PREMIUM PESCAN.IO - Analysis Report

File Structure
Analysis Image
PE Chart Code
Header PE (light blue)
Executable sections (pink)
Non-executable sections (black)
External injected code (red)
File Structure in red = malformed or corrupted header

Chart Code For Other Files
Printable characters (blue)
Non-printable characters (black)
Information
Size: 1,40 MB
SHA-256 Hash: C8F4CEB5940E99CE6CD30CB9F67202C1D853B19D8F4C83882823D1647A2971D9
SHA-1 Hash: AF748D49B26E8692579768C451C354E851F98830
MD5 Hash: 028444FA140270D784A3420187CF1B29
Imphash: F34D5F2D4577ED6D9CEEC516C1F5A744
MajorOSVersion: 4
MinorOSVersion: 0
CheckSum: 00000000
EntryPoint (rva): 167B4E
SizeOfHeaders: 200
SizeOfImage: 16C000
ImageBase: 400000
Architecture: x86
ImportTable: 167AF2
IAT: 2000
Characteristics: 102
TimeDateStamp: 8CDCBB2C
Date: 20/11/2044 17:34:36
File Type: EXE
Number Of Sections: 3
ASLR: Enabled
Section Names: .text, .rsrc, .reloc
Number Of Executable Sections: 1
Subsystem: Windows GUI
UAC Execution Level Manifest: asInvoker

Sections Info
Section Name Flags ROffset RSize VOffset VSizeEntropyChi2
.text
0x60000020
Code
Executable
Readable
200 165C00 2000 165B54
6.5685
25511088.28
.rsrc
0x40000040
Initialized Data
Readable
165E00 600 168000 575
3.8477
96992.33
.reloc
0x42000040
Initialized Data
GP-Relative
Readable
166400 200 16A000 C
0.1019
128015
Description
OriginalFilename: FGHDec.dll
LegalCopyright: Copyright 2026
ProductName: FGHDec
FileVersion: 1.0.0.0
FileDescription: FGHDec
ProductVersion: 1.0.0.0
Language: Unknown (ID=0x0)
CodePage: Unicode (UTF-16 LE) (0x4B0)

Binder/Joiner/Crypter
2 Executable files found

Entry Point
The section number (1) - (.text) have the Entry Point
Information -> EntryPoint (calculated) - 165D4E
Code -> FF25002040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
EP changed to another address -> (Address Of EntryPoint > Base Of Data)
Assembler
|JMP DWORD PTR [0X402000]
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
Signatures
Certificate - Digital Signature Not Found:
• The file is not signed

Packer/Compiler
Compiler: Microsoft Visual .NET - (You can use a decompiler for this...)
AnyCPU: False
Version: v4.0
Detect It Easy (die)
PE: library: .NET(v4.0.30319)[-]
PE: linker: Microsoft Linker(8.0)[-]
Entropy: 6.56412

File Access
19cr.exe
mscoree.dll
LumoinCX.dll
FGHDec.dll
7DiscUtils.LogicalDiskManager.Dat
?DiscUtils.LogicalDiskManager.Dat
5DiscUtils.LogicalDiskManager.Dat
GDiscUtils.Log
DiscUtils.Log
7DiscUtils.Log
?DiscUtils.Log
5DiscUtils.Log
.Log
DiscUtils.Internal.Log
LX_FyEqf0ktY00bwkff.zip
.7Z
Temp
RootDir
AppData

File Access (UNICODE)
FGHDec.dll
LX_FyEqf0ktY00bwkff_i.exe
30319\MSBuild.exe
cmd.exe
LumoinCX.dll
payload_package.dat
vBNE2@/;%.wds
Temp

Interest's Words
Decrypt
PassWord
<head
<link
<header
<main
exec
attrib
start
cipher
defrag
systeminfo
bootsect
replace

Interest's Words (UNICODE)
Encrypt
Decrypt
attrib
start
cipher
bootsect

URLs (UNICODE)
http://www.apple.com/DTDs/PropertyList-1.0.dtd

Emails
WGGU@ht4v.1N

IP Addresses
1.0.107.0

PE Carving
Start Offset Header End Offset Size (Bytes)
0 1F62C 1F62C
1F62C 166600 146FD4
Strings/Hex Code Found With The File Rules
Rule Type Encoding Matched (Word)
Text Unicode WinAPI Sockets (connect)
Text Ascii WinAPI Sockets (send)
Text Ascii File (GetTempPath)
Text Ascii File (CopyFile)
Text Ascii Encryption (CipherMode)
Text Ascii Encryption (CreateDecryptor)
Text Ascii Encryption (CryptoStream)
Text Ascii Encryption (CryptoStreamMode)
Text Ascii Encryption (FromBase64String)
Text Ascii Encryption (ICryptoTransform)
Text Ascii Execution (ShellExecute)
Text Ascii Execution (OpenEventA)
Text Ascii Malicious code executed after exploiting a vulnerability (Payload)
Text Ascii Process of gathering information about network resources (Enumeration)
Text Ascii Unauthorized movement of funds or data (Transfer)
Entry Point Hex Pattern Microsoft Visual C / Basic .NET
Entry Point Hex Pattern Microsoft Visual C++ 8
Entry Point Hex Pattern Microsoft Visual C++ 8.0
Entry Point Hex Pattern Microsoft Visual C v7.0 / Basic .NET
Entry Point Hex Pattern Microsoft Visual Studio .NET
Entry Point Hex Pattern .NET executable
Resources
Path DataRVA Size FileOffset CodeText
\VERSION\1\0 1680A0 35E 165EA0 5E0334000000560053005F00560045005200530049004F004E005F0049004E0046004F0000000000BD04EFFE000001000E00.4...V.S._.V.E.R.S.I.O.N._.I.N.F.O...............
\24\1\0 168400 175 166200 EFBBBF3C3F786D6C2076657273696F6E3D22312E302220656E636F64696E673D225554462D3822207374616E64616C6F6E65...<?xml version="1.0" encoding="UTF-8" standalone
Intelligent String
• 1.14.0.0
• LX_FyEqf0ktY00bwkff_i.exe
• .zip
• 1.0.0.0
• _CorDllMainmscoree.dll
• .exe
• cmd.exe
• .bat
• .vbs
• .pdf
• .doc
• .png
• .jpg
• .txt
• 'payload_package.dat
• LumoinCX.dll
• C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe
• !john@example.com
• http://www.apple.com/DTDs/PropertyList-1.0.dtd
• RAW.img,.ima,.vfd,.flp,.bif
• _CorExeMainmscoree.dll

Flow Anomalies
Offset RVA Section Description
2143A 10002000 .text JMP [static] | Indirect jump to absolute memory address
2B926 E046EEF .text CALL [static] | Indirect call to absolute memory address
2C26A E046EEF .text JMP [static] | Indirect jump to absolute memory address
352A7 70FB7993 .text JMP [static] | Indirect jump to absolute memory address
3CBA6 70FB7993 .text CALL [static] | Indirect call to absolute memory address
48E27 7531E02A .text CALL [static] | Indirect call to absolute memory address
49E25 1EB240B8 .text JMP [static] | Indirect jump to absolute memory address
4FB33 1EB240B8 .text CALL [static] | Indirect call to absolute memory address
50BA2 1EB240B8 .text CALL [static] | Indirect call to absolute memory address
55A21 28DD1C92 .text CALL [static] | Indirect call to absolute memory address
595E9 2A30AEEE .text JMP [static] | Indirect jump to absolute memory address
62A8B 2D9C5D95 .text CALL [static] | Indirect call to absolute memory address
65319 2D9C5D95 .text CALL [static] | Indirect call to absolute memory address
66438 2D9C5D95 .text JMP [static] | Indirect jump to absolute memory address
6BAF1 2D9C5D95 .text CALL [static] | Indirect call to absolute memory address
72694 2D9C5D95 .text CALL [static] | Indirect call to absolute memory address
776A5 2D9C5D95 .text CALL [static] | Indirect call to absolute memory address
79162 78E897FF .text CALL [static] | Indirect call to absolute memory address
7BDED 78E897FF .text JMP [static] | Indirect jump to absolute memory address
85B7B 78E897FF .text JMP [static] | Indirect jump to absolute memory address
861B4 78E897FF .text CALL [static] | Indirect call to absolute memory address
86A9E 78E897FF .text CALL [static] | Indirect call to absolute memory address
94B5B 7EAE699E .text CALL [static] | Indirect call to absolute memory address
AA5A6 A114A20 .text CALL [static] | Indirect call to absolute memory address
165D4E 402000 .text JMP [static] | Indirect jump to absolute memory address
Extra Analysis
Metric Value Percentage
Ascii Code 856300 58,3349%
Null Byte Code 386756 26,3475%
© 2026 All rights reserved.