PESCAN.IO - Analysis Report Basic

File Structure
Analysis Image
PE Chart Code
Header PE (light blue)
Executable sections (pink)
Non-executable sections (black)
External injected code (red)
File Structure in red = malformed or corrupted header

Chart Code For Other Files
Printable characters (blue)
Non-printable characters (black)
Information
Icon: Icon
Size: 1,07 MB
SHA-256 Hash: DC213575771C1422B74B31693B8E3403F8E013076BF7C9C86353126B29550515
SHA-1 Hash: D876BD9CCF08126D1F0E97A93F96885AD01DB25B
MD5 Hash: 0C5B0354476FFB48241F808AD8A8C136
Imphash: D221B1DC8C3A08622F6512E7876527C8
MajorOSVersion: 4
MinorOSVersion: 0
CheckSum: 00119089
EntryPoint (rva): 1D20
SizeOfHeaders: 1000
SizeOfImage: 10E000
ImageBase: 400000
Architecture: x86
ImportTable: 2134
IAT: 2000
Characteristics: 10F
TimeDateStamp: 4D46F4ED
Date: 31/01/2011 17:44:13
File Type: EXE
Number Of Sections: 5
ASLR: Disabled
Section Names: .text, .rdata, .data, .gentee, .rsrc
Number Of Executable Sections: 1
Subsystem: Windows GUI

Sections Info
Section Name Flags ROffset RSize VOffset VSizeEntropyChi2
.text
0x60000020
Code
Executable
Readable
1000 1000 1000 EAC
5.942
55361.88
.rdata
0x40000040
Initialized Data
Readable
2000 1000 2000 488
1.7379
701657.63
.data
0xC0000040
Initialized Data
Readable
Writeable
3000 1000 3000 560
1.0105
835081.75
.gentee
0x40000040
Initialized Data
Readable
4000 103000 4000 102EC1
7.9997
410.26
.rsrc
0x40000040
Initialized Data
Readable
107000 7000 107000 6904
7.3042
145096.09
Binder/Joiner/Crypter
Dropper code detected (EOF) - 17,34 KB

Entry Point
The section number (1) - (.text) have the Entry Point
Information -> EntryPoint (calculated) - 1D20
Code -> 558BEC6AFF682821400068A01E400064A100000000506489250000000083EC685356578965E833DB895DFC6A02FF15882040
Assembler
|PUSH EBP
|MOV EBP, ESP
|PUSH -1
|PUSH 0X402128
|PUSH 0X401EA0
|MOV EAX, DWORD PTR FS:[0]
|PUSH EAX
|MOV DWORD PTR FS:[0], ESP
|SUB ESP, 0X68
|PUSH EBX
|PUSH ESI
|PUSH EDI
|MOV DWORD PTR [EBP - 0X18], ESP
|XOR EBX, EBX
|MOV DWORD PTR [EBP - 4], EBX
|PUSH 2
Signatures
Rich Signature Analyzer:
Code -> 5FB8C1981BD9AFCB1BD9AFCB1BD9AFCB98C5A1CB1AD9AFCBF3C6ABCB19D9AFCB79C6BCCB1ED9AFCB1BD9AECB33D9AFCBF3C6A5CB0AD9AFCB526963681BD9AFCB
Footprint md5 Hash -> 170918B6DC12C0756FC2AF10CB8EDBAC
• The Rich header apparently has not been modified
Certificate - Digital Signature:
• The file is signed and the signature is correct

Packer/Compiler
Detect It Easy (die)
• PE: installer: Gentee Installer(-)[-]
• PE: compiler: EP:Microsoft Visual C/C++(6.0 (1720-9782))[EXE32]
• PE: compiler: Microsoft Visual C/C++(6.0)[msvcrt]
• PE: linker: Microsoft Linker(6.0)[-]
• Entropy: 7.97989

Suspicious Functions
Library Function Description
KERNEL32.DLL CreateMutexA Create a named or unnamed mutex object for controlling access to a shared resource.
KERNEL32.DLL GetModuleFileNameA Retrieve the fully qualified path for the executable file of a specified module.
KERNEL32.DLL VirtualAlloc Reserve, commit, or both, a region of memory within the virtual address space of a process.
KERNEL32.DLL WriteFile Writes data to a specified file or input/output (I/O) device.
KERNEL32.DLL LoadLibraryA Loads the specified module into the address space of the calling process.
KERNEL32.DLL GetModuleHandleA Retrieves a handle to the specified module.
KERNEL32.DLL GetProcAddress Retrieves the address of an exported function or variable from the specified dynamic-link library (DLL).
KERNEL32.DLL CreateFileA Creates or opens a file or I/O device.
KERNEL32.DLL DeleteFileA Deletes an existing file.
KERNEL32.DLL GetTempPathA Retrieves the temporary directory path.
KERNEL32.DLL CloseHandle Closes an open object handle.
File Access
%s\genteert.dll
Cannot create gentee.dll
MSVCRT.dll
USER32.dll
KERNEL32.dll
@.dat
Temp

File Access (UNICODE)
Temp

Interest's Words
Virus
PADDINGX
exec
attrib
start
ping

URLs
http://www.usertrust.com10
http://crl.usertrust.com/AddTrustExternalCARoot.crl
http://ocsp.usertrust.com
http://crl.usertrust.com/UTN-USERFirst-Object.crl
http://crt.usertrust.com/UTNAddTrustObject_CA.crt
http://crl.sectigo.com/COMODOTimeStampingCA_2.crl
http://crt.sectigo.com/COMODOTimeStampingCA_2.crt
http://ocsp.sectigo.com
http://crl.comodoca.com/COMODORSACodeSigningCA.crl
http://crt.comodoca.com/COMODORSACodeSigningCA.crt
http://ocsp.comodoca.com
http://crl.comodoca.com/COMODORSACertificationAuthority.crl
http://crt.comodoca.com/COMODORSAAddTrustCA.crt
http://crl.sectigo.com/SectigoRSATimeStampingCA.crl
http://crt.sectigo.com/SectigoRSATimeStampingCA.crt
http://crl.usertrust.com/USERTrustRSACertificationAuthority.crl
http://crt.usertrust.com/USERTrustRSAAddTrustCA.crt
https://sectigo.com/CPS0B
https://secure.comodo.net/CPS0C
https://sectigo.com/CPS0D

Known IP/Domains
yahoo.com

Strings/Hex Code Found With The File Rules
Rule Type Encoding Matched (Word)
Text Ascii Antivirus Software (comodo)
Entry Point Hex Pattern Microsoft Visual C++ 5.0
Entry Point Hex Pattern Microsoft Visual C++ 8
Entry Point Hex Pattern Microsoft Visual C++ 8.0
Entry Point Hex Pattern Microsoft Visual C++ v6.0
Entry Point Hex Pattern Microsoft Visual C++ v6.0
Entry Point Hex Pattern Microsoft Visual C++
Resources
Path DataRVA Size FileOffset CodeText
\ICON\1\1033 107484 2E8 107484 2800000020000000400000000100040000000000800200000000000000000000000000000000000000000000000080000080(... ...@.........................................
\DIALOG\IDD_DLGBROWSER2\1033 10776C 122 10776C 0100FFFF0000000000000100400400500600000000002C01DD00000000000000080000000001560065007200640061006E00............@..P......,...............V.e.r.d.a.n.
\DIALOG\IDD_DLGFIN2\1033 107890 1D8 107890 0100FFFF0000000000000100400400500D00000000002C01DD00000000000000080000000001560065007200640061006E00............@..P......,...............V.e.r.d.a.n.
\DIALOG\IDD_DLGLIC\0 107A68 1AC 107A68 0100FFFF0000000000000100400400500B00000000002C01DD00000000000000080000000001560065007200640061006E00............@..P......,...............V.e.r.d.a.n.
\DIALOG\IDD_DLGPATH\1033 107C14 220 107C14 0100FFFF0000000000000100400400500F00000000002C01DD00000000000000080000000001560065007200640061006E00............@..P......,...............V.e.r.d.a.n.
\DIALOG\IDD_DLGPROG\1033 107E34 258 107E34 0100FFFF0000000000000100400400500F00000000002C01DD00000000000000080000000001560065007200640061006E00............@..P......,...............V.e.r.d.a.n.
\DIALOG\IDD_DLGUCONF2\1033 10808C 138 10808C 0100FFFF0000000000000100400400500800000000002C01DD00000000000000080000000001560065007200640061006E00............@..P......,...............V.e.r.d.a.n.
\DIALOG\IDD_DLGUFIN2\0 1081C4 1B8 1081C4 0100FFFF0000000000000100400400500C00000000002C01DD00000000000000080000000001560065007200640061006E00............@..P......,...............V.e.r.d.a.n.
\DIALOG\IDD_DLGUNDEL\0 10837C 198 10837C 0100FFFF0000000000000100400400500B00000000002C01DD00000000000000080000000001560065007200640061006E00............@..P......,...............V.e.r.d.a.n.
\DIALOG\IDD_DLGUPROG\0 108514 198 108514 0100FFFF0000000000000100400400500A00000000002C01DD00000000000000080000000001560065007200640061006E00............@..P......,...............V.e.r.d.a.n.
\DIALOG\IDD_DLGWEL2\1033 1086AC 158 1086AC 0100FFFF0000000000000100400400500900000000002C01DD00000000000000080000000001560065007200640061006E00............@..P......,...............V.e.r.d.a.n.
\DIALOG\1000\1033 108804 36 108804 0100FFFF00000000000000004008CA100000000000002C01DD00000000000000080000000001560065007200640061006E0061000000............@.........,...............V.e.r.d.a.n.a...
\RCDATA\SETUP_TEMP\0 10883C 4944 10883C 47454100000019883C010200C0FF8A36AD31D501060000000100EF0000005548000000000000C60000004449000000000000GEA.....<......6.1............UH..........DI......
\GROUP_ICON\SETUP_ICON\0 10D180 14 10D180 0000010001002020000001000400E80200000100...... ............
\24\1\1033 10D194 76D 10D194 3C3F786D6C2076657273696F6E3D22312E302220656E636F64696E673D225554462D3822207374616E64616C6F6E653D2279<?xml version="1.0" encoding="UTF-8" standalone="y
Intelligent String
• MSVCRT.dll
• c:\temp%s\genteert.dll
• disk%i.pak

Flow Anomalies
Offset FlowVA Section Description
168E 403550 .text CALL [static] | Indirect call to absolute memory address
16CC 40201C .text CALL [static] | Indirect call to absolute memory address
16F5 40209C .text CALL [static] | Indirect call to absolute memory address
16FF 402014 .text CALL [static] | Indirect call to absolute memory address
171A 402010 .text CALL [static] | Indirect call to absolute memory address
1739 40200C .text CALL [static] | Indirect call to absolute memory address
1741 402008 .text CALL [static] | Indirect call to absolute memory address
1753 40209C .text CALL [static] | Indirect call to absolute memory address
175D 402014 .text CALL [static] | Indirect call to absolute memory address
17D7 402004 .text CALL [static] | Indirect call to absolute memory address
17EC 402000 .text CALL [static] | Indirect call to absolute memory address
17FD 40200C .text CALL [static] | Indirect call to absolute memory address
18E8 40204C .text CALL [static] | Indirect call to absolute memory address
1916 402048 .text CALL [static] | Indirect call to absolute memory address
191C 402044 .text CALL [static] | Indirect call to absolute memory address
1933 40200C .text CALL [static] | Indirect call to absolute memory address
195E 402010 .text CALL [static] | Indirect call to absolute memory address
1969 402040 .text CALL [static] | Indirect call to absolute memory address
1981 40200C .text CALL [static] | Indirect call to absolute memory address
198D 402000 .text CALL [static] | Indirect call to absolute memory address
1995 40203C .text CALL [static] | Indirect call to absolute memory address
19E8 402038 .text CALL [static] | Indirect call to absolute memory address
1A8E 40200C .text CALL [static] | Indirect call to absolute memory address
1ABD 40202C .text CALL [static] | Indirect call to absolute memory address
1AC4 402028 .text CALL [static] | Indirect call to absolute memory address
1ADF 40200C .text CALL [static] | Indirect call to absolute memory address
1AE6 402024 .text CALL [static] | Indirect call to absolute memory address
1AFD 402098 .text CALL [static] | Indirect call to absolute memory address
1B05 402028 .text CALL [static] | Indirect call to absolute memory address
1C2E 402050 .text CALL [static] | Indirect call to absolute memory address
1C4C 402054 .text CALL [static] | Indirect call to absolute memory address
1D4D 402088 .text CALL [static] | Indirect call to absolute memory address
1D62 402084 .text CALL [static] | Indirect call to absolute memory address
1D70 402080 .text CALL [static] | Indirect call to absolute memory address
1D9C 402078 .text CALL [static] | Indirect call to absolute memory address
1DD5 402070 .text CALL [static] | Indirect call to absolute memory address
1E24 402058 .text CALL [static] | Indirect call to absolute memory address
1E48 40203C .text CALL [static] | Indirect call to absolute memory address
1E58 402068 .text CALL [static] | Indirect call to absolute memory address
1E78 402060 .text CALL [static] | Indirect call to absolute memory address
1E7E 402064 .text JMP [static] | Indirect jump to absolute memory address
1E84 402074 .text JMP [static] | Indirect jump to absolute memory address
1EA0 40208C .text JMP [static] | Indirect jump to absolute memory address
1EA6 402090 .text JMP [static] | Indirect jump to absolute memory address
84ED 60C54615 .gentee JMP [static] | Indirect jump to absolute memory address
219FF 60C54615 .gentee CALL [static] | Indirect call to absolute memory address
27699 60C54615 .gentee JMP [static] | Indirect jump to absolute memory address
2847D 3399357 .gentee CALL [static] | Indirect call to absolute memory address
29CC7 3399357 .gentee JMP [static] | Indirect jump to absolute memory address
2E4A3 3399357 .gentee JMP [static] | Indirect jump to absolute memory address
33B93 19344E74 .gentee JMP [static] | Indirect jump to absolute memory address
49188 19344E74 .gentee JMP [static] | Indirect jump to absolute memory address
4D0C9 19344E74 .gentee CALL [static] | Indirect call to absolute memory address
5B01E 414DED52 .gentee JMP [static] | Indirect jump to absolute memory address
5EC95 2D2C3178 .gentee CALL [static] | Indirect call to absolute memory address
60AED 2D2C3178 .gentee CALL [static] | Indirect call to absolute memory address
64869 2D2C3178 .gentee JMP [static] | Indirect jump to absolute memory address
6F1DC 2D2C3178 .gentee JMP [static] | Indirect jump to absolute memory address
717E4 2D2C3178 .gentee CALL [static] | Indirect call to absolute memory address
7B551 1F542C0D .gentee JMP [static] | Indirect jump to absolute memory address
8234A 5EF11A4F .gentee CALL [static] | Indirect call to absolute memory address
83CBB 5EF11A4F .gentee CALL [static] | Indirect call to absolute memory address
8DD67 7F9E7BDB .gentee CALL [static] | Indirect call to absolute memory address
959E1 7F9E7BDB .gentee CALL [static] | Indirect call to absolute memory address
9CF06 7F9E7BDB .gentee CALL [static] | Indirect call to absolute memory address
9DA0B 7F9E7BDB .gentee CALL [static] | Indirect call to absolute memory address
B7BB9 7F9E7BDB .gentee CALL [static] | Indirect call to absolute memory address
BCE69 375E7929 .gentee CALL [static] | Indirect call to absolute memory address
C169A 74822286 .gentee CALL [static] | Indirect call to absolute memory address
D38DF ADCFF03 .gentee CALL [static] | Indirect call to absolute memory address
DEFA1 4AFA27 .gentee JMP [static] | Indirect jump to absolute memory address
FDDCB 4AFA27 .gentee JMP [static] | Indirect jump to absolute memory address
10FD91 4AFA27 *padding* JMP [static] | Indirect jump to absolute memory address
110DC3 4AFA27 *padding* JMP [static] | Indirect jump to absolute memory address
10E000 N/A *Overlay* 00E0100056A8CA52500000001347D63465218733 | ....V..RP....G.4e!.3
Extra Analysis
Metric Value Percentage
Ascii Code 764347 68,0218%
Null Byte Code 20139 1,7922%
NOP Cave Found 0x9090909090 Block Count: 17 | Total: 0,0038%
© 2026 All rights reserved.