PESCAN.IO - Analysis Report Basic

File Structure
Analysis Image
PE Chart Code
Header PE (light blue)
Executable sections (pink)
Non-executable sections (black)
External injected code (red)
File Structure in red = malformed or corrupted header

Chart Code For Other Files
Printable characters (blue)
Non-printable characters (black)
Information
Icon: Icon
Size: 5,94 MB
SHA-256 Hash: 51312177A9C81AE610E7B73A8D3330C54C130BAF901516351D250357D0C3FF6D
SHA-1 Hash: 18CFD77094A85BA4DD930CDCFC36FD0CBC01C446
MD5 Hash: 35956356B20F6D37C4FDCAF0D75804F0
Imphash: 40AB50289F7EF5FAE60801F88D4541FC
MajorOSVersion: 6
MinorOSVersion: 1
CheckSum: 005FA8CB
EntryPoint (rva): A83BC
SizeOfHeaders: 400
SizeOfImage: E7000
ImageBase: 400000
Architecture: x86
ExportTable: B7000
ImportTable: B5000
IAT: B52D4
Characteristics: 103
TimeDateStamp: 666711EF
Date: 10/06/2024 14:47:11
File Type: EXE
Number Of Sections: 10
ASLR: Enabled
Section Names: .text, .itext, .data, .bss, .idata, .didata, .edata, .tls, .rdata, .rsrc
Number Of Executable Sections: 2
Subsystem: Windows GUI
UAC Execution Level Manifest: asInvoker

Sections Info
Section Name Flags ROffset RSize VOffset VSizeEntropyChi2
.text
0x60000020
Code
Executable
Readable
400 A5800 1000 A568C
6.3772
6748568.4
.itext
0x60000020
Code
Executable
Readable
A5C00 1C00 A7000 1B64
6.1093
90975.64
.data
0xC0000040
Initialized Data
Readable
Writeable
A7800 3A00 A9000 3838
4.9592
589237.69
.bss
0xC0000000
Readable
Writeable
0 0 AD000 7258
N/A
N/A
.idata
0xC0000040
Initialized Data
Readable
Writeable
AB200 1000 B5000 FEC
5.0204
76756.5
.didata
0xC0000040
Initialized Data
Readable
Writeable
AC200 200 B6000 1A4
2.7293
55949
.edata
0x40000040
Initialized Data
Readable
AC400 200 B7000 71
1.3056
94269
.tls
0xC0000000
Readable
Writeable
0 0 B8000 18
N/A
N/A
.rdata
0x40000040
Initialized Data
Readable
AC600 200 B9000 5D
1.3893
93353
.rsrc
0x40000040
Initialized Data
Readable
AC800 2CC00 BA000 2CA90
2.8586
16831324.61
Description
CompanyName: AppSalt
LegalCopyright: AppSalt
ProductName: DeskRest
FileVersion: 1.0.2.1
FileDescription: DeskRest installer
ProductVersion: 1.0.2.1
Comments: This installation was built with Inno Setup.
Language: Unknown (ID=0x0)
CodePage: Unicode (UTF-16 LE) (0x4B0)

Binder/Joiner/Crypter
Dropper code detected (EOF) - 5,04 MB

Entry Point
The section number (2) - (.itext) have the Entry Point
Information -> EntryPoint (calculated) - A6FBC
Code -> 558BEC83C4A453565733C08945C48945C08945A48945D08945C88945CC8945D48945D88945ECB8BC2E4A00E85079F6FF33C0
Assembler
|PUSH EBP
|MOV EBP, ESP
|ADD ESP, -0X5C
|PUSH EBX
|PUSH ESI
|PUSH EDI
|XOR EAX, EAX
|MOV DWORD PTR [EBP - 0X3C], EAX
|MOV DWORD PTR [EBP - 0X40], EAX
|MOV DWORD PTR [EBP - 0X5C], EAX
|MOV DWORD PTR [EBP - 0X30], EAX
|MOV DWORD PTR [EBP - 0X38], EAX
|MOV DWORD PTR [EBP - 0X34], EAX
|MOV DWORD PTR [EBP - 0X2C], EAX
|MOV DWORD PTR [EBP - 0X28], EAX
|MOV DWORD PTR [EBP - 0X14], EAX
|MOV EAX, 0X4A2EBC
|CALL 0X40FD3C
|XOR EAX, EAX
Signatures
Certificate - Digital Signature:
• The file is signed and the signature is correct

Packer/Compiler
Detect It Easy (die)
• PE: installer: Inno Setup Module(6.3.0)[-]
• PE: compiler: Embarcadero Delphi(XE2-XE6)[-]
• PE: linker: Turbo Linker(2.25*,Delphi)[-]
• PE: overlay: Inno Setup Installer data(-)[-]
• Entropy: 7.89078

Suspicious Functions
Library Function Description
KERNEL32.DLL VirtualAlloc Reserve, commit, or both, a region of memory within the virtual address space of a process.
KERNEL32.DLL WriteFile Writes data to a specified file or input/output (I/O) device.
KERNEL32.DLL LoadLibraryA Loads the specified module into the address space of the calling process.
KERNEL32.DLL LoadLibraryW Loads the specified module into the address space of the calling process.
KERNEL32.DLL GetModuleHandleW Retrieves a handle to the specified module.
KERNEL32.DLL GetProcAddress Retrieves the address of an exported function or variable from the specified dynamic-link library (DLL).
KERNEL32.DLL CreateFileW Creates or opens a file object.
KERNEL32.DLL ReadFile Reads data from a file.
KERNEL32.DLL FindFirstFileW Starts file and directory enumeration.
KERNEL32.DLL FindClose Closes a file search handle.
KERNEL32.DLL ExitThread Terminates the current thread.
KERNEL32.DLL CloseHandle Closes an open object handle.
KERNEL32.DLL VirtualProtect Changes memory protection attributes.
KERNEL32.DLL CreateProcessW Creates and starts a new process.
KERNEL32.DLL ResumeThread Resumes a suspended thread.
KERNEL32.DLL CreateEventW Creates or opens an event object.
KERNEL32.DLL GetSystemInfo Retrieves system hardware information.
KERNEL32.DLL GetVersion Retrieves the operating system version.
ADVAPI32.DLL RegOpenKeyExW Opens an existing registry key.
Windows REG
System\D

Windows REG (UNICODE)
Software\Embarcadero\Locales
Software\CodeGear\Locales
Software\Borland\Locales
Software\Borland\Delphi\Locales
SOFTWARE\Microsoft\Windows NT\CurrentVersion

File Access
winhttp.dll
version.dll
textshaping.dll
netutils.dll
netapi32.dll
mpr.dll
comctl32.dll
kernel32.dll
user32.dll
advapi32.dll
oleaut32.dll
System.Sys
dSystem.Sys
PathFuncSystem.SysUtilsSystem.Internal.ExcUtilsSystem.Sys
PathFuncSystem.Sys
System.Sys
?System.Sys
.dat
Temp

File Access (UNICODE)
GetLogicalProcessorInformationkernel32.dll
kernel32.dll
DeskRest.exe
shell32.dll
ntmarta.dll
clbcatq.dll
comres.dll
profapi.dll
version.dll
oleacc.dll
cryptbase.dll
dwmapi.dll
propsys.dll
apphelp.dll
setupapi.dll
userenv.dll
uxtheme.dll
advapi32.dll
oleaut32.dll
NTDLL.DLL
ntdll.dll
Temp
UserProfile

Interest's Words
PADDINGX
PassWord
exec
attrib
start
shutdown
systeminfo
ping
expand

Interest's Words (UNICODE)
PassWord
exec
start
shutdown
ping
expand

URLs
http://schemas.microsoft.com/SMI/2005/WindowsSettings
http://ocsp.digicert.com
http://cacerts.digicert.com/DigiCertTrustedRootG4.crt
http://crl3.digicert.com/DigiCertTrustedRootG4.crl
http://www.digicert.com/CPS0
http://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl
http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl
http://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt
http://cacerts.digicert.com/DigiCertTrustedG4TimeStampingRSA4096SHA2562025CA1.crt
http://crl3.digicert.com/DigiCertTrustedG4TimeStampingRSA4096SHA2562025CA1.crl
http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt
http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl

URLs (UNICODE)
https://jrsoftware.org/ishelp/index.php?topic=setupcmdline

Strings/Hex Code Found With The File Rules
Rule Type Encoding Matched (Word)
Text Unicode Privileges (SeShutdownPrivilege)
Text Ascii Process of gathering information about network resources (Enumeration)
Text Unicode Malicious rerouting of traffic to an attacker-controlled site (Redirect)
Text Ascii Technique used to capture communications between systems (Intercept)
Entry Point Hex Pattern Borland Delphi 4.0
Entry Point Hex Pattern fasm - Tomasz Grysztar
Resources
Path DataRVA Size FileOffset CodeText
\ICON\100\1033 BA5B8 468 ACDB8 280000001000000020000000010020000000000000040000C30E0000C30E0000000000000000000000000000000000000000(....... ..... ...................................
\ICON\101\1033 BAA20 988 AD220 280000001800000030000000010020000000000000090000C30E0000C30E0000000000000000000000000000000000000000(.......0..... ...................................
\ICON\102\1033 BB3A8 10A8 ADBA8 280000002000000040000000010020000000000000100000C30E0000C30E0000000000000000000000000000000000000000(... ...@..... ...................................
\ICON\103\1033 BC450 25A8 AEC50 280000003000000060000000010020000000000000240000C30E0000C30E0000000000000000000000000000000000000000(...0........ ......$............................
\ICON\104\1033 BE9F8 4228 B11F8 280000004000000080000000010020000000000000400000C30E0000C30E0000000000000000000000000000000000000000(...@......... ......@............................
\ICON\105\1033 C2C20 5488 B5420 280000004800000090000000010020000000000000510000C30E0000C30E0000000000000000000000000000000000000000(...H......... ......Q............................
\ICON\106\1033 C80A8 94A8 BA8A8 2800000060000000C0000000010020000000000000900000C30E0000C30E0000000000000000000000000000000000000000(............ ...................................
\ICON\107\1033 D1550 10828 C3D50 280000008000000000010000010020000000000000000100C30E0000C30E0000000000000000000000000000000000000000(............. ...................................
\ICON\108\1033 E1D78 1B8B D4578 89504E470D0A1A0A0000000D49484452000001000000010008060000005C72A866000000016F724E5401CFA2779A00001B45.PNG........IHDR.............\r.f....orNT...w....E
\STRING\4086\0 E3904 3F8 D6104 1300570069006E0064006F00770073002000530065007200760065007200200032003000310036001300570069006E006400..W.i.n.d.o.w.s. .S.e.r.v.e.r. .2.0.1.6...W.i.n.d.
\STRING\4087\0 E3CFC 2DC D64FC 3700560041005200200061006E00640020004F0055005400200061007200670075006D0065006E007400730020006D0075007.V.A.R. .a.n.d. .O.U.T. .a.r.g.u.m.e.n.t.s. .m.u.
\STRING\4088\0 E3FD8 430 D67D8 1500500072006F0070006500720074007900200069007300200072006500610064002D006F006E006C007900170025007300..P.r.o.p.e.r.t.y. .i.s. .r.e.a.d.-.o.n.l.y...%.s.
\STRING\4089\0 E4408 44C D6C08 1A00430061006E006E006F0074002000610073007300690067006E0020006100200025007300200074006F00200061002000..C.a.n.n.o.t. .a.s.s.i.g.n. .a. .%.s. .t.o. .a. .
\STRING\4090\0 E4854 2D4 D7054 06004D006F006E006400610079000700540075006500730064006100790009005700650064006E0065007300640061007900..M.o.n.d.a.y...T.u.e.s.d.a.y...W.e.d.n.e.s.d.a.y.
\STRING\4091\0 E4B28 B8 D7328 03004D006100790004004A0075006E00650004004A0075006C00790006004100750067007500730074000900530065007000..M.a.y...J.u.n.e...J.u.l.y...A.u.g.u.s.t...S.e.p.
\STRING\4092\0 E4BE0 9C D73E0 03004A0061006E00030046006500620003004D0061007200030041007000720003004D006100790003004A0075006E000300..J.a.n...F.e.b...M.a.r...A.p.r...M.a.y...J.u.n...
\STRING\4093\0 E4C7C 374 D747C 140049006E00760061006C00690064002000760061007200690061006E0074002000740079007000650017004F0070006500..I.n.v.a.l.i.d. .v.a.r.i.a.n.t. .t.y.p.e...O.p.e.
\STRING\4094\0 E4FF0 398 D77F0 2200560061007200690061006E00740020006D006500740068006F0064002000630061006C006C00730020006E006F007400".V.a.r.i.a.n.t. .m.e.t.h.o.d. .c.a.l.l.s. .n.o.t.
\STRING\4095\0 E5388 368 D7B88 200049006E00760061006C0069006400200066006C006F006100740069006E006700200070006F0069006E00740020006F00.I.n.v.a.l.i.d. .f.l.o.a.t.i.n.g. .p.o.i.n.t. .o.
\STRING\4096\0 E56F0 2A4 D7EF0 2100270025007300270020006900730020006E006F007400200061002000760061006C0069006400200069006E0074006500!.’.%.s.’. .i.s. .n.o.t. .a. .v.a.l.i.d. .i.n.t.e.
\RCDATA\DVCLAL\0 E5994 10 D8194 23785D23B6A5F31943F3400226D111C7x]....C.@.&...
\RCDATA\PACKAGEINFO\0 E59A4 310 D81A4 000010CC0000000033000000010A53657475704C6472001C0F57696E6170692E516F73000CC457696E6170692E57696E646F........3.....SetupLdr...Winapi.Qos...Winapi.Windo
\RCDATA\11111\0 E5CB4 2C D84B4 72446C507453CDE6D77B0B2A0100000062DE5E0045F6510098FC30005EA7248AC484510000940D00A762B74CrDlPtS...{.*....b..E.Q...0..$...Q......b.L
\GROUP_ICON\MAINICON\1033 E5CE0 84 D84E0 000001000900101000000100200068040000640018180000010020008809000065002020000001002000A810000066003030............ .h...d....... .....e. .... .....f.00
\VERSION\1\1033 E5D64 584 D8564 840534000000560053005F00560045005200530049004F004E005F0049004E0046004F0000000000BD04EFFE000001000000..4...V.S._.V.E.R.S.I.O.N._.I.N.F.O...............
\24\1\1033 E62E8 7A8 D8AE8 3C3F786D6C2076657273696F6E3D22312E302220656E636F64696E673D225554462D3822207374616E64616C6F6E653D2279<?xml version="1.0" encoding="UTF-8" standalone="y
Intelligent String
• user32.dll
• kernel32.dll
• .tmp
• oleaut32.dll
• .bss
• @.tls
• ntdll.dll
• NTDLL.DLL
• advapi32.dll
• x:\dirname"
• For more detailed information, please visit https://jrsoftware.org/ishelp/index.php?topic=setupcmdline
• uxtheme.dll
• userenv.dll
• setupapi.dll
• apphelp.dll
• propsys.dll
• dwmapi.dll
• cryptbase.dll
• oleacc.dll
• version.dll
• profapi.dll
• comres.dll
• clbcatq.dll
• ntmarta.dll
• shell32.dll
• GetThreadLocalecomctl32.dll
• SafeArrayCreateadvapi32.dll
• MessageBoxAkernel32.dll
• <dpiAware xmlns="http://schemas.microsoft.com/SMI/2005/WindowsSettings">true</dpiAware>
• :060U00Uq]dL.g?O0U0E1-Q!m0U0y+m0k0$+0http://ocsp.digicert.com0C+07http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0EU>0<0:864http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0U

Flow Anomalies
Offset FlowVA Section Description
4590 4B52DC .text JMP [static] | Indirect jump to absolute memory address
4598 4B5310 .text JMP [static] | Indirect jump to absolute memory address
45A0 4B5434 .text JMP [static] | Indirect jump to absolute memory address
45A8 4B5408 .text JMP [static] | Indirect jump to absolute memory address
45B0 4B53EC .text JMP [static] | Indirect jump to absolute memory address
45B8 4B53A4 .text JMP [static] | Indirect jump to absolute memory address
45C0 4B5384 .text JMP [static] | Indirect jump to absolute memory address
45C8 4B53C4 .text JMP [static] | Indirect jump to absolute memory address
45D0 4B543C .text JMP [static] | Indirect jump to absolute memory address
45D8 4B5338 .text JMP [static] | Indirect jump to absolute memory address
45E0 4B5370 .text JMP [static] | Indirect jump to absolute memory address
45E8 4B535C .text JMP [static] | Indirect jump to absolute memory address
45F0 4B5438 .text JMP [static] | Indirect jump to absolute memory address
45F8 4B52FC .text JMP [static] | Indirect jump to absolute memory address
4600 4B5354 .text JMP [static] | Indirect jump to absolute memory address
4608 4B5308 .text JMP [static] | Indirect jump to absolute memory address
4610 4B5374 .text JMP [static] | Indirect jump to absolute memory address
4618 4B5328 .text JMP [static] | Indirect jump to absolute memory address
4620 4B5318 .text JMP [static] | Indirect jump to absolute memory address
4628 4B54B8 .text JMP [static] | Indirect jump to absolute memory address
4630 4B53BC .text JMP [static] | Indirect jump to absolute memory address
4638 4B532C .text JMP [static] | Indirect jump to absolute memory address
4640 4B5314 .text JMP [static] | Indirect jump to absolute memory address
4648 4B53C8 .text JMP [static] | Indirect jump to absolute memory address
4650 4B539C .text JMP [static] | Indirect jump to absolute memory address
4658 4B5368 .text JMP [static] | Indirect jump to absolute memory address
4660 4B52D4 .text JMP [static] | Indirect jump to absolute memory address
4668 4B540C .text JMP [static] | Indirect jump to absolute memory address
4670 4B5404 .text JMP [static] | Indirect jump to absolute memory address
4678 4B541C .text JMP [static] | Indirect jump to absolute memory address
4680 4B53F0 .text JMP [static] | Indirect jump to absolute memory address
4688 4B5458 .text JMP [static] | Indirect jump to absolute memory address
4690 4B5470 .text JMP [static] | Indirect jump to absolute memory address
4698 4B544C .text JMP [static] | Indirect jump to absolute memory address
46A0 4B54B0 .text JMP [static] | Indirect jump to absolute memory address
46A8 4B533C .text JMP [static] | Indirect jump to absolute memory address
46D0 4B6094 .text JMP [static] | Indirect jump to absolute memory address
46D8 4B5528 .text JMP [static] | Indirect jump to absolute memory address
46E0 4B5508 .text JMP [static] | Indirect jump to absolute memory address
46E8 4B551C .text JMP [static] | Indirect jump to absolute memory address
46F0 4B534C .text JMP [static] | Indirect jump to absolute memory address
46F8 4B53C0 .text JMP [static] | Indirect jump to absolute memory address
4700 4B5394 .text JMP [static] | Indirect jump to absolute memory address
4708 4B53F8 .text JMP [static] | Indirect jump to absolute memory address
4710 4B5378 .text JMP [static] | Indirect jump to absolute memory address
4718 4B54C8 .text JMP [static] | Indirect jump to absolute memory address
4720 4B54E8 .text JMP [static] | Indirect jump to absolute memory address
4728 4B54E4 .text JMP [static] | Indirect jump to absolute memory address
4730 4B53F4 .text JMP [static] | Indirect jump to absolute memory address
4758 4B6090 .text JMP [static] | Indirect jump to absolute memory address
4760 4B52F8 .text JMP [static] | Indirect jump to absolute memory address
4768 4B5300 .text JMP [static] | Indirect jump to absolute memory address
4770 4B5400 .text JMP [static] | Indirect jump to absolute memory address
4778 4B53E4 .text JMP [static] | Indirect jump to absolute memory address
4780 4B53D4 .text JMP [static] | Indirect jump to absolute memory address
47B4 4B53B8 .text JMP [static] | Indirect jump to absolute memory address
47BC 4B52F0 .text JMP [static] | Indirect jump to absolute memory address
47C4 4B5380 .text JMP [static] | Indirect jump to absolute memory address
47CC 4B5434 .text JMP [static] | Indirect jump to absolute memory address
6354 4A9774 .text CALL [static] | Indirect call to absolute memory address
636C 4A9768 .text CALL [static] | Indirect call to absolute memory address
6388 4A976C .text CALL [static] | Indirect call to absolute memory address
63A9 4A9770 .text CALL [static] | Indirect call to absolute memory address
63C2 4A976C .text CALL [static] | Indirect call to absolute memory address
63DB 4A9768 .text CALL [static] | Indirect call to absolute memory address
642F 4AD028 .text CALL [static] | Indirect call to absolute memory address
646E 4AD010 .text CALL [static] | Indirect call to absolute memory address
69E7 4A9044 .text CALL [static] | Indirect call to absolute memory address
6A05 4A9040 .text CALL [static] | Indirect call to absolute memory address
6AE8 4AD03C .text CALL [static] | Indirect call to absolute memory address
6F3E FFC0 .text JMP [static] | Indirect jump to absolute memory address
80B0 4AD01C .text CALL [static] | Indirect call to absolute memory address
80CE 4AD01C .text CALL [static] | Indirect call to absolute memory address
80E6 4AD01C .text CALL [static] | Indirect call to absolute memory address
8158 4AD01C .text CALL [static] | Indirect call to absolute memory address
8178 4AD01C .text CALL [static] | Indirect call to absolute memory address
8195 4AD01C .text CALL [static] | Indirect call to absolute memory address
8272 4AD020 .text CALL [static] | Indirect call to absolute memory address
8377 4AD018 .text CALL [static] | Indirect call to absolute memory address
83FA 4AD020 .text CALL [static] | Indirect call to absolute memory address
859A 4AD01C .text JMP [static] | Indirect jump to absolute memory address
8720 4AD020 .text CALL [static] | Indirect call to absolute memory address
8AF7 4AD35C .text CALL [static] | Indirect call to absolute memory address
8C74 4AD038 .text CALL [static] | Indirect call to absolute memory address
8D1D 4A9038 .text CALL [static] | Indirect call to absolute memory address
8D82 4A903C .text CALL [static] | Indirect call to absolute memory address
A291 4A9010 .text CALL [static] | Indirect call to absolute memory address
A949 4A9014 .text CALL [static] | Indirect call to absolute memory address
AA30 4A9018 .text CALL [static] | Indirect call to absolute memory address
C26F FF .text JMP [static] | Indirect jump to absolute memory address
C6AB 4AFC04 .text CALL [static] | Indirect call to absolute memory address
C6C8 4AFC04 .text CALL [static] | Indirect call to absolute memory address
C6E9 4AFC0C .text CALL [static] | Indirect call to absolute memory address
C747 4AFC08 .text CALL [static] | Indirect call to absolute memory address
C7A4 4AFC08 .text CALL [static] | Indirect call to absolute memory address
C7D7 4AFC08 .text CALL [static] | Indirect call to absolute memory address
E8D9 4A9050 .text CALL [static] | Indirect call to absolute memory address
EADC 4B5318 .text JMP [static] | Indirect jump to absolute memory address
EAE4 4B5314 .text JMP [static] | Indirect jump to absolute memory address
EAEC 4B5460 .text JMP [static] | Indirect jump to absolute memory address
D9400 N/A *Overlay* 7A6C621A16E694B7E00C5D0026968E700017F7EC | zlb.......].&..p....
Extra Analysis
Metric Value Percentage
Ascii Code 4138239 66,4488%
Null Byte Code 263424 4,2299%
© 2026 All rights reserved.