PESCAN.IO - Analysis Report Basic

File Structure
Analysis Image
PE Chart Code
Header PE (light blue)
Executable sections (pink)
Non-executable sections (black)
External injected code (red)
File Structure in red = malformed or corrupted header

Chart Code For Other Files
Printable characters (blue)
Non-printable characters (black)
Information
Icon: Icon
Size: 141,50 KB
SHA-256 Hash: FAC6ED314A0E64B23B1965808C1D17996DC02B2EDD969114CD7423309CBE4729
SHA-1 Hash: 7D40A1633E592245FECCE58740346B8F1D3575BD
MD5 Hash: 0F20699E36D83A8EDBAB87C9311E8F75
Imphash: 850F5AD9D549703C09FD08E5334C44E1
MajorOSVersion: 4
MinorOSVersion: 0
CheckSum: 00000000
EntryPoint (rva): 21240
SizeOfHeaders: 400
SizeOfImage: 2D000
ImageBase: 400000
Architecture: x86
ImportTable: 2C440
Characteristics: 20F
TimeDateStamp: 3C1A442E
Date: 14/12/2001 18:25:50
File Type: EXE
Number Of Sections: 6
ASLR: Disabled
Section Names: .text, .data, .bss, .idata, .rsrc, .protect
Number Of Executable Sections: 2
Subsystem: Windows Console

Sections Info
Section Name Flags ROffset RSize VOffset VSizeEntropyChi2
.text
0x60000020
Code
Executable
Readable
400 12400 1000 123C4
7.9926
798.17
.data
0xC0000040
Initialized Data
Readable
Writeable
12800 E00 14000 CD8
7.6022
7372.43
.bss
0xC0000080
Uninitialized Data
Readable
Writeable
0 0 15000 5F50
N/A
N/A
.idata
0xC0000040
Initialized Data
Readable
Writeable
13600 1400 1B000 137C
5.0066
127199.4
.rsrc
0xC0000040
Initialized Data
Readable
Writeable
14A00 3400 1D000 3360
5.1292
263975.46
.protect
0xE0000020
Code
Executable
Readable
Writeable
17E00 B800 21000 B6BF
7.9206
13866.42
Description
OriginalFilename: nhsrvice.exe
CompanyName: Aladdin Knowledge Systems
LegalCopyright: Copyright 1994-2001 Aladdin Knowledge Systems.
LegalTrademarks: Hasp is a trademark of AKS Ltd.
ProductName: NetHASP License Manager Service
FileVersion: 8.08
FileDescription: NetHASP License Manager Service
ProductVersion: 8.08
Comments: ** default version **
Language: English (United States) (ID=0x409)
CodePage: Unicode (UTF-16 LE) (0x4B0)

Binder/Joiner/Crypter
2 Executable files found

Entry Point
The section number (6) - (.protect) have the Entry Point
Information -> EntryPoint (calculated) - 18040
Code -> 558BEC535657608BC4A3D4144200B8001F42002B05201F4200A3201F4200833DD0144200000F8414000000A1D414420050FF
EP changed to another address -> (Address Of EntryPoint > Base Of Data)
Assembler
|PUSH EBP
|MOV EBP, ESP
|PUSH EBX
|PUSH ESI
|PUSH EDI
|PUSHAD
|MOV EAX, ESP
|MOV DWORD PTR [0X4214D4], EAX
|MOV EAX, 0X421F00
|SUB EAX, DWORD PTR [0X421F20]
|MOV DWORD PTR [0X421F20], EAX
|CMP DWORD PTR [0X4214D0], 0
|JE 0X42127F
|MOV EAX, DWORD PTR [0X4214D4]
|PUSH EAX
Signatures
Certificate - Digital Signature Not Found:
• The file is not signed

Packer/Compiler
Detect It Easy (die)
• PE: protector: HASP HL/SRM Protection(1.x)[HL]
• PE: compiler: MinGW(-)[-]
• PE: linker: GNU linker ld (GNU Binutils)(2.56*)[-]
• Entropy: 7.82686

Suspicious Functions
Library Function Description
KERNEL32.DLL CopyFileA Copies an existing file to a new file.
KERNEL32.DLL LoadLibraryA Loads the specified module into the address space of the calling process.
KERNEL32.DLL GetModuleHandleA Retrieves a handle to the specified module.
KERNEL32.DLL GetProcAddress Retrieves the address of an exported function or variable from the specified dynamic-link library (DLL).
KERNEL32.DLL CreateFileA Creates or opens a file or I/O device.
KERNEL32.DLL ReadFile Reads data from a file.
KERNEL32.DLL ExitThread Terminates the current thread.
KERNEL32.DLL CloseHandle Closes an open object handle.
KERNEL32.DLL WinExec Launches a specified application.
KERNEL32.DLL CreateSemaphoreA Creates or opens a semaphore object.
KERNEL32.DLL CreateEventA Creates or opens an event object.
KERNEL32.DLL GetVersion Retrieves the operating system version.
Ws2_32.DLL WSAStartup Initializes the Winsock networking library.
Ws2_32.DLL WSACleanup Releases Winsock networking resources.
Ws2_32.DLL bind Associates a socket with a local address.
Ws2_32.DLL listen Puts a socket into listening mode.
Ws2_32.DLL accept Accepts an incoming network connection.
Ws2_32.DLL recv Receives data from a network socket.
Ws2_32.DLL send Sends data through a network socket.
ADVAPI32.DLL OpenSCManagerA Opens the Service Control Manager.
ADVAPI32.DLL StartServiceCtrlDispatcherA Connects a service process to SCM.
File Access
WSOCK32.DLL
USER32.dll
SHELL32.DLL
NETAPI32.DLL
KERNEL32.dll
GDI32.dll
ADVAPI32.DLL
msvcrt40.dll
msvcrt.dll
.dat

File Access (UNICODE)
nhsrvice.exe

Interest's Words
exec
start
hostname
shutdown

Strings/Hex Code Found With The File Rules
Rule Type Encoding Matched (Word)
Text Ascii Software that records user activity (Logger)
Entry Point Hex Pattern MEW 10 packer v1.0 - Northfox
Resources
Path DataRVA Size FileOffset CodeText
\DLGINCLUDE\1\1031 1D3E4 14CF 14DE4 2F2A202449643A206E68737276776E742E682C7620312E3920323030312F30372F31372031343A33343A3037206368726973/* $Id: nhsrvwnt.h,v 1.9 2001/07/17 14:34:07 chris
\BITMAP\111\1031 1E8B4 1D0 162B4 2800000028000000120000000100040000000000680100000000000000000000000000000000000000000000000080000080(...(...............h.............................
\BITMAP\112\1031 1EA84 1D0 16484 2800000028000000120000000100040000000000680100000000000000000000000000000000000000000000000080000080(...(...............h.............................
\BITMAP\113\1031 1EC54 1D0 16654 2800000028000000120000000100040000000000680100000000000000000000000000000000000000000000000080000080(...(...............h.............................
\BITMAP\114\1031 1EE24 1D0 16824 2800000028000000120000000100040000000000680100000000000000000000000000000000000000000000000080000080(...(...............h.............................
\BITMAP\123\1031 1EFF4 1D0 169F4 2800000028000000120000000100040000000000680100000000000000000000000000000000000000000000000080000080(...(...............h.............................
\BITMAP\124\1031 1F1C4 1D0 16BC4 2800000028000000120000000100040000000000680100000000000000000000000000000000000000000000000080000080(...(...............h.............................
\BITMAP\130\1031 1F394 1D0 16D94 2800000028000000120000000100040000000000680100000000000000000000000000000000000000000000000080000080(...(...............h.............................
\ICON\1\1031 1F564 2E8 16F64 2800000020000000400000000100040000000000800200000000000000000000000000000000000000000000000080000080(... ...@.........................................
\ICON\2\1031 1F84C 2E8 1724C 2800000020000000400000000100040000000000800200000000000000000000000000000000000000000000000080000080(... ...@.........................................
\MENU\FIRSTMENU\1031 1FB34 120 17534 00000000100026004C006F0061006400000000006B0026004E0065007400420069006F007300000000007600260049005000......&.L.o.a.d.....k.&.N.e.t.B.i.o.s.....v.&.I.P.
\DIALOG\100\0 1FC54 234 17654 C000C89000000000050026002200D600840000000000410062006F0075007400200074006800650020004E00650074004800..........&.".........A.b.o.u.t. .t.h.e. .N.e.t.H.
\DIALOG\200\1033 1FE88 AC 17888 C000C8920000000003000B001000AF01EC00000000004100630074006900760069007400790020004C006F00670020000000......................A.c.t.i.v.i.t.y. .L.o.g. ...
\GROUP_ICON\103\1031 1FF34 14 17934 0000010001002020100001000400E80200000100...... ............
\GROUP_ICON\105\1031 1FF48 14 17948 0000010001002020100001000400E80200000200...... ............
\VERSION\1\1031 1FF5C 404 1795C 040434000000560053005F00560045005200530049004F004E005F0049004E0046004F0000000000BD04EFFE000001000800..4...V.S._.V.E.R.S.I.O.N._.I.N.F.O...............
Intelligent String
• KERNEL32.dll
• nhsrvice.exe
• .bss
• msvcrt.dll
• msvcrt40.dll
• ADVAPI32.DLL
• GDI32.dll
• NETAPI32.DLL
• USER32.dll
• WSOCK32.DLL

Flow Anomalies
Offset FlowVA Section Description
8F97 2D84BBE9 .text CALL [static] | Indirect call to absolute memory address
A812 2D84BBE9 .text JMP [static] | Indirect jump to absolute memory address
FA19 2D84BBE9 .text JMP [static] | Indirect jump to absolute memory address
12404 D4BB4EC .text JMP [static] | Indirect jump to absolute memory address
18071 4214D0 .protect CALL [static] | Indirect call to absolute memory address
18084 421F90 .protect CALL [static] | Indirect call to absolute memory address
18094 421F90 .protect CALL [static] | Indirect call to absolute memory address
18114 4214D0 .protect CALL [static] | Indirect call to absolute memory address
1B6AE 4214D0 .protect JMP [static] | Indirect jump to absolute memory address
17E00-235FF 21000 .protect Executable section anomaly, first bytes: 0000000000000000
Extra Analysis
Metric Value Percentage
Ascii Code 95302 65,7727%
Null Byte Code 7857 5,4225%
© 2026 All rights reserved.