PESCAN.IO - Analysis Report Basic

File Structure
Analysis Image
PE Chart Code
Header PE (light blue)
Executable sections (pink)
Non-executable sections (black)
External injected code (red)
File Structure in red = malformed or corrupted header

Chart Code For Other Files
Printable characters (blue)
Non-printable characters (black)
Information
Size: 7,50 KB
SHA-256 Hash: ADA88916B79BAE174C39F24F8D235C32171E496CC44B60EC80DAC9D421056BC9
SHA-1 Hash: 3B4F6D7637898F32B03B46A26EA6F114D7634ABA
MD5 Hash: CB1CE52E7FEEF4D42966DE300CEE05F5
Imphash: F34D5F2D4577ED6D9CEEC516C1F5A744
MajorOSVersion: 4
MinorOSVersion: 0
CheckSum: 00000000
EntryPoint (rva): 3332
SizeOfHeaders: 200
SizeOfImage: 8000
ImageBase: 400000
Architecture: x86
ImportTable: 32E0
IAT: 2000
Characteristics: 22
TimeDateStamp: 6A6097DD
Date: 22/07/2026 10:13:49
File Type: EXE
Number Of Sections: 3
ASLR: Disabled
Section Names: .text, .rsrc, .reloc
Number Of Executable Sections: 1
Subsystem: Windows Console
UAC Execution Level Manifest: asInvoker

Sections Info
Section Name Flags ROffset RSize VOffset VSizeEntropyChi2
.text
0x60000020
Code
Executable
Readable
200 1400 2000 1338
4.7603
192436
.rsrc
0x40000040
Initialized Data
Readable
1600 600 4000 5C4
4.1222
75878.67
.reloc
0x42000040
Initialized Data
GP-Relative
Readable
1C00 200 6000 C
0.0815
128522
Description
OriginalFilename: SharpRDPThief.exe
LegalCopyright: Copyright 2017
ProductName: FileMonitor
FileVersion: 1.0.0.0
FileDescription: FileMonitor
ProductVersion: 1.0.0.0
Language: Unknown (ID=0x0)
CodePage: Unicode (UTF-16 LE) (0x4B0)

Entry Point
The section number (1) - (.text) have the Entry Point
Information -> EntryPoint (calculated) - 1532
Code -> FF25002040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
Assembler
|JMP DWORD PTR [0X402000]
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
Signatures
Certificate - Digital Signature Not Found:
• The file is not signed

Packer/Compiler
Compiler: Microsoft Visual .NET - (You can use a decompiler for this...)
AnyCPU: True
Version: v4.0
Compiler: Microsoft Visual Studio
Detect It Easy (die)
PE: library: .NET(v4.0.30319)[-]
PE: linker: Microsoft Linker(48.0)[-]
Entropy: 4.37759

File Access
SharpRDPThief.exe
mscoree.dll

File Access (UNICODE)
SharpRDPThief.exe
*] Waiting for mstsc.exe
RDPHook.dll
Temp

Interest's Words
exec
attrib

Interest's Words (UNICODE)
sc.exe

Anti-VM/Sandbox/Debug Tricks (UNICODE)
LabTools - filemon

Strings/Hex Code Found With The File Rules
Rule Type Encoding Matched (Word)
Text Ascii Technique used to insert malicious code into legitimate processes (Inject)
Entry Point Hex Pattern Anticrack Software Protector v1.09 (ACProtect)
Entry Point Hex Pattern Microsoft Visual C / Basic .NET
Entry Point Hex Pattern Microsoft Visual C++ 8
Entry Point Hex Pattern Microsoft Visual C++ 8.0
Entry Point Hex Pattern Microsoft Visual C v7.0 / Basic .NET
Entry Point Hex Pattern Microsoft Visual Studio .NET
Entry Point Hex Pattern .NET executable
Resources
Path DataRVA Size FileOffset CodeText
\VERSION\1\0 4090 334 1690 340334000000560053005F00560045005200530049004F004E005F0049004E0046004F0000000000BD04EFFE0000010000004.4...V.S._.V.E.R.S.I.O.N._.I.N.F.O...............
\24\1\0 43D4 1EA 19D4 EFBBBF3C3F786D6C2076657273696F6E3D22312E302220656E636F64696E673D225554462D3822207374616E64616C6F6E65...<?xml version="1.0" encoding="UTF-8" standalone
Intelligent String
• 1.0.0.0
• SharpRDPThief.exe
• M[*] Waiting for mstsc.exe processes...
• D:\Tools\SharpRDPThief-master\SharpRDPThief\obj\Release\SharpRDPThief.pdb
• _CorExeMainmscoree.dll

Flow Anomalies
Offset FlowVA Section Description
1532 402000 .text JMP [static] | Indirect jump to absolute memory address
Extra Analysis
Metric Value Percentage
Ascii Code 3768 49,0625%
Null Byte Code 3439 44,7786%
© 2026 All rights reserved.