PESCAN.IO - Analysis Report Basic

File Structure
Analysis Image
PE Chart Code
Header PE (light blue)
Executable sections (pink)
Non-executable sections (black)
External injected code (red)
File Structure in red = malformed or corrupted header

Chart Code For Other Files
Printable characters (blue)
Non-printable characters (black)
Information
Icon: Icon
Size: 1,10 MB
SHA-256 Hash: B34757F8821E2560D383651A9000AEAD93586B5E6F0C4050D1C071D51AB186EE
SHA-1 Hash: 9F23225184C7725A31502D8632589DCEB4D86740
MD5 Hash: 0D837333C01AB8CDB6B87925F264D02B
Imphash: BF5A4AA99E5B160F8521CADD6BFE73B8
MajorOSVersion: 5
MinorOSVersion: 0
CheckSum: 00023BFB
EntryPoint (rva): CD2F
SizeOfHeaders: 400
SizeOfImage: 11D000
ImageBase: 400000
Architecture: x86
ImportTable: 215B4
IAT: 1B000
Characteristics: 123
TimeDateStamp: 5000A574
Date: 13/07/2012 22:47:16
File Type: EXE
Number Of Sections: 4
ASLR: Disabled
Section Names: .text, .rdata, .data, .rsrc
Number Of Executable Sections: 1
Subsystem: Windows GUI
UAC Execution Level Manifest: requireAdministrator

Sections Info
Section Name Flags ROffset RSize VOffset VSizeEntropyChi2
.text
0x60000020
Code
Executable
Readable
400 19800 1000 19718
6.7485
505402.35
.rdata
0x40000040
Initialized Data
Readable
19C00 6E00 1B000 6DB4
6.443
416895.69
.data
0xC0000040
Initialized Data
Readable
Writeable
20A00 1600 22000 30C0
3.2626
645695.36
.rsrc
0x40000040
Initialized Data
Readable
22000 F6E00 26000 F6C70
7.5197
3325141.08
Description
OriginalFilename: DRMPlayer.exe
CompanyName: Locking.ir
LegalCopyright: Copyright 2016 ~ 2023
ProductName: DRMPlayer
FileVersion: 7.9.5.0
FileDescription: DRMPlayer
ProductVersion: 7.9.5.0
Comments: Digital rights management video player
Language: Unknown (ID=0x0)
CodePage: Unicode (UTF-16 LE) (0x4B0)

Entry Point
The section number (1) - (.text) have the Entry Point
Information -> EntryPoint (calculated) - C12F
Code -> E8E15C0000E9A4FEFFFF8BFF558BEC83EC208B450856576A0859BE58F041008D7DE0F3A58945F88B450C5F8945FC5E85C074
Assembler
|CALL 0X412A15
|JMP 0X40CBDD
|MOV EDI, EDI
|PUSH EBP
|MOV EBP, ESP
|SUB ESP, 0X20
|MOV EAX, DWORD PTR [EBP + 8]
|PUSH ESI
|PUSH EDI
|PUSH 8
|POP ECX
|MOV ESI, 0X41F058
|LEA EDI, [EBP - 0X20]
|REP MOVSD DWORD PTR ES:[EDI], DWORD PTR [ESI]
|MOV DWORD PTR [EBP - 8], EAX
|MOV EAX, DWORD PTR [EBP + 0XC]
|POP EDI
|MOV DWORD PTR [EBP - 4], EAX
|POP ESI
|TEST EAX, EAX
Signatures
CheckSum Integrity Problem:
Header: 146427
Calculated: 1168938
Rich Signature Analyzer:
Code -> 6810842D2C71EA7E2C71EA7E2C71EA7E32237F7E3F71EA7E0BB7917E2B71EA7E2C71EB7E5C71EA7E32236E7E1C71EA7E3223697EA271EA7E32237B7E2D71EA7E526963682C71EA7E
Footprint md5 Hash -> 4C3EAC799AF49F781DE85AD79DD64B01
• The Rich header apparently has not been modified
Certificate - Digital Signature Not Found:
• The file is not signed

Packer/Compiler
Compiler: Microsoft Visual C ++
Detect It Easy (die)
PE: protector: .NET Reactor(4.5-4.7)[-]
PE: compiler: EP:Microsoft Visual C/C++(2008-2010)[EXE32]
PE: compiler: Microsoft Visual C/C++(2008)[libcmt]
PE: linker: Microsoft Linker(9.0)[-]
Entropy: 7.47413

Suspicious Functions
Library Function Description
KERNEL32.DLL GetModuleFileNameA Retrieve the fully qualified path for the executable file of a specified module.
KERNEL32.DLL VirtualAlloc Reserve, commit, or both, a region of memory within the virtual address space of a process.
KERNEL32.DLL GetModuleHandleA Retrieves a handle to the specified module.
KERNEL32.DLL WriteFile Writes data to a specified file or input/output (I/O) device.
KERNEL32.DLL LoadLibraryA Loads the specified module into the address space of the calling process.
KERNEL32.DLL CreateToolhelp32Snapshot Creates a snapshot of the specified processes, heaps, threads, and modules.
KERNEL32.DLL GetProcAddress Retrieves the address of an exported function or variable from the specified dynamic-link library (DLL).
KERNEL32.DLL CreateFileA Creates or opens a file or I/O device.
KERNEL32.DLL IsDebuggerPresent Determines if the calling process is being debugged by a user-mode debugger.
File Access
OLEAUT32.dll
ole32.dll
KERNEL32.dll
USER32.DLL
@.dat
Temp

File Access (UNICODE)
DRMPlayer.exe
KERNEL32.DLL
CorExitProcessmscoree.dll

Interest's Words
PADDINGX
exec
start
replace

URLs
http://schemas.microsoft.com/SMI/2005/WindowsSettings
http://schemas.microsoft.com/SMI/2016/WindowsSettings
https://docs.microsoft.com/windows/win32/fileio/maximum-file-path-limitation

Strings/Hex Code Found With The File Rules
Rule Type Encoding Matched (Word)
Text Ascii File (CreateFile)
Text Ascii File (WriteFile)
Text Ascii File (ReadFile)
Text Ascii Anti-Analysis VM (IsDebuggerPresent)
Text Ascii Anti-Analysis VM (CreateToolhelp32Snapshot)
Text Ascii Stealth (CloseHandle)
Text Ascii Stealth (VirtualAlloc)
Text Ascii Stealer malware focused on obtaining CVV codes to conduct unauthorized transactions (CVV)
Text Ascii Malware that monitors and collects user data (Spy)
Entry Point Hex Pattern Microsoft Visual C++ 8
Entry Point Hex Pattern Microsoft Visual C++ 8
Entry Point Hex Pattern Microsoft Visual C++ v7.0
Entry Point Hex Pattern VC8 - Microsoft Corporation
Resources
Path DataRVA Size FileOffset CodeText
\ICON\1\0 264E0 39F8 224E0 89504E470D0A1A0A0000000D49484452000001000000010008060000005C72A866000000097048597300000EC300000EC301.PNG........IHDR.............\r.f....pHYs.........
\ICON\2\0 29ED8 668 25ED8 2800000030000000600000000100040000000000800400000000000000000000000000000000000000000000000080000080(...0............................................
\ICON\3\0 2A540 2E8 26540 2800000020000000400000000100040000000000000200000000000000000000000000000000000000000000000080000080(... ...@.........................................
\ICON\4\0 2A828 128 26828 2800000010000000200000000100040000000000800000000000000000000000000000000000000000000000000080000080(....... .........................................
\ICON\5\0 2A950 87CC 26950 89504E470D0A1A0A0000000D49484452000001000000010008060000005C72A866000000097048597300000EC300000EC301.PNG........IHDR.............\r.f....pHYs.........
\ICON\6\0 3311C EA8 2F11C 280000003000000060000000010008000000000000090000000000000000000000010000000100000000000004040C000C0C(...0............................................
\ICON\7\0 33FC4 8A8 2FFC4 2800000020000000400000000100080000000000000400000000000000000000000100000001000000000000020204000302(... ...@.........................................
\ICON\8\0 3486C 568 3086C 2800000010000000200000000100080000000000000100000000000000000000000100000001000000000000010104000A0A(....... .........................................
\ICON\9\0 34DD4 10828 30DD4 2800000080000000000100000100200000000000000801000000000000000000000000000000000000000000000000000000(............. ...................................
\ICON\10\0 455FC 94A8 415FC 2800000060000000C00000000100200000000000809400000000000000000000000000000000000000000000000000000000(............ ...................................
\ICON\11\0 4EAA4 67E8 4AAA4 2800000050000000A00000000100200000000000C06700000000000000000000000000000000000000000000000000000000(...P......... ......g............................
\ICON\12\0 5528C 5488 5128C 2800000048000000900000000100200000000000605400000000000000000000000000000000000000000000000000000000(...H......... .....T............................
\ICON\13\0 5A714 4228 56714 2800000040000000800000000100200000000000004200000000000000000000000000000000000000000000000000000000(...@......... ......B............................
\ICON\14\0 5E93C 3A48 5A93C 280000003C000000780000000100200000000000203A00000000000000000000000000000000000000000000000000000000(...<...x..... ..... :............................
\ICON\15\0 62384 25A8 5E384 2800000030000000600000000100200000000000802500000000000000000000000000000000000000000000000000000000(...0........ ......%............................
\ICON\16\0 6492C 1A68 6092C 2800000028000000500000000100200000000000401A00000000000000000000000000000000000000000000000000000000(...(...P..... .....@.............................
\ICON\17\0 66394 10A8 62394 2800000020000000400000000100200000000000801000000000000000000000000000000000000000000000000000000000(... ...@..... ...................................
\ICON\18\0 6743C 6B8 6343C 2800000014000000280000000100200000000000900600000000000000000000000000000000000000000000000000000000(.......(..... ...................................
\ICON\19\0 67AF4 468 63AF4 2800000010000000200000000100200000000000400400000000000000000000000000000000000000000000000000000000(....... ..... .....@.............................
\RCDATA\__\0 67F5C B3A65 63F5C EC1B1A3B731189C35ACAAE0ADC8D55021FEFC35306348F46FCFBCCD4F08528FE6D84437E29EBC20BB03E88CBFB5750B96040...;s...Z.....U....S.4.F......(.m.C~)....>...WP.@
\GROUP_ICON\32512\0 11B9C4 110 1179C4 0000010013000000100001000400F8390000010030301000010004006806000002002020100001000400E802000003001010...............9....00......h..... ..............
\VERSION\1\0 11BAD4 388 117AD4 880334000000560053005F00560045005200530049004F004E005F0049004E0046004F0000000000BD04EFFE000001000900..4...V.S._.V.E.R.S.I.O.N._.I.N.F.O...............
\24\1\0 11BE5C E14 117E5C EFBBBF3C3F786D6C2076657273696F6E3D22312E302220656E636F64696E673D227574662D38223F3E0D0A3C617373656D62...<?xml version="1.0" encoding="utf-8"?>..<assemb
Intelligent String
• 7.9.5.0
• DRMPlayer.exe
• mscoree.dll
• KERNEL32.DLL
• Makes the application long-path aware. See https://docs.microsoft.com/windows/win32/fileio/maximum-file-path-limitation -->
• <dpiAware xmlns="http://schemas.microsoft.com/SMI/2005/WindowsSettings">true</dpiAware>
• <longPathAware xmlns="http://schemas.microsoft.com/SMI/2016/WindowsSettings">true</longPathAware>

Flow Anomalies
Offset FlowVA Section Description
41C 41B000 .text CALL [static] | Indirect call to absolute memory address
430 41B004 .text CALL [static] | Indirect call to absolute memory address
C98 41B174 .text CALL [static] | Indirect call to absolute memory address
D06 41B00C .text CALL [static] | Indirect call to absolute memory address
D2F 41B008 .text CALL [static] | Indirect call to absolute memory address
D40 41B004 .text CALL [static] | Indirect call to absolute memory address
D58 41B008 .text CALL [static] | Indirect call to absolute memory address
D80 41B008 .text CALL [static] | Indirect call to absolute memory address
DAE 41B010 .text CALL [static] | Indirect call to absolute memory address
DC3 41B170 .text CALL [static] | Indirect call to absolute memory address
DFD 41B17C .text CALL [static] | Indirect call to absolute memory address
ECD 41B044 .text CALL [static] | Indirect call to absolute memory address
109D 41B038 .text CALL [static] | Indirect call to absolute memory address
11C4 41B038 .text CALL [static] | Indirect call to absolute memory address
11CB 41B030 .text CALL [static] | Indirect call to absolute memory address
1290 41B02C .text CALL [static] | Indirect call to absolute memory address
129E 41B028 .text CALL [static] | Indirect call to absolute memory address
12A7 41B024 .text CALL [static] | Indirect call to absolute memory address
12B3 41B020 .text CALL [static] | Indirect call to absolute memory address
1302 41B020 .text CALL [static] | Indirect call to absolute memory address
13A6 41B01C .text CALL [static] | Indirect call to absolute memory address
13C8 41B020 .text CALL [static] | Indirect call to absolute memory address
14AE 41B018 .text CALL [static] | Indirect call to absolute memory address
1571 41B014 .text CALL [static] | Indirect call to absolute memory address
16F6 41B154 .text CALL [static] | Indirect call to absolute memory address
1708 41B158 .text CALL [static] | Indirect call to absolute memory address
171E 41B15C .text CALL [static] | Indirect call to absolute memory address
1755 41B160 .text CALL [static] | Indirect call to absolute memory address
1796 41B164 .text CALL [static] | Indirect call to absolute memory address
A17C 41B034 .text JMP [static] | Indirect jump to absolute memory address
A182 41B03C .text JMP [static] | Indirect jump to absolute memory address
A188 41B040 .text JMP [static] | Indirect jump to absolute memory address
A19B 42203C .text CALL [static] | Indirect call to absolute memory address
A1D0 41B064 .text CALL [static] | Indirect call to absolute memory address
A1E1 41B060 .text CALL [static] | Indirect call to absolute memory address
A293 41B064 .text CALL [static] | Indirect call to absolute memory address
A2A4 41B060 .text CALL [static] | Indirect call to absolute memory address
AB1D 41B060 .text CALL [static] | Indirect call to absolute memory address
AB2E 41B004 .text CALL [static] | Indirect call to absolute memory address
C072 41B06C .text CALL [static] | Indirect call to absolute memory address
C17B 41B000 .text CALL [static] | Indirect call to absolute memory address
C32A 4250B8 .text CALL [static] | Indirect call to absolute memory address
C949 41B070 .text CALL [static] | Indirect call to absolute memory address
CA15 41B07C .text CALL [static] | Indirect call to absolute memory address
CB0A 41B080 .text CALL [static] | Indirect call to absolute memory address
CDF9 41B060 .text CALL [static] | Indirect call to absolute memory address
CE80 41B088 .text CALL [static] | Indirect call to absolute memory address
CEB6 41B068 .text CALL [static] | Indirect call to absolute memory address
CED0 41B084 .text CALL [static] | Indirect call to absolute memory address
CEE7 41B060 .text CALL [static] | Indirect call to absolute memory address
CF5D 41B084 .text CALL [static] | Indirect call to absolute memory address
D6EF 41B068 .text CALL [static] | Indirect call to absolute memory address
D82C 41B068 .text CALL [static] | Indirect call to absolute memory address
D883 41B088 .text CALL [static] | Indirect call to absolute memory address
D8CA 41B004 .text CALL [static] | Indirect call to absolute memory address
D904 41B088 .text CALL [static] | Indirect call to absolute memory address
D957 41B004 .text CALL [static] | Indirect call to absolute memory address
D9EC 41B08C .text CALL [static] | Indirect call to absolute memory address
DAF8 41B0A0 .text CALL [static] | Indirect call to absolute memory address
DB02 41B09C .text CALL [static] | Indirect call to absolute memory address
DB0F 41B098 .text CALL [static] | Indirect call to absolute memory address
DB2A 41B094 .text CALL [static] | Indirect call to absolute memory address
DB31 41B090 .text CALL [static] | Indirect call to absolute memory address
DB76 41B0A8 .text CALL [static] | Indirect call to absolute memory address
DB7F 41B0A4 .text CALL [static] | Indirect call to absolute memory address
DBCD 41B0A4 .text CALL [static] | Indirect call to absolute memory address
DBDD 41B014 .text CALL [static] | Indirect call to absolute memory address
DBFF 41B0AC .text CALL [static] | Indirect call to absolute memory address
DC79 41F078 .text CALL [static] | Indirect call to absolute memory address
DCD4 425094 .text CALL [static] | Indirect call to absolute memory address
DF45 41B0B8 .text CALL [static] | Indirect call to absolute memory address
E018 41B0B4 .text CALL [static] | Indirect call to absolute memory address
E042 41B0B0 .text CALL [static] | Indirect call to absolute memory address
E738 41B0C4 .text CALL [static] | Indirect call to absolute memory address
E758 41B0C0 .text CALL [static] | Indirect call to absolute memory address
E848 41B0BC .text CALL [static] | Indirect call to absolute memory address
E871 41B0B0 .text CALL [static] | Indirect call to absolute memory address
E8CA 41B0B0 .text CALL [static] | Indirect call to absolute memory address
EA58 41B0B0 .text CALL [static] | Indirect call to absolute memory address
EB38 41B0B0 .text CALL [static] | Indirect call to absolute memory address
EC01 41B0BC .text CALL [static] | Indirect call to absolute memory address
EC32 41B0B0 .text CALL [static] | Indirect call to absolute memory address
EC48 41B004 .text CALL [static] | Indirect call to absolute memory address
EC89 41B0B0 .text CALL [static] | Indirect call to absolute memory address
ECA8 41B004 .text CALL [static] | Indirect call to absolute memory address
EF61 41B080 .text CALL [static] | Indirect call to absolute memory address
EF94 41B080 .text CALL [static] | Indirect call to absolute memory address
EFD0 41B07C .text CALL [static] | Indirect call to absolute memory address
EFFF 41B07C .text CALL [static] | Indirect call to absolute memory address
F32F 41B0C8 .text CALL [static] | Indirect call to absolute memory address
F3E7 41B0C8 .text CALL [static] | Indirect call to absolute memory address
F3F1 41B004 .text CALL [static] | Indirect call to absolute memory address
F52B 41B008 .text CALL [static] | Indirect call to absolute memory address
F538 41B004 .text CALL [static] | Indirect call to absolute memory address
F610 41B0C8 .text CALL [static] | Indirect call to absolute memory address
F61A 41B004 .text CALL [static] | Indirect call to absolute memory address
F6B8 41B004 .text CALL [static] | Indirect call to absolute memory address
F8AD 41B0A4 .text CALL [static] | Indirect call to absolute memory address
F8C8 41B014 .text CALL [static] | Indirect call to absolute memory address
F928 41B0A4 .text CALL [static] | Indirect call to absolute memory address
9B-A8 N/A *header* Potential obfuscated jump sequence detected, count: 7
Extra Analysis
Metric Value Percentage
Ascii Code 674365 58,6168%
Null Byte Code 136487 11,8636%
© 2026 All rights reserved.