PESCAN.IO - Analysis Report Basic

File Structure
Analysis Image
PE Chart Code
Header PE (light blue)
Executable sections (pink)
Non-executable sections (black)
External injected code (red)
File Structure in red = malformed or corrupted header

Chart Code For Other Files
Printable characters (blue)
Non-printable characters (black)
Information
Size: 76,00 KB
SHA-256 Hash: 3C800154F358414503FBBF0825B4077044FC0BFA319B6546C73636A6D4D51E3B
SHA-1 Hash: 562F83944C442DE21B918A7EF77826AEF17B82EF
MD5 Hash: 5E276910385AE62AA41C34FAEB3E7316
Imphash: F34D5F2D4577ED6D9CEEC516C1F5A744
MajorOSVersion: 4
MinorOSVersion: 0
CheckSum: 00018DB3
EntryPoint (rva): 1808A
SizeOfHeaders: 400
SizeOfImage: 1C000
ImageBase: 400000
Architecture: x86
ImportTable: 9158
IAT: 18080
Characteristics: 22
TimeDateStamp: 68532158
Date: 18/06/2025 20:28:08
File Type: EXE
Number Of Sections: 5
ASLR: Disabled
Section Names (Optional Header): .f-)k, .text, .rsrc, *unnamed*, .reloc
Number Of Executable Sections: 2
Subsystem: Windows Console
[Incomplete Binary or Compressor Packer - 36,00 KB Missing]

Sections Info
Section Name Flags ROffset RSize VOffset VSizeEntropyChi2
.f -)k
0xE0000040
Initialized Data
Executable
Readable
Writeable
400 4E00 2000 4CE8
7.9903
269.31
.text
0x60000020
Code
Executable
Readable
5200 D400 8000 D274
5.4804
1271310.58
.rsrc
0x40000040
Initialized Data
Readable
12600 600 16000 4EC
5.1082
23253
*unnamed*
0x60000020
Code
Executable
Readable
12C00 200 18000 90
0.1387
127005
.reloc
0x42000040
Initialized Data
GP-Relative
Readable
12E00 200 1A000 C
0.1019
128015
Entry Point
The section number (4) have the Entry Point
Information -> EntryPoint (calculated) - 12C8A
Code -> FF25808041000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
EP changed to another address -> (Address Of EntryPoint > Base Of Data)
Assembler
|JMP DWORD PTR [0X418080]
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
Signatures
CheckSum Integrity Problem:
Header: 101811
Calculated: 110126
Certificate - Digital Signature Not Found:
• The file is not signed

Packer/Compiler
Compiler: Microsoft Visual .NET - (You can use a decompiler for this...)
AnyCPU: True
Version: v4.0
--------> Agile .NET Obfuscator
Detect It Easy (die)
PE: library: .NET(v4.0.30319)[-]
PE: linker: Microsoft Linker(48.0)[-]
Entropy: 6.40996

Suspicious Functions
Library Function Description
KERNEL32.DLL VirtualProtect Changes memory protection attributes.
File Access
kernel32.dll
mscoree.dll

File Access (UNICODE)
4.0.0.0 AddInProcess.exe
ComponentModel.Dat
Tasks.Dat
b77a5c561934e089System.Dat
b77a5c561934e089System.Dat

Interest's Words
PADDINGX
Encrypt
Encryption
PassWord
exec
attrib
start
pause
ping
expand
replace

IP Addresses
10.0.0.0

Strings/Hex Code Found With The File Rules
Rule Type Encoding Matched (Word)
Text Ascii Encryption (ICryptoTransform)
Text Ascii Encryption (Rijndael)
Text Ascii Encryption (RijndaelManaged)
Text Ascii Malicious code executed after exploiting a vulnerability (Payload)
Text Ascii Technique used to make code harder to analyze (Obfuscation)
Text Ascii Process of gathering information about network resources (Enumeration)
Text Ascii Malicious rerouting of traffic to an attacker-controlled site (Redirect)
Entry Point Hex Pattern Microsoft Visual C++ 8
Entry Point Hex Pattern Microsoft Visual C++ 8.0
Resources
Path DataRVA Size FileOffset CodeText
\24\1\1033 16058 494 12658 3C617373656D626C7920786D6C6E733D2275726E3A736368656D61732D6D6963726F736F66742D636F6D3A61736D2E763122<assembly xmlns="urn:schemas-microsoft-com:asm.v1"
Intelligent String
• _CorExeMainmscoree.dll

Flow Anomalies
Offset FlowVA Section Description
12C8A 418080 *unnamed* JMP [static] | Indirect jump to absolute memory address
400-51FF 2000 .f -)k Executable section anomaly, first bytes: DE2203D24CBB1811
12C00-12DFF 18000 *unnamed* Executable section anomaly, first bytes: 0000000000000000
Extra Analysis
Metric Value Percentage
Ascii Code 49553 63,6732%
Null Byte Code 17884 22,9801%
© 2026 All rights reserved.