PREMIUM PESCAN.IO - Analysis Report

File Structure
Analysis Image
PE Chart Code
Header PE (light blue)
Executable sections (pink)
Non-executable sections (black)
External injected code (red)
File Structure in red = malformed or corrupted header

Chart Code For Other Files
Printable characters (blue)
Non-printable characters (black)
Information
Size: 1,08 MB
SHA-256 Hash: 763AC38C6373A4D5BD820B904E934C459E57BEE6016B5325368A45F7F5B8753E
SHA-1 Hash: E6D7F5D850B0593EDC1E358523168B7AF9FDE608
MD5 Hash: 1AB1A5888A6195491C8D56F2DFB89CC2
Imphash: 4335785F22C5B4F973BF218BDE712EE7
MajorOSVersion: 4
MinorOSVersion: 0
CheckSum: 00117CD3
EntryPoint (rva): 13B0
SizeOfHeaders: 400
SizeOfImage: 119000
ImageBase: 680C0000
Architecture: x86
ExportTable: 114000
ImportTable: 115000
IAT: 115108
Characteristics: 230E
TimeDateStamp: 6AAD88AA
Date: 18/09/2026 18:53:30
File Type: DLL
Number Of Sections: 10
ASLR: Enabled
Section Names: .text, .data, .rdata, .eh_fram, .bss, .edata, .idata, .CRT, .tls, .reloc
Number Of Executable Sections: 1
Subsystem: Windows Console

Sections Info
Section Name Flags ROffset RSize VOffset VSizeEntropyChi2
.text
0x60000060
Code
Initialized Data
Executable
Readable
400 1800 1000 1694
5.773
83141.58
.data
0xC0000040
Initialized Data
Readable
Writeable
1C00 200 3000 28
0.5093
115715
.rdata
0x40000040
Initialized Data
Readable
1E00 10D200 4000 10D054
6.2254
25124686.89
.eh_fram
0x40000040
Initialized Data
Readable
10F000 200 112000 184
3.9645
27208
.bss
0xC0000080
Uninitialized Data
Readable
Writeable
0 0 113000 8C
N/A
N/A
.edata
0x40000040
Initialized Data
Readable
10F200 200 114000 48
0.81
109054
.idata
0xC0000040
Initialized Data
Readable
Writeable
10F400 600 115000 498
4.116
76747.33
.CRT
0xC0000040
Initialized Data
Readable
Writeable
10FA00 200 116000 2C
0.2054
125000
.tls
0xC0000040
Initialized Data
Readable
Writeable
10FC00 200 117000 8
0
130560
.reloc
0x42000040
Initialized Data
GP-Relative
Readable
10FE00 200 118000 1F4
6.1676
3323
Binder/Joiner/Crypter
2 Executable files found

Entry Point
The section number (1) - (.text) have the Entry Point
Information -> EntryPoint (calculated) - 7B0
Code -> 83EC0CC70540301D68000000008B4C24188B5424148B442410E852FEFFFF83C40CC20C008DB426000000008D7426009083EC
Assembler
|SUB ESP, 0XC
|MOV DWORD PTR [0X681D3040], 0
|MOV ECX, DWORD PTR [ESP + 0X18]
|MOV EDX, DWORD PTR [ESP + 0X14]
|MOV EAX, DWORD PTR [ESP + 0X10]
|CALL 0X680C1220
|ADD ESP, 0XC
|RET 0XC
|LEA ESI, [ESI]
|LEA ESI, [ESI]
|NOP
Signatures
Certificate - Digital Signature:
• The file is signed and the signature is correct

Packer/Compiler
Detect It Easy (die)
PE: linker: GNU linker ld (GNU Binutils)(2.38)[-]
PE: Sign tool: Windows Authenticode(2.0)[PKCS 7]
Entropy: 6.24745

Suspicious Functions
Library Function Description
KERNEL32.DLL CopyFileW Copies an existing file to a new file.
KERNEL32.DLL WriteFile Writes data to a specified file or input/output (I/O) device.
KERNEL32.DLL LoadLibraryA Loads the specified module into the address space of the calling process.
KERNEL32.DLL GetModuleHandleA Retrieves a handle to the specified module.
KERNEL32.DLL GetProcAddress Retrieves the address of an exported function or variable from the specified dynamic-link library (DLL).
KERNEL32.DLL GetTempPathW Retrieves the temporary directory path.
KERNEL32.DLL CreateFileW Creates or opens a file object.
KERNEL32.DLL CloseHandle Closes an open object handle.
KERNEL32.DLL VirtualProtect Changes memory protection attributes.
KERNEL32.DLL CreateProcessW Creates and starts a new process.
KERNEL32.DLL CreateEventA Creates or opens an event object.
KERNEL32.DLL GetSystemInfo Retrieves system hardware information.
SHELL32.DLL ShellExecuteExW Performs a run operation on a specific file.
ET Functions (carving)
Original Name -> goopdate.dll
DllEntry

File Access
svchost.exe
levelagent.exe
USER32.dll
SHELL32.dll
msvcrt.dll
KERNEL32.dll
goopdate.dll
libgcc_s_dw2-1.dll
@.dat
.dat
Temp

File Access (UNICODE)
kta5rAgS7IPAmbVN.exe
QueryPerformanceFrequencyQueryPerformanceCounterkernelbase.dll
kernel32.dll
KernelBase.dll
sys.dll
cam_numbers_1382bf.pdf

Interest's Words
exec
start
systeminfo
ping
expand

URLs
http://www.microsoft.com/pkiops/crl/Microsoft%20ID%20Verified%20CS%20AOC%20CA%2004.crl
http://www.microsoft.com/pkiops/certs/Microsoft%20ID%20Verified%20CS%20AOC%20CA%2004.crt
http://www.microsoft.com/pkiops/Docs/Repository.htm
http://www.microsoft.com/pkiops/crl/Microsoft%20ID%20Verified%20Code%20Signing%20PCA%202021.crl
http://www.microsoft.com/pkiops/certs/Microsoft%20ID%20Verified%20Code%20Signing%20PCA%202021.crt
http://www.microsoft.com/pkiops/crl/Microsoft%20Identity%20Verification%20Root%20Certificate%20Authority%202020.crl
http://www.microsoft.com/pkiops/certs/Microsoft%20Identity%20Verification%20Root%20Certificate%20Authority%202020.crt
http://oneocsp.microsoft.com/ocsp0
http://www.microsoft.com/pkiops/crl/Microsoft%20Public%20RSA%20Timestamping%20CA%202020.crl
http://www.microsoft.com/pkiops/certs/Microsoft%20Public%20RSA%20Timestamping%20CA%202020.crt

IP Addresses
10.0.0.0

PE Carving
Start Offset Header End Offset Size (Bytes)
0 1F20 1F20
1F20 1139C0 111AA0
Intelligent String
• OriginalFilename=svchost.exe
• .tls
• .CRT
• @.bss
• kta5rAgS7IPAmbVN.exe
• cam_numbers_1382bf.pdf
• sys.dll
• KernelBase.dll
• kernel32.dll
• KERNEL32.dll
• msvcrt.dll
• PKERNEL32.dll

Flow Anomalies
Offset FlowVA Section Description
457 681D5148 .text CALL [static] | Indirect call to absolute memory address
810 681D5130 .text CALL [static] | Indirect call to absolute memory address
826 681D5144 .text CALL [static] | Indirect call to absolute memory address
8D4 681D5124 .text CALL [static] | Indirect call to absolute memory address
8FC 681D5138 .text CALL [static] | Indirect call to absolute memory address
971 681D5110 .text CALL [static] | Indirect call to absolute memory address
9B4 681D5158 .text CALL [static] | Indirect call to absolute memory address
A8F 681D5114 .text CALL [static] | Indirect call to absolute memory address
AF6 681D512C .text CALL [static] | Indirect call to absolute memory address
B4C 681D510C .text CALL [static] | Indirect call to absolute memory address
B9A 681D519C .text CALL [static] | Indirect call to absolute memory address
BB0 681D5128 .text CALL [static] | Indirect call to absolute memory address
C0F 681D511C .text CALL [static] | Indirect call to absolute memory address
EDB 681D5154 .text CALL [static] | Indirect call to absolute memory address
F43 681D5150 .text CALL [static] | Indirect call to absolute memory address
F50 681D5128 .text CALL [static] | Indirect call to absolute memory address
123E 681D5120 .text CALL [static] | Indirect call to absolute memory address
128C 681D5140 .text CALL [static] | Indirect call to absolute memory address
12E2 681D5120 .text CALL [static] | Indirect call to absolute memory address
1300 681D5140 .text CALL [static] | Indirect call to absolute memory address
1347 681D5120 .text CALL [static] | Indirect call to absolute memory address
1387 681D5140 .text CALL [static] | Indirect call to absolute memory address
1407 681D513C .text CALL [static] | Indirect call to absolute memory address
146C 681D5118 .text CALL [static] | Indirect call to absolute memory address
1890 681D5194 .text JMP [static] | Indirect jump to absolute memory address
1898 681D5190 .text JMP [static] | Indirect jump to absolute memory address
18A0 681D518C .text JMP [static] | Indirect jump to absolute memory address
18A8 681D5188 .text JMP [static] | Indirect jump to absolute memory address
18B0 681D5180 .text JMP [static] | Indirect jump to absolute memory address
18B8 681D517C .text JMP [static] | Indirect jump to absolute memory address
18C0 681D5178 .text JMP [static] | Indirect jump to absolute memory address
18C8 681D5174 .text JMP [static] | Indirect jump to absolute memory address
18D0 681D5164 .text JMP [static] | Indirect jump to absolute memory address
18D8 681D5160 .text JMP [static] | Indirect jump to absolute memory address
1A50 681D5184 .text JMP [static] | Indirect jump to absolute memory address
1A58 681D5170 .text JMP [static] | Indirect jump to absolute memory address
1A60 681D516C .text JMP [static] | Indirect jump to absolute memory address
2588 87F86 .rdata CALL [static] | Indirect call to absolute memory address
2793 87D5B .rdata CALL [static] | Indirect call to absolute memory address
289C 822C2 .rdata JMP [static] | Indirect jump to absolute memory address
2981 87BDD .rdata JMP [static] | Indirect jump to absolute memory address
2C99 87895 .rdata CALL [static] | Indirect call to absolute memory address
2D7E 877A8 .rdata CALL [static] | Indirect call to absolute memory address
2D8C 87752 .rdata CALL [static] | Indirect call to absolute memory address
3320 871B6 .rdata CALL [static] | Indirect call to absolute memory address
3375 87191 .rdata JMP [static] | Indirect jump to absolute memory address
33C4 87112 .rdata CALL [static] | Indirect call to absolute memory address
33E3 87123 .rdata CALL [static] | Indirect call to absolute memory address
3427 870AF .rdata CALL [static] | Indirect call to absolute memory address
346A 8709C .rdata CALL [static] | Indirect call to absolute memory address
34E7 87017 .rdata CALL [static] | Indirect call to absolute memory address
354D 86F81 .rdata CALL [static] | Indirect call to absolute memory address
3990 86C96 .rdata JMP [static] | Indirect jump to absolute memory address
3998 86C86 .rdata JMP [static] | Indirect jump to absolute memory address
39A0 86C76 .rdata JMP [static] | Indirect jump to absolute memory address
39A8 86C66 .rdata JMP [static] | Indirect jump to absolute memory address
39B0 86C56 .rdata JMP [static] | Indirect jump to absolute memory address
39B8 86C46 .rdata JMP [static] | Indirect jump to absolute memory address
39C0 86C36 .rdata JMP [static] | Indirect jump to absolute memory address
39C8 86C26 .rdata JMP [static] | Indirect jump to absolute memory address
39D0 86C16 .rdata JMP [static] | Indirect jump to absolute memory address
39D8 86C06 .rdata JMP [static] | Indirect jump to absolute memory address
39E0 86BF6 .rdata JMP [static] | Indirect jump to absolute memory address
39E8 86BE6 .rdata JMP [static] | Indirect jump to absolute memory address
39F0 86BD6 .rdata JMP [static] | Indirect jump to absolute memory address
39F8 86BC6 .rdata JMP [static] | Indirect jump to absolute memory address
3A00 86BA6 .rdata JMP [static] | Indirect jump to absolute memory address
3A08 86B96 .rdata JMP [static] | Indirect jump to absolute memory address
3A10 86B76 .rdata JMP [static] | Indirect jump to absolute memory address
3A18 86B66 .rdata JMP [static] | Indirect jump to absolute memory address
3A20 86B4E .rdata JMP [static] | Indirect jump to absolute memory address
3A28 86B3E .rdata JMP [static] | Indirect jump to absolute memory address
3A30 86B16 .rdata JMP [static] | Indirect jump to absolute memory address
3A38 86B06 .rdata JMP [static] | Indirect jump to absolute memory address
3AB0 86AA6 .rdata JMP [static] | Indirect jump to absolute memory address
3B07 86AA7 .rdata CALL [static] | Indirect call to absolute memory address
3B6A 86A4C .rdata CALL [static] | Indirect call to absolute memory address
4386 84554 .rdata CALL [static] | Indirect call to absolute memory address
4391 84541 .rdata CALL [static] | Indirect call to absolute memory address
4406 844CC .rdata CALL [static] | Indirect call to absolute memory address
72D1 844CC .rdata CALL [static] | Indirect call to absolute memory address
9247 1624F962 .rdata JMP [static] | Indirect jump to absolute memory address
A46C 1624F962 .rdata CALL [static] | Indirect call to absolute memory address
142A0 1624F962 .rdata CALL [static] | Indirect call to absolute memory address
22A11 426F9050 .rdata JMP [static] | Indirect jump to absolute memory address
37148 51063DF0 .rdata JMP [static] | Indirect jump to absolute memory address
3E89D 51063DF0 .rdata CALL [static] | Indirect call to absolute memory address
42D2A 56F02B3F .rdata JMP [static] | Indirect jump to absolute memory address
45B64 56F02B3F .rdata CALL [static] | Indirect call to absolute memory address
4F5CA 56F02B3F .rdata CALL [static] | Indirect call to absolute memory address
54EC8 56F02B3F .rdata CALL [static] | Indirect call to absolute memory address
64E24 2CC29B3F .rdata JMP [static] | Indirect jump to absolute memory address
65A47 2CC29B3F .rdata JMP [static] | Indirect jump to absolute memory address
6E944 2CC29B3F .rdata CALL [static] | Indirect call to absolute memory address
81D05 2CC29B3F .rdata JMP [static] | Indirect jump to absolute memory address
10FA18 680C1940 .CRT TLS Callback | Pointer to 1940 - 0xD40 .text
10FA1C 680C18F0 .CRT TLS Callback | Pointer to 18F0 - 0xCF0 .text
110000 N/A *Overlay* C039000000020200308239B306092A864886F70D | .9......0.9...*.H...
Extra Analysis
Metric Value Percentage
Ascii Code 620456 54,9613%
Null Byte Code 333696 29,5595%
NOP Cave Found 0x9090909090 Block Count: 56 | Total: 0,0124%
© 2026 All rights reserved.