PESCAN.IO - Analysis Report Basic |
|||||||
| File Structure |
|
PE Chart Code
Header PE (light blue)
Executable sections (pink)
Non-executable sections (black)
External injected code (red)
File Structure in red = malformed or corrupted header
Chart Code For Other Files
Printable characters (blue)
Non-printable characters (black)
| Information |
Icon: Size: 92,00 KBSHA-256 Hash: 4DE52F0C866B30D5E5D53904EF356FB637E2AD26FBF54406190DA4FA319D78BF SHA-1 Hash: B141DE67F55630BDA59E00F57F52AD20C81ED338 MD5 Hash: 88E7E7D0C1DB653AAAD97EDADF2BC18F Imphash: F34D5F2D4577ED6D9CEEC516C1F5A744 MajorOSVersion: 4 MinorOSVersion: 0 CheckSum: 00000000 EntryPoint (rva): C3EE SizeOfHeaders: 200 SizeOfImage: 1E000 ImageBase: 400000 Architecture: x86 ImportTable: C3A0 IAT: 2000 Characteristics: 102 TimeDateStamp: 6A02DA6C Date: 12/05/2026 7:44:44 File Type: EXE Number Of Sections: 3 ASLR: Enabled Section Names: .text, .rsrc, .reloc Number Of Executable Sections: 1 Subsystem: Windows GUI UAC Execution Level Manifest: asInvoker |
| Sections Info |
| Section Name | Flags | ROffset | RSize | VOffset | VSize | Entropy | Chi2 |
|---|---|---|---|---|---|---|---|
| .text | 0x60000020 Code Executable Readable |
200 | A400 | 2000 | A3F4 |
|
|
| .rsrc | 0x40000040 Initialized Data Readable |
A600 | C800 | E000 | C738 |
|
|
| .reloc | 0x42000040 Initialized Data GP-Relative Readable |
16E00 | 200 | 1C000 | C |
|
|
| Description |
| OriginalFilename: Untitled1.exe FileVersion: 0.0.0.0 ProductVersion: 0.0.0.0 Language: Unknown (ID=0x0) CodePage: Unicode (UTF-16 LE) (0x4B0) |
| Entry Point |
The section number (1) - (.text) have the Entry Point Information -> EntryPoint (calculated) - A5EE Code -> FF25002040000000000000000000000000000000000000000000000000000000040003000000300000800E00000080000080 Assembler |JMP DWORD PTR [0X402000] |ADD BYTE PTR [EAX], AL |ADD BYTE PTR [EAX], AL |ADD BYTE PTR [EAX], AL |ADD BYTE PTR [EAX], AL |ADD BYTE PTR [EAX], AL |ADD BYTE PTR [EAX], AL |ADD BYTE PTR [EAX], AL |ADD BYTE PTR [EAX], AL |ADD BYTE PTR [EAX], AL |ADD BYTE PTR [EAX], AL |ADD BYTE PTR [EAX], AL |ADD BYTE PTR [EAX], AL |ADD BYTE PTR [EAX], AL |ADD AL, 0 |ADD EAX, DWORD PTR [EAX] |ADD BYTE PTR [EAX], AL |XOR BYTE PTR [EAX], AL |ADD BYTE PTR [EAX + 0XE], AL |ADD BYTE PTR [EAX], 0 |
| Signatures |
| Certificate - Digital Signature Not Found: • The file is not signed |
| Packer/Compiler |
| Compiler: Microsoft Visual .NET - (You can use a decompiler for this...) • AnyCPU: True • Version: v4.0 Detect It Easy (die) • PE: library: .NET(v4.0.30319)[-] • PE: linker: Microsoft Linker(11.0)[-] • Entropy: 5.32018 |
| File Access |
| Untitled1.exe //codeberg.org/stepel35/ps1/raw/branch/main/Script.exe mscoree.dll user32.dll clr.dll kernel32.dll psapi.dll Runtime.InteropServices.Dll Untitled1.ps1 New-Object Win32.SYS Win32.SYS Temp |
| File Access (UNICODE) |
| Untitled1.exe Untitled1.ps1 |
| Interest's Words |
| PassWord <main exec powershell attrib start systeminfo replace |
| URLs |
| https://codeberg.org/stepel35/ps1/raw/branch/main/Script.exe |
| Strings/Hex Code Found With The File Rules |
| Rule Type | Encoding | Matched (Word) |
|---|---|---|
| Text | Ascii | WinAPI Sockets (send) |
| Text | Ascii | Anti-Analysis VM (GetSystemInfo) |
| Text | Ascii | Stealth (VirtualProtect) |
| Text | Ascii | Stealth (ReadProcessMemory) |
| Text | Ascii | Keyboard Key (Scroll) |
| Text | Ascii | Information used for user authentication (Credential) |
| Text | Ascii | Malicious rerouting of traffic to an attacker-controlled site (Redirect) |
| Entry Point | Hex Pattern | Microsoft Visual C++ 8 |
| Entry Point | Hex Pattern | Microsoft Visual C++ 8.0 |
| Entry Point | Hex Pattern | TrueVision Targa Graphics format |
| Resources |
| Path | DataRVA | Size | FileOffset | Code | Text |
|---|---|---|---|---|---|
| \ICON\2\0 | E4D0 | 1876 | AAD0 | 89504E470D0A1A0A0000000D49484452000001000000010008060000005C72A8660000183D49444154789CEDDD3F4C1B69DE | .PNG........IHDR.............\r.f...=IDATx...?L.i. |
| \ICON\3\0 | FD48 | 4228 | C348 | 28000000400000008000000001002000000000000042000000000000000000000000000000000000D77800FFD77800FFD778 | (...@......... ......B...................x...x...x |
| \ICON\4\0 | 13F70 | 25A8 | 10570 | 28000000300000006000000001002000000000008025000000000000000000000000000000000000D77800FFD77800FFD778 | (...0........ ......%...................x...x...x |
| \ICON\5\0 | 16518 | 1A68 | 12B18 | 2800000028000000500000000100200000000000401A000000000000000000000000000000000000D77800FFD77800FFD778 | (...(...P..... .....@....................x...x...x |
| \ICON\6\0 | 17F80 | 10A8 | 14580 | 28000000200000004000000001002000000000008010000000000000000000000000000000000000D77800FFD77800FFD778 | (... ...@..... ..........................x...x...x |
| \ICON\7\0 | 19028 | 988 | 15628 | 28000000180000003000000001002000000000006009000000000000000000000000000000000000D77800FFD77800FFD778 | (.......0..... .........................x...x...x |
| \ICON\8\0 | 199B0 | 6B8 | 15FB0 | 28000000140000002800000001002000000000009006000000000000000000000000000000000000D77800FFD77800FFD778 | (.......(..... ..........................x...x...x |
| \ICON\9\0 | 1A068 | 468 | 16668 | 28000000100000002000000001002000000000004004000000000000000000000000000000000000D77800FFD77800FFD778 | (....... ..... .....@....................x...x...x |
| \GROUP_ICON\32512\0 | 1A4D0 | 76 | 16AD0 | 000001000800000000000100200076180000020040400000010020002842000003003030000001002000A825000004002828 | ............ .v.....@@.... .(B....00.... ..%....(( |
| \VERSION\1\0 | E280 | 24C | A880 | 4C0234000000560053005F00560045005200530049004F004E005F0049004E0046004F0000000000BD04EFFE000001000000 | L.4...V.S._.V.E.R.S.I.O.N._.I.N.F.O............... |
| \24\1\0 | 1A548 | 1EA | 16B48 | EFBBBF3C3F786D6C2076657273696F6E3D22312E302220656E636F64696E673D225554462D3822207374616E64616C6F6E65 | ...<?xml version="1.0" encoding="UTF-8" standalone |
| Intelligent String |
| • 0.0.0.0 • Untitled1.exe • $url = "https://codeberg.org/stepel35/ps1/raw/branch/main/Script.exe" • Untitled1.ps1 • _CorExeMainmscoree.dll |
| Flow Anomalies |
| Offset | FlowVA | Section | Description |
|---|---|---|---|
| 6DCE | 2510133 | .text | CALL [static] | Indirect call to absolute memory address |
| A5EE | 402000 | .text | JMP [static] | Indirect jump to absolute memory address |
| Extra Analysis |
| Metric | Value | Percentage |
|---|---|---|
| Ascii Code | 45161 | 47,9375% |
| Null Byte Code | 17900 | 19,0005% |
© 2026 All rights reserved.