PREMIUM PESCAN.IO - Analysis Report

File Structure
Analysis Image
PE Chart Code
Header PE (light blue)
Executable sections (pink)
Non-executable sections (black)
External injected code (red)
File Structure in red = malformed or corrupted header

Chart Code For Other Files
Printable characters (blue)
Non-printable characters (black)
Information
Icon: Icon
Size: 52,00 KB
SHA-256 Hash: 13C73FB12CEE99EF733EC8C00D2826366662BF2482AAF337C833468EA6307B27
SHA-1 Hash: 448754CEB9CF0FAEFC5D66E9497D1D7ACFC9EB38
MD5 Hash: F23D607875BF460DCFF70D53F1A4E7F8
Imphash: AC50E2D8887B25BB7C869CEA2732EA10
MajorOSVersion: 4
MinorOSVersion: 0
CheckSum: 0001B745
EntryPoint (rva): C000
SizeOfHeaders: 1000
SizeOfImage: C019
ImageBase: 400000
Architecture: x86
ImportTable: 5694
IAT: 1000
Characteristics: 10F
TimeDateStamp: 496DCED4
Date: 14/01/2009 11:39:00
File Type: EXE
Number Of Sections: 4
ASLR: Disabled
Section Names: .text, .data, .rsrc, .topo0
Number Of Executable Sections: 2
Subsystem: Windows GUI

Sections Info
Section Name Flags ROffset RSize VOffset VSizeEntropyChi2
.text
0x60000020
Code
Executable
Readable
1000 5000 1000 4EB0
5.1925
681335.4
.data
0xC0000040
Initialized Data
Readable
Writeable
6000 1000 6000 E54
0.0159
1041922
.rsrc
0x40000040
Initialized Data
Readable
7000 5000 7000 450C
5.1267
738643.13
.topo0
0xE0000020
Code
Executable
Readable
Writeable
C000 1000 C000 19
0.0604
1031744.5
Description
OriginalFilename: 414.dll
CompanyName: 142
ProductName: 414
FileVersion: 1.10
ProductVersion: 1.10
Language: English (United States) (ID=0x409)
CodePage: Unicode (UTF-16 LE) (0x4B0)

Binder/Joiner/Crypter
Dropper code detected (EOF) - 3,98 KB

Entry Point
The section number (4) - (.topo0) have the Entry Point
Information -> EntryPoint (calculated) - C000
Code -> 9090909090909090909090909090909090909090E9525BFFFF00000000000000000000000000000000000000000000000000
EP changed to another address -> (Address Of EntryPoint > Base Of Data)
Assembler
|NOP
|NOP
|NOP
|NOP
|NOP
|NOP
|NOP
|NOP
|NOP
|NOP
|NOP
|NOP
|NOP
|NOP
|NOP
|NOP
|NOP
|NOP
|NOP
|NOP
|JMP 0X401B6B
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
|ADD BYTE PTR [EAX], AL
Signatures
CheckSum Integrity Problem:
Header: 112453
Calculated: 79847
Rich Signature Analyzer:
Code -> 7DE6A3D93987CD8A3987CD8A3987CD8ABA9BC38A3887CD8A5098C48A3F87CD8AD098C08A3887CD8A526963683987CD8A
Footprint md5 Hash -> 9B18DCA024BCA76AA49589D278E05B1F
• The Rich header apparently has not been modified
Certificate - Digital Signature Not Found:
• The file is not signed

Packer/Compiler
Compiler: Visual Basic 6 - (Native Code)
Detect It Easy (die)
PE: compiler: Microsoft Visual Basic(6.0)[Native]
PE: linker: Microsoft Linker(6.0*)[-]
Entropy: 4.50599

Suspicious Functions
Library Function Description
KERNEL32.DLL GetModuleFileNameA | Possible Call API By Name Retrieve the fully qualified path for the executable file of a specified module.
KERNEL32.DLL VirtualAlloc | Possible Call API By Name Reserve, commit, or both, a region of memory within the virtual address space of a process.
MSVBVM60.DLL DllFunctionCall It enables calling routines from external DLLs in VB code, integrating external code into Visual Basic projects.
KERNEL32.DLL GetModuleFileNameA Retrieve the fully qualified path for the executable file of a specified module.
KERNEL32.DLL GetModuleHandleA Retrieves a handle to the specified module.
KERNEL32.DLL RtlMoveMemory Moves a block of memory to another location.
KERNEL32.DLL LoadLibraryA Loads the specified module into the address space of the calling process.
KERNEL32.DLL CreateToolhelp32Snapshot Creates a snapshot of the specified processes, heaps, threads, and modules.
KERNEL32.DLL WriteProcessMemory Writes data to an area of memory in a specified process.
KERNEL32.DLL GetProcAddress Retrieves the address of an exported function or variable from the specified dynamic-link library (DLL).
USER32.DLL CallWindowProcA Invokes the window procedure for the specified window and messages.
ADVAPI32.DLL CryptEncrypt Performs a cryptographic operation on data in a data block.
ADVAPI32.DLL CryptDecrypt Performs a cryptographic operation on data in a data block.
SHELL32.DLL ShellExecuteA Performs a run operation on a specific file.
Windows REG (UNICODE)
Software\Microsoft\Windows\CurrentVersion
SYSTEM\ControlSet001\Services\Disk\Enum

File Access
MSVBVM60.DLL
advapi32.dll
\WINDOWS\system32\msvbvm60.dll
kernel32.dll
VBA6.DLL
shell32.dll
.dat
Temp

File Access (UNICODE)
cmd.exe
lsass.exe
\Lavasoft\Ad-Aware 2007\aawservice.exe
aawservice.exe
msnmsgr.exe
\ESET\ESET NOD32 Antivirus\egui.exe
egui.exe
\ESET\ESET NOD32 Antivirus\ekrn.exe
ekrn.exe
\lsass.exe
svchost.exe
\explorer.exe
explorer.exe
\svchost.exe
414.dll
dbghelp.dll
sbiedll.dll
0.dll
Temp
WinDir
ProgramFiles
UserProfile

Interest's Words
Encrypt
Decrypt
PassWord
exec

Interest's Words (UNICODE)
Virus
start

Anti-VM/Sandbox/Debug Tricks (UNICODE)
SandBoxie Library - SbieDll.dll
OllyDbg Libary - dbghelp.dll
JoeBox ProductID - 55274-640-2673064-23950
CWSandbox ProductID - 76487-644-3177037-23510
Anubis ProductID - 76487-337-8429955-22614

AV Services (UNICODE)
ekrn.exe - (ESET)
egui.exe - (ESET)
aawservice.exe - (Ad-Aware)

Strings/Hex Code Found With The File Rules
Rule Type Encoding Matched (Word)
Text Ascii Registry (RegOpenKeyEx)
Text Ascii File (GetTempPath)
Text Unicode Encryption (Microsoft Base Cryptographic Provider v1.0)
Text Ascii Encryption API (CryptAcquireContext)
Text Ascii Encryption API (CryptDeriveKey)
Text Ascii Encryption API (CryptDecrypt)
Text Ascii Encryption API (CryptReleaseContext)
Text Ascii Anti-Analysis VM (CreateToolhelp32Snapshot)
Text Unicode Stealth (GetThreadContext)
Text Unicode Stealth (SetThreadContext)
Text Ascii Stealth (CloseHandle)
Text Unicode Stealth (VirtualAlloc)
Text Unicode Stealth (NtUnmapViewOfSection)
Text Ascii Execution (CreateProcessA)
Text Ascii Execution (ShellExecute)
Text Unicode Execution (ResumeThread)
Text Unicode Sandbox Product ID (76487-337-8429955-22614)
Text Unicode Sandbox Product ID (76487-644-3177037-23510)
Text Unicode Sandbox Product ID (55274-640-2673064-23950)
Entry Point Hex Pattern Microsoft Visual C++ 8
Entry Point Hex Pattern Microsoft Visual C++ 8.0
Resources
Path DataRVA Size FileOffset CodeText
\ICON\1\0 70E8 4228 70E8 28000000400000008000000001002000000000000042000000000000000000000000000000000000FFFFFF00FFFFFF00FFFF(...@......... ......B............................
\GROUP_ICON\1\0 B310 14 B310 0000010001004040000001002000284200000100......@@.... .(B....
\VERSION\1\1033 B324 1E8 B324 E80134000000560053005F00560045005200530049004F004E005F0049004E0046004F0000003400BD04EFFE000001000100..4...V.S._.V.E.R.S.I.O.N._.I.N.F.O...4...........
Intelligent String
• "0.dll
• C:\Archivos de programa\Microsoft Visual Studio\VB98\VB6.OLB
• VBA6.DLL
• kernel32.dll
• \svchost.exe
• sbiedll.dll
• dbghelp.dll
• explorer.exe
• \explorer.exe
• svchost.exe
• \lsass.exe
• ekrn.exe
• \ESET\ESET NOD32 Antivirus\ekrn.exe
• egui.exe
• \ESET\ESET NOD32 Antivirus\egui.exe
• msnmsgr.exe
• aawservice.exe
• \Lavasoft\Ad-Aware 2007\aawservice.exe
• lsass.exe
• c:\windows\system32\msvbvm60.dll
• advapi32.dll
• 673353.tmp
• cmd /k
• cmd.exe
• cmd /c
• MSVBVM60.DLL
• 414.dll

Flow Anomalies
Offset FlowVA Section Description
1230 4010A8 .text JMP [static] | Indirect jump to absolute memory address
1236 4010FC .text JMP [static] | Indirect jump to absolute memory address
123C 40111C .text JMP [static] | Indirect jump to absolute memory address
1242 401080 .text JMP [static] | Indirect jump to absolute memory address
1248 40105C .text JMP [static] | Indirect jump to absolute memory address
124E 401168 .text JMP [static] | Indirect jump to absolute memory address
1254 401034 .text JMP [static] | Indirect jump to absolute memory address
125A 401184 .text JMP [static] | Indirect jump to absolute memory address
1260 401084 .text JMP [static] | Indirect jump to absolute memory address
1266 401180 .text JMP [static] | Indirect jump to absolute memory address
126C 40116C .text JMP [static] | Indirect jump to absolute memory address
1272 401110 .text JMP [static] | Indirect jump to absolute memory address
1278 4010DC .text JMP [static] | Indirect jump to absolute memory address
127E 40110C .text JMP [static] | Indirect jump to absolute memory address
1284 401040 .text JMP [static] | Indirect jump to absolute memory address
128A 40100C .text JMP [static] | Indirect jump to absolute memory address
1290 4011B0 .text JMP [static] | Indirect jump to absolute memory address
1296 401008 .text JMP [static] | Indirect jump to absolute memory address
129C 4011D0 .text JMP [static] | Indirect jump to absolute memory address
12A2 401144 .text JMP [static] | Indirect jump to absolute memory address
12A8 401098 .text JMP [static] | Indirect jump to absolute memory address
12AE 4010F4 .text JMP [static] | Indirect jump to absolute memory address
12B4 4011C4 .text JMP [static] | Indirect jump to absolute memory address
12BA 4011C0 .text JMP [static] | Indirect jump to absolute memory address
12C0 4010D8 .text JMP [static] | Indirect jump to absolute memory address
12C6 401030 .text JMP [static] | Indirect jump to absolute memory address
12CC 4010C8 .text JMP [static] | Indirect jump to absolute memory address
12D2 40102C .text JMP [static] | Indirect jump to absolute memory address
12D8 401178 .text JMP [static] | Indirect jump to absolute memory address
12DE 40104C .text JMP [static] | Indirect jump to absolute memory address
12E4 4011CC .text JMP [static] | Indirect jump to absolute memory address
12EA 401130 .text JMP [static] | Indirect jump to absolute memory address
12F0 401028 .text JMP [static] | Indirect jump to absolute memory address
12F6 40119C .text JMP [static] | Indirect jump to absolute memory address
12FC 401064 .text JMP [static] | Indirect jump to absolute memory address
1302 4010D0 .text JMP [static] | Indirect jump to absolute memory address
1308 4011A8 .text JMP [static] | Indirect jump to absolute memory address
130E 40112C .text JMP [static] | Indirect jump to absolute memory address
1314 40108C .text JMP [static] | Indirect jump to absolute memory address
131A 401094 .text JMP [static] | Indirect jump to absolute memory address
1320 401128 .text JMP [static] | Indirect jump to absolute memory address
1326 401074 .text JMP [static] | Indirect jump to absolute memory address
132C 401100 .text JMP [static] | Indirect jump to absolute memory address
1332 401014 .text JMP [static] | Indirect jump to absolute memory address
1338 4010B0 .text JMP [static] | Indirect jump to absolute memory address
133E 4010C4 .text JMP [static] | Indirect jump to absolute memory address
1344 401164 .text JMP [static] | Indirect jump to absolute memory address
134A 4010AC .text JMP [static] | Indirect jump to absolute memory address
1350 401024 .text JMP [static] | Indirect jump to absolute memory address
1356 40114C .text JMP [static] | Indirect jump to absolute memory address
135C 401170 .text JMP [static] | Indirect jump to absolute memory address
1362 4011DC .text JMP [static] | Indirect jump to absolute memory address
1368 401104 .text JMP [static] | Indirect jump to absolute memory address
136E 401198 .text JMP [static] | Indirect jump to absolute memory address
1374 401020 .text JMP [static] | Indirect jump to absolute memory address
137A 4011A4 .text JMP [static] | Indirect jump to absolute memory address
1380 401054 .text JMP [static] | Indirect jump to absolute memory address
1386 401058 .text JMP [static] | Indirect jump to absolute memory address
138C 40101C .text JMP [static] | Indirect jump to absolute memory address
1392 401140 .text JMP [static] | Indirect jump to absolute memory address
1398 401108 .text JMP [static] | Indirect jump to absolute memory address
139E 4011BC .text JMP [static] | Indirect jump to absolute memory address
13A4 401148 .text JMP [static] | Indirect jump to absolute memory address
13AA 4011B8 .text JMP [static] | Indirect jump to absolute memory address
13B0 401194 .text JMP [static] | Indirect jump to absolute memory address
13B6 401050 .text JMP [static] | Indirect jump to absolute memory address
13BC 40103C .text JMP [static] | Indirect jump to absolute memory address
13C2 401118 .text JMP [static] | Indirect jump to absolute memory address
13C8 401090 .text JMP [static] | Indirect jump to absolute memory address
13CE 401124 .text JMP [static] | Indirect jump to absolute memory address
13D4 401134 .text JMP [static] | Indirect jump to absolute memory address
13DA 401048 .text JMP [static] | Indirect jump to absolute memory address
13E0 4010E8 .text JMP [static] | Indirect jump to absolute memory address
13E6 401160 .text JMP [static] | Indirect jump to absolute memory address
13EC 401004 .text JMP [static] | Indirect jump to absolute memory address
13F2 401044 .text JMP [static] | Indirect jump to absolute memory address
13F8 401000 .text JMP [static] | Indirect jump to absolute memory address
13FE 4010E0 .text JMP [static] | Indirect jump to absolute memory address
1404 40107C .text JMP [static] | Indirect jump to absolute memory address
140A 4010BC .text JMP [static] | Indirect jump to absolute memory address
1410 4010A4 .text JMP [static] | Indirect jump to absolute memory address
1416 4010F0 .text JMP [static] | Indirect jump to absolute memory address
141C 40117C .text JMP [static] | Indirect jump to absolute memory address
1422 40106C .text JMP [static] | Indirect jump to absolute memory address
1428 4011AC .text JMP [static] | Indirect jump to absolute memory address
142E 40118C .text JMP [static] | Indirect jump to absolute memory address
1434 4010C0 .text JMP [static] | Indirect jump to absolute memory address
143A 4010D4 .text JMP [static] | Indirect jump to absolute memory address
1440 40115C .text JMP [static] | Indirect jump to absolute memory address
1446 4010B8 .text JMP [static] | Indirect jump to absolute memory address
144C 401060 .text JMP [static] | Indirect jump to absolute memory address
1452 4011B4 .text JMP [static] | Indirect jump to absolute memory address
1458 401114 .text JMP [static] | Indirect jump to absolute memory address
145E 4011D8 .text JMP [static] | Indirect jump to absolute memory address
1464 401068 .text JMP [static] | Indirect jump to absolute memory address
146A 40109C .text JMP [static] | Indirect jump to absolute memory address
1470 401120 .text JMP [static] | Indirect jump to absolute memory address
1476 401158 .text JMP [static] | Indirect jump to absolute memory address
147C 401154 .text JMP [static] | Indirect jump to absolute memory address
1482 401038 .text JMP [static] | Indirect jump to absolute memory address
C000 N/A .topo0 Entry Point Sled | NOPs=20
C014 4014FC .text Possible Original Entry Point Relocation | Score=7/7 - Redirects=3 - PreJumpInstructions=20 - JumpType=JMP_NEAR - TargetOffset=14FC - TargetSection=.text
C000-CFFF C000 .topo0 Executable section anomaly, first bytes: 9090909090909090
Extra Analysis
Metric Value Percentage
Ascii Code 17219 32,3374%
Null Byte Code 24331 45,6937%
NOP Cave Found 0x9090909090 Block Count: 6 | Total: 0,0282%
© 2026 All rights reserved.