PESCAN.IO - Analysis Report Basic

File Structure
Analysis Image
PE Chart Code
Header PE (light blue)
Executable sections (pink)
Non-executable sections (black)
External injected code (red)
File Structure in red = malformed or corrupted header

Chart Code For Other Files
Printable characters (blue)
Non-printable characters (black)
Information
Icon: Icon
Size: 108,12 KB
SHA-256 Hash: 2803B74D5466845E4DC9063BD516F3679AA2A3F70A30D9E93976C212E87F6E87
SHA-1 Hash: 10B1D1FC1DC4F11BEF3FEA1163CF68A88C29D3CF
MD5 Hash: 8CE68A756995DEB55746DEE1525EDEC3
Imphash: 95185ADF324098A432F1D2EF4BBE2768
MajorOSVersion: 6
MinorOSVersion: 0
CheckSum: 0002901A
EntryPoint (rva): AB30
SizeOfHeaders: 400
SizeOfImage: 1C000
ImageBase: 0000000140000000
Architecture: x64
ImportTable: 1281C
IAT: C000
Characteristics: 22
TimeDateStamp: 6363CD46
Date: 03/11/2022 14:16:38
File Type: EXE
Number Of Sections: 6
ASLR: Disabled
Section Names (Optional Header): .text, .rdata, .data, .pdata, .rsrc, .reloc
Number Of Executable Sections: 1
Subsystem: Windows GUI

Sections Info
Section Name Flags ROffset RSize VOffset VSizeEntropyChi2
.text
0x60000020
Code
Executable
Readable
400 B000 1000 AEB2
5.9423
594307.85
.rdata
0x40000040
Initialized Data
Readable
B400 8E00 C000 8D9C
4.9935
1036102.87
.data
0xC0000040
Initialized Data
Readable
Writeable
14200 200 15000 928
2.8684
51819
.pdata
0x40000040
Initialized Data
Readable
14400 E00 16000 C78
4.4901
218258.86
.rsrc
0x40000040
Initialized Data
Readable
15200 3400 17000 32D0
5.6282
252753.38
.reloc
0x42000040
Initialized Data
GP-Relative
Readable
18600 200 1B000 108
3.1414
41191
Description
OriginalFilename: vmtoolsd.exe
CompanyName: VMware, Inc.
LegalCopyright: Copyright 1998-2022 VMware, Inc.
ProductName: VMware Tools
FileVersion: 12.1.5.39265
FileDescription: VMware Tools Core Service
ProductVersion: 12.1.5 build-20735119
Language: English (United States) (ID=0x409)
CodePage: Unicode (UTF-16 LE) (0x4B0)

Entry Point
The section number (1) have the Entry Point
Information -> EntryPoint (calculated) - 9F30
Code -> 4883EC28E8AF0600004883C428E96AFEFFFFCCCC40534883EC20488BD9EB0F488BCBE88712000085C07413488BCBE8FD1100
Assembler
|SUB RSP, 0X28
|CALL 0X14000B1E8
|ADD RSP, 0X28
|JMP 0X14000A9AC
|INT3
|INT3
|PUSH RBX
|SUB RSP, 0X20
|MOV RBX, RCX
|JMP 0X14000AB5E
|MOV RCX, RBX
|CALL 0X14000BDDE
|TEST EAX, EAX
|JE 0X14000AB6E
|MOV RCX, RBX
Signatures
Rich Signature Analyzer:
Code -> 38F122607C904C337C904C337C904C3375E8DF3370904C332EE54D3278904C331AFFB1337D904C33C9E54D327E904C3315F84D327A904C337DFD4D327E904C332EE5493265904C332EE5483276904C332EE54F327F904C3398E04D3271904C337C904D3341914C33C9E5483277904C33C9E549327E904C33C9E5B3337D904C337C90DB337D904C33C9E54E327D904C33526963687C904C33
Footprint md5 Hash -> 31AA56E2C4770649052438A455D8358B
• The Rich header apparently has not been modified
Certificate - Digital Signature:
• The file is signed and the signature is correct

Packer/Compiler
Compiler: Microsoft Visual Studio
Detect It Easy (die)
PE+(64): compiler: Microsoft Visual C/C++(-)[-]
PE+(64): linker: Microsoft Linker(14.29**)[-]
PE+(64): Sign tool: Windows Authenticode(2.0)[PKCS 7]
Entropy: 6.2219

Suspicious Functions
Library Function Description
KERNEL32.DLL LoadLibraryW Loads the specified module into the address space of the calling process.
KERNEL32.DLL GetProcAddress Retrieves the address of an exported function or variable from the specified dynamic-link library (DLL).
KERNEL32.DLL IsDebuggerPresent Determines if the calling process is being debugged by a user-mode debugger.
Windows REG
Software\VMware, Inc.\NeedReboot

Windows REG (UNICODE)
Software\VMware, Inc.
SYSTEM\CurrentControlSet\Services\EventLog\Application\%S

File Access
api-ms-win-crt-math-l1-1-0.dll
api-ms-win-crt-stdio-l1-1-0.dll
api-ms-win-crt-string-l1-1-0.dll
api-ms-win-crt-locale-l1-1-0.dll
api-ms-win-crt-runtime-l1-1-0.dll
api-ms-win-crt-heap-l1-1-0.dll
VCRUNTIME140.dll
VCRUNTIME140_1.dll
KERNEL32.dll
vmtools.dll
gobject-2.0.dll
gmodule-2.0.dll
glib-2.0.dll
intl.dll
WS2_32.dll
VERSION.dll
USER32.dll
ole32.dll
ADVAPI32.dll
.dll
vmrpcdbg.dll
.dat
@.dat
@&!*@*@(cmdline.log
Temp

File Access (UNICODE)
vmtoolsd.exe
advapi32.dll
%windir%\system32\vsocklib.dll
WinDir

Interest's Words
exec
start
pause
shutdown
ping

Interest's Words (UNICODE)
start

URLs
http://schemas.microsoft.com/SMI/2016/WindowsSettings
http://schemas.microsoft.com/SMI/2005/WindowsSettings
http://ocsp.digicert.com
http://cacerts.digicert.com/DigiCertTrustedRootG4.crt
http://crl3.digicert.com/DigiCertTrustedRootG4.crl
http://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl
http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl
http://www.digicert.com/CPS0
http://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt
http://www.vmware.com/0/
http://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl
http://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt
http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt
http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl

Strings/Hex Code Found With The File Rules
Rule Type Encoding Matched (Word)
Text Ascii WinAPI Sockets (connect)
Text Ascii WinAPI Sockets (send)
Text Ascii Registry (RegOpenKeyEx)
Text Ascii Registry (RegSetValueEx)
Text Ascii Service (OpenSCManager)
Text Ascii Service (CreateService)
Text Ascii Service (StartServiceCtrlDispatcher)
Text Ascii Anti-Analysis VM (IsDebuggerPresent)
Text Ascii Stealth (CloseHandle)
Text Ascii Execution (OpenEventW)
Text Ascii Execution (CreateEventW)
Text Ascii Malicious access method to bypass normal authentication (Backdoor)
Text Ascii Software that records user activity (Logger)
Entry Point Hex Pattern Microsoft Visual C++ 8.0 (DLL)
Entry Point Hex Pattern PE-Exe Executable Image
Resources
Path DataRVA Size FileOffset CodeText
\ICON\1\0 17D10 25A8 15F10 2800000030000000600000000100200000000000000000000000000000000000000000000000000000000000000000000000(...0........ ...................................
\MESSAGETABLE\1\1033 17180 2C8 15380 01000000640000006D0000001000000044000100540068006500200025003100200073006500720076006900630065002000....d...m.......D...T.h.e. .%.1. .s.e.r.v.i.c.e. .
\GROUP_ICON\101\0 1A2B8 14 184B8 0000010001003030000001002000A82500000100......00.... ..%....
\VERSION\1\1033 17448 320 15648 200334000000560053005F00560045005200530049004F004E005F0049004E0046004F0000000000BD04EFFE000001000100.4...V.S._.V.E.R.S.I.O.N._.I.N.F.O...............
\24\1\1033 17768 5A6 15968 3C3F786D6C2076657273696F6E3D22312E302220656E636F64696E673D225554462D3822207374616E64616C6F6E653D2279<?xml version="1.0" encoding="UTF-8" standalone="y
Intelligent String
• api-ms-win-crt-locale-l1-1-0.dll
• api-ms-win-crt-runtime-l1-1-0.dll
• %S\VMwareToolsDumpStateEvent_%s
• Named event for 'DumpEvent' already exists. Exiting.
• dump-state
• @&!*@*@(cmdline.state)Dumps the internal state of a running service instance to the logs.
• vmrpcdbg.dll
• tcs_dump_state
• .dll
• %windir%\system32\vsocklib.dll
• d:/build/ob/bora-20735119/bora/lib/ntservice/NTService.cpp
• advapi32.dll
• d:\build\ob\bora-20735119\bora-vmsoft\build\release-x64\tools-for-windows\Win32\services\vmtoolsd\vmtoolsd.pdb
• .bss
• libintl_gettextintl.dll
• glib-2.0.dll
• VCRUNTIME140_1.dll
• VCRUNTIME140.dll
• api-ms-win-crt-heap-l1-1-0.dll
• api-ms-win-crt-string-l1-1-0.dll
• api-ms-win-crt-stdio-l1-1-0.dll
• api-ms-win-crt-math-l1-1-0.dll
• vmtoolsd.exe
• <dpiAwareness xmlns="http://schemas.microsoft.com/SMI/2016/WindowsSettings">PerMonitorV2,PerMonitor</dpiAwareness>
• <dpiAware xmlns="http://schemas.microsoft.com/SMI/2005/WindowsSettings">True/PM</dpiAware>
• :060U00Uq]dL.g?O0U0E1-Q!m0U0y+m0k0$+0http://ocsp.digicert.com0C+07http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0EU>0<0:864http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0U

Flow Anomalies
Offset FlowVA Section Description
42A N/A .text CALL QWORD PTR [RIP+0xB228]
443 N/A .text CALL QWORD PTR [RIP+0xB1DF]
455 N/A .text CALL QWORD PTR [RIP+0xB065]
462 N/A .text CALL QWORD PTR [RIP+0xB058]
474 N/A .text CALL QWORD PTR [RIP+0xB046]
4DC N/A .text CALL QWORD PTR [RIP+0xB966]
50F N/A .text CALL QWORD PTR [RIP+0xB933]
63F N/A .text CALL QWORD PTR [RIP+0xAE93]
7BE N/A .text CALL QWORD PTR [RIP+0xAEAC]
7D5 N/A .text CALL QWORD PTR [RIP+0xAE9D]
7F3 N/A .text CALL QWORD PTR [RIP+0xB64F]
800 N/A .text CALL QWORD PTR [RIP+0xAE7A]
81B N/A .text CALL QWORD PTR [RIP+0xAE4F]
8AB N/A .text CALL QWORD PTR [RIP+0xAC2F]
8E4 N/A .text CALL QWORD PTR [RIP+0xABDE]
956 N/A .text CALL QWORD PTR [RIP+0xB4EC]
969 N/A .text CALL QWORD PTR [RIP+0xB4D9]
9DB N/A .text JMP QWORD PTR [RIP+0xB467]
A3E N/A .text CALL QWORD PTR [RIP+0xB404]
B22 N/A .text CALL QWORD PTR [RIP+0xA8D8]
B2C N/A .text CALL QWORD PTR [RIP+0xA996]
B8B N/A .text CALL QWORD PTR [RIP+0xA897]
B9E N/A .text CALL QWORD PTR [RIP+0xABA4]
BBC N/A .text CALL QWORD PTR [RIP+0xA84E]
BC6 N/A .text CALL QWORD PTR [RIP+0xA8FC]
BE1 N/A .text CALL QWORD PTR [RIP+0xA831]
BEB N/A .text CALL QWORD PTR [RIP+0xA8D7]
C02 N/A .text CALL QWORD PTR [RIP+0xA818]
C0C N/A .text CALL QWORD PTR [RIP+0xA8B6]
C36 N/A .text CALL QWORD PTR [RIP+0xA8D4]
C58 N/A .text CALL QWORD PTR [RIP+0xAA02]
C60 N/A .text CALL QWORD PTR [RIP+0xA8AA]
C69 N/A .text CALL QWORD PTR [RIP+0xA9C1]
CA5 N/A .text CALL QWORD PTR [RIP+0xA9A5]
CB7 N/A .text CALL QWORD PTR [RIP+0xA80B]
CEA N/A .text CALL QWORD PTR [RIP+0xA928]
CFD N/A .text CALL QWORD PTR [RIP+0xA7E5]
D0F N/A .text CALL QWORD PTR [RIP+0xA7B3]
D6F N/A .text CALL QWORD PTR [RIP+0xA773]
D7C N/A .text CALL QWORD PTR [RIP+0xA746]
E34 N/A .text CALL QWORD PTR [RIP+0xA6AE]
E41 N/A .text CALL QWORD PTR [RIP+0xA681]
FA7 N/A .text CALL QWORD PTR [RIP+0xA58B]
FB1 N/A .text CALL QWORD PTR [RIP+0xA511]
FDF N/A .text CALL QWORD PTR [RIP+0xA50B]
FED N/A .text CALL QWORD PTR [RIP+0xA515]
FF3 N/A .text CALL QWORD PTR [RIP+0xA4FF]
1001 N/A .text CALL QWORD PTR [RIP+0xA4F9]
101C N/A .text CALL QWORD PTR [RIP+0xA4B6]
102B N/A .text CALL QWORD PTR [RIP+0xA507]
1051 N/A .text CALL QWORD PTR [RIP+0xA3B1]
105B N/A .text CALL QWORD PTR [RIP+0xA4BF]
1064 N/A .text CALL QWORD PTR [RIP+0xA6E6]
1089 N/A .text CALL QWORD PTR [RIP+0xADB9]
1124 N/A .text CALL QWORD PTR [RIP+0xA65E]
1154 N/A .text CALL QWORD PTR [RIP+0xA4B6]
117F N/A .text JMP QWORD PTR [RIP+0xA4E3]
11E3 N/A .text CALL QWORD PTR [RIP+0xA327]
11F6 N/A .text CALL QWORD PTR [RIP+0xA31C]
1206 N/A .text CALL QWORD PTR [RIP+0xAC3C]
121E N/A .text CALL QWORD PTR [RIP+0xA2F4]
122E N/A .text CALL QWORD PTR [RIP+0xAC14]
1245 N/A .text CALL QWORD PTR [RIP+0xA2DD]
1256 N/A .text CALL QWORD PTR [RIP+0xA274]
1280 N/A .text CALL QWORD PTR [RIP+0xA4E2]
139D N/A .text CALL QWORD PTR [RIP+0xA27D]
13E4 N/A .text CALL QWORD PTR [RIP+0xA1D6]
13F6 N/A .text CALL QWORD PTR [RIP+0xA134]
160D N/A .text CALL QWORD PTR [RIP+0xA835]
1621 N/A .text CALL QWORD PTR [RIP+0xA821]
1631 N/A .text CALL QWORD PTR [RIP+0xA811]
1648 N/A .text CALL QWORD PTR [RIP+0xA7FA]
167B N/A .text CALL QWORD PTR [RIP+0x9E47]
1698 N/A .text CALL QWORD PTR [RIP+0x9E2A]
16B5 N/A .text CALL QWORD PTR [RIP+0x9E0D]
1783 N/A .text CALL QWORD PTR [RIP+0x9FFF]
17B5 N/A .text CALL QWORD PTR [RIP+0x9FCD]
1824 N/A .text CALL QWORD PTR [RIP+0x9F5E]
18A1 N/A .text CALL QWORD PTR [RIP+0x9EE1]
18CF N/A .text CALL QWORD PTR [RIP+0x9EB3]
1936 N/A .text CALL QWORD PTR [RIP+0x9C04]
1970 N/A .text CALL QWORD PTR [RIP+0x9BCA]
1981 N/A .text CALL QWORD PTR [RIP+0x9B51]
198B N/A .text CALL QWORD PTR [RIP+0x9B37]
19C4 N/A .text CALL QWORD PTR [RIP+0x9AF6]
1F43 N/A .text CALL QWORD PTR [RIP+0x9807]
2005 N/A .text CALL QWORD PTR [RIP+0x977D]
20DC N/A .text CALL QWORD PTR [RIP+0x96A6]
2103 N/A .text CALL QWORD PTR [RIP+0x967F]
2121 N/A .text CALL QWORD PTR [RIP+0x9629]
2188 N/A .text CALL QWORD PTR [RIP+0x933A]
247B N/A .text CALL QWORD PTR [RIP+0x93E7]
24A0 N/A .text CALL QWORD PTR [RIP+0x90A2]
24C5 N/A .text CALL QWORD PTR [RIP+0x907D]
24E9 N/A .text CALL QWORD PTR [RIP+0x8FD9]
2555 N/A .text CALL QWORD PTR [RIP+0x91F5]
258A N/A .text CALL QWORD PTR [RIP+0x8F38]
25B5 N/A .text CALL QWORD PTR [RIP+0x8F0D]
261D N/A .text CALL QWORD PTR [RIP+0x912D]
2700 N/A .text CALL QWORD PTR [RIP+0x8DC2]
18800 N/A *Overlay* 78280000000202003082286A06092A864886F70D | x(......0.(j..*.H...)
Extra Analysis
Metric Value Percentage
Ascii Code 63478 57,3362%
Null Byte Code 25810 23,3127%
© 2026 All rights reserved.