PESCAN.IO - Analysis Report Basic

File Structure
Analysis Image
PE Chart Code
Header PE (light blue)
Executable sections (pink)
Non-executable sections (black)
External injected code (red)
File Structure in red = malformed or corrupted header

Chart Code For Other Files
Printable characters (blue)
Non-printable characters (black)
Information
Size: 88,50 KB
SHA-256 Hash: F7F62773D14515C98DC69D63943C91EEDC8D25A0A9C6F08A839635AE760DA208
SHA-1 Hash: B644CCCD9B77062A24451EBE5AF38252C72103E3
MD5 Hash: 29F4A3FEF649CE144B71A3B2B3FD71DB
Imphash: 245186F1AAED0B7C19422F1317D8DEC4
MajorOSVersion: 5
MinorOSVersion: 1
CheckSum: 00000000
EntryPoint (rva): 132E9
SizeOfHeaders: 400
SizeOfImage: 55000
ImageBase: 10000000
Architecture: x86
ExportTable: 154D0
ImportTable: 14F1C
IAT: 14000
Characteristics: 2102
TimeDateStamp: 5B12B3D6
Date: 02/06/2018 15:12:22
File Type: DLL
Number Of Sections: 6
ASLR: Enabled
Section Names: .text, .rdata, .data, .semapho, .rsrc, .reloc
Number Of Executable Sections: 1
Subsystem: Windows GUI
UAC Execution Level Manifest: asInvoker
[Incomplete Binary or Compressor Packer - 251,50 KB Missing]

Sections Info
Section Name Flags ROffset RSize VOffset VSizeEntropyChi2
.text
0x60000020
Code
Executable
Readable
400 12A00 1000 12989
6.6072
391739.64
.rdata
0x40000040
Initialized Data
Readable
12E00 1800 14000 16DD
5.2868
115691.58
.data
0xC0000040
Initialized Data
Readable
Writeable
14600 400 16000 3A3A0
3.0241
97672.5
.semapho
0xD0000040
Initialized Data
Discardable
Readable
Writeable
14A00 200 51000 4
0
130560
.rsrc
0x40000040
Initialized Data
Readable
14C00 200 52000 1F8
4.8728
7195
.reloc
0x42000040
Initialized Data
GP-Relative
Readable
14E00 1400 53000 123E
5.6945
116194
Entry Point
The section number (1) - (.text) have the Entry Point
Information -> EntryPoint (calculated) - 126E9
Code -> 8BFF558BEC837D0C017505E8E5040000FF75088B4D108B550CE8CCFEFFFF595DC20C008BFF558BEC81EC28030000A3680105
Assembler
|MOV EDI, EDI
|PUSH EBP
|MOV EBP, ESP
|CMP DWORD PTR [EBP + 0XC], 1
|JNE 0X100132F9
|CALL 0X100137DE
|PUSH DWORD PTR [EBP + 8]
|MOV ECX, DWORD PTR [EBP + 0X10]
|MOV EDX, DWORD PTR [EBP + 0XC]
|CALL 0X100131D3
|POP ECX
|POP EBP
|RET 0XC
|MOV EDI, EDI
|PUSH EBP
|MOV EBP, ESP
|SUB ESP, 0X328
Signatures
Rich Signature Analyzer:
Code -> 88527EF9CC3310AACC3310AACC3310AAA3458CAACE3310AA5F7D88AACD3310AAA3458EAAC93310AAA345BAAAC73310AAC54B83AACF3310AACC3311AA8B3310AAA345BBAAC63310AAA3458BAACD3310AAA3458AAACD3310AAA3458DAACD3310AA52696368CC3310AA
Footprint md5 Hash -> 1E97EB01CAA50D3131D155A3FBAAEBF3
• The Rich header apparently has not been modified
Certificate - Digital Signature Not Found:
• The file is not signed

Packer/Compiler
Compiler: Microsoft Visual Studio
Detect It Easy (die)
PE: compiler: EP:Microsoft Visual C/C++(2008-2010)[DLL32]
PE: compiler: Microsoft Visual C/C++(2010)[libcmt]
PE: linker: Microsoft Linker(10.0)[-]
Entropy: 6.61484

Suspicious Functions
Library Function Description
KERNEL32.DLL IsDebuggerPresent Determines if the calling process is being debugged by a user-mode debugger.
KERNEL32.DLL CloseHandle Closes an open object handle.
KERNEL32.DLL CreateEventA Creates or opens an event object.
KERNEL32.DLL GetSystemInfo Retrieves system hardware information.
KERNEL32.DLL GlobalMemoryStatusEx Retrieves memory usage information.
ET Functions (carving)
Original Name -> DDummy.dll
_CalcAllTables@20
_CalcAllTablesPBN@20
_CalcDDtable@68
_CalcDDtablePBN@84
_CalcPar@76
_CalcParPBN@92
_JNI_OnLoad@8
_Java_MyNative_abort@12
_Java_MyNative_callDDS@24
_Java_MyNative_checkInUse@8
_Java_MyNative_getPar@12
_Java_MyNative_reset@12
_SolveAllBoards@8
_SolveAllChunks@12
_SolveBoard@116
_SolveBoardPBN@132

File Access
DDummy.dll
MSVCR100.dll
KERNEL32.dll
@.dat
dump.txt

Interest's Words
exec
systeminfo

Strings/Hex Code Found With The File Rules
Rule Type Encoding Matched (Word)
Entry Point Hex Pattern Microsoft Visual C++ v7.0
Resources
Path DataRVA Size FileOffset CodeText
\24\2\1033 52060 196 14C60 EFBBBF3C3F786D6C2076657273696F6E3D22312E302220656E636F64696E673D225554462D3822207374616E64616C6F6E65...<?xml version="1.0" encoding="UTF-8" standalone
Intelligent String
• .gib
• dump.txt
• W:\DDummy_dll\Release\DDummy.pdb
• KERNEL32.dll
• .PAD
• .PAX

Flow Anomalies
Offset FlowVA Section Description
5A9 100140FC .text CALL [static] | Indirect call to absolute memory address
5D8 100140FC .text CALL [static] | Indirect call to absolute memory address
827 100140FC .text CALL [static] | Indirect call to absolute memory address
833 100140F4 .text CALL [static] | Indirect call to absolute memory address
83D 100140F8 .text CALL [static] | Indirect call to absolute memory address
E69 100140FC .text CALL [static] | Indirect call to absolute memory address
E75 100140F4 .text CALL [static] | Indirect call to absolute memory address
E7F 100140F8 .text CALL [static] | Indirect call to absolute memory address
E93 10014104 .text CALL [static] | Indirect call to absolute memory address
EA9 10014104 .text CALL [static] | Indirect call to absolute memory address
F76 100140F0 .text CALL [static] | Indirect call to absolute memory address
F94 100140F0 .text CALL [static] | Indirect call to absolute memory address
FB2 100140F0 .text CALL [static] | Indirect call to absolute memory address
FD0 100140F0 .text CALL [static] | Indirect call to absolute memory address
104F 100140F4 .text CALL [static] | Indirect call to absolute memory address
1059 100140F8 .text CALL [static] | Indirect call to absolute memory address
1168 100140F4 .text CALL [static] | Indirect call to absolute memory address
1172 100140F8 .text CALL [static] | Indirect call to absolute memory address
125A 100140F4 .text CALL [static] | Indirect call to absolute memory address
1264 100140F8 .text CALL [static] | Indirect call to absolute memory address
1355 100140E4 .text CALL [static] | Indirect call to absolute memory address
13A4 100140E4 .text CALL [static] | Indirect call to absolute memory address
13D3 100140E4 .text CALL [static] | Indirect call to absolute memory address
142A 100140F0 .text CALL [static] | Indirect call to absolute memory address
144F 100140F0 .text CALL [static] | Indirect call to absolute memory address
1474 100140F0 .text CALL [static] | Indirect call to absolute memory address
1499 100140F0 .text CALL [static] | Indirect call to absolute memory address
14BE 100140F0 .text CALL [static] | Indirect call to absolute memory address
14FF 100140F0 .text CALL [static] | Indirect call to absolute memory address
1524 100140F0 .text CALL [static] | Indirect call to absolute memory address
1549 100140F0 .text CALL [static] | Indirect call to absolute memory address
156E 100140F0 .text CALL [static] | Indirect call to absolute memory address
15AA 100140E4 .text CALL [static] | Indirect call to absolute memory address
179B 100140E8 .text CALL [static] | Indirect call to absolute memory address
188C 100140F4 .text CALL [static] | Indirect call to absolute memory address
1896 100140F8 .text CALL [static] | Indirect call to absolute memory address
19D4 100140D4 .text CALL [static] | Indirect call to absolute memory address
19E7 100140D8 .text CALL [static] | Indirect call to absolute memory address
1A06 10014004 .text CALL [static] | Indirect call to absolute memory address
1A61 10014000 .text CALL [static] | Indirect call to absolute memory address
1D59 100140D4 .text CALL [static] | Indirect call to absolute memory address
1D73 100140D4 .text CALL [static] | Indirect call to absolute memory address
1D8D 100140D4 .text CALL [static] | Indirect call to absolute memory address
1DC2 100140DC .text CALL [static] | Indirect call to absolute memory address
1DF5 100140DC .text CALL [static] | Indirect call to absolute memory address
1E32 100140DC .text CALL [static] | Indirect call to absolute memory address
1F75 100140D8 .text CALL [static] | Indirect call to absolute memory address
1F7D 100140D8 .text CALL [static] | Indirect call to absolute memory address
1FDE 100140D8 .text CALL [static] | Indirect call to absolute memory address
73C2 100140DC .text CALL [static] | Indirect call to absolute memory address
7402 100140DC .text CALL [static] | Indirect call to absolute memory address
7442 100140DC .text CALL [static] | Indirect call to absolute memory address
7547 100140D4 .text CALL [static] | Indirect call to absolute memory address
7642 100140D4 .text CALL [static] | Indirect call to absolute memory address
7712 100140D4 .text CALL [static] | Indirect call to absolute memory address
7A12 10014088 .text CALL [static] | Indirect call to absolute memory address
7A56 10014088 .text CALL [static] | Indirect call to absolute memory address
7B46 10014088 .text CALL [static] | Indirect call to absolute memory address
7C92 10014088 .text CALL [static] | Indirect call to absolute memory address
ABAF 10014068 .text CALL [static] | Indirect call to absolute memory address
ACA7 100140D0 .text CALL [static] | Indirect call to absolute memory address
AD2B 10014064 .text CALL [static] | Indirect call to absolute memory address
EECF 10014010 .text CALL [static] | Indirect call to absolute memory address
EEE6 1001400C .text CALL [static] | Indirect call to absolute memory address
EFF7 1001400C .text CALL [static] | Indirect call to absolute memory address
F01D 10014008 .text CALL [static] | Indirect call to absolute memory address
F108 10014018 .text CALL [static] | Indirect call to absolute memory address
F278 10014018 .text CALL [static] | Indirect call to absolute memory address
F3E9 10014010 .text CALL [static] | Indirect call to absolute memory address
F40A 10014008 .text CALL [static] | Indirect call to absolute memory address
F4F8 10014018 .text CALL [static] | Indirect call to absolute memory address
10145 10014010 .text CALL [static] | Indirect call to absolute memory address
10434 100140FC .text CALL [static] | Indirect call to absolute memory address
10584 10014088 .text CALL [static] | Indirect call to absolute memory address
1064E 10014088 .text CALL [static] | Indirect call to absolute memory address
108C9 10014070 .text CALL [static] | Indirect call to absolute memory address
109D7 10014088 .text CALL [static] | Indirect call to absolute memory address
10A6A 10014088 .text CALL [static] | Indirect call to absolute memory address
10C3A 10014088 .text CALL [static] | Indirect call to absolute memory address
10C97 10014074 .text CALL [static] | Indirect call to absolute memory address
110F6 10014088 .text CALL [static] | Indirect call to absolute memory address
11104 10014108 .text CALL [static] | Indirect call to absolute memory address
11114 10014084 .text CALL [static] | Indirect call to absolute memory address
1112A 10014088 .text CALL [static] | Indirect call to absolute memory address
11437 10014088 .text CALL [static] | Indirect call to absolute memory address
1147F 10014088 .text CALL [static] | Indirect call to absolute memory address
114D0 1001407C .text CALL [static] | Indirect call to absolute memory address
114DC 10014074 .text CALL [static] | Indirect call to absolute memory address
11516 10014088 .text CALL [static] | Indirect call to absolute memory address
1162C 10014078 .text CALL [static] | Indirect call to absolute memory address
11661 10014078 .text CALL [static] | Indirect call to absolute memory address
11721 10014088 .text CALL [static] | Indirect call to absolute memory address
1184E 10014088 .text CALL [static] | Indirect call to absolute memory address
11B8B 1001407C .text CALL [static] | Indirect call to absolute memory address
11C07 1001407C .text CALL [static] | Indirect call to absolute memory address
11D9A 10014088 .text CALL [static] | Indirect call to absolute memory address
11E51 10014088 .text CALL [static] | Indirect call to absolute memory address
11E9B 10014088 .text CALL [static] | Indirect call to absolute memory address
11F8D 1001408C .text CALL [static] | Indirect call to absolute memory address
11FB0 1001408C .text CALL [static] | Indirect call to absolute memory address
Extra Analysis
Metric Value Percentage
Ascii Code 51603 56,9419%
Null Byte Code 12156 13,4137%
© 2026 All rights reserved.