Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2015-Dec-22 13:21:15 |
Detected languages |
English - United States
Russian - Russia |
FileDescription | KIT_02C MFC Application |
FileVersion | 1, 0, 0, 1 |
InternalName | KIT_02C |
LegalCopyright | Copyright (C) 2004 |
OriginalFilename | KIT_02C.EXE |
ProductName | KIT_02C Application |
ProductVersion | 1, 0, 0, 1 |
Info | Matching compiler(s): |
Microsoft Visual C++ 6.0 - 8.0
Microsoft Visual C++ v7.0 Microsoft Visual C++ v7.1 EXE Microsoft Visual C++ 7.0 MFC |
Info | Interesting strings found in the binary: |
Contains domain names:
|
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
Suspicious | The PE is possibly a dropper. |
Resource 217 is possibly compressed or encrypted.
Resource 224 is possibly compressed or encrypted. Resource 265 is possibly compressed or encrypted. Resources amount for 89.0059% of the executable. |
Malicious | VirusTotal score: 6/73 (Scanned on 2024-07-09 16:37:25) |
APEX:
Malicious
AVG: Win32:RATX-gen [Trj] Avast: Win32:RATX-gen [Trj] Microsoft: Trojan:Win32/Wacatac.B!ml Rising: Trojan.Injector!1.FCCE (CLASSIC) Trapmine: malicious.moderate.ml.score |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x110 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 4 |
TimeDateStamp | 2015-Dec-22 13:21:15 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
|
Magic | PE32 |
---|---|
LinkerVersion | 7.0 |
SizeOfCode | 0x78000 |
SizeOfInitializedData | 0x519000 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x0005ED5E (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x79000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x1000 |
OperatingSystemVersion | 4.0 |
ImageVersion | 0.0 |
SubsystemVersion | 4.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x59b000 |
SizeOfHeaders | 0x1000 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
SizeofStackReserve | 0x770000 |
SizeofStackCommit | 0x71000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
GetSystemTimeAsFileTime
CreateDirectoryA ExitProcess TerminateProcess GetStartupInfoA RaiseException HeapSize HeapDestroy HeapCreate VirtualFree VirtualAlloc IsBadWritePtr GetTimeZoneInformation GetStdHandle UnhandledExceptionFilter FreeEnvironmentStringsA GetEnvironmentStrings FreeEnvironmentStringsW GetEnvironmentStringsW HeapAlloc GetFileType QueryPerformanceCounter GetCurrentProcessId SetUnhandledExceptionFilter LCMapStringA LCMapStringW GetStringTypeA GetStringTypeW IsBadReadPtr IsBadCodePtr VirtualProtect GetSystemInfo VirtualQuery SetStdHandle SetEnvironmentVariableA HeapReAlloc HeapFree RtlUnwind WritePrivateProfileStringA GetFileTime FileTimeToLocalFileTime SetErrorMode GetOEMCP GetCPInfo InterlockedIncrement TlsFree DeleteCriticalSection LocalReAlloc TlsSetValue TlsAlloc InitializeCriticalSection TlsGetValue EnterCriticalSection GlobalHandle GlobalReAlloc LeaveCriticalSection LocalAlloc GlobalFlags FormatMessageA LocalFree GetCurrentThread GlobalAlloc lstrcmpA ConvertDefaultLocale EnumResourceLanguagesA InterlockedDecrement FileTimeToSystemTime CreateFileA GetFullPathNameA GetVolumeInformationA GetCurrentProcess DuplicateHandle GetFileSize SetEndOfFile UnlockFile LockFile FlushFileBuffers SetFilePointer WriteFile ReadFile SetLastError GetModuleFileNameA lstrcpynA GetCurrentThreadId GlobalGetAtomNameA GlobalAddAtomA GlobalFindAtomA GlobalDeleteAtom LoadLibraryA FreeLibrary lstrcatA lstrcmpW lstrcpyA GetModuleHandleA GetProcAddress FreeResource lstrlenA lstrcmpiA CompareStringW CompareStringA GetVersion MultiByteToWideChar MulDiv CreateEventA CreateThread WideCharToMultiByte GetOverlappedResult GetLastError CloseHandle WaitForSingleObject TerminateThread FindResourceA LoadResource LockResource SizeofResource GetVersionExA GetThreadLocale GetLocaleInfoA GetACP InterlockedExchange DeleteFileA Sleep Beep FindFirstFileA FindClose FindNextFileA GetLocalTime GetCommandLineA GetTickCount GlobalLock GlobalUnlock GlobalFree GetFileAttributesA CancelIo SetHandleCount |
---|---|
USER32.dll |
GrayStringA
DrawTextExA DrawTextA TabbedTextOutA SetMenuItemBitmaps ModifyMenuA GetMenuState EnableMenuItem GetMenuCheckMarkDimensions LoadBitmapA ShowWindow MoveWindow SetWindowTextA IsDialogMessageA CreateWindowExA SetWindowsHookExA CallNextHookEx GetClassLongA GetClassInfoExA GetClassNameA SetPropA GetPropA RemovePropA SendDlgItemMessageA GetFocus SetFocus IsChild GetWindowTextA GetForegroundWindow GetLastActivePopup DispatchMessageA GetTopWindow UnhookWindowsHookEx GetMessageTime GetMessagePos MapWindowPoints MessageBoxA GetKeyState SetForegroundWindow UpdateWindow GetMenu GetSubMenu GetMenuItemID GetMenuItemCount GetSysColor ScreenToClient EqualRect RegisterClassA UnregisterClassA GetDlgCtrlID DefWindowProcA CallWindowProcA SetWindowLongA SetWindowPos OffsetRect IntersectRect SystemParametersInfoA GetWindowPlacement GetWindow GetDesktopWindow GetActiveWindow SetActiveWindow CreateDialogIndirectParamA DestroyWindow IsWindow GetWindowLongA GetDlgItem IsWindowEnabled GetParent GetNextDlgTabItem EndDialog RegisterWindowMessageA ReleaseCapture PtInRect SetCapture EnableWindow BeginPaint EndPaint MessageBeep GetNextDlgGroupItem InvalidateRgn CopyAcceleratorTableA IsRectEmpty CharNextA GetCapture CharUpperA PeekMessageA GetSystemMetrics LoadIconA WinHelpA KillTimer SetTimer IsIconic GetSystemMenu AppendMenuA DrawIcon PostMessageA InvalidateRect PostThreadMessageA GetWindowRect LoadImageA ReleaseDC GetDC CopyRect SetRect SendMessageA IsWindowVisible GetClientRect GetClassInfoA LoadCursorA GetSysColorBrush WindowFromPoint DestroyMenu RegisterClipboardFormatA SetWindowContextHelpId MapDialogRect GetMessageA TranslateMessage GetCursorPos ValidateRect SetCursor PostQuitMessage wsprintfA GetWindowDC AdjustWindowRectEx ClientToScreen CheckMenuItem |
GDI32.dll |
CreateFontIndirectA
CombineRgn PtInRegion GetClipBox SetBkColor SaveDC RestoreDC SetStretchBltMode SetMapMode SelectClipRgn GetViewportExtEx GetWindowExtEx StartDocA PtVisible RectVisible ExtTextOutA Escape SetViewportOrgEx OffsetViewportOrgEx SetViewportExtEx ScaleViewportExtEx SetWindowExtEx ScaleWindowExtEx ExtSelectClipRgn DeleteDC CreateRectRgnIndirect GetMapMode GetBkColor GetTextColor GetRgnBox SetTextColor SetBkMode SetTextAlign TextOutA MoveToEx LineTo CreateDIBitmap SetDIBits CreateRectRgn EndDoc EndPage StartPage GetDeviceCaps CreateDCA CreatePenIndirect CreateFontA CreateBitmap CreateSolidBrush CreateCompatibleDC GetObjectA StretchBlt GetTextExtentPoint32A CreatePen GetStockObject DeleteObject SelectObject Ellipse BitBlt |
WINSPOOL.DRV |
OpenPrinterA
DocumentPropertiesA ClosePrinter EnumPrintersA |
ADVAPI32.dll |
RegCloseKey
RegOpenKeyA RegOpenKeyExA RegDeleteKeyA RegEnumKeyA RegQueryValueA RegCreateKeyExA RegSetValueExA RegQueryValueExA |
COMCTL32.dll |
#17
ImageList_Destroy |
SHLWAPI.dll |
PathIsUNCA
PathFindExtensionA PathStripToRootA PathFindFileNameA |
oledlg.dll |
#8
|
ole32.dll |
CoTaskMemAlloc
OleRun CoTaskMemFree OleInitialize CoFreeUnusedLibraries OleUninitialize CLSIDFromString CLSIDFromProgID CoCreateInstance CoGetClassObject StgOpenStorageOnILockBytes StgCreateDocfileOnILockBytes CreateILockBytesOnHGlobal CoRegisterMessageFilter OleFlushClipboard OleIsCurrentClipboard CoRevokeClassObject |
OLEAUT32.dll |
SysFreeString
VariantChangeType VariantInit SysAllocStringLen SystemTimeToVariantTime SysAllocString SysStringLen SysAllocStringByteLen VariantCopy SafeArrayDestroy OleCreateFontIndirect VariantClear |
OLEACC.dll |
LresultFromObject
CreateStdAccessibleObject |
Open |
Save As |
All Files (*.*) |
Untitled |
an unnamed file |
&Hide |
No error message is available. |
An unsupported operation was attempted. |
A required resource was unavailable. |
Out of memory. |
An unknown error has occurred. |
Invalid filename. |
Failed to open document. |
Failed to save document. |
Save changes to %1? |
Failed to create empty document. |
The file is too large to open. |
Could not start print job. |
Failed to launch help. |
Internal application error. |
Command failed. |
Insufficient memory to perform operation. |
System registry entries have been removed and the INI file (if any) was deleted. |
Not all of the system registry entries (or INI file) were removed. |
This program requires the file %s, which was not found on this system. |
This program is linked to the missing export %s in the file %s. This machine may have an incompatible version of %s. |
Please enter an integer. |
Please enter a number. |
Please enter an integer between %1 and %2. |
Please enter a number between %1 and %2. |
Please enter no more than %1 characters. |
Please select a button. |
Please enter an integer between 0 and 255. |
Please enter a positive integer. |
Please enter a date and/or time. |
Please enter a currency. |
Please enter a GUID. |
Please enter a time. |
Please enter a date. |
Unexpected file format. |
%1 |
Cannot find this file. |
Please verify that the correct path and file name are given. |
Destination disk drive is full. |
Unable to read from %1, it is opened by someone else. |
Unable to write to %1, it is read-only or opened by someone else. |
An unexpected error occurred while reading %1. |
An unexpected error occurred while writing %1. |
%1: %2 |
Continue running script? |
Dispatch exception: %1 |
Unable to read write-only property. |
Unable to write read-only property. |
Unable to load mail system support. |
Mail system DLL is invalid. |
Send Mail failed to send message. |
No error occurred. |
An unknown error occurred while accessing %1. |
%1 was not found. |
%1 contains an invalid path. |
%1 could not be opened because there are too many open files. |
Access to %1 was denied. |
An invalid file handle was associated with %1. |
%1 could not be removed because it is the current directory. |
%1 could not be created because the directory is full. |
Seek failed on %1 |
A hardware I/O error was reported while accessing %1. |
A sharing violation occurred while accessing %1. |
A locking violation occurred while accessing %1. |
Disk full while accessing %1. |
An attempt was made to access %1 past its end. |
No error occurred. |
An unknown error occurred while accessing %1. |
An attempt was made to write to the reading %1. |
An attempt was made to access %1 past its end. |
An attempt was made to read from the writing %1. |
%1 has a bad format. |
%1 contained an unexpected object. |
%1 contains an incorrect schema. |
pixels |
Uncheck |
Check |
Mixed |
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 1.0.0.1 |
ProductVersion | 1.0.0.1 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
FileType |
VFT_APP
|
Language | Russian - Russia |
FileDescription | KIT_02C MFC Application |
FileVersion (#2) | 1, 0, 0, 1 |
InternalName | KIT_02C |
LegalCopyright | Copyright (C) 2004 |
OriginalFilename | KIT_02C.EXE |
ProductName | KIT_02C Application |
ProductVersion (#2) | 1, 0, 0, 1 |
Resource LangID | Russian - Russia |
---|
XOR Key | 0x1ad5bad5 |
---|---|
Unmarked objects | 0 |
39 (9162) | 1 |
37 (8755) | 2 |
C objects (9178) | 9 |
C objects (9177) | 1 |
Imports (9210) | 24 |
ASM objects (VS2002 (.NET) build 9466) | 30 |
C objects (VS2002 (.NET) build 9466) | 148 |
39 (8491) | 9 |
Linker (VC++ 6.0 SP5 imp/exp build 8447) | 3 |
Total imports | 579 |
C++ objects (VS2002 (.NET) build 9466) | 157 |
Resource objects (VS2002 (.NET) build 9466) | 1 |
Linker (VS2002 (.NET) build 9466) | 1 |