PREMIUM PESCAN.IO - Analysis Report

File Structure
Analysis Image
PE Chart Code
Header PE (light blue)
Executable sections (pink)
Non-executable sections (black)
External injected code (red)
File Structure in red = malformed or corrupted header

Chart Code For Other Files
Printable characters (blue)
Non-printable characters (black)
Information
Size: 41,50 KB
SHA-256 Hash: F5F0E9936CECF0FD912D8EF8B145A6761F8EEF5E4F43178AE3E4914C2BEBF22C
SHA-1 Hash: E60FA34B41EF4768FD7FB73DF2EDD688EFB9952A
MD5 Hash: 2C4C6285989FC28A37EB1B6068CAF0C2
Imphash: DAE02F32A21E03CE65412F6E56942DAA
MajorOSVersion: 4
MinorOSVersion: 0
CheckSum: 00000000
EntryPoint (rva): BCDE
SizeOfHeaders: 200
SizeOfImage: 10000
ImageBase: 400000
Architecture: x86
ImportTable: BC84
IAT: 2000
Characteristics: 2102
TimeDateStamp: 4EEF5044
Date: 19/12/2011 14:55:00
File Type: DLL
Number Of Sections: 3
ASLR: Enabled
Section Names: .text, .rsrc, .reloc
Number Of Executable Sections: 1
Subsystem: Windows Console
[Incomplete Binary or Compressor Packer - 22,50 KB Missing]

Sections Info
Section Name Flags ROffset RSize VOffset VSizeEntropyChi2
.text
0x60000020
Code
Executable
Readable
200 9E00 2000 9CE4
5.5683
931470.9
.rsrc
0x40000040
Initialized Data
Readable
A000 400 C000 380
2.9101
107286.5
.reloc
0x42000040
Initialized Data
GP-Relative
Readable
A400 200 E000 C
0.0815
128522
Description
OriginalFilename: UploadServices.dll
CompanyName: MotionDSP
LegalCopyright: Copyright MotionDSP 2010
ProductName: UploadServices
FileVersion: 3.1.3.0
FileDescription: UploadServices
ProductVersion: 3.1.3.0
Language: Unknown (ID=0x0)
CodePage: Unicode (UTF-16 LE) (0x4B0)

Entry Point
The section number (1) - (.text) have the Entry Point
Information -> EntryPoint (calculated) - 9EDE
Code -> FF25002040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
Assembler
|JMP DWORD PTR [0X402000]
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
Signatures
Certificate - Digital Signature Not Found:
• The file is not signed

Packer/Compiler
Compiler: Microsoft Visual .NET - (You can use a decompiler for this...)
AnyCPU: False
Version: v2.0
Detect It Easy (die)
PE: Protector: Eziriz .NET Reactor(6.x.x.x)[By Dr.FarFar]
PE: library: .NET(v2.0.50727)[-]
PE: linker: Microsoft Linker(8.0)[-]
Entropy: 5.4521

File Access
mscoree.dll
UploadServices.dll

File Access (UNICODE)
Exception@Wa.Log
;FBCore.Log
5FBCore.Log
UploadServices.dll

Interest's Words
PassWord
attrib
start
systeminfo
replace

Interest's Words (UNICODE)
start

URLs (UNICODE)
http://gdata.youtube.com/feeds/api/users/default
http://gdata.youtube.com/schemas/2007/developertags.cat
http://uploads.gdata.youtube.com/feeds/api/users/default/uploads
http://gdata.youtube.com/schemas/2007/categories.cat
http://wideralbum.com/p/
http://api-video.facebook.com/restserver.php[https://api.facebook.com/method/photos.upload
http://www.facebook.com/authorize.php?api_key=
https://graph.facebook.com/me/photos
https://graph.facebook.com/
https://graph.facebook.com/me/albums
https://graph.facebook.com/me/picture
https://graph.facebook.com/me/videos
https://graph.facebook.com/me/links
https://graph.facebook.com/me
https://graph.facebook.com/oauth/access_token?client_id=
https://login.facebook.com/login.php?api_key={0}&auth_token={1}&v={2}&type=user_agent&display=popup
https://www.facebook.com/logout.php?next={0}&access_token={1}
https://api.facebook.com/restserver.php?{0}
https://api.facebook.com/method/photos.upload
https://api.facebook.com/method/photos.getAlbums?{0}

Emails
Exception@Wa.Login
Exception@Wa.Login2
Exception@wa.ClickButton

Known IP/Domains (UNICODE)
facebook.com

Strings/Hex Code Found With The File Rules
Rule Type Encoding Matched (Word)
Text Ascii Encryption (MD5CryptoServiceProvider)
Text Unicode Antivirus Software (gdata)
Text Ascii Information used to authenticate a user’s identity (Credential)
Text Ascii Information used for user authentication (Credential)
Text Ascii Malicious rerouting of traffic to an attacker-controlled site (Redirect)
Entry Point Hex Pattern Microsoft Visual C / Basic .NET
Entry Point Hex Pattern Microsoft Visual C++ 8
Entry Point Hex Pattern Microsoft Visual C++ 8.0
Entry Point Hex Pattern Microsoft Visual C v7.0 / Basic .NET
Entry Point Hex Pattern Microsoft Visual Studio .NET
Entry Point Hex Pattern .NET executable
Entry Point Hex Pattern TrueVision Targa Graphics format
Resources
Path DataRVA Size FileOffset CodeText
\VERSION\1\0 C058 328 A058 280334000000560053005F00560045005200530049004F004E005F0049004E0046004F0000000000BD04EFFE000001000100(.4...V.S._.V.E.R.S.I.O.N._.I.N.F.O...............
Intelligent String
• 3.1.3.0
• UploadServices.dll
• www.google.com
• http://gdata.youtube.com/feeds/api/users/default
• http://gdata.youtube.com/schemas/2007/developertags.cat
• http://uploads.gdata.youtube.com/feeds/api/users/default/uploads
• http://gdata.youtube.com/schemas/2007/categories.cat
• 5WA: login() textBox msg:
• login
• 9WA: login() buttonToClick:
• Exception@Wa.Login:
• !www.facebook.com
• EWA: navigated to: www.facebook.com
• Exception@Wa.Login2:
• https://graph.facebook.com/me/photos
• https://graph.facebook.com/me/albums
• https://graph.facebook.com/me/picture
• https://graph.facebook.com/me/videos
• https://graph.facebook.com/me/links
• https://graph.facebook.com/me
• GFacebookUploader->Login(): email =
• aFacebookUploader->Login(): fbi.session_secret =
• .txt
• Ahttp%3A%2F%2Fwww.facebook.com%0A
• ;FBCore.LoginToFb: 446 , url:
• 5FBCore.LoginToFb: FAIL 454
• ;Error: facebook login failure
• ;FBCore.LoginToFb: SUCCESS 464
• 5FBCore.LoginToFb: FAIL 476
• https://graph.facebook.com/oauth/authorize?client_id=a0cc4d9ae652aca0426a9826e9acd4fb&redirect_uri=http://www.facebook.com/connect/login_success.html&scope=offline_access,publish_stream,user_status,user_photos,user_videos&type=user_agent&response_type=token
• https://login.facebook.com/login.php?api_key={0}&auth_token={1}&v={2}&type=user_agent&display=popup
• https://www.facebook.com/logout.php?next={0}&access_token={1}
• https://api.facebook.com/restserver.php?{0}
• http://api-video.facebook.com/restserver.php
• https://api.facebook.com/method/photos.upload
• https://api.facebook.com/method/photos.getAlbums?{0}
• D:\svn\din\vReveal\3.0\trunk\UploadServices\obj\x86\Release\UploadServices.pdb
• _CorDllMainmscoree.dll

Flow Anomalies
Offset FlowVA Section Description
9EDE 402000 .text JMP [static] | Indirect jump to absolute memory address
Extra Analysis
Metric Value Percentage
Ascii Code 24433 57,4948%
Null Byte Code 13340 31,3912%
© 2026 All rights reserved.