PREMIUM PESCAN.IO - Analysis Report

File Structure
Analysis Image
PE Chart Code
Header PE (light blue)
Executable sections (pink)
Non-executable sections (black)
External injected code (red)
File Structure in red = malformed or corrupted header

Chart Code For Other Files
Printable characters (blue)
Non-printable characters (black)
Information
Size: 96,50 KB
SHA-256 Hash: 33AA01DCCFFCB3EBB83F6937DCAFF128A09E54D52A037767382E6FD001E10CD1
SHA-1 Hash: E4DEE7680C41A3F8C9B81428EA1AFC3AEC970842
MD5 Hash: 9B8F5CD0C3BFEBEDD82B6EE9B9871616
Imphash: 7435010CA86A7C53ABBCF4946EE6CCD8
MajorOSVersion: 5
MinorOSVersion: 1
CheckSum: 000250EA
EntryPoint (rva): 40D0
SizeOfHeaders: 400
SizeOfImage: 1F000
ImageBase: 10000000
Architecture: x86
ExportTable: 157B0
ImportTable: 14DDC
IAT: 12000
Characteristics: 2102
TimeDateStamp: 688FB2B9
Date: 03/08/2025 19:04:25
File Type: DLL
Number Of Sections: 5
ASLR: Enabled
Section Names: .text, .rdata, .data, .rsrc, .reloc
Number Of Executable Sections: 1
Subsystem: Windows GUI
UAC Execution Level Manifest: asInvoker

Sections Info
Section Name Flags ROffset RSize VOffset VSizeEntropyChi2
.text
0x60000020
Code
Executable
Readable
400 10800 1000 10754
6.6591
340351.02
.rdata
0x40000040
Initialized Data
Readable
10C00 3A00 12000 380C
4.8986
587726.83
.data
0xC0000040
Initialized Data
Readable
Writeable
14600 1C00 16000 5B68
2.9805
875567.36
.rsrc
0x40000040
Initialized Data
Readable
16200 200 1C000 1B4
5.1126
5152
.reloc
0x42000040
Initialized Data
GP-Relative
Readable
16400 1E00 1D000 1D14
3.9845
598013.07
Entry Point
The section number (1) - (.text) have the Entry Point
Information -> EntryPoint (calculated) - 34D0
Code -> B801000000C20C00017505E8AC3C0000FF75088B4D108B550CE8ECFEFFFF595DC20C008BFF558BEC83EC208B450856576A08
Assembler
|MOV EAX, 1
|RET 0XC
|ADD DWORD PTR [EBP + 5], ESI
|CALL 0X4CBC
|PUSH DWORD PTR [EBP + 8]
|MOV ECX, DWORD PTR [EBP + 0X10]
|MOV EDX, DWORD PTR [EBP + 0XC]
|CALL 0XF0A
|POP ECX
|POP EBP
|RET 0XC
|MOV EDI, EDI
|PUSH EBP
|MOV EBP, ESP
|SUB ESP, 0X20
|MOV EAX, DWORD PTR [EBP + 8]
|PUSH ESI
|PUSH EDI
|PUSH 8
Signatures
CheckSum Integrity Problem:
Header: 151786
Calculated: 137369
Rich Signature Analyzer:
Code -> 49436C5C0D22020F0D22020F0D22020F62549C0F1922020F6254A80F8F22020F6254A90F2022020F045A810F0C22020F045A910F0222020F0D22030F9E22020F6254AD0F0022020F6254990F0C22020F62549F0F0C22020F526963680D22020F
Footprint md5 Hash -> 33F0E507EEAA08744F3E97D343B8C6BB
• The Rich header apparently has not been modified
Certificate - Digital Signature Not Found:
• The file is not signed

Packer/Compiler
Detect It Easy (die)
PE: patcher: simple patch(-)[-]
PE: compiler: Microsoft Visual C/C++(2010)[-]
PE: linker: Microsoft Linker(10.0)[-]
Entropy: 6.2475

Suspicious Functions
Library Function Description
KERNEL32.DLL GetModuleFileNameA Retrieve the fully qualified path for the executable file of a specified module.
KERNEL32.DLL VirtualAlloc Reserve, commit, or both, a region of memory within the virtual address space of a process.
KERNEL32.DLL WriteFile Writes data to a specified file or input/output (I/O) device.
KERNEL32.DLL LoadLibraryW Loads the specified module into the address space of the calling process.
KERNEL32.DLL WriteProcessMemory Writes data to an area of memory in a specified process.
KERNEL32.DLL GetProcAddress Retrieves the address of an exported function or variable from the specified dynamic-link library (DLL).
KERNEL32.DLL CreateFileA Creates or opens a file or I/O device.
KERNEL32.DLL IsDebuggerPresent Determines if the calling process is being debugged by a user-mode debugger.
ET Functions (carving)
Original Name -> .dll
fuckyou
run

File Access
Windows\System32\tracerpt.exe
Windows\SysWOW64\tracerpt.exe
.dll
WINMM.dll
WS2_32.dll
ole32.dll
SHELL32.dll
ADVAPI32.dll
KERNEL32.dll

File Access (UNICODE)
1bad allocationCorExitProcessmscoree.dll
KERNEL32.DLL
GetLastActivePopupGetActiveWindowMessageBoxWUSER32.DLL
Temp

Interest's Words
fuck - }:)
PADDINGX
exec
attrib
start

Strings/Hex Code Found With The File Rules
Rule Type Encoding Matched (Word)
Text Ascii Registry (RegOpenKeyEx)
Text Ascii Registry (RegSetValueEx)
Text Ascii File (CreateFile)
Text Ascii File (WriteFile)
Text Ascii File (ReadFile)
Text Ascii Anti-Analysis VM (IsDebuggerPresent)
Text Ascii Stealth (VirtualAlloc)
Text Ascii Execution (CreateProcessA)
Text Ascii Execution (ResumeThread)
Entry Point Hex Pattern FASM v1.3x
Resources
Path DataRVA Size FileOffset CodeText
\24\2\1033 1C058 15A 16258 3C617373656D626C7920786D6C6E733D2275726E3A736368656D61732D6D6963726F736F66742D636F6D3A61736D2E763122<assembly xmlns="urn:schemas-microsoft-com:asm.v1"
Intelligent String
• mscoree.dll
• KERNEL32.DLL
• Windows\SysWOW64\tracerpt.exe
• Windows\System32\tracerpt.exe
• %s\20250606.png
• KERNEL32.dll
• ADVAPI32.dll
• WS2_32.dll

Flow Anomalies
Offset FlowVA Section Description
41B 100120C4 .text CALL [static] | Indirect call to absolute memory address
53F 100120C0 .text CALL [static] | Indirect call to absolute memory address
572 100120C4 .text CALL [static] | Indirect call to absolute memory address
606 100120C0 .text CALL [static] | Indirect call to absolute memory address
635 100120C4 .text CALL [static] | Indirect call to absolute memory address
72A 10012064 .text CALL [static] | Indirect call to absolute memory address
73D 100121A0 .text CALL [static] | Indirect call to absolute memory address
748 1001205C .text CALL [static] | Indirect call to absolute memory address
7AC 100121C4 .text CALL [static] | Indirect call to absolute memory address
7B6 10012068 .text CALL [static] | Indirect call to absolute memory address
7BF 1001205C .text CALL [static] | Indirect call to absolute memory address
7C9 100121B4 .text CALL [static] | Indirect call to absolute memory address
7D3 10012038 .text CALL [static] | Indirect call to absolute memory address
80B 10012060 .text CALL [static] | Indirect call to absolute memory address
817 1001205C .text CALL [static] | Indirect call to absolute memory address
81D 10012190 .text CALL [static] | Indirect call to absolute memory address
84A 100121B0 .text CALL [static] | Indirect call to absolute memory address
876 10012058 .text CALL [static] | Indirect call to absolute memory address
882 10012054 .text CALL [static] | Indirect call to absolute memory address
8A1 10012058 .text CALL [static] | Indirect call to absolute memory address
8AD 10012054 .text CALL [static] | Indirect call to absolute memory address
8BB 100121B8 .text CALL [static] | Indirect call to absolute memory address
8DD 100121A4 .text CALL [static] | Indirect call to absolute memory address
8FB 1001219C .text CALL [static] | Indirect call to absolute memory address
9BC 10012198 .text CALL [static] | Indirect call to absolute memory address
9C7 1001205C .text CALL [static] | Indirect call to absolute memory address
A93 100121C0 .text CALL [static] | Indirect call to absolute memory address
B74 10012190 .text CALL [static] | Indirect call to absolute memory address
BBB 1001204C .text CALL [static] | Indirect call to absolute memory address
BD3 1001205C .text CALL [static] | Indirect call to absolute memory address
C7F 1001204C .text CALL [static] | Indirect call to absolute memory address
CE1 100121BC .text CALL [static] | Indirect call to absolute memory address
D1E 100121BC .text CALL [static] | Indirect call to absolute memory address
D76 1001205C .text CALL [static] | Indirect call to absolute memory address
E73 10012190 .text CALL [static] | Indirect call to absolute memory address
1042 10012004 .text CALL [static] | Indirect call to absolute memory address
1052 10012008 .text CALL [static] | Indirect call to absolute memory address
1070 10012014 .text CALL [static] | Indirect call to absolute memory address
107B 10012000 .text CALL [static] | Indirect call to absolute memory address
10DB 1001207C .text CALL [static] | Indirect call to absolute memory address
10F4 1001203C .text CALL [static] | Indirect call to absolute memory address
10FC 1001975C .text CALL [static] | Indirect call to absolute memory address
11C7 10012004 .text CALL [static] | Indirect call to absolute memory address
1246 100120C0 .text CALL [static] | Indirect call to absolute memory address
1271 10012000 .text CALL [static] | Indirect call to absolute memory address
12C5 100120C4 .text CALL [static] | Indirect call to absolute memory address
13E6 100120C0 .text CALL [static] | Indirect call to absolute memory address
1459 10012010 .text CALL [static] | Indirect call to absolute memory address
146C 10012008 .text CALL [static] | Indirect call to absolute memory address
1484 10012014 .text CALL [static] | Indirect call to absolute memory address
148E 10012000 .text CALL [static] | Indirect call to absolute memory address
14BE 1001203C .text CALL [static] | Indirect call to absolute memory address
1571 10012084 .text CALL [static] | Indirect call to absolute memory address
15A0 10012078 .text CALL [static] | Indirect call to absolute memory address
15E8 10012080 .text CALL [static] | Indirect call to absolute memory address
160E 10012088 .text CALL [static] | Indirect call to absolute memory address
1628 1001208C .text CALL [static] | Indirect call to absolute memory address
1647 1001206C .text CALL [static] | Indirect call to absolute memory address
1662 10012070 .text CALL [static] | Indirect call to absolute memory address
1681 10012090 .text CALL [static] | Indirect call to absolute memory address
1B31 10012004 .text CALL [static] | Indirect call to absolute memory address
1C8C 1001203C .text CALL [static] | Indirect call to absolute memory address
1DE7 1001203C .text CALL [static] | Indirect call to absolute memory address
1E33 10012040 .text CALL [static] | Indirect call to absolute memory address
1E79 10012034 .text CALL [static] | Indirect call to absolute memory address
1EDD 100120A0 .text CALL [static] | Indirect call to absolute memory address
1EEB 10012034 .text CALL [static] | Indirect call to absolute memory address
1EF7 10012048 .text CALL [static] | Indirect call to absolute memory address
1F0D 100121CC .text CALL [static] | Indirect call to absolute memory address
1F39 10012188 .text CALL [static] | Indirect call to absolute memory address
1F57 10012054 .text CALL [static] | Indirect call to absolute memory address
1F61 100121D0 .text CALL [static] | Indirect call to absolute memory address
1F71 100121D4 .text CALL [static] | Indirect call to absolute memory address
2020 10012098 .text CALL [static] | Indirect call to absolute memory address
2043 1001203C .text CALL [static] | Indirect call to absolute memory address
2054 10012094 .text CALL [static] | Indirect call to absolute memory address
205A 1001209C .text CALL [static] | Indirect call to absolute memory address
2066 10012094 .text CALL [static] | Indirect call to absolute memory address
2080 100120A0 .text CALL [static] | Indirect call to absolute memory address
208E 10012034 .text CALL [static] | Indirect call to absolute memory address
26EF 100120B0 .text CALL [static] | Indirect call to absolute memory address
2701 10012044 .text CALL [static] | Indirect call to absolute memory address
2758 100120BC .text CALL [static] | Indirect call to absolute memory address
2960 10012130 .text CALL [static] | Indirect call to absolute memory address
29D5 10012044 .text CALL [static] | Indirect call to absolute memory address
29DC 10012130 .text CALL [static] | Indirect call to absolute memory address
29E2 1001204C .text CALL [static] | Indirect call to absolute memory address
2A82 100120A0 .text CALL [static] | Indirect call to absolute memory address
2A8C 10012044 .text CALL [static] | Indirect call to absolute memory address
2B3F 10012138 .text CALL [static] | Indirect call to absolute memory address
2B7F 10012138 .text CALL [static] | Indirect call to absolute memory address
2FBA 10012140 .text CALL [static] | Indirect call to absolute memory address
2FCA 1001213C .text CALL [static] | Indirect call to absolute memory address
2FEC 10012094 .text CALL [static] | Indirect call to absolute memory address
307C 10012FAC .text CALL [static] | Indirect call to absolute memory address
30E9 1001BB64 .text CALL [static] | Indirect call to absolute memory address
32AF 10012144 .text CALL [static] | Indirect call to absolute memory address
3394 10012134 .text CALL [static] | Indirect call to absolute memory address
33A9 1001204C .text CALL [static] | Indirect call to absolute memory address
3535 10012148 .text CALL [static] | Indirect call to absolute memory address
Extra Analysis
Metric Value Percentage
Ascii Code 52515 53,1442%
Null Byte Code 21843 22,1047%
© 2026 All rights reserved.