Single-anomaly PE fixtures showing how four tools (dumpbin, Ghidra, pefile, IOCX) diverge on three underspecified points in the delay-load import format. Byte-level specs + recorded outputs; reproducible. Research artifact, not malware.
pefile reproducible-research reverse-engineering malware-analysis binary-analysis pe-format ghidra portable-executables delay-load
-
Updated
Jul 22, 2026 - Java