PESCAN.IO - Analysis Report Basic

File Structure
Analysis Image
PE Chart Code
Header PE (light blue)
Executable sections (pink)
Non-executable sections (black)
External injected code (red)
File Structure in red = malformed or corrupted header

Chart Code For Other Files
Printable characters (blue)
Non-printable characters (black)
Information
Size: 69,50 KB
SHA-256 Hash: F51D2153D382F49A312D4672BF8DA3F41209765C99E9A026B026CE632A4B2A1E
SHA-1 Hash: 5AA73E65F0C87A9B65420B33D4152F6FE6862FFA
MD5 Hash: 685692E9905DDCEE43D6C85469C91D36
Imphash: F34D5F2D4577ED6D9CEEC516C1F5A744
MajorOSVersion: 4
MinorOSVersion: 0
CheckSum: 00000000
EntryPoint (rva): 12A5E
SizeOfHeaders: 200
SizeOfImage: 18000
ImageBase: 400000
Architecture: x86
ImportTable: 12A0A
IAT: 2000
Characteristics: 22
TimeDateStamp: 6A5E8F81
Date: 20/07/2026 21:13:37
File Type: EXE
Number Of Sections: 3
ASLR: Disabled
Section Names: .text, .rsrc, .reloc
Number Of Executable Sections: 1
Subsystem: Windows GUI
UAC Execution Level Manifest: asInvoker
[Incomplete Binary or Compressor Packer - 26,50 KB Missing]

Sections Info
Section Name Flags ROffset RSize VOffset VSizeEntropyChi2
.text
0x60000020
Code
Executable
Readable
200 10C00 2000 10AB4
5.6942
1441021.16
.rsrc
0x40000040
Initialized Data
Readable
10E00 600 14000 5CC
4.151
74557
.reloc
0x42000040
Initialized Data
GP-Relative
Readable
11400 200 16000 C
0.1019
128015
Description
OriginalFilename: 2800-v5.exe
LegalCopyright: Copyright 2025
ProductName: WindowsApplication1
FileVersion: 1.0.0.0
FileDescription: WindowsApplication1
ProductVersion: 1.0.0.0
Language: Unknown (ID=0x0)
CodePage: Unicode (UTF-16 LE) (0x4B0)

Entry Point
The section number (1) - (.text) have the Entry Point
Information -> EntryPoint (calculated) - 10C5E
Code -> FF2500204000000000000000F83F000000000000F43F000000000000F03F000000000000E83F000000000000E03F33333333
Assembler
|JMP DWORD PTR [0X402000]
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|CLC
|AAS
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|HLT
|AAS
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
Signatures
Certificate - Digital Signature Not Found:
• The file is not signed

Packer/Compiler
Compiler: Microsoft Visual .NET - (You can use a decompiler for this...)
AnyCPU: False
Version: v4.0
Detect It Easy (die)
PE: library: .NET(v4.0.30319)[-]
PE: compiler: VB.NET(-)[-]
PE: linker: Microsoft Linker(80.0)[-]
Entropy: 5.6378

File Access
2800-v5.exe
mscoree.dll
System.Dat
Temp

File Access (UNICODE)
2800-v5.exe
%Save Spectrum_.txt
!SpectrumData.txt
txt)|*.txt

Interest's Words
exec
attrib
shutdown
replace

IP Addresses
11.0.0.0

Strings/Hex Code Found With The File Rules
Rule Type Encoding Matched (Word)
Text Ascii WinAPI Sockets (send)
Entry Point Hex Pattern Microsoft Visual C++ 8
Entry Point Hex Pattern Microsoft Visual C++ 8.0
Resources
Path DataRVA Size FileOffset CodeText
\VERSION\1\0 14090 33C 10E90 3C0334000000560053005F00560045005200530049004F004E005F0049004E0046004F0000000000BD04EFFE000001000000<.4...V.S._.V.E.R.S.I.O.N._.I.N.F.O...............
\24\1\0 143DC 1EA 111DC EFBBBF3C3F786D6C2076657273696F6E3D22312E302220656E636F64696E673D225554462D3822207374616E64616C6F6E65...<?xml version="1.0" encoding="UTF-8" standalone
Intelligent String
• 1.0.0.0
• 2800-v5.exe
• /Text File (*.txt)|*.txt
• !SpectrumData.txt
• %Save Spectrum_.txt
• E:\file excell &word\C-cofficient\Macro ETABS\Colection_2800-V5\2800-v5\WindowsApplication1\WindowsApplication1\obj\Debug\2800-v5.pdb2*
• _CorExeMainmscoree.dll

Flow Anomalies
Offset FlowVA Section Description
10C5E 402000 .text JMP [static] | Indirect jump to absolute memory address
Extra Analysis
Metric Value Percentage
Ascii Code 39205 55,088%
Null Byte Code 20362 28,6112%
© 2026 All rights reserved.