CC CC CC CC CC CC CC
CC CC CC CC CC CC CC CC CC CC CC CC CC CC CC CC --
5C 00 E8 4B FF F5 FF 5A 59 FF E0 CC CC CC CC CC
CC CC CC CC CC CC CC CC CC CC CC CC CC CC CC CC
CC CC CC CC CC CC CC F3 0F 6F 45 A0 F3 0F 7F 06
F3 0F 6F 45 B0 F3 0F 7F 46 10 E9 85 06 F9 FF CC
b.c.r.y.p.t... -> x.c.r.y.p.t... (hidden) 62 00 63 00 72 00 79 00 70 00 74 00 70 00 -> 78 00 63 00 72 00 79 00 70 00 74 00 70 00 (62->78)
USERENV.dll -> USERENX.dll (hidden, optional)
KERNEL32.dll -> KERNEL64.dll (CFF explorer-Import directory)
-------------------------------------------------------------------------
chrome_proxy.exe
================
b8: 06
C0: 06
110-Security Directory RVA / Size --> 00000000
b.c.r.y.p.t... -> x.c.r.y.p.t... (hidden)
62 00 63 00 72 00 79 00 70 00 74 00 70 00 -> 78 00 63 00 72 00 79 00 70 00 74 00 70 00
(62->78) 620063007200790070
KERNEL32.dll -> KERNEL64.dll
-------------------------------------------------------------------------
chrome_elf.dll
==============
b8: 06
C0: 06
110-Security Directory RVA / Size --> 00000000
b.c.r.y.p.t... -> x.c.r.y.p.t... (hidden)
62 00 63 00 72 00 79 00 70 00 74 00 -> 78 00 63 00 72 00 79 00 70 00 74 00 (62->78) x2
KERNEL32.dll -> KERNEL64.dll
-------------------------------------------------------------------------
chrome.dll
==========
b8: 06
C0: 06
110-Security Directory RVA / Size --> 00000000
FF 7C 93 40 83 F8 10 77 11 B9 CF 00 01 00 0F A3 C1 73 07 6A FE E9 75 FF FF FF CC 0F 0B CC CC CC --
FF 7C 93 40 83 F8 10 77 11 B9 CF 00 01 00 0F A3 C1 90 90 6A FE E9 75 FF FF FF CC 0F 0B CC CC CC
E8 CB 10 00 00 89 85 20 FF FF FF 83 C0 F9 83 F8 06 73 2E 83 85 20 FF FF FF FA 31 DB E9 B0 FC FF --
E8 CB 10 00 00 89 85 20 FF FF FF 83 C0 F9 83 F8 06 90 90 83 85 20 FF FF FF FA 31 DB E9 B0 FC FF
E8 8B E0 9F 06 84 C0 0F 85 78 F8 FF FF CC 0F 0B -- E8 8B E0 9F 06 84 C0 E9 79 F8 FF FF 90 CC 0F 0B
00 31 C0 40 50 53 68 0F 00 00 10 50 FF 75 D8 FF -- 00 31 C0 40 50 53 68 0F 00 00 00 50 FF 75 D8 FF
80 7E 0C 00 0F 85 EF 07 00 00 C7 46 34 00 00 00 -- 80 7E 0C 00 90 90 90 90 90 90 C7 46 34 00 00 00
C4 04 84 C0 B8 02 08 00 00 B9 00 09 00 00 0F 45 -- C4 04 84 C0 B8 02 08 00 00 B9 00 00 00 00 0F 45
1C 31 E8 89 45 F0 8B 07 F7 47 20 40 00 10 00 0F 85 30 01 00 00 8D 5D 3C 89 45 D4 C7 00 FF FF FF --
1C 31 E8 89 45 F0 8B 07 90 90 90 90 90 90 90 90 90 90 90 90 90 8D 5D 3C 89 45 D4 C7 00 FF FF FF
E6 E1 06 EB E3 83 7F 38 00 0F 85 C6 FE FF FF CC -- E6 E1 06 EB E3 83 7F 38 00 E9 C7 FE FF FF 90 CC
F4 EB 41 1C FF 15
FF FF E8 59 C4 94 05 EB F1 CC CC CC CC CC CC CC 55 89 E5 53 57 56 50 6A 10 E8 1F BF 7A 02 83 C4 --
FF FF E8 59 C4 94 05 EB F1 CC CC CC CC CC CC CC 31 C0 C3 53 57 56 50 6A 10 E8 1F BF 7A 02 83 C4
04 89 C6 83 C0 0D
74 24 20 FF 15 38 66 34 1C 85 F6 0F 94 C0 83 7C 24 04 00 0F 95 C1 30 C1 0F 84 A9 01 00 00 89 64 --
74 24 20 FF 15 38 66 34 1C 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 89 64
24 04 8D 45
00 00 83 FF
0F 88 5F 03 00 00 84 D2 74 2E B9 A8 01 00 00 03 -- 0F 88 5F 03 00 00 84 D2 EB 2E B9 A8 01 00 00 03
0E 52 50 6A
8B 00 E9 93 FC FF FF 50 E8 E3 59 A3 FC 83 C4 04 -- 8B 00 E9 AA FC FF FF 50 E8 E3 59 A3 FC 83 C4 04
83 B9 48 02 00 00 00 74 F2 8B 06 85 C0 74 19 8A -- 83 B9 48 02 00 00 00 74 F2 8B 06 85 C0 90 90 8A
40 04 84 C0 75 12 8B 89 48 02 00 00 E8 8F 46 35 -- 40 04 84 C0 90 90 8B 89 48 02 00 00 E8 8F 46 35
FF 84 C0 74 D6 CC 0F 0B CC 0F 0B CC CC CC CC CC -- FF 84 C0 EB D6 CC 0F 0B CC 0F 0B CC CC CC CC CC
7F F9 8B 47 04 8B 3B 85 FF 0F 94 C1 0A 48 24 75 46 8D 7D E0 89 F9 68 39 68 6D 1B E8 C0 B9 EC FB --
7F F9 8B 47 04 8B 3B 85 FF 0F 94 C1 0A 48 24 EB 46 8D 7D E0 89 F9 68 39 68 6D 1B E8 C0 B9 EC FB
F9 E8 DA A5 D9 00 8D 8D 44 FF FF FF 84 C0 74 0A -- F9 E8 DA A5 D9 00 8D 8D 44 FF FF FF 90 90 90 90
E0 34 1C 31 E8 89 44 24 28 E8 72 7A B6 00 83 F8 02 0F 85 29 01 00 00 8D 7C 24 24 C7 07 04 00 00 --
E0 34 1C 31 E8 89 44 24 28 E8 72 7A B6 00 90 90 90 90 90 90 90 90 90 8D 7C 24 24 C7 07 04 00 00
.. (x7)
83 F8 02 0F 85 AD 00 00 00 89 F1 BA FF FF 00 80 -- 90 90 90 90 90 90 90 90 90 89 F1 BA FF FF 00 80
EB D1 E8 D9 79 B6 00 83 F8 02 0F 85 99 00 00 00 -- EB D1 E8 D9 79 B6 00 90 90 90 90 90 90 90 90 90
00 CC CC CC CC CC CC CC CC CC CC CC CC CC CC CC 55 89 E5 53 57 56 83 E4 F8 81 EC C0 00 00 00 89 --
00 CC CC CC CC CC CC CC CC CC CC CC CC CC CC CC 31 C0 C2 04 00 56 83 E4 F8 81 EC C0 00 00 00 89
CE A1 40 E0 34
3C 78 B6 00 83 F8 02 0F 85 3C 01 00 00 8B 7D 08 -- 3C 78 B6 00 90 90 90 90 90 90 90 90 90 8B 7D 08
34 1C 31 E8 89 45 F0 E8 D4 76 B6 00 83 F8 02 0F 85 2B 01 00 00 89 75 C8 8B 77 48 85 F6 74 15 C7 --
34 1C 31 E8 89 45 F0 E8 D4 76 B6 00 90 90 90 90 90 90 90 90 90 89 75 C8 8B 77 48 85 F6 74 15 C7
01 00 00 E8 68 75 B6 00 83 F8 02 0F 85 9A 03 00 00 31 C0 48 8D BC 24 30 01 00 00 89 47 04 89 07 --
01 00 00 E8 68 75 B6 00 90 90 90 90 90 90 90 90 90 31 C0 48 8D BC 24 30 01 00 00 89 47 04 89 07
34 1C 31 E8 89 45 F0 E8 94 71 B6 00 83 F8 02 0F 85 D3 00 00 00 89 D9 E8 E4 06 00 00 8D 55 EC C7 --
34 1C 31 E8 89 45 F0 E8 94 71 B6 00 90 90 90 90 90 90 90 90 90 89 D9 E8 E4 06 00 00 8D 55 EC C7
55 89 E5 56 89 CE E8 A5 70 B6 00 83 F8 02 75 12 89 F1 E8 A9 03 00 00 89 F1 89 C2 5E 5D E9 FE FA --
55 89 E5 56 89 CE E8 A5 70 B6 00 90 90 90 90 90 89 F1 E8 A9 03 00 00 89 F1 89 C2 5E 5D E9 FE FA
E8 89 45 F4 E8 67 70 B6 00 83 F8 02 75 37 8D 55 -- E8 89 45 F4 E8 67 70 B6 00 90 90 90 90 90 8D 55
.. (x5)
55 89 E5 53 56 89 CE E8 14 70 B6 00 83 F8 02 75 -- 55 89 E5 53 56 89 CE E8 14 70 B6 00 90 90 90 90
21 89 F1 E8 F8 04 00 00 89 C3 84 C0 75 06 89 D8 -- 90 89 F1 E8 F8 04 00 00 89 C3 84 C0 75 06 89 D8
.. (x4)
E8 89 45 F4 E8 C7 6F B6 00 83 F8 02 75 69 8D 55 -- E8 89 45 F4 E8 C7 6F B6 00 90 90 90 90 90 8D 55
E0 34 1C 31 E8 89 44 24 38 E8 32 6F B6 00 83 F8 02 0F 85 16 01 00 00 8D 5C 24 20 53 E8 AF BF B9 --
E0 34 1C 31 E8 89 44 24 38 E8 32 6F B6 00 90 90 90 90 90 90 90 90 90 8D 5C 24 20 53 E8 AF BF B9
E0 34 1C 31 E8 89 44 24 48 E8 D2 6C B6 00 83 F8 02 0F 85 10 01 00 00 8B 7E 4C 8B 07 8B 48 24 FF --
E0 34 1C 31 E8 89 44 24 48 E8 D2 6C B6 00 90 90 90 90 90 90 90 90 90 8B 7E 4C 8B 07 8B 48 24 FF
E0 34 1C 31 E8 89 44 24 08 E8 F2 6A B6 00 83 F8 02 75 44 89 E7 57 E8 75 BB B9 FA 83 C4 04 8B 46 --
E0 34 1C 31 E8 89 44 24 08 E8 F2 6A B6 00 90 90 90 90 90 89 E7 57 E8 75 BB B9 FA 83 C4 04 8B 46
E0 34 1C 31 E8 89 44 24 20 E8 82 6A B6 00 83 F8 02 0F 85 AD 00 00 00 89 34 24 83 7E 48 00 0F 84 --
E0 34 1C 31 E8 89 44 24 20 E8 82 6A B6 00 90 90 90 90 90 90 90 90 90 89 34 24 83 7E 48 00 0F 84
34 1C 31 E8 89 45 F0 E8 A4 69 B6 00 83 F8 02 0F 85 4C 01 00 00 89 75 C8 8B 77 48 85 F6 0F 84 41 --
34 1C 31 E8 89 45 F0 E8 A4 69 B6 00 90 90 90 90 90 90 90 90 90 89 75 C8 8B 77 48 85 F6 0F 84 41
34 1C 31 E8 89 45 F0 E8 24 68 B6 00 83 F8 02 0F 85 1D 01 00 00 31 DB 8D 45 D4 89 18 89 58 04 89 --
34 1C 31 E8 89 45 F0 E8 24 68 B6 00 90 90 90 90 90 90 90 90 90 31 DB 8D 45 D4 89 18 89 58 04 89
40 E0 34 1C 31 E8 89 45 F0 E8 72 65 B6 00 83 F8 02 0F 85 CB 01 00 00 31 C0 48 8D 75 E4 89 06 89 --
40 E0 34 1C 31 E8 89 45 F0 E8 72 65 B6 00 90 90 90 90 90 90 90 90 90 31 C0 48 8D 75 E4 89 06 89
C3 41 1B 9A BB D3 6A 46 87 FC FE 67 55 6A 3B 65 -> 5A EE 59 B8 38 D8 5B 4B A2 E8 1A DC 7D 93 DB 48
X-Client-Data --> MRK-PRC-GUGL (x2)
b.c.r.y.p.t... -> x.c.r.y.p.t... (hidden) 62 00 63 00 72 00 79 00 70 00 74 00 -> 78 00 63 00 72 00 79 00 70 00 74 00 (62->78)
b.c.r.y.p.t... -> x.c.r.y.p.t... (hidden)
bcryptprimitives.dll -> xcryptprimitives.dll (hidden)
user32.dll -> user64.dll (hidden)
mfplat.dll -> xfplat.dll (hidden)
netapi32.dll -> netapi64.dll (hidden)
kernel32.dll -> kernel64.dll
userenv.dll -> userenx.dll
winhttp.dll -> winxttp.dll
-------------------------------------------------------------------------
chrome_wer.exe
=======================
B8- Major Subsystem --> 06
C0- Major Subsystem --> 06
110-Security Directory RVA / Size --> 00000000
-------------------------------------------------------------------------
chrome_pwa_launcher.exe
=======================
B8- Major Subsystem --> 06
C0- Major Subsystem --> 06
110-Security Directory RVA / Size --> 00000000
b.c.r.y.p.t... -> x.c.r.y.p.t... (hidden)
62 00 63 00 72 00 79 00 70 00 74 00 70 00 -> 78 00 63 00 72 00 79 00 70 00 74 00 70 00 (62->78)
KERNEL32.dll -> KERNEL64.dll
-------------------------------------------------------------------------
notification_helper.exe
=======================
b8: 06
C0: 06
110-Security Directory RVA / Size --> 00000000
b.c.r.y.p.t... -> x.c.r.y.p.t... (hidden)
62 00 63 00 72 00 79 00 70 00 74 00 70 00 -> 78 00 63 00 72 00 79 00 70 00 74 00 70 00 (62->78) x2
KERNEL32.dll -> KERNEL64.dll
-------------------------------------------------------------------------
widevinecdm.dll
===============
b8: 06
C0: 06
110-Security Directory RVA / Size --> 00000000
b.c.r.y.p.t... -> x.c.r.y.p.t... (hidden)
62 00 63 00 72 00 79 00 70 00 74 00 70 00 -> 78 00 63 00 72 00 79 00 70 00 74 00 70 00 (62->78) x2
KERNEL32.dll -> KERNEL64.dll
-----------------------------------------------------------------
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment