PESCAN.IO - Analysis Report Basic

File Structure
Analysis Image
PE Chart Code
Header PE (light blue)
Executable sections (pink)
Non-executable sections (black)
External injected code (red)
File Structure in red = malformed or corrupted header

Chart Code For Other Files
Printable characters (blue)
Non-printable characters (black)
Information
Size: 112,00 KB
SHA-256 Hash: 26842AE4F3E771C2D7789F14E2530C8B94FF7759B26B4E9A33732100971DA08D
SHA-1 Hash: 9945458E84F99D58162BF7B6CF3968E3437C6C55
MD5 Hash: D12FCF309B936700CA3B13E5793CB518
Imphash: 8629C5DAB64CA06A0196C82DB77D0B94
MajorOSVersion: 6
MinorOSVersion: 0
CheckSum: 00000000
EntryPoint (rva): 1442
SizeOfHeaders: 400
SizeOfImage: 21000
ImageBase: 400000
Architecture: x86
ImportTable: 1A784
IAT: 14000
Characteristics: 102
TimeDateStamp: 6936C674
Date: 08/12/2025 12:37:08
File Type: EXE
Number Of Sections: 6
ASLR: Enabled
Section Names: .text, .rdata, .data, .fptable, .rsrc, .reloc
Number Of Executable Sections: 1
Subsystem: Windows GUI
UAC Execution Level Manifest: asInvoker

Sections Info
Section Name Flags ROffset RSize VOffset VSizeEntropyChi2
.text
0x60000020
Code
Executable
Readable
400 12C00 1000 12BC3
6.6391
394219.18
.rdata
0x40000040
Initialized Data
Readable
13000 7000 14000 6E80
5.1154
1298892.34
.data
0xC0000040
Initialized Data
Readable
Writeable
1A000 A00 1B000 12EC
2.0902
389543.4
.fptable
0xC0000040
Initialized Data
Readable
Writeable
1AA00 200 1D000 80
0
130560
.rsrc
0x40000040
Initialized Data
Readable
1AC00 200 1E000 1E0
4.7101
9297
.reloc
0x42000040
Initialized Data
GP-Relative
Readable
1AE00 1200 1F000 106C
6.2779
34156.44
Entry Point
The section number (1) - (.text) have the Entry Point
Information -> EntryPoint (calculated) - 842
Code -> E8C8030000E977FEFFFF558BEC6A00FF153C404100FF7508FF153840410068090400C0FF154040410050FF15444041005DC3
Assembler
|CALL 0X40180F
|JMP 0X4012C3
|PUSH EBP
|MOV EBP, ESP
|PUSH 0
|CALL DWORD PTR [0X41403C]
|PUSH DWORD PTR [EBP + 8]
|CALL DWORD PTR [0X414038]
|PUSH 0XC0000409
|CALL DWORD PTR [0X414040]
|PUSH EAX
|CALL DWORD PTR [0X414044]
|POP EBP
|RET
Signatures
Rich Signature Analyzer:
Code -> C3CF37D787AE598487AE598487AE5984FE2F5A858CAE5984FE2F5C8509AE5984FE2F5D8594AE598400275A8593AE598400275D8596AE598400275C85A1AE5984FE2F588580AE598487AE5884E2AE59841327508586AE59841327A68486AE598413275B8586AE59845269636887AE5984
Footprint md5 Hash -> 12A354517393F9F1AD92872B7A2D4BB8
• The Rich header apparently has not been modified
Certificate - Digital Signature Not Found:
• The file is not signed

Packer/Compiler
Compiler: Microsoft Visual Studio
Detect It Easy (die)
PE: compiler: EP:Microsoft Visual C/C++(2017 v.15.5-6)[EXE32]
PE: compiler: Microsoft Visual C/C++(-)[-]
PE: linker: Microsoft Linker(14.44**)[-]
Entropy: 6.42963

Suspicious Functions
Library Function Description
KERNEL32.DLL WriteFile Writes data to a specified file or input/output (I/O) device.
KERNEL32.DLL LoadLibraryW Loads the specified module into the address space of the calling process.
KERNEL32.DLL GetModuleHandleW Retrieves a handle to the specified module.
KERNEL32.DLL GetProcAddress Retrieves the address of an exported function or variable from the specified dynamic-link library (DLL).
KERNEL32.DLL IsDebuggerPresent Determines if the calling process is being debugged by a user-mode debugger.
KERNEL32.DLL CreateFileW Creates or opens a file object.
KERNEL32.DLL FindNextFileW Continues file and directory enumeration.
KERNEL32.DLL FindClose Closes a file search handle.
KERNEL32.DLL CloseHandle Closes an open object handle.
KERNEL32.DLL VirtualProtect Changes memory protection attributes.
KERNEL32.DLL CreateProcessW Creates and starts a new process.
SHELL32.DLL ShellExecuteW Performs a run operation on a specific file.
File Access
SHELL32.dll
KERNEL32.dll
.dat
@.dat

File Access (UNICODE)
onis.exe
Pixray.exe
api-ms-win-crt-runtime-l1-1-0.dll
mscoree.dll

Interest's Words
exec
start

Strings/Hex Code Found With The File Rules
Rule Type Encoding Matched (Word)
Hex Hex Pattern PEB AntiDebug (Flag BeingDebugged)
Entry Point Hex Pattern Microsoft Visual C++ 8
Entry Point Hex Pattern Microsoft Visual C++ 8
Entry Point Hex Pattern Microsoft Visual C++ v7.0
Entry Point Hex Pattern PE-Exe Executable Image
Entry Point Hex Pattern VC8 - Microsoft Corporation
Resources
Path DataRVA Size FileOffset CodeText
\24\1\1033 1E060 17D 1AC60 3C3F786D6C2076657273696F6E3D27312E302720656E636F64696E673D275554462D3827207374616E64616C6F6E653D2779<?xml version=’1.0’ encoding=’UTF-8’ standalone=’y
Intelligent String
• mscoree.dll
• api-ms-win-crt-runtime-l1-1-0.dll
• Pixray.exe
• onis.exe
• C:\Users\m.bakhtvar\source\repos\Pixray\Release\Startup.pdb
• .bss
• KERNEL32.dll

Flow Anomalies
Offset FlowVA Section Description
49A 41400C .text CALL [static] | Indirect call to absolute memory address
4A9 41401C .text CALL [static] | Indirect call to absolute memory address
51D 414014 .text CALL [static] | Indirect call to absolute memory address
527 414004 .text CALL [static] | Indirect call to absolute memory address
54E 414000 .text CALL [static] | Indirect call to absolute memory address
55D 414020 .text CALL [static] | Indirect call to absolute memory address
567 414004 .text CALL [static] | Indirect call to absolute memory address
5D6 414130 .text CALL [static] | Indirect call to absolute memory address
77E 414138 .text CALL [static] | Indirect call to absolute memory address
851 41403C .text CALL [static] | Indirect call to absolute memory address
85A 414038 .text CALL [static] | Indirect call to absolute memory address
865 414040 .text CALL [static] | Indirect call to absolute memory address
86C 414044 .text CALL [static] | Indirect call to absolute memory address
87F 414048 .text CALL [static] | Indirect call to absolute memory address
BD4 414058 .text CALL [static] | Indirect call to absolute memory address
BE3 414054 .text CALL [static] | Indirect call to absolute memory address
BEC 414050 .text CALL [static] | Indirect call to absolute memory address
BF9 41404C .text CALL [static] | Indirect call to absolute memory address
C6C 41405C .text CALL [static] | Indirect call to absolute memory address
CE1 414048 .text CALL [static] | Indirect call to absolute memory address
DAD 414060 .text CALL [static] | Indirect call to absolute memory address
DC6 41403C .text CALL [static] | Indirect call to absolute memory address
DD0 414038 .text CALL [static] | Indirect call to absolute memory address
E04 414064 .text CALL [static] | Indirect call to absolute memory address
E21 414018 .text CALL [static] | Indirect call to absolute memory address
E66 41403C .text CALL [static] | Indirect call to absolute memory address
EE7 414138 .text CALL [static] | Indirect call to absolute memory address
F13 414138 .text CALL [static] | Indirect call to absolute memory address
F8E 414048 .text CALL [static] | Indirect call to absolute memory address
13EC 414138 .text CALL [static] | Indirect call to absolute memory address
1540 414138 .text CALL [static] | Indirect call to absolute memory address
191F 414068 .text CALL [static] | Indirect call to absolute memory address
19AF 414004 .text CALL [static] | Indirect call to absolute memory address
1A28 41406C .text CALL [static] | Indirect call to absolute memory address
1AD6 414078 .text CALL [static] | Indirect call to absolute memory address
1BA6 41401C .text CALL [static] | Indirect call to absolute memory address
1BB0 414010 .text CALL [static] | Indirect call to absolute memory address
1BD0 414090 .text CALL [static] | Indirect call to absolute memory address
1BDA 414004 .text CALL [static] | Indirect call to absolute memory address
1C02 414090 .text CALL [static] | Indirect call to absolute memory address
1C36 414138 .text CALL [static] | Indirect call to absolute memory address
1C43 414080 .text JMP [static] | Indirect jump to absolute memory address
1C71 414138 .text CALL [static] | Indirect call to absolute memory address
1C7B 41408C .text CALL [static] | Indirect call to absolute memory address
1CAC 414138 .text CALL [static] | Indirect call to absolute memory address
1CB6 414084 .text CALL [static] | Indirect call to absolute memory address
1CEA 414138 .text CALL [static] | Indirect call to absolute memory address
1CF4 414088 .text CALL [static] | Indirect call to absolute memory address
1D2B 414138 .text CALL [static] | Indirect call to absolute memory address
1D3B 41407C .text CALL [static] | Indirect call to absolute memory address
1F66 414068 .text CALL [static] | Indirect call to absolute memory address
26E3 414138 .text CALL [static] | Indirect call to absolute memory address
2CA7 414094 .text CALL [static] | Indirect call to absolute memory address
2F17 414138 .text CALL [static] | Indirect call to absolute memory address
34AB 414138 .text CALL [static] | Indirect call to absolute memory address
3599 414138 .text CALL [static] | Indirect call to absolute memory address
35CA 414098 .text CALL [static] | Indirect call to absolute memory address
36E1 414078 .text CALL [static] | Indirect call to absolute memory address
3710 414070 .text CALL [static] | Indirect call to absolute memory address
3724 414074 .text CALL [static] | Indirect call to absolute memory address
453A 414004 .text CALL [static] | Indirect call to absolute memory address
456F 41406C .text CALL [static] | Indirect call to absolute memory address
458E 414004 .text CALL [static] | Indirect call to absolute memory address
45C4 41406C .text CALL [static] | Indirect call to absolute memory address
56F4 414138 .text CALL [static] | Indirect call to absolute memory address
570D 414138 .text CALL [static] | Indirect call to absolute memory address
579B 414138 .text CALL [static] | Indirect call to absolute memory address
5D48 414138 .text CALL [static] | Indirect call to absolute memory address
5D70 414138 .text CALL [static] | Indirect call to absolute memory address
5E63 414138 .text CALL [static] | Indirect call to absolute memory address
5FC5 414040 .text CALL [static] | Indirect call to absolute memory address
5FCC 414044 .text CALL [static] | Indirect call to absolute memory address
5FDE 4140A8 .text CALL [static] | Indirect call to absolute memory address
601A 4140AC .text CALL [static] | Indirect call to absolute memory address
602C 414010 .text CALL [static] | Indirect call to absolute memory address
603D 414138 .text CALL [static] | Indirect call to absolute memory address
604E 41401C .text CALL [static] | Indirect call to absolute memory address
64AC 414138 .text CALL [static] | Indirect call to absolute memory address
679A 414138 .text CALL [static] | Indirect call to absolute memory address
686B 414048 .text CALL [static] | Indirect call to absolute memory address
6974 414138 .text JMP [static] | Indirect jump to absolute memory address
6985 414004 .text CALL [static] | Indirect call to absolute memory address
6994 41406C .text CALL [static] | Indirect call to absolute memory address
6A9B 414060 .text CALL [static] | Indirect call to absolute memory address
6AA5 41403C .text CALL [static] | Indirect call to absolute memory address
6AB2 414038 .text CALL [static] | Indirect call to absolute memory address
6B58 414138 .text CALL [static] | Indirect call to absolute memory address
6BB1 414048 .text CALL [static] | Indirect call to absolute memory address
6BD4 414040 .text CALL [static] | Indirect call to absolute memory address
6BDB 414044 .text CALL [static] | Indirect call to absolute memory address
6D84 4140B0 .text CALL [static] | Indirect call to absolute memory address
6DB6 4140B4 .text CALL [static] | Indirect call to absolute memory address
6DC1 414004 .text CALL [static] | Indirect call to absolute memory address
6ECF 4140CC .text CALL [static] | Indirect call to absolute memory address
6EF7 4140CC .text CALL [static] | Indirect call to absolute memory address
6F19 41401C .text CALL [static] | Indirect call to absolute memory address
6F23 414010 .text CALL [static] | Indirect call to absolute memory address
6F42 414090 .text CALL [static] | Indirect call to absolute memory address
6F4C 414004 .text CALL [static] | Indirect call to absolute memory address
6F8A 414090 .text CALL [static] | Indirect call to absolute memory address
847 4012C3 .text Entry Point Backward Redirect | Score=1/7 - Redirects=1 - PreJumpInstructions=1 - JumpType=JMP_NEAR - TargetOffset=0x6C3 - TargetSection=.text - Confidence=Low
Extra Analysis
Metric Value Percentage
Ascii Code 64176 55,957%
Null Byte Code 23376 20,3823%
© 2026 All rights reserved.