PESCAN.IO - Analysis Report Basic

File Structure
Analysis Image
PE Chart Code
Header PE (light blue)
Executable sections (pink)
Non-executable sections (black)
External injected code (red)
File Structure in red = malformed or corrupted header

Chart Code For Other Files
Printable characters (blue)
Non-printable characters (black)
Information
Size: 56,00 KB
SHA-256 Hash: 9A8E9D587B570D4074F1C8317B163AA8D0C566EFD88F294D9D85BC7776352A28
SHA-1 Hash: C0408DA553D905857AC4F559B0438B99316F1BDA
MD5 Hash: 1FDB1DD742674D3939F636C3FC4B761F
Imphash: F34D5F2D4577ED6D9CEEC516C1F5A744
MajorOSVersion: 4
MinorOSVersion: 0
CheckSum: 00000000
EntryPoint (rva): F55E
SizeOfHeaders: 200
SizeOfImage: 14000
ImageBase: 400000
Architecture: x86
ImportTable: F50C
IAT: 2000
Characteristics: 22
TimeDateStamp: B933288D
Date: 17/06/2068 5:47:57
File Type: EXE
Number Of Sections: 3
ASLR: Enabled
Section Names: .text, .rsrc, .reloc
Number Of Executable Sections: 1
Subsystem: Windows Console
UAC Execution Level Manifest: asInvoker
[Incomplete Binary or Compressor Packer - 24,00 KB Missing]

Sections Info
Section Name Flags ROffset RSize VOffset VSizeEntropyChi2
.text
0x60000020
Code
Executable
Readable
200 D600 2000 D564
5.9134
928368.39
.rsrc
0x40000040
Initialized Data
Readable
D800 600 10000 5AC
4.0712
78285.33
.reloc
0x42000040
Initialized Data
GP-Relative
Readable
DE00 200 12000 C
0.0815
128522
Description
OriginalFilename: GodPotato.exe
LegalCopyright: Copyright 2022
ProductName: GodPotato
FileVersion: 1.0.0.0
FileDescription: GodPotato
ProductVersion: 1.0.0.0
Language: Unknown (ID=0x0)
CodePage: Unicode (UTF-16 LE) (0x4B0)

Entry Point
The section number (1) - (.text) have the Entry Point
Information -> EntryPoint (calculated) - D75E
Code -> FF25002040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
Assembler
|JMP DWORD PTR [0X402000]
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
Signatures
Certificate - Digital Signature Not Found:
• The file is not signed

Packer/Compiler
Compiler: Microsoft Visual .NET - (You can use a decompiler for this...)
AnyCPU: True
Version: v4.0
Detect It Easy (die)
PE: library: .NET(v4.0.30319)[-]
PE: linker: Microsoft Linker(48.0)[-]
Entropy: 5.82724

File Access
GodPotato.exe
mscoree.dll
ntdll.dll
psapi.dll
secur32.dll
kernel32.dll
advapi32.dll
wtsapi32.dll
ole32.dll
Temp

File Access (UNICODE)
GodPotato.exe
combase.dll

Interest's Words
PassWord
exec
attrib
start
whoami
systeminfo
ping
replace

Interest's Words (UNICODE)
fuck - }:)
start

IP Addresses
127.0.0.1

Strings/Hex Code Found With The File Rules
Rule Type Encoding Matched (Word)
Text Ascii WinAPI Sockets (bind)
Text Ascii File (CreateFile)
Text Ascii Encryption (FromBase64String)
Text Ascii Stealth (CloseHandle)
Text Ascii Stealth (VirtualProtect)
Text Ascii Execution (CreateProcessA)
Text Ascii Execution (CreateProcessW)
Text Ascii Privileges (SE_PRIVILEGE_ENABLED)
Text Ascii Privileges (SE_PRIVILEGE_ENABLED_BY_DEFAULT)
Text Ascii Privileges (SE_PRIVILEGE_REMOVED)
Text Ascii Information used for user authentication (Credential)
Text Ascii Unauthorized movement of funds or data (Transfer)
Entry Point Hex Pattern Microsoft Visual C / Basic .NET
Entry Point Hex Pattern Microsoft Visual C++ 8
Entry Point Hex Pattern Microsoft Visual C++ 8.0
Entry Point Hex Pattern Microsoft Visual C v7.0 / Basic .NET
Entry Point Hex Pattern Microsoft Visual Studio .NET
Entry Point Hex Pattern .NET executable
Resources
Path DataRVA Size FileOffset CodeText
\VERSION\1\0 10090 31C D890 1C0334000000560053005F00560045005200530049004F004E005F0049004E0046004F0000000000BD04EFFE000001000000..4...V.S._.V.E.R.S.I.O.N._.I.N.F.O...............
\24\1\0 103BC 1EA DBBC EFBBBF3C3F786D6C2076657273696F6E3D22312E302220656E636F64696E673D225554462D3822207374616E64616C6F6E65...<?xml version="1.0" encoding="UTF-8" standalone
Intelligent String
• 1.0.0.0
• GodPotato.exe
• combase.dll
• \pipe\epmapper
• ![\pipe\epmapper]
• TInheritedTAllowMultiple<cmdcmd /c whoamiTDescriptionCommandLineTRequired
• _CorExeMainmscoree.dll

Flow Anomalies
Offset RVA Section Description
68CE 1910530 .text JMP [static] | Indirect jump to absolute memory address
D75E 402000 .text JMP [static] | Indirect jump to absolute memory address
Extra Analysis
Metric Value Percentage
Ascii Code 34744 60,5887%
Null Byte Code 15178 26,4683%
© 2026 All rights reserved.