PESCAN.IO - Analysis Report Basic |
|||||||
| File Structure |
|
PE Chart Code
Header PE (light blue)
Executable sections (pink)
Non-executable sections (black)
External injected code (red)
File Structure in red = malformed or corrupted header
Chart Code For Other Files
Printable characters (blue)
Non-printable characters (black)
| Information |
| Size: 1,63 MB SHA-256 Hash: CD55F7976FF35228C4FC53C06F4C42F5489D896702E1EDB73F45F90888D62DE3 SHA-1 Hash: D727B9525A1E0622C376701AC6A27552C9E37B6E MD5 Hash: 2D4E939C1D57A72B5503970CBD459216 Imphash: 31F9C505E93F008FBF4655B5D87103CB MajorOSVersion: 4 MinorOSVersion: 0 CheckSum: 001546AB EntryPoint (rva): 24C39 SizeOfHeaders: 400 SizeOfImage: 1A3000 ImageBase: 400000 Architecture: x86 ImportTable: 1A151C Characteristics: 12F TimeDateStamp: 6AB79F29 Date: 26/09/2026 10:32:09 File Type: EXE Number Of Sections: 4 ASLR: Disabled Section Names: UPX0, UPX1, .rsrc, .SCY Number Of Executable Sections: 3 Subsystem: Windows GUI UAC Execution Level Manifest: requireAdministrator |
| Sections Info |
| Section Name | Flags | ROffset | RSize | VOffset | VSize | Entropy | Chi2 |
|---|---|---|---|---|---|---|---|
| UPX0 | 0xE0000080 Uninitialized Data Executable Readable Writeable |
400 | 50000 | 1000 | 50000 |
|
|
| UPX1 | 0xE0000040 Initialized Data Executable Readable Writeable |
50400 | 14F000 | 51000 | 14F000 |
|
|
| .rsrc | 0xC0000040 Initialized Data Readable Writeable |
19F400 | 800 | 1A0000 | 1000 |
|
|
| .SCY | 0xE0000060 Code Initialized Data Executable Readable Writeable |
19FC00 | 1E00 | 1A1000 | 2000 |
|
|
| Description |
| CompanyName: 23x LegalCopyright: (C) 2023 23x.com Inc. All rights reserved ProductName: 23x FileVersion: 1.0.1111.112 FileDescription: 23xlQS ukg@g!jWW ProductVersion: 1.0.1111.112 Comments: 23x.dll Language: Chinese (Peoples Republic of China) (ID=0x804) CodePage: Unicode (UTF-16 LE) (0x4B0) |
| Binder/Joiner/Crypter |
| 3 Executable files found |
| Entry Point |
The section number (1) - (UPX0) have the Entry Point Information -> EntryPoint (calculated) - 24039 Code -> 558BEC6AFF68E89B430068F47B420064A100000000506489250000000083EC585356578965E8FF152C82430033D28AD48915 Assembler |PUSH EBP |MOV EBP, ESP |PUSH -1 |PUSH 0X439BE8 |PUSH 0X427BF4 |MOV EAX, DWORD PTR FS:[0] |PUSH EAX |MOV DWORD PTR FS:[0], ESP |SUB ESP, 0X58 |PUSH EBX |PUSH ESI |PUSH EDI |MOV DWORD PTR [EBP - 0X18], ESP |CALL DWORD PTR [0X43822C] |XOR EDX, EDX |MOV DL, AH |
| Signatures |
| CheckSum Integrity Problem: • Header: 1394347 • Calculated: 1741978 Rich Signature Analyzer: Code -> 7314306837755E3B37755E3B37755E3B4C69523B36755E3BF47A013B31755E3BB469503B28755E3B0153543BBE755E3BF47A033B2E755E3B37755F3BD8745E3B0153553B93755E3B37755E3B36755E3BDF6A553B35755E3B5269636837755E3B Footprint md5 Hash -> D23175AA17335114211F8FB8A8378F47 • The Rich header apparently has not been modified Certificate - Digital Signature Not Found: • The file is not signed |
| Packer/Compiler |
| Compiler: Microsoft Visual C ++ Compression: UPX Detect It Easy (die) • PE: compiler: EP:Microsoft Visual C/C++(6.0 (1720-9782))[EXE32] • PE: compiler: Microsoft Visual C/C++(6.0)[libcmt] • PE: linker: Microsoft Linker(6.0)[-] • Entropy: 7.69556 |
| Suspicious Functions |
| Library | Function | Description |
|---|---|---|
| ADVAPI32.DLL | CryptAcquireContextA | Acquires a cryptographic provider context. |
| ADVAPI32.DLL | CryptReleaseContext | Releases a cryptographic provider context. |
| KERNEL32.DLL | GetModuleFileNameA | Retrieve the fully qualified path for the executable file of a specified module. |
| KERNEL32.DLL | VirtualAlloc | Reserve, commit, or both, a region of memory within the virtual address space of a process. |
| KERNEL32.DLL | RtlMoveMemory | Moves a block of memory to another location. |
| KERNEL32.DLL | WriteFile | Writes data to a specified file or input/output (I/O) device. |
| KERNEL32.DLL | LoadLibraryA | Loads the specified module into the address space of the calling process. |
| KERNEL32.DLL | GetModuleHandleA | Retrieves a handle to the specified module. |
| KERNEL32.DLL | CreateToolhelp32Snapshot | Creates a snapshot of the specified processes, heaps, threads, and modules. |
| KERNEL32.DLL | WriteProcessMemory | Writes data to an area of memory in a specified process. |
| KERNEL32.DLL | ReadProcessMemory | Reads data from an area of memory in a specified process. |
| KERNEL32.DLL | GetProcAddress | Retrieves the address of an exported function or variable from the specified dynamic-link library (DLL). |
| KERNEL32.DLL | CreateFileA | Creates or opens a file or I/O device. |
| KERNEL32.DLL | DeleteFileA | Deletes an existing file. |
| KERNEL32.DLL | GetTempPathA | Retrieves the temporary directory path. |
| KERNEL32.DLL | CreateFileW | Creates or opens a file object. |
| KERNEL32.DLL | ReadFile | Reads data from a file. |
| KERNEL32.DLL | FindFirstFileA | Starts file and directory enumeration. |
| KERNEL32.DLL | FindNextFileA | Continues file and directory enumeration. |
| KERNEL32.DLL | FindClose | Closes a file search handle. |
| KERNEL32.DLL | GetThreadContext | Retrieves a thread execution context. |
| KERNEL32.DLL | SetThreadContext | Modifies a thread execution context. |
| KERNEL32.DLL | CloseHandle | Closes an open object handle. |
| KERNEL32.DLL | IsBadReadPtr | Checks whether memory is readable. |
| KERNEL32.DLL | VirtualProtect | Changes memory protection attributes. |
| KERNEL32.DLL | CreateProcessA | Creates and starts a new process. |
| KERNEL32.DLL | ResumeThread | Resumes a suspended thread. |
| KERNEL32.DLL | OpenEventA | Opens an existing event object. |
| KERNEL32.DLL | CreateEventA | Creates or opens an event object. |
| KERNEL32.DLL | GetVersion | Retrieves the operating system version. |
| KERNEL32.DLL | OpenProcess | Opens an existing process. |
| KERNEL32.DLL | VirtualAllocEx | Allocates memory within the virtual address space of another process. |
| KERNEL32.DLL | VirtualProtectEx | Changes the protection on a region of memory in another process. |
| USER32.DLL | CallWindowProcA | Invokes the window procedure for the specified window and messages. |
| ADVAPI32.DLL | RegCreateKeyExA | Creates a new registry key or opens an existing one. |
| ADVAPI32.DLL | RegSetValueExA | Sets the data and type of a specified value under a registry key. |
| ADVAPI32.DLL | RegCreateKeyExA | Creates or opens a registry key. |
| ADVAPI32.DLL | RegOpenKeyExA | Opens an existing registry key. |
| SHELL32.DLL | ShellExecuteA | Performs a run operation on a specific file. |
| WININET.DLL | InternetOpenA | Initializes an application’s use of the WinINet functions. |
| NtosKrnl.exe | ZwUnmapViewOfSection | Unmaps a mapped view of a section from a process’s address space. |
| File Access |
| oledlg.dll ole32.dll user32.dll shlwapi.dll shell32.dll oleaut32.dll kernel32.dll gdi32.dll comctl32.dll advapi32.dll ntdll.dll yz)Kernel32.dll srv.dll WININET.dll WINHTTP.dll PSAPI.DLL OLEPRO32.DLL CRYPT32.dll WS2_32.dll WINMM.dll comdlg32.dll omdlg32.dll @.dat .INI Temp |
| File Access (UNICODE) |
| 23x.dll |
| Interest's Words |
| PassWord exec netsh attrib start comspec netstat |
| PE Carving |
| Start Offset Header | End Offset | Size (Bytes) |
|---|---|---|
| 0 | 3EF4D | 3EF4D |
| 3EF4D | 9074A | 517FD |
| 9074A | 1A1A00 | 1112B6 |
| Strings/Hex Code Found With The File Rules |
| Rule Type | Encoding | Matched (Word) |
|---|---|---|
| Entry Point | Hex Pattern | Borland Delphi 4.0 |
| Entry Point | Hex Pattern | Borland Delphi |
| Entry Point | Hex Pattern | Microsoft Visual C++ 5.0 |
| Entry Point | Hex Pattern | Microsoft Visual C++ v6.0 |
| Entry Point | Hex Pattern | Microsoft Visual C++ v6.0 |
| Entry Point | Hex Pattern | Microsoft Visual C++ |
| Resources |
| Path | DataRVA | Size | FileOffset | Code | Text |
|---|---|---|---|---|---|
| \VERSION\1\2052 | 1A005C | 314 | 19F45C | 140334000000560053005F00560045005200530049004F004E005F0049004E0046004F0000000000BD04EFFE000000000100 | ..4...V.S._.V.E.R.S.I.O.N._.I.N.F.O............... |
| Intelligent String |
| • user32.dll • shlwapi.dll • shell32.dll • oledlg.dll • oleaut32.dll • ole32.dll • gdi32.dll • comctl32.dll • advapi32.dll • kernel32.dll • wininet.dll • winhttp.dll • psapi.dll • olepro32.dll • crypt32.dll • .SCY • COMCTL32.DLL • CfIB.INI • .HLP • CLSID\%1\InprocHandler32ole32.dll • omdlg32.dll • ComSpec • 23x.dll • .PAX • CreateDialogIndirectParamA |
| Flow Anomalies |
| Offset | FlowVA | Section | Description |
|---|---|---|---|
| 1879 | 43823C | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 1946 | 438310 | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 1A74 | 438314 | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 1DDF | 4380DC | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 1E89 | 4380DC | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 1FD8 | 43831C | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 213D | 438110 | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 2191 | 438114 | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 23AB | 438028 | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 245D | 438028 | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 24F1 | 438024 | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 252F | 438020 | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 25FB | 438000 | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 2634 | 43801C | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 2665 | 438020 | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 2718 | 438018 | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 2751 | 43801C | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 2782 | 438020 | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 2B51 | 43801C | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 2B82 | 438020 | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 30AB | 58843B | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 333B | 58843F | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 372A | 588443 | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 3B32 | 588447 | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 3E41 | 58844B | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 4240 | 58844F | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 44E4 | 588453 | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 470F | 588457 | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 4765 | 58845B | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 47E6 | 58845F | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 488D | 588463 | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 4AA3 | 588443 | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 4E1D | 588467 | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 4F8E | 58846B | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 517E | 588463 | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 5208 | 58846F | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 5284 | 588473 | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 5464 | 588477 | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 5638 | 58847B | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 567D | 58847F | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 56C0 | 588483 | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 56F6 | 588483 | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 5845 | 588487 | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 58C3 | 588487 | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 593E | 58848B | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 5977 | 588483 | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 59AD | 588483 | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 5AAC | 438118 | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 5AFC | 43811C | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 847C | 438500 | UPX0 | CALL [static] | Indirect call to absolute memory address |
| BBC3 | 438504 | UPX0 | CALL [static] | Indirect call to absolute memory address |
| BC3B | 438120 | UPX0 | CALL [static] | Indirect call to absolute memory address |
| C6D8 | 438124 | UPX0 | CALL [static] | Indirect call to absolute memory address |
| C71D | 438128 | UPX0 | CALL [static] | Indirect call to absolute memory address |
| C75D | 438340 | UPX0 | CALL [static] | Indirect call to absolute memory address |
| C7AF | 43812C | UPX0 | CALL [static] | Indirect call to absolute memory address |
| C7E5 | 43812C | UPX0 | CALL [static] | Indirect call to absolute memory address |
| DC7E | 438130 | UPX0 | CALL [static] | Indirect call to absolute memory address |
| E1E4 | 438134 | UPX0 | CALL [static] | Indirect call to absolute memory address |
| E2C6 | 438138 | UPX0 | CALL [static] | Indirect call to absolute memory address |
| F5B6 | 43833C | UPX0 | CALL [static] | Indirect call to absolute memory address |
| F6B5 | 438338 | UPX0 | CALL [static] | Indirect call to absolute memory address |
| F7AC | 438334 | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 108AD | 43813C | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 108F9 | 438140 | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 10928 | 43812C | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 10AC6 | 438144 | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 10BA3 | 438148 | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 10C42 | 43814C | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 10D4B | 438308 | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 11BB0 | 438150 | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 11CCE | 438304 | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 11E75 | 438154 | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 1202E | 438158 | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 122DB | 438214 | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 12321 | 438210 | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 12362 | 438330 | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 123AF | 43812C | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 153D0 | 43820C | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 154AD | 438208 | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 15629 | 43812C | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 156EA | 438204 | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 157D4 | 43812C | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 162CF | 438500 | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 16A43 | 438504 | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 16B02 | 438324 | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 17E06 | 43820C | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 17EE3 | 438208 | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 1805F | 43812C | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 18129 | 438204 | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 18213 | 43812C | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 182A4 | 438200 | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 182E2 | 4381FC | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 1832A | 4381F8 | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 18359 | 43812C | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 1851A | 58848F | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 185D5 | 43832C | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 1865B | 43834C | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 186D1 | 43834C | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 187C5 | 43836C | UPX0 | CALL [static] | Indirect call to absolute memory address |
| 400-503FF | 1000 | UPX0 | Executable section anomaly, first bytes: 558BECE80E000000 |
| 50400-19F3FF | 51000 | UPX1 | Executable section anomaly, first bytes: D36ECAD45E3A53BC |
| 19FC00-1A19FF | 1A1000 | .SCY | Executable section anomaly, first bytes: B9161A00C9161A00 |
| Extra Analysis |
| Metric | Value | Percentage |
|---|---|---|
| Ascii Code | 1081621 | 63,2308% |
| Null Byte Code | 148997 | 8,7103% |
| NOP Cave Found | 0x9090909090 | Block Count: 178 | Total: 0,026% |
© 2026 All rights reserved.