PESCAN.IO - Analysis Report Basic |
|||||||
| File Structure |
|
PE Chart Code
Header PE (light blue)
Executable sections (pink)
Non-executable sections (black)
External injected code (red)
File Structure in red = malformed or corrupted header
Chart Code For Other Files
Printable characters (blue)
Non-printable characters (black)
| Information |
Icon: Size: 1,10 MBSHA-256 Hash: B34757F8821E2560D383651A9000AEAD93586B5E6F0C4050D1C071D51AB186EE SHA-1 Hash: 9F23225184C7725A31502D8632589DCEB4D86740 MD5 Hash: 0D837333C01AB8CDB6B87925F264D02B Imphash: BF5A4AA99E5B160F8521CADD6BFE73B8 MajorOSVersion: 5 MinorOSVersion: 0 CheckSum: 00023BFB EntryPoint (rva): CD2F SizeOfHeaders: 400 SizeOfImage: 11D000 ImageBase: 400000 Architecture: x86 ImportTable: 215B4 IAT: 1B000 Characteristics: 123 TimeDateStamp: 5000A574 Date: 13/07/2012 22:47:16 File Type: EXE Number Of Sections: 4 ASLR: Disabled Section Names: .text, .rdata, .data, .rsrc Number Of Executable Sections: 1 Subsystem: Windows GUI UAC Execution Level Manifest: requireAdministrator |
| Sections Info |
| Section Name | Flags | ROffset | RSize | VOffset | VSize | Entropy | Chi2 |
|---|---|---|---|---|---|---|---|
| .text | 0x60000020 Code Executable Readable |
400 | 19800 | 1000 | 19718 |
|
|
| .rdata | 0x40000040 Initialized Data Readable |
19C00 | 6E00 | 1B000 | 6DB4 |
|
|
| .data | 0xC0000040 Initialized Data Readable Writeable |
20A00 | 1600 | 22000 | 30C0 |
|
|
| .rsrc | 0x40000040 Initialized Data Readable |
22000 | F6E00 | 26000 | F6C70 |
|
|
| Description |
| OriginalFilename: DRMPlayer.exe CompanyName: Locking.ir LegalCopyright: Copyright 2016 ~ 2023 ProductName: DRMPlayer FileVersion: 7.9.5.0 FileDescription: DRMPlayer ProductVersion: 7.9.5.0 Comments: Digital rights management video player Language: Unknown (ID=0x0) CodePage: Unicode (UTF-16 LE) (0x4B0) |
| Entry Point |
The section number (1) - (.text) have the Entry Point Information -> EntryPoint (calculated) - C12F Code -> E8E15C0000E9A4FEFFFF8BFF558BEC83EC208B450856576A0859BE58F041008D7DE0F3A58945F88B450C5F8945FC5E85C074 Assembler |CALL 0X412A15 |JMP 0X40CBDD |MOV EDI, EDI |PUSH EBP |MOV EBP, ESP |SUB ESP, 0X20 |MOV EAX, DWORD PTR [EBP + 8] |PUSH ESI |PUSH EDI |PUSH 8 |POP ECX |MOV ESI, 0X41F058 |LEA EDI, [EBP - 0X20] |REP MOVSD DWORD PTR ES:[EDI], DWORD PTR [ESI] |MOV DWORD PTR [EBP - 8], EAX |MOV EAX, DWORD PTR [EBP + 0XC] |POP EDI |MOV DWORD PTR [EBP - 4], EAX |POP ESI |TEST EAX, EAX |
| Signatures |
| CheckSum Integrity Problem: • Header: 146427 • Calculated: 1168938 Rich Signature Analyzer: Code -> 6810842D2C71EA7E2C71EA7E2C71EA7E32237F7E3F71EA7E0BB7917E2B71EA7E2C71EB7E5C71EA7E32236E7E1C71EA7E3223697EA271EA7E32237B7E2D71EA7E526963682C71EA7E Footprint md5 Hash -> 4C3EAC799AF49F781DE85AD79DD64B01 • The Rich header apparently has not been modified Certificate - Digital Signature Not Found: • The file is not signed |
| Packer/Compiler |
| Compiler: Microsoft Visual C ++ Detect It Easy (die) • PE: protector: .NET Reactor(4.5-4.7)[-] • PE: compiler: EP:Microsoft Visual C/C++(2008-2010)[EXE32] • PE: compiler: Microsoft Visual C/C++(2008)[libcmt] • PE: linker: Microsoft Linker(9.0)[-] • Entropy: 7.47413 |
| Suspicious Functions |
| Library | Function | Description |
|---|---|---|
| KERNEL32.DLL | GetModuleFileNameA | Retrieve the fully qualified path for the executable file of a specified module. |
| KERNEL32.DLL | VirtualAlloc | Reserve, commit, or both, a region of memory within the virtual address space of a process. |
| KERNEL32.DLL | GetModuleHandleA | Retrieves a handle to the specified module. |
| KERNEL32.DLL | WriteFile | Writes data to a specified file or input/output (I/O) device. |
| KERNEL32.DLL | LoadLibraryA | Loads the specified module into the address space of the calling process. |
| KERNEL32.DLL | CreateToolhelp32Snapshot | Creates a snapshot of the specified processes, heaps, threads, and modules. |
| KERNEL32.DLL | GetProcAddress | Retrieves the address of an exported function or variable from the specified dynamic-link library (DLL). |
| KERNEL32.DLL | CreateFileA | Creates or opens a file or I/O device. |
| KERNEL32.DLL | IsDebuggerPresent | Determines if the calling process is being debugged by a user-mode debugger. |
| File Access |
| OLEAUT32.dll ole32.dll KERNEL32.dll USER32.DLL @.dat Temp |
| File Access (UNICODE) |
| DRMPlayer.exe KERNEL32.DLL CorExitProcessmscoree.dll |
| Interest's Words |
| PADDINGX exec start replace |
| URLs |
| http://schemas.microsoft.com/SMI/2005/WindowsSettings http://schemas.microsoft.com/SMI/2016/WindowsSettings https://docs.microsoft.com/windows/win32/fileio/maximum-file-path-limitation |
| Strings/Hex Code Found With The File Rules |
| Rule Type | Encoding | Matched (Word) |
|---|---|---|
| Text | Ascii | File (CreateFile) |
| Text | Ascii | File (WriteFile) |
| Text | Ascii | File (ReadFile) |
| Text | Ascii | Anti-Analysis VM (IsDebuggerPresent) |
| Text | Ascii | Anti-Analysis VM (CreateToolhelp32Snapshot) |
| Text | Ascii | Stealth (CloseHandle) |
| Text | Ascii | Stealth (VirtualAlloc) |
| Text | Ascii | Stealer malware focused on obtaining CVV codes to conduct unauthorized transactions (CVV) |
| Text | Ascii | Malware that monitors and collects user data (Spy) |
| Entry Point | Hex Pattern | Microsoft Visual C++ 8 |
| Entry Point | Hex Pattern | Microsoft Visual C++ 8 |
| Entry Point | Hex Pattern | Microsoft Visual C++ v7.0 |
| Entry Point | Hex Pattern | VC8 - Microsoft Corporation |
| Resources |
| Path | DataRVA | Size | FileOffset | Code | Text |
|---|---|---|---|---|---|
| \ICON\1\0 | 264E0 | 39F8 | 224E0 | 89504E470D0A1A0A0000000D49484452000001000000010008060000005C72A866000000097048597300000EC300000EC301 | .PNG........IHDR.............\r.f....pHYs......... |
| \ICON\2\0 | 29ED8 | 668 | 25ED8 | 2800000030000000600000000100040000000000800400000000000000000000000000000000000000000000000080000080 | (...0............................................ |
| \ICON\3\0 | 2A540 | 2E8 | 26540 | 2800000020000000400000000100040000000000000200000000000000000000000000000000000000000000000080000080 | (... ...@......................................... |
| \ICON\4\0 | 2A828 | 128 | 26828 | 2800000010000000200000000100040000000000800000000000000000000000000000000000000000000000000080000080 | (....... ......................................... |
| \ICON\5\0 | 2A950 | 87CC | 26950 | 89504E470D0A1A0A0000000D49484452000001000000010008060000005C72A866000000097048597300000EC300000EC301 | .PNG........IHDR.............\r.f....pHYs......... |
| \ICON\6\0 | 3311C | EA8 | 2F11C | 280000003000000060000000010008000000000000090000000000000000000000010000000100000000000004040C000C0C | (...0............................................ |
| \ICON\7\0 | 33FC4 | 8A8 | 2FFC4 | 2800000020000000400000000100080000000000000400000000000000000000000100000001000000000000020204000302 | (... ...@......................................... |
| \ICON\8\0 | 3486C | 568 | 3086C | 2800000010000000200000000100080000000000000100000000000000000000000100000001000000000000010104000A0A | (....... ......................................... |
| \ICON\9\0 | 34DD4 | 10828 | 30DD4 | 2800000080000000000100000100200000000000000801000000000000000000000000000000000000000000000000000000 | (............. ................................... |
| \ICON\10\0 | 455FC | 94A8 | 415FC | 2800000060000000C00000000100200000000000809400000000000000000000000000000000000000000000000000000000 | (............ ................................... |
| \ICON\11\0 | 4EAA4 | 67E8 | 4AAA4 | 2800000050000000A00000000100200000000000C06700000000000000000000000000000000000000000000000000000000 | (...P......... ......g............................ |
| \ICON\12\0 | 5528C | 5488 | 5128C | 2800000048000000900000000100200000000000605400000000000000000000000000000000000000000000000000000000 | (...H......... .....T............................ |
| \ICON\13\0 | 5A714 | 4228 | 56714 | 2800000040000000800000000100200000000000004200000000000000000000000000000000000000000000000000000000 | (...@......... ......B............................ |
| \ICON\14\0 | 5E93C | 3A48 | 5A93C | 280000003C000000780000000100200000000000203A00000000000000000000000000000000000000000000000000000000 | (...<...x..... ..... :............................ |
| \ICON\15\0 | 62384 | 25A8 | 5E384 | 2800000030000000600000000100200000000000802500000000000000000000000000000000000000000000000000000000 | (...0........ ......%............................ |
| \ICON\16\0 | 6492C | 1A68 | 6092C | 2800000028000000500000000100200000000000401A00000000000000000000000000000000000000000000000000000000 | (...(...P..... .....@............................. |
| \ICON\17\0 | 66394 | 10A8 | 62394 | 2800000020000000400000000100200000000000801000000000000000000000000000000000000000000000000000000000 | (... ...@..... ................................... |
| \ICON\18\0 | 6743C | 6B8 | 6343C | 2800000014000000280000000100200000000000900600000000000000000000000000000000000000000000000000000000 | (.......(..... ................................... |
| \ICON\19\0 | 67AF4 | 468 | 63AF4 | 2800000010000000200000000100200000000000400400000000000000000000000000000000000000000000000000000000 | (....... ..... .....@............................. |
| \RCDATA\__\0 | 67F5C | B3A65 | 63F5C | EC1B1A3B731189C35ACAAE0ADC8D55021FEFC35306348F46FCFBCCD4F08528FE6D84437E29EBC20BB03E88CBFB5750B96040 | ...;s...Z.....U....S.4.F......(.m.C~)....>...WP.@ |
| \GROUP_ICON\32512\0 | 11B9C4 | 110 | 1179C4 | 0000010013000000100001000400F8390000010030301000010004006806000002002020100001000400E802000003001010 | ...............9....00......h..... .............. |
| \VERSION\1\0 | 11BAD4 | 388 | 117AD4 | 880334000000560053005F00560045005200530049004F004E005F0049004E0046004F0000000000BD04EFFE000001000900 | ..4...V.S._.V.E.R.S.I.O.N._.I.N.F.O............... |
| \24\1\0 | 11BE5C | E14 | 117E5C | EFBBBF3C3F786D6C2076657273696F6E3D22312E302220656E636F64696E673D227574662D38223F3E0D0A3C617373656D62 | ...<?xml version="1.0" encoding="utf-8"?>..<assemb |
| Intelligent String |
| • 7.9.5.0 • DRMPlayer.exe • mscoree.dll • KERNEL32.DLL • Makes the application long-path aware. See https://docs.microsoft.com/windows/win32/fileio/maximum-file-path-limitation --> • <dpiAware xmlns="http://schemas.microsoft.com/SMI/2005/WindowsSettings">true</dpiAware> • <longPathAware xmlns="http://schemas.microsoft.com/SMI/2016/WindowsSettings">true</longPathAware> |
| Flow Anomalies |
| Offset | FlowVA | Section | Description |
|---|---|---|---|
| 41C | 41B000 | .text | CALL [static] | Indirect call to absolute memory address |
| 430 | 41B004 | .text | CALL [static] | Indirect call to absolute memory address |
| C98 | 41B174 | .text | CALL [static] | Indirect call to absolute memory address |
| D06 | 41B00C | .text | CALL [static] | Indirect call to absolute memory address |
| D2F | 41B008 | .text | CALL [static] | Indirect call to absolute memory address |
| D40 | 41B004 | .text | CALL [static] | Indirect call to absolute memory address |
| D58 | 41B008 | .text | CALL [static] | Indirect call to absolute memory address |
| D80 | 41B008 | .text | CALL [static] | Indirect call to absolute memory address |
| DAE | 41B010 | .text | CALL [static] | Indirect call to absolute memory address |
| DC3 | 41B170 | .text | CALL [static] | Indirect call to absolute memory address |
| DFD | 41B17C | .text | CALL [static] | Indirect call to absolute memory address |
| ECD | 41B044 | .text | CALL [static] | Indirect call to absolute memory address |
| 109D | 41B038 | .text | CALL [static] | Indirect call to absolute memory address |
| 11C4 | 41B038 | .text | CALL [static] | Indirect call to absolute memory address |
| 11CB | 41B030 | .text | CALL [static] | Indirect call to absolute memory address |
| 1290 | 41B02C | .text | CALL [static] | Indirect call to absolute memory address |
| 129E | 41B028 | .text | CALL [static] | Indirect call to absolute memory address |
| 12A7 | 41B024 | .text | CALL [static] | Indirect call to absolute memory address |
| 12B3 | 41B020 | .text | CALL [static] | Indirect call to absolute memory address |
| 1302 | 41B020 | .text | CALL [static] | Indirect call to absolute memory address |
| 13A6 | 41B01C | .text | CALL [static] | Indirect call to absolute memory address |
| 13C8 | 41B020 | .text | CALL [static] | Indirect call to absolute memory address |
| 14AE | 41B018 | .text | CALL [static] | Indirect call to absolute memory address |
| 1571 | 41B014 | .text | CALL [static] | Indirect call to absolute memory address |
| 16F6 | 41B154 | .text | CALL [static] | Indirect call to absolute memory address |
| 1708 | 41B158 | .text | CALL [static] | Indirect call to absolute memory address |
| 171E | 41B15C | .text | CALL [static] | Indirect call to absolute memory address |
| 1755 | 41B160 | .text | CALL [static] | Indirect call to absolute memory address |
| 1796 | 41B164 | .text | CALL [static] | Indirect call to absolute memory address |
| A17C | 41B034 | .text | JMP [static] | Indirect jump to absolute memory address |
| A182 | 41B03C | .text | JMP [static] | Indirect jump to absolute memory address |
| A188 | 41B040 | .text | JMP [static] | Indirect jump to absolute memory address |
| A19B | 42203C | .text | CALL [static] | Indirect call to absolute memory address |
| A1D0 | 41B064 | .text | CALL [static] | Indirect call to absolute memory address |
| A1E1 | 41B060 | .text | CALL [static] | Indirect call to absolute memory address |
| A293 | 41B064 | .text | CALL [static] | Indirect call to absolute memory address |
| A2A4 | 41B060 | .text | CALL [static] | Indirect call to absolute memory address |
| AB1D | 41B060 | .text | CALL [static] | Indirect call to absolute memory address |
| AB2E | 41B004 | .text | CALL [static] | Indirect call to absolute memory address |
| C072 | 41B06C | .text | CALL [static] | Indirect call to absolute memory address |
| C17B | 41B000 | .text | CALL [static] | Indirect call to absolute memory address |
| C32A | 4250B8 | .text | CALL [static] | Indirect call to absolute memory address |
| C949 | 41B070 | .text | CALL [static] | Indirect call to absolute memory address |
| CA15 | 41B07C | .text | CALL [static] | Indirect call to absolute memory address |
| CB0A | 41B080 | .text | CALL [static] | Indirect call to absolute memory address |
| CDF9 | 41B060 | .text | CALL [static] | Indirect call to absolute memory address |
| CE80 | 41B088 | .text | CALL [static] | Indirect call to absolute memory address |
| CEB6 | 41B068 | .text | CALL [static] | Indirect call to absolute memory address |
| CED0 | 41B084 | .text | CALL [static] | Indirect call to absolute memory address |
| CEE7 | 41B060 | .text | CALL [static] | Indirect call to absolute memory address |
| CF5D | 41B084 | .text | CALL [static] | Indirect call to absolute memory address |
| D6EF | 41B068 | .text | CALL [static] | Indirect call to absolute memory address |
| D82C | 41B068 | .text | CALL [static] | Indirect call to absolute memory address |
| D883 | 41B088 | .text | CALL [static] | Indirect call to absolute memory address |
| D8CA | 41B004 | .text | CALL [static] | Indirect call to absolute memory address |
| D904 | 41B088 | .text | CALL [static] | Indirect call to absolute memory address |
| D957 | 41B004 | .text | CALL [static] | Indirect call to absolute memory address |
| D9EC | 41B08C | .text | CALL [static] | Indirect call to absolute memory address |
| DAF8 | 41B0A0 | .text | CALL [static] | Indirect call to absolute memory address |
| DB02 | 41B09C | .text | CALL [static] | Indirect call to absolute memory address |
| DB0F | 41B098 | .text | CALL [static] | Indirect call to absolute memory address |
| DB2A | 41B094 | .text | CALL [static] | Indirect call to absolute memory address |
| DB31 | 41B090 | .text | CALL [static] | Indirect call to absolute memory address |
| DB76 | 41B0A8 | .text | CALL [static] | Indirect call to absolute memory address |
| DB7F | 41B0A4 | .text | CALL [static] | Indirect call to absolute memory address |
| DBCD | 41B0A4 | .text | CALL [static] | Indirect call to absolute memory address |
| DBDD | 41B014 | .text | CALL [static] | Indirect call to absolute memory address |
| DBFF | 41B0AC | .text | CALL [static] | Indirect call to absolute memory address |
| DC79 | 41F078 | .text | CALL [static] | Indirect call to absolute memory address |
| DCD4 | 425094 | .text | CALL [static] | Indirect call to absolute memory address |
| DF45 | 41B0B8 | .text | CALL [static] | Indirect call to absolute memory address |
| E018 | 41B0B4 | .text | CALL [static] | Indirect call to absolute memory address |
| E042 | 41B0B0 | .text | CALL [static] | Indirect call to absolute memory address |
| E738 | 41B0C4 | .text | CALL [static] | Indirect call to absolute memory address |
| E758 | 41B0C0 | .text | CALL [static] | Indirect call to absolute memory address |
| E848 | 41B0BC | .text | CALL [static] | Indirect call to absolute memory address |
| E871 | 41B0B0 | .text | CALL [static] | Indirect call to absolute memory address |
| E8CA | 41B0B0 | .text | CALL [static] | Indirect call to absolute memory address |
| EA58 | 41B0B0 | .text | CALL [static] | Indirect call to absolute memory address |
| EB38 | 41B0B0 | .text | CALL [static] | Indirect call to absolute memory address |
| EC01 | 41B0BC | .text | CALL [static] | Indirect call to absolute memory address |
| EC32 | 41B0B0 | .text | CALL [static] | Indirect call to absolute memory address |
| EC48 | 41B004 | .text | CALL [static] | Indirect call to absolute memory address |
| EC89 | 41B0B0 | .text | CALL [static] | Indirect call to absolute memory address |
| ECA8 | 41B004 | .text | CALL [static] | Indirect call to absolute memory address |
| EF61 | 41B080 | .text | CALL [static] | Indirect call to absolute memory address |
| EF94 | 41B080 | .text | CALL [static] | Indirect call to absolute memory address |
| EFD0 | 41B07C | .text | CALL [static] | Indirect call to absolute memory address |
| EFFF | 41B07C | .text | CALL [static] | Indirect call to absolute memory address |
| F32F | 41B0C8 | .text | CALL [static] | Indirect call to absolute memory address |
| F3E7 | 41B0C8 | .text | CALL [static] | Indirect call to absolute memory address |
| F3F1 | 41B004 | .text | CALL [static] | Indirect call to absolute memory address |
| F52B | 41B008 | .text | CALL [static] | Indirect call to absolute memory address |
| F538 | 41B004 | .text | CALL [static] | Indirect call to absolute memory address |
| F610 | 41B0C8 | .text | CALL [static] | Indirect call to absolute memory address |
| F61A | 41B004 | .text | CALL [static] | Indirect call to absolute memory address |
| F6B8 | 41B004 | .text | CALL [static] | Indirect call to absolute memory address |
| F8AD | 41B0A4 | .text | CALL [static] | Indirect call to absolute memory address |
| F8C8 | 41B014 | .text | CALL [static] | Indirect call to absolute memory address |
| F928 | 41B0A4 | .text | CALL [static] | Indirect call to absolute memory address |
| 9B-A8 | N/A | *header* | Potential obfuscated jump sequence detected, count: 7 |
| Extra Analysis |
| Metric | Value | Percentage |
|---|---|---|
| Ascii Code | 674365 | 58,6168% |
| Null Byte Code | 136487 | 11,8636% |
© 2026 All rights reserved.