PESCAN.IO - Analysis Report Basic

File Structure
Analysis Image
PE Chart Code
Header PE (light blue)
Executable sections (pink)
Non-executable sections (black)
External injected code (red)
File Structure in red = malformed or corrupted header

Chart Code For Other Files
Printable characters (blue)
Non-printable characters (black)
Information
Icon: Icon
Size: 3,01 MB
SHA-256 Hash: 847269A452B595E1D6A47C0921F491CA81C494D378FE61B2830A65DBA7A2B13E
SHA-1 Hash: 6937E0FB96DB4DC50F9CFF97FCA694CD239FABC0
MD5 Hash: A9EA8F9DDE7DD913492770C56016A917
Imphash: 5E5AC8AB7BE27AC2D1C548E5589378B6
MajorOSVersion: 5
MinorOSVersion: 0
CheckSum: 0030E285
EntryPoint (rva): 8C45
SizeOfHeaders: 400
SizeOfImage: 6C7000
ImageBase: 400000
Architecture: x86
ExportTable: 5C3068
ImportTable: 5C3CB8
Characteristics: 102
TimeDateStamp: 69EE8CF3
Date: 26/04/2026 22:08:51
File Type: EXE
Number Of Sections: 9
ASLR: Enabled
Section Names (Optional Header): *unnamed*, *unnamed*, *unnamed*, *unnamed*, *unnamed*, *unnamed*, .rsrc, *unnamed*, .data
Number Of Executable Sections: 2
Subsystem: Windows GUI
UAC Execution Level Manifest: asInvoker
[Incomplete Binary or Compressor Packer - 3,77 MB Missing]

Sections Info
Section Name Flags ROffset RSize VOffset VSizeEntropyChi2
*unnamed*
0xE0000040
Initialized Data
Executable
Readable
Writeable
400 7E00 1000 E000
7.9818
1194.14
*unnamed*
0xE0000040
Initialized Data
Executable
Readable
Writeable
8200 E00 F000 3000
7.5201
12339
*unnamed*
0xE0000040
Initialized Data
Executable
Readable
Writeable
9000 1A600 12000 68000
7.9964
620.3
*unnamed*
0xE0000040
Initialized Data
Executable
Readable
Writeable
23600 200 7A000 18000
0.9971
106239
*unnamed*
0xE0000040
Initialized Data
Executable
Readable
Writeable
23800 0 92000 2000
N/A
N/A
*unnamed*
0xE0000040
Initialized Data
Executable
Readable
Writeable
23800 199C00 94000 25D000
7.9999
227.97
.rsrc
0xE0000040
Initialized Data
Executable
Readable
Writeable
1BD400 17200 2F1000 18000
7.7118
140083.26
*unnamed*
0xE0000040
Initialized Data
Executable
Readable
Writeable
1D4600 29A00 309000 2BA000
7.9983
428.35
.data
0xE0000040
Initialized Data
Executable
Readable
Writeable
1FE000 103800 5C3000 104000
7.9899
15175.07
Entry Point
The section number (8) have the Entry Point
Information -> EntryPoint (calculated) - 8045
Code -> E861000000E979FEFFFF6860BB440064FF35000000008B442410896C24108D6C24102BE0535657A1CC6E46003145FC33C550
Assembler
|CALL 0X408CAB
|JMP 0X408AC8
|PUSH 0X44BB60
|PUSH DWORD PTR FS:[0]
|MOV EAX, DWORD PTR [ESP + 0X10]
|MOV DWORD PTR [ESP + 0X10], EBP
|LEA EBP, [ESP + 0X10]
|SUB ESP, EAX
|PUSH EBX
|PUSH ESI
|PUSH EDI
|MOV EAX, DWORD PTR [0X466ECC]
|XOR DWORD PTR [EBP - 4], EAX
|XOR EAX, EBP
|PUSH EAX
Signatures
Rich Signature Analyzer:
Code -> E26D969BA60CF8C8A60CF8C8A60CF8C81B436EC8A70CF8C8AF746DC8B40CF8C881CA83C8AB0CF8C8A60CF9C8250CF8C8AF747CC8940CF8C8AF747BC8C50CF8C8B85E6CC8A70CF8C8AF7469C8A70CF8C852696368A60CF8C8
Footprint md5 Hash -> 8A57BE1341BC33E03B2570B5B317059B
• The Rich header apparently has not been modified

Duplicate Sections
Section *unnamed* duplicate 7 times

Packer/Compiler
Detect It Easy (die)
PE: compiler: Microsoft Visual C/C++(2008)[-]
PE: linker: Microsoft Linker(9.0)[-]
PE: Sign tool: Windows Authenticode(2.0)[PKCS 7]
Entropy: 7.99693

Suspicious Functions
Library Function Description
KERNEL32.DLL LoadLibraryA Loads the specified module into the address space of the calling process.
KERNEL32.DLL GetModuleHandleA Retrieves a handle to the specified module.
KERNEL32.DLL GetProcAddress Retrieves the address of an exported function or variable from the specified dynamic-link library (DLL).
SHELL32.DLL ShellExecuteA Performs a run operation on a specific file.
File Access
version.dll
shell32.dll
gdi32.dll
oleaut32.dll
advapi32.dll
user32.dll
kernel32.dll
.dat

Interest's Words
exec

Strings/Hex Code Found With The File Rules
Rule Type Encoding Matched (Word)
Entry Point Hex Pattern Microsoft Visual C++ 8
Entry Point Hex Pattern Microsoft Visual C++ 8.0
Entry Point Hex Pattern Microsoft Visual C++ 8
Entry Point Hex Pattern Microsoft Visual C++ 8
Entry Point Hex Pattern VC8 - Microsoft Corporation
Resources
Path DataRVA Size FileOffset CodeText
\ICON\1\0 2F11D8 25A8 1BD5D8 2800000030000000600000000100200000000000000000000000000000000000000000000000000000000001000000030000(...0........ ...................................
\ICON\2\0 2F3780 178E 1BFB80 89504E470D0A1A0A0000000D4948445200000040000000400806000000AA6971DE000017554944415478DAED5B0B5C54551A.PNG........IHDR...@...@......iq....UIDATx..[.\TU.
\ICON\3\0 2F4F10 4525 1C1310 89504E470D0A1A0A0000000D4948445200000080000000800806000000C33E61CB000044EC4944415478DAED7D07601BE5D9.PNG........IHDR..............>a...D.IDATx..}....
\ICON\4\0 2F9438 DA62 1C5838 89504E470D0A1A0A0000000D49484452000001000000010008060000005C72A8660000DA294944415478DAECBD097C1BE775.PNG........IHDR.............\r.f...)IDATx....|..u
\ICON\5\0 306E9C CA8 1D329C 2800000020000000400000000100180000000000000000000000000000000000000000000000000000000000000000000000(... ...@.........................................
\ICON\6\0 307B44 368 1D3F44 2800000010000000200000000100180000000000000000000000000000000000000000000000000000000000000000000000(....... .........................................
\GROUP_ICON\1\0 307EAC 5A 1D42AC 0000010006003030000001002000A825000001000D0D00000100000D8E17000002000D0D00000100000D2545000003000D0D00000100000D62DA000004002020000001001800A80C000005001010000001001800680300000600......00.... ..%..........................%E............b..... ....................h.....
\24\1\1033 307F08 15A 1D4308 3C617373656D626C7920786D6C6E733D2275726E3A736368656D61732D6D6963726F736F66742D636F6D3A61736D2E763122<assembly xmlns="urn:schemas-microsoft-com:asm.v1"
Intelligent String
• kernel32.dll
• user32.dll
• advapi32.dll
• oleaut32.dll
• gdi32.dll
• shell32.dll
• version.dll

Flow Anomalies
Offset FlowVA Section Description
67AD 5481E75C *unnamed* JMP [static] | Indirect jump to absolute memory address
F8B1 5E663B36 *unnamed* JMP [static] | Indirect jump to absolute memory address
1DA34 5E663B36 *unnamed* CALL [static] | Indirect call to absolute memory address
1E91A 5E663B36 *unnamed* JMP [static] | Indirect jump to absolute memory address
1FA3A 5E663B36 *unnamed* CALL [static] | Indirect call to absolute memory address
22D10 2A077613 *unnamed* CALL [static] | Indirect call to absolute memory address
29B8D 2A077613 *unnamed* CALL [static] | Indirect call to absolute memory address
43DA8 55F9835D *unnamed* CALL [static] | Indirect call to absolute memory address
57965 7B7590D2 *unnamed* CALL [static] | Indirect call to absolute memory address
5A963 7B7590D2 *unnamed* CALL [static] | Indirect call to absolute memory address
5C85D 7B7590D2 *unnamed* JMP [static] | Indirect jump to absolute memory address
996F0 7B7590D2 *unnamed* CALL [static] | Indirect call to absolute memory address
A0BCF 17AFAAF5 *unnamed* CALL [static] | Indirect call to absolute memory address
A531A 7AADD5CD *unnamed* CALL [static] | Indirect call to absolute memory address
B67E3 6411C1E *unnamed* JMP [static] | Indirect jump to absolute memory address
BFBF7 6411C1E *unnamed* CALL [static] | Indirect call to absolute memory address
C048A 7C96094A *unnamed* CALL [static] | Indirect call to absolute memory address
C3BEF 7C96094A *unnamed* CALL [static] | Indirect call to absolute memory address
CEE3A 7C96094A *unnamed* CALL [static] | Indirect call to absolute memory address
D2086 7C96094A *unnamed* CALL [static] | Indirect call to absolute memory address
DC7E3 55E893B2 *unnamed* CALL [static] | Indirect call to absolute memory address
E4BE4 55E893B2 *unnamed* JMP [static] | Indirect jump to absolute memory address
E7A61 577E90C3 *unnamed* JMP [static] | Indirect jump to absolute memory address
E9B1E 472D022E *unnamed* CALL [static] | Indirect call to absolute memory address
F694D 387FCDCD *unnamed* CALL [static] | Indirect call to absolute memory address
F6D30 387FCDCD *unnamed* CALL [static] | Indirect call to absolute memory address
FA6E1 6C2A956F *unnamed* JMP [static] | Indirect jump to absolute memory address
10FA6C 6C2A956F *unnamed* CALL [static] | Indirect call to absolute memory address
114158 41573752 *unnamed* CALL [static] | Indirect call to absolute memory address
121879 41573752 *unnamed* CALL [static] | Indirect call to absolute memory address
1233A0 41573752 *unnamed* CALL [static] | Indirect call to absolute memory address
133585 77DB9B1D *unnamed* CALL [static] | Indirect call to absolute memory address
1362EC 77DB9B1D *unnamed* CALL [static] | Indirect call to absolute memory address
137345 77DB9B1D *unnamed* JMP [static] | Indirect jump to absolute memory address
13A1A0 77DB9B1D *unnamed* CALL [static] | Indirect call to absolute memory address
13B0AF 2289E3DA *unnamed* JMP [static] | Indirect jump to absolute memory address
13DA98 2289E3DA *unnamed* JMP [static] | Indirect jump to absolute memory address
147821 580F054C *unnamed* CALL [static] | Indirect call to absolute memory address
148983 580F054C *unnamed* CALL [static] | Indirect call to absolute memory address
150EB4 580F054C *unnamed* JMP [static] | Indirect jump to absolute memory address
156DA0 3F6B5DBC *unnamed* CALL [static] | Indirect call to absolute memory address
15CC10 6CC68518 *unnamed* JMP [static] | Indirect jump to absolute memory address
1711D4 1EB2C9DD *unnamed* JMP [static] | Indirect jump to absolute memory address
182445 4F081546 *unnamed* CALL [static] | Indirect call to absolute memory address
182D2D 173D0A96 *unnamed* CALL [static] | Indirect call to absolute memory address
1833EC 634BB840 *unnamed* JMP [static] | Indirect jump to absolute memory address
191B75 634BB840 *unnamed* CALL [static] | Indirect call to absolute memory address
197281 3F5BBDCC *unnamed* CALL [static] | Indirect call to absolute memory address
1A379A 11E6EB16 *unnamed* JMP [static] | Indirect jump to absolute memory address
1A3C3F 6B94FD21 *unnamed* JMP [static] | Indirect jump to absolute memory address
1AEC84 6B94FD21 *unnamed* CALL [static] | Indirect call to absolute memory address
1B9B6C 6B94FD21 *unnamed* JMP [static] | Indirect jump to absolute memory address
1C6129 6B94FD21 .rsrc JMP [static] | Indirect jump to absolute memory address
1D11C0 6B94FD21 .rsrc JMP [static] | Indirect jump to absolute memory address
1E22C4 6B94FD21 *unnamed* CALL [static] | Indirect call to absolute memory address
1EDDAE 6B94FD21 *unnamed* JMP [static] | Indirect jump to absolute memory address
1EEB0F 6B94FD21 *unnamed* JMP [static] | Indirect jump to absolute memory address
203606 6B94FD21 .data JMP [static] | Indirect jump to absolute memory address
20AC93 7CE7068F .data JMP [static] | Indirect jump to absolute memory address
21682C 147C88E5 .data JMP [static] | Indirect jump to absolute memory address
2171AF 7B3335E3 .data CALL [static] | Indirect call to absolute memory address
2214C0 7B3335E3 .data JMP [static] | Indirect jump to absolute memory address
23B450 7B3335E3 .data JMP [static] | Indirect jump to absolute memory address
23D61F 13021AF1 .data JMP [static] | Indirect jump to absolute memory address
24376D 13021AF1 .data CALL [static] | Indirect call to absolute memory address
245758 13021AF1 .data JMP [static] | Indirect jump to absolute memory address
248D39 13021AF1 .data CALL [static] | Indirect call to absolute memory address
249D81 13021AF1 .data JMP [static] | Indirect jump to absolute memory address
251ADD 30B34BFB .data CALL [static] | Indirect call to absolute memory address
2549C6 30B34BFB .data JMP [static] | Indirect jump to absolute memory address
25543D 2F5F96F2 .data JMP [static] | Indirect jump to absolute memory address
2580E5 634F3045 .data CALL [static] | Indirect call to absolute memory address
25D508 634F3045 .data JMP [static] | Indirect jump to absolute memory address
26D78D 634F3045 .data CALL [static] | Indirect call to absolute memory address
276C33 2CC26E0A .data JMP [static] | Indirect jump to absolute memory address
27A587 48E5E707 .data CALL [static] | Indirect call to absolute memory address
28084D 6D961FF9 .data CALL [static] | Indirect call to absolute memory address
289C67 6D961FF9 .data JMP [static] | Indirect jump to absolute memory address
28B1D4 6D961FF9 .data CALL [static] | Indirect call to absolute memory address
29117C 6D961FF9 .data CALL [static] | Indirect call to absolute memory address
29BF79 50408C36 .data CALL [static] | Indirect call to absolute memory address
29EE77 50408C36 .data JMP [static] | Indirect jump to absolute memory address
2B66A4 50408C36 .data CALL [static] | Indirect call to absolute memory address
2B6D68 50408C36 .data CALL [static] | Indirect call to absolute memory address
2BEDE0 283F6A0 .data JMP [static] | Indirect jump to absolute memory address
2D81B7 283F6A0 .data CALL [static] | Indirect call to absolute memory address
2FB299 928F994 .data CALL [static] | Indirect call to absolute memory address
20200C-202021 N/A .data Potential obfuscated jump sequence detected, count: 11
230EBA-230ECD N/A .data Potential obfuscated jump sequence detected, count: 10
400-81FF 1000 *unnamed* Executable section anomaly, first bytes: EA181BFB19DDC322
1BD400-1D45FF 2F1000 .rsrc Executable section anomaly, first bytes: 0000000000000000
1FE000-3017FF 5C3000 .data Executable section anomaly, first bytes: 01AB5743D38C2100
301800 N/A *Overlay* A0050000000202003082059106092A864886F70D | ........0.....*.H...
Extra Analysis
Metric Value Percentage
Ascii Code 2158596 68,4549%
Null Byte Code 23081 0,732%
© 2026 All rights reserved.