PREMIUM PESCAN.IO - Analysis Report |
|||||||
| File Structure |
|
PE Chart Code
Header PE (light blue)
Executable sections (pink)
Non-executable sections (black)
External injected code (red)
File Structure in red = malformed or corrupted header
Chart Code For Other Files
Printable characters (blue)
Non-printable characters (black)
| Information |
| Size: 96,50 KB SHA-256 Hash: 33AA01DCCFFCB3EBB83F6937DCAFF128A09E54D52A037767382E6FD001E10CD1 SHA-1 Hash: E4DEE7680C41A3F8C9B81428EA1AFC3AEC970842 MD5 Hash: 9B8F5CD0C3BFEBEDD82B6EE9B9871616 Imphash: 7435010CA86A7C53ABBCF4946EE6CCD8 MajorOSVersion: 5 MinorOSVersion: 1 CheckSum: 000250EA EntryPoint (rva): 40D0 SizeOfHeaders: 400 SizeOfImage: 1F000 ImageBase: 10000000 Architecture: x86 ExportTable: 157B0 ImportTable: 14DDC IAT: 12000 Characteristics: 2102 TimeDateStamp: 688FB2B9 Date: 03/08/2025 19:04:25 File Type: DLL Number Of Sections: 5 ASLR: Enabled Section Names: .text, .rdata, .data, .rsrc, .reloc Number Of Executable Sections: 1 Subsystem: Windows GUI UAC Execution Level Manifest: asInvoker |
| Sections Info |
| Section Name | Flags | ROffset | RSize | VOffset | VSize | Entropy | Chi2 |
|---|---|---|---|---|---|---|---|
| .text | 0x60000020 Code Executable Readable |
400 | 10800 | 1000 | 10754 |
|
|
| .rdata | 0x40000040 Initialized Data Readable |
10C00 | 3A00 | 12000 | 380C |
|
|
| .data | 0xC0000040 Initialized Data Readable Writeable |
14600 | 1C00 | 16000 | 5B68 |
|
|
| .rsrc | 0x40000040 Initialized Data Readable |
16200 | 200 | 1C000 | 1B4 |
|
|
| .reloc | 0x42000040 Initialized Data GP-Relative Readable |
16400 | 1E00 | 1D000 | 1D14 |
|
|
| Entry Point |
The section number (1) - (.text) have the Entry Point Information -> EntryPoint (calculated) - 34D0 Code -> B801000000C20C00017505E8AC3C0000FF75088B4D108B550CE8ECFEFFFF595DC20C008BFF558BEC83EC208B450856576A08 Assembler |MOV EAX, 1 |RET 0XC |ADD DWORD PTR [EBP + 5], ESI |CALL 0X4CBC |PUSH DWORD PTR [EBP + 8] |MOV ECX, DWORD PTR [EBP + 0X10] |MOV EDX, DWORD PTR [EBP + 0XC] |CALL 0XF0A |POP ECX |POP EBP |RET 0XC |MOV EDI, EDI |PUSH EBP |MOV EBP, ESP |SUB ESP, 0X20 |MOV EAX, DWORD PTR [EBP + 8] |PUSH ESI |PUSH EDI |PUSH 8 |
| Signatures |
| CheckSum Integrity Problem: • Header: 151786 • Calculated: 137369 Rich Signature Analyzer: Code -> 49436C5C0D22020F0D22020F0D22020F62549C0F1922020F6254A80F8F22020F6254A90F2022020F045A810F0C22020F045A910F0222020F0D22030F9E22020F6254AD0F0022020F6254990F0C22020F62549F0F0C22020F526963680D22020F Footprint md5 Hash -> 33F0E507EEAA08744F3E97D343B8C6BB • The Rich header apparently has not been modified Certificate - Digital Signature Not Found: • The file is not signed |
| Packer/Compiler |
| Detect It Easy (die) • PE: patcher: simple patch(-)[-] • PE: compiler: Microsoft Visual C/C++(2010)[-] • PE: linker: Microsoft Linker(10.0)[-] • Entropy: 6.2475 |
| Suspicious Functions |
| Library | Function | Description |
|---|---|---|
| KERNEL32.DLL | GetModuleFileNameA | Retrieve the fully qualified path for the executable file of a specified module. |
| KERNEL32.DLL | VirtualAlloc | Reserve, commit, or both, a region of memory within the virtual address space of a process. |
| KERNEL32.DLL | WriteFile | Writes data to a specified file or input/output (I/O) device. |
| KERNEL32.DLL | LoadLibraryW | Loads the specified module into the address space of the calling process. |
| KERNEL32.DLL | WriteProcessMemory | Writes data to an area of memory in a specified process. |
| KERNEL32.DLL | GetProcAddress | Retrieves the address of an exported function or variable from the specified dynamic-link library (DLL). |
| KERNEL32.DLL | CreateFileA | Creates or opens a file or I/O device. |
| KERNEL32.DLL | IsDebuggerPresent | Determines if the calling process is being debugged by a user-mode debugger. |
| ET Functions (carving) |
| Original Name -> .dll fuckyou run |
| File Access |
| Windows\System32\tracerpt.exe Windows\SysWOW64\tracerpt.exe .dll WINMM.dll WS2_32.dll ole32.dll SHELL32.dll ADVAPI32.dll KERNEL32.dll |
| File Access (UNICODE) |
| 1bad allocationCorExitProcessmscoree.dll KERNEL32.DLL GetLastActivePopupGetActiveWindowMessageBoxWUSER32.DLL Temp |
| Interest's Words |
| fuck - }:) PADDINGX exec attrib start |
| Strings/Hex Code Found With The File Rules |
| Rule Type | Encoding | Matched (Word) |
|---|---|---|
| Text | Ascii | Registry (RegOpenKeyEx) |
| Text | Ascii | Registry (RegSetValueEx) |
| Text | Ascii | File (CreateFile) |
| Text | Ascii | File (WriteFile) |
| Text | Ascii | File (ReadFile) |
| Text | Ascii | Anti-Analysis VM (IsDebuggerPresent) |
| Text | Ascii | Stealth (VirtualAlloc) |
| Text | Ascii | Execution (CreateProcessA) |
| Text | Ascii | Execution (ResumeThread) |
| Entry Point | Hex Pattern | FASM v1.3x |
| Resources |
| Path | DataRVA | Size | FileOffset | Code | Text |
|---|---|---|---|---|---|
| \24\2\1033 | 1C058 | 15A | 16258 | 3C617373656D626C7920786D6C6E733D2275726E3A736368656D61732D6D6963726F736F66742D636F6D3A61736D2E763122 | <assembly xmlns="urn:schemas-microsoft-com:asm.v1" |
| Intelligent String |
| • mscoree.dll • KERNEL32.DLL • Windows\SysWOW64\tracerpt.exe • Windows\System32\tracerpt.exe • %s\20250606.png • KERNEL32.dll • ADVAPI32.dll • WS2_32.dll |
| Flow Anomalies |
| Offset | FlowVA | Section | Description |
|---|---|---|---|
| 41B | 100120C4 | .text | CALL [static] | Indirect call to absolute memory address |
| 53F | 100120C0 | .text | CALL [static] | Indirect call to absolute memory address |
| 572 | 100120C4 | .text | CALL [static] | Indirect call to absolute memory address |
| 606 | 100120C0 | .text | CALL [static] | Indirect call to absolute memory address |
| 635 | 100120C4 | .text | CALL [static] | Indirect call to absolute memory address |
| 72A | 10012064 | .text | CALL [static] | Indirect call to absolute memory address |
| 73D | 100121A0 | .text | CALL [static] | Indirect call to absolute memory address |
| 748 | 1001205C | .text | CALL [static] | Indirect call to absolute memory address |
| 7AC | 100121C4 | .text | CALL [static] | Indirect call to absolute memory address |
| 7B6 | 10012068 | .text | CALL [static] | Indirect call to absolute memory address |
| 7BF | 1001205C | .text | CALL [static] | Indirect call to absolute memory address |
| 7C9 | 100121B4 | .text | CALL [static] | Indirect call to absolute memory address |
| 7D3 | 10012038 | .text | CALL [static] | Indirect call to absolute memory address |
| 80B | 10012060 | .text | CALL [static] | Indirect call to absolute memory address |
| 817 | 1001205C | .text | CALL [static] | Indirect call to absolute memory address |
| 81D | 10012190 | .text | CALL [static] | Indirect call to absolute memory address |
| 84A | 100121B0 | .text | CALL [static] | Indirect call to absolute memory address |
| 876 | 10012058 | .text | CALL [static] | Indirect call to absolute memory address |
| 882 | 10012054 | .text | CALL [static] | Indirect call to absolute memory address |
| 8A1 | 10012058 | .text | CALL [static] | Indirect call to absolute memory address |
| 8AD | 10012054 | .text | CALL [static] | Indirect call to absolute memory address |
| 8BB | 100121B8 | .text | CALL [static] | Indirect call to absolute memory address |
| 8DD | 100121A4 | .text | CALL [static] | Indirect call to absolute memory address |
| 8FB | 1001219C | .text | CALL [static] | Indirect call to absolute memory address |
| 9BC | 10012198 | .text | CALL [static] | Indirect call to absolute memory address |
| 9C7 | 1001205C | .text | CALL [static] | Indirect call to absolute memory address |
| A93 | 100121C0 | .text | CALL [static] | Indirect call to absolute memory address |
| B74 | 10012190 | .text | CALL [static] | Indirect call to absolute memory address |
| BBB | 1001204C | .text | CALL [static] | Indirect call to absolute memory address |
| BD3 | 1001205C | .text | CALL [static] | Indirect call to absolute memory address |
| C7F | 1001204C | .text | CALL [static] | Indirect call to absolute memory address |
| CE1 | 100121BC | .text | CALL [static] | Indirect call to absolute memory address |
| D1E | 100121BC | .text | CALL [static] | Indirect call to absolute memory address |
| D76 | 1001205C | .text | CALL [static] | Indirect call to absolute memory address |
| E73 | 10012190 | .text | CALL [static] | Indirect call to absolute memory address |
| 1042 | 10012004 | .text | CALL [static] | Indirect call to absolute memory address |
| 1052 | 10012008 | .text | CALL [static] | Indirect call to absolute memory address |
| 1070 | 10012014 | .text | CALL [static] | Indirect call to absolute memory address |
| 107B | 10012000 | .text | CALL [static] | Indirect call to absolute memory address |
| 10DB | 1001207C | .text | CALL [static] | Indirect call to absolute memory address |
| 10F4 | 1001203C | .text | CALL [static] | Indirect call to absolute memory address |
| 10FC | 1001975C | .text | CALL [static] | Indirect call to absolute memory address |
| 11C7 | 10012004 | .text | CALL [static] | Indirect call to absolute memory address |
| 1246 | 100120C0 | .text | CALL [static] | Indirect call to absolute memory address |
| 1271 | 10012000 | .text | CALL [static] | Indirect call to absolute memory address |
| 12C5 | 100120C4 | .text | CALL [static] | Indirect call to absolute memory address |
| 13E6 | 100120C0 | .text | CALL [static] | Indirect call to absolute memory address |
| 1459 | 10012010 | .text | CALL [static] | Indirect call to absolute memory address |
| 146C | 10012008 | .text | CALL [static] | Indirect call to absolute memory address |
| 1484 | 10012014 | .text | CALL [static] | Indirect call to absolute memory address |
| 148E | 10012000 | .text | CALL [static] | Indirect call to absolute memory address |
| 14BE | 1001203C | .text | CALL [static] | Indirect call to absolute memory address |
| 1571 | 10012084 | .text | CALL [static] | Indirect call to absolute memory address |
| 15A0 | 10012078 | .text | CALL [static] | Indirect call to absolute memory address |
| 15E8 | 10012080 | .text | CALL [static] | Indirect call to absolute memory address |
| 160E | 10012088 | .text | CALL [static] | Indirect call to absolute memory address |
| 1628 | 1001208C | .text | CALL [static] | Indirect call to absolute memory address |
| 1647 | 1001206C | .text | CALL [static] | Indirect call to absolute memory address |
| 1662 | 10012070 | .text | CALL [static] | Indirect call to absolute memory address |
| 1681 | 10012090 | .text | CALL [static] | Indirect call to absolute memory address |
| 1B31 | 10012004 | .text | CALL [static] | Indirect call to absolute memory address |
| 1C8C | 1001203C | .text | CALL [static] | Indirect call to absolute memory address |
| 1DE7 | 1001203C | .text | CALL [static] | Indirect call to absolute memory address |
| 1E33 | 10012040 | .text | CALL [static] | Indirect call to absolute memory address |
| 1E79 | 10012034 | .text | CALL [static] | Indirect call to absolute memory address |
| 1EDD | 100120A0 | .text | CALL [static] | Indirect call to absolute memory address |
| 1EEB | 10012034 | .text | CALL [static] | Indirect call to absolute memory address |
| 1EF7 | 10012048 | .text | CALL [static] | Indirect call to absolute memory address |
| 1F0D | 100121CC | .text | CALL [static] | Indirect call to absolute memory address |
| 1F39 | 10012188 | .text | CALL [static] | Indirect call to absolute memory address |
| 1F57 | 10012054 | .text | CALL [static] | Indirect call to absolute memory address |
| 1F61 | 100121D0 | .text | CALL [static] | Indirect call to absolute memory address |
| 1F71 | 100121D4 | .text | CALL [static] | Indirect call to absolute memory address |
| 2020 | 10012098 | .text | CALL [static] | Indirect call to absolute memory address |
| 2043 | 1001203C | .text | CALL [static] | Indirect call to absolute memory address |
| 2054 | 10012094 | .text | CALL [static] | Indirect call to absolute memory address |
| 205A | 1001209C | .text | CALL [static] | Indirect call to absolute memory address |
| 2066 | 10012094 | .text | CALL [static] | Indirect call to absolute memory address |
| 2080 | 100120A0 | .text | CALL [static] | Indirect call to absolute memory address |
| 208E | 10012034 | .text | CALL [static] | Indirect call to absolute memory address |
| 26EF | 100120B0 | .text | CALL [static] | Indirect call to absolute memory address |
| 2701 | 10012044 | .text | CALL [static] | Indirect call to absolute memory address |
| 2758 | 100120BC | .text | CALL [static] | Indirect call to absolute memory address |
| 2960 | 10012130 | .text | CALL [static] | Indirect call to absolute memory address |
| 29D5 | 10012044 | .text | CALL [static] | Indirect call to absolute memory address |
| 29DC | 10012130 | .text | CALL [static] | Indirect call to absolute memory address |
| 29E2 | 1001204C | .text | CALL [static] | Indirect call to absolute memory address |
| 2A82 | 100120A0 | .text | CALL [static] | Indirect call to absolute memory address |
| 2A8C | 10012044 | .text | CALL [static] | Indirect call to absolute memory address |
| 2B3F | 10012138 | .text | CALL [static] | Indirect call to absolute memory address |
| 2B7F | 10012138 | .text | CALL [static] | Indirect call to absolute memory address |
| 2FBA | 10012140 | .text | CALL [static] | Indirect call to absolute memory address |
| 2FCA | 1001213C | .text | CALL [static] | Indirect call to absolute memory address |
| 2FEC | 10012094 | .text | CALL [static] | Indirect call to absolute memory address |
| 307C | 10012FAC | .text | CALL [static] | Indirect call to absolute memory address |
| 30E9 | 1001BB64 | .text | CALL [static] | Indirect call to absolute memory address |
| 32AF | 10012144 | .text | CALL [static] | Indirect call to absolute memory address |
| 3394 | 10012134 | .text | CALL [static] | Indirect call to absolute memory address |
| 33A9 | 1001204C | .text | CALL [static] | Indirect call to absolute memory address |
| 3535 | 10012148 | .text | CALL [static] | Indirect call to absolute memory address |
| Extra Analysis |
| Metric | Value | Percentage |
|---|---|---|
| Ascii Code | 52515 | 53,1442% |
| Null Byte Code | 21843 | 22,1047% |
© 2026 All rights reserved.