PREMIUM PESCAN.IO - Analysis Report |
|||||||
| File Structure |
|
PE Chart Code
Header PE (light blue)
Executable sections (pink)
Non-executable sections (black)
External injected code (red)
File Structure in red = malformed or corrupted header
Chart Code For Other Files
Printable characters (blue)
Non-printable characters (black)
| Information |
Icon: Size: 52,00 KBSHA-256 Hash: 13C73FB12CEE99EF733EC8C00D2826366662BF2482AAF337C833468EA6307B27 SHA-1 Hash: 448754CEB9CF0FAEFC5D66E9497D1D7ACFC9EB38 MD5 Hash: F23D607875BF460DCFF70D53F1A4E7F8 Imphash: AC50E2D8887B25BB7C869CEA2732EA10 MajorOSVersion: 4 MinorOSVersion: 0 CheckSum: 0001B745 EntryPoint (rva): C000 SizeOfHeaders: 1000 SizeOfImage: C019 ImageBase: 400000 Architecture: x86 ImportTable: 5694 IAT: 1000 Characteristics: 10F TimeDateStamp: 496DCED4 Date: 14/01/2009 11:39:00 File Type: EXE Number Of Sections: 4 ASLR: Disabled Section Names: .text, .data, .rsrc, .topo0 Number Of Executable Sections: 2 Subsystem: Windows GUI |
| Sections Info |
| Section Name | Flags | ROffset | RSize | VOffset | VSize | Entropy | Chi2 |
|---|---|---|---|---|---|---|---|
| .text | 0x60000020 Code Executable Readable |
1000 | 5000 | 1000 | 4EB0 |
|
|
| .data | 0xC0000040 Initialized Data Readable Writeable |
6000 | 1000 | 6000 | E54 |
|
|
| .rsrc | 0x40000040 Initialized Data Readable |
7000 | 5000 | 7000 | 450C |
|
|
| .topo0 | 0xE0000020 Code Executable Readable Writeable |
C000 | 1000 | C000 | 19 |
|
|
| Description |
| OriginalFilename: 414.dll CompanyName: 142 ProductName: 414 FileVersion: 1.10 ProductVersion: 1.10 Language: English (United States) (ID=0x409) CodePage: Unicode (UTF-16 LE) (0x4B0) |
| Binder/Joiner/Crypter |
| Dropper code detected (EOF) - 3,98 KB |
| Entry Point |
The section number (4) - (.topo0) have the Entry Point Information -> EntryPoint (calculated) - C000 Code -> 9090909090909090909090909090909090909090E9525BFFFF00000000000000000000000000000000000000000000000000 EP changed to another address -> (Address Of EntryPoint > Base Of Data) Assembler |NOP |NOP |NOP |NOP |NOP |NOP |NOP |NOP |NOP |NOP |NOP |NOP |NOP |NOP |NOP |NOP |NOP |NOP |NOP |NOP |JMP 0X401B6B |ADD BYTE PTR [EAX], AL |ADD BYTE PTR [EAX], AL |ADD BYTE PTR [EAX], AL |ADD BYTE PTR [EAX], AL |ADD BYTE PTR [EAX], AL |ADD BYTE PTR [EAX], AL |ADD BYTE PTR [EAX], AL |ADD BYTE PTR [EAX], AL |ADD BYTE PTR [EAX], AL |ADD BYTE PTR [EAX], AL |ADD BYTE PTR [EAX], AL |ADD BYTE PTR [EAX], AL |
| Signatures |
| CheckSum Integrity Problem: • Header: 112453 • Calculated: 79847 Rich Signature Analyzer: Code -> 7DE6A3D93987CD8A3987CD8A3987CD8ABA9BC38A3887CD8A5098C48A3F87CD8AD098C08A3887CD8A526963683987CD8A Footprint md5 Hash -> 9B18DCA024BCA76AA49589D278E05B1F • The Rich header apparently has not been modified Certificate - Digital Signature Not Found: • The file is not signed |
| Packer/Compiler |
| Compiler: Visual Basic 6 - (Native Code) Detect It Easy (die) • PE: compiler: Microsoft Visual Basic(6.0)[Native] • PE: linker: Microsoft Linker(6.0*)[-] • Entropy: 4.50599 |
| Suspicious Functions |
| Library | Function | Description |
|---|---|---|
| KERNEL32.DLL | GetModuleFileNameA | Possible Call API By Name | Retrieve the fully qualified path for the executable file of a specified module. |
| KERNEL32.DLL | VirtualAlloc | Possible Call API By Name | Reserve, commit, or both, a region of memory within the virtual address space of a process. |
| MSVBVM60.DLL | DllFunctionCall | It enables calling routines from external DLLs in VB code, integrating external code into Visual Basic projects. |
| KERNEL32.DLL | GetModuleFileNameA | Retrieve the fully qualified path for the executable file of a specified module. |
| KERNEL32.DLL | GetModuleHandleA | Retrieves a handle to the specified module. |
| KERNEL32.DLL | RtlMoveMemory | Moves a block of memory to another location. |
| KERNEL32.DLL | LoadLibraryA | Loads the specified module into the address space of the calling process. |
| KERNEL32.DLL | CreateToolhelp32Snapshot | Creates a snapshot of the specified processes, heaps, threads, and modules. |
| KERNEL32.DLL | WriteProcessMemory | Writes data to an area of memory in a specified process. |
| KERNEL32.DLL | GetProcAddress | Retrieves the address of an exported function or variable from the specified dynamic-link library (DLL). |
| USER32.DLL | CallWindowProcA | Invokes the window procedure for the specified window and messages. |
| ADVAPI32.DLL | CryptEncrypt | Performs a cryptographic operation on data in a data block. |
| ADVAPI32.DLL | CryptDecrypt | Performs a cryptographic operation on data in a data block. |
| SHELL32.DLL | ShellExecuteA | Performs a run operation on a specific file. |
| Windows REG (UNICODE) |
| Software\Microsoft\Windows\CurrentVersion SYSTEM\ControlSet001\Services\Disk\Enum |
| File Access |
| MSVBVM60.DLL advapi32.dll \WINDOWS\system32\msvbvm60.dll kernel32.dll VBA6.DLL shell32.dll .dat Temp |
| File Access (UNICODE) |
| cmd.exe lsass.exe \Lavasoft\Ad-Aware 2007\aawservice.exe aawservice.exe msnmsgr.exe \ESET\ESET NOD32 Antivirus\egui.exe egui.exe \ESET\ESET NOD32 Antivirus\ekrn.exe ekrn.exe \lsass.exe svchost.exe \explorer.exe explorer.exe \svchost.exe 414.dll dbghelp.dll sbiedll.dll 0.dll Temp WinDir ProgramFiles UserProfile |
| Interest's Words |
| Encrypt Decrypt PassWord exec |
| Interest's Words (UNICODE) |
| Virus start |
| Anti-VM/Sandbox/Debug Tricks (UNICODE) |
| SandBoxie Library - SbieDll.dll OllyDbg Libary - dbghelp.dll JoeBox ProductID - 55274-640-2673064-23950 CWSandbox ProductID - 76487-644-3177037-23510 Anubis ProductID - 76487-337-8429955-22614 |
| AV Services (UNICODE) |
| ekrn.exe - (ESET) egui.exe - (ESET) aawservice.exe - (Ad-Aware) |
| Strings/Hex Code Found With The File Rules |
| Rule Type | Encoding | Matched (Word) |
|---|---|---|
| Text | Ascii | Registry (RegOpenKeyEx) |
| Text | Ascii | File (GetTempPath) |
| Text | Unicode | Encryption (Microsoft Base Cryptographic Provider v1.0) |
| Text | Ascii | Encryption API (CryptAcquireContext) |
| Text | Ascii | Encryption API (CryptDeriveKey) |
| Text | Ascii | Encryption API (CryptDecrypt) |
| Text | Ascii | Encryption API (CryptReleaseContext) |
| Text | Ascii | Anti-Analysis VM (CreateToolhelp32Snapshot) |
| Text | Unicode | Stealth (GetThreadContext) |
| Text | Unicode | Stealth (SetThreadContext) |
| Text | Ascii | Stealth (CloseHandle) |
| Text | Unicode | Stealth (VirtualAlloc) |
| Text | Unicode | Stealth (NtUnmapViewOfSection) |
| Text | Ascii | Execution (CreateProcessA) |
| Text | Ascii | Execution (ShellExecute) |
| Text | Unicode | Execution (ResumeThread) |
| Text | Unicode | Sandbox Product ID (76487-337-8429955-22614) |
| Text | Unicode | Sandbox Product ID (76487-644-3177037-23510) |
| Text | Unicode | Sandbox Product ID (55274-640-2673064-23950) |
| Entry Point | Hex Pattern | Microsoft Visual C++ 8 |
| Entry Point | Hex Pattern | Microsoft Visual C++ 8.0 |
| Resources |
| Path | DataRVA | Size | FileOffset | Code | Text |
|---|---|---|---|---|---|
| \ICON\1\0 | 70E8 | 4228 | 70E8 | 28000000400000008000000001002000000000000042000000000000000000000000000000000000FFFFFF00FFFFFF00FFFF | (...@......... ......B............................ |
| \GROUP_ICON\1\0 | B310 | 14 | B310 | 0000010001004040000001002000284200000100 | ......@@.... .(B.... |
| \VERSION\1\1033 | B324 | 1E8 | B324 | E80134000000560053005F00560045005200530049004F004E005F0049004E0046004F0000003400BD04EFFE000001000100 | ..4...V.S._.V.E.R.S.I.O.N._.I.N.F.O...4........... |
| Intelligent String |
| • "0.dll • C:\Archivos de programa\Microsoft Visual Studio\VB98\VB6.OLB • VBA6.DLL • kernel32.dll • \svchost.exe • sbiedll.dll • dbghelp.dll • explorer.exe • \explorer.exe • svchost.exe • \lsass.exe • ekrn.exe • \ESET\ESET NOD32 Antivirus\ekrn.exe • egui.exe • \ESET\ESET NOD32 Antivirus\egui.exe • msnmsgr.exe • aawservice.exe • \Lavasoft\Ad-Aware 2007\aawservice.exe • lsass.exe • c:\windows\system32\msvbvm60.dll • advapi32.dll • 673353.tmp • cmd /k • cmd.exe • cmd /c • MSVBVM60.DLL • 414.dll |
| Flow Anomalies |
| Offset | FlowVA | Section | Description |
|---|---|---|---|
| 1230 | 4010A8 | .text | JMP [static] | Indirect jump to absolute memory address |
| 1236 | 4010FC | .text | JMP [static] | Indirect jump to absolute memory address |
| 123C | 40111C | .text | JMP [static] | Indirect jump to absolute memory address |
| 1242 | 401080 | .text | JMP [static] | Indirect jump to absolute memory address |
| 1248 | 40105C | .text | JMP [static] | Indirect jump to absolute memory address |
| 124E | 401168 | .text | JMP [static] | Indirect jump to absolute memory address |
| 1254 | 401034 | .text | JMP [static] | Indirect jump to absolute memory address |
| 125A | 401184 | .text | JMP [static] | Indirect jump to absolute memory address |
| 1260 | 401084 | .text | JMP [static] | Indirect jump to absolute memory address |
| 1266 | 401180 | .text | JMP [static] | Indirect jump to absolute memory address |
| 126C | 40116C | .text | JMP [static] | Indirect jump to absolute memory address |
| 1272 | 401110 | .text | JMP [static] | Indirect jump to absolute memory address |
| 1278 | 4010DC | .text | JMP [static] | Indirect jump to absolute memory address |
| 127E | 40110C | .text | JMP [static] | Indirect jump to absolute memory address |
| 1284 | 401040 | .text | JMP [static] | Indirect jump to absolute memory address |
| 128A | 40100C | .text | JMP [static] | Indirect jump to absolute memory address |
| 1290 | 4011B0 | .text | JMP [static] | Indirect jump to absolute memory address |
| 1296 | 401008 | .text | JMP [static] | Indirect jump to absolute memory address |
| 129C | 4011D0 | .text | JMP [static] | Indirect jump to absolute memory address |
| 12A2 | 401144 | .text | JMP [static] | Indirect jump to absolute memory address |
| 12A8 | 401098 | .text | JMP [static] | Indirect jump to absolute memory address |
| 12AE | 4010F4 | .text | JMP [static] | Indirect jump to absolute memory address |
| 12B4 | 4011C4 | .text | JMP [static] | Indirect jump to absolute memory address |
| 12BA | 4011C0 | .text | JMP [static] | Indirect jump to absolute memory address |
| 12C0 | 4010D8 | .text | JMP [static] | Indirect jump to absolute memory address |
| 12C6 | 401030 | .text | JMP [static] | Indirect jump to absolute memory address |
| 12CC | 4010C8 | .text | JMP [static] | Indirect jump to absolute memory address |
| 12D2 | 40102C | .text | JMP [static] | Indirect jump to absolute memory address |
| 12D8 | 401178 | .text | JMP [static] | Indirect jump to absolute memory address |
| 12DE | 40104C | .text | JMP [static] | Indirect jump to absolute memory address |
| 12E4 | 4011CC | .text | JMP [static] | Indirect jump to absolute memory address |
| 12EA | 401130 | .text | JMP [static] | Indirect jump to absolute memory address |
| 12F0 | 401028 | .text | JMP [static] | Indirect jump to absolute memory address |
| 12F6 | 40119C | .text | JMP [static] | Indirect jump to absolute memory address |
| 12FC | 401064 | .text | JMP [static] | Indirect jump to absolute memory address |
| 1302 | 4010D0 | .text | JMP [static] | Indirect jump to absolute memory address |
| 1308 | 4011A8 | .text | JMP [static] | Indirect jump to absolute memory address |
| 130E | 40112C | .text | JMP [static] | Indirect jump to absolute memory address |
| 1314 | 40108C | .text | JMP [static] | Indirect jump to absolute memory address |
| 131A | 401094 | .text | JMP [static] | Indirect jump to absolute memory address |
| 1320 | 401128 | .text | JMP [static] | Indirect jump to absolute memory address |
| 1326 | 401074 | .text | JMP [static] | Indirect jump to absolute memory address |
| 132C | 401100 | .text | JMP [static] | Indirect jump to absolute memory address |
| 1332 | 401014 | .text | JMP [static] | Indirect jump to absolute memory address |
| 1338 | 4010B0 | .text | JMP [static] | Indirect jump to absolute memory address |
| 133E | 4010C4 | .text | JMP [static] | Indirect jump to absolute memory address |
| 1344 | 401164 | .text | JMP [static] | Indirect jump to absolute memory address |
| 134A | 4010AC | .text | JMP [static] | Indirect jump to absolute memory address |
| 1350 | 401024 | .text | JMP [static] | Indirect jump to absolute memory address |
| 1356 | 40114C | .text | JMP [static] | Indirect jump to absolute memory address |
| 135C | 401170 | .text | JMP [static] | Indirect jump to absolute memory address |
| 1362 | 4011DC | .text | JMP [static] | Indirect jump to absolute memory address |
| 1368 | 401104 | .text | JMP [static] | Indirect jump to absolute memory address |
| 136E | 401198 | .text | JMP [static] | Indirect jump to absolute memory address |
| 1374 | 401020 | .text | JMP [static] | Indirect jump to absolute memory address |
| 137A | 4011A4 | .text | JMP [static] | Indirect jump to absolute memory address |
| 1380 | 401054 | .text | JMP [static] | Indirect jump to absolute memory address |
| 1386 | 401058 | .text | JMP [static] | Indirect jump to absolute memory address |
| 138C | 40101C | .text | JMP [static] | Indirect jump to absolute memory address |
| 1392 | 401140 | .text | JMP [static] | Indirect jump to absolute memory address |
| 1398 | 401108 | .text | JMP [static] | Indirect jump to absolute memory address |
| 139E | 4011BC | .text | JMP [static] | Indirect jump to absolute memory address |
| 13A4 | 401148 | .text | JMP [static] | Indirect jump to absolute memory address |
| 13AA | 4011B8 | .text | JMP [static] | Indirect jump to absolute memory address |
| 13B0 | 401194 | .text | JMP [static] | Indirect jump to absolute memory address |
| 13B6 | 401050 | .text | JMP [static] | Indirect jump to absolute memory address |
| 13BC | 40103C | .text | JMP [static] | Indirect jump to absolute memory address |
| 13C2 | 401118 | .text | JMP [static] | Indirect jump to absolute memory address |
| 13C8 | 401090 | .text | JMP [static] | Indirect jump to absolute memory address |
| 13CE | 401124 | .text | JMP [static] | Indirect jump to absolute memory address |
| 13D4 | 401134 | .text | JMP [static] | Indirect jump to absolute memory address |
| 13DA | 401048 | .text | JMP [static] | Indirect jump to absolute memory address |
| 13E0 | 4010E8 | .text | JMP [static] | Indirect jump to absolute memory address |
| 13E6 | 401160 | .text | JMP [static] | Indirect jump to absolute memory address |
| 13EC | 401004 | .text | JMP [static] | Indirect jump to absolute memory address |
| 13F2 | 401044 | .text | JMP [static] | Indirect jump to absolute memory address |
| 13F8 | 401000 | .text | JMP [static] | Indirect jump to absolute memory address |
| 13FE | 4010E0 | .text | JMP [static] | Indirect jump to absolute memory address |
| 1404 | 40107C | .text | JMP [static] | Indirect jump to absolute memory address |
| 140A | 4010BC | .text | JMP [static] | Indirect jump to absolute memory address |
| 1410 | 4010A4 | .text | JMP [static] | Indirect jump to absolute memory address |
| 1416 | 4010F0 | .text | JMP [static] | Indirect jump to absolute memory address |
| 141C | 40117C | .text | JMP [static] | Indirect jump to absolute memory address |
| 1422 | 40106C | .text | JMP [static] | Indirect jump to absolute memory address |
| 1428 | 4011AC | .text | JMP [static] | Indirect jump to absolute memory address |
| 142E | 40118C | .text | JMP [static] | Indirect jump to absolute memory address |
| 1434 | 4010C0 | .text | JMP [static] | Indirect jump to absolute memory address |
| 143A | 4010D4 | .text | JMP [static] | Indirect jump to absolute memory address |
| 1440 | 40115C | .text | JMP [static] | Indirect jump to absolute memory address |
| 1446 | 4010B8 | .text | JMP [static] | Indirect jump to absolute memory address |
| 144C | 401060 | .text | JMP [static] | Indirect jump to absolute memory address |
| 1452 | 4011B4 | .text | JMP [static] | Indirect jump to absolute memory address |
| 1458 | 401114 | .text | JMP [static] | Indirect jump to absolute memory address |
| 145E | 4011D8 | .text | JMP [static] | Indirect jump to absolute memory address |
| 1464 | 401068 | .text | JMP [static] | Indirect jump to absolute memory address |
| 146A | 40109C | .text | JMP [static] | Indirect jump to absolute memory address |
| 1470 | 401120 | .text | JMP [static] | Indirect jump to absolute memory address |
| 1476 | 401158 | .text | JMP [static] | Indirect jump to absolute memory address |
| 147C | 401154 | .text | JMP [static] | Indirect jump to absolute memory address |
| 1482 | 401038 | .text | JMP [static] | Indirect jump to absolute memory address |
| C000 | N/A | .topo0 | Entry Point Sled | NOPs=20 |
| C014 | 4014FC | .text | Possible Original Entry Point Relocation | Score=7/7 - Redirects=3 - PreJumpInstructions=20 - JumpType=JMP_NEAR - TargetOffset=14FC - TargetSection=.text |
| C000-CFFF | C000 | .topo0 | Executable section anomaly, first bytes: 9090909090909090 |
| Extra Analysis |
| Metric | Value | Percentage |
|---|---|---|
| Ascii Code | 17219 | 32,3374% |
| Null Byte Code | 24331 | 45,6937% |
| NOP Cave Found | 0x9090909090 | Block Count: 6 | Total: 0,0282% |
© 2026 All rights reserved.