PESCAN.IO - Analysis Report Basic

File Structure
Analysis Image
PE Chart Code
Header PE (light blue)
Executable sections (pink)
Non-executable sections (black)
External injected code (red)
File Structure in red = malformed or corrupted header

Chart Code For Other Files
Printable characters (blue)
Non-printable characters (black)
Information
Icon: Icon
Size: 92,00 KB
SHA-256 Hash: 4DE52F0C866B30D5E5D53904EF356FB637E2AD26FBF54406190DA4FA319D78BF
SHA-1 Hash: B141DE67F55630BDA59E00F57F52AD20C81ED338
MD5 Hash: 88E7E7D0C1DB653AAAD97EDADF2BC18F
Imphash: F34D5F2D4577ED6D9CEEC516C1F5A744
MajorOSVersion: 4
MinorOSVersion: 0
CheckSum: 00000000
EntryPoint (rva): C3EE
SizeOfHeaders: 200
SizeOfImage: 1E000
ImageBase: 400000
Architecture: x86
ImportTable: C3A0
IAT: 2000
Characteristics: 102
TimeDateStamp: 6A02DA6C
Date: 12/05/2026 7:44:44
File Type: EXE
Number Of Sections: 3
ASLR: Enabled
Section Names: .text, .rsrc, .reloc
Number Of Executable Sections: 1
Subsystem: Windows GUI
UAC Execution Level Manifest: asInvoker

Sections Info
Section Name Flags ROffset RSize VOffset VSizeEntropyChi2
.text
0x60000020
Code
Executable
Readable
200 A400 2000 A3F4
6.0296
412862.39
.rsrc
0x40000040
Initialized Data
Readable
A600 C800 E000 C738
3.7491
2414598.9
.reloc
0x42000040
Initialized Data
GP-Relative
Readable
16E00 200 1C000 C
0.0815
128522
Description
OriginalFilename: Untitled1.exe
FileVersion: 0.0.0.0
ProductVersion: 0.0.0.0
Language: Unknown (ID=0x0)
CodePage: Unicode (UTF-16 LE) (0x4B0)

Entry Point
The section number (1) - (.text) have the Entry Point
Information -> EntryPoint (calculated) - A5EE
Code -> FF25002040000000000000000000000000000000000000000000000000000000040003000000300000800E00000080000080
Assembler
|JMP DWORD PTR [0X402000]
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD AL, 0
|ADD EAX, DWORD PTR [EAX]
|ADD BYTE PTR [EAX], AL
|XOR BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX + 0XE], AL
|ADD BYTE PTR [EAX], 0
Signatures
Certificate - Digital Signature Not Found:
• The file is not signed

Packer/Compiler
Compiler: Microsoft Visual .NET - (You can use a decompiler for this...)
AnyCPU: True
Version: v4.0
Detect It Easy (die)
PE: library: .NET(v4.0.30319)[-]
PE: linker: Microsoft Linker(11.0)[-]
Entropy: 5.32018

File Access
Untitled1.exe
//codeberg.org/stepel35/ps1/raw/branch/main/Script.exe
mscoree.dll
user32.dll
clr.dll
kernel32.dll
psapi.dll
Runtime.InteropServices.Dll
Untitled1.ps1
New-Object Win32.SYS
Win32.SYS
Temp

File Access (UNICODE)
Untitled1.exe
Untitled1.ps1

Interest's Words
PassWord
<main
exec
powershell
attrib
start
systeminfo
replace

URLs
https://codeberg.org/stepel35/ps1/raw/branch/main/Script.exe

Strings/Hex Code Found With The File Rules
Rule Type Encoding Matched (Word)
Text Ascii WinAPI Sockets (send)
Text Ascii Anti-Analysis VM (GetSystemInfo)
Text Ascii Stealth (VirtualProtect)
Text Ascii Stealth (ReadProcessMemory)
Text Ascii Keyboard Key (Scroll)
Text Ascii Information used for user authentication (Credential)
Text Ascii Malicious rerouting of traffic to an attacker-controlled site (Redirect)
Entry Point Hex Pattern Microsoft Visual C++ 8
Entry Point Hex Pattern Microsoft Visual C++ 8.0
Entry Point Hex Pattern TrueVision Targa Graphics format
Resources
Path DataRVA Size FileOffset CodeText
\ICON\2\0 E4D0 1876 AAD0 89504E470D0A1A0A0000000D49484452000001000000010008060000005C72A8660000183D49444154789CEDDD3F4C1B69DE.PNG........IHDR.............\r.f...=IDATx...?L.i.
\ICON\3\0 FD48 4228 C348 28000000400000008000000001002000000000000042000000000000000000000000000000000000D77800FFD77800FFD778(...@......... ......B...................x...x...x
\ICON\4\0 13F70 25A8 10570 28000000300000006000000001002000000000008025000000000000000000000000000000000000D77800FFD77800FFD778(...0........ ......%...................x...x...x
\ICON\5\0 16518 1A68 12B18 2800000028000000500000000100200000000000401A000000000000000000000000000000000000D77800FFD77800FFD778(...(...P..... .....@....................x...x...x
\ICON\6\0 17F80 10A8 14580 28000000200000004000000001002000000000008010000000000000000000000000000000000000D77800FFD77800FFD778(... ...@..... ..........................x...x...x
\ICON\7\0 19028 988 15628 28000000180000003000000001002000000000006009000000000000000000000000000000000000D77800FFD77800FFD778(.......0..... .........................x...x...x
\ICON\8\0 199B0 6B8 15FB0 28000000140000002800000001002000000000009006000000000000000000000000000000000000D77800FFD77800FFD778(.......(..... ..........................x...x...x
\ICON\9\0 1A068 468 16668 28000000100000002000000001002000000000004004000000000000000000000000000000000000D77800FFD77800FFD778(....... ..... .....@....................x...x...x
\GROUP_ICON\32512\0 1A4D0 76 16AD0 000001000800000000000100200076180000020040400000010020002842000003003030000001002000A825000004002828............ .v.....@@.... .(B....00.... ..%....((
\VERSION\1\0 E280 24C A880 4C0234000000560053005F00560045005200530049004F004E005F0049004E0046004F0000000000BD04EFFE000001000000L.4...V.S._.V.E.R.S.I.O.N._.I.N.F.O...............
\24\1\0 1A548 1EA 16B48 EFBBBF3C3F786D6C2076657273696F6E3D22312E302220656E636F64696E673D225554462D3822207374616E64616C6F6E65...<?xml version="1.0" encoding="UTF-8" standalone
Intelligent String
• 0.0.0.0
• Untitled1.exe
• $url = "https://codeberg.org/stepel35/ps1/raw/branch/main/Script.exe"
• Untitled1.ps1
• _CorExeMainmscoree.dll

Flow Anomalies
Offset FlowVA Section Description
6DCE 2510133 .text CALL [static] | Indirect call to absolute memory address
A5EE 402000 .text JMP [static] | Indirect jump to absolute memory address
Extra Analysis
Metric Value Percentage
Ascii Code 45161 47,9375%
Null Byte Code 17900 19,0005%
© 2026 All rights reserved.