PREMIUM PESCAN.IO - Analysis Report

File Structure
Analysis Image
PE Chart Code
Header PE (light blue)
Executable sections (pink)
Non-executable sections (black)
External injected code (red)
File Structure in red = malformed or corrupted header

Chart Code For Other Files
Printable characters (blue)
Non-printable characters (black)
Information
Size: 20,00 KB
SHA-256 Hash: 5C1C6EC40D70B1E67B864C8A55C7AD9C2384FF4B34FB52BA0509BD31311CD730
SHA-1 Hash: 462E81AFCC42D81D8EB3EFE990D73AA8880BDF82
MD5 Hash: DB0BFC75DD4B63EA35F103186E35C648
Imphash: E2CCA75642339E3ECB426E4D7786BBB8
MajorOSVersion: 4
MinorOSVersion: 0
CheckSum: 0000EF94
EntryPoint (rva): 14D0
SizeOfHeaders: 400
SizeOfImage: D000
ImageBase: 0000000140000000
Architecture: x64
ImportTable: 9000
IAT: 91D0
Characteristics: 22E
TimeDateStamp: 6A7AB8B9
Date: 11/08/2026 5:52:57
File Type: EXE
Number Of Sections: 10
ASLR: Disabled
Section Names (Optional Header): .text, .data, .rdata, .pdata, .xdata, .bss, .idata, .CRT, .tls, .reloc
Number Of Executable Sections: 1
Subsystem: Windows GUI

Sections Info
Section Name Flags ROffset RSize VOffset VSizeEntropyChi2
.text
0x60000060
Code
Initialized Data
Executable
Readable
400 2A00 1000 28A8
6.0514
129931.1
.data
0xC0000040
Initialized Data
Readable
Writeable
2E00 200 4000 B0
0.6614
110086
.rdata
0x40000040
Initialized Data
Readable
3000 C00 5000 A90
4.5626
94276.83
.pdata
0x40000040
Initialized Data
Readable
3C00 400 6000 270
2.6353
129225.5
.xdata
0x40000040
Initialized Data
Readable
4000 200 7000 1F8
3.847
18959
.bss
0xC0000080
Uninitialized Data
Readable
Writeable
0 0 8000 240
N/A
N/A
.idata
0xC0000040
Initialized Data
Readable
Writeable
4200 800 9000 6DC
3.521
165073
.CRT
0xC0000040
Initialized Data
Readable
Writeable
4A00 200 A000 68
0.3353
120561
.tls
0xC0000040
Initialized Data
Readable
Writeable
4C00 200 B000 10
0
130560
.reloc
0x42000040
Initialized Data
GP-Relative
Readable
4E00 200 C000 84
1.5251
85167
Entry Point
The section number (1) have the Entry Point
Information -> EntryPoint (calculated) - 8D0
Code -> 4883EC28488B0585410000C70001000000E8AAFCFFFF90904883C428C30F1F004883EC28488B0565410000C70000000000E8
Assembler
|SUB RSP, 0X28
|MOV RAX, QWORD PTR [RIP + 0X4185]
|MOV DWORD PTR [RAX], 1
|CALL 0X140001190
|NOP
|NOP
|ADD RSP, 0X28
|RET
|NOP DWORD PTR [RAX]
|SUB RSP, 0X28
|MOV RAX, QWORD PTR [RIP + 0X4165]
|MOV DWORD PTR [RAX], 0
Signatures
Certificate - Digital Signature Not Found:
• The file is not signed

Packer/Compiler
Detect It Easy (die)
PE+(64): linker: GNU linker ld (GNU Binutils)(2.38)[-]
Entropy: 5.25418

Suspicious Functions
Library Function Description
KERNEL32.DLL GetModuleFileNameA Retrieve the fully qualified path for the executable file of a specified module.
KERNEL32.DLL VirtualAlloc Reserve, commit, or both, a region of memory within the virtual address space of a process.
KERNEL32.DLL LoadLibraryA Loads the specified module into the address space of the calling process.
KERNEL32.DLL GetModuleHandleA Retrieves a handle to the specified module.
KERNEL32.DLL GetProcAddress Retrieves the address of an exported function or variable from the specified dynamic-link library (DLL).
KERNEL32.DLL VirtualProtect Changes memory protection attributes.
KERNEL32.DLL CreateEventA Creates or opens an event object.
Windows REG
Software\Microsoft\Windows\CurrentVersion\Run
Rebuilt string - SOFTWARE\Microsoft\Windows\CurrentVersion\Run

File Access
PSAPI.DLL
msvcrt.dll
KERNEL32.dll
wininet.dll
advapi32.dll
user32.dll
ntdll.dll
.dat

Interest's Words
start

URLs
http://172.98.23.179/811.b

IP Addresses
172.98.23.179

Strings/Hex Code Found With The File Rules
Rule Type Encoding Matched (Word)
Entry Point Hex Pattern Microsoft Visual C++ 8.0 (DLL)
Intelligent String
• wininet.dll
• advapi32.dll
• user32.dll
• ntdll.dll
• kernel32.dll
• @.bss
• .CRT
• .tls
• software\microsoft\windows\currentversion\runmicinternetopenainternetopenurlainternetreadfileinternetclosehandlevirtualprotectregopenkeyexaregsetvalueexaregclosekeygetmessageadispatchmessageatranslatemessagegetprocaddressvirtualalloccreatethreadwaitforsingleobjectcreateeventagetmodulefilenameagetmodulehandleagetcurrentprocesspsapi.dll
• KERNEL32.dll
• msvcrt.dll
• PSAPI.DLL

Flow Anomalies
Offset FlowVA Section Description
668 N/A .text CALL QWORD PTR [RIP+0x7FB2]
873 N/A .text CALL QWORD PTR [RIP+0x7D87]
B73 N/A .text CALL QWORD PTR [RIP+0x7A77]
B90 N/A .text CALL QWORD PTR [RIP+0x7A4A]
DA4 N/A .text JMP QWORD PTR [RIP+0x784E]
F2F N/A .text CALL QWORD PTR [RIP+0x76E3]
1056 N/A .text CALL QWORD PTR [RIP+0x759C]
10F4 N/A .text CALL QWORD PTR [RIP+0x751E]
1830 N/A .text JMP QWORD PTR [RIP+0x6F0A]
1838 N/A .text JMP QWORD PTR [RIP+0x6EFA]
1911 N/A .text JMP QWORD PTR [RIP+0x6D61]
1C29 N/A .text CALL QWORD PTR [RIP+0x6A11]
1D0E N/A .text CALL QWORD PTR [RIP+0x6924]
1D1C N/A .text CALL QWORD PTR [RIP+0x68C6]
22B0 N/A .text CALL QWORD PTR [RIP+0x6322]
2305 N/A .text JMP QWORD PTR [RIP+0x6305]
2354 N/A .text CALL QWORD PTR [RIP+0x627E]
2373 N/A .text CALL QWORD PTR [RIP+0x6297]
23B7 N/A .text CALL QWORD PTR [RIP+0x621B]
23FA N/A .text CALL QWORD PTR [RIP+0x6210]
2477 N/A .text CALL QWORD PTR [RIP+0x618B]
24DD N/A .text CALL QWORD PTR [RIP+0x60ED]
2920 N/A .text JMP QWORD PTR [RIP+0x5E02]
2928 N/A .text JMP QWORD PTR [RIP+0x5DF2]
2930 N/A .text JMP QWORD PTR [RIP+0x5DE2]
2938 N/A .text JMP QWORD PTR [RIP+0x5DD2]
2940 N/A .text JMP QWORD PTR [RIP+0x5DC2]
2948 N/A .text JMP QWORD PTR [RIP+0x5DB2]
2950 N/A .text JMP QWORD PTR [RIP+0x5DA2]
2958 N/A .text JMP QWORD PTR [RIP+0x5D92]
2960 N/A .text JMP QWORD PTR [RIP+0x5D82]
2968 N/A .text JMP QWORD PTR [RIP+0x5D72]
2970 N/A .text JMP QWORD PTR [RIP+0x5D62]
2978 N/A .text JMP QWORD PTR [RIP+0x5D52]
2980 N/A .text JMP QWORD PTR [RIP+0x5D42]
2988 N/A .text JMP QWORD PTR [RIP+0x5D32]
2990 N/A .text JMP QWORD PTR [RIP+0x5D22]
2998 N/A .text JMP QWORD PTR [RIP+0x5D02]
29A0 N/A .text JMP QWORD PTR [RIP+0x5CF2]
29A8 N/A .text JMP QWORD PTR [RIP+0x5CDA]
29B0 N/A .text JMP QWORD PTR [RIP+0x5CCA]
29B8 N/A .text JMP QWORD PTR [RIP+0x5CBA]
29C0 N/A .text JMP QWORD PTR [RIP+0x5C9A]
29C8 N/A .text JMP QWORD PTR [RIP+0x5C8A]
2A40 N/A .text JMP QWORD PTR [RIP+0x5C2A]
2A50 N/A .text JMP QWORD PTR [RIP+0x5BF2]
2A58 N/A .text JMP QWORD PTR [RIP+0x5BE2]
2A60 N/A .text JMP QWORD PTR [RIP+0x5BD2]
2A68 N/A .text JMP QWORD PTR [RIP+0x5BC2]
2A70 N/A .text JMP QWORD PTR [RIP+0x5BB2]
2A78 N/A .text JMP QWORD PTR [RIP+0x5BA2]
2A80 N/A .text JMP QWORD PTR [RIP+0x5B92]
2A88 N/A .text JMP QWORD PTR [RIP+0x5B82]
2A90 N/A .text JMP QWORD PTR [RIP+0x5B72]
2A98 N/A .text JMP QWORD PTR [RIP+0x5B62]
2AA0 N/A .text JMP QWORD PTR [RIP+0x5B52]
2AA8 N/A .text JMP QWORD PTR [RIP+0x5B42]
2AB0 N/A .text JMP QWORD PTR [RIP+0x5B32]
2AB8 N/A .text JMP QWORD PTR [RIP+0x5B22]
2AC0 N/A .text JMP QWORD PTR [RIP+0x5B12]
2AC8 N/A .text JMP QWORD PTR [RIP+0x5B02]
2B85 N/A .text CALL QWORD PTR [RIP+0x491D]
2BC6 N/A .text CALL QWORD PTR [RIP+0x48E4]
2C3F N/A .text CALL QWORD PTR [RIP+0x5A03]
4A40 140002560 .CRT TLS Callback | Pointer to 2560 - 0x1960 .text
4A48 140002530 .CRT TLS Callback | Pointer to 2530 - 0x1930 .text
3C00 140001000 .pdata ExceptionHook | Pointer to 1000 - 0x400 .text + UnwindInfo: .xdata
3C0C 140001010 .pdata ExceptionHook | Pointer to 1010 - 0x410 .text + UnwindInfo: .xdata
3C18 140001140 .pdata ExceptionHook | Pointer to 1140 - 0x540 .text + UnwindInfo: .xdata
3C24 140001190 .pdata ExceptionHook | Pointer to 1190 - 0x590 .text + UnwindInfo: .xdata
3C30 1400014D0 .pdata ExceptionHook | Pointer to 14D0 - 0x8D0 .text + UnwindInfo: .xdata
3C3C 1400014F0 .pdata ExceptionHook | Pointer to 14F0 - 0x8F0 .text + UnwindInfo: .xdata
3C48 140001510 .pdata ExceptionHook | Pointer to 1510 - 0x910 .text + UnwindInfo: .xdata
3C54 140001530 .pdata ExceptionHook | Pointer to 1530 - 0x930 .text + UnwindInfo: .xdata
3C60 140001540 .pdata ExceptionHook | Pointer to 1540 - 0x940 .text + UnwindInfo: .xdata
3C6C 140001550 .pdata ExceptionHook | Pointer to 1550 - 0x950 .text + UnwindInfo: .xdata
3C78 1400018E0 .pdata ExceptionHook | Pointer to 18E0 - 0xCE0 .text + UnwindInfo: .xdata
3C84 1400019B0 .pdata ExceptionHook | Pointer to 19B0 - 0xDB0 .text + UnwindInfo: .xdata
3C90 140001B50 .pdata ExceptionHook | Pointer to 1B50 - 0xF50 .text + UnwindInfo: .xdata
3C9C 140001C20 .pdata ExceptionHook | Pointer to 1C20 - 0x1020 .text + UnwindInfo: .xdata
3CA8 140002440 .pdata ExceptionHook | Pointer to 2440 - 0x1840 .text + UnwindInfo: .xdata
3CB4 140002480 .pdata ExceptionHook | Pointer to 2480 - 0x1880 .text + UnwindInfo: .xdata
3CC0 1400024F0 .pdata ExceptionHook | Pointer to 24F0 - 0x18F0 .text + UnwindInfo: .xdata
3CCC 140002510 .pdata ExceptionHook | Pointer to 2510 - 0x1910 .text + UnwindInfo: .xdata
3CD8 140002520 .pdata ExceptionHook | Pointer to 2520 - 0x1920 .text + UnwindInfo: .xdata
3CE4 140002530 .pdata ExceptionHook | Pointer to 2530 - 0x1930 .text + UnwindInfo: .xdata
3CF0 140002560 .pdata ExceptionHook | Pointer to 2560 - 0x1960 .text + UnwindInfo: .xdata
3CFC 1400025F0 .pdata ExceptionHook | Pointer to 25F0 - 0x19F0 .text + UnwindInfo: .xdata
3D08 140002600 .pdata ExceptionHook | Pointer to 2600 - 0x1A00 .text + UnwindInfo: .xdata
3D14 140002700 .pdata ExceptionHook | Pointer to 2700 - 0x1B00 .text + UnwindInfo: .xdata
3D20 140002710 .pdata ExceptionHook | Pointer to 2710 - 0x1B10 .text + UnwindInfo: .xdata
3D2C 140002780 .pdata ExceptionHook | Pointer to 2780 - 0x1B80 .text + UnwindInfo: .xdata
3D38 1400029A0 .pdata ExceptionHook | Pointer to 29A0 - 0x1DA0 .text + UnwindInfo: .xdata
3D44 140002C90 .pdata ExceptionHook | Pointer to 2C90 - 0x2090 .text + UnwindInfo: .xdata
3D50 140002CE0 .pdata ExceptionHook | Pointer to 2CE0 - 0x20E0 .text + UnwindInfo: .xdata
3D5C 140002CF0 .pdata ExceptionHook | Pointer to 2CF0 - 0x20F0 .text + UnwindInfo: .xdata
3D68 140002EA0 .pdata ExceptionHook | Pointer to 2EA0 - 0x22A0 .text + UnwindInfo: .xdata
3D74 140002F10 .pdata ExceptionHook | Pointer to 2F10 - 0x2310 .text + UnwindInfo: .xdata
3D80 140002F90 .pdata ExceptionHook | Pointer to 2F90 - 0x2390 .text + UnwindInfo: .xdata
3D8C 140003020 .pdata ExceptionHook | Pointer to 3020 - 0x2420 .text + UnwindInfo: .xdata
3D98 140003100 .pdata ExceptionHook | Pointer to 3100 - 0x2500 .text + UnwindInfo: .xdata
3DA4 140003120 .pdata ExceptionHook | Pointer to 3120 - 0x2520 .text + UnwindInfo: .xdata
3DB0 140003140 .pdata ExceptionHook | Pointer to 3140 - 0x2540 .text + UnwindInfo: .xdata
3DBC 140003190 .pdata ExceptionHook | Pointer to 3190 - 0x2590 .text + UnwindInfo: .xdata
3DC8 140003230 .pdata ExceptionHook | Pointer to 3230 - 0x2630 .text + UnwindInfo: .xdata
3DD4 1400032C0 .pdata ExceptionHook | Pointer to 32C0 - 0x26C0 .text + UnwindInfo: .xdata
3DE0 1400032F0 .pdata ExceptionHook | Pointer to 32F0 - 0x26F0 .text + UnwindInfo: .xdata
3DEC 140003360 .pdata ExceptionHook | Pointer to 3360 - 0x2760 .text + UnwindInfo: .xdata
3DF8 140003390 .pdata ExceptionHook | Pointer to 3390 - 0x2790 .text + UnwindInfo: .xdata
3E04 140003420 .pdata ExceptionHook | Pointer to 3420 - 0x2820 .text + UnwindInfo: .xdata
3E10 1400035D0 .pdata ExceptionHook | Pointer to 35D0 - 0x29D0 .text + UnwindInfo: .xdata
3E1C 1400035F0 .pdata ExceptionHook | Pointer to 35F0 - 0x29F0 .text + UnwindInfo: .xdata
3E28 140003600 .pdata ExceptionHook | Pointer to 3600 - 0x2A00 .text + UnwindInfo: .xdata
3E34 140003610 .pdata ExceptionHook | Pointer to 3610 - 0x2A10 .text + UnwindInfo: .xdata
3E40 140003620 .pdata ExceptionHook | Pointer to 3620 - 0x2A20 .text + UnwindInfo: .xdata
3E4C 140003630 .pdata ExceptionHook | Pointer to 3630 - 0x2A30 .text + UnwindInfo: .xdata
3E58 1400036D0 .pdata ExceptionHook | Pointer to 36D0 - 0x2AD0 .text + UnwindInfo: .xdata
3E64 140003870 .pdata ExceptionHook | Pointer to 3870 - 0x2C70 .text + UnwindInfo: .xdata
Extra Analysis
Metric Value Percentage
Ascii Code 9283 45,3271%
Null Byte Code 7861 38,3838%
NOP Cave Found 0x9090909090 Block Count: 27 | Total: 0,3296%
© 2026 All rights reserved.