PESCAN.IO - Analysis Report Basic |
|||||||
| File Structure |
|
PE Chart Code
Header PE (light blue)
Executable sections (pink)
Non-executable sections (black)
External injected code (red)
File Structure in red = malformed or corrupted header
Chart Code For Other Files
Printable characters (blue)
Non-printable characters (black)
| Information |
| Size: 1,17 MB SHA-256 Hash: 9CEFE9DE454A473B63B9B017FDE5CC8943C4A66843BED116E2E18BBBB53152F8 SHA-1 Hash: 24995A42EA796BCCDD658DA27850599C5F766400 MD5 Hash: 6CE564C9E9414E30EFA98CF2E89DCE85 Imphash: E41EDF75E3F1B2CD492BA70A839748A6 MajorOSVersion: 6 MinorOSVersion: 0 CheckSum: 00000000 EntryPoint (rva): 90EB2 SizeOfHeaders: 400 SizeOfImage: 136000 ImageBase: 10000000 Architecture: x86 ImportTable: FA980 IAT: BE000 Characteristics: 2102 TimeDateStamp: 6640D826 Date: 12/05/2024 14:54:30 File Type: DLL Number Of Sections: 5 ASLR: Enabled Section Names: .text, .rdata, .data, .rsrc, .reloc Number Of Executable Sections: 1 Subsystem: Windows GUI |
| Sections Info |
| Section Name | Flags | ROffset | RSize | VOffset | VSize | Entropy | Chi2 |
|---|---|---|---|---|---|---|---|
| .text | 0x60000020 Code Executable Readable |
400 | BC600 | 1000 | BC47A |
|
|
| .rdata | 0x40000040 Initialized Data Readable |
BCA00 | 3DA00 | BE000 | 3D8EA |
|
|
| .data | 0xC0000040 Initialized Data Readable Writeable |
FA400 | 2C00 | FC000 | ABCC |
|
|
| .rsrc | 0x40000040 Initialized Data Readable |
FD000 | 28A00 | 107000 | 289A8 |
|
|
| .reloc | 0x42000040 Initialized Data GP-Relative Readable |
125A00 | 5E00 | 130000 | 5DBC |
|
|
| Entry Point |
The section number (1) - (.text) have the Entry Point Information -> EntryPoint (calculated) - 902B2 Code -> 558BEC837D0C017505E8E2040000FF7510FF750CFF7508E8AEFEFFFF83C40C5DC20C008B4DF464890D00000000595F5F5E5B Assembler |PUSH EBP |MOV EBP, ESP |CMP DWORD PTR [EBP + 0XC], 1 |JNE 0X10090EC0 |CALL 0X100913A2 |PUSH DWORD PTR [EBP + 0X10] |PUSH DWORD PTR [EBP + 0XC] |PUSH DWORD PTR [EBP + 8] |CALL 0X10090D7C |ADD ESP, 0XC |POP EBP |RET 0XC |MOV ECX, DWORD PTR [EBP - 0XC] |MOV DWORD PTR FS:[0], ECX |POP ECX |POP EDI |POP EDI |POP ESI |POP EBX |
| Signatures |
| Rich Signature Analyzer: Code -> CFD116898BB078DA8BB078DA8BB078DA9FDB7BDB95B078DA9FDB7DDB34B078DA9FDB7CDB91B078DA9ECF7CDB9BB078DA9ECF7BDB92B078DA59E2E4DA89B078DA9ECF7DDBDBB078DA9FDB79DB84B078DA8BB079DA68B078DAB33071DB9CB078DAB33087DA8AB078DA8BB0EFDA8AB078DAB3307ADB8AB078DA526963688BB078DA Footprint md5 Hash -> 3D8BE19F8BEAA8DB85A723239C937506 • The Rich header apparently has not been modified Certificate - Digital Signature Not Found: • The file is not signed |
| Packer/Compiler |
| Detect It Easy (die) • PE: linker: Microsoft Linker(14.37**)[-] • Entropy: 6.95044 |
| Suspicious Functions |
| Library | Function | Description |
|---|---|---|
| KERNEL32.DLL | VirtualAlloc | Reserve, commit, or both, a region of memory within the virtual address space of a process. |
| KERNEL32.DLL | GetModuleHandleA | Retrieves a handle to the specified module. |
| KERNEL32.DLL | WriteFile | Writes data to a specified file or input/output (I/O) device. |
| KERNEL32.DLL | LoadLibraryA | Loads the specified module into the address space of the calling process. |
| KERNEL32.DLL | CreateToolhelp32Snapshot | Creates a snapshot of the specified processes, heaps, threads, and modules. |
| KERNEL32.DLL | GetProcAddress | Retrieves the address of an exported function or variable from the specified dynamic-link library (DLL). |
| KERNEL32.DLL | CreateFileA | Creates or opens a file or I/O device. |
| KERNEL32.DLL | DeleteFileA | Deletes an existing file. |
| KERNEL32.DLL | IsDebuggerPresent | Determines if the calling process is being debugged by a user-mode debugger. |
| USER32.DLL | GetAsyncKeyState | Retrieves the status of a virtual key asynchronously. |
| File Access |
| IMM32.dll SHLWAPI.dll d3dx9_43.dll USER32.dll KERNEL32.dll xinput1_1.dll xinput1_2.dll xinput9_1_0.dll xinput1_3.dll xinput1_4.dll ntdll.dll \d3d9.dll client.dll netc.dll .dat @.dat Logger.log imgui_log.txt imgui.ini Temp |
| File Access (UNICODE) |
| Snetc.dll mscoree.dll kernel32.dll |
| Interest's Words |
| fuck - }:) JFIF Encrypt exec attrib start pause ping expand replace |
| URLs |
| http://scripts.sil.org/OFL https://github.com/marmonsalve/Ruda-new) https://github.com/marmonsalve/Ruda-new)Ruda |
| URLs (UNICODE) |
| http://scripts.sil.org/OFL https://github.com/marmonsalve/Ruda-new) |
| Strings/Hex Code Found With The File Rules |
| Rule Type | Encoding | Matched (Word) |
|---|---|---|
| Text | Ascii | WinAPI Sockets (connect) |
| Text | Ascii | WinAPI Sockets (send) |
| Text | Ascii | File (GetTempPath) |
| Text | Ascii | File (CreateFile) |
| Text | Ascii | File (WriteFile) |
| Text | Ascii | File (ReadFile) |
| Text | Ascii | Anti-Analysis VM (IsDebuggerPresent) |
| Text | Ascii | Anti-Analysis VM (CreateToolhelp32Snapshot) |
| Text | Ascii | Reconnaissance (FindNextFileW) |
| Text | Ascii | Reconnaissance (FindClose) |
| Text | Ascii | Stealth (GetThreadContext) |
| Text | Ascii | Stealth (SetThreadContext) |
| Text | Ascii | Stealth (CloseHandle) |
| Text | Ascii | Stealth (UnmapViewOfFile) |
| Text | Ascii | Stealth (MapViewOfFile) |
| Text | Ascii | Stealth (CreateFileMappingA) |
| Text | Ascii | Stealth (VirtualAlloc) |
| Text | Ascii | Stealth (VirtualProtect) |
| Text | Ascii | Execution (ResumeThread) |
| Text | Ascii | Keyboard Key (Scroll) |
| Text | Ascii | Keyboard Key (DownArrow) |
| Text | Ascii | Keyboard Key (RightArrow) |
| Text | Ascii | Keyboard Key (UpArrow) |
| Text | Ascii | Keyboard Key (LeftArrow) |
| Text | Ascii | Keyboard Key (PageDown) |
| Text | Ascii | Keyboard Key (PageUp) |
| Text | Ascii | Keyboard Key (CapsLock) |
| Text | Ascii | Keyboard Key (Backspace) |
| Text | Ascii | Keyboard Key (Ctrl+S) |
| Text | Ascii | Software that records user activity (Logger) |
| Entry Point | Hex Pattern | Microsoft Visual C++ 8 |
| Entry Point | Hex Pattern | VC8 - Microsoft Corporation |
| Resources |
| Path | DataRVA | Size | FileOffset | Code | Text |
|---|---|---|---|---|---|
| \RCDATA\102\1049 | 107100 | 184E | FD100 | FFD8FFE000104A46494600010101004800480000FFDB0043000A07070807060A0808080B0A0A0B0E18100E0D0D0E1D151611 | ......JFIF.....H.H.....C.......................... |
| \RCDATA\103\1049 | 108950 | 1A360 | FE950 | 4F54544F000D00800003005043464620117A4CB300000D580001746F4646544D8282CF25000199800000001C4744454605F6 | OTTO.......PCFF .zL....X..toFFTM...%........GDEF.. |
| \RCDATA\104\1049 | 122CB0 | CC5D | 118CB0 | 89504E470D0A1A0A0000000D49484452000000C8000000C80806000000AD58AE9E000000017352474201D9C92C7F00000009 | .PNG........IHDR..............X......sRGB...,..... |
| \24\2\1033 | 12F910 | 91 | 125910 | 3C3F786D6C2076657273696F6E3D27312E302720656E636F64696E673D275554462D3827207374616E64616C6F6E653D2779 | <?xml version='1.0' encoding='UTF-8' standalone='y |
| Intelligent String |
| • Copyright 2019 The Ruda Project Authors (https://github.com/marmonsalve/Ruda-new) • netc.dll • kernel32.dll • .exe • .cmd • .bat • .com • mscoree.dll • Logger.log • client.dll • \d3d9.dll • fileKeyLuaExecutorLuaEditorresources.lua • Search for a scriptsearchresdumpResources-- This Script Is Luac Dump To See Encryptey Codes • dumpEditor • Dump All Resource • ntdll.dll • imgui.ini • imgui_log.txt • xinput1_4.dll • xinput1_3.dll • xinput9_1_0.dll • xinput1_2.dll • xinput1_1.dll • dump • .tls • .bss • d3dx9_43.dll • www.mukamonsalve.com.ar www.angelinasanchez.com.ar • This Font Software is licensed under the SIL Open Font License, Version 1.1. This license is available with a FAQ at: http://scripts.sil.org/OFL • http://scripts.sil.org/OFL |
| Flow Anomalies |
| Offset | FlowVA | Section | Description |
|---|---|---|---|
| 2009 | 100BE120 | .text | CALL [static] | Indirect call to absolute memory address |
| 201A | 100BE148 | .text | CALL [static] | Indirect call to absolute memory address |
| 2021 | 100BE030 | .text | CALL [static] | Indirect call to absolute memory address |
| 2529 | 100BE14C | .text | CALL [static] | Indirect call to absolute memory address |
| 25D9 | 100BE14C | .text | CALL [static] | Indirect call to absolute memory address |
| 488D | 100BE14C | .text | CALL [static] | Indirect call to absolute memory address |
| 5607 | 100BE110 | .text | CALL [static] | Indirect call to absolute memory address |
| 5667 | 100BE058 | .text | CALL [static] | Indirect call to absolute memory address |
| 5711 | 100BE110 | .text | CALL [static] | Indirect call to absolute memory address |
| 5771 | 100BE058 | .text | CALL [static] | Indirect call to absolute memory address |
| 5853 | 100BE110 | .text | CALL [static] | Indirect call to absolute memory address |
| 58B3 | 100BE058 | .text | CALL [static] | Indirect call to absolute memory address |
| 5909 | 100BE234 | .text | CALL [static] | Indirect call to absolute memory address |
| 5A3C | 100BE020 | .text | CALL [static] | Indirect call to absolute memory address |
| 5B95 | 100BE144 | .text | CALL [static] | Indirect call to absolute memory address |
| 5CA4 | 100BE12C | .text | CALL [static] | Indirect call to absolute memory address |
| 5D33 | 100BE038 | .text | CALL [static] | Indirect call to absolute memory address |
| 5D42 | 100BE01C | .text | CALL [static] | Indirect call to absolute memory address |
| 5DD1 | 100BE154 | .text | CALL [static] | Indirect call to absolute memory address |
| 5DF3 | 100BE10C | .text | CALL [static] | Indirect call to absolute memory address |
| 5E05 | 100BE048 | .text | CALL [static] | Indirect call to absolute memory address |
| 5E1B | 100BE05C | .text | CALL [static] | Indirect call to absolute memory address |
| 5E33 | 100BE124 | .text | CALL [static] | Indirect call to absolute memory address |
| 5E4C | 100BE03C | .text | CALL [static] | Indirect call to absolute memory address |
| 6075 | 100BE020 | .text | CALL [static] | Indirect call to absolute memory address |
| 60C8 | 100BE118 | .text | CALL [static] | Indirect call to absolute memory address |
| 6103 | 100BE118 | .text | CALL [static] | Indirect call to absolute memory address |
| 6121 | 100BE054 | .text | CALL [static] | Indirect call to absolute memory address |
| 614B | 100BE054 | .text | CALL [static] | Indirect call to absolute memory address |
| 626E | 101000F0 | .text | CALL [static] | Indirect call to absolute memory address |
| 63C4 | 101000DC | .text | CALL [static] | Indirect call to absolute memory address |
| 642B | 101000DC | .text | CALL [static] | Indirect call to absolute memory address |
| 64D0 | 100BE280 | .text | CALL [static] | Indirect call to absolute memory address |
| 6FE0 | 100FFAAC | .text | JMP [static] | Indirect jump to absolute memory address |
| 6FF4 | 100FFAC4 | .text | JMP [static] | Indirect jump to absolute memory address |
| 713C | 100FFAB0 | .text | CALL [static] | Indirect call to absolute memory address |
| 72DB | 101000EC | .text | CALL [static] | Indirect call to absolute memory address |
| 7514 | 1010010C | .text | CALL [static] | Indirect call to absolute memory address |
| 76E6 | 101000F8 | .text | JMP [static] | Indirect jump to absolute memory address |
| 77DB | 100BE014 | .text | CALL [static] | Indirect call to absolute memory address |
| 7896 | 100BE018 | .text | CALL [static] | Indirect call to absolute memory address |
| 802F | 100BE08C | .text | CALL [static] | Indirect call to absolute memory address |
| 8044 | 100BE094 | .text | CALL [static] | Indirect call to absolute memory address |
| 8118 | 100BE018 | .text | CALL [static] | Indirect call to absolute memory address |
| 828A | 100BE268 | .text | CALL [static] | Indirect call to absolute memory address |
| 82D2 | 100BE094 | .text | CALL [static] | Indirect call to absolute memory address |
| 835E | 100BE25C | .text | CALL [static] | Indirect call to absolute memory address |
| 83A1 | 100BE254 | .text | CALL [static] | Indirect call to absolute memory address |
| 83B7 | 100BE274 | .text | CALL [static] | Indirect call to absolute memory address |
| 83D9 | 100BE23C | .text | CALL [static] | Indirect call to absolute memory address |
| 83F2 | 100BE27C | .text | CALL [static] | Indirect call to absolute memory address |
| 8466 | 100BE23C | .text | CALL [static] | Indirect call to absolute memory address |
| 8479 | 100BE27C | .text | CALL [static] | Indirect call to absolute memory address |
| 9C81 | 100FFABC | .text | CALL [static] | Indirect call to absolute memory address |
| 9C9F | 100BE244 | .text | CALL [static] | Indirect call to absolute memory address |
| B212 | 1010491C | .text | CALL [static] | Indirect call to absolute memory address |
| B389 | 100BE148 | .text | CALL [static] | Indirect call to absolute memory address |
| B390 | 100BE138 | .text | CALL [static] | Indirect call to absolute memory address |
| E63F | 100BE138 | .text | JMP [static] | Indirect jump to absolute memory address |
| F24B | 100BE138 | .text | JMP [static] | Indirect jump to absolute memory address |
| 11D2C | 100BE138 | .text | JMP [static] | Indirect jump to absolute memory address |
| 122CD | 100BE148 | .text | CALL [static] | Indirect call to absolute memory address |
| 122D4 | 100BE030 | .text | CALL [static] | Indirect call to absolute memory address |
| 128A9 | 100BE030 | .text | JMP [static] | Indirect jump to absolute memory address |
| 128D5 | 100BE030 | .text | CALL [static] | Indirect call to absolute memory address |
| 13F9B | 100BE120 | .text | CALL [static] | Indirect call to absolute memory address |
| 13FA2 | 100BE040 | .text | CALL [static] | Indirect call to absolute memory address |
| 14098 | 100BE120 | .text | CALL [static] | Indirect call to absolute memory address |
| 140B1 | 101000F8 | .text | CALL [static] | Indirect call to absolute memory address |
| 140B9 | 101000F4 | .text | CALL [static] | Indirect call to absolute memory address |
| 141B1 | 100BE120 | .text | CALL [static] | Indirect call to absolute memory address |
| 142F8 | 100FFAC4 | .text | CALL [static] | Indirect call to absolute memory address |
| 147AD | 100BE04C | .text | CALL [static] | Indirect call to absolute memory address |
| 147D9 | 100BE11C | .text | CALL [static] | Indirect call to absolute memory address |
| 14800 | 100BE130 | .text | CALL [static] | Indirect call to absolute memory address |
| 14828 | 100BE068 | .text | CALL [static] | Indirect call to absolute memory address |
| 14831 | 100BE128 | .text | CALL [static] | Indirect call to absolute memory address |
| 14849 | 100BE134 | .text | CALL [static] | Indirect call to absolute memory address |
| 1485B | 100BE098 | .text | CALL [static] | Indirect call to absolute memory address |
| 1486F | 100BE034 | .text | CALL [static] | Indirect call to absolute memory address |
| 156BA | 100BE148 | .text | CALL [static] | Indirect call to absolute memory address |
| 156C1 | 100BE050 | .text | CALL [static] | Indirect call to absolute memory address |
| 17832 | 100BE064 | .text | CALL [static] | Indirect call to absolute memory address |
| 17874 | 100BE148 | .text | CALL [static] | Indirect call to absolute memory address |
| 1787B | 100BE050 | .text | CALL [static] | Indirect call to absolute memory address |
| 17C32 | 100BE064 | .text | CALL [static] | Indirect call to absolute memory address |
| 17C74 | 100BE148 | .text | CALL [static] | Indirect call to absolute memory address |
| 17C7B | 100BE050 | .text | CALL [static] | Indirect call to absolute memory address |
| 18624 | 100BE14C | .text | CALL [static] | Indirect call to absolute memory address |
| 186CA | 100BE14C | .text | CALL [static] | Indirect call to absolute memory address |
| 18760 | 100BE148 | .text | CALL [static] | Indirect call to absolute memory address |
| 18767 | 100BE050 | .text | CALL [static] | Indirect call to absolute memory address |
| 18824 | 100BE14C | .text | CALL [static] | Indirect call to absolute memory address |
| 188CA | 100BE14C | .text | CALL [static] | Indirect call to absolute memory address |
| 18960 | 100BE148 | .text | CALL [static] | Indirect call to absolute memory address |
| 18967 | 100BE050 | .text | CALL [static] | Indirect call to absolute memory address |
| 190A2 | 100BE148 | .text | CALL [static] | Indirect call to absolute memory address |
| 190A9 | 100BE050 | .text | CALL [static] | Indirect call to absolute memory address |
| 19212 | 100BE148 | .text | CALL [static] | Indirect call to absolute memory address |
| 19219 | 100BE050 | .text | CALL [static] | Indirect call to absolute memory address |
| Extra Analysis |
| Metric | Value | Percentage |
|---|---|---|
| Ascii Code | 733412 | 59,7849% |
| Null Byte Code | 144634 | 11,79% |
© 2026 All rights reserved.