PESCAN.IO - Analysis Report Basic

File Structure
Analysis Image
PE Chart Code
Header PE (light blue)
Executable sections (pink)
Non-executable sections (black)
External injected code (red)
File Structure in red = malformed or corrupted header

Chart Code For Other Files
Printable characters (blue)
Non-printable characters (black)
Information
Size: 72,07 KB
SHA-256 Hash: 6E4F8DE7277B78686FE389E6D1DF2B24F5BC3564208B76C8AF5D1319073D1B2E
SHA-1 Hash: 5CE98E43D7E6D33409A0305CA4C797AB759365D8
MD5 Hash: E17408BA8828D05C74A63D0A3B5525B7
Imphash: 481F47BBB2C9C21E108D65F52B04C448
MajorOSVersion: 4
MinorOSVersion: 0
CheckSum: 00000000
EntryPoint (rva): 7FE6
SizeOfHeaders: 1000
SizeOfImage: 16000
ImageBase: 400000
Architecture: x86
ImportTable: C76C
IAT: C000
Characteristics: 10F
TimeDateStamp: 49EB032C
Date: 19/04/2009 10:55:40
File Type: EXE
Number Of Sections: 4
ASLR: Disabled
Section Names: .text, .rdata, .data, .rsrc
Number Of Executable Sections: 1
Subsystem: Windows GUI

Sections Info
Section Name Flags ROffset RSize VOffset VSizeEntropyChi2
.text
0x60000020
Code
Executable
Readable
1000 B000 1000 A966
7.0236
200042.06
.rdata
0x40000040
Initialized Data
Readable
C000 1000 C000 FE6
5.3184
99428.63
.data
0xC0000040
Initialized Data
Readable
Writeable
D000 4000 D000 705C
4.4078
437980.09
.rsrc
0x40000040
Initialized Data
Readable
11000 1000 15000 7C8
1.9583
629607
Description
OriginalFilename: ab.exe
CompanyName: Apache Software Foundation
LegalCopyright: Copyright 2009 The Apache Software Foundation.
ProductName: Apache HTTP Server
FileVersion: 2.2.14
FileDescription: ApacheBench command line utility
ProductVersion: 2.2.14
Comments: Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with the License. You may obtain a copy of the License athttp://www.apache.org/licenses/LICENSE-2.0Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the specific language governing permissions and limitations under the License.
Language: English (United States) (ID=0x409)
CodePage: Unicode (UTF-16 LE) (0x4B0)

Entry Point
The section number (1) - (.text) have the Entry Point
Information -> EntryPoint (calculated) - 7FE6
Code -> 3742984B4A9042439340F9419827919F374A903F429140909099903F9941F9494BFD9B99FD42434041FC404AF9933F3FFD42
Assembler
|AAA
|INC EDX
|CWDE
|DEC EBX
|DEC EDX
|NOP
|INC EDX
|INC EBX
|XCHG EAX, EBX
|INC EAX
|STC
|INC ECX
|CWDE
|DAA
|XCHG EAX, ECX
|LAHF
|AAA
|DEC EDX
|NOP
|AAS
|INC EDX
|XCHG EAX, ECX
|INC EAX
|NOP
|NOP
|CDQ
|NOP
|AAS
|CDQ
|INC ECX
|STC
|DEC ECX
|DEC EBX
|STD
|WAIT
|CDQ
|STD
|INC EDX
|INC EBX
|INC EAX
|INC ECX
|CLD
|INC EAX
|DEC EDX
|STC
|XCHG EAX, EBX
|AAS
|AAS
|STD
|INC EDX
Signatures
Rich Signature Analyzer:
Code -> 9338F0D6D7599E85D7599E85D7599E85AC459285D3599E8554459085DE599E85B8469485DC599E85B8469A85D4599E85D7599F851E599E855451C385DF599E85837AAE85FF599E85105F9885D6599E8552696368D7599E85
Footprint md5 Hash -> 274018F55839EA6177BC43726E13C7A7
• The Rich header apparently has not been modified
Certificate - Digital Signature Not Found:
• The file is not signed

Packer/Compiler
Detect It Easy (die)
PE: linker: Microsoft Linker(6.0*)[-]
PE: overlay: PDB 2.0 file link(-)[-]
Entropy: 6.32786

Suspicious Functions
Library Function Description
KERNEL32.DLL CreateMutexA Create a named or unnamed mutex object for controlling access to a shared resource.
KERNEL32.DLL WriteFile Writes data to a specified file or input/output (I/O) device.
KERNEL32.DLL LoadLibraryA Loads the specified module into the address space of the calling process.
KERNEL32.DLL GetProcAddress Retrieves the address of an exported function or variable from the specified dynamic-link library (DLL).
KERNEL32.DLL CreateFileA Creates or opens a file or I/O device.
KERNEL32.DLL CreateFileW Creates or opens a file object.
KERNEL32.DLL ReadFile Reads data from a file.
KERNEL32.DLL CloseHandle Closes an open object handle.
KERNEL32.DLL CreateEventA Creates or opens an event object.
Ws2_32.DLL socket Create a communication endpoint for networking applications.
Ws2_32.DLL recv Receives data from a network socket.
File Access
ntdll.dll
WS2_32.dll
WSOCK32.dll
ADVAPI32.dll
KERNEL32.dll
MSVCRT.dll
@.dat

File Access (UNICODE)
ab.exe

Interest's Words
PassWord
<table
exec
attrib
start
hostname
shutdown
route

URLs
http://www.apache.org/<br
http://www.zeustech.net/<br
http://www.apache.org/
http://www.zeustech.net/
http://]hostname[:port]/path

Strings/Hex Code Found With The File Rules
Rule Type Encoding Matched (Word)
Hex Hex Pattern Metasploit Shellcode 15 (Reverse TCP x86 - FCE88F00000060)
Text Ascii Unauthorized movement of funds or data (Transfer)
Entry Point Hex Pattern HA Archive
Entry Point Hex Pattern NE-Exe Executable Image
Resources
Path DataRVA Size FileOffset CodeText
\VERSION\1\1033 15060 768 11060 680734000000560053005F00560045005200530049004F004E005F0049004E0046004F0000000000BD04EFFE000001000200h.4...V.S._.V.E.R.S.I.O.N._.I.N.F.O...............
Intelligent String
• ab.exe
• Licensed to The Apache Software Foundation, http://www.apache.org/<br>
• Copyright 1996 Adam Twiss, Zeus Technology Ltd, http://www.zeustech.net/<br>
• Usage: %s [options] [http://]hostname[:port]/path
• http://ab: Could not read POST data file: %s
• ntdll.dll
• http://www.apache.org/licenses/LICENSE-2.0
• C:\local0\asf\release\build-2.2.14\support\Release\ab.pdb

Flow Anomalies
Offset FlowVA Section Description
10C3 40C1E9 .text CALL [static] | Indirect call to absolute memory address
1106 6340C16C .text CALL [static] | Indirect call to absolute memory address
111A 6340C16C .text CALL [static] | Indirect call to absolute memory address
1152 6340C16C .text CALL [static] | Indirect call to absolute memory address
11CD 40C170 .text CALL [static] | Indirect call to absolute memory address
1214 40C170 .text CALL [static] | Indirect call to absolute memory address
122D 40C1B2 .text CALL [static] | Indirect call to absolute memory address
1241 40716C .text CALL [static] | Indirect call to absolute memory address
1766 40C180 .text CALL [static] | Indirect call to absolute memory address
177E 7040D57D .text CALL [static] | Indirect call to absolute memory address
1789 7040D57D .text CALL [static] | Indirect call to absolute memory address
1841 40C18C .text CALL [static] | Indirect call to absolute memory address
1A66 40C164 .text CALL [static] | Indirect call to absolute memory address
1AB5 4140C180 .text CALL [static] | Indirect call to absolute memory address
1BAE 40C160 .text CALL [static] | Indirect call to absolute memory address
1DFA 404D80 .text CALL [static] | Indirect call to absolute memory address
1E83 402F64 .text CALL [static] | Indirect call to absolute memory address
2042 40C164 .text CALL [static] | Indirect call to absolute memory address
2700 40C144 .text CALL [static] | Indirect call to absolute memory address
288A 40C144 .text CALL [static] | Indirect call to absolute memory address
2E9A 4EC148 .text CALL [static] | Indirect call to absolute memory address
2EAE 40C14C .text CALL [static] | Indirect call to absolute memory address
2EB9 405070 .text CALL [static] | Indirect call to absolute memory address
2F4E 405070 .text CALL [static] | Indirect call to absolute memory address
2F6A 40C148 .text CALL [static] | Indirect call to absolute memory address
2F7F 40C14C .text CALL [static] | Indirect call to absolute memory address
2F8A 40C170 .text CALL [static] | Indirect call to absolute memory address
2F96 7C40C180 .text CALL [static] | Indirect call to absolute memory address
30BC 401950 .text CALL [static] | Indirect call to absolute memory address
3C1C 40C154 .text CALL [static] | Indirect call to absolute memory address
3D6B 40C154 .text CALL [static] | Indirect call to absolute memory address
3E46 404DC0 .text CALL [static] | Indirect call to absolute memory address
4032 3040C16C .text CALL [static] | Indirect call to absolute memory address
4222 3140C180 .text CALL [static] | Indirect call to absolute memory address
4555 402D70 .text CALL [static] | Indirect call to absolute memory address
45B1 F65F55 .text CALL [static] | Indirect call to absolute memory address
46A6 4F40C17D .text CALL [static] | Indirect call to absolute memory address
47C0 4F40C17D .text CALL [static] | Indirect call to absolute memory address
487F 4F40C17D .text CALL [static] | Indirect call to absolute memory address
503C AFC15C .text CALL [static] | Indirect call to absolute memory address
555A F265C .text CALL [static] | Indirect call to absolute memory address
5BF1 DC17C .text CALL [static] | Indirect call to absolute memory address
5D57 40C05C .text CALL [static] | Indirect call to absolute memory address
5DB4 40C091 .text CALL [static] | Indirect call to absolute memory address
5DDD 40C15C .text CALL [static] | Indirect call to absolute memory address
5E25 40C130 .text CALL [static] | Indirect call to absolute memory address
5E3A 407B4C .text CALL [static] | Indirect call to absolute memory address
5E8C 40C15C .text CALL [static] | Indirect call to absolute memory address
5E9F 40C15C .text CALL [static] | Indirect call to absolute memory address
5EC5 40C120 .text CALL [static] | Indirect call to absolute memory address
5F54 40C060 .text CALL [static] | Indirect call to absolute memory address
5F98 77C110 .text CALL [static] | Indirect call to absolute memory address
5FD0 40C1D4 .text CALL [static] | Indirect call to absolute memory address
5FF2 40C1D4 .text CALL [static] | Indirect call to absolute memory address
5FFE 28C0CB .text CALL [static] | Indirect call to absolute memory address
661B 40C1BC .text CALL [static] | Indirect call to absolute memory address
6664 40C011 .text CALL [static] | Indirect call to absolute memory address
668C 8FC1C0 .text CALL [static] | Indirect call to absolute memory address
6923 40C1C4 .text CALL [static] | Indirect call to absolute memory address
6974 4FC18D .text CALL [static] | Indirect call to absolute memory address
6BA9 40C088 .text CALL [static] | Indirect call to absolute memory address
6C41 40C084 .text CALL [static] | Indirect call to absolute memory address
6C4F 40C0EF .text CALL [static] | Indirect call to absolute memory address
6C7C 40C090 .text CALL [static] | Indirect call to absolute memory address
6D21 40C080 .text CALL [static] | Indirect call to absolute memory address
6D78 40C090 .text CALL [static] | Indirect call to absolute memory address
6E96 40C090 .text CALL [static] | Indirect call to absolute memory address
6ED7 40556C .text CALL [static] | Indirect call to absolute memory address
6FF2 40C1C8 .text CALL [static] | Indirect call to absolute memory address
707E 40C1AC .text CALL [static] | Indirect call to absolute memory address
717E 40C108 .text CALL [static] | Indirect call to absolute memory address
72BC 40C17C .text CALL [static] | Indirect call to absolute memory address
7351 40C134 .text CALL [static] | Indirect call to absolute memory address
822C D2C1C1 .text CALL [static] | Indirect call to absolute memory address
83D9 40C168 .text CALL [static] | Indirect call to absolute memory address
89F0 B2C094 .text CALL [static] | Indirect call to absolute memory address
8A87 BC1AF .text CALL [static] | Indirect call to absolute memory address
8AF3 40C198 .text CALL [static] | Indirect call to absolute memory address
8B7C 40C198 .text CALL [static] | Indirect call to absolute memory address
8BE8 40E2B4 .text CALL [static] | Indirect call to absolute memory address
8E13 40E2B4 .text CALL [static] | Indirect call to absolute memory address
8E6E 40C105 .text CALL [static] | Indirect call to absolute memory address
8ECD 40C1B8 .text CALL [static] | Indirect call to absolute memory address
8FA6 40C1B8 .text CALL [static] | Indirect call to absolute memory address
8FF2 40C1B8 .text CALL [static] | Indirect call to absolute memory address
905A 40C1B8 .text CALL [static] | Indirect call to absolute memory address
90C5 2140B5B8 .text CALL [static] | Indirect call to absolute memory address
928B 40C110 .text CALL [static] | Indirect call to absolute memory address
92C8 409410 .text CALL [static] | Indirect call to absolute memory address
9376 40D408 .text CALL [static] | Indirect call to absolute memory address
9394 40C108 .text CALL [static] | Indirect call to absolute memory address
93A1 40C0A4 .text CALL [static] | Indirect call to absolute memory address
93B2 697FC18F .text CALL [static] | Indirect call to absolute memory address
93BF A6C0A4 .text CALL [static] | Indirect call to absolute memory address
93CB 409974 .text CALL [static] | Indirect call to absolute memory address
93E7 DD9384 .text CALL [static] | Indirect call to absolute memory address
9536 40BEB0 .text CALL [static] | Indirect call to absolute memory address
9550 40C0AC .text CALL [static] | Indirect call to absolute memory address
95E9 40C0A8 .text CALL [static] | Indirect call to absolute memory address
9724 40C0B8 .text CALL [static] | Indirect call to absolute memory address
8020 N/A .text Injected Junk Code | HitsBL=179/200 - UniqueHits=26 - Ratio=0,90
12000 N/A *Overlay* 4E423130000000003680C14A01000000433A5C6C | NB10....6..J....C:\l
Extra Analysis
Metric Value Percentage
Ascii Code 42734 57,9036%
Null Byte Code 17992 24,3787%
NOP Cave Found 0x9090909090 Block Count: 65 | Total: 0,2202%
© 2026 All rights reserved.