PESCAN.IO - Analysis Report Basic

File Structure
Analysis Image
PE Chart Code
Header PE (light blue)
Executable sections (pink)
Non-executable sections (black)
External injected code (red)
File Structure in red = malformed or corrupted header

Chart Code For Other Files
Printable characters (blue)
Non-printable characters (black)
Information
Size: 148,36 KB
SHA-256 Hash: D56E8F40E062F500A4E0E35747529C226A0D2B74AB9F57EEEE1ED6666134E0D2
SHA-1 Hash: DBFEA3FF1CA9E12AFF02E3DB0F33DB5FEBDE63A7
MD5 Hash: BC709A6C2B2ACA666C511095784F0321
Imphash: 43FA4C71D5E33E01A83811EC5B9FFC1B
MajorOSVersion: 4
MinorOSVersion: 0
CheckSum: 00000000
EntryPoint (rva): 45560
SizeOfHeaders: 200
SizeOfImage: 47000
ImageBase: 0000000140000000
Architecture: x64
ImportTable: 464EC
Characteristics: 26
TimeDateStamp: 6A5308E7
Date: 12/07/2026 3:24:23
File Type: DLL
Number Of Sections: 3
ASLR: Disabled
Section Names (Optional Header): UPX0, UPX1, .rsrc
Number Of Executable Sections: 2
Subsystem: Windows Console
UAC Execution Level Manifest: asInvoker
[Incomplete Binary or Compressor Packer - 135,64 KB Missing]

Sections Info
Section Name Flags ROffset RSize VOffset VSizeEntropyChi2
UPX0
0xE0000080
Uninitialized Data
Executable
Readable
Writeable
200 0 1000 2D000
N/A
N/A
UPX1
0xE0000040
Initialized Data
Executable
Readable
Writeable
200 17A00 2E000 18000
7.8419
27398.5
.rsrc
0xC0000040
Initialized Data
Readable
Writeable
17C00 800 46000 1000
4.6079
60952.75
Entry Point
The section number (2) have the Entry Point
Information -> EntryPoint (calculated) - 17760
Code -> 53565755488D35BA8AFEFF488DBEDB2FFDFF5731DB31C94883CDFFE85000000001DB7402F3C38B1E4883EEFC11DB8A16F3C3
Assembler
|PUSH RBX
|PUSH RSI
|PUSH RDI
|PUSH RBP
|LEA RSI, [RIP - 0X17546]
|LEA RDI, [RSI - 0X2D025]
|PUSH RDI
|XOR EBX, EBX
|XOR ECX, ECX
|OR RBP, 0XFFFFFFFFFFFFFFFF
|CALL 0X1400455D0
|ADD EBX, EBX
|JE 0X140045586
|RET
|MOV EBX, DWORD PTR [RSI]
|SUB RSI, -4
|ADC EBX, EBX
|MOV DL, BYTE PTR [RSI]
|RET
Signatures
Certificate - Digital Signature Not Found:
• The file is not signed

Packer/Compiler
Compression: UPX
Detect It Easy (die)
PE+(64): packer: UPX(5.20)[NRV,best]
Entropy: 6.82167

Suspicious Functions
Library Function Description
KERNEL32.DLL GetModuleFileNameA Retrieve the fully qualified path for the executable file of a specified module.
KERNEL32.DLL LoadLibraryA Loads the specified module into the address space of the calling process.
KERNEL32.DLL GetModuleHandleA Retrieves a handle to the specified module.
KERNEL32.DLL GetProcAddress Retrieves the address of an exported function or variable from the specified dynamic-link library (DLL).
KERNEL32.DLL ReadFile Reads data from a file.
KERNEL32.DLL CloseHandle Closes an open object handle.
KERNEL32.DLL VirtualProtect Changes memory protection attributes.
Ws2_32.DLL socket Create a communication endpoint for networking applications.
Ws2_32.DLL WSAStartup Initializes the Winsock networking library.
Ws2_32.DLL WSACleanup Releases Winsock networking resources.
Ws2_32.DLL bind Associates a socket with a local address.
Ws2_32.DLL listen Puts a socket into listening mode.
Ws2_32.DLL accept Accepts an incoming network connection.
Ws2_32.DLL recv Receives data from a network socket.
Ws2_32.DLL send Sends data through a network socket.
ADVAPI32.DLL RegSetValueExA Sets the data and type of a specified value under a registry key.
ADVAPI32.DLL RegOpenKeyExA Opens an existing registry key.
WININET.DLL InternetOpenA Initializes an application’s use of the WinINet functions.
WININET.DLL InternetReadFile Reads data from an Internet resource.
Windows REG
Software\Mic[Vs\Wiqs\C~1Von\

File Access
WS2_32.dll
WININET.dll
msvcrt.dll
KERNEL32.DLL
ADVAPI32.dll
.dat

Interest's Words
exec
start

Strings/Hex Code Found With The File Rules
Rule Type Encoding Matched (Word)
Entry Point Hex Pattern Microsoft Visual C++ 8.0 (DLL)
Entry Point Hex Pattern ZM-Exe Executable Image
Resources
Path DataRVA Size FileOffset CodeText
\24\1\0 4605C 48F 17C5C 3C3F786D6C2076657273696F6E3D22312E302220656E636F64696E673D225554462D3822207374616E64616C6F6E653D2279<?xml version="1.0" encoding="UTF-8" standalone="y
Intelligent String
• .bss
• .hZh
• .tls

Flow Anomalies
Offset FlowVA Section Description
365 N/A UPX1 CALL QWORD PTR [RIP+0x15E3E1DC]
96D N/A UPX1 JMP QWORD PTR [RIP+0x12072422]
BD0 N/A UPX1 CALL QWORD PTR [RIP+0xD157]
178CF N/A UPX1 CALL QWORD PTR [RIP+0xE9F]
178ED N/A UPX1 CALL QWORD PTR [RIP+0xE91]
17901 N/A UPX1 JMP QWORD PTR [RIP+0xE75]
17A18 1400457C0 UPX1 TLS Callback | Pointer to 457C0 - 0x179C0 UPX1
200-17BFF 2E000 UPX1 Executable section anomaly, first bytes: 352E323000555058
18400 N/A *Overlay* 2E66696C650000005F000000FEFF000067016372 | .file..._.......g.cr
Extra Analysis
Metric Value Percentage
Ascii Code 87294 57,4586%
Null Byte Code 31607 20,8043%
© 2026 All rights reserved.