| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 1999-Dec-04 19:51:04 |
| Detected languages |
English - United States
|
| FileDescription | StukSt MFC Application |
| FileVersion | 1, 0, 0, 1 |
| InternalName | StukSt |
| LegalCopyright | Copyright (C) 1999 |
| OriginalFilename | StukSt.EXE |
| ProductName | StukSt Application |
| ProductVersion | 1, 0, 0, 1 |
| Info | Matching compiler(s): |
Microsoft Visual C++ 6.0 - 8.0
Microsoft Visual C 5.0 Microsoft Visual C++ Microsoft Visual C++ v6.0 |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
May have dropper capabilities:
|
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Malicious | VirusTotal score: 45/71 (Scanned on 2026-05-07 19:34:01) |
ALYac:
Backdoor.Stukach.A
AVG: Win32:Rit [Trj] Alibaba: TrojanPSW:Win32/PWStealer.b217ab11 Antiy-AVL: Trojan[PSW]/Win32.Rit Arcabit: Backdoor.Stukach.A Avast: Win32:Rit [Trj] Avira: TR/PSW.Rit.Gen BitDefender: Backdoor.Stukach.A CTX: exe.trojan.generic ClamAV: Win.Trojan.Rit-2 Cylance: Unsafe DeepInstinct: MALICIOUS DrWeb: Trojan.Stukach ESET-NOD32: Win32/PSW.Rit trojan Emsisoft: Backdoor.Stukach.A (B) F-Secure: Trojan.TR/PSW.Rit.Gen GData: Backdoor.Stukach.A Google: Detected Jiangmin: Trojan/PSW.Rit Kingsoft: Win32.Troj.PSW.Rit Malwarebytes: Generic.Malware/Suspicious MaxSecure: Trojan.Malware.854841.susgen McAfeeD: ti!E5214851E095 MicroWorld-eScan: Backdoor.Stukach.A Microsoft: PWS:Win32/Rit NANO-Antivirus: Trojan.Win32.Rit.dmlg Panda: Trj/PSW.Gen Rising: Trojan.PSW.Rit (CLASSIC) Skyhigh: BehavesLike.Win32.Infected.cm Sophos: Mal/Generic-S Symantec: Trojan.Gen.MBT TACHYON: Trojan/W32.Rit.189952 Tencent: Malware.Win32.Gencirc.143ad81d TrellixENS: Adware-Stukach TrendMicro: TROJ_PSW.RIT.A TrendMicro-HouseCall: TROJ_PSW.RIT.A VIPRE: Backdoor.Stukach.A Varist: W32/PWS.YJQX-9388 ViRobot: Trojan.Win32.PSWRit.189952 VirIT: Trojan.Win32.Generic.EU Xcitium: TrojWare.Win32.PSW.Rit@3a1t Yandex: Trojan.GenAsa!JCChIMGZqss Zillya: Trojan.Rit.Win32.7 ZoneAlarm: Troj/Rit alibabacloud: RiskWare:Win/Rit.Gen |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x80 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 5 |
| TimeDateStamp | 1999-Dec-04 19:51:04 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 5.0 |
| SizeOfCode | 0x18c00 |
| SizeOfInitializedData | 0x19600 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00002EE0 (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x1a000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 4.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 4.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x35000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
HeapAlloc
HeapFree RaiseException HeapSize GetCPInfo GetACP GetOEMCP HeapReAlloc FreeEnvironmentStringsA UnhandledExceptionFilter GetEnvironmentStrings GetEnvironmentStringsW SetHandleCount GetStdHandle GetFileType HeapDestroy HeapCreate VirtualFree FreeEnvironmentStringsW ExitProcess TerminateProcess GetCommandLineA lstrcpynA IsBadReadPtr IsBadWritePtr IsBadCodePtr GetStringTypeA GetStringTypeW GetLocaleInfoA GetLocaleInfoW CompareStringA CompareStringW SetEnvironmentVariableA SetStdHandle FindResourceA LoadResource GetStartupInfoA GetModuleHandleA GetLocalTime GetSystemTime GetTimeZoneInformation RtlUnwind SetErrorMode GlobalGetAtomNameA GlobalAddAtomA GetVersionExA SizeofResource GetModuleFileNameA GetFullPathNameA GetVolumeInformationA FindFirstFileA FindClose LoadLibraryA GetProcAddress FreeLibrary FlushFileBuffers GetCurrentProcess GetProcessVersion GetLastError SetLastError MultiByteToWideChar WideCharToMultiByte InterlockedIncrement lstrcpyA WritePrivateProfileStringA GlobalFlags lstrlenA LCMapStringA TlsGetValue GlobalLock LocalReAlloc CloseHandle TlsSetValue EnterCriticalSection GlobalReAlloc LeaveCriticalSection GlobalHandle DeleteCriticalSection TlsAlloc InitializeCriticalSection LocalFree LocalAlloc MulDiv InterlockedDecrement GetVersion lstrcatA GlobalUnlock GlobalFree LockResource LCMapStringW VirtualAlloc SetUnhandledExceptionFilter GlobalAlloc WinExec GetFileSize CreateFileA ReadFile SetFilePointer WriteFile GetProfileStringA GetCurrentThreadId GetCurrentThread lstrcmpiA lstrcmpA GlobalDeleteAtom |
|---|---|
| USER32.dll |
ShowWindow
GetDC ReleaseDC GetWindowDC BeginPaint EndPaint TabbedTextOutA DrawTextA GrayStringA LoadCursorA ReleaseCapture GetDesktopWindow WindowFromPoint ClientToScreen GetClassNameA PtInRect GetSysColorBrush LoadStringA CharUpperA DestroyMenu FindWindowA InvalidateRect OffsetRect SetRectEmpty LoadAcceleratorsA TranslateAcceleratorA LoadMenuA SetMenu ReuseDDElParam UnpackDDElParam BringWindowToTop IntersectRect InflateRect EqualRect DeferWindowPos BeginDeferWindowPos CopyRect EndDeferWindowPos ScreenToClient ScrollWindow SetScrollInfo ShowScrollBar SetScrollRange GetScrollPos SetScrollPos GetTopWindow IsChild GetCapture IsDialogMessageA wsprintfA AdjustWindowRectEx RegisterClassA GetMenuItemCount SetWindowTextA GetWindowTextLengthA GetWindowTextA GetDlgCtrlID CreateWindowExA SetPropA UnhookWindowsHookEx GetLastActivePopup GetForegroundWindow SetForegroundWindow GetPropA CallWindowProcA RemovePropA GetMessageTime GetMessagePos GetWindow GetWindowRect SetWindowLongA SetWindowPos RegisterWindowMessageA EndDialog SetActiveWindow IsWindow CreateDialogIndirectParamA DestroyWindow GetWindowLongA GetDlgItem IsWindowEnabled GetMenuCheckMarkDimensions LoadBitmapA GetMenuState ModifyMenuA SetMenuItemBitmaps CheckMenuItem EnableMenuItem GetFocus GetParent GetNextDlgTabItem GetMessageA TranslateMessage DispatchMessageA GetActiveWindow GetKeyState CallNextHookEx ValidateRect IsWindowVisible PeekMessageA GetCursorPos SetWindowsHookExA SetCursor ShowOwnedPopups PostQuitMessage PostMessageA EnableWindow MessageBoxA SetDlgItemTextA IsIconic GetSystemMetrics GetClientRect SetDlgItemInt GetDlgItemTextA GetDlgItemInt CheckRadioButton CheckDlgButton UpdateWindow SendDlgItemMessageA SystemParametersInfoA MapWindowPoints GetSysColor SetFocus GetSubMenu IsDlgButtonChecked GetMenu WinHelpA GetClassInfoA DrawIcon SendMessageA LoadIconA DefWindowProcA GetMenuItemID DrawFocusRect ExcludeUpdateRgn DefDlgProcA IsWindowUnicode CharNextA UnregisterClassA ShowCaret HideCaret |
| GDI32.dll |
SetTextColor
GetObjectA DeleteDC SaveDC RestoreDC SelectObject GetStockObject SetBkMode SetMapMode SetViewportOrgEx OffsetViewportOrgEx SetViewportExtEx ScaleViewportExtEx SetWindowExtEx CreateBitmap GetClipBox IntersectClipRect DeleteObject GetDeviceCaps CreateSolidBrush PtVisible RectVisible TextOutA ExtTextOutA Escape GetTextExtentPointA PatBlt CreateDIBitmap CreateCompatibleDC BitBlt SetBkColor ScaleWindowExtEx |
| comdlg32.dll |
GetOpenFileNameA
|
| WINSPOOL.DRV |
DocumentPropertiesA
ClosePrinter OpenPrinterA |
| ADVAPI32.dll |
RegCloseKey
RegSetValueExA RegQueryValueExA RegOpenKeyExA RegCreateKeyExA |
| SHELL32.dll |
DragFinish
DragQueryFileA |
| COMCTL32.dll |
ImageList_Destroy
#17 |
| Open |
| Save As |
| All Files (*.*) |
| Untitled |
| an unnamed file |
| &Hide |
| No error message is available. |
| An unsupported operation was attempted. |
| A required resource was unavailable. |
| Out of memory. |
| An unknown error has occurred. |
| Invalid filename. |
| Failed to open document. |
| Failed to save document. |
| Save changes to %1? |
| Failed to create empty document. |
| The file is too large to open. |
| Could not start print job. |
| Failed to launch help. |
| Internal application error. |
| Command failed. |
| Insufficient memory to perform operation. |
| System registry entries have been removed and the INI file (if any) was deleted. |
| Not all of the system registry entries (or INI file) were removed. |
| This program requires the file %s, which was not found on this system. |
| This program is linked to the missing export %s in the file %s. This machine may have an incompatible version of %s. |
| Please enter an integer. |
| Please enter a number. |
| Please enter an integer between %1 and %2. |
| Please enter a number between %1 and %2. |
| Please enter no more than %1 characters. |
| Please select a button. |
| Please enter an integer between 0 and 255. |
| Please enter a positive integer. |
| Please enter a date and/or time. |
| Please enter a currency. |
| Unexpected file format. |
| %1 |
| Cannot find this file. |
| Please verify that the correct path and file name are given. |
| Destination disk drive is full. |
| Unable to read from %1, it is opened by someone else. |
| Unable to write to %1, it is read-only or opened by someone else. |
| An unexpected error occurred while reading %1. |
| An unexpected error occurred while writing %1. |
| Unable to read write-only property. |
| Unable to write read-only property. |
| Unable to load mail system support. |
| Mail system DLL is invalid. |
| Send Mail failed to send message. |
| No error occurred. |
| An unknown error occurred while accessing %1. |
| %1 was not found. |
| %1 contains an invalid path. |
| %1 could not be opened because there are too many open files. |
| Access to %1 was denied. |
| An invalid file handle was associated with %1. |
| %1 could not be removed because it is the current directory. |
| %1 could not be created because the directory is full. |
| Seek failed on %1 |
| A hardware I/O error was reported while accessing %1. |
| A sharing violation occurred while accessing %1. |
| A locking violation occurred while accessing %1. |
| Disk full while accessing %1. |
| An attempt was made to access %1 past its end. |
| No error occurred. |
| An unknown error occurred while accessing %1. |
| An attempt was made to write to the reading %1. |
| An attempt was made to access %1 past its end. |
| An attempt was made to read from the writing %1. |
| %1 has a bad format. |
| %1 contained an unexpected object. |
| %1 contains an incorrect schema. |
| pixels |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 1.0.0.1 |
| ProductVersion | 1.0.0.1 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | English - United States |
| FileDescription | StukSt MFC Application |
| FileVersion (#2) | 1, 0, 0, 1 |
| InternalName | StukSt |
| LegalCopyright | Copyright (C) 1999 |
| OriginalFilename | StukSt.EXE |
| ProductName | StukSt Application |
| ProductVersion (#2) | 1, 0, 0, 1 |
| Resource LangID | English - United States |
|---|
No comments yet.