Architecture |
Subsystem |
Compilation Date | 2015-Dec-22 13:21:15 |
Detected languages |
English - United States
Russian - Russia |
FileDescription | KIT_02C MFC Application |
FileVersion | 1, 0, 0, 1 |
InternalName | KIT_02C |
LegalCopyright | Copyright (C) 2004 |
OriginalFilename | KIT_02C.EXE |
ProductName | KIT_02C Application |
ProductVersion | 1, 0, 0, 1 |
Info | Matching compiler(s): |
Microsoft Visual C++ 6.0 - 8.0
Microsoft Visual C++ v7.0 Microsoft Visual C++ v7.1 EXE Microsoft Visual C++ 7.0 MFC |
Info | Interesting strings found in the binary: |
Contains domain names:
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
Suspicious | The PE is possibly a dropper. |
Resource 217 is possibly compressed or encrypted.
Resource 224 is possibly compressed or encrypted. Resource 265 is possibly compressed or encrypted. Resources amount for 89.0059% of the executable. |
Malicious | VirusTotal score: 6/73 (Scanned on 2024-07-09 16:37:25) |
AVG: Win32:RATX-gen [Trj] Avast: Win32:RATX-gen [Trj] Microsoft: Trojan:Win32/Wacatac.B!ml Rising: Trojan.Injector!1.FCCE (CLASSIC) Trapmine: |
e_magic | MZ |
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x110 |
Signature | PE |
Machine |
NumberofSections | 4 |
TimeDateStamp | 2015-Dec-22 13:21:15 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
Magic | PE32 |
LinkerVersion | 7.0 |
SizeOfCode | 0x78000 |
SizeOfInitializedData | 0x519000 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x0005ED5E (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x79000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x1000 |
OperatingSystemVersion | 4.0 |
ImageVersion | 0.0 |
SubsystemVersion | 4.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x59b000 |
SizeOfHeaders | 0x1000 |
Checksum | 0 |
Subsystem |
SizeofStackReserve | 0x770000 |
SizeofStackCommit | 0x71000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
CreateDirectoryA ExitProcess TerminateProcess GetStartupInfoA RaiseException HeapSize HeapDestroy HeapCreate VirtualFree VirtualAlloc IsBadWritePtr GetTimeZoneInformation GetStdHandle UnhandledExceptionFilter FreeEnvironmentStringsA GetEnvironmentStrings FreeEnvironmentStringsW GetEnvironmentStringsW HeapAlloc GetFileType QueryPerformanceCounter GetCurrentProcessId SetUnhandledExceptionFilter LCMapStringA LCMapStringW GetStringTypeA GetStringTypeW IsBadReadPtr IsBadCodePtr VirtualProtect GetSystemInfo VirtualQuery SetStdHandle SetEnvironmentVariableA HeapReAlloc HeapFree RtlUnwind WritePrivateProfileStringA GetFileTime FileTimeToLocalFileTime SetErrorMode GetOEMCP GetCPInfo InterlockedIncrement TlsFree DeleteCriticalSection LocalReAlloc TlsSetValue TlsAlloc InitializeCriticalSection TlsGetValue EnterCriticalSection GlobalHandle GlobalReAlloc LeaveCriticalSection LocalAlloc GlobalFlags FormatMessageA LocalFree GetCurrentThread GlobalAlloc lstrcmpA ConvertDefaultLocale EnumResourceLanguagesA InterlockedDecrement FileTimeToSystemTime CreateFileA GetFullPathNameA GetVolumeInformationA GetCurrentProcess DuplicateHandle GetFileSize SetEndOfFile UnlockFile LockFile FlushFileBuffers SetFilePointer WriteFile ReadFile SetLastError GetModuleFileNameA lstrcpynA GetCurrentThreadId GlobalGetAtomNameA GlobalAddAtomA GlobalFindAtomA GlobalDeleteAtom LoadLibraryA FreeLibrary lstrcatA lstrcmpW lstrcpyA GetModuleHandleA GetProcAddress FreeResource lstrlenA lstrcmpiA CompareStringW CompareStringA GetVersion MultiByteToWideChar MulDiv CreateEventA CreateThread WideCharToMultiByte GetOverlappedResult GetLastError CloseHandle WaitForSingleObject TerminateThread FindResourceA LoadResource LockResource SizeofResource GetVersionExA GetThreadLocale GetLocaleInfoA GetACP InterlockedExchange DeleteFileA Sleep Beep FindFirstFileA FindClose FindNextFileA GetLocalTime GetCommandLineA GetTickCount GlobalLock GlobalUnlock GlobalFree GetFileAttributesA CancelIo SetHandleCount |
USER32.dll |
DrawTextExA DrawTextA TabbedTextOutA SetMenuItemBitmaps ModifyMenuA GetMenuState EnableMenuItem GetMenuCheckMarkDimensions LoadBitmapA ShowWindow MoveWindow SetWindowTextA IsDialogMessageA CreateWindowExA SetWindowsHookExA CallNextHookEx GetClassLongA GetClassInfoExA GetClassNameA SetPropA GetPropA RemovePropA SendDlgItemMessageA GetFocus SetFocus IsChild GetWindowTextA GetForegroundWindow GetLastActivePopup DispatchMessageA GetTopWindow UnhookWindowsHookEx GetMessageTime GetMessagePos MapWindowPoints MessageBoxA GetKeyState SetForegroundWindow UpdateWindow GetMenu GetSubMenu GetMenuItemID GetMenuItemCount GetSysColor ScreenToClient EqualRect RegisterClassA UnregisterClassA GetDlgCtrlID DefWindowProcA CallWindowProcA SetWindowLongA SetWindowPos OffsetRect IntersectRect SystemParametersInfoA GetWindowPlacement GetWindow GetDesktopWindow GetActiveWindow SetActiveWindow CreateDialogIndirectParamA DestroyWindow IsWindow GetWindowLongA GetDlgItem IsWindowEnabled GetParent GetNextDlgTabItem EndDialog RegisterWindowMessageA ReleaseCapture PtInRect SetCapture EnableWindow BeginPaint EndPaint MessageBeep GetNextDlgGroupItem InvalidateRgn CopyAcceleratorTableA IsRectEmpty CharNextA GetCapture CharUpperA PeekMessageA GetSystemMetrics LoadIconA WinHelpA KillTimer SetTimer IsIconic GetSystemMenu AppendMenuA DrawIcon PostMessageA InvalidateRect PostThreadMessageA GetWindowRect LoadImageA ReleaseDC GetDC CopyRect SetRect SendMessageA IsWindowVisible GetClientRect GetClassInfoA LoadCursorA GetSysColorBrush WindowFromPoint DestroyMenu RegisterClipboardFormatA SetWindowContextHelpId MapDialogRect GetMessageA TranslateMessage GetCursorPos ValidateRect SetCursor PostQuitMessage wsprintfA GetWindowDC AdjustWindowRectEx ClientToScreen CheckMenuItem |
GDI32.dll |
CombineRgn PtInRegion GetClipBox SetBkColor SaveDC RestoreDC SetStretchBltMode SetMapMode SelectClipRgn GetViewportExtEx GetWindowExtEx StartDocA PtVisible RectVisible ExtTextOutA Escape SetViewportOrgEx OffsetViewportOrgEx SetViewportExtEx ScaleViewportExtEx SetWindowExtEx ScaleWindowExtEx ExtSelectClipRgn DeleteDC CreateRectRgnIndirect GetMapMode GetBkColor GetTextColor GetRgnBox SetTextColor SetBkMode SetTextAlign TextOutA MoveToEx LineTo CreateDIBitmap SetDIBits CreateRectRgn EndDoc EndPage StartPage GetDeviceCaps CreateDCA CreatePenIndirect CreateFontA CreateBitmap CreateSolidBrush CreateCompatibleDC GetObjectA StretchBlt GetTextExtentPoint32A CreatePen GetStockObject DeleteObject SelectObject Ellipse BitBlt |
DocumentPropertiesA ClosePrinter EnumPrintersA |
ADVAPI32.dll |
RegOpenKeyA RegOpenKeyExA RegDeleteKeyA RegEnumKeyA RegQueryValueA RegCreateKeyExA RegSetValueExA RegQueryValueExA |
COMCTL32.dll |
ImageList_Destroy |
PathFindExtensionA PathStripToRootA PathFindFileNameA |
oledlg.dll |
ole32.dll |
OleRun CoTaskMemFree OleInitialize CoFreeUnusedLibraries OleUninitialize CLSIDFromString CLSIDFromProgID CoCreateInstance CoGetClassObject StgOpenStorageOnILockBytes StgCreateDocfileOnILockBytes CreateILockBytesOnHGlobal CoRegisterMessageFilter OleFlushClipboard OleIsCurrentClipboard CoRevokeClassObject |
OLEAUT32.dll |
VariantChangeType VariantInit SysAllocStringLen SystemTimeToVariantTime SysAllocString SysStringLen SysAllocStringByteLen VariantCopy SafeArrayDestroy OleCreateFontIndirect VariantClear |
OLEACC.dll |
CreateStdAccessibleObject |
Signature | 0xfeef04bd |
StructVersion | 0x10000 |
FileVersion | |
ProductVersion | |
FileFlags | (EMPTY) |
FileOs |
FileType |
Language | Russian - Russia |
FileDescription | KIT_02C MFC Application |
FileVersion (#2) | 1, 0, 0, 1 |
InternalName | KIT_02C |
LegalCopyright | Copyright (C) 2004 |
OriginalFilename | KIT_02C.EXE |
ProductName | KIT_02C Application |
ProductVersion (#2) | 1, 0, 0, 1 |
Resource LangID | Russian - Russia |
XOR Key | 0x1ad5bad5 |
Unmarked objects | 0 |
39 (9162) | 1 |
37 (8755) | 2 |
C objects (9178) | 9 |
C objects (9177) | 1 |
Imports (9210) | 24 |
ASM objects (VS2002 (.NET) build 9466) | 30 |
C objects (VS2002 (.NET) build 9466) | 148 |
39 (8491) | 9 |
Linker (VC++ 6.0 SP5 imp/exp build 8447) | 3 |
Total imports | 579 |
C++ objects (VS2002 (.NET) build 9466) | 157 |
Resource objects (VS2002 (.NET) build 9466) | 1 |
Linker (VS2002 (.NET) build 9466) | 1 |