PREMIUM PESCAN.IO - Analysis Report |
|||||||
| File Structure |
|
PE Chart Code
Header PE (light blue)
Executable sections (pink)
Non-executable sections (black)
External injected code (red)
File Structure in red = malformed or corrupted header
Chart Code For Other Files
Printable characters (blue)
Non-printable characters (black)
| Information |
| Size: 191,50 KB SHA-256 Hash: 125C0A801C9854EA87003F2E7091AC05FD79991F9493C6486964D827256D8F01 SHA-1 Hash: CA2D659986F00C49911AC2F5FCCDCE8537DC57F8 MD5 Hash: A3A59F9567D36173AA5A39B25152D48A Imphash: DAE02F32A21E03CE65412F6E56942DAA MajorOSVersion: 4 MinorOSVersion: 0 CheckSum: 00000000 EntryPoint (rva): 313CE SizeOfHeaders: 200 SizeOfImage: 36000 ImageBase: 10000000 Architecture: x86 ImportTable: 31380 IAT: 2000 Characteristics: 2102 TimeDateStamp: 6A5E15F2 Date: 20/07/2026 12:34:58 File Type: DLL Number Of Sections: 3 ASLR: Enabled Section Names: .text, .rsrc, .reloc Number Of Executable Sections: 1 Subsystem: Windows Console |
| Sections Info |
| Section Name | Flags | ROffset | RSize | VOffset | VSize | Entropy | Chi2 |
|---|---|---|---|---|---|---|---|
| .text | 0x60000020 Code Executable Readable |
200 | 2F400 | 2000 | 2F3D4 |
|
|
| .rsrc | 0x40000040 Initialized Data Readable |
2F600 | 600 | 32000 | 4B0 |
|
|
| .reloc | 0x42000040 Initialized Data GP-Relative Readable |
2FC00 | 200 | 34000 | C |
|
|
| Description |
| OriginalFilename: main.dll CompanyName: Microsoft Corporation LegalCopyright: Copyright (C) Microsoft Corporation. All rights reserved. ProductName: Windows Configuration Utility FileVersion: 6.3.9600.17415 FileDescription: System Configuration Manager ProductVersion: 6.3.9600.17415 Comments: Manages system configuration and maintenance tasks for Windows. Language: Unknown (ID=0x0) CodePage: Unicode (UTF-16 LE) (0x4B0) |
| Entry Point |
The section number (1) - (.text) have the Entry Point Information -> EntryPoint (calculated) - 2F5CE Code -> FF25002000100000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 Assembler |JMP DWORD PTR [0X10002000] |ADD BYTE PTR [EAX], AL |ADD BYTE PTR [EAX], AL |ADD BYTE PTR [EAX], AL |ADD BYTE PTR [EAX], AL |ADD BYTE PTR [EAX], AL |ADD BYTE PTR [EAX], AL |ADD BYTE PTR [EAX], AL |ADD BYTE PTR [EAX], AL |ADD BYTE PTR [EAX], AL |ADD BYTE PTR [EAX], AL |ADD BYTE PTR [EAX], AL |ADD BYTE PTR [EAX], AL |ADD BYTE PTR [EAX], AL |ADD BYTE PTR [EAX], AL |ADD BYTE PTR [EAX], AL |ADD BYTE PTR [EAX], AL |ADD BYTE PTR [EAX], AL |ADD BYTE PTR [EAX], AL |ADD BYTE PTR [EAX], AL |ADD BYTE PTR [EAX], AL |ADD BYTE PTR [EAX], AL |ADD BYTE PTR [EAX], AL |
| Signatures |
| Certificate - Digital Signature Not Found: • The file is not signed |
| Packer/Compiler |
| Compiler: Microsoft Visual .NET - (You can use a decompiler for this...) • AnyCPU: True • Version: v4.0 Detect It Easy (die) • PE: Protector: Eziriz .NET Reactor(6.x.x.x)[By Dr.FarFar] • PE: library: .NET(v4.0.30319)[-] • PE: linker: Microsoft Linker(11.0)[-] • Entropy: 7.57874 |
| Suspicious Functions |
| Library | Function | Description |
|---|---|---|
| KERNEL32.DLL | GetModuleHandle | Retrieves a handle to the specified module. |
| KERNEL32.DLL | GetProcAddress | Retrieves the address of an exported function or variable from the specified dynamic-link library (DLL). |
| ADVAPI32.DLL | CryptDecrypt | Performs a cryptographic operation on data in a data block. |
| Windows REG (UNICODE) |
| SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform Rebuilt string - SOFTWARE\Policies\Microsoft\Windows\System |
| File Access |
| mscoree.dll winsqlite3.dll bcrypt.dll user32.dll kernel32.dll main.dll Temp |
| File Access (UNICODE) |
| main.dll cmd.exe 7Started client.exe ECreated client.exe /Created client.exe client.exe \Program Files\VMware\VMware Tools\vmtoolsd.exe \Windows\System32\VBoxService.exe \Windows\System32\vmtoolsd.exe bcrypt.dll 9Created main_client.dll main_client.dll ntdll.dll amsi.dll 3wallet_scanner_report.txt history.txt autofill.txt creditcards.txt cookies.txt passwords.txt process.txt information.txt Exec - netsh wlan show profiles Exec - netsh wlan show profile name= Temp |
| SQL Queries |
| SELECT * FROM AntivirusProduct SELECT * FROM Win32_ComputerSystem SELECT * FROM Win32_Processor SELECT * FROM Win32_VideoController SELECT origin_url, username_value, password_value FROM logins SELECT service, encrypted_token FROM token_service SELECT host_key, name, encrypted_value, expires_utc, is_secure, is_httponly FROM cookies SELECT name_on_card, card_number_encrypted, expiration_month, expiration_year FROM credit_cards SELECT name, value FROM autofill SELECT url, title, visit_count, last_visit_time FROM urls ORDER BY last_visit_time DESC LIMIT 5000 SELECT UUID FROM Win32_ComputerSystemProduct SELECT InstallDate FROM Win32_OperatingSystem |
| Interest's Words |
| JFIF Encrypt Decrypt KeyLogger exec attrib start cipher hostname systeminfo getmac replace |
| Interest's Words (UNICODE) |
| Virus Encrypt Decrypt PassWord powershell netsh start hostname wevtutil |
| Anti-VM/Sandbox/Debug Tricks (UNICODE) |
| VirtualBox Service - VBoxService.exe |
| URLs (UNICODE) |
| http://ip-api.com/json/query https://develmakss.cc * https://t.me/raven * https://t.me/Raven *===================================================== https://curl.se/docs/http-cookies.htmlS This file was generated by exfiltration https://api.telegram.org/bot |
| AV Services (UNICODE) |
| securitycenter2.exe - (SecurityCenter2) |
| Strings/Hex Code Found With The File Rules |
| Rule Type | Encoding | Matched (Word) |
|---|---|---|
| Text | Ascii | WinAPI Sockets (send) |
| Text | Unicode | WinAPI Sockets (send) |
| Text | Ascii | File (GetTempPath) |
| Text | Ascii | Encryption (FromBase64String) |
| Text | Ascii | Encryption (ToBase64String) |
| Text | Ascii | Encryption API (CryptDecrypt) |
| Text | Ascii | Stealth (VirtualProtect) |
| Text | Ascii | Execution (ShellExecute) |
| Text | Ascii | Software that records keystrokes to steal credentials (Keylogger) |
| Text | Ascii | Malicious rerouting of traffic to an attacker-controlled site (Redirect) |
| Entry Point | Hex Pattern | Microsoft Visual C / Basic .NET |
| Entry Point | Hex Pattern | TrueVision Targa Graphics format |
| Resources |
| Path | DataRVA | Size | FileOffset | Code | Text |
|---|---|---|---|---|---|
| \VERSION\1\0 | 32058 | 454 | 2F658 | 540434000000560053005F00560045005200530049004F004E005F0049004E0046004F0000000000BD04EFFE000001000300 | T.4...V.S._.V.E.R.S.I.O.N._.I.N.F.O............... |
| Intelligent String |
| • main.dll • +:\s+(.+) • amsi.dll • ntdll.dll • C:\Windows\System32\vmtoolsd.exe • C:\Windows\System32\VBoxService.exe • C:\Program Files\VMware\VMware Tools\vmtoolsd.exe • client.exe • main_client.dll • /Created client.exe at: • ECreated client.exe (fallback) at: • 7Started client.exe (normal) • cmd.exe • 7/c netsh wlan show profiles • information.txt • .exe • process.txt • TG @Raven.jpg • Login Data • {SELECT origin_url, username_value, password_value FROM logins • Login: • passwords.txt • cookies.txt • creditcards.txt • autofill.txt • history.txt • 3wallet_scanner_report.txt • .txt • Q https://curl.se/docs/http-cookies.html • .zip • https://api.telegram.org/bot • .bat • .wav • _CorDllMainmscoree.dll |
| Flow Anomalies |
| Offset | FlowVA | Section | Description |
|---|---|---|---|
| 2F5CE | 10002000 | .text | JMP [static] | Indirect jump to absolute memory address |
| Extra Analysis |
| Metric | Value | Percentage |
|---|---|---|
| Ascii Code | 126474 | 64,496% |
| Null Byte Code | 19784 | 10,0889% |
© 2026 All rights reserved.