Malware Family Analysis • Windows

Qakbot Unpacking: Bypassing Multi-Layer Obfuscation & Resource Decryption

Trace Qakbot unpacking routines to bypass multi-layer code obfuscation, decrypt embedded PE resources, and recover the core banking trojan payload.

Qbot (also known as QakBot or QuackBot) is indeed a, persistent, and highly sophisticated banking trojan that has been consistently packed or packed in a new layer of obfuscation for many years to evade detection by security software

It is considered a "Swiss Army knife" for threat actors, operating not only as a banking trojan to steal credentials but also as a malware loader for ransomware

Sample: https://malshare.com/sample.php?action=detail&hash=112a64190b9a0f356880eebf05e195f4c16407032bf89fa843fd136da6f5d515

File Identification

Sections

IndexNameSHA-256 HashEntropyFile RatioRaw Size (Bytes)Virtual Size (Bytes)Raw Address (Begin)Virtual Address
0.text
0917EF1437D686D73C90CE2823E761224AFF706BC2AFCF50FC14070A4AE5AB35
5.5172.99 %82,43282,0580x000004000x00001000
1.rdata
CA63C02CAA8C0248F3F6A8291F23B0C2F64A6B933F9E7C99DF7E4B62762A7480
3.2130.02 %5122630x000146000x00016000
2.data
126425A525E41E910B9358492365743A2330C7F260247AEA3F906E09B298490F
5.5800.41 %11,26411,3000x000148000x00017000
3a2
AF3AB617E13B364CA364C8A8192346E14E55A2271662E409424DBB415B1798B3
0.1390.02 %512100x000174000x0001A000
4a3
0F2F59AFFEEC6B89C23DFF01782CBE898B57D866326E828C5952104BAD4BEB5C
1.15789.96 %2,478,5922,478,2940x000176000x0001B000
5a32
60AE7E06BA7EA296D2D0A11FD046BA9098E1673CCBB76B81C7E72752B4100862
4.8450.04 %1,0241,0100x002748000x00279000
6a322
B76B11A36D44B4C17175B5AE7E018B975E79F7B02EEB6E44B4F143316343A33A
5.4744.61 %126,976126,8430x00274C000x0027A000
7.rsrc
597AB4CED962CE1851893DF4A910C0F2A54D7A0034166CBF1006CA9153966D6C
3.6321.88 %51,71251,4160x00293C000x00299000

Key Observations

▪Space Efficiency: The file has a total raw size of approximately 2.63 MB, of which 2.36 MB belongs solely to the a3 section.
▪Entropy Alert: Section a3 shows extremely low entropy (1.157), indicating it is almost entirely redundant data (null bytes or repetitive padding), effectively "bloating" the file size.
▪Non-Standard PE Layout: The sequential naming of a2 through a322 is a strong indicator of a custom packer or an obfuscation layer designed to make manual analysis more difficult.

Imports

Library (DLL)Function NameBindingLocation (VA)
KERNEL32.dllSleepImplicit0x000188F8
GetLastErrorImplicit0x00018900
GetModuleHandleWImplicit0x00018910
LoadLibraryAImplicit0x00018924
GetProcAddressImplicit0x00018934
CreateMutexAImplicit0x00018946
VirtualAllocImplicit0x00018A8E
WriteFileImplicit0x00018AAC
WinExecImplicit0x000190EE
CreateThreadImplicit0x00018E26
USER32.dllGetKeyStateImplicit0x000193D4
GetAsyncKeyStateImplicit0x000194B2
BlockInputImplicit0x00019450
wsprintfWImplicit0x00019530
SendMessageWImplicit0x0001953C
ADVAPI32.dllRegOpenKeyExWImplicit0x000198E6
RegSetValueExWImplicit0x000199E0
CryptAcquireContextAImplicit0x0001994C
CryptGenRandomImplicit0x0001999A
CryptHashDataImplicit0x00019A68
GDI32.dllCreateSolidBrushImplicit0x00019664
DeleteObjectImplicit0x000196F6
GetDeviceCapsImplicit0x0001985C
SHELL32.dllShellExecuteWImplicit0x00019B28
SHCreateProcessAsUserWImplicit0x00019AF8
SHLWAPI.dllPathFindFileNameWImplicit0x00019B92
PathCombineWImplicit0x00019BBC
ole32.dllCoTaskMemFreeImplicit0x00019B66
Library (DLL)BindingImport CountDescription
KERNEL32.dllImplicit146Windows NT BASE API Client
USER32.dllImplicit40Multi-User Windows USER API Client Library
GDI32.dllImplicit37GDI Client Library
ADVAPI32.dllImplicit33Advanced Windows 32 Base API
SHELL32.dllImplicit6Windows Shell Library
SHLWAPI.dllImplicit3Shell Light-weight Utility Library
ole32.dllImplicit2Microsoft OLE for Windows

Analysis of Imports

Based on these specific function calls, the file possesses several notable capabilities:

▪Execution & Persistence: The presence of WinExec, CreateThread, and ShellExecuteW indicates the ability to launch other processes or run code in parallel.
▪System Interference: BlockInput (USER32) is a sensitive function often used by malware or utility tools to prevent the user from using their keyboard or mouse.
▪Cryptography: The ADVAPI32 imports (CryptHashData, CryptGenRandom) show the binary can generate or verify encrypted data and hashes.
▪File/Registry Activity: Extensive use of RegOpenKeyExW and WriteFile suggests it can modify system settings and drop files to the disk.
▪Core Logic (KERNEL32): With 146 imports, the bulk of the program's activity involves low-level system operations like memory management, file I/O, and process handling.
▪User Interface (USER32 & GDI32): The 77 combined imports from these libraries indicate a graphical component, likely involving window management, drawing, and capturing user input.
▪Privileged Operations (ADVAPI32): 33 imports here suggest significant interaction with the Windows Registry, service management, or cryptographic providers.
▪Shell Integration: The inclusion of SHELL32 and SHLWAPI suggests the program interacts with the Windows Explorer shell, likely for path manipulation or executing commands with higher-level shell functions.

X32-DBG

load the sample in x32dbg hit f9 to get into user space. ctrl + g go to VirtualAlloc

Screenshot 2026-01-30 at 11.22.20 AM.png
Figure: Screenshot 2026-01-30 at 11.22.20 AM.png Click to zoom ↗
Screenshot 2026-01-30 at 11.24.58 AM.png
Figure: Screenshot 2026-01-30 at 11.24.58 AM.png Click to zoom ↗

Set breakpoint, hit f9 until hit this breakpoint.

Screenshot 2026-01-30 at 11.25.39 AM.png
Figure: Screenshot 2026-01-30 at 11.25.39 AM.png Click to zoom ↗

Then ctrl + f9 then f8 to get back to userspcae.

Screenshot 2026-01-30 at 11.41.19 AM.png
Figure: Screenshot 2026-01-30 at 11.41.19 AM.png Click to zoom ↗

In hexdump ctrl + g follow eax.

Screenshot 2026-01-30 at 11.48.01 AM.png
Figure: Screenshot 2026-01-30 at 11.48.01 AM.png Click to zoom ↗

Set breakpoint.

Screenshot 2026-01-30 at 11.49.54 AM.png
Figure: Screenshot 2026-01-30 at 11.49.54 AM.png Click to zoom ↗

hit f9 we can see first byte 8F in the memory dump.

Screenshot 2026-01-30 at 11.51.29 AM.png
Figure: Screenshot 2026-01-30 at 11.51.29 AM.png Click to zoom ↗

then hit f9 couple of times 7times we got this.

Screenshot 2026-01-30 at 11.54.42 AM.png
Figure: Screenshot 2026-01-30 at 11.54.42 AM.png Click to zoom ↗

looks like an api lists.

Screenshot 2026-01-30 at 11.56.09 AM.png
Figure: Screenshot 2026-01-30 at 11.56.09 AM.png Click to zoom ↗

I restarted the program disable VirtualAlloc breakpoint.

Screenshot 2026-01-30 at 12.00.28 PM.png
Figure: Screenshot 2026-01-30 at 12.00.28 PM.png Click to zoom ↗

Inside VirtuallAlloc set Breakpoint, So Kernel32 Virtually calls Kernelbase Alloc

Screenshot 2026-01-30 at 12.02.42 PM.png
Figure: Screenshot 2026-01-30 at 12.02.42 PM.png Click to zoom ↗

F9hit the break point

Screenshot 2026-01-30 at 12.14.08 PM.png
Figure: Screenshot 2026-01-30 at 12.14.08 PM.png Click to zoom ↗

hit ctrl + F9 and F8 .

Then in memory dump ctrl + g Follow EAX.

Screenshot 2026-01-30 at 12.15.52 PM.png
Figure: Screenshot 2026-01-30 at 12.15.52 PM.png Click to zoom ↗

Set break point

Screenshot 2026-01-30 at 12.16.47 PM.png
Figure: Screenshot 2026-01-30 at 12.16.47 PM.png Click to zoom ↗

As before hit f9 we see first byte 8F

Screenshot 2026-01-30 at 12.17.43 PM.png
Figure: Screenshot 2026-01-30 at 12.17.43 PM.png Click to zoom ↗

now hit F9 until you see clear text in memory dump or a virtualAlloc

Screenshot 2026-01-30 at 12.36.04 PM.png
Figure: Screenshot 2026-01-30 at 12.36.04 PM.png Click to zoom ↗

then ctrl + f9 then f8 .

in Memory dump2 Follow EAX set hardware breakpoint. hit f9 we can see the first byte

Screenshot 2026-01-30 at 12.38.47 PM.png
Figure: Screenshot 2026-01-30 at 12.38.47 PM.png Click to zoom ↗

Continue hitting f9 four times.

We get the MZ header

Screenshot 2026-01-30 at 12.40.53 PM.png
Figure: Screenshot 2026-01-30 at 12.40.53 PM.png Click to zoom ↗

scrolling a bit after mz header end of the header the first section starts from 400 hex.

Screenshot 2026-01-30 at 12.47.25 PM.png
Figure: Screenshot 2026-01-30 at 12.47.25 PM.png Click to zoom ↗

We can Verify it .text section begins with 400

Screenshot 2026-01-30 at 12.58.49 PM.png
Figure: Screenshot 2026-01-30 at 12.58.49 PM.png Click to zoom ↗

Dump Memory

Screenshot 2026-01-30 at 1.05.49 PM.png
Figure: Screenshot 2026-01-30 at 1.05.49 PM.png Click to zoom ↗

Now Some calculations

Open new dump file in any pe analyzer tool.

Screenshot 2026-01-30 at 2.39.29 PM.png
Figure: Screenshot 2026-01-30 at 2.39.29 PM.png Click to zoom ↗

Let’s focus on .reloc end section of the binary.

Fileoffset + Size 35400 + C00 = 36000

Screenshot 2026-01-30 at 2.50.33 PM.png
Figure: Screenshot 2026-01-30 at 2.50.33 PM.png Click to zoom ↗

We can verify offset 36000 it’s point to the end of the file.

Screenshot 2026-01-30 at 2.57.38 PM.png
Figure: Screenshot 2026-01-30 at 2.57.38 PM.png Click to zoom ↗

So we don’t need any cleanup.

qakbot023B0000.bin

Basic properties

PE section

IndexNameEntropyFile RatioRaw SizeVirtual SizeRaw Address (Begin)Virtual Address
0.text6.38617.82 %39,42439,3700x000004000x00001000
1.rdata7.5159.26 %20,48020,0720x00009E000x0000B000
2.data4.3900.69 %1,53610,1320x0000EE000x00010000
3.rsrc7.86370.37 %155,648155,6120x0000F4000x00013000
4.reloc5.4751.39 %3,0722,6780x000354000x00039000

Key Observations for the Decrypted File

▪Resource Dominance: The .rsrc section now accounts for over 70% of the file. Its extremely high entropy (7.863) suggests it contains compressed data, encrypted payloads, or high-resolution media.
▪Normalized Naming: Unlike the encrypted version (which used non-standard names like a2, a3), this file uses standard Microsoft compiler section names (.text, .rdata, etc.), confirming a successful "unpacking" or "decryption."
▪Data Expansion: In section [2] (.data), the virtual size (10,132 bytes) is significantly larger than the raw size (1,536 bytes). This is typical for uninitialized data or variables that expand in memory once the program is loaded.
▪Code Complexity: The .text section (where the executable code resides) has an entropy of 6.386, which is standard for a compiled C++ application.

Decrypted Import Address Table Imports

Library (DLL)Functions
KERNEL32.dllGetLastError, GetProcAddress, LoadLibraryA, lstrcmpiW, GetModuleHandleA, CloseHandle, GetCurrentProcessId, GetEnvironmentVariableW, lstrlenA, WideCharToMultiByte, lstrcatA, GetEnvironmentVariableA, MultiByteToWideChar, lstrlenW, lstrcatW, lstrcpyA, HeapAlloc, HeapFree, HeapCreate, VirtualAlloc, GetFileSize, lstrcmpiA, GetModuleFileNameA, GetThreadContext, GetCurrentProcess, CreateEventA, LoadLibraryW, TerminateProcess, DeleteFileW, ResumeThread, ExpandEnvironmentStringsW, GetComputerNameW, GetVolumeInformationW, ReleaseMutex, GetExitCodeProcess, GetSystemTimeAsFileTime, SetEnvironmentVariableW, GetTickCount, GetModuleFileNameW, GetSystemInfo, SetEnvironmentVariableA, GetVersionExA, GetWindowsDirectoryW, SetEvent, OpenEventA, CopyFileW, TerminateThread, CreateThread, GetFileAttributesA, GetFileAttributesW, GetCurrentThread, LocalAlloc, GetLocalTime, LocalFree, lstrcpyW, CreateDirectoryW, SleepEx, WaitForSingleObject, FreeLibrary, GetDriveTypeW, lstrcmpA, GetCommandLineW, ExitProcess, lstrcpynW, Sleep, SystemTimeToFileTime, GetSystemTime, GetModuleHandleW, CreateMutexA
ADVAPI32.dllRegOpenKeyExW, RegEnumValueW, RegDeleteValueW, RegQueryInfoKeyW, LookupAccountNameW, EqualSid, SetServiceStatus, RegUnLoadKeyW, RegLoadKeyW, ConvertSidToStringSidW, RegSetValueExW, RegQueryValueExW, SetSecurityDescriptorDacl, InitializeSecurityDescriptor, GetTokenInformation, RegisterServiceCtrlHandlerA, StartServiceCtrlDispatcherA, RegCloseKey, SetFileSecurityW, OpenProcessToken, GetSidSubAuthority, OpenThreadToken, GetSidSubAuthorityCount, LookupAccountSidW, CreateProcessAsUserW
USER32.dllCharUpperBuffA, MessageBoxA, GetClassNameA, CharUpperBuffW
SHELL32.dllSHGetFolderPathW, CommandLineToArgvW, ShellExecuteW
ole32.dllCoInitialize, CoInitializeEx, CoInitializeSecurity, CoSetProxyBlanket, CoUninitialize, CoCreateInstance
NETAPI32.dllNetApiBufferFree, NetUserEnum, NetGetDCName
SETUPAPI.dllSetupDiEnumDeviceInfo, SetupDiDestroyDeviceInfoList, SetupDiGetClassDevsA, SetupDiGetDeviceRegistryPropertyA
msvcrt.dll_vsnprintf, _ltoa, _except_handler3, memset, _vsnwprintf, memcpy
USERENV.dllGetUserProfileDirectoryW

Critical Behavioral Indicators

Analyzing these specific imports reveals the binary's core capabilities:

▪Process Hollowing/Injection: The combination of GetThreadContext, VirtualAlloc, and ResumeThread is a classic signature for process hollowing, where the binary injects code into a suspended legitimate process.
▪Privilege Escalation & Identity: Imports like OpenProcessToken, GetTokenInformation, and CreateProcessAsUserW suggest the ability to manipulate user tokens or run tasks with administrative/SYSTEM privileges.
▪Network Enumeration: NetUserEnum and NetGetDCName indicate that the file is designed to query domain controllers and list users on a network, common in reconnaissance phases.
▪Persistence: StartServiceCtrlDispatcherA and SetServiceStatus show the binary can operate as a Windows Service, allowing it to start automatically with the OS.
▪Hardware Profiling: The SETUPAPI.dll imports suggest it is looking for specific hardware or drivers, possibly for environment keying or anti-VM checks.

Sample 2

Sample: https://malshare.com/sample.php?action=detail&hash=1042f400ed776bc5d2c68becb386fb2ef3116417f96a67c14e8ca5b421ae7bc9

PE section

IndexNameSHA-256 (Full)EntropyFile RatioRaw Size (Bytes)Virtual SizeCharacteristics
0.text
4EB5A21D4AA7DE4C2FCF4124FF224378F597DAF0B205E2F2680757BC46D74AA3
7.23880.11%531,968531,865Execute, Read
1.rdata4
1E8428ACD7003A0DF93471CE69B1CFD9A4A50D6D148AB95AB5E0E16C0FE14FB7
5.9030.08%512483Read
2.rdata3
1E8428ACD7003A0DF93471CE69B1CFD9A4A50D6D148AB95AB5E0E16C0FE14FB7
5.9030.08%512483Read
3.rdata2
1E8428ACD7003A0DF93471CE69B1CFD9A4A50D6D148AB95AB5E0E16C0FE14FB7
5.9030.08%512483Read
4.rdata
B17141BD9DEB3C6FBA87E5CE806D4CC11A98F8A5A4CB699296D4EBA8E608ADA2
3.3780.08%512280Read
5.data
57EA9046FE23666E1C9AA5C428B274D4F340B0D8FE6411D788E0ED570744E5D7
5.51318.58%123,392123,396Read, Write
6.rdata5
1E8428ACD7003A0DF93471CE69B1CFD9A4A50D6D148AB95AB5E0E16C0FE14FB7
5.9030.08%512483Read, Write, Exec*
7.rsrc
716AEBF3D58674C078A9F93F3A5D020AB0E7D33A072DBCDEC0E43A9C4C2F7ED7
5.9030.62%4,0963,824Read

Memory and Execution offsets

ItemValueSection Association
Entry Point0x00082630Falls outside standard .text mapping
Base of Code0x00001000.text
Base of Data0x00083000.rdata4
Import Directory0x0009F870.data
Resource Directory0x000A7000.rsrc
Import Address Table0x000A06D4.data
▪Identical Sections: Sections .rdata4, .rdata3, .rdata2, and .rdata5 share the exact same SHA-256 hash. This indicates these sections are likely duplicates or placeholders filled with the same static data.
▪High Code Entropy: The .text section has an entropy of 7.238. This is quite high for standard executable code and often suggests the code is either compressed or contains an embedded encrypted payload.
▪Self-Modifying / W+X Flag: Section .rdata5 is flagged for Execute and Write permissions and is marked as self-modifying. This is a significant indicator of a packer or a polymorphic engine.
▪Entry Point Anomaly: The Entry Point is at 0x00082630, which places it far beyond the .text section's virtual end. This suggests the execution starts in a later section (likely the self-modifying .rdata5 or a custom tail), a common trait of packed malware.

Imports

Library (DLL)Notable Functions
KERNEL32.dllVirtualAlloc, VirtualProtect, WriteProcessMemory, ReadProcessMemory, CreateProcessW, WinExec, CreateThread, Module32FirstW, GetThreadContext, SetThreadPriority, SleepEx, GetTickCount, QueryPerformanceFrequency, MapViewOfFile, CreateFileMappingW
USER32.dllSetWindowsHookExW, GetAsyncKeyState, GetKeyState, GetForegroundWindow, OpenDesktopW, AttachThreadInput, keybd_event, OpenClipboard, GetClipboardData, EmptyClipboard, EnumDisplayMonitors
ADVAPI32.dllRegCreateKeyExA, RegSetValueExA, RegDeleteValueA, RegDeleteKeyA, RegOpenKeyExA, RegFlushKey, RegQueryInfoKeyA
GDI32.dllBitBlt, StretchBlt, CreateCompatibleBitmap, SelectObject, CreateCompatibleDC, GetDeviceCaps, DeleteObject
SHELL32.dllShellExecuteExW, SHCreateProcessAsUserW, SHChangeNotify, SHGetPathFromIDListW, DoEnvironmentSubstA
COMCTL32.dllImageList_BeginDrag, ImageList_DragMove, ImageList_DragEnter, ImageList_EndDrag, DPA_DeleteAllPtrs
ole32.dllCoCreateInstance, CoInitializeEx, CoUninitialize, DoDragDrop

MITRE ATT&CK Mapping

TacticTechniqueIDIndicators (API/Logic)
PersistenceBoot or Logon Autostart Execution: Registry Run KeysT1547.001RegCreateKeyExA, RegSetValueExA
Privilege EscalationProcess Injection: Process HollowingT1055.012VirtualAllocEx, WriteProcessMemory, ResumeThread, GetThreadContext
Defense EvasionObfuscated Files or Information: Software PackingT1027.002High entropy in .text (7.238), Self-modifying .rdata5 section
Virtualization/Sandbox Evasion: Time-Based EvasionT1497.003QueryPerformanceFrequency, GetTickCount
Indicator Removal: File DeletionT1070.004DeleteFileW, RemoveDirectoryW
DiscoverySystem Information DiscoveryT1082GetVersionExW, GetSystemInfo, GlobalMemoryStatusEx
Process DiscoveryT1057Module32FirstW
CollectionInput Capture: KeyloggingT1056.001GetAsyncKeyState, GetKeyState
Screen CaptureT1113BitBlt, StretchBlt, CreateCompatibleDC
Archive Collected Data: Clipboard DataT1115OpenClipboard, GetClipboardData
ExecutionShared ModulesT1129Extensive use of LoadLibraryW and GetProcAddress

Initial Observations

▪Signature: Unlike the previous samples, this one explicitly mentions Windows Authenticode, indicating the file is (or claims to be) digitally signed.
▪Size: At ~648 KB, it is significantly smaller than your first sample's encrypted state but larger than the decrypted payload.
▪Tooling: TrID suggests a high likelihood of MS Visual C++ origin.

Technical Summary:

This binary is a digitally signed Win32 executable that exhibits strong characteristics of a packed surveillance tool or Remote Access Trojan (RAT).

1. Delivery & Structure

▪Packing Signature: The high entropy in .text (7.238) and the existence of a self-modifying, executable section (.rdata5) indicate the core logic is encrypted or compressed.
▪Execution Anomaly: The program starts at an unusual Entry Point (0x00082630) located outside the main code section, which is a classic indicator of a packer stub.
▪Size: At 648 KB, it is compact enough for quick delivery while containing significant functionality.

2. Core Capabilities (via Imports)

▪Code Injection: It can manipulate other processes using WriteProcessMemory and VirtualProtect, likely to hide its presence within legitimate system tasks.
▪Information Theft:
▪Keylogging: Monitors background keystrokes (GetAsyncKeyState).
▪Clipboard Stealing: Accesses and clears user clipboard data (OpenClipboard).
▪Screen Grabbing: Capable of capturing the desktop via GDI drawing functions.
▪Persistence: Extensive Registry access (ADVAPI32.dll) suggests it modifies system "Run" keys to ensure it starts automatically upon reboot.

3. Operational Risk

The combination of Keylogging, Clipboard access, and Screen capture suggests this sample is designed for credential harvesting and user monitoring. Its ability to inject code further increases the risk of it evading standard task manager detection.

Unpacking

X32 DBG

Setting breakpoint on VirtuallAlloc

Screenshot 2026-02-01 at 12.52.08 PM.png
Figure: Screenshot 2026-02-01 at 12.52.08 PM.png Click to zoom ↗

After hitting the breakpoint ctrl + f9 and f8

Screenshot 2026-02-01 at 12.54.13 PM.png
Figure: Screenshot 2026-02-01 at 12.54.13 PM.png Click to zoom ↗

Follow eax in memory dump.

Screenshot 2026-02-01 at 12.56.28 PM.png
Figure: Screenshot 2026-02-01 at 12.56.28 PM.png Click to zoom ↗

Setting hardware breakpoints.

Screenshot 2026-02-01 at 12.57.54 PM.png
Figure: Screenshot 2026-02-01 at 12.57.54 PM.png Click to zoom ↗

Then f9 we can see the first byte A4

Screenshot 2026-02-01 at 12.59.06 PM.png
Figure: Screenshot 2026-02-01 at 12.59.06 PM.png Click to zoom ↗

hit f9 couple of times. until you see the MZ header decoded.

Screenshot 2026-02-01 at 1.01.57 PM.png
Figure: Screenshot 2026-02-01 at 1.01.57 PM.png Click to zoom ↗

We can see the .text section starts from 400 hex

Screenshot 2026-02-01 at 1.03.48 PM.png
Figure: Screenshot 2026-02-01 at 1.03.48 PM.png Click to zoom ↗

We will dump this.

Screenshot 2026-02-01 at 1.05.36 PM.png
Figure: Screenshot 2026-02-01 at 1.05.36 PM.png Click to zoom ↗

Dump memory to file.

Screenshot 2026-02-01 at 1.06.40 PM.png
Figure: Screenshot 2026-02-01 at 1.06.40 PM.png Click to zoom ↗

Open the the dumped bin file into pe bear.

last section .reloc

Raw Addr. + Raw size

0x40800 + 0x1600 = 0x41E00

Screenshot 2026-02-01 at 1.27.41 PM.png
Figure: Screenshot 2026-02-01 at 1.27.41 PM.png Click to zoom ↗

now open the file in hxd and go to offset 0x41E00 to verify.

We can see there are bytes after 41E00 because this unpacked file didn’t stopped at the end of the heap.

Screenshot 2026-02-01 at 1.33.15 PM.png
Figure: Screenshot 2026-02-01 at 1.33.15 PM.png Click to zoom ↗

Select and delete everything after 41E00 and make surer to save it.

Screenshot 2026-02-01 at 1.39.41 PM.png
Figure: Screenshot 2026-02-01 at 1.39.41 PM.png Click to zoom ↗
Copied