PESCAN.IO - Analysis Report Basic

File Structure
Analysis Image
PE Chart Code
Header PE (light blue)
Executable sections (pink)
Non-executable sections (black)
External injected code (red)
File Structure in red = malformed or corrupted header

Chart Code For Other Files
Printable characters (blue)
Non-printable characters (black)
Information
Size: 5,63 MB
SHA-256 Hash: F619B3C9DAA88AC266ACC8C7290EAF724C1F97F0C060303D8612FA2C56F19FA3
SHA-1 Hash: EA87F1B66AC7A0ECFE8493C01140196E8352B209
MD5 Hash: FCBE54BFF5ACACD4F253B82D5484170C
Imphash: 047F9737FB30963A523F2293F14CF651
MajorOSVersion: 6
MinorOSVersion: 0
CheckSum: 00000000
EntryPoint (rva): 6B8AF7
SizeOfHeaders: 400
SizeOfImage: 945000
ImageBase: 0000000140000000
Architecture: x64
ExportTable: 704398
ImportTable: 78EDC8
IAT: 3A4000
Characteristics: 23
TimeDateStamp: 6A32C797
Date: 17/06/2026 16:13:11
File Type: EXE
Number Of Sections: 8
ASLR: Disabled
Section Names (Optional Header): .text, .rdata, .data, .pdata, .fptable, .m\f, .L=, .c0w
Number Of Executable Sections: 3
Subsystem: Windows Console
[Incomplete Binary or Compressor Packer - 3,64 MB Missing]

Sections Info
Section Name Flags ROffset RSize VOffset VSizeEntropyChi2
.text
0x60000020
Code
Executable
Readable
0 0 1000 45F80
N/A
N/A
.rdata
0x40000040
Initialized Data
Readable
0 0 47000 19084
N/A
N/A
.data
0xC0000040
Initialized Data
Readable
Writeable
0 0 61000 1760
N/A
N/A
.pdata
0x40000040
Initialized Data
Readable
0 0 63000 2B38
N/A
N/A
.fptable
0xC0000040
Initialized Data
Readable
Writeable
0 0 66000 100
N/A
N/A
.m\f
0x60000020
Code
Executable
Readable
0 0 67000 33CD31
N/A
N/A
.L=
0xC0000040
Initialized Data
Readable
Writeable
400 C00 3A4000 A68
0.1634
763018.33
.c0w
0x68000060
Code
Initialized Data
Shared
Executable
Readable
1000 59F600 3A5000 59F5F0
7.9142
1044419.79
Entry Point
The section number (8) have the Entry Point
Information -> EntryPoint (calculated) - 314AF7
Code -> 41539C49BB677666216E18404B5548BD0351EF6F3E2DF10548F7DDE83F4D120067BC2CC4061E5F29C459870120C48FEA2ADB
Assembler
|PUSH R11
|PUSHFQ
|MOVABS R11, 0X4B40186E21667667
|PUSH RBP
|MOVABS RBP, 0X5F12D3E6FEF5103
|NEG RBP
|CALL 0X1407DD856
|MOV ESP, 0X1E06C42C
|POP RDI
|SUB ESP, EAX
|POP RCX
|XCHG DWORD PTR [RCX], EAX
|AND AH, AL
Signatures
Certificate - Digital Signature Not Found:
• The file is not signed

Packer/Compiler
Detect It Easy (die)
PE+(64): linker: Microsoft Linker(14.51)[-]
Entropy: 7.91289

Suspicious Functions
Library Function Description
KERNEL32.DLL WriteFile Writes data to a specified file or input/output (I/O) device.
KERNEL32.DLL LoadLibraryA Loads the specified module into the address space of the calling process.
KERNEL32.DLL GetModuleHandleA Retrieves a handle to the specified module.
KERNEL32.DLL GetProcAddress Retrieves the address of an exported function or variable from the specified dynamic-link library (DLL).
KERNEL32.DLL CreateFileW Creates or opens a file object.
KERNEL32.DLL GetVersion Retrieves the operating system version.
File Access
ntdll.dll
kernel32.dll
USER32.dll
api-ms-win-core-synch-l1-2-0.dll
@.dat

Strings/Hex Code Found With The File Rules
Rule Type Encoding Matched (Word)
Entry Point Hex Pattern HA Archive
Intelligent String
• USER32.dll
• *.YlT

Flow Anomalies
Offset FlowVA Section Description
7FC7 N/A .c0w JMP QWORD PTR [RIP+0xCD6BA6C2]
142BC N/A .c0w JMP QWORD PTR [RIP+0x5133D621]
14538 N/A .c0w JMP QWORD PTR [RIP+0xA9CC62A6]
14F46 N/A .c0w JMP QWORD PTR [RIP+0xBB977B44]
2072C N/A .c0w CALL QWORD PTR [RIP+0x849CF188]
26A0C N/A .c0w JMP QWORD PTR [RIP+0x4F907E3B]
2B1B6 N/A .c0w JMP QWORD PTR [RIP+0x36308041]
30E05 N/A .c0w CALL QWORD PTR [RIP+0xA8594AF3]
47953 N/A .c0w JMP QWORD PTR [RIP+0xA75D7989]
48121 N/A .c0w CALL QWORD PTR [RIP+0xD2A76B60]
61294 N/A .c0w CALL QWORD PTR [RIP+0x232BDD08]
64797 N/A .c0w CALL QWORD PTR [RIP+0x94D3B639]
717F7 N/A .c0w JMP QWORD PTR [RIP+0xE43A6853]
74DB1 N/A .c0w JMP QWORD PTR [RIP+0x8825FDAB]
79C0F N/A .c0w CALL QWORD PTR [RIP+0xA29D7EC5]
823D5 N/A .c0w JMP QWORD PTR [RIP+0x229D0F36]
89B42 N/A .c0w CALL QWORD PTR [RIP+0x5C6D5356]
987CB N/A .c0w JMP QWORD PTR [RIP+0x7FEE878D]
A704E N/A .c0w CALL QWORD PTR [RIP+0x9F7E8DBE]
AB920 N/A .c0w JMP QWORD PTR [RIP+0x84188841]
B3653 N/A .c0w JMP QWORD PTR [RIP+0x8C001F86]
C3189 N/A .c0w JMP QWORD PTR [RIP+0xB6BC9C2F]
C8994 N/A .c0w CALL QWORD PTR [RIP+0xCCE7CC2A]
CD9F0 N/A .c0w JMP QWORD PTR [RIP+0x16B47437]
CDA66 N/A .c0w CALL QWORD PTR [RIP+0xE809BCD5]
D0170 N/A .c0w CALL QWORD PTR [RIP+0xBACA9AA6]
D7098 N/A .c0w CALL QWORD PTR [RIP+0x60B8C2A7]
DDAC1 N/A .c0w JMP QWORD PTR [RIP+0x4D1D819A]
DF713 N/A .c0w CALL QWORD PTR [RIP+0x1D2FD4F5]
F4D16 N/A .c0w JMP QWORD PTR [RIP+0xA232270A]
F52FD N/A .c0w JMP QWORD PTR [RIP+0xD52A3924]
FED1B N/A .c0w CALL QWORD PTR [RIP+0x8D31339A]
FF0B6 N/A .c0w CALL QWORD PTR [RIP+0xBA043DD9]
10ED03 N/A .c0w JMP QWORD PTR [RIP+0xA6A006F7]
117D23 N/A .c0w CALL QWORD PTR [RIP+0x5990B5E3]
1193F0 N/A .c0w CALL QWORD PTR [RIP+0x3C7FEE01]
119C28 N/A .c0w CALL QWORD PTR [RIP+0xBB5017A3]
11D1E8 N/A .c0w CALL QWORD PTR [RIP+0xE5C5ACD5]
124C72 N/A .c0w CALL QWORD PTR [RIP+0x787DF0DF]
128B7C N/A .c0w CALL QWORD PTR [RIP+0x40E9C847]
131D97 N/A .c0w CALL QWORD PTR [RIP+0xB926AB1F]
139B6F N/A .c0w CALL QWORD PTR [RIP+0x41FE07F8]
14031C N/A .c0w CALL QWORD PTR [RIP+0x1AECD498]
1445AF N/A .c0w CALL QWORD PTR [RIP+0x16B0B850]
15DE68 N/A .c0w CALL QWORD PTR [RIP+0x1A5454C4]
16B217 N/A .c0w JMP QWORD PTR [RIP+0x284E8C05]
16F507 N/A .c0w JMP QWORD PTR [RIP+0x8226FF0D]
172ABB N/A .c0w JMP QWORD PTR [RIP+0xCDCAEFCA]
17891D N/A .c0w CALL QWORD PTR [RIP+0x57A31B50]
1793B8 N/A .c0w JMP QWORD PTR [RIP+0x9A4CB5EE]
17B553 N/A .c0w JMP QWORD PTR [RIP+0x54D462B0]
196BCF N/A .c0w JMP QWORD PTR [RIP+0xC9E2BAC8]
19F4E8 N/A .c0w JMP QWORD PTR [RIP+0x7D12610A]
1A1EE4 N/A .c0w JMP QWORD PTR [RIP+0x674CF867]
1A3E41 N/A .c0w CALL QWORD PTR [RIP+0xC7D1B7CB]
1A808E N/A .c0w CALL QWORD PTR [RIP+0x6C63C1C1]
1AD706 N/A .c0w JMP QWORD PTR [RIP+0x9A74C60B]
1B49D8 N/A .c0w CALL QWORD PTR [RIP+0x46BD95CB]
1C039E N/A .c0w CALL QWORD PTR [RIP+0xEFF0CA3]
1C3F24 N/A .c0w CALL QWORD PTR [RIP+0x1504433F]
1C64AB N/A .c0w JMP QWORD PTR [RIP+0x9C21F785]
1CBC8F N/A .c0w JMP QWORD PTR [RIP+0xBDDD08DF]
1E4ECD N/A .c0w CALL QWORD PTR [RIP+0x455E50B9]
1EA2D3 N/A .c0w CALL QWORD PTR [RIP+0x151A021C]
1EDA77 N/A .c0w JMP QWORD PTR [RIP+0xF867EBF2]
1F78A6 N/A .c0w CALL QWORD PTR [RIP+0xC8531AC4]
1FF056 N/A .c0w JMP QWORD PTR [RIP+0xD71B1168]
2027C4 N/A .c0w CALL QWORD PTR [RIP+0x9473D5FE]
20C891 N/A .c0w JMP QWORD PTR [RIP+0x41F0A2CE]
226F1F N/A .c0w CALL QWORD PTR [RIP+0x7C933C2C]
2328AC N/A .c0w JMP QWORD PTR [RIP+0xCB0F7D16]
24F964 N/A .c0w JMP QWORD PTR [RIP+0x9BE91C3E]
254998 N/A .c0w JMP QWORD PTR [RIP+0xBF8A09CB]
255115 N/A .c0w JMP QWORD PTR [RIP+0xA47273ED]
25A9B0 N/A .c0w CALL QWORD PTR [RIP+0x3B40C852]
25C02E N/A .c0w JMP QWORD PTR [RIP+0x59711332]
25CAFF N/A .c0w JMP QWORD PTR [RIP+0x527ED106]
260396 N/A .c0w CALL QWORD PTR [RIP+0xA49F3255]
2654F9 N/A .c0w JMP QWORD PTR [RIP+0x6D50D8DD]
277B35 N/A .c0w CALL QWORD PTR [RIP+0x49624CEF]
2863B1 N/A .c0w CALL QWORD PTR [RIP+0xC90606AA]
29E952 N/A .c0w CALL QWORD PTR [RIP+0xE17C2CFC]
2A2469 N/A .c0w JMP QWORD PTR [RIP+0x77D51093]
2AC995 N/A .c0w CALL QWORD PTR [RIP+0x64EEDC10]
2C6396 N/A .c0w JMP QWORD PTR [RIP+0x22260AC8]
2CC306 N/A .c0w CALL QWORD PTR [RIP+0x14C202F6]
2D0EB9 N/A .c0w CALL QWORD PTR [RIP+0x68513120]
2D462B N/A .c0w JMP QWORD PTR [RIP+0x6ECBDB77]
2D47E4 N/A .c0w CALL QWORD PTR [RIP+0xE40EC937]
2D6960 N/A .c0w JMP QWORD PTR [RIP+0x15ACBD90]
2DD732 N/A .c0w CALL QWORD PTR [RIP+0x52306DCD]
2E23D2 N/A .c0w JMP QWORD PTR [RIP+0xF1EAF858]
2F33C5 N/A .c0w JMP QWORD PTR [RIP+0x5B40EBC9]
2FCA37 N/A .c0w CALL QWORD PTR [RIP+0x65B880F4]
30957E N/A .c0w CALL QWORD PTR [RIP+0x462047B5]
309E69 N/A .c0w CALL QWORD PTR [RIP+0x4C0BB611]
30DA55 N/A .c0w CALL QWORD PTR [RIP+0x2F2912F5]
30E945 N/A .c0w CALL QWORD PTR [RIP+0x46415DB5]
3114E9 N/A .c0w JMP QWORD PTR [RIP+0x9BB88C41]
31CE98 N/A .c0w JMP QWORD PTR [RIP+0x4E4FA389]
33AB1B-33AB28 N/A .c0w Potential obfuscated jump sequence detected, count: 7
44B898 1403A7F2F .c0w TLS Callback | Pointer to 3A7F2F - 0x3F2F .c0w
44B8A0 140037130 .c0w TLS Callback | Pointer to 37130 - 0x36130 .text
1000-5A05FF 3A5000 .c0w Executable section anomaly, first bytes: 567D7F7026F97040
Extra Analysis
Metric Value Percentage
Ascii Code 4052842 68,6948%
Null Byte Code 105557 1,7892%
© 2026 All rights reserved.