PREMIUM PESCAN.IO - Analysis Report |
|||||||
| File Structure |
|
PE Chart Code
Header PE (light blue)
Executable sections (pink)
Non-executable sections (black)
External injected code (red)
File Structure in red = malformed or corrupted header
Chart Code For Other Files
Printable characters (blue)
Non-printable characters (black)
| Information |
| Size: 172,00 KB SHA-256 Hash: F154BE4057E821D85890232D3737C28140B396DBA65DB14A0D6B2DB554F1D9A8 SHA-1 Hash: D16B3E76E718FF95BED8AAA0B4AC5DA20CCC62C9 MD5 Hash: 93A268E1AD1505C222182E5A4DD75790 Imphash: B6FE1394CE89E6C21FE5AF76775C6E31 MajorOSVersion: 4 MinorOSVersion: 0 CheckSum: 00000000 EntryPoint (rva): 127CA SizeOfHeaders: 1000 SizeOfImage: 2C000 ImageBase: 10000000 Architecture: x86 ExportTable: 15420 ImportTable: 16000 IAT: 1648C Characteristics: 210E TimeDateStamp: 580BB5F9 Date: 22/10/2016 18:54:49 File Type: DLL Number Of Sections: 5 ASLR: Disabled Section Names: .text, .rdata, .idata, .rsrc, .reloc Number Of Executable Sections: 1 Subsystem: Windows Console |
| Sections Info |
| Section Name | Flags | ROffset | RSize | VOffset | VSize | Entropy | Chi2 |
|---|---|---|---|---|---|---|---|
| .text | 0xE0000020 Code Executable Readable Writeable |
1000 | 12000 | 1000 | 12504 |
|
|
| .rdata | 0x40000040 Initialized Data Readable |
13000 | 2000 | 14000 | 1485 |
|
|
| .idata | 0xC0000040 Initialized Data Readable Writeable |
15000 | 2000 | 16000 | 17B8 |
|
|
| .rsrc | 0x40000040 Initialized Data Readable |
17000 | 12000 | 18000 | 11670 |
|
|
| .reloc | 0x42000040 Initialized Data GP-Relative Readable |
29000 | 2000 | 2A000 | 1078 |
|
|
| Description |
| OriginalFilename: bfsvc.exe CompanyName: Microsoft Corporation LegalCopyright: Microsoft Corporation. All rights reserved. ProductName: Microsoft Windows Operating System FileVersion: 6.1.7601.17514 (win7sp1_rtm.101119-1850) FileDescription: Boot File Servicing Utility ProductVersion: 6.1.7601.17514 |
| Binder/Joiner/Crypter |
| 2 Executable files found |
| Entry Point |
The section number (1) - (.text) have the Entry Point Information -> EntryPoint (calculated) - 127CA Code -> 558BEC538B5D08568B750C578B7D1085F67509833DF034011000EB2683FE01740583FE027522A10035011085C07409575653 Assembler |PUSH EBP |MOV EBP, ESP |PUSH EBX |MOV EBX, DWORD PTR [EBP + 8] |PUSH ESI |MOV ESI, DWORD PTR [EBP + 0XC] |PUSH EDI |MOV EDI, DWORD PTR [EBP + 0X10] |TEST ESI, ESI |JNE 0X101C |CMP DWORD PTR [0X100134F0], 0 |JMP 0X1042 |CMP ESI, 1 |JE 0X1026 |CMP ESI, 2 |JNE 0X1048 |MOV EAX, DWORD PTR [0X10013500] |TEST EAX, EAX |JE 0X1038 |PUSH EDI |PUSH ESI |PUSH EBX |
| Signatures |
| Rich Signature Analyzer: Code -> 6B5C04F32F3D6AA02F3D6AA02F3D6AA0542166A02E3D6AA0AC2164A02C3D6AA0402260A02B3D6AA040226EA02B3D6AA0C72260A0233D6AA02F3D6BA0FC3D6AA0EC3237A0383D6AA0191B61A0203D6AA0E83B6CA02E3D6AA0D01D6EA02E3D6AA0526963682F3D6AA0 Footprint md5 Hash -> 3AF3551C4999E13BA6E5D533F20D038C • The Rich header apparently has not been modified Certificate - Digital Signature Not Found: • The file is not signed |
| Packer/Compiler |
| Compiler: Microsoft Visual Studio Compiler: Microsoft Visual C ++ 6 DLL Detect It Easy (die) • PE: compiler: EP:Microsoft Visual C/C++(6.0 (1720-8966))[DLL32] • PE: compiler: Microsoft Visual C/C++(6.0)[msvcrt] • PE: linker: Microsoft Linker(6.0)[-] • Entropy: 5.94578 |
| Suspicious Functions |
| Library | Function | Description |
|---|---|---|
| KERNEL32.DLL | GetModuleFileNameA | Retrieve the fully qualified path for the executable file of a specified module. |
| KERNEL32.DLL | VirtualAlloc | Reserve, commit, or both, a region of memory within the virtual address space of a process. |
| KERNEL32.DLL | GetModuleHandleA | Retrieves a handle to the specified module. |
| KERNEL32.DLL | CopyFileA | Copies an existing file to a new file. |
| KERNEL32.DLL | WriteFile | Writes data to a specified file or input/output (I/O) device. |
| KERNEL32.DLL | LoadLibraryA | Loads the specified module into the address space of the calling process. |
| KERNEL32.DLL | CreateToolhelp32Snapshot | Creates a snapshot of the specified processes, heaps, threads, and modules. |
| KERNEL32.DLL | GetProcAddress | Retrieves the address of an exported function or variable from the specified dynamic-link library (DLL). |
| KERNEL32.DLL | CreateFileA | Creates or opens a file or I/O device. |
| KERNEL32.DLL | DeleteFileA | Deletes an existing file. |
| ADVAPI32.DLL | RegCreateKeyExA | Creates a new registry key or opens an existing one. |
| ADVAPI32.DLL | RegDeleteKeyA | Used to delete a subkey and its values from the Windows registry. |
| ADVAPI32.DLL | RegSetValueExA | Sets the data and type of a specified value under a registry key. |
| ADVAPI32.DLL | RegDeleteValueA | Removes a named value from the specified registry key. Note that value names are not case sensitive. |
| SHELL32.DLL | ShellExecuteA | Performs a run operation on a specific file. |
| Windows REG |
| SOFTWARE\%d SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost SYSTEM\CurrentControlSet\Services\ |
| Windows REG (UNICODE) |
| System\Setup SYSTEM\CurrentControlSet\Control SYSTEM\CurrentControlSet\Control\Syspart |
| File Access |
| chost.exe rundll32.exe \CMD.EXE VERSION.dll ntdll.dll SHLWAPI.dll SHELL32.dll imagehlp.dll msvcrt.dll KERNEL32.dll ADVAPI32.dll USERENV.dll WTSAPI32.dll MSVCP60.dll WS2_32.dll WININET.dll IMM32.dll USER32.dll GDI32.dll MSIMG32.dll PSAPI.dll NetTemp.ini Temp |
| File Access (UNICODE) |
| bfsvc.exe bootmgr.exe Temp |
| Interest's Words |
| exec attrib start shutdown rundll32 systeminfo ping rundll expand |
| Interest's Words (UNICODE) |
| attrib start ping expand |
| PE Carving |
| Start Offset Header | End Offset | Size (Bytes) |
|---|---|---|
| 0 | 17070 | 17070 |
| 17070 | 2B000 | 13F90 |
| Strings/Hex Code Found With The File Rules |
| Rule Type | Encoding | Matched (Word) |
|---|---|---|
| Text | Ascii | WinAPI Sockets (connect) |
| Text | Ascii | Registry (RegCreateKeyEx) |
| Text | Ascii | Registry (RegOpenKeyEx) |
| Text | Ascii | Registry (RegSetValueEx) |
| Text | Ascii | File (CopyFile) |
| Text | Unicode | File (CopyFile) |
| Text | Ascii | File (CreateFile) |
| Text | Unicode | File (CreateFile) |
| Text | Ascii | File (WriteFile) |
| Text | Ascii | File (ReadFile) |
| Text | Ascii | Service (OpenSCManager) |
| Text | Ascii | Service (CreateService) |
| Text | Ascii | Anti-Analysis VM (GetVersion) |
| Text | Ascii | Anti-Analysis VM (CreateToolhelp32Snapshot) |
| Text | Ascii | Stealth (VirtualAlloc) |
| Text | Ascii | Execution (CreateProcessA) |
| Text | Ascii | Execution (ShellExecute) |
| Text | Ascii | Privileges (SeBackupPrivilege) |
| Text | Unicode | Privileges (SeBackupPrivilege) |
| Text | Ascii | Privileges (SeDebugPrivilege) |
| Text | Unicode | Privileges (SeDebugPrivilege) |
| Text | Ascii | Privileges (SeRestorePrivilege) |
| Text | Unicode | Privileges (SeRestorePrivilege) |
| Text | Unicode | Privileges (SeSecurityPrivilege) |
| Text | Ascii | Privileges (SeShutdownPrivilege) |
| Text | Unicode | Privileges (SeTakeOwnershipPrivilege) |
| Entry Point | Hex Pattern | Armadillov1xxv2xx |
| Entry Point | Hex Pattern | Microsoft Visual C++ 6.0 DLL |
| Entry Point | Hex Pattern | Microsoft Visual C++ 6.0 |
| Entry Point | Hex Pattern | Microsoft Visual C++ v6.0 DLL |
| Entry Point | Hex Pattern | NeoLite v2.0 |
| Resources |
| Path | DataRVA | Size | FileOffset | Code | Text | PE/Payload |
|---|---|---|---|---|---|---|
| \BFSFC\176\1042 | 18070 | 11600 | 17070 | 4D5A90000300000004000000FFFF0000B8000000000000004000000000000000000000000000000000000000000000000000 | MZ......................@......................... | (Executable found) |
| Intelligent String |
| • bfsvc.exe • kernel32.dll • Ws2_32.dll • user32.dll • User32.dll • USER32.dll • DISPLAYGDI32.dll • \CMD.EXE • Kernel32.dll • PSAPI.dll • WININET.dll • Global\Net_%d • rundll32.exe "%s", MerCedesWIN32 Application • chost.exe -k imgsvc%SystemRoot%\System32\sv • c:\heygirl.ddd • ADVAPI32.dll • MSVCRT.dll • WS2_32.dll • |SYSPART|\|DEST|\BOOTSTAT.DAT • |SYSPART|\|DEST|\BCD.LOG • bootmgfw.efi • bootx64.efi • .mui • bootfix.bin • bootmgr.exe • bfsvc.pdb • msvcrt.dll • imagehlp.dll |
| Flow Anomalies |
| Offset | FlowVA | Section | Description |
|---|---|---|---|
| 312D | 10016658 | .text | CALL [static] | Indirect call to absolute memory address |
| 3134 | 10016644 | .text | CALL [static] | Indirect call to absolute memory address |
| 3183 | 10016658 | .text | CALL [static] | Indirect call to absolute memory address |
| 318A | 10016644 | .text | CALL [static] | Indirect call to absolute memory address |
| 31A5 | 1001664C | .text | CALL [static] | Indirect call to absolute memory address |
| 31C3 | 10016658 | .text | CALL [static] | Indirect call to absolute memory address |
| 31CA | 10016644 | .text | CALL [static] | Indirect call to absolute memory address |
| 31DE | 10016648 | .text | CALL [static] | Indirect call to absolute memory address |
| 3263 | 10016658 | .text | CALL [static] | Indirect call to absolute memory address |
| 326A | 10016644 | .text | CALL [static] | Indirect call to absolute memory address |
| 327E | 10016648 | .text | CALL [static] | Indirect call to absolute memory address |
| 32E3 | 100166EC | .text | CALL [static] | Indirect call to absolute memory address |
| 33B0 | 100166E8 | .text | CALL [static] | Indirect call to absolute memory address |
| 34B0 | 100166E8 | .text | CALL [static] | Indirect call to absolute memory address |
| 355F | 10016658 | .text | CALL [static] | Indirect call to absolute memory address |
| 3566 | 10016644 | .text | CALL [static] | Indirect call to absolute memory address |
| 3572 | 10016648 | .text | CALL [static] | Indirect call to absolute memory address |
| 361D | 100167DC | .text | CALL [static] | Indirect call to absolute memory address |
| 362B | 10016640 | .text | CALL [static] | Indirect call to absolute memory address |
| 36EC | 10016638 | .text | CALL [static] | Indirect call to absolute memory address |
| 371A | 100167D8 | .text | CALL [static] | Indirect call to absolute memory address |
| 3785 | 10016634 | .text | CALL [static] | Indirect call to absolute memory address |
| 37B7 | 100167C4 | .text | CALL [static] | Indirect call to absolute memory address |
| 37E9 | 100167EC | .text | CALL [static] | Indirect call to absolute memory address |
| 3820 | 100167CC | .text | CALL [static] | Indirect call to absolute memory address |
| 3844 | 100167D0 | .text | CALL [static] | Indirect call to absolute memory address |
| 38A3 | 10016658 | .text | CALL [static] | Indirect call to absolute memory address |
| 38AA | 10016644 | .text | CALL [static] | Indirect call to absolute memory address |
| 3901 | 100167D4 | .text | CALL [static] | Indirect call to absolute memory address |
| 397F | 100167E0 | .text | CALL [static] | Indirect call to absolute memory address |
| 39B7 | 100167E8 | .text | CALL [static] | Indirect call to absolute memory address |
| 39C8 | 100167F0 | .text | CALL [static] | Indirect call to absolute memory address |
| 39F2 | 100167BC | .text | CALL [static] | Indirect call to absolute memory address |
| 3AB7 | 100167E0 | .text | CALL [static] | Indirect call to absolute memory address |
| 3AED | 100167E8 | .text | CALL [static] | Indirect call to absolute memory address |
| 3B12 | 100167BC | .text | CALL [static] | Indirect call to absolute memory address |
| 3B3D | 100167EC | .text | CALL [static] | Indirect call to absolute memory address |
| 3B72 | 100167C0 | .text | CALL [static] | Indirect call to absolute memory address |
| 3B8D | 100167E0 | .text | CALL [static] | Indirect call to absolute memory address |
| 3BC5 | 100167E8 | .text | CALL [static] | Indirect call to absolute memory address |
| 3BD6 | 100167F0 | .text | CALL [static] | Indirect call to absolute memory address |
| 3C00 | 100167BC | .text | CALL [static] | Indirect call to absolute memory address |
| 3C30 | 100167F0 | .text | CALL [static] | Indirect call to absolute memory address |
| 3CAE | 100167E8 | .text | CALL [static] | Indirect call to absolute memory address |
| 3D39 | 10016638 | .text | CALL [static] | Indirect call to absolute memory address |
| 3F2F | 10016658 | .text | CALL [static] | Indirect call to absolute memory address |
| 3F36 | 10016644 | .text | CALL [static] | Indirect call to absolute memory address |
| 3F64 | 100167E4 | .text | CALL [static] | Indirect call to absolute memory address |
| 3F71 | 10016628 | .text | CALL [static] | Indirect call to absolute memory address |
| 3F89 | 100167F0 | .text | CALL [static] | Indirect call to absolute memory address |
| 3F96 | 1001662C | .text | CALL [static] | Indirect call to absolute memory address |
| 4161 | 100167E0 | .text | CALL [static] | Indirect call to absolute memory address |
| 418E | 10016624 | .text | CALL [static] | Indirect call to absolute memory address |
| 41AB | 100167E0 | .text | CALL [static] | Indirect call to absolute memory address |
| 42E2 | 10016690 | .text | CALL [static] | Indirect call to absolute memory address |
| 43BD | 10016620 | .text | CALL [static] | Indirect call to absolute memory address |
| 44E1 | 10016610 | .text | CALL [static] | Indirect call to absolute memory address |
| 44E9 | 100166CC | .text | CALL [static] | Indirect call to absolute memory address |
| 4501 | 10016630 | .text | CALL [static] | Indirect call to absolute memory address |
| 452D | 100167A4 | .text | CALL [static] | Indirect call to absolute memory address |
| 454B | 100167A4 | .text | CALL [static] | Indirect call to absolute memory address |
| 459C | 10016618 | .text | CALL [static] | Indirect call to absolute memory address |
| 45A6 | 1001661C | .text | CALL [static] | Indirect call to absolute memory address |
| 45C4 | 100167A4 | .text | CALL [static] | Indirect call to absolute memory address |
| 45D9 | 100166D0 | .text | CALL [static] | Indirect call to absolute memory address |
| 4604 | 100166D0 | .text | CALL [static] | Indirect call to absolute memory address |
| 4639 | 10016658 | .text | CALL [static] | Indirect call to absolute memory address |
| 4647 | 10016644 | .text | CALL [static] | Indirect call to absolute memory address |
| 467E | 1001660C | .text | CALL [static] | Indirect call to absolute memory address |
| 46B3 | 100165FC | .text | CALL [static] | Indirect call to absolute memory address |
| 46D7 | 10016658 | .text | CALL [static] | Indirect call to absolute memory address |
| 46E9 | 10016644 | .text | CALL [static] | Indirect call to absolute memory address |
| 4728 | 10016600 | .text | CALL [static] | Indirect call to absolute memory address |
| 4785 | 10016604 | .text | CALL [static] | Indirect call to absolute memory address |
| 47CC | 10016608 | .text | CALL [static] | Indirect call to absolute memory address |
| 4836 | 10016610 | .text | CALL [static] | Indirect call to absolute memory address |
| 484F | 1001660C | .text | CALL [static] | Indirect call to absolute memory address |
| 48A2 | 100165E4 | .text | CALL [static] | Indirect call to absolute memory address |
| 48E2 | 100166C4 | .text | CALL [static] | Indirect call to absolute memory address |
| 48F8 | 100165E8 | .text | CALL [static] | Indirect call to absolute memory address |
| 494D | 100165EC | .text | CALL [static] | Indirect call to absolute memory address |
| 49DC | 10016610 | .text | CALL [static] | Indirect call to absolute memory address |
| 4A2F | 100165F0 | .text | CALL [static] | Indirect call to absolute memory address |
| 4A4B | 100165F4 | .text | CALL [static] | Indirect call to absolute memory address |
| 4A56 | 100165F8 | .text | CALL [static] | Indirect call to absolute memory address |
| 4B19 | 10016658 | .text | CALL [static] | Indirect call to absolute memory address |
| 4B20 | 10016644 | .text | CALL [static] | Indirect call to absolute memory address |
| 4B79 | 100165E8 | .text | CALL [static] | Indirect call to absolute memory address |
| 4BF1 | 100165F0 | .text | CALL [static] | Indirect call to absolute memory address |
| 4BFC | 100165F8 | .text | CALL [static] | Indirect call to absolute memory address |
| 4CAF | 10016658 | .text | CALL [static] | Indirect call to absolute memory address |
| 4CB6 | 10016644 | .text | CALL [static] | Indirect call to absolute memory address |
| 4D1B | 100165E0 | .text | CALL [static] | Indirect call to absolute memory address |
| 4D24 | 1001663C | .text | CALL [static] | Indirect call to absolute memory address |
| 4D2B | 10016610 | .text | CALL [static] | Indirect call to absolute memory address |
| 4D39 | 100165E4 | .text | CALL [static] | Indirect call to absolute memory address |
| 4D67 | 10016610 | .text | CALL [static] | Indirect call to absolute memory address |
| 4D8F | 100165F4 | .text | CALL [static] | Indirect call to absolute memory address |
| 4E3A | 10016658 | .text | CALL [static] | Indirect call to absolute memory address |
| 4E41 | 10016644 | .text | CALL [static] | Indirect call to absolute memory address |
| A427-A446 | N/A | .text | Unusual NOPS Space, count: 32 |
| Extra Analysis |
| Metric | Value | Percentage |
|---|---|---|
| Ascii Code | 90210 | 51,2184% |
| Null Byte Code | 48913 | 27,7713% |
| NOP Cave Found | 0x9090909090 | Block Count: 300 | Total: 0,4258% |
© 2026 All rights reserved.