Sample details: 93aeb21ba85d600e273169f5ba127117 --

Hashes
MD5: 93aeb21ba85d600e273169f5ba127117
SHA1: 397aa8de55e89c734e6f1de3ec60675571db53e4
SHA256: 0eb633fae5cfd0ef55217e24cda47d75168c9af19c2e8077376a6dcb8b5a4b55
SSDEEP: 1536:czvQSZpGS4/31A6mQgL2eYCGDwRcMkVQd8YhY0/EqfIzmd:nSHIG6mQwGmfOQd8YhY0/EqUG
Details
File Type: PE32
Yara Hits
YRP/Microsoft_Visual_Cpp_v50v60_MFC | YRP/IsPE32 | YRP/IsWindowsGUI | YRP/HasRichSignature | YRP/maldoc_find_kernel32_base_method_1 | YRP/domain | YRP/url | YRP/contentis_base64 | YRP/Browsers | YRP/DebuggerCheck__QueryInfo | YRP/network_dns | YRP/CRC32_poly_Constant | YRP/CRC32_table | YRP/Str_Win32_Winsock2_Library | YRP/with_sqlite |
Source
http://gamesarena.gdn/games/KC2i.exe
Strings
		!This program cannot be run in DOS mode.
`.rdata
@.data
9D$(ub
L$(9L$@
v89l$D|0
uM9l$D}G
D$0;D$(
9|$4r4
9|$4r4
+L$PRQW
+D$P][_^
AP32uS
L$<+L$
L$<+L$
L$<+L$
XjTZj3f
XjNYjEf
Xjr^jlf
ZjPXjIf
Xj2_jSf
je[j3f
ZjHXjEf
WWhM8g
t8VVh@
QVVVWVV
tCVVh[
YYGt]h
WWhQ]V
QSSSSSSh 
WWh_*y
WWh_*y
SWh0QA
uiSShx
t{;Atsv
u.hpSA
QQQQQQRP
uWSVW3
u.hTSA
[Sh@TA
>versu
VVVQPR
u8hXaA
tOWVhPeA
t-Sh,dA
tOSVWh
tOSVWh
t3hPdA
tOSVWh
tOSVWh
tOSVWh
tJSVWh
t3hPdA
_PSh\QA
t2Wh@?
QWWWVWWW
uVhpiA
WVhTlA
j*XjMf
XjiYjlf
HSVWjAXjcYjof
Xjt[j*f
Xjf_j%f
Yj\ZjDf
Xje^jkf
YjSXjof
HSVWj%Xjsf
Xji[jlf
Xjo^jt_jfZjef
XjrYjPf
jmXjlf
pSVWj%ZjS^jYXjTf
XjEYjMf
ZjoXjff
Xja[jrf
Xje_jnf
ji^jlZjgf
Yj\XjD_jtf
_jmXj.f
SVWjSXjof
Xjr[je^j\ZjWf
XjiYjn_jCf
YjUXjAf
DSVWj%Xjsf
Xje[jr_jaf
Xj ^jMZjiYjlf
WVh`sA
0SVWj%Xjs[j\Zj._jpYju^jrf
YjeXjaf
4SVWj%Xjsf
Xj\^jPf
Xjo_jcZjmf
XjaYji[jlf
SVWjSXjOf
XjE[j\Yjf_jl^jaf
XjkZjaf
jmZVXjp^j.f
^juYjhf
YjaXjpf
YjaXjpf
js[jmXjaYj.f
YjtZjp^jaf
[jmXjaf
ZjpXjhf
ju^jhXjef
^jpXjof
VjaXjdf
PSVWj%Xjsf
Xj\[jTf
Xju^jlYjyf
XjaZji_jDf
SVWj%Xjsf
Xj\Yjyf
Xj2ZjPf
YjOXj3f
Xj.[jx^jm_jlf
j\XjSf
Yj%Xjsf
j\XjyZjMf
XjiYj\f
VShLwA
VShhwA
7PSh|wA
umj1Xf
u.hpiA
<0u8Wh
t]VWh0
Vj*Xj.f
SVWj*Xj.f
XjnYjff
Xjs[j\_jNf
Xjo^jtZjef
YjFXjlf
HSVWj%Xjsf
XjoYjnf
Xje[jpf
Xjt_jwf
XjlZjd^j\f
YjoXjzf
j8Xj.f
SVWj*Xj.Zjpf
XjgYj%f
Zj\Xjtf
Xjc[jk_je^j\f
j%Xjsf
TSVWj%Xjs^j\[jMf
XjiZjcYjrf
XjS_jkf
j*Xj.f
8VWj%Xjs_j\^jTf
XjoZj-f
XjDYj f
YjLXjif
j%XjsYj\f
 j*Xj.f
XjsYj\f
$SVWj*[j._jk^jdZjbYjxXf
(j%Xjsf
Xj ZjRf
XjoYjbf
,VWj*Xj.f
Xjb_jMf
Xji^jkYjrf
XjoZjtf
@SVWjSXjof
Xjt^jwf
Xjr[je_jFf
XjlZj YjTf
8VWjPXja^jsYjwf
XjrZjdf
jSXjof
SjcXj:f
jSXjoZjf
Xjr[jef
XjB_j Yjaf
XjiYjnf
Xjs[j\f
ZjtXjaf
YjeXjAf
VjPXjof
XjrYjSf
Sj%XjsYj\f
u@h(mA
uLh(mA
j.Xjzf
(Vj*Xj.f
XjmZjsYjc^jwf
WWh_*y
QQSVWh
tqNt*Nt
PWh\QA
jOXjLf
Xj3[j2_j.ZjdYjl^f
PPhM8g
t:WPVh
$@0123456789ABCDEF
UNIQUE
SQLite format 3
DlRycq1tP2vSeaogj5bEUFzQiHT9dmKCn6uf7xsOY0hpwr43VINX8JGBAkLMZW
http://
https://
MachineGuid
SOFTWARE\Microsoft\Cryptography
LdrGetProcedureAddress
RtlNtStatusToDosError
RtlSetLastWin32Error
ZwQueryInformationProcess
RtlCreateUserThread
ZwAllocateVirtualMemory
NtFreeVirtualMemory
NtWriteVirtualMemory
ZwReadVirtualMemory
ZwResumeThread
last_compatible_version
password_value
username_value
origin_url
logins
VaultEnumerateItems
VaultEnumerateVaults
VaultFree
VaultGetItem
VaultOpenVault
VaultCloseVault
SELECT encryptedUsername, encryptedPassword, formSubmitURL, hostname FROM moz_logins
hostname
encryptedUsername
encryptedPassword
NSS_Init
NSS_Shutdown
PK11_GetInternalKeySlot
PK11_FreeSlot
PK11_Authenticate
PK11SDR_Decrypt
PK11_CheckUserPassword
SECITEM_FreeItem
sqlite3_finalize
sqlite3_step
sqlite3_close
sqlite3_column_text
sqlite3_open16
sqlite3_prepare_v2
sqlite3_prepare
ffffff
CloseHandle
CreateFileW
WriteFile
ExitProcess
CryptStringToBinaryA
StrStrA
GetProcAddress
LoadLibraryW
X!2$6*9(SKiasb+!v<.qF58_qwe~QsRTYvdeTYb
string
Server
settings
server
username
protocol
LsaICryptUnprotectData
UserName
Password
MAC=%02X%02X%02XINSTALL=%08X%08Xk
Fuckav.ru
aPLib v1.01  -  the smaller the better :)
Copyright (c) 1998-2009 by Joergen Ibsen, All Rights Reserved.
More information: http://www.ibsensoftware.com/
Qkkbal
getaddrinfo
freeaddrinfo
WS2_32.dll
GetLastError
SetLastError
HeapAlloc
HeapFree
GetProcessHeap
KERNEL32.dll
CoInitialize
CoUninitialize
CoCreateInstance
ole32.dll
OLEAUT32.dll