PREMIUM PESCAN.IO - Analysis Report |
|||||||
| File Structure |
|
PE Chart Code
Header PE (light blue)
Executable sections (pink)
Non-executable sections (black)
External injected code (red)
File Structure in red = malformed or corrupted header
Chart Code For Other Files
Printable characters (blue)
Non-printable characters (black)
| Information |
| Size: 1,08 MB SHA-256 Hash: 763AC38C6373A4D5BD820B904E934C459E57BEE6016B5325368A45F7F5B8753E SHA-1 Hash: E6D7F5D850B0593EDC1E358523168B7AF9FDE608 MD5 Hash: 1AB1A5888A6195491C8D56F2DFB89CC2 Imphash: 4335785F22C5B4F973BF218BDE712EE7 MajorOSVersion: 4 MinorOSVersion: 0 CheckSum: 00117CD3 EntryPoint (rva): 13B0 SizeOfHeaders: 400 SizeOfImage: 119000 ImageBase: 680C0000 Architecture: x86 ExportTable: 114000 ImportTable: 115000 IAT: 115108 Characteristics: 230E TimeDateStamp: 6AAD88AA Date: 18/09/2026 18:53:30 File Type: DLL Number Of Sections: 10 ASLR: Enabled Section Names: .text, .data, .rdata, .eh_fram, .bss, .edata, .idata, .CRT, .tls, .reloc Number Of Executable Sections: 1 Subsystem: Windows Console |
| Sections Info |
| Section Name | Flags | ROffset | RSize | VOffset | VSize | Entropy | Chi2 |
|---|---|---|---|---|---|---|---|
| .text | 0x60000060 Code Initialized Data Executable Readable |
400 | 1800 | 1000 | 1694 |
|
|
| .data | 0xC0000040 Initialized Data Readable Writeable |
1C00 | 200 | 3000 | 28 |
|
|
| .rdata | 0x40000040 Initialized Data Readable |
1E00 | 10D200 | 4000 | 10D054 |
|
|
| .eh_fram | 0x40000040 Initialized Data Readable |
10F000 | 200 | 112000 | 184 |
|
|
| .bss | 0xC0000080 Uninitialized Data Readable Writeable |
0 | 0 | 113000 | 8C |
|
|
| .edata | 0x40000040 Initialized Data Readable |
10F200 | 200 | 114000 | 48 |
|
|
| .idata | 0xC0000040 Initialized Data Readable Writeable |
10F400 | 600 | 115000 | 498 |
|
|
| .CRT | 0xC0000040 Initialized Data Readable Writeable |
10FA00 | 200 | 116000 | 2C |
|
|
| .tls | 0xC0000040 Initialized Data Readable Writeable |
10FC00 | 200 | 117000 | 8 |
|
|
| .reloc | 0x42000040 Initialized Data GP-Relative Readable |
10FE00 | 200 | 118000 | 1F4 |
|
|
| Binder/Joiner/Crypter |
| 2 Executable files found |
| Entry Point |
The section number (1) - (.text) have the Entry Point Information -> EntryPoint (calculated) - 7B0 Code -> 83EC0CC70540301D68000000008B4C24188B5424148B442410E852FEFFFF83C40CC20C008DB426000000008D7426009083EC Assembler |SUB ESP, 0XC |MOV DWORD PTR [0X681D3040], 0 |MOV ECX, DWORD PTR [ESP + 0X18] |MOV EDX, DWORD PTR [ESP + 0X14] |MOV EAX, DWORD PTR [ESP + 0X10] |CALL 0X680C1220 |ADD ESP, 0XC |RET 0XC |LEA ESI, [ESI] |LEA ESI, [ESI] |NOP |
| Signatures |
| Certificate - Digital Signature: • The file is signed and the signature is correct |
| Packer/Compiler |
| Detect It Easy (die) • PE: linker: GNU linker ld (GNU Binutils)(2.38)[-] • PE: Sign tool: Windows Authenticode(2.0)[PKCS 7] • Entropy: 6.24745 |
| Suspicious Functions |
| Library | Function | Description |
|---|---|---|
| KERNEL32.DLL | CopyFileW | Copies an existing file to a new file. |
| KERNEL32.DLL | WriteFile | Writes data to a specified file or input/output (I/O) device. |
| KERNEL32.DLL | LoadLibraryA | Loads the specified module into the address space of the calling process. |
| KERNEL32.DLL | GetModuleHandleA | Retrieves a handle to the specified module. |
| KERNEL32.DLL | GetProcAddress | Retrieves the address of an exported function or variable from the specified dynamic-link library (DLL). |
| KERNEL32.DLL | GetTempPathW | Retrieves the temporary directory path. |
| KERNEL32.DLL | CreateFileW | Creates or opens a file object. |
| KERNEL32.DLL | CloseHandle | Closes an open object handle. |
| KERNEL32.DLL | VirtualProtect | Changes memory protection attributes. |
| KERNEL32.DLL | CreateProcessW | Creates and starts a new process. |
| KERNEL32.DLL | CreateEventA | Creates or opens an event object. |
| KERNEL32.DLL | GetSystemInfo | Retrieves system hardware information. |
| SHELL32.DLL | ShellExecuteExW | Performs a run operation on a specific file. |
| ET Functions (carving) |
| Original Name -> goopdate.dll DllEntry |
| File Access |
| svchost.exe levelagent.exe USER32.dll SHELL32.dll msvcrt.dll KERNEL32.dll goopdate.dll libgcc_s_dw2-1.dll @.dat .dat Temp |
| File Access (UNICODE) |
| kta5rAgS7IPAmbVN.exe QueryPerformanceFrequencyQueryPerformanceCounterkernelbase.dll kernel32.dll KernelBase.dll sys.dll cam_numbers_1382bf.pdf |
| Interest's Words |
| exec start systeminfo ping expand |
| URLs |
| http://www.microsoft.com/pkiops/crl/Microsoft%20ID%20Verified%20CS%20AOC%20CA%2004.crl http://www.microsoft.com/pkiops/certs/Microsoft%20ID%20Verified%20CS%20AOC%20CA%2004.crt http://www.microsoft.com/pkiops/Docs/Repository.htm http://www.microsoft.com/pkiops/crl/Microsoft%20ID%20Verified%20Code%20Signing%20PCA%202021.crl http://www.microsoft.com/pkiops/certs/Microsoft%20ID%20Verified%20Code%20Signing%20PCA%202021.crt http://www.microsoft.com/pkiops/crl/Microsoft%20Identity%20Verification%20Root%20Certificate%20Authority%202020.crl http://www.microsoft.com/pkiops/certs/Microsoft%20Identity%20Verification%20Root%20Certificate%20Authority%202020.crt http://oneocsp.microsoft.com/ocsp0 http://www.microsoft.com/pkiops/crl/Microsoft%20Public%20RSA%20Timestamping%20CA%202020.crl http://www.microsoft.com/pkiops/certs/Microsoft%20Public%20RSA%20Timestamping%20CA%202020.crt |
| IP Addresses |
| 10.0.0.0 |
| PE Carving |
| Start Offset Header | End Offset | Size (Bytes) |
|---|---|---|
| 0 | 1F20 | 1F20 |
| 1F20 | 1139C0 | 111AA0 |
| Intelligent String |
| • OriginalFilename=svchost.exe • .tls • .CRT • @.bss • kta5rAgS7IPAmbVN.exe • cam_numbers_1382bf.pdf • sys.dll • KernelBase.dll • kernel32.dll • KERNEL32.dll • msvcrt.dll • PKERNEL32.dll |
| Flow Anomalies |
| Offset | FlowVA | Section | Description |
|---|---|---|---|
| 457 | 681D5148 | .text | CALL [static] | Indirect call to absolute memory address |
| 810 | 681D5130 | .text | CALL [static] | Indirect call to absolute memory address |
| 826 | 681D5144 | .text | CALL [static] | Indirect call to absolute memory address |
| 8D4 | 681D5124 | .text | CALL [static] | Indirect call to absolute memory address |
| 8FC | 681D5138 | .text | CALL [static] | Indirect call to absolute memory address |
| 971 | 681D5110 | .text | CALL [static] | Indirect call to absolute memory address |
| 9B4 | 681D5158 | .text | CALL [static] | Indirect call to absolute memory address |
| A8F | 681D5114 | .text | CALL [static] | Indirect call to absolute memory address |
| AF6 | 681D512C | .text | CALL [static] | Indirect call to absolute memory address |
| B4C | 681D510C | .text | CALL [static] | Indirect call to absolute memory address |
| B9A | 681D519C | .text | CALL [static] | Indirect call to absolute memory address |
| BB0 | 681D5128 | .text | CALL [static] | Indirect call to absolute memory address |
| C0F | 681D511C | .text | CALL [static] | Indirect call to absolute memory address |
| EDB | 681D5154 | .text | CALL [static] | Indirect call to absolute memory address |
| F43 | 681D5150 | .text | CALL [static] | Indirect call to absolute memory address |
| F50 | 681D5128 | .text | CALL [static] | Indirect call to absolute memory address |
| 123E | 681D5120 | .text | CALL [static] | Indirect call to absolute memory address |
| 128C | 681D5140 | .text | CALL [static] | Indirect call to absolute memory address |
| 12E2 | 681D5120 | .text | CALL [static] | Indirect call to absolute memory address |
| 1300 | 681D5140 | .text | CALL [static] | Indirect call to absolute memory address |
| 1347 | 681D5120 | .text | CALL [static] | Indirect call to absolute memory address |
| 1387 | 681D5140 | .text | CALL [static] | Indirect call to absolute memory address |
| 1407 | 681D513C | .text | CALL [static] | Indirect call to absolute memory address |
| 146C | 681D5118 | .text | CALL [static] | Indirect call to absolute memory address |
| 1890 | 681D5194 | .text | JMP [static] | Indirect jump to absolute memory address |
| 1898 | 681D5190 | .text | JMP [static] | Indirect jump to absolute memory address |
| 18A0 | 681D518C | .text | JMP [static] | Indirect jump to absolute memory address |
| 18A8 | 681D5188 | .text | JMP [static] | Indirect jump to absolute memory address |
| 18B0 | 681D5180 | .text | JMP [static] | Indirect jump to absolute memory address |
| 18B8 | 681D517C | .text | JMP [static] | Indirect jump to absolute memory address |
| 18C0 | 681D5178 | .text | JMP [static] | Indirect jump to absolute memory address |
| 18C8 | 681D5174 | .text | JMP [static] | Indirect jump to absolute memory address |
| 18D0 | 681D5164 | .text | JMP [static] | Indirect jump to absolute memory address |
| 18D8 | 681D5160 | .text | JMP [static] | Indirect jump to absolute memory address |
| 1A50 | 681D5184 | .text | JMP [static] | Indirect jump to absolute memory address |
| 1A58 | 681D5170 | .text | JMP [static] | Indirect jump to absolute memory address |
| 1A60 | 681D516C | .text | JMP [static] | Indirect jump to absolute memory address |
| 2588 | 87F86 | .rdata | CALL [static] | Indirect call to absolute memory address |
| 2793 | 87D5B | .rdata | CALL [static] | Indirect call to absolute memory address |
| 289C | 822C2 | .rdata | JMP [static] | Indirect jump to absolute memory address |
| 2981 | 87BDD | .rdata | JMP [static] | Indirect jump to absolute memory address |
| 2C99 | 87895 | .rdata | CALL [static] | Indirect call to absolute memory address |
| 2D7E | 877A8 | .rdata | CALL [static] | Indirect call to absolute memory address |
| 2D8C | 87752 | .rdata | CALL [static] | Indirect call to absolute memory address |
| 3320 | 871B6 | .rdata | CALL [static] | Indirect call to absolute memory address |
| 3375 | 87191 | .rdata | JMP [static] | Indirect jump to absolute memory address |
| 33C4 | 87112 | .rdata | CALL [static] | Indirect call to absolute memory address |
| 33E3 | 87123 | .rdata | CALL [static] | Indirect call to absolute memory address |
| 3427 | 870AF | .rdata | CALL [static] | Indirect call to absolute memory address |
| 346A | 8709C | .rdata | CALL [static] | Indirect call to absolute memory address |
| 34E7 | 87017 | .rdata | CALL [static] | Indirect call to absolute memory address |
| 354D | 86F81 | .rdata | CALL [static] | Indirect call to absolute memory address |
| 3990 | 86C96 | .rdata | JMP [static] | Indirect jump to absolute memory address |
| 3998 | 86C86 | .rdata | JMP [static] | Indirect jump to absolute memory address |
| 39A0 | 86C76 | .rdata | JMP [static] | Indirect jump to absolute memory address |
| 39A8 | 86C66 | .rdata | JMP [static] | Indirect jump to absolute memory address |
| 39B0 | 86C56 | .rdata | JMP [static] | Indirect jump to absolute memory address |
| 39B8 | 86C46 | .rdata | JMP [static] | Indirect jump to absolute memory address |
| 39C0 | 86C36 | .rdata | JMP [static] | Indirect jump to absolute memory address |
| 39C8 | 86C26 | .rdata | JMP [static] | Indirect jump to absolute memory address |
| 39D0 | 86C16 | .rdata | JMP [static] | Indirect jump to absolute memory address |
| 39D8 | 86C06 | .rdata | JMP [static] | Indirect jump to absolute memory address |
| 39E0 | 86BF6 | .rdata | JMP [static] | Indirect jump to absolute memory address |
| 39E8 | 86BE6 | .rdata | JMP [static] | Indirect jump to absolute memory address |
| 39F0 | 86BD6 | .rdata | JMP [static] | Indirect jump to absolute memory address |
| 39F8 | 86BC6 | .rdata | JMP [static] | Indirect jump to absolute memory address |
| 3A00 | 86BA6 | .rdata | JMP [static] | Indirect jump to absolute memory address |
| 3A08 | 86B96 | .rdata | JMP [static] | Indirect jump to absolute memory address |
| 3A10 | 86B76 | .rdata | JMP [static] | Indirect jump to absolute memory address |
| 3A18 | 86B66 | .rdata | JMP [static] | Indirect jump to absolute memory address |
| 3A20 | 86B4E | .rdata | JMP [static] | Indirect jump to absolute memory address |
| 3A28 | 86B3E | .rdata | JMP [static] | Indirect jump to absolute memory address |
| 3A30 | 86B16 | .rdata | JMP [static] | Indirect jump to absolute memory address |
| 3A38 | 86B06 | .rdata | JMP [static] | Indirect jump to absolute memory address |
| 3AB0 | 86AA6 | .rdata | JMP [static] | Indirect jump to absolute memory address |
| 3B07 | 86AA7 | .rdata | CALL [static] | Indirect call to absolute memory address |
| 3B6A | 86A4C | .rdata | CALL [static] | Indirect call to absolute memory address |
| 4386 | 84554 | .rdata | CALL [static] | Indirect call to absolute memory address |
| 4391 | 84541 | .rdata | CALL [static] | Indirect call to absolute memory address |
| 4406 | 844CC | .rdata | CALL [static] | Indirect call to absolute memory address |
| 72D1 | 844CC | .rdata | CALL [static] | Indirect call to absolute memory address |
| 9247 | 1624F962 | .rdata | JMP [static] | Indirect jump to absolute memory address |
| A46C | 1624F962 | .rdata | CALL [static] | Indirect call to absolute memory address |
| 142A0 | 1624F962 | .rdata | CALL [static] | Indirect call to absolute memory address |
| 22A11 | 426F9050 | .rdata | JMP [static] | Indirect jump to absolute memory address |
| 37148 | 51063DF0 | .rdata | JMP [static] | Indirect jump to absolute memory address |
| 3E89D | 51063DF0 | .rdata | CALL [static] | Indirect call to absolute memory address |
| 42D2A | 56F02B3F | .rdata | JMP [static] | Indirect jump to absolute memory address |
| 45B64 | 56F02B3F | .rdata | CALL [static] | Indirect call to absolute memory address |
| 4F5CA | 56F02B3F | .rdata | CALL [static] | Indirect call to absolute memory address |
| 54EC8 | 56F02B3F | .rdata | CALL [static] | Indirect call to absolute memory address |
| 64E24 | 2CC29B3F | .rdata | JMP [static] | Indirect jump to absolute memory address |
| 65A47 | 2CC29B3F | .rdata | JMP [static] | Indirect jump to absolute memory address |
| 6E944 | 2CC29B3F | .rdata | CALL [static] | Indirect call to absolute memory address |
| 81D05 | 2CC29B3F | .rdata | JMP [static] | Indirect jump to absolute memory address |
| 10FA18 | 680C1940 | .CRT | TLS Callback | Pointer to 1940 - 0xD40 .text |
| 10FA1C | 680C18F0 | .CRT | TLS Callback | Pointer to 18F0 - 0xCF0 .text |
| 110000 | N/A | *Overlay* | C039000000020200308239B306092A864886F70D | .9......0.9...*.H... |
| Extra Analysis |
| Metric | Value | Percentage |
|---|---|---|
| Ascii Code | 620456 | 54,9613% |
| Null Byte Code | 333696 | 29,5595% |
| NOP Cave Found | 0x9090909090 | Block Count: 56 | Total: 0,0124% |
© 2026 All rights reserved.