PESCAN.IO - Analysis Report Basic |
|||||||
| File Structure |
|
PE Chart Code
Header PE (light blue)
Executable sections (pink)
Non-executable sections (black)
External injected code (red)
File Structure in red = malformed or corrupted header
Chart Code For Other Files
Printable characters (blue)
Non-printable characters (black)
| Information |
| Size: 72,07 KB SHA-256 Hash: 6E4F8DE7277B78686FE389E6D1DF2B24F5BC3564208B76C8AF5D1319073D1B2E SHA-1 Hash: 5CE98E43D7E6D33409A0305CA4C797AB759365D8 MD5 Hash: E17408BA8828D05C74A63D0A3B5525B7 Imphash: 481F47BBB2C9C21E108D65F52B04C448 MajorOSVersion: 4 MinorOSVersion: 0 CheckSum: 00000000 EntryPoint (rva): 7FE6 SizeOfHeaders: 1000 SizeOfImage: 16000 ImageBase: 400000 Architecture: x86 ImportTable: C76C IAT: C000 Characteristics: 10F TimeDateStamp: 49EB032C Date: 19/04/2009 10:55:40 File Type: EXE Number Of Sections: 4 ASLR: Disabled Section Names: .text, .rdata, .data, .rsrc Number Of Executable Sections: 1 Subsystem: Windows GUI |
| Sections Info |
| Section Name | Flags | ROffset | RSize | VOffset | VSize | Entropy | Chi2 |
|---|---|---|---|---|---|---|---|
| .text | 0x60000020 Code Executable Readable |
1000 | B000 | 1000 | A966 |
|
|
| .rdata | 0x40000040 Initialized Data Readable |
C000 | 1000 | C000 | FE6 |
|
|
| .data | 0xC0000040 Initialized Data Readable Writeable |
D000 | 4000 | D000 | 705C |
|
|
| .rsrc | 0x40000040 Initialized Data Readable |
11000 | 1000 | 15000 | 7C8 |
|
|
| Description |
| OriginalFilename: ab.exe CompanyName: Apache Software Foundation LegalCopyright: Copyright 2009 The Apache Software Foundation. ProductName: Apache HTTP Server FileVersion: 2.2.14 FileDescription: ApacheBench command line utility ProductVersion: 2.2.14 Comments: Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with the License. You may obtain a copy of the License athttp://www.apache.org/licenses/LICENSE-2.0Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the specific language governing permissions and limitations under the License. Language: English (United States) (ID=0x409) CodePage: Unicode (UTF-16 LE) (0x4B0) |
| Entry Point |
The section number (1) - (.text) have the Entry Point Information -> EntryPoint (calculated) - 7FE6 Code -> 3742984B4A9042439340F9419827919F374A903F429140909099903F9941F9494BFD9B99FD42434041FC404AF9933F3FFD42 Assembler |AAA |INC EDX |CWDE |DEC EBX |DEC EDX |NOP |INC EDX |INC EBX |XCHG EAX, EBX |INC EAX |STC |INC ECX |CWDE |DAA |XCHG EAX, ECX |LAHF |AAA |DEC EDX |NOP |AAS |INC EDX |XCHG EAX, ECX |INC EAX |NOP |NOP |CDQ |NOP |AAS |CDQ |INC ECX |STC |DEC ECX |DEC EBX |STD |WAIT |CDQ |STD |INC EDX |INC EBX |INC EAX |INC ECX |CLD |INC EAX |DEC EDX |STC |XCHG EAX, EBX |AAS |AAS |STD |INC EDX |
| Signatures |
| Rich Signature Analyzer: Code -> 9338F0D6D7599E85D7599E85D7599E85AC459285D3599E8554459085DE599E85B8469485DC599E85B8469A85D4599E85D7599F851E599E855451C385DF599E85837AAE85FF599E85105F9885D6599E8552696368D7599E85 Footprint md5 Hash -> 274018F55839EA6177BC43726E13C7A7 • The Rich header apparently has not been modified Certificate - Digital Signature Not Found: • The file is not signed |
| Packer/Compiler |
| Detect It Easy (die) • PE: linker: Microsoft Linker(6.0*)[-] • PE: overlay: PDB 2.0 file link(-)[-] • Entropy: 6.32786 |
| Suspicious Functions |
| Library | Function | Description |
|---|---|---|
| KERNEL32.DLL | CreateMutexA | Create a named or unnamed mutex object for controlling access to a shared resource. |
| KERNEL32.DLL | WriteFile | Writes data to a specified file or input/output (I/O) device. |
| KERNEL32.DLL | LoadLibraryA | Loads the specified module into the address space of the calling process. |
| KERNEL32.DLL | GetProcAddress | Retrieves the address of an exported function or variable from the specified dynamic-link library (DLL). |
| KERNEL32.DLL | CreateFileA | Creates or opens a file or I/O device. |
| KERNEL32.DLL | CreateFileW | Creates or opens a file object. |
| KERNEL32.DLL | ReadFile | Reads data from a file. |
| KERNEL32.DLL | CloseHandle | Closes an open object handle. |
| KERNEL32.DLL | CreateEventA | Creates or opens an event object. |
| Ws2_32.DLL | socket | Create a communication endpoint for networking applications. |
| Ws2_32.DLL | recv | Receives data from a network socket. |
| File Access |
| ntdll.dll WS2_32.dll WSOCK32.dll ADVAPI32.dll KERNEL32.dll MSVCRT.dll @.dat |
| File Access (UNICODE) |
| ab.exe |
| Interest's Words |
| PassWord <table exec attrib start hostname shutdown route |
| URLs |
| http://www.apache.org/<br http://www.zeustech.net/<br http://www.apache.org/ http://www.zeustech.net/ http://]hostname[:port]/path |
| Strings/Hex Code Found With The File Rules |
| Rule Type | Encoding | Matched (Word) |
|---|---|---|
| Hex | Hex Pattern | Metasploit Shellcode 15 (Reverse TCP x86 - FCE88F00000060) |
| Text | Ascii | Unauthorized movement of funds or data (Transfer) |
| Entry Point | Hex Pattern | HA Archive |
| Entry Point | Hex Pattern | NE-Exe Executable Image |
| Resources |
| Path | DataRVA | Size | FileOffset | Code | Text |
|---|---|---|---|---|---|
| \VERSION\1\1033 | 15060 | 768 | 11060 | 680734000000560053005F00560045005200530049004F004E005F0049004E0046004F0000000000BD04EFFE000001000200 | h.4...V.S._.V.E.R.S.I.O.N._.I.N.F.O............... |
| Intelligent String |
| • ab.exe • Licensed to The Apache Software Foundation, http://www.apache.org/<br> • Copyright 1996 Adam Twiss, Zeus Technology Ltd, http://www.zeustech.net/<br> • Usage: %s [options] [http://]hostname[:port]/path • http://ab: Could not read POST data file: %s • ntdll.dll • http://www.apache.org/licenses/LICENSE-2.0 • C:\local0\asf\release\build-2.2.14\support\Release\ab.pdb |
| Flow Anomalies |
| Offset | FlowVA | Section | Description |
|---|---|---|---|
| 10C3 | 40C1E9 | .text | CALL [static] | Indirect call to absolute memory address |
| 1106 | 6340C16C | .text | CALL [static] | Indirect call to absolute memory address |
| 111A | 6340C16C | .text | CALL [static] | Indirect call to absolute memory address |
| 1152 | 6340C16C | .text | CALL [static] | Indirect call to absolute memory address |
| 11CD | 40C170 | .text | CALL [static] | Indirect call to absolute memory address |
| 1214 | 40C170 | .text | CALL [static] | Indirect call to absolute memory address |
| 122D | 40C1B2 | .text | CALL [static] | Indirect call to absolute memory address |
| 1241 | 40716C | .text | CALL [static] | Indirect call to absolute memory address |
| 1766 | 40C180 | .text | CALL [static] | Indirect call to absolute memory address |
| 177E | 7040D57D | .text | CALL [static] | Indirect call to absolute memory address |
| 1789 | 7040D57D | .text | CALL [static] | Indirect call to absolute memory address |
| 1841 | 40C18C | .text | CALL [static] | Indirect call to absolute memory address |
| 1A66 | 40C164 | .text | CALL [static] | Indirect call to absolute memory address |
| 1AB5 | 4140C180 | .text | CALL [static] | Indirect call to absolute memory address |
| 1BAE | 40C160 | .text | CALL [static] | Indirect call to absolute memory address |
| 1DFA | 404D80 | .text | CALL [static] | Indirect call to absolute memory address |
| 1E83 | 402F64 | .text | CALL [static] | Indirect call to absolute memory address |
| 2042 | 40C164 | .text | CALL [static] | Indirect call to absolute memory address |
| 2700 | 40C144 | .text | CALL [static] | Indirect call to absolute memory address |
| 288A | 40C144 | .text | CALL [static] | Indirect call to absolute memory address |
| 2E9A | 4EC148 | .text | CALL [static] | Indirect call to absolute memory address |
| 2EAE | 40C14C | .text | CALL [static] | Indirect call to absolute memory address |
| 2EB9 | 405070 | .text | CALL [static] | Indirect call to absolute memory address |
| 2F4E | 405070 | .text | CALL [static] | Indirect call to absolute memory address |
| 2F6A | 40C148 | .text | CALL [static] | Indirect call to absolute memory address |
| 2F7F | 40C14C | .text | CALL [static] | Indirect call to absolute memory address |
| 2F8A | 40C170 | .text | CALL [static] | Indirect call to absolute memory address |
| 2F96 | 7C40C180 | .text | CALL [static] | Indirect call to absolute memory address |
| 30BC | 401950 | .text | CALL [static] | Indirect call to absolute memory address |
| 3C1C | 40C154 | .text | CALL [static] | Indirect call to absolute memory address |
| 3D6B | 40C154 | .text | CALL [static] | Indirect call to absolute memory address |
| 3E46 | 404DC0 | .text | CALL [static] | Indirect call to absolute memory address |
| 4032 | 3040C16C | .text | CALL [static] | Indirect call to absolute memory address |
| 4222 | 3140C180 | .text | CALL [static] | Indirect call to absolute memory address |
| 4555 | 402D70 | .text | CALL [static] | Indirect call to absolute memory address |
| 45B1 | F65F55 | .text | CALL [static] | Indirect call to absolute memory address |
| 46A6 | 4F40C17D | .text | CALL [static] | Indirect call to absolute memory address |
| 47C0 | 4F40C17D | .text | CALL [static] | Indirect call to absolute memory address |
| 487F | 4F40C17D | .text | CALL [static] | Indirect call to absolute memory address |
| 503C | AFC15C | .text | CALL [static] | Indirect call to absolute memory address |
| 555A | F265C | .text | CALL [static] | Indirect call to absolute memory address |
| 5BF1 | DC17C | .text | CALL [static] | Indirect call to absolute memory address |
| 5D57 | 40C05C | .text | CALL [static] | Indirect call to absolute memory address |
| 5DB4 | 40C091 | .text | CALL [static] | Indirect call to absolute memory address |
| 5DDD | 40C15C | .text | CALL [static] | Indirect call to absolute memory address |
| 5E25 | 40C130 | .text | CALL [static] | Indirect call to absolute memory address |
| 5E3A | 407B4C | .text | CALL [static] | Indirect call to absolute memory address |
| 5E8C | 40C15C | .text | CALL [static] | Indirect call to absolute memory address |
| 5E9F | 40C15C | .text | CALL [static] | Indirect call to absolute memory address |
| 5EC5 | 40C120 | .text | CALL [static] | Indirect call to absolute memory address |
| 5F54 | 40C060 | .text | CALL [static] | Indirect call to absolute memory address |
| 5F98 | 77C110 | .text | CALL [static] | Indirect call to absolute memory address |
| 5FD0 | 40C1D4 | .text | CALL [static] | Indirect call to absolute memory address |
| 5FF2 | 40C1D4 | .text | CALL [static] | Indirect call to absolute memory address |
| 5FFE | 28C0CB | .text | CALL [static] | Indirect call to absolute memory address |
| 661B | 40C1BC | .text | CALL [static] | Indirect call to absolute memory address |
| 6664 | 40C011 | .text | CALL [static] | Indirect call to absolute memory address |
| 668C | 8FC1C0 | .text | CALL [static] | Indirect call to absolute memory address |
| 6923 | 40C1C4 | .text | CALL [static] | Indirect call to absolute memory address |
| 6974 | 4FC18D | .text | CALL [static] | Indirect call to absolute memory address |
| 6BA9 | 40C088 | .text | CALL [static] | Indirect call to absolute memory address |
| 6C41 | 40C084 | .text | CALL [static] | Indirect call to absolute memory address |
| 6C4F | 40C0EF | .text | CALL [static] | Indirect call to absolute memory address |
| 6C7C | 40C090 | .text | CALL [static] | Indirect call to absolute memory address |
| 6D21 | 40C080 | .text | CALL [static] | Indirect call to absolute memory address |
| 6D78 | 40C090 | .text | CALL [static] | Indirect call to absolute memory address |
| 6E96 | 40C090 | .text | CALL [static] | Indirect call to absolute memory address |
| 6ED7 | 40556C | .text | CALL [static] | Indirect call to absolute memory address |
| 6FF2 | 40C1C8 | .text | CALL [static] | Indirect call to absolute memory address |
| 707E | 40C1AC | .text | CALL [static] | Indirect call to absolute memory address |
| 717E | 40C108 | .text | CALL [static] | Indirect call to absolute memory address |
| 72BC | 40C17C | .text | CALL [static] | Indirect call to absolute memory address |
| 7351 | 40C134 | .text | CALL [static] | Indirect call to absolute memory address |
| 822C | D2C1C1 | .text | CALL [static] | Indirect call to absolute memory address |
| 83D9 | 40C168 | .text | CALL [static] | Indirect call to absolute memory address |
| 89F0 | B2C094 | .text | CALL [static] | Indirect call to absolute memory address |
| 8A87 | BC1AF | .text | CALL [static] | Indirect call to absolute memory address |
| 8AF3 | 40C198 | .text | CALL [static] | Indirect call to absolute memory address |
| 8B7C | 40C198 | .text | CALL [static] | Indirect call to absolute memory address |
| 8BE8 | 40E2B4 | .text | CALL [static] | Indirect call to absolute memory address |
| 8E13 | 40E2B4 | .text | CALL [static] | Indirect call to absolute memory address |
| 8E6E | 40C105 | .text | CALL [static] | Indirect call to absolute memory address |
| 8ECD | 40C1B8 | .text | CALL [static] | Indirect call to absolute memory address |
| 8FA6 | 40C1B8 | .text | CALL [static] | Indirect call to absolute memory address |
| 8FF2 | 40C1B8 | .text | CALL [static] | Indirect call to absolute memory address |
| 905A | 40C1B8 | .text | CALL [static] | Indirect call to absolute memory address |
| 90C5 | 2140B5B8 | .text | CALL [static] | Indirect call to absolute memory address |
| 928B | 40C110 | .text | CALL [static] | Indirect call to absolute memory address |
| 92C8 | 409410 | .text | CALL [static] | Indirect call to absolute memory address |
| 9376 | 40D408 | .text | CALL [static] | Indirect call to absolute memory address |
| 9394 | 40C108 | .text | CALL [static] | Indirect call to absolute memory address |
| 93A1 | 40C0A4 | .text | CALL [static] | Indirect call to absolute memory address |
| 93B2 | 697FC18F | .text | CALL [static] | Indirect call to absolute memory address |
| 93BF | A6C0A4 | .text | CALL [static] | Indirect call to absolute memory address |
| 93CB | 409974 | .text | CALL [static] | Indirect call to absolute memory address |
| 93E7 | DD9384 | .text | CALL [static] | Indirect call to absolute memory address |
| 9536 | 40BEB0 | .text | CALL [static] | Indirect call to absolute memory address |
| 9550 | 40C0AC | .text | CALL [static] | Indirect call to absolute memory address |
| 95E9 | 40C0A8 | .text | CALL [static] | Indirect call to absolute memory address |
| 9724 | 40C0B8 | .text | CALL [static] | Indirect call to absolute memory address |
| 8020 | N/A | .text | Injected Junk Code | HitsBL=179/200 - UniqueHits=26 - Ratio=0,90 |
| 12000 | N/A | *Overlay* | 4E423130000000003680C14A01000000433A5C6C | NB10....6..J....C:\l |
| Extra Analysis |
| Metric | Value | Percentage |
|---|---|---|
| Ascii Code | 42734 | 57,9036% |
| Null Byte Code | 17992 | 24,3787% |
| NOP Cave Found | 0x9090909090 | Block Count: 65 | Total: 0,2202% |
© 2026 All rights reserved.