PREMIUM PESCAN.IO - Analysis Report

File Structure
Analysis Image
PE Chart Code
Header PE (light blue)
Executable sections (pink)
Non-executable sections (black)
External injected code (red)
File Structure in red = malformed or corrupted header

Chart Code For Other Files
Printable characters (blue)
Non-printable characters (black)
Information
Size: 27,50 KB
SHA-256 Hash: 418A07EBD7C417BB91E8CA0CBD5CC4CA89697104CE0E5480D9ED09B100463E5E
SHA-1 Hash: 3E4E8EA47D947AB79C5546E83CB1E90BDF98C3F2
MD5 Hash: 29D0CA716E7BA7BFDB279053351225D6
Imphash: F34D5F2D4577ED6D9CEEC516C1F5A744
MajorOSVersion: 4
MinorOSVersion: 0
CheckSum: 00000000
EntryPoint (rva): 80FA
SizeOfHeaders: 200
SizeOfImage: E000
ImageBase: 400000
Architecture: x86
ImportTable: 80A8
IAT: 2000
Characteristics: 102
TimeDateStamp: 9C4AA5A5
Date: 02/02/2053 19:36:05
File Type: EXE
Number Of Sections: 3
ASLR: Disabled
Section Names: .text, .rsrc, .reloc
Number Of Executable Sections: 1
Subsystem: Windows GUI
UAC Execution Level Manifest: asInvoker

Sections Info
Section Name Flags ROffset RSize VOffset VSizeEntropyChi2
.text
0x60000020
Code
Executable
Readable
200 6200 2000 6120
5.6701
520641.51
.rsrc
0x40000040
Initialized Data
Readable
6400 800 A000 7F0
4.834
47840.75
.reloc
0x42000040
Initialized Data
GP-Relative
Readable
6C00 200 C000 C
0.0815
128522
Description
OriginalFilename: AU88APP.exe
FileVersion: 1.0.0.0
ProductVersion: 1.0.0.0
Language: Unknown (ID=0x0)
CodePage: Unicode (UTF-16 LE) (0x4B0)

Entry Point
The section number (1) - (.text) have the Entry Point
Information -> EntryPoint (calculated) - 62FA
Code -> FF2500204000BFEB1E56FBCD973BB219022430A57843003D5644D21E62B9D4F180E7E6C33941000000000000000000000000
Assembler
|JMP DWORD PTR [0X402000]
|MOV EDI, 0XFB561EEB
|INT 0X97
|CMP ESI, DWORD PTR [EDX + 0X30240219]
|MOVSD DWORD PTR ES:[EDI], DWORD PTR [ESI]
|JS 0X408153
|ADD BYTE PTR [0X1ED24456], BH
|BOUND EDI, QWORD PTR [ECX - 0X187F0E2C]
|OUT 0XC3, AL
|CMP DWORD PTR [ECX], EAX
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
Signatures
Certificate - Digital Signature Not Found:
• The file is not signed

Packer/Compiler
Compiler: Microsoft Visual .NET - (You can use a decompiler for this...)
AnyCPU: False
Version: v4.0
Detect It Easy (die)
PE: library: .NET(v4.0.30319)[-]
PE: compiler: VB.NET(-)[-]
PE: linker: Microsoft Linker(48.0)[-]
Entropy: 5.56333

File Access
AU88APP.exe
mscoree.dll
ntdll.dll
user32.dll
kernel32.dll
Temp

File Access (UNICODE)
AU88APP.exe
Test.exe
SbieDll.dll
AppData

SQL Queries
Select * from Win32_ComputerSystem
Select * from AntivirusProduct

Interest's Words
Virus
Encrypt
Decrypt
<head
<header
exec
attrib
start
cipher
hostname
systeminfo
ping
expand
replace

Interest's Words (UNICODE)
Virus
schtasks
start
schtask
ping

Anti-VM/Sandbox/Debug Tricks (UNICODE)
SandBoxie Library - SbieDll.dll

URLs
http://schemas.microsoft.com/SMI/2005/WindowsSettings

AV Services (UNICODE)
securitycenter2.exe - (SecurityCenter2)

Strings/Hex Code Found With The File Rules
Rule Type Encoding Matched (Word)
Text Ascii Encryption (AesCryptoServiceProvider)
Text Ascii Encryption (CipherMode)
Text Ascii Encryption (CreateDecryptor)
Text Ascii Encryption (CryptoStream)
Text Ascii Encryption (CryptoStreamMode)
Text Ascii Encryption (FromBase64String)
Text Ascii Encryption (ICryptoTransform)
Text Ascii Encryption (MD5CryptoServiceProvider)
Text Ascii Encryption (ToBase64String)
Text Ascii Information used to authenticate a user’s identity (Credential)
Text Ascii Information used for user authentication (Credential)
Entry Point Hex Pattern Microsoft Visual C++ 8
Entry Point Hex Pattern Microsoft Visual C++ 8.0
Resources
Path DataRVA Size FileOffset CodeText
\VERSION\1\0 A090 2D4 6490 D40234000000560053005F00560045005200530049004F004E005F0049004E0046004F0000000000BD04EFFE000001000000..4...V.S._.V.E.R.S.I.O.N._.I.N.F.O...............
\24\1\0 A374 478 6774 EFBBBF3C617373656D626C7920786D6C6E733D2275726E3A736368656D61732D6D6963726F736F66742D636F6D3A61736D2E...<assembly xmlns="urn:schemas-microsoft-com:asm.
Intelligent String
• 1.0.0.0
• AU88APP.exe
• new88.ooo
• Test.exe
• i/c schtasks /create /f /sc onlogon /rl highest /tn "
• .bat
• SbieDll.dll
• _CorExeMainmscoree.dll
• <asmv3:windowsSettings xmlns="http://schemas.microsoft.com/SMI/2005/WindowsSettings">

Flow Anomalies
Offset FlowVA Section Description
62FA 402000 .text JMP [static] | Indirect jump to absolute memory address
Extra Analysis
Metric Value Percentage
Ascii Code 16285 57,8303%
Null Byte Code 8374 29,7372%
© 2026 All rights reserved.