PESCAN.IO - Analysis Report Basic

File Structure
Analysis Image
PE Chart Code
Header PE (light blue)
Executable sections (pink)
Non-executable sections (black)
External injected code (red)
File Structure in red = malformed or corrupted header

Chart Code For Other Files
Printable characters (blue)
Non-printable characters (black)
Information
Icon: Icon
Size: 395,00 KB
SHA-256 Hash: 46D775DA900DBB5F7EF647E84F651E50B59CE65C04BA29EC8DECA49F45E506FC
SHA-1 Hash: 0A89EE7E2FF077C102CA3AB3A091F58EFEFEAFFD
MD5 Hash: EF17CC4494B54299C828B1510A7CADA8
Imphash: F34D5F2D4577ED6D9CEEC516C1F5A744
MajorOSVersion: 4
MinorOSVersion: 0
CheckSum: 00000000
EntryPoint (rva): 3C351
SizeOfHeaders: 400
SizeOfImage: A2000
ImageBase: 400000
Architecture: x86
ImportTable: 3F8E4
IAT: 3A000
Characteristics: 22
TimeDateStamp: C2F6838B
Date: 26/08/2073 1:10:35
File Type: EXE
Number Of Sections: 6
ASLR: Disabled
Section Names: .text, .87L, .9i, .?C$, .rsrc, .reloc
Number Of Executable Sections: 3
Subsystem: Windows Console
UAC Execution Level Manifest: asInvoker
[Incomplete Binary or Compressor Packer - 253,00 KB Missing]

Sections Info
Section Name Flags ROffset RSize VOffset VSizeEntropyChi2
.text
0x60000020
Code
Executable
Readable
0 0 2000 5B08
N/A
N/A
.87L
0x60000020
Code
Executable
Readable
0 0 8000 319FF
N/A
N/A
.9i
0xC0000040
Initialized Data
Readable
Writeable
400 200 3A000 8
0.0408
129539
.?C$
0x60000020
Code
Executable
Readable
600 60800 3C000 606FC
7.5566
783956.85
.rsrc
0x40000040
Initialized Data
Readable
60E00 1C00 9E000 1BA0
3.8017
632263.36
.reloc
0x42000040
Initialized Data
GP-Relative
Readable
62A00 200 A0000 C
0.1184
127510
Description
OriginalFilename: RSKeyGen.exe
LegalCopyright: Copyright 2025
ProductName: RSKeyGen
FileVersion: 1.0.0.0
FileDescription: RSKeyGen
ProductVersion: 1.0.0.0
Language: Unknown (ID=0x0)
CodePage: Unicode (UTF-16 LE) (0x4B0)

Entry Point
The section number (4) - (.?C$) have the Entry Point
Information -> EntryPoint (calculated) - 951
Code -> FF2500A043008DC6BB033B7047BC033FDF37BC0339FE713FBB033AD3E3BC0334AB92080634B9FC387A3445B6A0BC033043BE
EP changed to another address -> (Address Of EntryPoint > Base Of Data)
Assembler
|JMP DWORD PTR [0X43A000]
Signatures
Certificate - Digital Signature Not Found:
• The file is not signed

Packer/Compiler
Compiler: Microsoft Visual .NET - (You can use a decompiler for this...)
AnyCPU: False
Version: v4.0
--------> Agile .NET Obfuscator
Detect It Easy (die)
PE: library: .NET(v4.0.30319)[-]
PE: linker: Microsoft Linker(48.0)[-]
Entropy: 7.49808

File Access
RSKeyGen.exe
mscoree.dll

File Access (UNICODE)
RSKeyGen.exe

Interest's Words
exec
attrib
start
hostname
replace

IP Addresses
17.0.0.0

Strings/Hex Code Found With The File Rules
Rule Type Encoding Matched (Word)
Text Ascii Encryption (FromBase64String)
Text Ascii Encryption (ToBase64String)
Text Ascii Technique used to make code harder to analyze (Obfuscation)
Entry Point Hex Pattern XE Executable Image (using DOSExtender)
Resources
Path DataRVA Size FileOffset CodeText
\ICON\1\0 9E120 10A8 60F20 2800000020000000400000000100200000000000002000000000000000000000000000000000000000000000000000000000(... ...@..... ...... ............................
\ICON\2\0 9F1D8 468 61FD8 2800000010000000200000000100200000000000000800000000000000000000000000000000000000000000000000000000(....... ..... ...................................
\GROUP_ICON\32512\0 9F650 22 62450 0000010002002020000001002000A810000001001010000001002000680400000200...... .... ............. .h.....
\VERSION\1\0 9F684 31C 62484 1C0334000000560053005F00560045005200530049004F004E005F0049004E0046004F0000000000BD04EFFE000001000000..4...V.S._.V.E.R.S.I.O.N._.I.N.F.O...............
\24\1\0 9F9B0 1EA 627B0 EFBBBF3C3F786D6C2076657273696F6E3D22312E302220656E636F64696E673D225554462D3822207374616E64616C6F6E65...<?xml version="1.0" encoding="UTF-8" standalone
Intelligent String
• 1.0.0.0
• RSKeyGen.exe

Flow Anomalies
Offset FlowVA Section Description
951 43A000 .?C$ JMP [static] | Indirect jump to absolute memory address
9505 43A000 .?C$ CALL [static] | Indirect call to absolute memory address
DD07 43A000 .?C$ JMP [static] | Indirect jump to absolute memory address
E02C 2FF33225 .?C$ CALL [static] | Indirect call to absolute memory address
14A5C 3335CFAD .?C$ CALL [static] | Indirect call to absolute memory address
220A6 4BF0975A .?C$ JMP [static] | Indirect jump to absolute memory address
23138 4BF0975A .?C$ CALL [static] | Indirect call to absolute memory address
29B67 4BF0975A .?C$ CALL [static] | Indirect call to absolute memory address
31F7A F2E31B0 .?C$ CALL [static] | Indirect call to absolute memory address
600-60DFF 3C000 .?C$ Executable section anomaly, first bytes: 890A35053A93B232
Extra Analysis
Metric Value Percentage
Ascii Code 257236 63,5967%
Null Byte Code 38883 9,6131%
© 2026 All rights reserved.