PREMIUM PESCAN.IO - Analysis Report

File Structure
Analysis Image
PE Chart Code
Header PE (light blue)
Executable sections (pink)
Non-executable sections (black)
External injected code (red)
File Structure in red = malformed or corrupted header

Chart Code For Other Files
Printable characters (blue)
Non-printable characters (black)
Information
Size: 11,00 KB
SHA-256 Hash: 7D94532BCD5594AEDA34B6449823B1F9F7746F329760C876870C7C9E06568C5A
SHA-1 Hash: 61478EA92072746131F60F7031BD4A8E97D31C8C
MD5 Hash: 7FB0BE9976E55348A7AF8EDBBC08276D
Imphash: 42CF01D41EF6DC0627982490AFC9CDDD
MajorOSVersion: 5
MinorOSVersion: 0
CheckSum: 0000F784
EntryPoint (rva): 18A5
SizeOfHeaders: 400
SizeOfImage: 6000
ImageBase: 400000
Architecture: x86
ImportTable: 266C
IAT: 2000
Characteristics: 102
TimeDateStamp: 6A846C9C
Date: 18/08/2026 14:30:52
File Type: EXE
Number Of Sections: 5
ASLR: Enabled
Section Names: .text, .rdata, .data, .rsrc, .reloc
Number Of Executable Sections: 1
Subsystem: Windows GUI
UAC Execution Level Manifest: asInvoker

Sections Info
Section Name Flags ROffset RSize VOffset VSizeEntropyChi2
.text
0x60000020
Code
Executable
Readable
400 1000 1000 E0A
5.6622
73163.63
.rdata
0x40000040
Initialized Data
Readable
1400 E00 2000 C84
4.2632
202680.86
.data
0xC0000040
Initialized Data
Readable
Writeable
2200 200 3000 38C
0.3528
120094
.rsrc
0x40000040
Initialized Data
Readable
2400 400 4000 2B0
5.1945
8722.5
.reloc
0x42000040
Initialized Data
GP-Relative
Readable
2800 400 5000 23A
3.6819
85713.5
Entry Point
The section number (1) - (.text) have the Entry Point
Information -> EntryPoint (calculated) - CA5
Code -> E87E030000E937FDFFFF8BFF558BEC8B45088B00813863736DE0752A8378100375248B40143D2005931974153D2105931974
Assembler
|CALL 0X401C28
|JMP 0X4015E6
|MOV EDI, EDI
|PUSH EBP
|MOV EBP, ESP
|MOV EAX, DWORD PTR [EBP + 8]
|MOV EAX, DWORD PTR [EAX]
|CMP DWORD PTR [EAX], 0XE06D7363
|JNE 0X4018EB
|CMP DWORD PTR [EAX + 0X10], 3
|JNE 0X4018EB
|MOV EAX, DWORD PTR [EAX + 0X14]
|CMP EAX, 0X19930520
|JE 0X4018E6
|CMP EAX, 0X19930521
Signatures
Rich Signature Analyzer:
Code -> 194464015D250A525D250A525D250A527AE3715251250A52545D99525E250A525D250B5260250A52545D9F525F250A52545D895248250A52545D8E525E250A52545D9B525C250A52526963685D250A52
Footprint md5 Hash -> 7FDE775A6CA57A24AB5C19F650D533F8
• The Rich header apparently has not been modified
Certificate - Digital Signature Not Found:
• The file is not signed

Packer/Compiler
Detect It Easy (die)
PE: compiler: EP:Microsoft Visual C/C++(2008-2010)[EXE32]
PE: compiler: Microsoft Visual C/C++(2008 SP1)[msvcrt,wWinMain]
PE: linker: Microsoft Linker(9.0)[-]
Entropy: 5.10296

Suspicious Functions
Library Function Description
KERNEL32.DLL WriteFile Writes data to a specified file or input/output (I/O) device.
KERNEL32.DLL GetModuleHandleW Retrieves a handle to the specified module.
KERNEL32.DLL GetProcAddress Retrieves the address of an exported function or variable from the specified dynamic-link library (DLL).
KERNEL32.DLL IsDebuggerPresent Determines if the calling process is being debugged by a user-mode debugger.
KERNEL32.DLL CreateFileW Creates or opens a file object.
KERNEL32.DLL ReadFile Reads data from a file.
KERNEL32.DLL CloseHandle Closes an open object handle.
KERNEL32.DLL CreateProcessW Creates and starts a new process.
KERNEL32.DLL GetVersion Retrieves the operating system version.
URLMON.DLL URLDownloadToFileW Download a file from the internet and save it to a local file.
SHELL32.DLL ShellExecuteW Performs a run operation on a specific file.
WININET.DLL InternetOpenW Initializes an application’s use of the WinINet functions.
WININET.DLL InternetReadFile Reads data from an Internet resource.
File Access
SHELL32.dll
USER32.dll
KERNEL32.dll
urlmon.dll
SHLWAPI.dll
WININET.dll
MSVCR90.dll
@.dat

File Access (UNICODE)
109/1.exe
109/2.exe
109/3.exe
109/4.exe
109/5.exe
109/6.exe
109/7.exe
109/xmrget.exe
109/xmr.exe
109/grab.exe
%s\%d%d.exe
ntdll.dll
ggggggggggghhhdhs.txt
d3333333333333333333.txt
Temp
AppData

Interest's Words
PADDINGX
exec
start
expand

URLs (UNICODE)
http://178.16.54.109/grab.exe
http://178.16.54.109/xmr.exe
http://178.16.54.109/xmrget.exe
http://178.16.54.109/7.exe
http://178.16.54.109/6.exe
http://178.16.54.109/5.exe
http://178.16.54.109/4.exe
http://178.16.54.109/3.exe
http://178.16.54.109/2.exe
http://178.16.54.109/1.exe

IP Addresses
128.0.0.0
178.16.54.109

Strings/Hex Code Found With The File Rules
Rule Type Encoding Matched (Word)
Entry Point Hex Pattern Microsoft Visual C++ 8
Entry Point Hex Pattern Microsoft Visual C++ 8
Entry Point Hex Pattern Microsoft Visual C++ v7.0
Entry Point Hex Pattern PE-Exe Executable Image
Entry Point Hex Pattern VC8 - Microsoft Corporation
Resources
Path DataRVA Size FileOffset CodeText
\24\1\1033 4058 256 2458 3C617373656D626C7920786D6C6E733D2275726E3A736368656D61732D6D6963726F736F66742D636F6D3A61736D2E763122<assembly xmlns="urn:schemas-microsoft-com:asm.v1"
Intelligent String
• %s\%d%d.exe
• d3333333333333333333.txt
• ggggggggggghhhdhs.txt
• ntdll.dll
• http://178.16.54.109/grab.exe
• http://178.16.54.109/xmr.exe
• http://178.16.54.109/xmrget.exe
• http://178.16.54.109/7.exe
• http://178.16.54.109/6.exe
• http://178.16.54.109/5.exe
• http://178.16.54.109/4.exe
• http://178.16.54.109/3.exe
• http://178.16.54.109/2.exe
• http://178.16.54.109/1.exe
• urlmon.dll

Flow Anomalies
Offset FlowVA Section Description
455 402024 .text CALL [static] | Indirect call to absolute memory address
465 402028 .text CALL [static] | Indirect call to absolute memory address
48B 4020D8 .text CALL [static] | Indirect call to absolute memory address
49B 402028 .text CALL [static] | Indirect call to absolute memory address
4B8 402010 .text CALL [static] | Indirect call to absolute memory address
4DC 402014 .text CALL [static] | Indirect call to absolute memory address
532 4020F4 .text CALL [static] | Indirect call to absolute memory address
54B 402100 .text CALL [static] | Indirect call to absolute memory address
56E 402018 .text CALL [static] | Indirect call to absolute memory address
599 40201C .text CALL [static] | Indirect call to absolute memory address
5B2 4020F8 .text CALL [static] | Indirect call to absolute memory address
5BF 40202C .text CALL [static] | Indirect call to absolute memory address
5F1 402020 .text CALL [static] | Indirect call to absolute memory address
5FC 402028 .text CALL [static] | Indirect call to absolute memory address
61A 4020FC .text CALL [static] | Indirect call to absolute memory address
623 4020FC .text CALL [static] | Indirect call to absolute memory address
62E 402028 .text CALL [static] | Indirect call to absolute memory address
64E 402028 .text CALL [static] | Indirect call to absolute memory address
6D8 402020 .text CALL [static] | Indirect call to absolute memory address
6E3 402028 .text CALL [static] | Indirect call to absolute memory address
715 402014 .text CALL [static] | Indirect call to absolute memory address
730 4020E0 .text CALL [static] | Indirect call to absolute memory address
73D 4020E4 .text CALL [static] | Indirect call to absolute memory address
75A 402018 .text CALL [static] | Indirect call to absolute memory address
766 40202C .text CALL [static] | Indirect call to absolute memory address
78A 402014 .text CALL [static] | Indirect call to absolute memory address
7A5 4020E0 .text CALL [static] | Indirect call to absolute memory address
7B2 4020E4 .text CALL [static] | Indirect call to absolute memory address
7CF 402018 .text CALL [static] | Indirect call to absolute memory address
7DB 40202C .text CALL [static] | Indirect call to absolute memory address
7FF 402014 .text CALL [static] | Indirect call to absolute memory address
818 4020EC .text CALL [static] | Indirect call to absolute memory address
828 4020E4 .text CALL [static] | Indirect call to absolute memory address
844 402008 .text CALL [static] | Indirect call to absolute memory address
854 40200C .text CALL [static] | Indirect call to absolute memory address
8B8 402028 .text CALL [static] | Indirect call to absolute memory address
958 4020D0 .text JMP [static] | Indirect jump to absolute memory address
95E 4020C8 .text JMP [static] | Indirect jump to absolute memory address
964 4020C4 .text JMP [static] | Indirect jump to absolute memory address
96A 4020C0 .text JMP [static] | Indirect jump to absolute memory address
9CB 4020B8 .text CALL [static] | Indirect call to absolute memory address
9FE 402048 .text CALL [static] | Indirect call to absolute memory address
A26 402054 .text CALL [static] | Indirect call to absolute memory address
A41 402028 .text CALL [static] | Indirect call to absolute memory address
AB9 402004 .text CALL [static] | Indirect call to absolute memory address
ADA 403388 .text CALL [static] | Indirect call to absolute memory address
B44 4020A8 .text CALL [static] | Indirect call to absolute memory address
B89 4020B0 .text CALL [static] | Indirect call to absolute memory address
B97 4020B4 .text CALL [static] | Indirect call to absolute memory address
C2A 402080 .text CALL [static] | Indirect call to absolute memory address
C32 402084 .text CALL [static] | Indirect call to absolute memory address
C44 402088 .text CALL [static] | Indirect call to absolute memory address
C52 40208C .text CALL [static] | Indirect call to absolute memory address
C84 402094 .text CALL [static] | Indirect call to absolute memory address
C9B 402098 .text CALL [static] | Indirect call to absolute memory address
CF6 402050 .text CALL [static] | Indirect call to absolute memory address
D00 4020BC .text JMP [static] | Indirect jump to absolute memory address
D2C 402064 .text CALL [static] | Indirect call to absolute memory address
E0E 4020AC .text JMP [static] | Indirect jump to absolute memory address
F6E 4020A0 .text JMP [static] | Indirect jump to absolute memory address
F74 40209C .text JMP [static] | Indirect jump to absolute memory address
105F 402038 .text CALL [static] | Indirect call to absolute memory address
106B 402034 .text CALL [static] | Indirect call to absolute memory address
1073 402030 .text CALL [static] | Indirect call to absolute memory address
107B 402010 .text CALL [static] | Indirect call to absolute memory address
1087 402000 .text CALL [static] | Indirect call to absolute memory address
10BE 40207C .text JMP [static] | Indirect jump to absolute memory address
10C4 402068 .text JMP [static] | Indirect jump to absolute memory address
10CA 40205C .text JMP [static] | Indirect jump to absolute memory address
10D0 402060 .text JMP [static] | Indirect jump to absolute memory address
10E6 40206C .text JMP [static] | Indirect jump to absolute memory address
10EC 402070 .text JMP [static] | Indirect jump to absolute memory address
10F2 402074 .text JMP [static] | Indirect jump to absolute memory address
11B3 40204C .text CALL [static] | Indirect call to absolute memory address
11C8 402050 .text CALL [static] | Indirect call to absolute memory address
11D3 402044 .text CALL [static] | Indirect call to absolute memory address
11EF 402040 .text CALL [static] | Indirect call to absolute memory address
11F6 40203C .text CALL [static] | Indirect call to absolute memory address
11FE 402078 .text JMP [static] | Indirect jump to absolute memory address
1204 402108 .text JMP [static] | Indirect jump to absolute memory address
CAA 4015E6 .text Entry Point Backward Redirect | Score=1/7 - Redirects=1 - PreJumpInstructions=1 - JumpType=JMP_NEAR - TargetOffset=0x9E6 - TargetSection=.text - Confidence=Low
Extra Analysis
Metric Value Percentage
Ascii Code 5528 49,0767%
Null Byte Code 4586 40,7138%
© 2026 All rights reserved.