PREMIUM PESCAN.IO - Analysis Report

File Structure
Analysis Image
PE Chart Code
Header PE (light blue)
Executable sections (pink)
Non-executable sections (black)
External injected code (red)
File Structure in red = malformed or corrupted header

Chart Code For Other Files
Printable characters (blue)
Non-printable characters (black)
Information
Size: 172,00 KB
SHA-256 Hash: F154BE4057E821D85890232D3737C28140B396DBA65DB14A0D6B2DB554F1D9A8
SHA-1 Hash: D16B3E76E718FF95BED8AAA0B4AC5DA20CCC62C9
MD5 Hash: 93A268E1AD1505C222182E5A4DD75790
Imphash: B6FE1394CE89E6C21FE5AF76775C6E31
MajorOSVersion: 4
MinorOSVersion: 0
CheckSum: 00000000
EntryPoint (rva): 127CA
SizeOfHeaders: 1000
SizeOfImage: 2C000
ImageBase: 10000000
Architecture: x86
ExportTable: 15420
ImportTable: 16000
IAT: 1648C
Characteristics: 210E
TimeDateStamp: 580BB5F9
Date: 22/10/2016 18:54:49
File Type: DLL
Number Of Sections: 5
ASLR: Disabled
Section Names: .text, .rdata, .idata, .rsrc, .reloc
Number Of Executable Sections: 1
Subsystem: Windows Console

Sections Info
Section Name Flags ROffset RSize VOffset VSizeEntropyChi2
.text
0xE0000020
Code
Executable
Readable
Writeable
1000 12000 1000 12504
6.3763
631153.49
.rdata
0x40000040
Initialized Data
Readable
13000 2000 14000 1485
2.9233
936110.88
.idata
0xC0000040
Initialized Data
Readable
Writeable
15000 2000 16000 17B8
4.5
339709.56
.rsrc
0x40000040
Initialized Data
Readable
17000 12000 18000 11670
5.8984
1405691.34
.reloc
0x42000040
Initialized Data
GP-Relative
Readable
29000 2000 2A000 1078
3.4607
828263.56
Description
OriginalFilename: bfsvc.exe
CompanyName: Microsoft Corporation
LegalCopyright: Microsoft Corporation. All rights reserved.
ProductName: Microsoft Windows Operating System
FileVersion: 6.1.7601.17514 (win7sp1_rtm.101119-1850)
FileDescription: Boot File Servicing Utility
ProductVersion: 6.1.7601.17514

Binder/Joiner/Crypter
2 Executable files found

Entry Point
The section number (1) - (.text) have the Entry Point
Information -> EntryPoint (calculated) - 127CA
Code -> 558BEC538B5D08568B750C578B7D1085F67509833DF034011000EB2683FE01740583FE027522A10035011085C07409575653
Assembler
|PUSH EBP
|MOV EBP, ESP
|PUSH EBX
|MOV EBX, DWORD PTR [EBP + 8]
|PUSH ESI
|MOV ESI, DWORD PTR [EBP + 0XC]
|PUSH EDI
|MOV EDI, DWORD PTR [EBP + 0X10]
|TEST ESI, ESI
|JNE 0X101C
|CMP DWORD PTR [0X100134F0], 0
|JMP 0X1042
|CMP ESI, 1
|JE 0X1026
|CMP ESI, 2
|JNE 0X1048
|MOV EAX, DWORD PTR [0X10013500]
|TEST EAX, EAX
|JE 0X1038
|PUSH EDI
|PUSH ESI
|PUSH EBX
Signatures
Rich Signature Analyzer:
Code -> 6B5C04F32F3D6AA02F3D6AA02F3D6AA0542166A02E3D6AA0AC2164A02C3D6AA0402260A02B3D6AA040226EA02B3D6AA0C72260A0233D6AA02F3D6BA0FC3D6AA0EC3237A0383D6AA0191B61A0203D6AA0E83B6CA02E3D6AA0D01D6EA02E3D6AA0526963682F3D6AA0
Footprint md5 Hash -> 3AF3551C4999E13BA6E5D533F20D038C
• The Rich header apparently has not been modified
Certificate - Digital Signature Not Found:
• The file is not signed

Packer/Compiler
Compiler: Microsoft Visual Studio
Compiler: Microsoft Visual C ++ 6 DLL
Detect It Easy (die)
PE: compiler: EP:Microsoft Visual C/C++(6.0 (1720-8966))[DLL32]
PE: compiler: Microsoft Visual C/C++(6.0)[msvcrt]
PE: linker: Microsoft Linker(6.0)[-]
Entropy: 5.94578

Suspicious Functions
Library Function Description
KERNEL32.DLL GetModuleFileNameA Retrieve the fully qualified path for the executable file of a specified module.
KERNEL32.DLL VirtualAlloc Reserve, commit, or both, a region of memory within the virtual address space of a process.
KERNEL32.DLL GetModuleHandleA Retrieves a handle to the specified module.
KERNEL32.DLL CopyFileA Copies an existing file to a new file.
KERNEL32.DLL WriteFile Writes data to a specified file or input/output (I/O) device.
KERNEL32.DLL LoadLibraryA Loads the specified module into the address space of the calling process.
KERNEL32.DLL CreateToolhelp32Snapshot Creates a snapshot of the specified processes, heaps, threads, and modules.
KERNEL32.DLL GetProcAddress Retrieves the address of an exported function or variable from the specified dynamic-link library (DLL).
KERNEL32.DLL CreateFileA Creates or opens a file or I/O device.
KERNEL32.DLL DeleteFileA Deletes an existing file.
ADVAPI32.DLL RegCreateKeyExA Creates a new registry key or opens an existing one.
ADVAPI32.DLL RegDeleteKeyA Used to delete a subkey and its values from the Windows registry.
ADVAPI32.DLL RegSetValueExA Sets the data and type of a specified value under a registry key.
ADVAPI32.DLL RegDeleteValueA Removes a named value from the specified registry key. Note that value names are not case sensitive.
SHELL32.DLL ShellExecuteA Performs a run operation on a specific file.
Windows REG
SOFTWARE\%d
SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost
SYSTEM\CurrentControlSet\Services\

Windows REG (UNICODE)
System\Setup
SYSTEM\CurrentControlSet\Control
SYSTEM\CurrentControlSet\Control\Syspart

File Access
chost.exe
rundll32.exe
\CMD.EXE
VERSION.dll
ntdll.dll
SHLWAPI.dll
SHELL32.dll
imagehlp.dll
msvcrt.dll
KERNEL32.dll
ADVAPI32.dll
USERENV.dll
WTSAPI32.dll
MSVCP60.dll
WS2_32.dll
WININET.dll
IMM32.dll
USER32.dll
GDI32.dll
MSIMG32.dll
PSAPI.dll
NetTemp.ini
Temp

File Access (UNICODE)
bfsvc.exe
bootmgr.exe
Temp

Interest's Words
exec
attrib
start
shutdown
rundll32
systeminfo
ping
rundll
expand

Interest's Words (UNICODE)
attrib
start
ping
expand

PE Carving
Start Offset Header End Offset Size (Bytes)
0 17070 17070
17070 2B000 13F90
Strings/Hex Code Found With The File Rules
Rule Type Encoding Matched (Word)
Text Ascii WinAPI Sockets (connect)
Text Ascii Registry (RegCreateKeyEx)
Text Ascii Registry (RegOpenKeyEx)
Text Ascii Registry (RegSetValueEx)
Text Ascii File (CopyFile)
Text Unicode File (CopyFile)
Text Ascii File (CreateFile)
Text Unicode File (CreateFile)
Text Ascii File (WriteFile)
Text Ascii File (ReadFile)
Text Ascii Service (OpenSCManager)
Text Ascii Service (CreateService)
Text Ascii Anti-Analysis VM (GetVersion)
Text Ascii Anti-Analysis VM (CreateToolhelp32Snapshot)
Text Ascii Stealth (VirtualAlloc)
Text Ascii Execution (CreateProcessA)
Text Ascii Execution (ShellExecute)
Text Ascii Privileges (SeBackupPrivilege)
Text Unicode Privileges (SeBackupPrivilege)
Text Ascii Privileges (SeDebugPrivilege)
Text Unicode Privileges (SeDebugPrivilege)
Text Ascii Privileges (SeRestorePrivilege)
Text Unicode Privileges (SeRestorePrivilege)
Text Unicode Privileges (SeSecurityPrivilege)
Text Ascii Privileges (SeShutdownPrivilege)
Text Unicode Privileges (SeTakeOwnershipPrivilege)
Entry Point Hex Pattern Armadillov1xxv2xx
Entry Point Hex Pattern Microsoft Visual C++ 6.0 DLL
Entry Point Hex Pattern Microsoft Visual C++ 6.0
Entry Point Hex Pattern Microsoft Visual C++ v6.0 DLL
Entry Point Hex Pattern NeoLite v2.0
Resources
Path DataRVA Size FileOffset CodeTextPE/Payload
\BFSFC\176\1042 18070 11600 17070 4D5A90000300000004000000FFFF0000B8000000000000004000000000000000000000000000000000000000000000000000MZ......................@.........................(Executable found)
Intelligent String
• bfsvc.exe
• kernel32.dll
• Ws2_32.dll
• user32.dll
• User32.dll
• USER32.dll
• DISPLAYGDI32.dll
• \CMD.EXE
• Kernel32.dll
• PSAPI.dll
• WININET.dll
• Global\Net_%d
• rundll32.exe "%s", MerCedesWIN32 Application
• chost.exe -k imgsvc%SystemRoot%\System32\sv
• c:\heygirl.ddd
• ADVAPI32.dll
• MSVCRT.dll
• WS2_32.dll
• |SYSPART|\|DEST|\BOOTSTAT.DAT
• |SYSPART|\|DEST|\BCD.LOG
• bootmgfw.efi
• bootx64.efi
• .mui
• bootfix.bin
• bootmgr.exe
• bfsvc.pdb
• msvcrt.dll
• imagehlp.dll

Flow Anomalies
Offset FlowVA Section Description
312D 10016658 .text CALL [static] | Indirect call to absolute memory address
3134 10016644 .text CALL [static] | Indirect call to absolute memory address
3183 10016658 .text CALL [static] | Indirect call to absolute memory address
318A 10016644 .text CALL [static] | Indirect call to absolute memory address
31A5 1001664C .text CALL [static] | Indirect call to absolute memory address
31C3 10016658 .text CALL [static] | Indirect call to absolute memory address
31CA 10016644 .text CALL [static] | Indirect call to absolute memory address
31DE 10016648 .text CALL [static] | Indirect call to absolute memory address
3263 10016658 .text CALL [static] | Indirect call to absolute memory address
326A 10016644 .text CALL [static] | Indirect call to absolute memory address
327E 10016648 .text CALL [static] | Indirect call to absolute memory address
32E3 100166EC .text CALL [static] | Indirect call to absolute memory address
33B0 100166E8 .text CALL [static] | Indirect call to absolute memory address
34B0 100166E8 .text CALL [static] | Indirect call to absolute memory address
355F 10016658 .text CALL [static] | Indirect call to absolute memory address
3566 10016644 .text CALL [static] | Indirect call to absolute memory address
3572 10016648 .text CALL [static] | Indirect call to absolute memory address
361D 100167DC .text CALL [static] | Indirect call to absolute memory address
362B 10016640 .text CALL [static] | Indirect call to absolute memory address
36EC 10016638 .text CALL [static] | Indirect call to absolute memory address
371A 100167D8 .text CALL [static] | Indirect call to absolute memory address
3785 10016634 .text CALL [static] | Indirect call to absolute memory address
37B7 100167C4 .text CALL [static] | Indirect call to absolute memory address
37E9 100167EC .text CALL [static] | Indirect call to absolute memory address
3820 100167CC .text CALL [static] | Indirect call to absolute memory address
3844 100167D0 .text CALL [static] | Indirect call to absolute memory address
38A3 10016658 .text CALL [static] | Indirect call to absolute memory address
38AA 10016644 .text CALL [static] | Indirect call to absolute memory address
3901 100167D4 .text CALL [static] | Indirect call to absolute memory address
397F 100167E0 .text CALL [static] | Indirect call to absolute memory address
39B7 100167E8 .text CALL [static] | Indirect call to absolute memory address
39C8 100167F0 .text CALL [static] | Indirect call to absolute memory address
39F2 100167BC .text CALL [static] | Indirect call to absolute memory address
3AB7 100167E0 .text CALL [static] | Indirect call to absolute memory address
3AED 100167E8 .text CALL [static] | Indirect call to absolute memory address
3B12 100167BC .text CALL [static] | Indirect call to absolute memory address
3B3D 100167EC .text CALL [static] | Indirect call to absolute memory address
3B72 100167C0 .text CALL [static] | Indirect call to absolute memory address
3B8D 100167E0 .text CALL [static] | Indirect call to absolute memory address
3BC5 100167E8 .text CALL [static] | Indirect call to absolute memory address
3BD6 100167F0 .text CALL [static] | Indirect call to absolute memory address
3C00 100167BC .text CALL [static] | Indirect call to absolute memory address
3C30 100167F0 .text CALL [static] | Indirect call to absolute memory address
3CAE 100167E8 .text CALL [static] | Indirect call to absolute memory address
3D39 10016638 .text CALL [static] | Indirect call to absolute memory address
3F2F 10016658 .text CALL [static] | Indirect call to absolute memory address
3F36 10016644 .text CALL [static] | Indirect call to absolute memory address
3F64 100167E4 .text CALL [static] | Indirect call to absolute memory address
3F71 10016628 .text CALL [static] | Indirect call to absolute memory address
3F89 100167F0 .text CALL [static] | Indirect call to absolute memory address
3F96 1001662C .text CALL [static] | Indirect call to absolute memory address
4161 100167E0 .text CALL [static] | Indirect call to absolute memory address
418E 10016624 .text CALL [static] | Indirect call to absolute memory address
41AB 100167E0 .text CALL [static] | Indirect call to absolute memory address
42E2 10016690 .text CALL [static] | Indirect call to absolute memory address
43BD 10016620 .text CALL [static] | Indirect call to absolute memory address
44E1 10016610 .text CALL [static] | Indirect call to absolute memory address
44E9 100166CC .text CALL [static] | Indirect call to absolute memory address
4501 10016630 .text CALL [static] | Indirect call to absolute memory address
452D 100167A4 .text CALL [static] | Indirect call to absolute memory address
454B 100167A4 .text CALL [static] | Indirect call to absolute memory address
459C 10016618 .text CALL [static] | Indirect call to absolute memory address
45A6 1001661C .text CALL [static] | Indirect call to absolute memory address
45C4 100167A4 .text CALL [static] | Indirect call to absolute memory address
45D9 100166D0 .text CALL [static] | Indirect call to absolute memory address
4604 100166D0 .text CALL [static] | Indirect call to absolute memory address
4639 10016658 .text CALL [static] | Indirect call to absolute memory address
4647 10016644 .text CALL [static] | Indirect call to absolute memory address
467E 1001660C .text CALL [static] | Indirect call to absolute memory address
46B3 100165FC .text CALL [static] | Indirect call to absolute memory address
46D7 10016658 .text CALL [static] | Indirect call to absolute memory address
46E9 10016644 .text CALL [static] | Indirect call to absolute memory address
4728 10016600 .text CALL [static] | Indirect call to absolute memory address
4785 10016604 .text CALL [static] | Indirect call to absolute memory address
47CC 10016608 .text CALL [static] | Indirect call to absolute memory address
4836 10016610 .text CALL [static] | Indirect call to absolute memory address
484F 1001660C .text CALL [static] | Indirect call to absolute memory address
48A2 100165E4 .text CALL [static] | Indirect call to absolute memory address
48E2 100166C4 .text CALL [static] | Indirect call to absolute memory address
48F8 100165E8 .text CALL [static] | Indirect call to absolute memory address
494D 100165EC .text CALL [static] | Indirect call to absolute memory address
49DC 10016610 .text CALL [static] | Indirect call to absolute memory address
4A2F 100165F0 .text CALL [static] | Indirect call to absolute memory address
4A4B 100165F4 .text CALL [static] | Indirect call to absolute memory address
4A56 100165F8 .text CALL [static] | Indirect call to absolute memory address
4B19 10016658 .text CALL [static] | Indirect call to absolute memory address
4B20 10016644 .text CALL [static] | Indirect call to absolute memory address
4B79 100165E8 .text CALL [static] | Indirect call to absolute memory address
4BF1 100165F0 .text CALL [static] | Indirect call to absolute memory address
4BFC 100165F8 .text CALL [static] | Indirect call to absolute memory address
4CAF 10016658 .text CALL [static] | Indirect call to absolute memory address
4CB6 10016644 .text CALL [static] | Indirect call to absolute memory address
4D1B 100165E0 .text CALL [static] | Indirect call to absolute memory address
4D24 1001663C .text CALL [static] | Indirect call to absolute memory address
4D2B 10016610 .text CALL [static] | Indirect call to absolute memory address
4D39 100165E4 .text CALL [static] | Indirect call to absolute memory address
4D67 10016610 .text CALL [static] | Indirect call to absolute memory address
4D8F 100165F4 .text CALL [static] | Indirect call to absolute memory address
4E3A 10016658 .text CALL [static] | Indirect call to absolute memory address
4E41 10016644 .text CALL [static] | Indirect call to absolute memory address
A427-A446 N/A .text Unusual NOPS Space, count: 32
Extra Analysis
Metric Value Percentage
Ascii Code 90210 51,2184%
Null Byte Code 48913 27,7713%
NOP Cave Found 0x9090909090 Block Count: 300 | Total: 0,4258%
© 2026 All rights reserved.