PESCAN.IO - Analysis Report Basic

File Structure
Analysis Image
PE Chart Code
Header PE (light blue)
Executable sections (pink)
Non-executable sections (black)
External injected code (red)
File Structure in red = malformed or corrupted header

Chart Code For Other Files
Printable characters (blue)
Non-printable characters (black)
Information
Icon: Icon
Size: 979,50 KB
SHA-256 Hash: 31BA43AAA890C727DAFEC9FF1B88358E057D3E9E70340CA31D9AD9F8E040E883
SHA-1 Hash: DBF50B5D6368E872CCB59ACF8F7F177161A7936E
MD5 Hash: 96D6AEAD26FB94F2F8874EDCA09EB8EC
Imphash: F34D5F2D4577ED6D9CEEC516C1F5A744
MajorOSVersion: 4
MinorOSVersion: 0
CheckSum: 00000000
EntryPoint (rva): F451A
SizeOfHeaders: 200
SizeOfImage: FC000
ImageBase: 400000
Architecture: x86
ImportTable: F44C8
IAT: 2000
Characteristics: 22
TimeDateStamp: 6363E7A9
Date: 03/11/2022 16:09:13
File Type: EXE
Number Of Sections: 3
ASLR: Disabled
Section Names: .text, .rsrc, .reloc
Number Of Executable Sections: 1
Subsystem: Windows GUI
UAC Execution Level Manifest: asInvoker

Sections Info
Section Name Flags ROffset RSize VOffset VSizeEntropyChi2
.text
0x60000020
Code
Executable
Readable
200 F2600 2000 F25E0
5.6657
12085451.7
.rsrc
0x40000040
Initialized Data
Readable
F2800 2400 F6000 23F8
4.702
217798.94
.reloc
0x42000040
Initialized Data
GP-Relative
Readable
F4C00 200 FA000 C
0.1019
128015
Description
LegalCopyright: Copyright fox1001 (mod tompsongun A @07@5H5=8O fox1001)
FileVersion: 2.2.2.0
ProductVersion: 2.2.2.0
Language: Unknown (ID=0x0)
CodePage: Unicode (UTF-16 LE) (0x4B0)
Unusual Chars Found In Description File - (Polymorphic patterns or unicode characters)

Entry Point
The section number (1) - (.text) have the Entry Point
Information -> EntryPoint (calculated) - F271A
Code -> FF2500204000F2000000F2000000F2000000DB000000EE000000F3000000B6000000DD000000E800000093000000CD000000
Assembler
|JMP DWORD PTR [0X402000]
|ADD BYTE PTR [EAX], AL
|ADD DL, DH
|ADD BYTE PTR [EAX], AL
|ADD DL, DH
|ADD BYTE PTR [EAX], AL
|ADD BL, BL
|ADD BYTE PTR [EAX], AL
|ADD DH, CH
|ADD BYTE PTR [EAX], AL
|ADD BL, DH
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [ESI - 0X23000000], DH
|ADD BYTE PTR [EAX], AL
|ADD AL, CH
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EBX - 0X33000000], DL
|ADD BYTE PTR [EAX], AL
Signatures
Certificate - Digital Signature Not Found:
• The file is not signed

Packer/Compiler
Compiler: Microsoft Visual .NET - (You can use a decompiler for this...)
• AnyCPU: False
• Version: v4.0
Compiler: Microsoft Visual Studio
Detect It Easy (die)
• PE: library: .NET(v4.0.30319)[-]
• PE: compiler: VB.NET(-)[-]
• PE: linker: Microsoft Linker(80.0)[-]
• Entropy: 5.67427

File Access
.exe
mscoree.dll
Temp

Interest's Words
exec
attrib
start
shutdown
expand
replace

Interest's Words (UNICODE)
expand
replace

URLs
http://www.w3.org/2001/XMLSchema-instance
https://yoomoney.ru/to/4100174421236

IP Addresses
11.0.0.0
12.0.0.0

Strings/Hex Code Found With The File Rules
Rule Type Encoding Matched (Word)
Text Ascii Keyboard Key (LBUTTON)
Text Ascii Keyboard Key (Scroll)
Entry Point Hex Pattern Microsoft Visual C++ 8
Resources
Path DataRVA Size FileOffset CodeText
\ICON\1\0 F6100 10A8 F2900 280000002000000040000000010020000000000000100000C30E0000C30E000000000000000000000000FFFF0000FFFF0000(... ...@..... ...................................
\GROUP_ICON\32512\0 F71B8 14 F39B8 0000010001002020000001002000A81000000100...... .... .......
\VERSION\1\0 F71DC 3E0 F39DC E00334000000560053005F00560045005200530049004F004E005F0049004E0046004F0000000000BD04EFFE000001000200..4...V.S._.V.E.R.S.I.O.N._.I.N.F.O...............
\24\1\0 F75CC E26 F3DCC EFBBBF3C3F786D6C2076657273696F6E3D22312E302220656E636F64696E673D227574662D38223F3E0D0A3C61736D76313A...<?xml version="1.0" encoding="utf-8"?>..<asmv1:
Intelligent String
• .exe
• 2.2.2.0
• .xml
• : https://yoomoney.ru/to/4100174421236
• .pdb
• _CorExeMainmscoree.dll
• 1.0.1.3
• <asmv1:assembly manifestVersion="1.0" xmlns="urn:schemas-microsoft-com:asm.v1" xmlns:asmv1="urn:schemas-microsoft-com:asm.v1" xmlns:asmv2="urn:schemas-microsoft-com:asm.v2" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance">

Flow Anomalies
Offset FlowVA Section Description
2B87C F75CC .text JMP [static] | Indirect jump to absolute memory address
F271A 402000 .text JMP [static] | Indirect jump to absolute memory address
Extra Analysis
Metric Value Percentage
Ascii Code 791266 78,8893%
Null Byte Code 52757 5,2599%
© 2026 All rights reserved.