PESCAN.IO - Analysis Report Basic |
|||||||
| File Structure |
|
PE Chart Code
Header PE (light blue)
Executable sections (pink)
Non-executable sections (black)
External injected code (red)
File Structure in red = malformed or corrupted header
Chart Code For Other Files
Printable characters (blue)
Non-printable characters (black)
| Information |
Icon: Size: 1,07 MBSHA-256 Hash: DC213575771C1422B74B31693B8E3403F8E013076BF7C9C86353126B29550515 SHA-1 Hash: D876BD9CCF08126D1F0E97A93F96885AD01DB25B MD5 Hash: 0C5B0354476FFB48241F808AD8A8C136 Imphash: D221B1DC8C3A08622F6512E7876527C8 MajorOSVersion: 4 MinorOSVersion: 0 CheckSum: 00119089 EntryPoint (rva): 1D20 SizeOfHeaders: 1000 SizeOfImage: 10E000 ImageBase: 400000 Architecture: x86 ImportTable: 2134 IAT: 2000 Characteristics: 10F TimeDateStamp: 4D46F4ED Date: 31/01/2011 17:44:13 File Type: EXE Number Of Sections: 5 ASLR: Disabled Section Names: .text, .rdata, .data, .gentee, .rsrc Number Of Executable Sections: 1 Subsystem: Windows GUI |
| Sections Info |
| Section Name | Flags | ROffset | RSize | VOffset | VSize | Entropy | Chi2 |
|---|---|---|---|---|---|---|---|
| .text | 0x60000020 Code Executable Readable |
1000 | 1000 | 1000 | EAC |
|
|
| .rdata | 0x40000040 Initialized Data Readable |
2000 | 1000 | 2000 | 488 |
|
|
| .data | 0xC0000040 Initialized Data Readable Writeable |
3000 | 1000 | 3000 | 560 |
|
|
| .gentee | 0x40000040 Initialized Data Readable |
4000 | 103000 | 4000 | 102EC1 |
|
|
| .rsrc | 0x40000040 Initialized Data Readable |
107000 | 7000 | 107000 | 6904 |
|
|
| Binder/Joiner/Crypter |
| Dropper code detected (EOF) - 17,34 KB |
| Entry Point |
The section number (1) - (.text) have the Entry Point Information -> EntryPoint (calculated) - 1D20 Code -> 558BEC6AFF682821400068A01E400064A100000000506489250000000083EC685356578965E833DB895DFC6A02FF15882040 Assembler |PUSH EBP |MOV EBP, ESP |PUSH -1 |PUSH 0X402128 |PUSH 0X401EA0 |MOV EAX, DWORD PTR FS:[0] |PUSH EAX |MOV DWORD PTR FS:[0], ESP |SUB ESP, 0X68 |PUSH EBX |PUSH ESI |PUSH EDI |MOV DWORD PTR [EBP - 0X18], ESP |XOR EBX, EBX |MOV DWORD PTR [EBP - 4], EBX |PUSH 2 |
| Signatures |
| Rich Signature Analyzer: Code -> 5FB8C1981BD9AFCB1BD9AFCB1BD9AFCB98C5A1CB1AD9AFCBF3C6ABCB19D9AFCB79C6BCCB1ED9AFCB1BD9AECB33D9AFCBF3C6A5CB0AD9AFCB526963681BD9AFCB Footprint md5 Hash -> 170918B6DC12C0756FC2AF10CB8EDBAC • The Rich header apparently has not been modified Certificate - Digital Signature: • The file is signed and the signature is correct |
| Packer/Compiler |
| Detect It Easy (die) • PE: installer: Gentee Installer(-)[-] • PE: compiler: EP:Microsoft Visual C/C++(6.0 (1720-9782))[EXE32] • PE: compiler: Microsoft Visual C/C++(6.0)[msvcrt] • PE: linker: Microsoft Linker(6.0)[-] • Entropy: 7.97989 |
| Suspicious Functions |
| Library | Function | Description |
|---|---|---|
| KERNEL32.DLL | CreateMutexA | Create a named or unnamed mutex object for controlling access to a shared resource. |
| KERNEL32.DLL | GetModuleFileNameA | Retrieve the fully qualified path for the executable file of a specified module. |
| KERNEL32.DLL | VirtualAlloc | Reserve, commit, or both, a region of memory within the virtual address space of a process. |
| KERNEL32.DLL | WriteFile | Writes data to a specified file or input/output (I/O) device. |
| KERNEL32.DLL | LoadLibraryA | Loads the specified module into the address space of the calling process. |
| KERNEL32.DLL | GetModuleHandleA | Retrieves a handle to the specified module. |
| KERNEL32.DLL | GetProcAddress | Retrieves the address of an exported function or variable from the specified dynamic-link library (DLL). |
| KERNEL32.DLL | CreateFileA | Creates or opens a file or I/O device. |
| KERNEL32.DLL | DeleteFileA | Deletes an existing file. |
| KERNEL32.DLL | GetTempPathA | Retrieves the temporary directory path. |
| KERNEL32.DLL | CloseHandle | Closes an open object handle. |
| File Access |
| %s\genteert.dll Cannot create gentee.dll MSVCRT.dll USER32.dll KERNEL32.dll @.dat Temp |
| File Access (UNICODE) |
| Temp |
| Interest's Words |
| Virus PADDINGX exec attrib start ping |
| URLs |
| http://www.usertrust.com10 http://crl.usertrust.com/AddTrustExternalCARoot.crl http://ocsp.usertrust.com http://crl.usertrust.com/UTN-USERFirst-Object.crl http://crt.usertrust.com/UTNAddTrustObject_CA.crt http://crl.sectigo.com/COMODOTimeStampingCA_2.crl http://crt.sectigo.com/COMODOTimeStampingCA_2.crt http://ocsp.sectigo.com http://crl.comodoca.com/COMODORSACodeSigningCA.crl http://crt.comodoca.com/COMODORSACodeSigningCA.crt http://ocsp.comodoca.com http://crl.comodoca.com/COMODORSACertificationAuthority.crl http://crt.comodoca.com/COMODORSAAddTrustCA.crt http://crl.sectigo.com/SectigoRSATimeStampingCA.crl http://crt.sectigo.com/SectigoRSATimeStampingCA.crt http://crl.usertrust.com/USERTrustRSACertificationAuthority.crl http://crt.usertrust.com/USERTrustRSAAddTrustCA.crt https://sectigo.com/CPS0B https://secure.comodo.net/CPS0C https://sectigo.com/CPS0D |
| Known IP/Domains |
| yahoo.com |
| Strings/Hex Code Found With The File Rules |
| Rule Type | Encoding | Matched (Word) |
|---|---|---|
| Text | Ascii | Antivirus Software (comodo) |
| Entry Point | Hex Pattern | Microsoft Visual C++ 5.0 |
| Entry Point | Hex Pattern | Microsoft Visual C++ 8 |
| Entry Point | Hex Pattern | Microsoft Visual C++ 8.0 |
| Entry Point | Hex Pattern | Microsoft Visual C++ v6.0 |
| Entry Point | Hex Pattern | Microsoft Visual C++ v6.0 |
| Entry Point | Hex Pattern | Microsoft Visual C++ |
| Resources |
| Path | DataRVA | Size | FileOffset | Code | Text |
|---|---|---|---|---|---|
| \ICON\1\1033 | 107484 | 2E8 | 107484 | 2800000020000000400000000100040000000000800200000000000000000000000000000000000000000000000080000080 | (... ...@......................................... |
| \DIALOG\IDD_DLGBROWSER2\1033 | 10776C | 122 | 10776C | 0100FFFF0000000000000100400400500600000000002C01DD00000000000000080000000001560065007200640061006E00 | ............@..P......,...............V.e.r.d.a.n. |
| \DIALOG\IDD_DLGFIN2\1033 | 107890 | 1D8 | 107890 | 0100FFFF0000000000000100400400500D00000000002C01DD00000000000000080000000001560065007200640061006E00 | ............@..P......,...............V.e.r.d.a.n. |
| \DIALOG\IDD_DLGLIC\0 | 107A68 | 1AC | 107A68 | 0100FFFF0000000000000100400400500B00000000002C01DD00000000000000080000000001560065007200640061006E00 | ............@..P......,...............V.e.r.d.a.n. |
| \DIALOG\IDD_DLGPATH\1033 | 107C14 | 220 | 107C14 | 0100FFFF0000000000000100400400500F00000000002C01DD00000000000000080000000001560065007200640061006E00 | ............@..P......,...............V.e.r.d.a.n. |
| \DIALOG\IDD_DLGPROG\1033 | 107E34 | 258 | 107E34 | 0100FFFF0000000000000100400400500F00000000002C01DD00000000000000080000000001560065007200640061006E00 | ............@..P......,...............V.e.r.d.a.n. |
| \DIALOG\IDD_DLGUCONF2\1033 | 10808C | 138 | 10808C | 0100FFFF0000000000000100400400500800000000002C01DD00000000000000080000000001560065007200640061006E00 | ............@..P......,...............V.e.r.d.a.n. |
| \DIALOG\IDD_DLGUFIN2\0 | 1081C4 | 1B8 | 1081C4 | 0100FFFF0000000000000100400400500C00000000002C01DD00000000000000080000000001560065007200640061006E00 | ............@..P......,...............V.e.r.d.a.n. |
| \DIALOG\IDD_DLGUNDEL\0 | 10837C | 198 | 10837C | 0100FFFF0000000000000100400400500B00000000002C01DD00000000000000080000000001560065007200640061006E00 | ............@..P......,...............V.e.r.d.a.n. |
| \DIALOG\IDD_DLGUPROG\0 | 108514 | 198 | 108514 | 0100FFFF0000000000000100400400500A00000000002C01DD00000000000000080000000001560065007200640061006E00 | ............@..P......,...............V.e.r.d.a.n. |
| \DIALOG\IDD_DLGWEL2\1033 | 1086AC | 158 | 1086AC | 0100FFFF0000000000000100400400500900000000002C01DD00000000000000080000000001560065007200640061006E00 | ............@..P......,...............V.e.r.d.a.n. |
| \DIALOG\1000\1033 | 108804 | 36 | 108804 | 0100FFFF00000000000000004008CA100000000000002C01DD00000000000000080000000001560065007200640061006E0061000000 | ............@.........,...............V.e.r.d.a.n.a... |
| \RCDATA\SETUP_TEMP\0 | 10883C | 4944 | 10883C | 47454100000019883C010200C0FF8A36AD31D501060000000100EF0000005548000000000000C60000004449000000000000 | GEA.....<......6.1............UH..........DI...... |
| \GROUP_ICON\SETUP_ICON\0 | 10D180 | 14 | 10D180 | 0000010001002020000001000400E80200000100 | ...... ............ |
| \24\1\1033 | 10D194 | 76D | 10D194 | 3C3F786D6C2076657273696F6E3D22312E302220656E636F64696E673D225554462D3822207374616E64616C6F6E653D2279 | <?xml version="1.0" encoding="UTF-8" standalone="y |
| Intelligent String |
| • MSVCRT.dll • c:\temp%s\genteert.dll • disk%i.pak |
| Flow Anomalies |
| Offset | FlowVA | Section | Description |
|---|---|---|---|
| 168E | 403550 | .text | CALL [static] | Indirect call to absolute memory address |
| 16CC | 40201C | .text | CALL [static] | Indirect call to absolute memory address |
| 16F5 | 40209C | .text | CALL [static] | Indirect call to absolute memory address |
| 16FF | 402014 | .text | CALL [static] | Indirect call to absolute memory address |
| 171A | 402010 | .text | CALL [static] | Indirect call to absolute memory address |
| 1739 | 40200C | .text | CALL [static] | Indirect call to absolute memory address |
| 1741 | 402008 | .text | CALL [static] | Indirect call to absolute memory address |
| 1753 | 40209C | .text | CALL [static] | Indirect call to absolute memory address |
| 175D | 402014 | .text | CALL [static] | Indirect call to absolute memory address |
| 17D7 | 402004 | .text | CALL [static] | Indirect call to absolute memory address |
| 17EC | 402000 | .text | CALL [static] | Indirect call to absolute memory address |
| 17FD | 40200C | .text | CALL [static] | Indirect call to absolute memory address |
| 18E8 | 40204C | .text | CALL [static] | Indirect call to absolute memory address |
| 1916 | 402048 | .text | CALL [static] | Indirect call to absolute memory address |
| 191C | 402044 | .text | CALL [static] | Indirect call to absolute memory address |
| 1933 | 40200C | .text | CALL [static] | Indirect call to absolute memory address |
| 195E | 402010 | .text | CALL [static] | Indirect call to absolute memory address |
| 1969 | 402040 | .text | CALL [static] | Indirect call to absolute memory address |
| 1981 | 40200C | .text | CALL [static] | Indirect call to absolute memory address |
| 198D | 402000 | .text | CALL [static] | Indirect call to absolute memory address |
| 1995 | 40203C | .text | CALL [static] | Indirect call to absolute memory address |
| 19E8 | 402038 | .text | CALL [static] | Indirect call to absolute memory address |
| 1A8E | 40200C | .text | CALL [static] | Indirect call to absolute memory address |
| 1ABD | 40202C | .text | CALL [static] | Indirect call to absolute memory address |
| 1AC4 | 402028 | .text | CALL [static] | Indirect call to absolute memory address |
| 1ADF | 40200C | .text | CALL [static] | Indirect call to absolute memory address |
| 1AE6 | 402024 | .text | CALL [static] | Indirect call to absolute memory address |
| 1AFD | 402098 | .text | CALL [static] | Indirect call to absolute memory address |
| 1B05 | 402028 | .text | CALL [static] | Indirect call to absolute memory address |
| 1C2E | 402050 | .text | CALL [static] | Indirect call to absolute memory address |
| 1C4C | 402054 | .text | CALL [static] | Indirect call to absolute memory address |
| 1D4D | 402088 | .text | CALL [static] | Indirect call to absolute memory address |
| 1D62 | 402084 | .text | CALL [static] | Indirect call to absolute memory address |
| 1D70 | 402080 | .text | CALL [static] | Indirect call to absolute memory address |
| 1D9C | 402078 | .text | CALL [static] | Indirect call to absolute memory address |
| 1DD5 | 402070 | .text | CALL [static] | Indirect call to absolute memory address |
| 1E24 | 402058 | .text | CALL [static] | Indirect call to absolute memory address |
| 1E48 | 40203C | .text | CALL [static] | Indirect call to absolute memory address |
| 1E58 | 402068 | .text | CALL [static] | Indirect call to absolute memory address |
| 1E78 | 402060 | .text | CALL [static] | Indirect call to absolute memory address |
| 1E7E | 402064 | .text | JMP [static] | Indirect jump to absolute memory address |
| 1E84 | 402074 | .text | JMP [static] | Indirect jump to absolute memory address |
| 1EA0 | 40208C | .text | JMP [static] | Indirect jump to absolute memory address |
| 1EA6 | 402090 | .text | JMP [static] | Indirect jump to absolute memory address |
| 84ED | 60C54615 | .gentee | JMP [static] | Indirect jump to absolute memory address |
| 219FF | 60C54615 | .gentee | CALL [static] | Indirect call to absolute memory address |
| 27699 | 60C54615 | .gentee | JMP [static] | Indirect jump to absolute memory address |
| 2847D | 3399357 | .gentee | CALL [static] | Indirect call to absolute memory address |
| 29CC7 | 3399357 | .gentee | JMP [static] | Indirect jump to absolute memory address |
| 2E4A3 | 3399357 | .gentee | JMP [static] | Indirect jump to absolute memory address |
| 33B93 | 19344E74 | .gentee | JMP [static] | Indirect jump to absolute memory address |
| 49188 | 19344E74 | .gentee | JMP [static] | Indirect jump to absolute memory address |
| 4D0C9 | 19344E74 | .gentee | CALL [static] | Indirect call to absolute memory address |
| 5B01E | 414DED52 | .gentee | JMP [static] | Indirect jump to absolute memory address |
| 5EC95 | 2D2C3178 | .gentee | CALL [static] | Indirect call to absolute memory address |
| 60AED | 2D2C3178 | .gentee | CALL [static] | Indirect call to absolute memory address |
| 64869 | 2D2C3178 | .gentee | JMP [static] | Indirect jump to absolute memory address |
| 6F1DC | 2D2C3178 | .gentee | JMP [static] | Indirect jump to absolute memory address |
| 717E4 | 2D2C3178 | .gentee | CALL [static] | Indirect call to absolute memory address |
| 7B551 | 1F542C0D | .gentee | JMP [static] | Indirect jump to absolute memory address |
| 8234A | 5EF11A4F | .gentee | CALL [static] | Indirect call to absolute memory address |
| 83CBB | 5EF11A4F | .gentee | CALL [static] | Indirect call to absolute memory address |
| 8DD67 | 7F9E7BDB | .gentee | CALL [static] | Indirect call to absolute memory address |
| 959E1 | 7F9E7BDB | .gentee | CALL [static] | Indirect call to absolute memory address |
| 9CF06 | 7F9E7BDB | .gentee | CALL [static] | Indirect call to absolute memory address |
| 9DA0B | 7F9E7BDB | .gentee | CALL [static] | Indirect call to absolute memory address |
| B7BB9 | 7F9E7BDB | .gentee | CALL [static] | Indirect call to absolute memory address |
| BCE69 | 375E7929 | .gentee | CALL [static] | Indirect call to absolute memory address |
| C169A | 74822286 | .gentee | CALL [static] | Indirect call to absolute memory address |
| D38DF | ADCFF03 | .gentee | CALL [static] | Indirect call to absolute memory address |
| DEFA1 | 4AFA27 | .gentee | JMP [static] | Indirect jump to absolute memory address |
| FDDCB | 4AFA27 | .gentee | JMP [static] | Indirect jump to absolute memory address |
| 10FD91 | 4AFA27 | *padding* | JMP [static] | Indirect jump to absolute memory address |
| 110DC3 | 4AFA27 | *padding* | JMP [static] | Indirect jump to absolute memory address |
| 10E000 | N/A | *Overlay* | 00E0100056A8CA52500000001347D63465218733 | ....V..RP....G.4e!.3 |
| Extra Analysis |
| Metric | Value | Percentage |
|---|---|---|
| Ascii Code | 764347 | 68,0218% |
| Null Byte Code | 20139 | 1,7922% |
| NOP Cave Found | 0x9090909090 | Block Count: 17 | Total: 0,0038% |
© 2026 All rights reserved.