PESCAN.IO - Analysis Report Basic

File Structure
Analysis Image
PE Chart Code
Header PE (light blue)
Executable sections (pink)
Non-executable sections (black)
External injected code (red)
File Structure in red = malformed or corrupted header

Chart Code For Other Files
Printable characters (blue)
Non-printable characters (black)
Information
Icon: Icon
Size: 823,24 KB
SHA-256 Hash: C8DFEDFDB3EE6C5761AC119655D522850ABD84649E13D0BF55EFA8F0AD4F7FD7
SHA-1 Hash: 1A51BD6EFD4B8DDF12FF456A54F55102FBD3F986
MD5 Hash: CF22C17CA19F7C31DBF098683D458B9C
Imphash: 3786A4CF8BFEE8B4821DB03449141DF4
MajorOSVersion: 4
MinorOSVersion: 0
CheckSum: 000DB109
EntryPoint (rva): 14B04
SizeOfHeaders: 400
SizeOfImage: 6A000
ImageBase: 400000
Architecture: x86
ImportTable: 1E9E4
IAT: 1B000
Characteristics: 10F
TimeDateStamp: 4CE553F7
Date: 18/11/2010 16:27:35
File Type: EXE
Number Of Sections: 5
ASLR: Disabled
Section Names: .text, .rdata, .data, .sxdata, .rsrc
Number Of Executable Sections: 1
Subsystem: Windows GUI

Sections Info
Section Name Flags ROffset RSize VOffset VSizeEntropyChi2
.text
0x60000020
Code
Executable
Readable
400 19A00 1000 199EA
6.6085
562936.64
.rdata
0x40000040
Initialized Data
Readable
19E00 4600 1B000 4494
4.368
1021425.66
.data
0xC0000040
Initialized Data
Readable
Writeable
1E400 3200 20000 5A48
1.3705
2489390.96
.sxdata
0xC0000240
Initialized Data
Readable
Writeable
21600 200 26000 4
0.0204
130049
.rsrc
0x40000040
Initialized Data
Readable
21800 42800 27000 4268C
5.1026
9386791.99
Description
CompanyName: Gallery Inc
LegalCopyright: Gallery Inc.
ProductName: Defender Remover
FileVersion: 12.8.4
FileDescription: Defender Remover
ProductVersion: 12.8.4
Language: English (United States) (ID=0x409)
CodePage: Unicode (UTF-16 LE) (0x4B0)

Binder/Joiner/Crypter
Dropper code detected (EOF) - 399,24 KB

Entry Point
The section number (1) - (.text) have the Entry Point
Information -> EntryPoint (calculated) - 13F04
Code -> 558BEC6AFF68E0B94100682C4A410064A100000000506489250000000083EC585356578965E8FF1574B0410033D28AD48915
Assembler
|PUSH EBP
|MOV EBP, ESP
|PUSH -1
|PUSH 0X41B9E0
|PUSH 0X414A2C
|MOV EAX, DWORD PTR FS:[0]
|PUSH EAX
|MOV DWORD PTR FS:[0], ESP
|SUB ESP, 0X58
|PUSH EBX
|PUSH ESI
|PUSH EDI
|MOV DWORD PTR [EBP - 0X18], ESP
|CALL DWORD PTR [0X41B074]
|XOR EDX, EDX
|MOV DL, AH
Signatures
CheckSum Integrity Problem:
Header: 897289
Calculated: 893749
Rich Signature Analyzer:
Code -> DDE11D579980730499807304998073041A9C7D0480807304AFA67904D980730417882C049880730499807204218073041A882E0490807304AFA67804D4807304F6F6D9049E807304F6F6ED04988073045E867504988073045269636899807304
Footprint md5 Hash -> 1ADC3947BA1A92DEB9CB5A7630F83FCD
• The Rich header apparently has not been modified
Certificate - Digital Signature Not Found:
• The file is not signed

Packer/Compiler
Compiler: Microsoft Visual C ++
Detect It Easy (die)
PE: installer: 7-Zip(-)[-]
PE: compiler: EP:Microsoft Visual C/C++(6.0 (1720-9782))[EXE32]
PE: compiler: Microsoft Visual C/C++(2010)[libcmt]
PE: archive: 7-Zip(0.4)[-]
PE: linker: Microsoft Linker(6.0*)[-]
PE: overlay: 7-zip Installer data(-)[-]
Entropy: 7.17516

Suspicious Functions
Library Function Description
KERNEL32.DLL GetModuleFileNameA Retrieve the fully qualified path for the executable file of a specified module.
KERNEL32.DLL VirtualAlloc Reserve, commit, or both, a region of memory within the virtual address space of a process.
KERNEL32.DLL WriteFile Writes data to a specified file or input/output (I/O) device.
KERNEL32.DLL LoadLibraryA Loads the specified module into the address space of the calling process.
KERNEL32.DLL GetModuleHandleA Retrieves a handle to the specified module.
KERNEL32.DLL GetProcAddress Retrieves the address of an exported function or variable from the specified dynamic-link library (DLL).
KERNEL32.DLL CreateFileA Creates or opens a file or I/O device.
KERNEL32.DLL DeleteFileA Deletes an existing file.
KERNEL32.DLL GetTempPathA Retrieves the temporary directory path.
KERNEL32.DLL CreateFileW Creates or opens a file object.
KERNEL32.DLL ReadFile Reads data from a file.
KERNEL32.DLL FindFirstFileA Starts file and directory enumeration.
KERNEL32.DLL FindNextFileA Continues file and directory enumeration.
KERNEL32.DLL FindFirstFileW Starts file and directory enumeration.
KERNEL32.DLL FindClose Closes a file search handle.
KERNEL32.DLL ExitThread Terminates the current thread.
KERNEL32.DLL CloseHandle Closes an open object handle.
KERNEL32.DLL IsBadReadPtr Checks whether memory is readable.
KERNEL32.DLL CreateProcessA Creates and starts a new process.
KERNEL32.DLL CreateEventA Creates or opens an event object.
KERNEL32.DLL GetVersion Retrieves the operating system version.
SHELL32.DLL ShellExecuteExA Performs a run operation on a specific file.
File Access
KERNEL32.dll
SHELL32.dll
USER32.dll
OLEAUT32.dll
Script_Run.bat
@.dat
;copy /b compiler.mpm + config.txt
Temp

File Access (UNICODE)
setup.exe
Can not find setup.exe
Temp

Interest's Words
exec
attrib
start

Interest's Words (UNICODE)
exec

Strings/Hex Code Found With The File Rules
Rule Type Encoding Matched (Word)
Entry Point Hex Pattern Microsoft Visual C++ 5.0
Entry Point Hex Pattern Microsoft Visual C++ v6.0
Entry Point Hex Pattern Microsoft Visual C++ v6.0
Entry Point Hex Pattern Microsoft Visual C++
Resources
Path DataRVA Size FileOffset CodeText
\ICON\1\1033 271A8 42108 219A8 2800000000010000000200000100200000000000000004000000000000000000000000000000000000000000000000000000(............. ...................................
\DIALOG\500\1033 692B0 B8 63AB0 C008C88000000000020000000000BC003C0000000000500072006F0067007200650073007300000008004D00530020005300................<.....P.r.o.g.r.e.s.s.....M.S. .S.
\STRING\1\1033 69368 94 63B68 00000000000000000000000000001100450078007400720061006300740069006F006E0020004600610069006C0065006400................E.x.t.r.a.c.t.i.o.n. .F.a.i.l.e.d.
\STRING\5\1033 693FC 34 63BFC 000000000000000000000A00450078007400720061006300740069006E0067000000000000000000000000000000000000000000............E.x.t.r.a.c.t.i.n.g.....................
\GROUP_ICON\1\1033 69430 14 63C30 0000010001000000000001002000082104000100............ ..!....
\VERSION\1\1033 69444 248 63C44 480234000000560053005F00560045005200530049004F004E005F0049004E0046004F0000000000BD04EFFE000001000800H.4...V.S._.V.E.R.S.I.O.N._.I.N.F.O...............
Intelligent String
• OLEAUT32.dll
• KERNEL32.dll
• Can not find setup.exe
• setup.exe
• .PAX
• .PAD

Flow Anomalies
Offset FlowVA Section Description
48B 41B094 .text CALL [static] | Indirect call to absolute memory address
706 41B1E4 .text CALL [static] | Indirect call to absolute memory address
9DF 41B1E4 .text CALL [static] | Indirect call to absolute memory address
AD7 41B19C .text CALL [static] | Indirect call to absolute memory address
C89 41B08C .text CALL [static] | Indirect call to absolute memory address
D40 41B088 .text CALL [static] | Indirect call to absolute memory address
D65 41B084 .text CALL [static] | Indirect call to absolute memory address
D6E 41B088 .text CALL [static] | Indirect call to absolute memory address
E6B 41B098 .text CALL [static] | Indirect call to absolute memory address
1B26 41B0A0 .text CALL [static] | Indirect call to absolute memory address
1B49 41B09C .text CALL [static] | Indirect call to absolute memory address
1B87 41B0A0 .text CALL [static] | Indirect call to absolute memory address
1B9C 41B09C .text CALL [static] | Indirect call to absolute memory address
2185 41B0A0 .text CALL [static] | Indirect call to absolute memory address
218F 41B09C .text CALL [static] | Indirect call to absolute memory address
24FB 41B1E0 .text CALL [static] | Indirect call to absolute memory address
2761 41B1DC .text CALL [static] | Indirect call to absolute memory address
2A51 41B1D8 .text CALL [static] | Indirect call to absolute memory address
2A5D 41B1D8 .text CALL [static] | Indirect call to absolute memory address
2AC9 41B0A4 .text CALL [static] | Indirect call to absolute memory address
2AD7 41B0A4 .text CALL [static] | Indirect call to absolute memory address
2BEC 41B1D4 .text CALL [static] | Indirect call to absolute memory address
2EC2 41B1CC .text CALL [static] | Indirect call to absolute memory address
2ECE 41B0B0 .text CALL [static] | Indirect call to absolute memory address
2EE9 41B0AC .text CALL [static] | Indirect call to absolute memory address
2F02 41B1D0 .text CALL [static] | Indirect call to absolute memory address
2F15 41B0A8 .text CALL [static] | Indirect call to absolute memory address
2FF1 41B0A8 .text CALL [static] | Indirect call to absolute memory address
30A8 41B0AC .text CALL [static] | Indirect call to absolute memory address
39BA 41B0BC .text CALL [static] | Indirect call to absolute memory address
3A18 41B0C0 .text CALL [static] | Indirect call to absolute memory address
3A63 41B0B8 .text CALL [static] | Indirect call to absolute memory address
3B08 41B0C8 .text CALL [static] | Indirect call to absolute memory address
3B23 41B0C4 .text CALL [static] | Indirect call to absolute memory address
3B5A 41B0CC .text CALL [static] | Indirect call to absolute memory address
3B75 41B0C4 .text CALL [static] | Indirect call to absolute memory address
3BF3 41B0D0 .text CALL [static] | Indirect call to absolute memory address
3C24 41B0B8 .text CALL [static] | Indirect call to absolute memory address
3C4F 41B0DC .text CALL [static] | Indirect call to absolute memory address
3C6B 41B0D8 .text CALL [static] | Indirect call to absolute memory address
3C82 41B0D4 .text CALL [static] | Indirect call to absolute memory address
3C8E 41B088 .text CALL [static] | Indirect call to absolute memory address
3C9E 41B0E0 .text CALL [static] | Indirect call to absolute memory address
3CAB 41B0E4 .text CALL [static] | Indirect call to absolute memory address
3CF1 41B0E8 .text CALL [static] | Indirect call to absolute memory address
3D20 41B0B8 .text CALL [static] | Indirect call to absolute memory address
3D80 41B0EC .text CALL [static] | Indirect call to absolute memory address
3D90 41B0F0 .text CALL [static] | Indirect call to absolute memory address
3DD0 41B0F4 .text CALL [static] | Indirect call to absolute memory address
3E6D 41B0B0 .text CALL [static] | Indirect call to absolute memory address
3FED 41B0F8 .text CALL [static] | Indirect call to absolute memory address
403C 41B0FC .text CALL [static] | Indirect call to absolute memory address
4235 41B104 .text CALL [static] | Indirect call to absolute memory address
425E 41B100 .text CALL [static] | Indirect call to absolute memory address
42C6 41B108 .text CALL [static] | Indirect call to absolute memory address
444A 41B10C .text CALL [static] | Indirect call to absolute memory address
4486 41B110 .text CALL [static] | Indirect call to absolute memory address
44CE 41B114 .text CALL [static] | Indirect call to absolute memory address
462C 41B0B0 .text CALL [static] | Indirect call to absolute memory address
4925 41B118 .text CALL [static] | Indirect call to absolute memory address
4959 41B11C .text CALL [static] | Indirect call to absolute memory address
4A11 41B120 .text CALL [static] | Indirect call to absolute memory address
4A3D 41B0B8 .text CALL [static] | Indirect call to absolute memory address
4A5E 41B11C .text CALL [static] | Indirect call to absolute memory address
4B70 41B0B8 .text CALL [static] | Indirect call to absolute memory address
4BE2 41B124 .text CALL [static] | Indirect call to absolute memory address
4D9C 41B128 .text CALL [static] | Indirect call to absolute memory address
4DDC 41B0B8 .text CALL [static] | Indirect call to absolute memory address
4E41 41B0D8 .text CALL [static] | Indirect call to absolute memory address
4E6E 41B088 .text CALL [static] | Indirect call to absolute memory address
4E8E 41B12C .text CALL [static] | Indirect call to absolute memory address
4E9B 41B0B0 .text CALL [static] | Indirect call to absolute memory address
4EE9 41B130 .text CALL [static] | Indirect call to absolute memory address
4EF7 41B0B0 .text CALL [static] | Indirect call to absolute memory address
4F91 41B134 .text CALL [static] | Indirect call to absolute memory address
5068 41B0D4 .text CALL [static] | Indirect call to absolute memory address
50AA 41B138 .text CALL [static] | Indirect call to absolute memory address
50C3 41B13C .text CALL [static] | Indirect call to absolute memory address
5171 41B194 .text CALL [static] | Indirect call to absolute memory address
525B 41B190 .text CALL [static] | Indirect call to absolute memory address
5312 41B1C8 .text CALL [static] | Indirect call to absolute memory address
53BC 41B1C4 .text CALL [static] | Indirect call to absolute memory address
5466 41B1BC .text CALL [static] | Indirect call to absolute memory address
548E 41B1F0 .text CALL [static] | Indirect call to absolute memory address
55B4 41B1B4 .text CALL [static] | Indirect call to absolute memory address
55C0 41B1B8 .text CALL [static] | Indirect call to absolute memory address
5638 41B1AC .text CALL [static] | Indirect call to absolute memory address
56AA 41B1B0 .text CALL [static] | Indirect call to absolute memory address
593B 41B0B0 .text CALL [static] | Indirect call to absolute memory address
5975 41B140 .text CALL [static] | Indirect call to absolute memory address
597C 41B134 .text CALL [static] | Indirect call to absolute memory address
5994 41B0B0 .text CALL [static] | Indirect call to absolute memory address
64A9 41B0A0 .text CALL [static] | Indirect call to absolute memory address
64DD 41B09C .text CALL [static] | Indirect call to absolute memory address
64F7 41B09C .text CALL [static] | Indirect call to absolute memory address
6A5E 41B144 .text CALL [static] | Indirect call to absolute memory address
6F3C 41B0B0 .text CALL [static] | Indirect call to absolute memory address
7D94 41B0B0 .text CALL [static] | Indirect call to absolute memory address
83D3 41B0B0 .text CALL [static] | Indirect call to absolute memory address
89CA 41B148 .text CALL [static] | Indirect call to absolute memory address
64000 N/A *Overlay* 3B2140496E7374616C6C40215554462D38210D0A | ;!@Install@!UTF-8!..
Extra Analysis
Metric Value Percentage
Ascii Code 470655 55,8314%
Null Byte Code 122845 14,5725%
© 2026 All rights reserved.