PESCAN.IO - Analysis Report Basic

File Structure
Analysis Image
PE Chart Code
Header PE (light blue)
Executable sections (pink)
Non-executable sections (black)
External injected code (red)
File Structure in red = malformed or corrupted header

Chart Code For Other Files
Printable characters (blue)
Non-printable characters (black)
Information
Size: 1,17 MB
SHA-256 Hash: 9CEFE9DE454A473B63B9B017FDE5CC8943C4A66843BED116E2E18BBBB53152F8
SHA-1 Hash: 24995A42EA796BCCDD658DA27850599C5F766400
MD5 Hash: 6CE564C9E9414E30EFA98CF2E89DCE85
Imphash: E41EDF75E3F1B2CD492BA70A839748A6
MajorOSVersion: 6
MinorOSVersion: 0
CheckSum: 00000000
EntryPoint (rva): 90EB2
SizeOfHeaders: 400
SizeOfImage: 136000
ImageBase: 10000000
Architecture: x86
ImportTable: FA980
IAT: BE000
Characteristics: 2102
TimeDateStamp: 6640D826
Date: 12/05/2024 14:54:30
File Type: DLL
Number Of Sections: 5
ASLR: Enabled
Section Names: .text, .rdata, .data, .rsrc, .reloc
Number Of Executable Sections: 1
Subsystem: Windows GUI

Sections Info
Section Name Flags ROffset RSize VOffset VSizeEntropyChi2
.text
0x60000020
Code
Executable
Readable
400 BC600 1000 BC47A
6.6466
4122876.44
.rdata
0x40000040
Initialized Data
Readable
BCA00 3DA00 BE000 3D8EA
6.7845
2005478.75
.data
0xC0000040
Initialized Data
Readable
Writeable
FA400 2C00 FC000 ABCC
4.9989
261636.68
.rsrc
0x40000040
Initialized Data
Readable
FD000 28A00 107000 289A8
6.7639
1197226.31
.reloc
0x42000040
Initialized Data
GP-Relative
Readable
125A00 5E00 130000 5DBC
6.6364
100305.72
Entry Point
The section number (1) - (.text) have the Entry Point
Information -> EntryPoint (calculated) - 902B2
Code -> 558BEC837D0C017505E8E2040000FF7510FF750CFF7508E8AEFEFFFF83C40C5DC20C008B4DF464890D00000000595F5F5E5B
Assembler
|PUSH EBP
|MOV EBP, ESP
|CMP DWORD PTR [EBP + 0XC], 1
|JNE 0X10090EC0
|CALL 0X100913A2
|PUSH DWORD PTR [EBP + 0X10]
|PUSH DWORD PTR [EBP + 0XC]
|PUSH DWORD PTR [EBP + 8]
|CALL 0X10090D7C
|ADD ESP, 0XC
|POP EBP
|RET 0XC
|MOV ECX, DWORD PTR [EBP - 0XC]
|MOV DWORD PTR FS:[0], ECX
|POP ECX
|POP EDI
|POP EDI
|POP ESI
|POP EBX
Signatures
Rich Signature Analyzer:
Code -> CFD116898BB078DA8BB078DA8BB078DA9FDB7BDB95B078DA9FDB7DDB34B078DA9FDB7CDB91B078DA9ECF7CDB9BB078DA9ECF7BDB92B078DA59E2E4DA89B078DA9ECF7DDBDBB078DA9FDB79DB84B078DA8BB079DA68B078DAB33071DB9CB078DAB33087DA8AB078DA8BB0EFDA8AB078DAB3307ADB8AB078DA526963688BB078DA
Footprint md5 Hash -> 3D8BE19F8BEAA8DB85A723239C937506
• The Rich header apparently has not been modified
Certificate - Digital Signature Not Found:
• The file is not signed

Packer/Compiler
Detect It Easy (die)
PE: linker: Microsoft Linker(14.37**)[-]
Entropy: 6.95044

Suspicious Functions
Library Function Description
KERNEL32.DLL VirtualAlloc Reserve, commit, or both, a region of memory within the virtual address space of a process.
KERNEL32.DLL GetModuleHandleA Retrieves a handle to the specified module.
KERNEL32.DLL WriteFile Writes data to a specified file or input/output (I/O) device.
KERNEL32.DLL LoadLibraryA Loads the specified module into the address space of the calling process.
KERNEL32.DLL CreateToolhelp32Snapshot Creates a snapshot of the specified processes, heaps, threads, and modules.
KERNEL32.DLL GetProcAddress Retrieves the address of an exported function or variable from the specified dynamic-link library (DLL).
KERNEL32.DLL CreateFileA Creates or opens a file or I/O device.
KERNEL32.DLL DeleteFileA Deletes an existing file.
KERNEL32.DLL IsDebuggerPresent Determines if the calling process is being debugged by a user-mode debugger.
USER32.DLL GetAsyncKeyState Retrieves the status of a virtual key asynchronously.
File Access
IMM32.dll
SHLWAPI.dll
d3dx9_43.dll
USER32.dll
KERNEL32.dll
xinput1_1.dll
xinput1_2.dll
xinput9_1_0.dll
xinput1_3.dll
xinput1_4.dll
ntdll.dll
\d3d9.dll
client.dll
netc.dll
.dat
@.dat
Logger.log
imgui_log.txt
imgui.ini
Temp

File Access (UNICODE)
Snetc.dll
mscoree.dll
kernel32.dll

Interest's Words
fuck - }:)
JFIF
Encrypt
exec
attrib
start
pause
ping
expand
replace

URLs
http://scripts.sil.org/OFL
https://github.com/marmonsalve/Ruda-new)
https://github.com/marmonsalve/Ruda-new)Ruda

URLs (UNICODE)
http://scripts.sil.org/OFL
https://github.com/marmonsalve/Ruda-new)

Strings/Hex Code Found With The File Rules
Rule Type Encoding Matched (Word)
Text Ascii WinAPI Sockets (connect)
Text Ascii WinAPI Sockets (send)
Text Ascii File (GetTempPath)
Text Ascii File (CreateFile)
Text Ascii File (WriteFile)
Text Ascii File (ReadFile)
Text Ascii Anti-Analysis VM (IsDebuggerPresent)
Text Ascii Anti-Analysis VM (CreateToolhelp32Snapshot)
Text Ascii Reconnaissance (FindNextFileW)
Text Ascii Reconnaissance (FindClose)
Text Ascii Stealth (GetThreadContext)
Text Ascii Stealth (SetThreadContext)
Text Ascii Stealth (CloseHandle)
Text Ascii Stealth (UnmapViewOfFile)
Text Ascii Stealth (MapViewOfFile)
Text Ascii Stealth (CreateFileMappingA)
Text Ascii Stealth (VirtualAlloc)
Text Ascii Stealth (VirtualProtect)
Text Ascii Execution (ResumeThread)
Text Ascii Keyboard Key (Scroll)
Text Ascii Keyboard Key (DownArrow)
Text Ascii Keyboard Key (RightArrow)
Text Ascii Keyboard Key (UpArrow)
Text Ascii Keyboard Key (LeftArrow)
Text Ascii Keyboard Key (PageDown)
Text Ascii Keyboard Key (PageUp)
Text Ascii Keyboard Key (CapsLock)
Text Ascii Keyboard Key (Backspace)
Text Ascii Keyboard Key (Ctrl+S)
Text Ascii Software that records user activity (Logger)
Entry Point Hex Pattern Microsoft Visual C++ 8
Entry Point Hex Pattern VC8 - Microsoft Corporation
Resources
Path DataRVA Size FileOffset CodeText
\RCDATA\102\1049 107100 184E FD100 FFD8FFE000104A46494600010101004800480000FFDB0043000A07070807060A0808080B0A0A0B0E18100E0D0D0E1D151611......JFIF.....H.H.....C..........................
\RCDATA\103\1049 108950 1A360 FE950 4F54544F000D00800003005043464620117A4CB300000D580001746F4646544D8282CF25000199800000001C4744454605F6OTTO.......PCFF .zL....X..toFFTM...%........GDEF..
\RCDATA\104\1049 122CB0 CC5D 118CB0 89504E470D0A1A0A0000000D49484452000000C8000000C80806000000AD58AE9E000000017352474201D9C92C7F00000009.PNG........IHDR..............X......sRGB...,.....
\24\2\1033 12F910 91 125910 3C3F786D6C2076657273696F6E3D27312E302720656E636F64696E673D275554462D3827207374616E64616C6F6E653D2779<?xml version='1.0' encoding='UTF-8' standalone='y
Intelligent String
• Copyright 2019 The Ruda Project Authors (https://github.com/marmonsalve/Ruda-new)
• netc.dll
• kernel32.dll
• .exe
• .cmd
• .bat
• .com
• mscoree.dll
• Logger.log
• client.dll
• \d3d9.dll
• fileKeyLuaExecutorLuaEditorresources.lua
• Search for a scriptsearchresdumpResources-- This Script Is Luac Dump To See Encryptey Codes
• dumpEditor
• Dump All Resource
• ntdll.dll
• imgui.ini
• imgui_log.txt
• xinput1_4.dll
• xinput1_3.dll
• xinput9_1_0.dll
• xinput1_2.dll
• xinput1_1.dll
• dump
• .tls
• .bss
• d3dx9_43.dll
• www.mukamonsalve.com.ar www.angelinasanchez.com.ar
• This Font Software is licensed under the SIL Open Font License, Version 1.1. This license is available with a FAQ at: http://scripts.sil.org/OFL
• http://scripts.sil.org/OFL

Flow Anomalies
Offset FlowVA Section Description
2009 100BE120 .text CALL [static] | Indirect call to absolute memory address
201A 100BE148 .text CALL [static] | Indirect call to absolute memory address
2021 100BE030 .text CALL [static] | Indirect call to absolute memory address
2529 100BE14C .text CALL [static] | Indirect call to absolute memory address
25D9 100BE14C .text CALL [static] | Indirect call to absolute memory address
488D 100BE14C .text CALL [static] | Indirect call to absolute memory address
5607 100BE110 .text CALL [static] | Indirect call to absolute memory address
5667 100BE058 .text CALL [static] | Indirect call to absolute memory address
5711 100BE110 .text CALL [static] | Indirect call to absolute memory address
5771 100BE058 .text CALL [static] | Indirect call to absolute memory address
5853 100BE110 .text CALL [static] | Indirect call to absolute memory address
58B3 100BE058 .text CALL [static] | Indirect call to absolute memory address
5909 100BE234 .text CALL [static] | Indirect call to absolute memory address
5A3C 100BE020 .text CALL [static] | Indirect call to absolute memory address
5B95 100BE144 .text CALL [static] | Indirect call to absolute memory address
5CA4 100BE12C .text CALL [static] | Indirect call to absolute memory address
5D33 100BE038 .text CALL [static] | Indirect call to absolute memory address
5D42 100BE01C .text CALL [static] | Indirect call to absolute memory address
5DD1 100BE154 .text CALL [static] | Indirect call to absolute memory address
5DF3 100BE10C .text CALL [static] | Indirect call to absolute memory address
5E05 100BE048 .text CALL [static] | Indirect call to absolute memory address
5E1B 100BE05C .text CALL [static] | Indirect call to absolute memory address
5E33 100BE124 .text CALL [static] | Indirect call to absolute memory address
5E4C 100BE03C .text CALL [static] | Indirect call to absolute memory address
6075 100BE020 .text CALL [static] | Indirect call to absolute memory address
60C8 100BE118 .text CALL [static] | Indirect call to absolute memory address
6103 100BE118 .text CALL [static] | Indirect call to absolute memory address
6121 100BE054 .text CALL [static] | Indirect call to absolute memory address
614B 100BE054 .text CALL [static] | Indirect call to absolute memory address
626E 101000F0 .text CALL [static] | Indirect call to absolute memory address
63C4 101000DC .text CALL [static] | Indirect call to absolute memory address
642B 101000DC .text CALL [static] | Indirect call to absolute memory address
64D0 100BE280 .text CALL [static] | Indirect call to absolute memory address
6FE0 100FFAAC .text JMP [static] | Indirect jump to absolute memory address
6FF4 100FFAC4 .text JMP [static] | Indirect jump to absolute memory address
713C 100FFAB0 .text CALL [static] | Indirect call to absolute memory address
72DB 101000EC .text CALL [static] | Indirect call to absolute memory address
7514 1010010C .text CALL [static] | Indirect call to absolute memory address
76E6 101000F8 .text JMP [static] | Indirect jump to absolute memory address
77DB 100BE014 .text CALL [static] | Indirect call to absolute memory address
7896 100BE018 .text CALL [static] | Indirect call to absolute memory address
802F 100BE08C .text CALL [static] | Indirect call to absolute memory address
8044 100BE094 .text CALL [static] | Indirect call to absolute memory address
8118 100BE018 .text CALL [static] | Indirect call to absolute memory address
828A 100BE268 .text CALL [static] | Indirect call to absolute memory address
82D2 100BE094 .text CALL [static] | Indirect call to absolute memory address
835E 100BE25C .text CALL [static] | Indirect call to absolute memory address
83A1 100BE254 .text CALL [static] | Indirect call to absolute memory address
83B7 100BE274 .text CALL [static] | Indirect call to absolute memory address
83D9 100BE23C .text CALL [static] | Indirect call to absolute memory address
83F2 100BE27C .text CALL [static] | Indirect call to absolute memory address
8466 100BE23C .text CALL [static] | Indirect call to absolute memory address
8479 100BE27C .text CALL [static] | Indirect call to absolute memory address
9C81 100FFABC .text CALL [static] | Indirect call to absolute memory address
9C9F 100BE244 .text CALL [static] | Indirect call to absolute memory address
B212 1010491C .text CALL [static] | Indirect call to absolute memory address
B389 100BE148 .text CALL [static] | Indirect call to absolute memory address
B390 100BE138 .text CALL [static] | Indirect call to absolute memory address
E63F 100BE138 .text JMP [static] | Indirect jump to absolute memory address
F24B 100BE138 .text JMP [static] | Indirect jump to absolute memory address
11D2C 100BE138 .text JMP [static] | Indirect jump to absolute memory address
122CD 100BE148 .text CALL [static] | Indirect call to absolute memory address
122D4 100BE030 .text CALL [static] | Indirect call to absolute memory address
128A9 100BE030 .text JMP [static] | Indirect jump to absolute memory address
128D5 100BE030 .text CALL [static] | Indirect call to absolute memory address
13F9B 100BE120 .text CALL [static] | Indirect call to absolute memory address
13FA2 100BE040 .text CALL [static] | Indirect call to absolute memory address
14098 100BE120 .text CALL [static] | Indirect call to absolute memory address
140B1 101000F8 .text CALL [static] | Indirect call to absolute memory address
140B9 101000F4 .text CALL [static] | Indirect call to absolute memory address
141B1 100BE120 .text CALL [static] | Indirect call to absolute memory address
142F8 100FFAC4 .text CALL [static] | Indirect call to absolute memory address
147AD 100BE04C .text CALL [static] | Indirect call to absolute memory address
147D9 100BE11C .text CALL [static] | Indirect call to absolute memory address
14800 100BE130 .text CALL [static] | Indirect call to absolute memory address
14828 100BE068 .text CALL [static] | Indirect call to absolute memory address
14831 100BE128 .text CALL [static] | Indirect call to absolute memory address
14849 100BE134 .text CALL [static] | Indirect call to absolute memory address
1485B 100BE098 .text CALL [static] | Indirect call to absolute memory address
1486F 100BE034 .text CALL [static] | Indirect call to absolute memory address
156BA 100BE148 .text CALL [static] | Indirect call to absolute memory address
156C1 100BE050 .text CALL [static] | Indirect call to absolute memory address
17832 100BE064 .text CALL [static] | Indirect call to absolute memory address
17874 100BE148 .text CALL [static] | Indirect call to absolute memory address
1787B 100BE050 .text CALL [static] | Indirect call to absolute memory address
17C32 100BE064 .text CALL [static] | Indirect call to absolute memory address
17C74 100BE148 .text CALL [static] | Indirect call to absolute memory address
17C7B 100BE050 .text CALL [static] | Indirect call to absolute memory address
18624 100BE14C .text CALL [static] | Indirect call to absolute memory address
186CA 100BE14C .text CALL [static] | Indirect call to absolute memory address
18760 100BE148 .text CALL [static] | Indirect call to absolute memory address
18767 100BE050 .text CALL [static] | Indirect call to absolute memory address
18824 100BE14C .text CALL [static] | Indirect call to absolute memory address
188CA 100BE14C .text CALL [static] | Indirect call to absolute memory address
18960 100BE148 .text CALL [static] | Indirect call to absolute memory address
18967 100BE050 .text CALL [static] | Indirect call to absolute memory address
190A2 100BE148 .text CALL [static] | Indirect call to absolute memory address
190A9 100BE050 .text CALL [static] | Indirect call to absolute memory address
19212 100BE148 .text CALL [static] | Indirect call to absolute memory address
19219 100BE050 .text CALL [static] | Indirect call to absolute memory address
Extra Analysis
Metric Value Percentage
Ascii Code 733412 59,7849%
Null Byte Code 144634 11,79%
© 2026 All rights reserved.