PREMIUM PESCAN.IO - Analysis Report

File Structure
Analysis Image
PE Chart Code
Header PE (light blue)
Executable sections (pink)
Non-executable sections (black)
External injected code (red)
File Structure in red = malformed or corrupted header

Chart Code For Other Files
Printable characters (blue)
Non-printable characters (black)
Information
Size: 191,50 KB
SHA-256 Hash: 125C0A801C9854EA87003F2E7091AC05FD79991F9493C6486964D827256D8F01
SHA-1 Hash: CA2D659986F00C49911AC2F5FCCDCE8537DC57F8
MD5 Hash: A3A59F9567D36173AA5A39B25152D48A
Imphash: DAE02F32A21E03CE65412F6E56942DAA
MajorOSVersion: 4
MinorOSVersion: 0
CheckSum: 00000000
EntryPoint (rva): 313CE
SizeOfHeaders: 200
SizeOfImage: 36000
ImageBase: 10000000
Architecture: x86
ImportTable: 31380
IAT: 2000
Characteristics: 2102
TimeDateStamp: 6A5E15F2
Date: 20/07/2026 12:34:58
File Type: DLL
Number Of Sections: 3
ASLR: Enabled
Section Names: .text, .rsrc, .reloc
Number Of Executable Sections: 1
Subsystem: Windows Console

Sections Info
Section Name Flags ROffset RSize VOffset VSizeEntropyChi2
.text
0x60000020
Code
Executable
Readable
200 2F400 2000 2F3D4
7.6193
414404.02
.rsrc
0x40000040
Initialized Data
Readable
2F600 600 32000 4B0
2.7904
170967
.reloc
0x42000040
Initialized Data
GP-Relative
Readable
2FC00 200 34000 C
0.1019
128015
Description
OriginalFilename: main.dll
CompanyName: Microsoft Corporation
LegalCopyright: Copyright (C) Microsoft Corporation. All rights reserved.
ProductName: Windows Configuration Utility
FileVersion: 6.3.9600.17415
FileDescription: System Configuration Manager
ProductVersion: 6.3.9600.17415
Comments: Manages system configuration and maintenance tasks for Windows.
Language: Unknown (ID=0x0)
CodePage: Unicode (UTF-16 LE) (0x4B0)

Entry Point
The section number (1) - (.text) have the Entry Point
Information -> EntryPoint (calculated) - 2F5CE
Code -> FF25002000100000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
Assembler
|JMP DWORD PTR [0X10002000]
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
Signatures
Certificate - Digital Signature Not Found:
• The file is not signed

Packer/Compiler
Compiler: Microsoft Visual .NET - (You can use a decompiler for this...)
AnyCPU: True
Version: v4.0
Detect It Easy (die)
PE: Protector: Eziriz .NET Reactor(6.x.x.x)[By Dr.FarFar]
PE: library: .NET(v4.0.30319)[-]
PE: linker: Microsoft Linker(11.0)[-]
Entropy: 7.57874

Suspicious Functions
Library Function Description
KERNEL32.DLL GetModuleHandle Retrieves a handle to the specified module.
KERNEL32.DLL GetProcAddress Retrieves the address of an exported function or variable from the specified dynamic-link library (DLL).
ADVAPI32.DLL CryptDecrypt Performs a cryptographic operation on data in a data block.
Windows REG (UNICODE)
SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform
Rebuilt string - SOFTWARE\Policies\Microsoft\Windows\System

File Access
mscoree.dll
winsqlite3.dll
bcrypt.dll
user32.dll
kernel32.dll
main.dll
Temp

File Access (UNICODE)
main.dll
cmd.exe
7Started client.exe
ECreated client.exe
/Created client.exe
client.exe
\Program Files\VMware\VMware Tools\vmtoolsd.exe
\Windows\System32\VBoxService.exe
\Windows\System32\vmtoolsd.exe
bcrypt.dll
9Created main_client.dll
main_client.dll
ntdll.dll
amsi.dll
3wallet_scanner_report.txt
history.txt
autofill.txt
creditcards.txt
cookies.txt
passwords.txt
process.txt
information.txt
Exec - netsh wlan show profiles
Exec - netsh wlan show profile name=
Temp

SQL Queries
SELECT * FROM AntivirusProduct
SELECT * FROM Win32_ComputerSystem
SELECT * FROM Win32_Processor
SELECT * FROM Win32_VideoController
SELECT origin_url, username_value, password_value FROM logins
SELECT service, encrypted_token FROM token_service
SELECT host_key, name, encrypted_value, expires_utc, is_secure, is_httponly FROM cookies
SELECT name_on_card, card_number_encrypted, expiration_month, expiration_year FROM credit_cards
SELECT name, value FROM autofill
SELECT url, title, visit_count, last_visit_time FROM urls ORDER BY last_visit_time DESC LIMIT 5000
SELECT UUID FROM Win32_ComputerSystemProduct
SELECT InstallDate FROM Win32_OperatingSystem

Interest's Words
JFIF
Encrypt
Decrypt
KeyLogger
exec
attrib
start
cipher
hostname
systeminfo
getmac
replace

Interest's Words (UNICODE)
Virus
Encrypt
Decrypt
PassWord
powershell
netsh
start
hostname
wevtutil

Anti-VM/Sandbox/Debug Tricks (UNICODE)
VirtualBox Service - VBoxService.exe

URLs (UNICODE)
http://ip-api.com/json/query
https://develmakss.cc *
https://t.me/raven *
https://t.me/Raven *=====================================================
https://curl.se/docs/http-cookies.htmlS This file was generated by exfiltration
https://api.telegram.org/bot

AV Services (UNICODE)
securitycenter2.exe - (SecurityCenter2)

Strings/Hex Code Found With The File Rules
Rule Type Encoding Matched (Word)
Text Ascii WinAPI Sockets (send)
Text Unicode WinAPI Sockets (send)
Text Ascii File (GetTempPath)
Text Ascii Encryption (FromBase64String)
Text Ascii Encryption (ToBase64String)
Text Ascii Encryption API (CryptDecrypt)
Text Ascii Stealth (VirtualProtect)
Text Ascii Execution (ShellExecute)
Text Ascii Software that records keystrokes to steal credentials (Keylogger)
Text Ascii Malicious rerouting of traffic to an attacker-controlled site (Redirect)
Entry Point Hex Pattern Microsoft Visual C / Basic .NET
Entry Point Hex Pattern TrueVision Targa Graphics format
Resources
Path DataRVA Size FileOffset CodeText
\VERSION\1\0 32058 454 2F658 540434000000560053005F00560045005200530049004F004E005F0049004E0046004F0000000000BD04EFFE000001000300T.4...V.S._.V.E.R.S.I.O.N._.I.N.F.O...............
Intelligent String
• main.dll
• +:\s+(.+)
• amsi.dll
• ntdll.dll
• C:\Windows\System32\vmtoolsd.exe
• C:\Windows\System32\VBoxService.exe
• C:\Program Files\VMware\VMware Tools\vmtoolsd.exe
• client.exe
• main_client.dll
• /Created client.exe at:
• ECreated client.exe (fallback) at:
• 7Started client.exe (normal)
• cmd.exe
• 7/c netsh wlan show profiles
• information.txt
• .exe
• process.txt
• TG @Raven.jpg
• Login Data
• {SELECT origin_url, username_value, password_value FROM logins
• Login:
• passwords.txt
• cookies.txt
• creditcards.txt
• autofill.txt
• history.txt
• 3wallet_scanner_report.txt
• .txt
• Q https://curl.se/docs/http-cookies.html
• .zip
• https://api.telegram.org/bot
• .bat
• .wav
• _CorDllMainmscoree.dll

Flow Anomalies
Offset FlowVA Section Description
2F5CE 10002000 .text JMP [static] | Indirect jump to absolute memory address
Extra Analysis
Metric Value Percentage
Ascii Code 126474 64,496%
Null Byte Code 19784 10,0889%
© 2026 All rights reserved.