PESCAN.IO - Analysis Report Basic |
|||||||
| File Structure |
|
PE Chart Code
Header PE (light blue)
Executable sections (pink)
Non-executable sections (black)
External injected code (red)
File Structure in red = malformed or corrupted header
Chart Code For Other Files
Printable characters (blue)
Non-printable characters (black)
| Information |
| Size: 112,00 KB SHA-256 Hash: 26842AE4F3E771C2D7789F14E2530C8B94FF7759B26B4E9A33732100971DA08D SHA-1 Hash: 9945458E84F99D58162BF7B6CF3968E3437C6C55 MD5 Hash: D12FCF309B936700CA3B13E5793CB518 Imphash: 8629C5DAB64CA06A0196C82DB77D0B94 MajorOSVersion: 6 MinorOSVersion: 0 CheckSum: 00000000 EntryPoint (rva): 1442 SizeOfHeaders: 400 SizeOfImage: 21000 ImageBase: 400000 Architecture: x86 ImportTable: 1A784 IAT: 14000 Characteristics: 102 TimeDateStamp: 6936C674 Date: 08/12/2025 12:37:08 File Type: EXE Number Of Sections: 6 ASLR: Enabled Section Names: .text, .rdata, .data, .fptable, .rsrc, .reloc Number Of Executable Sections: 1 Subsystem: Windows GUI UAC Execution Level Manifest: asInvoker |
| Sections Info |
| Section Name | Flags | ROffset | RSize | VOffset | VSize | Entropy | Chi2 |
|---|---|---|---|---|---|---|---|
| .text | 0x60000020 Code Executable Readable |
400 | 12C00 | 1000 | 12BC3 |
|
|
| .rdata | 0x40000040 Initialized Data Readable |
13000 | 7000 | 14000 | 6E80 |
|
|
| .data | 0xC0000040 Initialized Data Readable Writeable |
1A000 | A00 | 1B000 | 12EC |
|
|
| .fptable | 0xC0000040 Initialized Data Readable Writeable |
1AA00 | 200 | 1D000 | 80 |
|
|
| .rsrc | 0x40000040 Initialized Data Readable |
1AC00 | 200 | 1E000 | 1E0 |
|
|
| .reloc | 0x42000040 Initialized Data GP-Relative Readable |
1AE00 | 1200 | 1F000 | 106C |
|
|
| Entry Point |
The section number (1) - (.text) have the Entry Point Information -> EntryPoint (calculated) - 842 Code -> E8C8030000E977FEFFFF558BEC6A00FF153C404100FF7508FF153840410068090400C0FF154040410050FF15444041005DC3 Assembler |CALL 0X40180F |JMP 0X4012C3 |PUSH EBP |MOV EBP, ESP |PUSH 0 |CALL DWORD PTR [0X41403C] |PUSH DWORD PTR [EBP + 8] |CALL DWORD PTR [0X414038] |PUSH 0XC0000409 |CALL DWORD PTR [0X414040] |PUSH EAX |CALL DWORD PTR [0X414044] |POP EBP |RET |
| Signatures |
| Rich Signature Analyzer: Code -> C3CF37D787AE598487AE598487AE5984FE2F5A858CAE5984FE2F5C8509AE5984FE2F5D8594AE598400275A8593AE598400275D8596AE598400275C85A1AE5984FE2F588580AE598487AE5884E2AE59841327508586AE59841327A68486AE598413275B8586AE59845269636887AE5984 Footprint md5 Hash -> 12A354517393F9F1AD92872B7A2D4BB8 • The Rich header apparently has not been modified Certificate - Digital Signature Not Found: • The file is not signed |
| Packer/Compiler |
| Compiler: Microsoft Visual Studio Detect It Easy (die) • PE: compiler: EP:Microsoft Visual C/C++(2017 v.15.5-6)[EXE32] • PE: compiler: Microsoft Visual C/C++(-)[-] • PE: linker: Microsoft Linker(14.44**)[-] • Entropy: 6.42963 |
| Suspicious Functions |
| Library | Function | Description |
|---|---|---|
| KERNEL32.DLL | WriteFile | Writes data to a specified file or input/output (I/O) device. |
| KERNEL32.DLL | LoadLibraryW | Loads the specified module into the address space of the calling process. |
| KERNEL32.DLL | GetModuleHandleW | Retrieves a handle to the specified module. |
| KERNEL32.DLL | GetProcAddress | Retrieves the address of an exported function or variable from the specified dynamic-link library (DLL). |
| KERNEL32.DLL | IsDebuggerPresent | Determines if the calling process is being debugged by a user-mode debugger. |
| KERNEL32.DLL | CreateFileW | Creates or opens a file object. |
| KERNEL32.DLL | FindNextFileW | Continues file and directory enumeration. |
| KERNEL32.DLL | FindClose | Closes a file search handle. |
| KERNEL32.DLL | CloseHandle | Closes an open object handle. |
| KERNEL32.DLL | VirtualProtect | Changes memory protection attributes. |
| KERNEL32.DLL | CreateProcessW | Creates and starts a new process. |
| SHELL32.DLL | ShellExecuteW | Performs a run operation on a specific file. |
| File Access |
| SHELL32.dll KERNEL32.dll .dat @.dat |
| File Access (UNICODE) |
| onis.exe Pixray.exe api-ms-win-crt-runtime-l1-1-0.dll mscoree.dll |
| Interest's Words |
| exec start |
| Strings/Hex Code Found With The File Rules |
| Rule Type | Encoding | Matched (Word) |
|---|---|---|
| Hex | Hex Pattern | PEB AntiDebug (Flag BeingDebugged) |
| Entry Point | Hex Pattern | Microsoft Visual C++ 8 |
| Entry Point | Hex Pattern | Microsoft Visual C++ 8 |
| Entry Point | Hex Pattern | Microsoft Visual C++ v7.0 |
| Entry Point | Hex Pattern | PE-Exe Executable Image |
| Entry Point | Hex Pattern | VC8 - Microsoft Corporation |
| Resources |
| Path | DataRVA | Size | FileOffset | Code | Text |
|---|---|---|---|---|---|
| \24\1\1033 | 1E060 | 17D | 1AC60 | 3C3F786D6C2076657273696F6E3D27312E302720656E636F64696E673D275554462D3827207374616E64616C6F6E653D2779 | <?xml version=’1.0’ encoding=’UTF-8’ standalone=’y |
| Intelligent String |
| • mscoree.dll • api-ms-win-crt-runtime-l1-1-0.dll • Pixray.exe • onis.exe • C:\Users\m.bakhtvar\source\repos\Pixray\Release\Startup.pdb • .bss • KERNEL32.dll |
| Flow Anomalies |
| Offset | FlowVA | Section | Description |
|---|---|---|---|
| 49A | 41400C | .text | CALL [static] | Indirect call to absolute memory address |
| 4A9 | 41401C | .text | CALL [static] | Indirect call to absolute memory address |
| 51D | 414014 | .text | CALL [static] | Indirect call to absolute memory address |
| 527 | 414004 | .text | CALL [static] | Indirect call to absolute memory address |
| 54E | 414000 | .text | CALL [static] | Indirect call to absolute memory address |
| 55D | 414020 | .text | CALL [static] | Indirect call to absolute memory address |
| 567 | 414004 | .text | CALL [static] | Indirect call to absolute memory address |
| 5D6 | 414130 | .text | CALL [static] | Indirect call to absolute memory address |
| 77E | 414138 | .text | CALL [static] | Indirect call to absolute memory address |
| 851 | 41403C | .text | CALL [static] | Indirect call to absolute memory address |
| 85A | 414038 | .text | CALL [static] | Indirect call to absolute memory address |
| 865 | 414040 | .text | CALL [static] | Indirect call to absolute memory address |
| 86C | 414044 | .text | CALL [static] | Indirect call to absolute memory address |
| 87F | 414048 | .text | CALL [static] | Indirect call to absolute memory address |
| BD4 | 414058 | .text | CALL [static] | Indirect call to absolute memory address |
| BE3 | 414054 | .text | CALL [static] | Indirect call to absolute memory address |
| BEC | 414050 | .text | CALL [static] | Indirect call to absolute memory address |
| BF9 | 41404C | .text | CALL [static] | Indirect call to absolute memory address |
| C6C | 41405C | .text | CALL [static] | Indirect call to absolute memory address |
| CE1 | 414048 | .text | CALL [static] | Indirect call to absolute memory address |
| DAD | 414060 | .text | CALL [static] | Indirect call to absolute memory address |
| DC6 | 41403C | .text | CALL [static] | Indirect call to absolute memory address |
| DD0 | 414038 | .text | CALL [static] | Indirect call to absolute memory address |
| E04 | 414064 | .text | CALL [static] | Indirect call to absolute memory address |
| E21 | 414018 | .text | CALL [static] | Indirect call to absolute memory address |
| E66 | 41403C | .text | CALL [static] | Indirect call to absolute memory address |
| EE7 | 414138 | .text | CALL [static] | Indirect call to absolute memory address |
| F13 | 414138 | .text | CALL [static] | Indirect call to absolute memory address |
| F8E | 414048 | .text | CALL [static] | Indirect call to absolute memory address |
| 13EC | 414138 | .text | CALL [static] | Indirect call to absolute memory address |
| 1540 | 414138 | .text | CALL [static] | Indirect call to absolute memory address |
| 191F | 414068 | .text | CALL [static] | Indirect call to absolute memory address |
| 19AF | 414004 | .text | CALL [static] | Indirect call to absolute memory address |
| 1A28 | 41406C | .text | CALL [static] | Indirect call to absolute memory address |
| 1AD6 | 414078 | .text | CALL [static] | Indirect call to absolute memory address |
| 1BA6 | 41401C | .text | CALL [static] | Indirect call to absolute memory address |
| 1BB0 | 414010 | .text | CALL [static] | Indirect call to absolute memory address |
| 1BD0 | 414090 | .text | CALL [static] | Indirect call to absolute memory address |
| 1BDA | 414004 | .text | CALL [static] | Indirect call to absolute memory address |
| 1C02 | 414090 | .text | CALL [static] | Indirect call to absolute memory address |
| 1C36 | 414138 | .text | CALL [static] | Indirect call to absolute memory address |
| 1C43 | 414080 | .text | JMP [static] | Indirect jump to absolute memory address |
| 1C71 | 414138 | .text | CALL [static] | Indirect call to absolute memory address |
| 1C7B | 41408C | .text | CALL [static] | Indirect call to absolute memory address |
| 1CAC | 414138 | .text | CALL [static] | Indirect call to absolute memory address |
| 1CB6 | 414084 | .text | CALL [static] | Indirect call to absolute memory address |
| 1CEA | 414138 | .text | CALL [static] | Indirect call to absolute memory address |
| 1CF4 | 414088 | .text | CALL [static] | Indirect call to absolute memory address |
| 1D2B | 414138 | .text | CALL [static] | Indirect call to absolute memory address |
| 1D3B | 41407C | .text | CALL [static] | Indirect call to absolute memory address |
| 1F66 | 414068 | .text | CALL [static] | Indirect call to absolute memory address |
| 26E3 | 414138 | .text | CALL [static] | Indirect call to absolute memory address |
| 2CA7 | 414094 | .text | CALL [static] | Indirect call to absolute memory address |
| 2F17 | 414138 | .text | CALL [static] | Indirect call to absolute memory address |
| 34AB | 414138 | .text | CALL [static] | Indirect call to absolute memory address |
| 3599 | 414138 | .text | CALL [static] | Indirect call to absolute memory address |
| 35CA | 414098 | .text | CALL [static] | Indirect call to absolute memory address |
| 36E1 | 414078 | .text | CALL [static] | Indirect call to absolute memory address |
| 3710 | 414070 | .text | CALL [static] | Indirect call to absolute memory address |
| 3724 | 414074 | .text | CALL [static] | Indirect call to absolute memory address |
| 453A | 414004 | .text | CALL [static] | Indirect call to absolute memory address |
| 456F | 41406C | .text | CALL [static] | Indirect call to absolute memory address |
| 458E | 414004 | .text | CALL [static] | Indirect call to absolute memory address |
| 45C4 | 41406C | .text | CALL [static] | Indirect call to absolute memory address |
| 56F4 | 414138 | .text | CALL [static] | Indirect call to absolute memory address |
| 570D | 414138 | .text | CALL [static] | Indirect call to absolute memory address |
| 579B | 414138 | .text | CALL [static] | Indirect call to absolute memory address |
| 5D48 | 414138 | .text | CALL [static] | Indirect call to absolute memory address |
| 5D70 | 414138 | .text | CALL [static] | Indirect call to absolute memory address |
| 5E63 | 414138 | .text | CALL [static] | Indirect call to absolute memory address |
| 5FC5 | 414040 | .text | CALL [static] | Indirect call to absolute memory address |
| 5FCC | 414044 | .text | CALL [static] | Indirect call to absolute memory address |
| 5FDE | 4140A8 | .text | CALL [static] | Indirect call to absolute memory address |
| 601A | 4140AC | .text | CALL [static] | Indirect call to absolute memory address |
| 602C | 414010 | .text | CALL [static] | Indirect call to absolute memory address |
| 603D | 414138 | .text | CALL [static] | Indirect call to absolute memory address |
| 604E | 41401C | .text | CALL [static] | Indirect call to absolute memory address |
| 64AC | 414138 | .text | CALL [static] | Indirect call to absolute memory address |
| 679A | 414138 | .text | CALL [static] | Indirect call to absolute memory address |
| 686B | 414048 | .text | CALL [static] | Indirect call to absolute memory address |
| 6974 | 414138 | .text | JMP [static] | Indirect jump to absolute memory address |
| 6985 | 414004 | .text | CALL [static] | Indirect call to absolute memory address |
| 6994 | 41406C | .text | CALL [static] | Indirect call to absolute memory address |
| 6A9B | 414060 | .text | CALL [static] | Indirect call to absolute memory address |
| 6AA5 | 41403C | .text | CALL [static] | Indirect call to absolute memory address |
| 6AB2 | 414038 | .text | CALL [static] | Indirect call to absolute memory address |
| 6B58 | 414138 | .text | CALL [static] | Indirect call to absolute memory address |
| 6BB1 | 414048 | .text | CALL [static] | Indirect call to absolute memory address |
| 6BD4 | 414040 | .text | CALL [static] | Indirect call to absolute memory address |
| 6BDB | 414044 | .text | CALL [static] | Indirect call to absolute memory address |
| 6D84 | 4140B0 | .text | CALL [static] | Indirect call to absolute memory address |
| 6DB6 | 4140B4 | .text | CALL [static] | Indirect call to absolute memory address |
| 6DC1 | 414004 | .text | CALL [static] | Indirect call to absolute memory address |
| 6ECF | 4140CC | .text | CALL [static] | Indirect call to absolute memory address |
| 6EF7 | 4140CC | .text | CALL [static] | Indirect call to absolute memory address |
| 6F19 | 41401C | .text | CALL [static] | Indirect call to absolute memory address |
| 6F23 | 414010 | .text | CALL [static] | Indirect call to absolute memory address |
| 6F42 | 414090 | .text | CALL [static] | Indirect call to absolute memory address |
| 6F4C | 414004 | .text | CALL [static] | Indirect call to absolute memory address |
| 6F8A | 414090 | .text | CALL [static] | Indirect call to absolute memory address |
| 847 | 4012C3 | .text | Entry Point Backward Redirect | Score=1/7 - Redirects=1 - PreJumpInstructions=1 - JumpType=JMP_NEAR - TargetOffset=0x6C3 - TargetSection=.text - Confidence=Low |
| Extra Analysis |
| Metric | Value | Percentage |
|---|---|---|
| Ascii Code | 64176 | 55,957% |
| Null Byte Code | 23376 | 20,3823% |
© 2026 All rights reserved.