PESCAN.IO - Analysis Report Basic |
|||||||
| File Structure |
|
PE Chart Code
Header PE (light blue)
Executable sections (pink)
Non-executable sections (black)
External injected code (red)
File Structure in red = malformed or corrupted header
Chart Code For Other Files
Printable characters (blue)
Non-printable characters (black)
| Information |
Icon: Size: 108,12 KBSHA-256 Hash: 2803B74D5466845E4DC9063BD516F3679AA2A3F70A30D9E93976C212E87F6E87 SHA-1 Hash: 10B1D1FC1DC4F11BEF3FEA1163CF68A88C29D3CF MD5 Hash: 8CE68A756995DEB55746DEE1525EDEC3 Imphash: 95185ADF324098A432F1D2EF4BBE2768 MajorOSVersion: 6 MinorOSVersion: 0 CheckSum: 0002901A EntryPoint (rva): AB30 SizeOfHeaders: 400 SizeOfImage: 1C000 ImageBase: 0000000140000000 Architecture: x64 ImportTable: 1281C IAT: C000 Characteristics: 22 TimeDateStamp: 6363CD46 Date: 03/11/2022 14:16:38 File Type: EXE Number Of Sections: 6 ASLR: Disabled Section Names (Optional Header): .text, .rdata, .data, .pdata, .rsrc, .reloc Number Of Executable Sections: 1 Subsystem: Windows GUI |
| Sections Info |
| Section Name | Flags | ROffset | RSize | VOffset | VSize | Entropy | Chi2 |
|---|---|---|---|---|---|---|---|
| .text | 0x60000020 Code Executable Readable |
400 | B000 | 1000 | AEB2 |
|
|
| .rdata | 0x40000040 Initialized Data Readable |
B400 | 8E00 | C000 | 8D9C |
|
|
| .data | 0xC0000040 Initialized Data Readable Writeable |
14200 | 200 | 15000 | 928 |
|
|
| .pdata | 0x40000040 Initialized Data Readable |
14400 | E00 | 16000 | C78 |
|
|
| .rsrc | 0x40000040 Initialized Data Readable |
15200 | 3400 | 17000 | 32D0 |
|
|
| .reloc | 0x42000040 Initialized Data GP-Relative Readable |
18600 | 200 | 1B000 | 108 |
|
|
| Description |
| OriginalFilename: vmtoolsd.exe CompanyName: VMware, Inc. LegalCopyright: Copyright 1998-2022 VMware, Inc. ProductName: VMware Tools FileVersion: 12.1.5.39265 FileDescription: VMware Tools Core Service ProductVersion: 12.1.5 build-20735119 Language: English (United States) (ID=0x409) CodePage: Unicode (UTF-16 LE) (0x4B0) |
| Entry Point |
The section number (1) have the Entry Point Information -> EntryPoint (calculated) - 9F30 Code -> 4883EC28E8AF0600004883C428E96AFEFFFFCCCC40534883EC20488BD9EB0F488BCBE88712000085C07413488BCBE8FD1100 Assembler |SUB RSP, 0X28 |CALL 0X14000B1E8 |ADD RSP, 0X28 |JMP 0X14000A9AC |INT3 |INT3 |PUSH RBX |SUB RSP, 0X20 |MOV RBX, RCX |JMP 0X14000AB5E |MOV RCX, RBX |CALL 0X14000BDDE |TEST EAX, EAX |JE 0X14000AB6E |MOV RCX, RBX |
| Signatures |
| Rich Signature Analyzer: Code -> 38F122607C904C337C904C337C904C3375E8DF3370904C332EE54D3278904C331AFFB1337D904C33C9E54D327E904C3315F84D327A904C337DFD4D327E904C332EE5493265904C332EE5483276904C332EE54F327F904C3398E04D3271904C337C904D3341914C33C9E5483277904C33C9E549327E904C33C9E5B3337D904C337C90DB337D904C33C9E54E327D904C33526963687C904C33 Footprint md5 Hash -> 31AA56E2C4770649052438A455D8358B • The Rich header apparently has not been modified Certificate - Digital Signature: • The file is signed and the signature is correct |
| Packer/Compiler |
| Compiler: Microsoft Visual Studio Detect It Easy (die) • PE+(64): compiler: Microsoft Visual C/C++(-)[-] • PE+(64): linker: Microsoft Linker(14.29**)[-] • PE+(64): Sign tool: Windows Authenticode(2.0)[PKCS 7] • Entropy: 6.2219 |
| Suspicious Functions |
| Library | Function | Description |
|---|---|---|
| KERNEL32.DLL | LoadLibraryW | Loads the specified module into the address space of the calling process. |
| KERNEL32.DLL | GetProcAddress | Retrieves the address of an exported function or variable from the specified dynamic-link library (DLL). |
| KERNEL32.DLL | IsDebuggerPresent | Determines if the calling process is being debugged by a user-mode debugger. |
| Windows REG |
| Software\VMware, Inc.\NeedReboot |
| Windows REG (UNICODE) |
| Software\VMware, Inc. SYSTEM\CurrentControlSet\Services\EventLog\Application\%S |
| File Access |
| api-ms-win-crt-math-l1-1-0.dll api-ms-win-crt-stdio-l1-1-0.dll api-ms-win-crt-string-l1-1-0.dll api-ms-win-crt-locale-l1-1-0.dll api-ms-win-crt-runtime-l1-1-0.dll api-ms-win-crt-heap-l1-1-0.dll VCRUNTIME140.dll VCRUNTIME140_1.dll KERNEL32.dll vmtools.dll gobject-2.0.dll gmodule-2.0.dll glib-2.0.dll intl.dll WS2_32.dll VERSION.dll USER32.dll ole32.dll ADVAPI32.dll .dll vmrpcdbg.dll .dat @.dat @&!*@*@(cmdline.log Temp |
| File Access (UNICODE) |
| vmtoolsd.exe advapi32.dll %windir%\system32\vsocklib.dll WinDir |
| Interest's Words |
| exec start pause shutdown ping |
| Interest's Words (UNICODE) |
| start |
| URLs |
| http://schemas.microsoft.com/SMI/2016/WindowsSettings http://schemas.microsoft.com/SMI/2005/WindowsSettings http://ocsp.digicert.com http://cacerts.digicert.com/DigiCertTrustedRootG4.crt http://crl3.digicert.com/DigiCertTrustedRootG4.crl http://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl http://www.digicert.com/CPS0 http://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt http://www.vmware.com/0/ http://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl http://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl |
| Strings/Hex Code Found With The File Rules |
| Rule Type | Encoding | Matched (Word) |
|---|---|---|
| Text | Ascii | WinAPI Sockets (connect) |
| Text | Ascii | WinAPI Sockets (send) |
| Text | Ascii | Registry (RegOpenKeyEx) |
| Text | Ascii | Registry (RegSetValueEx) |
| Text | Ascii | Service (OpenSCManager) |
| Text | Ascii | Service (CreateService) |
| Text | Ascii | Service (StartServiceCtrlDispatcher) |
| Text | Ascii | Anti-Analysis VM (IsDebuggerPresent) |
| Text | Ascii | Stealth (CloseHandle) |
| Text | Ascii | Execution (OpenEventW) |
| Text | Ascii | Execution (CreateEventW) |
| Text | Ascii | Malicious access method to bypass normal authentication (Backdoor) |
| Text | Ascii | Software that records user activity (Logger) |
| Entry Point | Hex Pattern | Microsoft Visual C++ 8.0 (DLL) |
| Entry Point | Hex Pattern | PE-Exe Executable Image |
| Resources |
| Path | DataRVA | Size | FileOffset | Code | Text |
|---|---|---|---|---|---|
| \ICON\1\0 | 17D10 | 25A8 | 15F10 | 2800000030000000600000000100200000000000000000000000000000000000000000000000000000000000000000000000 | (...0........ ................................... |
| \MESSAGETABLE\1\1033 | 17180 | 2C8 | 15380 | 01000000640000006D0000001000000044000100540068006500200025003100200073006500720076006900630065002000 | ....d...m.......D...T.h.e. .%.1. .s.e.r.v.i.c.e. . |
| \GROUP_ICON\101\0 | 1A2B8 | 14 | 184B8 | 0000010001003030000001002000A82500000100 | ......00.... ..%.... |
| \VERSION\1\1033 | 17448 | 320 | 15648 | 200334000000560053005F00560045005200530049004F004E005F0049004E0046004F0000000000BD04EFFE000001000100 | .4...V.S._.V.E.R.S.I.O.N._.I.N.F.O............... |
| \24\1\1033 | 17768 | 5A6 | 15968 | 3C3F786D6C2076657273696F6E3D22312E302220656E636F64696E673D225554462D3822207374616E64616C6F6E653D2279 | <?xml version="1.0" encoding="UTF-8" standalone="y |
| Intelligent String |
| • api-ms-win-crt-locale-l1-1-0.dll • api-ms-win-crt-runtime-l1-1-0.dll • %S\VMwareToolsDumpStateEvent_%s • Named event for 'DumpEvent' already exists. Exiting. • dump-state • @&!*@*@(cmdline.state)Dumps the internal state of a running service instance to the logs. • vmrpcdbg.dll • tcs_dump_state • .dll • %windir%\system32\vsocklib.dll • d:/build/ob/bora-20735119/bora/lib/ntservice/NTService.cpp • advapi32.dll • d:\build\ob\bora-20735119\bora-vmsoft\build\release-x64\tools-for-windows\Win32\services\vmtoolsd\vmtoolsd.pdb • .bss • libintl_gettextintl.dll • glib-2.0.dll • VCRUNTIME140_1.dll • VCRUNTIME140.dll • api-ms-win-crt-heap-l1-1-0.dll • api-ms-win-crt-string-l1-1-0.dll • api-ms-win-crt-stdio-l1-1-0.dll • api-ms-win-crt-math-l1-1-0.dll • vmtoolsd.exe • <dpiAwareness xmlns="http://schemas.microsoft.com/SMI/2016/WindowsSettings">PerMonitorV2,PerMonitor</dpiAwareness> • <dpiAware xmlns="http://schemas.microsoft.com/SMI/2005/WindowsSettings">True/PM</dpiAware> • :060U00Uq]dL.g?O0U0E1-Q!m0U0y+m0k0$+0http://ocsp.digicert.com0C+07http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0EU>0<0:864http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0U |
| Flow Anomalies |
| Offset | FlowVA | Section | Description |
|---|---|---|---|
| 42A | N/A | .text | CALL QWORD PTR [RIP+0xB228] |
| 443 | N/A | .text | CALL QWORD PTR [RIP+0xB1DF] |
| 455 | N/A | .text | CALL QWORD PTR [RIP+0xB065] |
| 462 | N/A | .text | CALL QWORD PTR [RIP+0xB058] |
| 474 | N/A | .text | CALL QWORD PTR [RIP+0xB046] |
| 4DC | N/A | .text | CALL QWORD PTR [RIP+0xB966] |
| 50F | N/A | .text | CALL QWORD PTR [RIP+0xB933] |
| 63F | N/A | .text | CALL QWORD PTR [RIP+0xAE93] |
| 7BE | N/A | .text | CALL QWORD PTR [RIP+0xAEAC] |
| 7D5 | N/A | .text | CALL QWORD PTR [RIP+0xAE9D] |
| 7F3 | N/A | .text | CALL QWORD PTR [RIP+0xB64F] |
| 800 | N/A | .text | CALL QWORD PTR [RIP+0xAE7A] |
| 81B | N/A | .text | CALL QWORD PTR [RIP+0xAE4F] |
| 8AB | N/A | .text | CALL QWORD PTR [RIP+0xAC2F] |
| 8E4 | N/A | .text | CALL QWORD PTR [RIP+0xABDE] |
| 956 | N/A | .text | CALL QWORD PTR [RIP+0xB4EC] |
| 969 | N/A | .text | CALL QWORD PTR [RIP+0xB4D9] |
| 9DB | N/A | .text | JMP QWORD PTR [RIP+0xB467] |
| A3E | N/A | .text | CALL QWORD PTR [RIP+0xB404] |
| B22 | N/A | .text | CALL QWORD PTR [RIP+0xA8D8] |
| B2C | N/A | .text | CALL QWORD PTR [RIP+0xA996] |
| B8B | N/A | .text | CALL QWORD PTR [RIP+0xA897] |
| B9E | N/A | .text | CALL QWORD PTR [RIP+0xABA4] |
| BBC | N/A | .text | CALL QWORD PTR [RIP+0xA84E] |
| BC6 | N/A | .text | CALL QWORD PTR [RIP+0xA8FC] |
| BE1 | N/A | .text | CALL QWORD PTR [RIP+0xA831] |
| BEB | N/A | .text | CALL QWORD PTR [RIP+0xA8D7] |
| C02 | N/A | .text | CALL QWORD PTR [RIP+0xA818] |
| C0C | N/A | .text | CALL QWORD PTR [RIP+0xA8B6] |
| C36 | N/A | .text | CALL QWORD PTR [RIP+0xA8D4] |
| C58 | N/A | .text | CALL QWORD PTR [RIP+0xAA02] |
| C60 | N/A | .text | CALL QWORD PTR [RIP+0xA8AA] |
| C69 | N/A | .text | CALL QWORD PTR [RIP+0xA9C1] |
| CA5 | N/A | .text | CALL QWORD PTR [RIP+0xA9A5] |
| CB7 | N/A | .text | CALL QWORD PTR [RIP+0xA80B] |
| CEA | N/A | .text | CALL QWORD PTR [RIP+0xA928] |
| CFD | N/A | .text | CALL QWORD PTR [RIP+0xA7E5] |
| D0F | N/A | .text | CALL QWORD PTR [RIP+0xA7B3] |
| D6F | N/A | .text | CALL QWORD PTR [RIP+0xA773] |
| D7C | N/A | .text | CALL QWORD PTR [RIP+0xA746] |
| E34 | N/A | .text | CALL QWORD PTR [RIP+0xA6AE] |
| E41 | N/A | .text | CALL QWORD PTR [RIP+0xA681] |
| FA7 | N/A | .text | CALL QWORD PTR [RIP+0xA58B] |
| FB1 | N/A | .text | CALL QWORD PTR [RIP+0xA511] |
| FDF | N/A | .text | CALL QWORD PTR [RIP+0xA50B] |
| FED | N/A | .text | CALL QWORD PTR [RIP+0xA515] |
| FF3 | N/A | .text | CALL QWORD PTR [RIP+0xA4FF] |
| 1001 | N/A | .text | CALL QWORD PTR [RIP+0xA4F9] |
| 101C | N/A | .text | CALL QWORD PTR [RIP+0xA4B6] |
| 102B | N/A | .text | CALL QWORD PTR [RIP+0xA507] |
| 1051 | N/A | .text | CALL QWORD PTR [RIP+0xA3B1] |
| 105B | N/A | .text | CALL QWORD PTR [RIP+0xA4BF] |
| 1064 | N/A | .text | CALL QWORD PTR [RIP+0xA6E6] |
| 1089 | N/A | .text | CALL QWORD PTR [RIP+0xADB9] |
| 1124 | N/A | .text | CALL QWORD PTR [RIP+0xA65E] |
| 1154 | N/A | .text | CALL QWORD PTR [RIP+0xA4B6] |
| 117F | N/A | .text | JMP QWORD PTR [RIP+0xA4E3] |
| 11E3 | N/A | .text | CALL QWORD PTR [RIP+0xA327] |
| 11F6 | N/A | .text | CALL QWORD PTR [RIP+0xA31C] |
| 1206 | N/A | .text | CALL QWORD PTR [RIP+0xAC3C] |
| 121E | N/A | .text | CALL QWORD PTR [RIP+0xA2F4] |
| 122E | N/A | .text | CALL QWORD PTR [RIP+0xAC14] |
| 1245 | N/A | .text | CALL QWORD PTR [RIP+0xA2DD] |
| 1256 | N/A | .text | CALL QWORD PTR [RIP+0xA274] |
| 1280 | N/A | .text | CALL QWORD PTR [RIP+0xA4E2] |
| 139D | N/A | .text | CALL QWORD PTR [RIP+0xA27D] |
| 13E4 | N/A | .text | CALL QWORD PTR [RIP+0xA1D6] |
| 13F6 | N/A | .text | CALL QWORD PTR [RIP+0xA134] |
| 160D | N/A | .text | CALL QWORD PTR [RIP+0xA835] |
| 1621 | N/A | .text | CALL QWORD PTR [RIP+0xA821] |
| 1631 | N/A | .text | CALL QWORD PTR [RIP+0xA811] |
| 1648 | N/A | .text | CALL QWORD PTR [RIP+0xA7FA] |
| 167B | N/A | .text | CALL QWORD PTR [RIP+0x9E47] |
| 1698 | N/A | .text | CALL QWORD PTR [RIP+0x9E2A] |
| 16B5 | N/A | .text | CALL QWORD PTR [RIP+0x9E0D] |
| 1783 | N/A | .text | CALL QWORD PTR [RIP+0x9FFF] |
| 17B5 | N/A | .text | CALL QWORD PTR [RIP+0x9FCD] |
| 1824 | N/A | .text | CALL QWORD PTR [RIP+0x9F5E] |
| 18A1 | N/A | .text | CALL QWORD PTR [RIP+0x9EE1] |
| 18CF | N/A | .text | CALL QWORD PTR [RIP+0x9EB3] |
| 1936 | N/A | .text | CALL QWORD PTR [RIP+0x9C04] |
| 1970 | N/A | .text | CALL QWORD PTR [RIP+0x9BCA] |
| 1981 | N/A | .text | CALL QWORD PTR [RIP+0x9B51] |
| 198B | N/A | .text | CALL QWORD PTR [RIP+0x9B37] |
| 19C4 | N/A | .text | CALL QWORD PTR [RIP+0x9AF6] |
| 1F43 | N/A | .text | CALL QWORD PTR [RIP+0x9807] |
| 2005 | N/A | .text | CALL QWORD PTR [RIP+0x977D] |
| 20DC | N/A | .text | CALL QWORD PTR [RIP+0x96A6] |
| 2103 | N/A | .text | CALL QWORD PTR [RIP+0x967F] |
| 2121 | N/A | .text | CALL QWORD PTR [RIP+0x9629] |
| 2188 | N/A | .text | CALL QWORD PTR [RIP+0x933A] |
| 247B | N/A | .text | CALL QWORD PTR [RIP+0x93E7] |
| 24A0 | N/A | .text | CALL QWORD PTR [RIP+0x90A2] |
| 24C5 | N/A | .text | CALL QWORD PTR [RIP+0x907D] |
| 24E9 | N/A | .text | CALL QWORD PTR [RIP+0x8FD9] |
| 2555 | N/A | .text | CALL QWORD PTR [RIP+0x91F5] |
| 258A | N/A | .text | CALL QWORD PTR [RIP+0x8F38] |
| 25B5 | N/A | .text | CALL QWORD PTR [RIP+0x8F0D] |
| 261D | N/A | .text | CALL QWORD PTR [RIP+0x912D] |
| 2700 | N/A | .text | CALL QWORD PTR [RIP+0x8DC2] |
| 18800 | N/A | *Overlay* | 78280000000202003082286A06092A864886F70D | x(......0.(j..*.H...) |
| Extra Analysis |
| Metric | Value | Percentage |
|---|---|---|
| Ascii Code | 63478 | 57,3362% |
| Null Byte Code | 25810 | 23,3127% |
© 2026 All rights reserved.