PESCAN.IO - Analysis Report Basic

File Structure
Analysis Image
PE Chart Code
Header PE (light blue)
Executable sections (pink)
Non-executable sections (black)
External injected code (red)
File Structure in red = malformed or corrupted header

Chart Code For Other Files
Printable characters (blue)
Non-printable characters (black)
Information
Size: 14,00 KB
SHA-256 Hash: BBB3DE5707629E6A60A0C238CD477B28F07F0066982FDA953FA6FCEC39073A4A
SHA-1 Hash: 32F4A73F1F15E2CC04DA20DFFD60E5AA40D32466
MD5 Hash: 91538DF53511BE83EE84A43E97430041
Imphash: 77D2A6FFFE40A245D700FAE4D8114870
MajorOSVersion: 6
MinorOSVersion: 0
CheckSum: 00000000
EntryPoint (rva): 1D40
SizeOfHeaders: 400
SizeOfImage: 9000
ImageBase: 0000000140000000
Architecture: x64
ImportTable: 3A04
IAT: 3000
Characteristics: 22
TimeDateStamp: 646827E4
Date: 20/05/2023 1:52:36
File Type: EXE
Number Of Sections: 6
ASLR: Disabled
Section Names (Optional Header): .text, .rdata, .data, .pdata, .rsrc, .reloc
Number Of Executable Sections: 1
Subsystem: Windows Console
UAC Execution Level Manifest: asInvoker

Sections Info
Section Name Flags ROffset RSize VOffset VSizeEntropyChi2
.text
0x60000020
Code
Executable
Readable
400 1800 1000 17BC
6.1561
59632.25
.rdata
0x40000040
Initialized Data
Readable
1C00 1400 3000 132C
4.1976
313109.5
.data
0xC0000040
Initialized Data
Readable
Writeable
3000 200 5000 648
0.4444
118591
.pdata
0x40000040
Initialized Data
Readable
3200 200 6000 1EC
3.7101
36552
.rsrc
0x40000040
Initialized Data
Readable
3400 200 7000 1E0
4.7015
9406
.reloc
0x42000040
Initialized Data
GP-Relative
Readable
3600 200 8000 30
0.7178
110491
Entry Point
The section number (1) have the Entry Point
Information -> EntryPoint (calculated) - 1140
Code -> 4883EC28E8D70300004883C428E972FEFFFFCCCC40534883EC20488BD933C9FF15F3120000488BCBFF15E2120000FF15EC12
Assembler
|SUB RSP, 0X28
|CALL 0X140002120
|ADD RSP, 0X28
|JMP 0X140001BC4
|INT3
|INT3
|PUSH RBX
|SUB RSP, 0X20
|MOV RBX, RCX
|XOR ECX, ECX
|CALL QWORD PTR [RIP + 0X12F3]
|MOV RCX, RBX
|CALL QWORD PTR [RIP + 0X12E2]
Signatures
Rich Signature Analyzer:
Code -> E702CB62A363A531A363A531A363A531AA1B3631B363A531071DA430A163A531071D5831A763A531071DA030B063A531071DA130A963A531071DA630A063A531E81BA430A063A531A363A431E663A531B71CA130A263A531B71C5A31A263A531B71CA730A263A53152696368A363A531
Footprint md5 Hash -> DCF34EC2D77E7FF3EE385EC36EFFB0BA
• The Rich header apparently has not been modified
Certificate - Digital Signature Not Found:
• The file is not signed

Packer/Compiler
Detect It Easy (die)
PE+(64): compiler: Microsoft Visual C/C++(-)[-]
PE+(64): linker: Microsoft Linker(14.36**)[-]
Entropy: 5.25058

Suspicious Functions
Library Function Description
KERNEL32.DLL GetModuleFileNameA Retrieve the fully qualified path for the executable file of a specified module.
KERNEL32.DLL GetModuleHandleW Retrieves a handle to the specified module.
KERNEL32.DLL CreateFileA Creates or opens a file or I/O device.
KERNEL32.DLL IsDebuggerPresent Determines if the calling process is being debugged by a user-mode debugger.
KERNEL32.DLL CreateProcessA Creates and starts a new process.
File Access
!python.exe
api-ms-win-crt-process-l1-1-0.dll
api-ms-win-crt-locale-l1-1-0.dll
api-ms-win-crt-math-l1-1-0.dll
api-ms-win-crt-string-l1-1-0.dll
api-ms-win-crt-stdio-l1-1-0.dll
api-ms-win-crt-runtime-l1-1-0.dll
api-ms-win-crt-filesystem-l1-1-0.dll
api-ms-win-crt-heap-l1-1-0.dll
VCRUNTIME140.dll
KERNEL32.dll
.dat
@.dat

Interest's Words
exec

Strings/Hex Code Found With The File Rules
Rule Type Encoding Matched (Word)
Entry Point Hex Pattern Microsoft Visual C++ 8.0 (DLL)
Entry Point Hex Pattern PE-Exe Executable Image
Resources
Path DataRVA Size FileOffset CodeText
\24\1\1033 7060 17D 3460 3C3F786D6C2076657273696F6E3D27312E302720656E636F64696E673D275554462D3827207374616E64616C6F6E653D2779<?xml version=’1.0’ encoding=’UTF-8’ standalone=’y
Intelligent String
• !python.exe
• .bss
• KERNEL32.dll
• api-ms-win-crt-heap-l1-1-0.dll
• api-ms-win-crt-filesystem-l1-1-0.dll
• api-ms-win-crt-runtime-l1-1-0.dll
• api-ms-win-crt-stdio-l1-1-0.dll
• api-ms-win-crt-string-l1-1-0.dll
• api-ms-win-crt-math-l1-1-0.dll
• api-ms-win-crt-locale-l1-1-0.dll

Flow Anomalies
Offset FlowVA Section Description
424 N/A .text CALL QWORD PTR [RIP+0x200E]
477 N/A .text CALL QWORD PTR [RIP+0x2183]
4DE N/A .text CALL QWORD PTR [RIP+0x202C]
4F7 N/A .text CALL QWORD PTR [RIP+0x2133]
508 N/A .text CALL QWORD PTR [RIP+0x2122]
521 N/A .text CALL QWORD PTR [RIP+0x2109]
5B1 N/A .text CALL QWORD PTR [RIP+0x2079]
5C7 N/A .text CALL QWORD PTR [RIP+0x2063]
63C N/A .text CALL QWORD PTR [RIP+0x1ECE]
713 N/A .text CALL QWORD PTR [RIP+0x1D0F]
740 N/A .text CALL QWORD PTR [RIP+0x1CBA]
756 N/A .text CALL QWORD PTR [RIP+0x1CAC]
7E0 N/A .text CALL QWORD PTR [RIP+0x1E22]
880 N/A .text CALL QWORD PTR [RIP+0x1DBA]
90C N/A .text CALL QWORD PTR [RIP+0x1BE6]
94D N/A .text CALL QWORD PTR [RIP+0x1BA5]
9D2 N/A .text CALL QWORD PTR [RIP+0x1B18]
9E2 N/A .text CALL QWORD PTR [RIP+0x1B28]
9FB N/A .text CALL QWORD PTR [RIP+0x1B0F]
A10 N/A .text CALL QWORD PTR [RIP+0x1C22]
A22 N/A .text CALL QWORD PTR [RIP+0x1BE0]
A64 N/A .text CALL QWORD PTR [RIP+0x1AA6]
ACC N/A .text CALL QWORD PTR [RIP+0x1A3E]
BAA N/A .text CALL QWORD PTR [RIP+0x1990]
BB5 N/A .text CALL QWORD PTR [RIP+0x1A4D]
C2D N/A .text CALL QWORD PTR [RIP+0x18DD]
CE7 N/A .text CALL QWORD PTR [RIP+0x1743]
D21 N/A .text CALL QWORD PTR [RIP+0x16F9]
D2E N/A .text CALL QWORD PTR [RIP+0x18D4]
D57 N/A .text CALL QWORD PTR [RIP+0x16B3]
D66 N/A .text CALL QWORD PTR [RIP+0x16AC]
D73 N/A .text CALL QWORD PTR [RIP+0x188F]
E1B N/A .text CALL QWORD PTR [RIP+0x17D7]
1086 N/A .text CALL QWORD PTR [RIP+0x15D4]
115F N/A .text CALL QWORD PTR [RIP+0x12F3]
1168 N/A .text CALL QWORD PTR [RIP+0x12E2]
116E N/A .text CALL QWORD PTR [RIP+0x12EC]
1182 N/A .text JMP QWORD PTR [RIP+0x12E0]
1196 N/A .text CALL QWORD PTR [RIP+0x130C]
1267 N/A .text CALL QWORD PTR [RIP+0x1243]
1281 N/A .text CALL QWORD PTR [RIP+0x11B9]
12B8 N/A .text CALL QWORD PTR [RIP+0x118A]
154C N/A .text CALL QWORD PTR [RIP+0xF36]
155A N/A .text CALL QWORD PTR [RIP+0xF30]
1566 N/A .text CALL QWORD PTR [RIP+0xF2C]
1576 N/A .text CALL QWORD PTR [RIP+0xF24]
15E8 N/A .text JMP QWORD PTR [RIP+0xE92]
165C N/A .text CALL QWORD PTR [RIP+0xE46]
1689 N/A .text CALL QWORD PTR [RIP+0xE21]
16A3 N/A .text CALL QWORD PTR [RIP+0xD97]
16E4 N/A .text CALL QWORD PTR [RIP+0xD5E]
1738 N/A .text CALL QWORD PTR [RIP+0xD3A]
1759 N/A .text CALL QWORD PTR [RIP+0xCF9]
1764 N/A .text CALL QWORD PTR [RIP+0xCE6]
179A N/A .text CALL QWORD PTR [RIP+0xCD0]
17F0 N/A .text JMP QWORD PTR [RIP+0xC62]
1876 N/A .text CALL QWORD PTR [RIP+0xDE4]
18B2 N/A .text CALL QWORD PTR [RIP+0xDA8]
192C N/A .text JMP QWORD PTR [RIP+0xFFF3FF0]
1A90 N/A .text JMP QWORD PTR [RIP+0xA32]
1A96 N/A .text JMP QWORD PTR [RIP+0xA24]
1A9C N/A .text JMP QWORD PTR [RIP+0xA2E]
1AA2 N/A .text JMP QWORD PTR [RIP+0xA30]
1AA8 N/A .text JMP QWORD PTR [RIP+0xADA]
1AAE N/A .text JMP QWORD PTR [RIP+0xAEC]
1AB4 N/A .text JMP QWORD PTR [RIP+0xAEE]
1ABA N/A .text JMP QWORD PTR [RIP+0xAF0]
1AC0 N/A .text JMP QWORD PTR [RIP+0xA6A]
1AC6 N/A .text JMP QWORD PTR [RIP+0xAFC]
1ACC N/A .text JMP QWORD PTR [RIP+0xAEE]
1AD2 N/A .text JMP QWORD PTR [RIP+0xAC0]
1AD8 N/A .text JMP QWORD PTR [RIP+0xADA]
1ADE N/A .text JMP QWORD PTR [RIP+0xAAC]
1AE4 N/A .text JMP QWORD PTR [RIP+0xA96]
1AEA N/A .text JMP QWORD PTR [RIP+0xA88]
1AF0 N/A .text JMP QWORD PTR [RIP+0xAFA]
1AF6 N/A .text JMP QWORD PTR [RIP+0xA64]
1AFC N/A .text JMP QWORD PTR [RIP+0xA6E]
1B02 N/A .text JMP QWORD PTR [RIP+0xAD0]
1B08 N/A .text JMP QWORD PTR [RIP+0xA12]
1B0E N/A .text JMP QWORD PTR [RIP+0x9F4]
1B14 N/A .text JMP QWORD PTR [RIP+0xAFE]
1B1A N/A .text JMP QWORD PTR [RIP+0xA30]
1B20 N/A .text JMP QWORD PTR [RIP+0xA32]
1B26 N/A .text JMP QWORD PTR [RIP+0xAA4]
1B2C N/A .text JMP QWORD PTR [RIP+0xA36]
1B32 N/A .text JMP QWORD PTR [RIP+0xAB0]
1B38 N/A .text JMP QWORD PTR [RIP+0xAD2]
1B3E N/A .text JMP QWORD PTR [RIP+0xADC]
1B44 N/A .text JMP QWORD PTR [RIP+0x996]
1B80 N/A .text JMP QWORD PTR [RIP+0xADA]
21B8 N/A .rdata JMP QWORD PTR [RIP+0x26040000]
3200 140001010 .pdata ExceptionHook | Pointer to 1010 - 0x410 .text + UnwindInfo: .rdata
320C 140001040 .pdata ExceptionHook | Pointer to 1040 - 0x440 .text + UnwindInfo: .rdata
3218 1400010A0 .pdata ExceptionHook | Pointer to 10A0 - 0x4A0 .text + UnwindInfo: .rdata
3224 140001200 .pdata ExceptionHook | Pointer to 1200 - 0x600 .text + UnwindInfo: .rdata
3230 1400012D0 .pdata ExceptionHook | Pointer to 12D0 - 0x6D0 .text + UnwindInfo: .rdata
323C 140001401 .pdata ExceptionHook | Pointer to 1401 - 0x801 .text + UnwindInfo: .rdata
3248 14000164C .pdata ExceptionHook | Pointer to 164C - 0xA4C .text + UnwindInfo: .rdata
3254 14000199A .pdata ExceptionHook | Pointer to 199A - 0xD9A .text + UnwindInfo: .rdata
3260 1400019B2 .pdata ExceptionHook | Pointer to 19B2 - 0xDB2 .text + UnwindInfo: .rdata
326C 1400019D0 .pdata ExceptionHook | Pointer to 19D0 - 0xDD0 .text + UnwindInfo: .rdata
3278 140001A30 .pdata ExceptionHook | Pointer to 1A30 - 0xE30 .text + UnwindInfo: .rdata
3284 140001A50 .pdata ExceptionHook | Pointer to 1A50 - 0xE50 .text + UnwindInfo: .rdata
3290 140001AC0 .pdata ExceptionHook | Pointer to 1AC0 - 0xEC0 .text + UnwindInfo: .rdata
329C 140001AE0 .pdata ExceptionHook | Pointer to 1AE0 - 0xEE0 .text + UnwindInfo: .rdata
32A8 140001B98 .pdata ExceptionHook | Pointer to 1B98 - 0xF98 .text + UnwindInfo: .rdata
32B4 140001BA8 .pdata ExceptionHook | Pointer to 1BA8 - 0xFA8 .text + UnwindInfo: .rdata
32C0 140001BC4 .pdata ExceptionHook | Pointer to 1BC4 - 0xFC4 .text + UnwindInfo: .rdata
32CC 140001D40 .pdata ExceptionHook | Pointer to 1D40 - 0x1140 .text + UnwindInfo: .rdata
32D8 140001D54 .pdata ExceptionHook | Pointer to 1D54 - 0x1154 .text + UnwindInfo: .rdata
32E4 140001D88 .pdata ExceptionHook | Pointer to 1D88 - 0x1188 .text + UnwindInfo: .rdata
32F0 140001E5C .pdata ExceptionHook | Pointer to 1E5C - 0x125C .text + UnwindInfo: .rdata
32FC 140001ED0 .pdata ExceptionHook | Pointer to 1ED0 - 0x12D0 .text + UnwindInfo: .rdata
3308 140001F0C .pdata ExceptionHook | Pointer to 1F0C - 0x130C .text + UnwindInfo: .rdata
3314 140001F58 .pdata ExceptionHook | Pointer to 1F58 - 0x1358 .text + UnwindInfo: .rdata
3320 140001FE4 .pdata ExceptionHook | Pointer to 1FE4 - 0x13E4 .text + UnwindInfo: .rdata
332C 14000207C .pdata ExceptionHook | Pointer to 207C - 0x147C .text + UnwindInfo: .rdata
3338 1400020A0 .pdata ExceptionHook | Pointer to 20A0 - 0x14A0 .text + UnwindInfo: .rdata
3344 1400020CC .pdata ExceptionHook | Pointer to 20CC - 0x14CC .text + UnwindInfo: .rdata
3350 140002108 .pdata ExceptionHook | Pointer to 2108 - 0x1508 .text + UnwindInfo: .rdata
335C 140002120 .pdata ExceptionHook | Pointer to 2120 - 0x1520 .text + UnwindInfo: .rdata
3368 140002200 .pdata ExceptionHook | Pointer to 2200 - 0x1600 .text + UnwindInfo: .rdata
3374 140002240 .pdata ExceptionHook | Pointer to 2240 - 0x1640 .text + UnwindInfo: .rdata
3380 140002394 .pdata ExceptionHook | Pointer to 2394 - 0x1794 .text + UnwindInfo: .rdata
338C 1400023F8 .pdata ExceptionHook | Pointer to 23F8 - 0x17F8 .text + UnwindInfo: .rdata
3398 140002454 .pdata ExceptionHook | Pointer to 2454 - 0x1854 .text + UnwindInfo: .rdata
33A4 140002490 .pdata ExceptionHook | Pointer to 2490 - 0x1890 .text + UnwindInfo: .rdata
33B0 1400024CC .pdata ExceptionHook | Pointer to 24CC - 0x18CC .text + UnwindInfo: .rdata
33BC 140002760 .pdata ExceptionHook | Pointer to 2760 - 0x1B60 .text + UnwindInfo: .rdata
33C8 140002780 .pdata ExceptionHook | Pointer to 2780 - 0x1B80 .text + UnwindInfo: .rdata
33D4 140002786 .pdata ExceptionHook | Pointer to 2786 - 0x1B86 .text + UnwindInfo: .rdata
33E0 1400027A4 .pdata ExceptionHook | Pointer to 27A4 - 0x1BA4 .text + UnwindInfo: .rdata
114D 140001BC4 .text Entry Point Backward Redirect | Score=1/7 - Redirects=1 - PreJumpInstructions=3 - JumpType=JMP_NEAR - TargetOffset=0xFC4 - TargetSection=.text - Confidence=Low
Extra Analysis
Metric Value Percentage
Ascii Code 6928 48,3259%
Null Byte Code 5558 38,7695%
© 2026 All rights reserved.