PESCAN.IO - Analysis Report Basic

File Structure
Analysis Image
PE Chart Code
Header PE (light blue)
Executable sections (pink)
Non-executable sections (black)
External injected code (red)
File Structure in red = malformed or corrupted header

Chart Code For Other Files
Printable characters (blue)
Non-printable characters (black)
Information
Size: 1,63 MB
SHA-256 Hash: CD55F7976FF35228C4FC53C06F4C42F5489D896702E1EDB73F45F90888D62DE3
SHA-1 Hash: D727B9525A1E0622C376701AC6A27552C9E37B6E
MD5 Hash: 2D4E939C1D57A72B5503970CBD459216
Imphash: 31F9C505E93F008FBF4655B5D87103CB
MajorOSVersion: 4
MinorOSVersion: 0
CheckSum: 001546AB
EntryPoint (rva): 24C39
SizeOfHeaders: 400
SizeOfImage: 1A3000
ImageBase: 400000
Architecture: x86
ImportTable: 1A151C
Characteristics: 12F
TimeDateStamp: 6AB79F29
Date: 26/09/2026 10:32:09
File Type: EXE
Number Of Sections: 4
ASLR: Disabled
Section Names: UPX0, UPX1, .rsrc, .SCY
Number Of Executable Sections: 3
Subsystem: Windows GUI
UAC Execution Level Manifest: requireAdministrator

Sections Info
Section Name Flags ROffset RSize VOffset VSizeEntropyChi2
UPX0
0xE0000080
Uninitialized Data
Executable
Readable
Writeable
400 50000 1000 50000
6.8235
2340102.56
UPX1
0xE0000040
Initialized Data
Executable
Readable
Writeable
50400 14F000 51000 14F000
7.805
1476035.18
.rsrc
0xC0000040
Initialized Data
Readable
Writeable
19F400 800 1A0000 1000
3.247
202152.75
.SCY
0xE0000060
Code
Initialized Data
Executable
Readable
Writeable
19FC00 1E00 1A1000 2000
5.4498
111079.73
Description
CompanyName: 23x
LegalCopyright: (C) 2023 23x.com Inc. All rights reserved
ProductName: 23x
FileVersion: 1.0.1111.112
FileDescription: 23xlQS ukg@g!jWW
ProductVersion: 1.0.1111.112
Comments: 23x.dll
Language: Chinese (Peoples Republic of China) (ID=0x804)
CodePage: Unicode (UTF-16 LE) (0x4B0)

Binder/Joiner/Crypter
3 Executable files found

Entry Point
The section number (1) - (UPX0) have the Entry Point
Information -> EntryPoint (calculated) - 24039
Code -> 558BEC6AFF68E89B430068F47B420064A100000000506489250000000083EC585356578965E8FF152C82430033D28AD48915
Assembler
|PUSH EBP
|MOV EBP, ESP
|PUSH -1
|PUSH 0X439BE8
|PUSH 0X427BF4
|MOV EAX, DWORD PTR FS:[0]
|PUSH EAX
|MOV DWORD PTR FS:[0], ESP
|SUB ESP, 0X58
|PUSH EBX
|PUSH ESI
|PUSH EDI
|MOV DWORD PTR [EBP - 0X18], ESP
|CALL DWORD PTR [0X43822C]
|XOR EDX, EDX
|MOV DL, AH
Signatures
CheckSum Integrity Problem:
• Header: 1394347
• Calculated: 1741978
Rich Signature Analyzer:
Code -> 7314306837755E3B37755E3B37755E3B4C69523B36755E3BF47A013B31755E3BB469503B28755E3B0153543BBE755E3BF47A033B2E755E3B37755F3BD8745E3B0153553B93755E3B37755E3B36755E3BDF6A553B35755E3B5269636837755E3B
Footprint md5 Hash -> D23175AA17335114211F8FB8A8378F47
• The Rich header apparently has not been modified
Certificate - Digital Signature Not Found:
• The file is not signed

Packer/Compiler
Compiler: Microsoft Visual C ++
Compression: UPX
Detect It Easy (die)
• PE: compiler: EP:Microsoft Visual C/C++(6.0 (1720-9782))[EXE32]
• PE: compiler: Microsoft Visual C/C++(6.0)[libcmt]
• PE: linker: Microsoft Linker(6.0)[-]
• Entropy: 7.69556

Suspicious Functions
Library Function Description
ADVAPI32.DLL CryptAcquireContextA Acquires a cryptographic provider context.
ADVAPI32.DLL CryptReleaseContext Releases a cryptographic provider context.
KERNEL32.DLL GetModuleFileNameA Retrieve the fully qualified path for the executable file of a specified module.
KERNEL32.DLL VirtualAlloc Reserve, commit, or both, a region of memory within the virtual address space of a process.
KERNEL32.DLL RtlMoveMemory Moves a block of memory to another location.
KERNEL32.DLL WriteFile Writes data to a specified file or input/output (I/O) device.
KERNEL32.DLL LoadLibraryA Loads the specified module into the address space of the calling process.
KERNEL32.DLL GetModuleHandleA Retrieves a handle to the specified module.
KERNEL32.DLL CreateToolhelp32Snapshot Creates a snapshot of the specified processes, heaps, threads, and modules.
KERNEL32.DLL WriteProcessMemory Writes data to an area of memory in a specified process.
KERNEL32.DLL ReadProcessMemory Reads data from an area of memory in a specified process.
KERNEL32.DLL GetProcAddress Retrieves the address of an exported function or variable from the specified dynamic-link library (DLL).
KERNEL32.DLL CreateFileA Creates or opens a file or I/O device.
KERNEL32.DLL DeleteFileA Deletes an existing file.
KERNEL32.DLL GetTempPathA Retrieves the temporary directory path.
KERNEL32.DLL CreateFileW Creates or opens a file object.
KERNEL32.DLL ReadFile Reads data from a file.
KERNEL32.DLL FindFirstFileA Starts file and directory enumeration.
KERNEL32.DLL FindNextFileA Continues file and directory enumeration.
KERNEL32.DLL FindClose Closes a file search handle.
KERNEL32.DLL GetThreadContext Retrieves a thread execution context.
KERNEL32.DLL SetThreadContext Modifies a thread execution context.
KERNEL32.DLL CloseHandle Closes an open object handle.
KERNEL32.DLL IsBadReadPtr Checks whether memory is readable.
KERNEL32.DLL VirtualProtect Changes memory protection attributes.
KERNEL32.DLL CreateProcessA Creates and starts a new process.
KERNEL32.DLL ResumeThread Resumes a suspended thread.
KERNEL32.DLL OpenEventA Opens an existing event object.
KERNEL32.DLL CreateEventA Creates or opens an event object.
KERNEL32.DLL GetVersion Retrieves the operating system version.
KERNEL32.DLL OpenProcess Opens an existing process.
KERNEL32.DLL VirtualAllocEx Allocates memory within the virtual address space of another process.
KERNEL32.DLL VirtualProtectEx Changes the protection on a region of memory in another process.
USER32.DLL CallWindowProcA Invokes the window procedure for the specified window and messages.
ADVAPI32.DLL RegCreateKeyExA Creates a new registry key or opens an existing one.
ADVAPI32.DLL RegSetValueExA Sets the data and type of a specified value under a registry key.
ADVAPI32.DLL RegCreateKeyExA Creates or opens a registry key.
ADVAPI32.DLL RegOpenKeyExA Opens an existing registry key.
SHELL32.DLL ShellExecuteA Performs a run operation on a specific file.
WININET.DLL InternetOpenA Initializes an application’s use of the WinINet functions.
NtosKrnl.exe ZwUnmapViewOfSection Unmaps a mapped view of a section from a process’s address space.
File Access
oledlg.dll
ole32.dll
user32.dll
shlwapi.dll
shell32.dll
oleaut32.dll
kernel32.dll
gdi32.dll
comctl32.dll
advapi32.dll
ntdll.dll
yz)Kernel32.dll
srv.dll
WININET.dll
WINHTTP.dll
PSAPI.DLL
OLEPRO32.DLL
CRYPT32.dll
WS2_32.dll
WINMM.dll
comdlg32.dll
omdlg32.dll
@.dat
.INI
Temp

File Access (UNICODE)
23x.dll

Interest's Words
PassWord
exec
netsh
attrib
start
comspec
netstat

PE Carving
Start Offset Header End Offset Size (Bytes)
0 3EF4D 3EF4D
3EF4D 9074A 517FD
9074A 1A1A00 1112B6
Strings/Hex Code Found With The File Rules
Rule Type Encoding Matched (Word)
Entry Point Hex Pattern Borland Delphi 4.0
Entry Point Hex Pattern Borland Delphi
Entry Point Hex Pattern Microsoft Visual C++ 5.0
Entry Point Hex Pattern Microsoft Visual C++ v6.0
Entry Point Hex Pattern Microsoft Visual C++ v6.0
Entry Point Hex Pattern Microsoft Visual C++
Resources
Path DataRVA Size FileOffset CodeText
\VERSION\1\2052 1A005C 314 19F45C 140334000000560053005F00560045005200530049004F004E005F0049004E0046004F0000000000BD04EFFE000000000100..4...V.S._.V.E.R.S.I.O.N._.I.N.F.O...............
Intelligent String
• user32.dll
• shlwapi.dll
• shell32.dll
• oledlg.dll
• oleaut32.dll
• ole32.dll
• gdi32.dll
• comctl32.dll
• advapi32.dll
• kernel32.dll
• wininet.dll
• winhttp.dll
• psapi.dll
• olepro32.dll
• crypt32.dll
• .SCY
• COMCTL32.DLL
• CfIB.INI
• .HLP
• CLSID\%1\InprocHandler32ole32.dll
• omdlg32.dll
• ComSpec
• 23x.dll
• .PAX
• CreateDialogIndirectParamA

Flow Anomalies
Offset FlowVA Section Description
1879 43823C UPX0 CALL [static] | Indirect call to absolute memory address
1946 438310 UPX0 CALL [static] | Indirect call to absolute memory address
1A74 438314 UPX0 CALL [static] | Indirect call to absolute memory address
1DDF 4380DC UPX0 CALL [static] | Indirect call to absolute memory address
1E89 4380DC UPX0 CALL [static] | Indirect call to absolute memory address
1FD8 43831C UPX0 CALL [static] | Indirect call to absolute memory address
213D 438110 UPX0 CALL [static] | Indirect call to absolute memory address
2191 438114 UPX0 CALL [static] | Indirect call to absolute memory address
23AB 438028 UPX0 CALL [static] | Indirect call to absolute memory address
245D 438028 UPX0 CALL [static] | Indirect call to absolute memory address
24F1 438024 UPX0 CALL [static] | Indirect call to absolute memory address
252F 438020 UPX0 CALL [static] | Indirect call to absolute memory address
25FB 438000 UPX0 CALL [static] | Indirect call to absolute memory address
2634 43801C UPX0 CALL [static] | Indirect call to absolute memory address
2665 438020 UPX0 CALL [static] | Indirect call to absolute memory address
2718 438018 UPX0 CALL [static] | Indirect call to absolute memory address
2751 43801C UPX0 CALL [static] | Indirect call to absolute memory address
2782 438020 UPX0 CALL [static] | Indirect call to absolute memory address
2B51 43801C UPX0 CALL [static] | Indirect call to absolute memory address
2B82 438020 UPX0 CALL [static] | Indirect call to absolute memory address
30AB 58843B UPX0 CALL [static] | Indirect call to absolute memory address
333B 58843F UPX0 CALL [static] | Indirect call to absolute memory address
372A 588443 UPX0 CALL [static] | Indirect call to absolute memory address
3B32 588447 UPX0 CALL [static] | Indirect call to absolute memory address
3E41 58844B UPX0 CALL [static] | Indirect call to absolute memory address
4240 58844F UPX0 CALL [static] | Indirect call to absolute memory address
44E4 588453 UPX0 CALL [static] | Indirect call to absolute memory address
470F 588457 UPX0 CALL [static] | Indirect call to absolute memory address
4765 58845B UPX0 CALL [static] | Indirect call to absolute memory address
47E6 58845F UPX0 CALL [static] | Indirect call to absolute memory address
488D 588463 UPX0 CALL [static] | Indirect call to absolute memory address
4AA3 588443 UPX0 CALL [static] | Indirect call to absolute memory address
4E1D 588467 UPX0 CALL [static] | Indirect call to absolute memory address
4F8E 58846B UPX0 CALL [static] | Indirect call to absolute memory address
517E 588463 UPX0 CALL [static] | Indirect call to absolute memory address
5208 58846F UPX0 CALL [static] | Indirect call to absolute memory address
5284 588473 UPX0 CALL [static] | Indirect call to absolute memory address
5464 588477 UPX0 CALL [static] | Indirect call to absolute memory address
5638 58847B UPX0 CALL [static] | Indirect call to absolute memory address
567D 58847F UPX0 CALL [static] | Indirect call to absolute memory address
56C0 588483 UPX0 CALL [static] | Indirect call to absolute memory address
56F6 588483 UPX0 CALL [static] | Indirect call to absolute memory address
5845 588487 UPX0 CALL [static] | Indirect call to absolute memory address
58C3 588487 UPX0 CALL [static] | Indirect call to absolute memory address
593E 58848B UPX0 CALL [static] | Indirect call to absolute memory address
5977 588483 UPX0 CALL [static] | Indirect call to absolute memory address
59AD 588483 UPX0 CALL [static] | Indirect call to absolute memory address
5AAC 438118 UPX0 CALL [static] | Indirect call to absolute memory address
5AFC 43811C UPX0 CALL [static] | Indirect call to absolute memory address
847C 438500 UPX0 CALL [static] | Indirect call to absolute memory address
BBC3 438504 UPX0 CALL [static] | Indirect call to absolute memory address
BC3B 438120 UPX0 CALL [static] | Indirect call to absolute memory address
C6D8 438124 UPX0 CALL [static] | Indirect call to absolute memory address
C71D 438128 UPX0 CALL [static] | Indirect call to absolute memory address
C75D 438340 UPX0 CALL [static] | Indirect call to absolute memory address
C7AF 43812C UPX0 CALL [static] | Indirect call to absolute memory address
C7E5 43812C UPX0 CALL [static] | Indirect call to absolute memory address
DC7E 438130 UPX0 CALL [static] | Indirect call to absolute memory address
E1E4 438134 UPX0 CALL [static] | Indirect call to absolute memory address
E2C6 438138 UPX0 CALL [static] | Indirect call to absolute memory address
F5B6 43833C UPX0 CALL [static] | Indirect call to absolute memory address
F6B5 438338 UPX0 CALL [static] | Indirect call to absolute memory address
F7AC 438334 UPX0 CALL [static] | Indirect call to absolute memory address
108AD 43813C UPX0 CALL [static] | Indirect call to absolute memory address
108F9 438140 UPX0 CALL [static] | Indirect call to absolute memory address
10928 43812C UPX0 CALL [static] | Indirect call to absolute memory address
10AC6 438144 UPX0 CALL [static] | Indirect call to absolute memory address
10BA3 438148 UPX0 CALL [static] | Indirect call to absolute memory address
10C42 43814C UPX0 CALL [static] | Indirect call to absolute memory address
10D4B 438308 UPX0 CALL [static] | Indirect call to absolute memory address
11BB0 438150 UPX0 CALL [static] | Indirect call to absolute memory address
11CCE 438304 UPX0 CALL [static] | Indirect call to absolute memory address
11E75 438154 UPX0 CALL [static] | Indirect call to absolute memory address
1202E 438158 UPX0 CALL [static] | Indirect call to absolute memory address
122DB 438214 UPX0 CALL [static] | Indirect call to absolute memory address
12321 438210 UPX0 CALL [static] | Indirect call to absolute memory address
12362 438330 UPX0 CALL [static] | Indirect call to absolute memory address
123AF 43812C UPX0 CALL [static] | Indirect call to absolute memory address
153D0 43820C UPX0 CALL [static] | Indirect call to absolute memory address
154AD 438208 UPX0 CALL [static] | Indirect call to absolute memory address
15629 43812C UPX0 CALL [static] | Indirect call to absolute memory address
156EA 438204 UPX0 CALL [static] | Indirect call to absolute memory address
157D4 43812C UPX0 CALL [static] | Indirect call to absolute memory address
162CF 438500 UPX0 CALL [static] | Indirect call to absolute memory address
16A43 438504 UPX0 CALL [static] | Indirect call to absolute memory address
16B02 438324 UPX0 CALL [static] | Indirect call to absolute memory address
17E06 43820C UPX0 CALL [static] | Indirect call to absolute memory address
17EE3 438208 UPX0 CALL [static] | Indirect call to absolute memory address
1805F 43812C UPX0 CALL [static] | Indirect call to absolute memory address
18129 438204 UPX0 CALL [static] | Indirect call to absolute memory address
18213 43812C UPX0 CALL [static] | Indirect call to absolute memory address
182A4 438200 UPX0 CALL [static] | Indirect call to absolute memory address
182E2 4381FC UPX0 CALL [static] | Indirect call to absolute memory address
1832A 4381F8 UPX0 CALL [static] | Indirect call to absolute memory address
18359 43812C UPX0 CALL [static] | Indirect call to absolute memory address
1851A 58848F UPX0 CALL [static] | Indirect call to absolute memory address
185D5 43832C UPX0 CALL [static] | Indirect call to absolute memory address
1865B 43834C UPX0 CALL [static] | Indirect call to absolute memory address
186D1 43834C UPX0 CALL [static] | Indirect call to absolute memory address
187C5 43836C UPX0 CALL [static] | Indirect call to absolute memory address
400-503FF 1000 UPX0 Executable section anomaly, first bytes: 558BECE80E000000
50400-19F3FF 51000 UPX1 Executable section anomaly, first bytes: D36ECAD45E3A53BC
19FC00-1A19FF 1A1000 .SCY Executable section anomaly, first bytes: B9161A00C9161A00
Extra Analysis
Metric Value Percentage
Ascii Code 1081621 63,2308%
Null Byte Code 148997 8,7103%
NOP Cave Found 0x9090909090 Block Count: 178 | Total: 0,026%
© 2026 All rights reserved.