PESCAN.IO - Analysis Report Basic

File Structure
Analysis Image
PE Chart Code
Header PE (light blue)
Executable sections (pink)
Non-executable sections (black)
External injected code (red)
File Structure in red = malformed or corrupted header

Chart Code For Other Files
Printable characters (blue)
Non-printable characters (black)
Information
Icon: Icon
Size: 23,50 KB
SHA-256 Hash: D34533E13518ACC27C087F26429DBE611D02E743899CDF1AAED75AD41C5211E6
SHA-1 Hash: E23B00F8391902AD7CC2A93ED6F1A3E00F05EA8E
MD5 Hash: 1AFFF8BEA802B78D9239CEB66A3B16DC
Imphash: A451F4ACCEBDC105F8D2CFB3B5108037
MajorOSVersion: 4
MinorOSVersion: 0
CheckSum: 00000000
EntryPoint (rva): 1000
SizeOfHeaders: 400
SizeOfImage: 9000
ImageBase: 400000
Architecture: x86
ImportTable: 2080
IAT: 2000
Characteristics: 10F
TimeDateStamp: 379334B7
Date: 19/07/1999 14:22:47
File Type: EXE
Number Of Sections: 4
ASLR: Disabled
Section Names: .text, .rdata, .data, .rsrc
Number Of Executable Sections: 1
Subsystem: Windows GUI

Sections Info
Section Name Flags ROffset RSize VOffset VSizeEntropyChi2
.text
0xE0000020
Code
Executable
Readable
Writeable
400 600 1000 4C6
4.4878
67043
.rdata
0x40000040
Initialized Data
Readable
A00 400 2000 340
4.1385
54464
.data
0xC0000040
Initialized Data
Readable
Writeable
E00 200 3000 180
4.0753
21263
.rsrc
0xC0000040
Initialized Data
Readable
Writeable
1000 4E00 4000 4D28
5.448
728158.49
Entry Point
The section number (1) - (.text) have the Entry Point
Information -> EntryPoint (calculated) - 400
Code -> 6A00E817040000A3643140006A056A006A00FF3564314000E80600000050E8F5030000558BEC83C4B433DBC745D030000000
Assembler
|PUSH 0
|CALL 0X40141E
|MOV DWORD PTR [0X403164], EAX
|PUSH 5
|PUSH 0
|PUSH 0
|PUSH DWORD PTR [0X403164]
|CALL 0X401023
|PUSH EAX
|CALL 0X401418
|PUSH EBP
|MOV EBP, ESP
|ADD ESP, -0X4C
|XOR EBX, EBX
|MOV DWORD PTR [EBP - 0X30], 0X30
Signatures
Rich Signature Analyzer:
Code -> F11B19DBB57A7788B57A7788B57A7788B57A7788917A778836667988B47A7788727C7188B47A778852696368B57A7788
Footprint md5 Hash -> B8B7B4AA00B35A4E7136EDC7CD98FE97
• The Rich header apparently has not been modified
Certificate - Digital Signature Not Found:
• The file is not signed

Packer/Compiler
Compiler: Microsoft Visual .NET - (You can use a decompiler for this...)
AnyCPU: False
Detect It Easy (die)
PE: linker: Microsoft Linker(5.12*)[-]
Entropy: 5.48328

Suspicious Functions
Library Function Description
KERNEL32.DLL GetModuleHandleA Retrieves a handle to the specified module.
File Access
GDI32.dll
USER32.dll
KERNEL32.dll
@.dat

Strings/Hex Code Found With The File Rules
Rule Type Encoding Matched (Word)
Entry Point Hex Pattern Borland Delphi 4.0
Entry Point Hex Pattern PE Diminisher v0.1
Resources
Path DataRVA Size FileOffset CodeText
\BITMAP\201\1033 49B0 4372 19B0 28000000C800000051000000010008000000000000000000120B0000120B0000000000000000000006020600130E12000D06(.......Q.........................................
\ICON\1\1033 40F0 8A8 10F0 2800000020000000400000000100080000000000000400000000000000000000000000000000000000000000607860003040(... ...@...................................x.0@
\GROUP_ICON\200\1033 4998 14 1998 0000010001002020000001000800A80800000100...... ............
Intelligent String
• KERNEL32.dll
• USER32.dll
• GDI32.dll

Flow Anomalies
Offset FlowVA Section Description
818 402028 .text JMP [static] | Indirect jump to absolute memory address
81E 40202C .text JMP [static] | Indirect jump to absolute memory address
824 402070 .text JMP [static] | Indirect jump to absolute memory address
82A 40206C .text JMP [static] | Indirect jump to absolute memory address
830 402068 .text JMP [static] | Indirect jump to absolute memory address
836 402064 .text JMP [static] | Indirect jump to absolute memory address
83C 402060 .text JMP [static] | Indirect jump to absolute memory address
842 40205C .text JMP [static] | Indirect jump to absolute memory address
848 402058 .text JMP [static] | Indirect jump to absolute memory address
84E 402054 .text JMP [static] | Indirect jump to absolute memory address
854 402050 .text JMP [static] | Indirect jump to absolute memory address
85A 40203C .text JMP [static] | Indirect jump to absolute memory address
860 402038 .text JMP [static] | Indirect jump to absolute memory address
866 402034 .text JMP [static] | Indirect jump to absolute memory address
86C 402074 .text JMP [static] | Indirect jump to absolute memory address
872 402078 .text JMP [static] | Indirect jump to absolute memory address
878 402044 .text JMP [static] | Indirect jump to absolute memory address
87E 402048 .text JMP [static] | Indirect jump to absolute memory address
884 40204C .text JMP [static] | Indirect jump to absolute memory address
88A 402040 .text JMP [static] | Indirect jump to absolute memory address
890 402020 .text JMP [static] | Indirect jump to absolute memory address
896 40201C .text JMP [static] | Indirect jump to absolute memory address
89C 402018 .text JMP [static] | Indirect jump to absolute memory address
8A2 402014 .text JMP [static] | Indirect jump to absolute memory address
8A8 402010 .text JMP [static] | Indirect jump to absolute memory address
8AE 40200C .text JMP [static] | Indirect jump to absolute memory address
8B4 402008 .text JMP [static] | Indirect jump to absolute memory address
8BA 402004 .text JMP [static] | Indirect jump to absolute memory address
8C0 402000 .text JMP [static] | Indirect jump to absolute memory address
2AA9 17315657 .rsrc CALL [static] | Indirect call to absolute memory address
2DA7 17476666 .rsrc CALL [static] | Indirect call to absolute memory address
2E6F 2A476766 .rsrc CALL [static] | Indirect call to absolute memory address
30C7 2457742D .rsrc CALL [static] | Indirect call to absolute memory address
3100 35407268 .rsrc CALL [static] | Indirect call to absolute memory address
35B5 3155652D .rsrc CALL [static] | Indirect call to absolute memory address
37F2 474A561A .rsrc CALL [static] | Indirect call to absolute memory address
Extra Analysis
Metric Value Percentage
Ascii Code 9353 38,8672%
Null Byte Code 3923 16,3024%
© 2026 All rights reserved.