PESCAN.IO - Analysis Report Basic |
|||||||
| File Structure |
|
PE Chart Code
Header PE (light blue)
Executable sections (pink)
Non-executable sections (black)
External injected code (red)
File Structure in red = malformed or corrupted header
Chart Code For Other Files
Printable characters (blue)
Non-printable characters (black)
| Information |
Icon: Size: 823,24 KBSHA-256 Hash: C8DFEDFDB3EE6C5761AC119655D522850ABD84649E13D0BF55EFA8F0AD4F7FD7 SHA-1 Hash: 1A51BD6EFD4B8DDF12FF456A54F55102FBD3F986 MD5 Hash: CF22C17CA19F7C31DBF098683D458B9C Imphash: 3786A4CF8BFEE8B4821DB03449141DF4 MajorOSVersion: 4 MinorOSVersion: 0 CheckSum: 000DB109 EntryPoint (rva): 14B04 SizeOfHeaders: 400 SizeOfImage: 6A000 ImageBase: 400000 Architecture: x86 ImportTable: 1E9E4 IAT: 1B000 Characteristics: 10F TimeDateStamp: 4CE553F7 Date: 18/11/2010 16:27:35 File Type: EXE Number Of Sections: 5 ASLR: Disabled Section Names: .text, .rdata, .data, .sxdata, .rsrc Number Of Executable Sections: 1 Subsystem: Windows GUI |
| Sections Info |
| Section Name | Flags | ROffset | RSize | VOffset | VSize | Entropy | Chi2 |
|---|---|---|---|---|---|---|---|
| .text | 0x60000020 Code Executable Readable |
400 | 19A00 | 1000 | 199EA |
|
|
| .rdata | 0x40000040 Initialized Data Readable |
19E00 | 4600 | 1B000 | 4494 |
|
|
| .data | 0xC0000040 Initialized Data Readable Writeable |
1E400 | 3200 | 20000 | 5A48 |
|
|
| .sxdata | 0xC0000240 Initialized Data Readable Writeable |
21600 | 200 | 26000 | 4 |
|
|
| .rsrc | 0x40000040 Initialized Data Readable |
21800 | 42800 | 27000 | 4268C |
|
|
| Description |
| CompanyName: Gallery Inc LegalCopyright: Gallery Inc. ProductName: Defender Remover FileVersion: 12.8.4 FileDescription: Defender Remover ProductVersion: 12.8.4 Language: English (United States) (ID=0x409) CodePage: Unicode (UTF-16 LE) (0x4B0) |
| Binder/Joiner/Crypter |
| Dropper code detected (EOF) - 399,24 KB |
| Entry Point |
The section number (1) - (.text) have the Entry Point Information -> EntryPoint (calculated) - 13F04 Code -> 558BEC6AFF68E0B94100682C4A410064A100000000506489250000000083EC585356578965E8FF1574B0410033D28AD48915 Assembler |PUSH EBP |MOV EBP, ESP |PUSH -1 |PUSH 0X41B9E0 |PUSH 0X414A2C |MOV EAX, DWORD PTR FS:[0] |PUSH EAX |MOV DWORD PTR FS:[0], ESP |SUB ESP, 0X58 |PUSH EBX |PUSH ESI |PUSH EDI |MOV DWORD PTR [EBP - 0X18], ESP |CALL DWORD PTR [0X41B074] |XOR EDX, EDX |MOV DL, AH |
| Signatures |
| CheckSum Integrity Problem: • Header: 897289 • Calculated: 893749 Rich Signature Analyzer: Code -> DDE11D579980730499807304998073041A9C7D0480807304AFA67904D980730417882C049880730499807204218073041A882E0490807304AFA67804D4807304F6F6D9049E807304F6F6ED04988073045E867504988073045269636899807304 Footprint md5 Hash -> 1ADC3947BA1A92DEB9CB5A7630F83FCD • The Rich header apparently has not been modified Certificate - Digital Signature Not Found: • The file is not signed |
| Packer/Compiler |
| Compiler: Microsoft Visual C ++ Detect It Easy (die) • PE: installer: 7-Zip(-)[-] • PE: compiler: EP:Microsoft Visual C/C++(6.0 (1720-9782))[EXE32] • PE: compiler: Microsoft Visual C/C++(2010)[libcmt] • PE: archive: 7-Zip(0.4)[-] • PE: linker: Microsoft Linker(6.0*)[-] • PE: overlay: 7-zip Installer data(-)[-] • Entropy: 7.17516 |
| Suspicious Functions |
| Library | Function | Description |
|---|---|---|
| KERNEL32.DLL | GetModuleFileNameA | Retrieve the fully qualified path for the executable file of a specified module. |
| KERNEL32.DLL | VirtualAlloc | Reserve, commit, or both, a region of memory within the virtual address space of a process. |
| KERNEL32.DLL | WriteFile | Writes data to a specified file or input/output (I/O) device. |
| KERNEL32.DLL | LoadLibraryA | Loads the specified module into the address space of the calling process. |
| KERNEL32.DLL | GetModuleHandleA | Retrieves a handle to the specified module. |
| KERNEL32.DLL | GetProcAddress | Retrieves the address of an exported function or variable from the specified dynamic-link library (DLL). |
| KERNEL32.DLL | CreateFileA | Creates or opens a file or I/O device. |
| KERNEL32.DLL | DeleteFileA | Deletes an existing file. |
| KERNEL32.DLL | GetTempPathA | Retrieves the temporary directory path. |
| KERNEL32.DLL | CreateFileW | Creates or opens a file object. |
| KERNEL32.DLL | ReadFile | Reads data from a file. |
| KERNEL32.DLL | FindFirstFileA | Starts file and directory enumeration. |
| KERNEL32.DLL | FindNextFileA | Continues file and directory enumeration. |
| KERNEL32.DLL | FindFirstFileW | Starts file and directory enumeration. |
| KERNEL32.DLL | FindClose | Closes a file search handle. |
| KERNEL32.DLL | ExitThread | Terminates the current thread. |
| KERNEL32.DLL | CloseHandle | Closes an open object handle. |
| KERNEL32.DLL | IsBadReadPtr | Checks whether memory is readable. |
| KERNEL32.DLL | CreateProcessA | Creates and starts a new process. |
| KERNEL32.DLL | CreateEventA | Creates or opens an event object. |
| KERNEL32.DLL | GetVersion | Retrieves the operating system version. |
| SHELL32.DLL | ShellExecuteExA | Performs a run operation on a specific file. |
| File Access |
| KERNEL32.dll SHELL32.dll USER32.dll OLEAUT32.dll Script_Run.bat @.dat ;copy /b compiler.mpm + config.txt Temp |
| File Access (UNICODE) |
| setup.exe Can not find setup.exe Temp |
| Interest's Words |
| exec attrib start |
| Interest's Words (UNICODE) |
| exec |
| Strings/Hex Code Found With The File Rules |
| Rule Type | Encoding | Matched (Word) |
|---|---|---|
| Entry Point | Hex Pattern | Microsoft Visual C++ 5.0 |
| Entry Point | Hex Pattern | Microsoft Visual C++ v6.0 |
| Entry Point | Hex Pattern | Microsoft Visual C++ v6.0 |
| Entry Point | Hex Pattern | Microsoft Visual C++ |
| Resources |
| Path | DataRVA | Size | FileOffset | Code | Text |
|---|---|---|---|---|---|
| \ICON\1\1033 | 271A8 | 42108 | 219A8 | 2800000000010000000200000100200000000000000004000000000000000000000000000000000000000000000000000000 | (............. ................................... |
| \DIALOG\500\1033 | 692B0 | B8 | 63AB0 | C008C88000000000020000000000BC003C0000000000500072006F0067007200650073007300000008004D00530020005300 | ................<.....P.r.o.g.r.e.s.s.....M.S. .S. |
| \STRING\1\1033 | 69368 | 94 | 63B68 | 00000000000000000000000000001100450078007400720061006300740069006F006E0020004600610069006C0065006400 | ................E.x.t.r.a.c.t.i.o.n. .F.a.i.l.e.d. |
| \STRING\5\1033 | 693FC | 34 | 63BFC | 000000000000000000000A00450078007400720061006300740069006E0067000000000000000000000000000000000000000000 | ............E.x.t.r.a.c.t.i.n.g..................... |
| \GROUP_ICON\1\1033 | 69430 | 14 | 63C30 | 0000010001000000000001002000082104000100 | ............ ..!.... |
| \VERSION\1\1033 | 69444 | 248 | 63C44 | 480234000000560053005F00560045005200530049004F004E005F0049004E0046004F0000000000BD04EFFE000001000800 | H.4...V.S._.V.E.R.S.I.O.N._.I.N.F.O............... |
| Intelligent String |
| • OLEAUT32.dll • KERNEL32.dll • Can not find setup.exe • setup.exe • .PAX • .PAD |
| Flow Anomalies |
| Offset | FlowVA | Section | Description |
|---|---|---|---|
| 48B | 41B094 | .text | CALL [static] | Indirect call to absolute memory address |
| 706 | 41B1E4 | .text | CALL [static] | Indirect call to absolute memory address |
| 9DF | 41B1E4 | .text | CALL [static] | Indirect call to absolute memory address |
| AD7 | 41B19C | .text | CALL [static] | Indirect call to absolute memory address |
| C89 | 41B08C | .text | CALL [static] | Indirect call to absolute memory address |
| D40 | 41B088 | .text | CALL [static] | Indirect call to absolute memory address |
| D65 | 41B084 | .text | CALL [static] | Indirect call to absolute memory address |
| D6E | 41B088 | .text | CALL [static] | Indirect call to absolute memory address |
| E6B | 41B098 | .text | CALL [static] | Indirect call to absolute memory address |
| 1B26 | 41B0A0 | .text | CALL [static] | Indirect call to absolute memory address |
| 1B49 | 41B09C | .text | CALL [static] | Indirect call to absolute memory address |
| 1B87 | 41B0A0 | .text | CALL [static] | Indirect call to absolute memory address |
| 1B9C | 41B09C | .text | CALL [static] | Indirect call to absolute memory address |
| 2185 | 41B0A0 | .text | CALL [static] | Indirect call to absolute memory address |
| 218F | 41B09C | .text | CALL [static] | Indirect call to absolute memory address |
| 24FB | 41B1E0 | .text | CALL [static] | Indirect call to absolute memory address |
| 2761 | 41B1DC | .text | CALL [static] | Indirect call to absolute memory address |
| 2A51 | 41B1D8 | .text | CALL [static] | Indirect call to absolute memory address |
| 2A5D | 41B1D8 | .text | CALL [static] | Indirect call to absolute memory address |
| 2AC9 | 41B0A4 | .text | CALL [static] | Indirect call to absolute memory address |
| 2AD7 | 41B0A4 | .text | CALL [static] | Indirect call to absolute memory address |
| 2BEC | 41B1D4 | .text | CALL [static] | Indirect call to absolute memory address |
| 2EC2 | 41B1CC | .text | CALL [static] | Indirect call to absolute memory address |
| 2ECE | 41B0B0 | .text | CALL [static] | Indirect call to absolute memory address |
| 2EE9 | 41B0AC | .text | CALL [static] | Indirect call to absolute memory address |
| 2F02 | 41B1D0 | .text | CALL [static] | Indirect call to absolute memory address |
| 2F15 | 41B0A8 | .text | CALL [static] | Indirect call to absolute memory address |
| 2FF1 | 41B0A8 | .text | CALL [static] | Indirect call to absolute memory address |
| 30A8 | 41B0AC | .text | CALL [static] | Indirect call to absolute memory address |
| 39BA | 41B0BC | .text | CALL [static] | Indirect call to absolute memory address |
| 3A18 | 41B0C0 | .text | CALL [static] | Indirect call to absolute memory address |
| 3A63 | 41B0B8 | .text | CALL [static] | Indirect call to absolute memory address |
| 3B08 | 41B0C8 | .text | CALL [static] | Indirect call to absolute memory address |
| 3B23 | 41B0C4 | .text | CALL [static] | Indirect call to absolute memory address |
| 3B5A | 41B0CC | .text | CALL [static] | Indirect call to absolute memory address |
| 3B75 | 41B0C4 | .text | CALL [static] | Indirect call to absolute memory address |
| 3BF3 | 41B0D0 | .text | CALL [static] | Indirect call to absolute memory address |
| 3C24 | 41B0B8 | .text | CALL [static] | Indirect call to absolute memory address |
| 3C4F | 41B0DC | .text | CALL [static] | Indirect call to absolute memory address |
| 3C6B | 41B0D8 | .text | CALL [static] | Indirect call to absolute memory address |
| 3C82 | 41B0D4 | .text | CALL [static] | Indirect call to absolute memory address |
| 3C8E | 41B088 | .text | CALL [static] | Indirect call to absolute memory address |
| 3C9E | 41B0E0 | .text | CALL [static] | Indirect call to absolute memory address |
| 3CAB | 41B0E4 | .text | CALL [static] | Indirect call to absolute memory address |
| 3CF1 | 41B0E8 | .text | CALL [static] | Indirect call to absolute memory address |
| 3D20 | 41B0B8 | .text | CALL [static] | Indirect call to absolute memory address |
| 3D80 | 41B0EC | .text | CALL [static] | Indirect call to absolute memory address |
| 3D90 | 41B0F0 | .text | CALL [static] | Indirect call to absolute memory address |
| 3DD0 | 41B0F4 | .text | CALL [static] | Indirect call to absolute memory address |
| 3E6D | 41B0B0 | .text | CALL [static] | Indirect call to absolute memory address |
| 3FED | 41B0F8 | .text | CALL [static] | Indirect call to absolute memory address |
| 403C | 41B0FC | .text | CALL [static] | Indirect call to absolute memory address |
| 4235 | 41B104 | .text | CALL [static] | Indirect call to absolute memory address |
| 425E | 41B100 | .text | CALL [static] | Indirect call to absolute memory address |
| 42C6 | 41B108 | .text | CALL [static] | Indirect call to absolute memory address |
| 444A | 41B10C | .text | CALL [static] | Indirect call to absolute memory address |
| 4486 | 41B110 | .text | CALL [static] | Indirect call to absolute memory address |
| 44CE | 41B114 | .text | CALL [static] | Indirect call to absolute memory address |
| 462C | 41B0B0 | .text | CALL [static] | Indirect call to absolute memory address |
| 4925 | 41B118 | .text | CALL [static] | Indirect call to absolute memory address |
| 4959 | 41B11C | .text | CALL [static] | Indirect call to absolute memory address |
| 4A11 | 41B120 | .text | CALL [static] | Indirect call to absolute memory address |
| 4A3D | 41B0B8 | .text | CALL [static] | Indirect call to absolute memory address |
| 4A5E | 41B11C | .text | CALL [static] | Indirect call to absolute memory address |
| 4B70 | 41B0B8 | .text | CALL [static] | Indirect call to absolute memory address |
| 4BE2 | 41B124 | .text | CALL [static] | Indirect call to absolute memory address |
| 4D9C | 41B128 | .text | CALL [static] | Indirect call to absolute memory address |
| 4DDC | 41B0B8 | .text | CALL [static] | Indirect call to absolute memory address |
| 4E41 | 41B0D8 | .text | CALL [static] | Indirect call to absolute memory address |
| 4E6E | 41B088 | .text | CALL [static] | Indirect call to absolute memory address |
| 4E8E | 41B12C | .text | CALL [static] | Indirect call to absolute memory address |
| 4E9B | 41B0B0 | .text | CALL [static] | Indirect call to absolute memory address |
| 4EE9 | 41B130 | .text | CALL [static] | Indirect call to absolute memory address |
| 4EF7 | 41B0B0 | .text | CALL [static] | Indirect call to absolute memory address |
| 4F91 | 41B134 | .text | CALL [static] | Indirect call to absolute memory address |
| 5068 | 41B0D4 | .text | CALL [static] | Indirect call to absolute memory address |
| 50AA | 41B138 | .text | CALL [static] | Indirect call to absolute memory address |
| 50C3 | 41B13C | .text | CALL [static] | Indirect call to absolute memory address |
| 5171 | 41B194 | .text | CALL [static] | Indirect call to absolute memory address |
| 525B | 41B190 | .text | CALL [static] | Indirect call to absolute memory address |
| 5312 | 41B1C8 | .text | CALL [static] | Indirect call to absolute memory address |
| 53BC | 41B1C4 | .text | CALL [static] | Indirect call to absolute memory address |
| 5466 | 41B1BC | .text | CALL [static] | Indirect call to absolute memory address |
| 548E | 41B1F0 | .text | CALL [static] | Indirect call to absolute memory address |
| 55B4 | 41B1B4 | .text | CALL [static] | Indirect call to absolute memory address |
| 55C0 | 41B1B8 | .text | CALL [static] | Indirect call to absolute memory address |
| 5638 | 41B1AC | .text | CALL [static] | Indirect call to absolute memory address |
| 56AA | 41B1B0 | .text | CALL [static] | Indirect call to absolute memory address |
| 593B | 41B0B0 | .text | CALL [static] | Indirect call to absolute memory address |
| 5975 | 41B140 | .text | CALL [static] | Indirect call to absolute memory address |
| 597C | 41B134 | .text | CALL [static] | Indirect call to absolute memory address |
| 5994 | 41B0B0 | .text | CALL [static] | Indirect call to absolute memory address |
| 64A9 | 41B0A0 | .text | CALL [static] | Indirect call to absolute memory address |
| 64DD | 41B09C | .text | CALL [static] | Indirect call to absolute memory address |
| 64F7 | 41B09C | .text | CALL [static] | Indirect call to absolute memory address |
| 6A5E | 41B144 | .text | CALL [static] | Indirect call to absolute memory address |
| 6F3C | 41B0B0 | .text | CALL [static] | Indirect call to absolute memory address |
| 7D94 | 41B0B0 | .text | CALL [static] | Indirect call to absolute memory address |
| 83D3 | 41B0B0 | .text | CALL [static] | Indirect call to absolute memory address |
| 89CA | 41B148 | .text | CALL [static] | Indirect call to absolute memory address |
| 64000 | N/A | *Overlay* | 3B2140496E7374616C6C40215554462D38210D0A | ;!@Install@!UTF-8!.. |
| Extra Analysis |
| Metric | Value | Percentage |
|---|---|---|
| Ascii Code | 470655 | 55,8314% |
| Null Byte Code | 122845 | 14,5725% |
© 2026 All rights reserved.