PESCAN.IO - Analysis Report Basic |
|||||||
| File Structure |
|
PE Chart Code
Header PE (light blue)
Executable sections (pink)
Non-executable sections (black)
External injected code (red)
File Structure in red = malformed or corrupted header
Chart Code For Other Files
Printable characters (blue)
Non-printable characters (black)
| Information |
Icon: Size: 3,01 MBSHA-256 Hash: 847269A452B595E1D6A47C0921F491CA81C494D378FE61B2830A65DBA7A2B13E SHA-1 Hash: 6937E0FB96DB4DC50F9CFF97FCA694CD239FABC0 MD5 Hash: A9EA8F9DDE7DD913492770C56016A917 Imphash: 5E5AC8AB7BE27AC2D1C548E5589378B6 MajorOSVersion: 5 MinorOSVersion: 0 CheckSum: 0030E285 EntryPoint (rva): 8C45 SizeOfHeaders: 400 SizeOfImage: 6C7000 ImageBase: 400000 Architecture: x86 ExportTable: 5C3068 ImportTable: 5C3CB8 Characteristics: 102 TimeDateStamp: 69EE8CF3 Date: 26/04/2026 22:08:51 File Type: EXE Number Of Sections: 9 ASLR: Enabled Section Names (Optional Header): *unnamed*, *unnamed*, *unnamed*, *unnamed*, *unnamed*, *unnamed*, .rsrc, *unnamed*, .data Number Of Executable Sections: 2 Subsystem: Windows GUI UAC Execution Level Manifest: asInvoker [Incomplete Binary or Compressor Packer - 3,77 MB Missing] |
| Sections Info |
| Section Name | Flags | ROffset | RSize | VOffset | VSize | Entropy | Chi2 |
|---|---|---|---|---|---|---|---|
| *unnamed* | 0xE0000040 Initialized Data Executable Readable Writeable |
400 | 7E00 | 1000 | E000 |
|
|
| *unnamed* | 0xE0000040 Initialized Data Executable Readable Writeable |
8200 | E00 | F000 | 3000 |
|
|
| *unnamed* | 0xE0000040 Initialized Data Executable Readable Writeable |
9000 | 1A600 | 12000 | 68000 |
|
|
| *unnamed* | 0xE0000040 Initialized Data Executable Readable Writeable |
23600 | 200 | 7A000 | 18000 |
|
|
| *unnamed* | 0xE0000040 Initialized Data Executable Readable Writeable |
23800 | 0 | 92000 | 2000 |
|
|
| *unnamed* | 0xE0000040 Initialized Data Executable Readable Writeable |
23800 | 199C00 | 94000 | 25D000 |
|
|
| .rsrc | 0xE0000040 Initialized Data Executable Readable Writeable |
1BD400 | 17200 | 2F1000 | 18000 |
|
|
| *unnamed* | 0xE0000040 Initialized Data Executable Readable Writeable |
1D4600 | 29A00 | 309000 | 2BA000 |
|
|
| .data | 0xE0000040 Initialized Data Executable Readable Writeable |
1FE000 | 103800 | 5C3000 | 104000 |
|
|
| Entry Point |
The section number (8) have the Entry Point Information -> EntryPoint (calculated) - 8045 Code -> E861000000E979FEFFFF6860BB440064FF35000000008B442410896C24108D6C24102BE0535657A1CC6E46003145FC33C550 Assembler |CALL 0X408CAB |JMP 0X408AC8 |PUSH 0X44BB60 |PUSH DWORD PTR FS:[0] |MOV EAX, DWORD PTR [ESP + 0X10] |MOV DWORD PTR [ESP + 0X10], EBP |LEA EBP, [ESP + 0X10] |SUB ESP, EAX |PUSH EBX |PUSH ESI |PUSH EDI |MOV EAX, DWORD PTR [0X466ECC] |XOR DWORD PTR [EBP - 4], EAX |XOR EAX, EBP |PUSH EAX |
| Signatures |
| Rich Signature Analyzer: Code -> E26D969BA60CF8C8A60CF8C8A60CF8C81B436EC8A70CF8C8AF746DC8B40CF8C881CA83C8AB0CF8C8A60CF9C8250CF8C8AF747CC8940CF8C8AF747BC8C50CF8C8B85E6CC8A70CF8C8AF7469C8A70CF8C852696368A60CF8C8 Footprint md5 Hash -> 8A57BE1341BC33E03B2570B5B317059B • The Rich header apparently has not been modified |
| Duplicate Sections |
| Section *unnamed* duplicate 7 times |
| Packer/Compiler |
| Detect It Easy (die) • PE: compiler: Microsoft Visual C/C++(2008)[-] • PE: linker: Microsoft Linker(9.0)[-] • PE: Sign tool: Windows Authenticode(2.0)[PKCS 7] • Entropy: 7.99693 |
| Suspicious Functions |
| Library | Function | Description |
|---|---|---|
| KERNEL32.DLL | LoadLibraryA | Loads the specified module into the address space of the calling process. |
| KERNEL32.DLL | GetModuleHandleA | Retrieves a handle to the specified module. |
| KERNEL32.DLL | GetProcAddress | Retrieves the address of an exported function or variable from the specified dynamic-link library (DLL). |
| SHELL32.DLL | ShellExecuteA | Performs a run operation on a specific file. |
| File Access |
| version.dll shell32.dll gdi32.dll oleaut32.dll advapi32.dll user32.dll kernel32.dll .dat |
| Interest's Words |
| exec |
| Strings/Hex Code Found With The File Rules |
| Rule Type | Encoding | Matched (Word) |
|---|---|---|
| Entry Point | Hex Pattern | Microsoft Visual C++ 8 |
| Entry Point | Hex Pattern | Microsoft Visual C++ 8.0 |
| Entry Point | Hex Pattern | Microsoft Visual C++ 8 |
| Entry Point | Hex Pattern | Microsoft Visual C++ 8 |
| Entry Point | Hex Pattern | VC8 - Microsoft Corporation |
| Resources |
| Path | DataRVA | Size | FileOffset | Code | Text |
|---|---|---|---|---|---|
| \ICON\1\0 | 2F11D8 | 25A8 | 1BD5D8 | 2800000030000000600000000100200000000000000000000000000000000000000000000000000000000001000000030000 | (...0........ ................................... |
| \ICON\2\0 | 2F3780 | 178E | 1BFB80 | 89504E470D0A1A0A0000000D4948445200000040000000400806000000AA6971DE000017554944415478DAED5B0B5C54551A | .PNG........IHDR...@...@......iq....UIDATx..[.\TU. |
| \ICON\3\0 | 2F4F10 | 4525 | 1C1310 | 89504E470D0A1A0A0000000D4948445200000080000000800806000000C33E61CB000044EC4944415478DAED7D07601BE5D9 | .PNG........IHDR..............>a...D.IDATx..}.... |
| \ICON\4\0 | 2F9438 | DA62 | 1C5838 | 89504E470D0A1A0A0000000D49484452000001000000010008060000005C72A8660000DA294944415478DAECBD097C1BE775 | .PNG........IHDR.............\r.f...)IDATx....|..u |
| \ICON\5\0 | 306E9C | CA8 | 1D329C | 2800000020000000400000000100180000000000000000000000000000000000000000000000000000000000000000000000 | (... ...@......................................... |
| \ICON\6\0 | 307B44 | 368 | 1D3F44 | 2800000010000000200000000100180000000000000000000000000000000000000000000000000000000000000000000000 | (....... ......................................... |
| \GROUP_ICON\1\0 | 307EAC | 5A | 1D42AC | 0000010006003030000001002000A825000001000D0D00000100000D8E17000002000D0D00000100000D2545000003000D0D00000100000D62DA000004002020000001001800A80C000005001010000001001800680300000600 | ......00.... ..%..........................%E............b..... ....................h..... |
| \24\1\1033 | 307F08 | 15A | 1D4308 | 3C617373656D626C7920786D6C6E733D2275726E3A736368656D61732D6D6963726F736F66742D636F6D3A61736D2E763122 | <assembly xmlns="urn:schemas-microsoft-com:asm.v1" |
| Intelligent String |
| • kernel32.dll • user32.dll • advapi32.dll • oleaut32.dll • gdi32.dll • shell32.dll • version.dll |
| Flow Anomalies |
| Offset | FlowVA | Section | Description |
|---|---|---|---|
| 67AD | 5481E75C | *unnamed* | JMP [static] | Indirect jump to absolute memory address |
| F8B1 | 5E663B36 | *unnamed* | JMP [static] | Indirect jump to absolute memory address |
| 1DA34 | 5E663B36 | *unnamed* | CALL [static] | Indirect call to absolute memory address |
| 1E91A | 5E663B36 | *unnamed* | JMP [static] | Indirect jump to absolute memory address |
| 1FA3A | 5E663B36 | *unnamed* | CALL [static] | Indirect call to absolute memory address |
| 22D10 | 2A077613 | *unnamed* | CALL [static] | Indirect call to absolute memory address |
| 29B8D | 2A077613 | *unnamed* | CALL [static] | Indirect call to absolute memory address |
| 43DA8 | 55F9835D | *unnamed* | CALL [static] | Indirect call to absolute memory address |
| 57965 | 7B7590D2 | *unnamed* | CALL [static] | Indirect call to absolute memory address |
| 5A963 | 7B7590D2 | *unnamed* | CALL [static] | Indirect call to absolute memory address |
| 5C85D | 7B7590D2 | *unnamed* | JMP [static] | Indirect jump to absolute memory address |
| 996F0 | 7B7590D2 | *unnamed* | CALL [static] | Indirect call to absolute memory address |
| A0BCF | 17AFAAF5 | *unnamed* | CALL [static] | Indirect call to absolute memory address |
| A531A | 7AADD5CD | *unnamed* | CALL [static] | Indirect call to absolute memory address |
| B67E3 | 6411C1E | *unnamed* | JMP [static] | Indirect jump to absolute memory address |
| BFBF7 | 6411C1E | *unnamed* | CALL [static] | Indirect call to absolute memory address |
| C048A | 7C96094A | *unnamed* | CALL [static] | Indirect call to absolute memory address |
| C3BEF | 7C96094A | *unnamed* | CALL [static] | Indirect call to absolute memory address |
| CEE3A | 7C96094A | *unnamed* | CALL [static] | Indirect call to absolute memory address |
| D2086 | 7C96094A | *unnamed* | CALL [static] | Indirect call to absolute memory address |
| DC7E3 | 55E893B2 | *unnamed* | CALL [static] | Indirect call to absolute memory address |
| E4BE4 | 55E893B2 | *unnamed* | JMP [static] | Indirect jump to absolute memory address |
| E7A61 | 577E90C3 | *unnamed* | JMP [static] | Indirect jump to absolute memory address |
| E9B1E | 472D022E | *unnamed* | CALL [static] | Indirect call to absolute memory address |
| F694D | 387FCDCD | *unnamed* | CALL [static] | Indirect call to absolute memory address |
| F6D30 | 387FCDCD | *unnamed* | CALL [static] | Indirect call to absolute memory address |
| FA6E1 | 6C2A956F | *unnamed* | JMP [static] | Indirect jump to absolute memory address |
| 10FA6C | 6C2A956F | *unnamed* | CALL [static] | Indirect call to absolute memory address |
| 114158 | 41573752 | *unnamed* | CALL [static] | Indirect call to absolute memory address |
| 121879 | 41573752 | *unnamed* | CALL [static] | Indirect call to absolute memory address |
| 1233A0 | 41573752 | *unnamed* | CALL [static] | Indirect call to absolute memory address |
| 133585 | 77DB9B1D | *unnamed* | CALL [static] | Indirect call to absolute memory address |
| 1362EC | 77DB9B1D | *unnamed* | CALL [static] | Indirect call to absolute memory address |
| 137345 | 77DB9B1D | *unnamed* | JMP [static] | Indirect jump to absolute memory address |
| 13A1A0 | 77DB9B1D | *unnamed* | CALL [static] | Indirect call to absolute memory address |
| 13B0AF | 2289E3DA | *unnamed* | JMP [static] | Indirect jump to absolute memory address |
| 13DA98 | 2289E3DA | *unnamed* | JMP [static] | Indirect jump to absolute memory address |
| 147821 | 580F054C | *unnamed* | CALL [static] | Indirect call to absolute memory address |
| 148983 | 580F054C | *unnamed* | CALL [static] | Indirect call to absolute memory address |
| 150EB4 | 580F054C | *unnamed* | JMP [static] | Indirect jump to absolute memory address |
| 156DA0 | 3F6B5DBC | *unnamed* | CALL [static] | Indirect call to absolute memory address |
| 15CC10 | 6CC68518 | *unnamed* | JMP [static] | Indirect jump to absolute memory address |
| 1711D4 | 1EB2C9DD | *unnamed* | JMP [static] | Indirect jump to absolute memory address |
| 182445 | 4F081546 | *unnamed* | CALL [static] | Indirect call to absolute memory address |
| 182D2D | 173D0A96 | *unnamed* | CALL [static] | Indirect call to absolute memory address |
| 1833EC | 634BB840 | *unnamed* | JMP [static] | Indirect jump to absolute memory address |
| 191B75 | 634BB840 | *unnamed* | CALL [static] | Indirect call to absolute memory address |
| 197281 | 3F5BBDCC | *unnamed* | CALL [static] | Indirect call to absolute memory address |
| 1A379A | 11E6EB16 | *unnamed* | JMP [static] | Indirect jump to absolute memory address |
| 1A3C3F | 6B94FD21 | *unnamed* | JMP [static] | Indirect jump to absolute memory address |
| 1AEC84 | 6B94FD21 | *unnamed* | CALL [static] | Indirect call to absolute memory address |
| 1B9B6C | 6B94FD21 | *unnamed* | JMP [static] | Indirect jump to absolute memory address |
| 1C6129 | 6B94FD21 | .rsrc | JMP [static] | Indirect jump to absolute memory address |
| 1D11C0 | 6B94FD21 | .rsrc | JMP [static] | Indirect jump to absolute memory address |
| 1E22C4 | 6B94FD21 | *unnamed* | CALL [static] | Indirect call to absolute memory address |
| 1EDDAE | 6B94FD21 | *unnamed* | JMP [static] | Indirect jump to absolute memory address |
| 1EEB0F | 6B94FD21 | *unnamed* | JMP [static] | Indirect jump to absolute memory address |
| 203606 | 6B94FD21 | .data | JMP [static] | Indirect jump to absolute memory address |
| 20AC93 | 7CE7068F | .data | JMP [static] | Indirect jump to absolute memory address |
| 21682C | 147C88E5 | .data | JMP [static] | Indirect jump to absolute memory address |
| 2171AF | 7B3335E3 | .data | CALL [static] | Indirect call to absolute memory address |
| 2214C0 | 7B3335E3 | .data | JMP [static] | Indirect jump to absolute memory address |
| 23B450 | 7B3335E3 | .data | JMP [static] | Indirect jump to absolute memory address |
| 23D61F | 13021AF1 | .data | JMP [static] | Indirect jump to absolute memory address |
| 24376D | 13021AF1 | .data | CALL [static] | Indirect call to absolute memory address |
| 245758 | 13021AF1 | .data | JMP [static] | Indirect jump to absolute memory address |
| 248D39 | 13021AF1 | .data | CALL [static] | Indirect call to absolute memory address |
| 249D81 | 13021AF1 | .data | JMP [static] | Indirect jump to absolute memory address |
| 251ADD | 30B34BFB | .data | CALL [static] | Indirect call to absolute memory address |
| 2549C6 | 30B34BFB | .data | JMP [static] | Indirect jump to absolute memory address |
| 25543D | 2F5F96F2 | .data | JMP [static] | Indirect jump to absolute memory address |
| 2580E5 | 634F3045 | .data | CALL [static] | Indirect call to absolute memory address |
| 25D508 | 634F3045 | .data | JMP [static] | Indirect jump to absolute memory address |
| 26D78D | 634F3045 | .data | CALL [static] | Indirect call to absolute memory address |
| 276C33 | 2CC26E0A | .data | JMP [static] | Indirect jump to absolute memory address |
| 27A587 | 48E5E707 | .data | CALL [static] | Indirect call to absolute memory address |
| 28084D | 6D961FF9 | .data | CALL [static] | Indirect call to absolute memory address |
| 289C67 | 6D961FF9 | .data | JMP [static] | Indirect jump to absolute memory address |
| 28B1D4 | 6D961FF9 | .data | CALL [static] | Indirect call to absolute memory address |
| 29117C | 6D961FF9 | .data | CALL [static] | Indirect call to absolute memory address |
| 29BF79 | 50408C36 | .data | CALL [static] | Indirect call to absolute memory address |
| 29EE77 | 50408C36 | .data | JMP [static] | Indirect jump to absolute memory address |
| 2B66A4 | 50408C36 | .data | CALL [static] | Indirect call to absolute memory address |
| 2B6D68 | 50408C36 | .data | CALL [static] | Indirect call to absolute memory address |
| 2BEDE0 | 283F6A0 | .data | JMP [static] | Indirect jump to absolute memory address |
| 2D81B7 | 283F6A0 | .data | CALL [static] | Indirect call to absolute memory address |
| 2FB299 | 928F994 | .data | CALL [static] | Indirect call to absolute memory address |
| 20200C-202021 | N/A | .data | Potential obfuscated jump sequence detected, count: 11 |
| 230EBA-230ECD | N/A | .data | Potential obfuscated jump sequence detected, count: 10 |
| 400-81FF | 1000 | *unnamed* | Executable section anomaly, first bytes: EA181BFB19DDC322 |
| 1BD400-1D45FF | 2F1000 | .rsrc | Executable section anomaly, first bytes: 0000000000000000 |
| 1FE000-3017FF | 5C3000 | .data | Executable section anomaly, first bytes: 01AB5743D38C2100 |
| 301800 | N/A | *Overlay* | A0050000000202003082059106092A864886F70D | ........0.....*.H... |
| Extra Analysis |
| Metric | Value | Percentage |
|---|---|---|
| Ascii Code | 2158596 | 68,4549% |
| Null Byte Code | 23081 | 0,732% |
© 2026 All rights reserved.