Static | ZeroBOX

PE Compile Time

2021-09-03 16:41:16

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00040ba0 0x00040c00 7.97971384983
.rsrc 0x00044000 0x00029f08 0x0002a000 4.27265128233
.reloc 0x0006e000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0006d5a4 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0006d5a4 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0006d5a4 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0006d5a4 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0006d5a4 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0006d5a4 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0006d5a4 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0006d5a4 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0006d5a4 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x0006da0c 0x00000084 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0006da90 0x000002c4 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0006dd54 0x000001b4 LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with very long lines, with no line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
PgaT^bI
5^Ek)K
W}NNn'
D~Q&~"
!6.>!.
_IbnEjb\
}'XWuB&
ux&hOC
r8<[tx
]<:!m0
UXO7l?@H
w*|C?Er
rx;Avm
E;+hgM
/1eUs
.[cwjp
#1?7wb;^`J
bEJw%R
Vr2&x2&
D0`p;
8rR\y.
AWAu!X9)
Q-ru,W
~9e#A;v
^#zE[h
wLTl`NH
l.L-~
Sn?F>I
o6V/=0
`cOB'/
mhG;Pg
~!lc=xx
FsoDbpc
{(70I9y
-vW0te
sinsq}
?`_*dJ
%Lo1$K
r6@B)X:
`D(^g2
E=^z&w%
Wzc5SM
5P:\{k
'ii'FE
=G>3~9
dx/\\<
!=_",
%3z3&W
-LRzXk
cz|BN
w]\[m=
C5v\+-
]}6EyN
i94WN\
;:7=)KTi
Yf=>%H
pU6r^K0
:[22|=
:Ma^0p
3LnvR`
b,O`y]
'I^ex6/
a0Ma_g`
Qay~}4
% aU]CD
Gt$G&D
b NPYF:
-FOU}
`D"4XP
miqT&+
hL#G?.)
A6'YrS}
g]U")Z
zXw.QHiD
+~7p%}
CNPAPa
9`l;ah
iwz\X#
:6;Lyn
LwuuuuuUu
t6'C}~
~MenN-m5
t9pJ"'
kKAUsAx
/~y[Kyy
)Jr4dP
)bNhYP
A?JNNh^
9RU.2$
*Htkg
?5XF^Q
OrBF)B
>xog:o
UIHbCZX0
FhFH{S
robP"~
h.x71D
+Ic\kb
9k')h
Cok6K
_'*)zl^
kUKACj
n/=OwY*
^fYP,m
)F1kaH
cEu[h4}
?fKnw\ZZ
J~DzcxJ
-%YFD9=+
8X`^Z
:b|B:c
=EV,#<A
lMs<UG
YHGY@,
.;{a1n
7#-,I
U0#{t]
Xa\b20
zd$%BJ{
COSyvP
G$*cN\
?dF5Y?M
4RVJi
0AB013T
%eWJ4k
oqdF3[gd
4"a-{
$}o8&<
V nLNM
RzkzUz
$/Um`S
i{ac?x
JC2WF-
#)v*q4
CyFa5M
o_m+YR|
uyRONk[qyQI
/Pp[d<
Ck/{rB
`+pQ2&
NlM|o9
SJIZf1
'ThOQt)
&|Pr{V
%9\`6;
Zp:d>"&'
K1MT8Z
f=,=M5
D40p;a
77Tavm
Rn{',q'
<](BPO
bg *?j
kZmsi'
2J!:Bk{(q
kr$261,h`
cjbFbVFVz
^Zev6=Egd#Np4
y{ .K"
r;G;:>
_%U)E
Wah_gA&\
6bbDD&&
>-8S@J
Y{JvxM
i<S7oK;
hrBV'FF
]'mQTH
$>dwnOdM
~I^V|
^s<r4r
ZrhaJU
K)I3_7
:6]?Ay
\N*'.0
QZ]\]X
Le3460
uTF-[qLS
lgNnmfd
Qr^5_g_P
NAI{XY+
ET$z~t}
ybH2pTZ[
"3~Lkq
6Jwwwww7K# Hw
tJwwJwI
:H3tb
DU*LZ1:
zj<@m&k
#e-mdm
A#9&@1
sJ*Q(q
X.1qsF
J$>V4F
8, jLr
`lluqlm
Q#_Wv/+
>7v6$
&v4{,i
oFXt1
xT)#'H
*d.z7'N
QijV5i\=
=yTl-P
Nyv}+7=Nf
8<" X<,
@~\iWz
8JHPp-
6o$}x+i
$1-h*q
ALX"*B
$SL/L(p
" f)'O
AsG1n[
*e!|4~
`p|K&@
iXwJm
KqRYa=mU
IqGW)\
~2$?SF3
A5#I7C
SfvO !
;"Q-B*8q
#68rs
ae-?t;
VK$.!9
O*Cl}/$
0#[=\x
%_2,R'
1v?;*A
&-,"n(
nnH.lF
P3%2834
s+uy]%
o8_z5Yf
VSCOdk
!&oH(y:
~9I\N
2-'d;|z
^WcB4/
_H1Gv!
g^5>gG-
r]Yj_,
U{=)5g
-]va.@
Y@=|rP
F>u'W#
HRO#wg
Y["}th
hI0tZv3
J"ea|D
]<JHW^
VM%6@Ua$
x&o16S5
?o7%i+
_D+g?b
i7">y3
;@;]:k
GwsH$8%
CB(zIPL
NS=Ui*J
EeH}u<f
{EOFJSQ
lZ-g_B
@.~D.d.
wv;r{N
Za*"zf
]RdH(*O
5mI<5z
z$kdJO
2G6HS
1A(s}8
vr[r/"
=L>)")
p"6h`G(
<.OC>X
Dbwyfk
Cfo8rd
]_AV12
?iW3yT
k#4PihW
TYG`VPTh
-8XXq7
"3lgpWQP}eX8
vptW'0
vD3#-
4@Uynz
i|^t(e[
!P#^c
blaTsU
|c@TFg
*ss+'J
*khDb<
{!SO2t
heSyq
@S;o7k
VETY[lD
[nc3Ki/
;4so9@s
GR66A`
tDw\,=
sd@my 1
pix&rL
}^Tv1uV;
j4E$=*
GB]Oo"
kU2f<Q}
+C-.g+
?f4OuG7\
5h7Iiyn
R|>Iqc
rD2=>W:l
[Ma6/C
FemNu
HsB'`=
~#%WT]7
e-~?`n
\{c[?0
\GZl9R
2*k;vfK
oF.C(!b
$s|F#D
"+~zYNt
/%[(YpR
d17_4m
o[zV_#C_k
=}5Z~s
jw[A;{
%\S<0~o
>)G?iJ
k=3KWj
DOyn/;U
3?I/+
jj\3k'
ahZHjA"
ln[,No`o4
=.2EjIG
Ikvg4!
Mpw*r"i
'-(6FV
BT]8)%
(r:^OC
$EwrbI2
^R=c@./
fZy{`dM
OkPosy|z
Z[}Ao+
,:[yL7
)Yg/--r
2Q\[[FI
2[IeQI
EFE#DE
?7Hxph$
b]P"Pz 7
_n-oLZ
lfodgF
#W?.'|
R<(|to
4 Az_5n(
o\0MAT
~uIptuIv
QRX/v
:Kz4_!
}vF1oa
2S&T>F6
!esUG/3>.B
)HW5jG
zS8#,"~
~n2":'
:K7Q:+}}g
qA.RCO>
/VP[K+x
|j$xoY
wN1U@*
8k0cD\
5>s9EZ
s2xE|XW3
M#e_er
$]b\,>
27o>U-S
R(G,Nf
u2,=A*
+>pbsS
b7waa3
|1%W@=
BmIqZ7\
tHS!Sf^
'{~]&Z
Wo"45N
G!yF@k
~TX\du
z86]/p
g1Mo\HvP
"?cj9k(#
TeE0ly
cZ)\S'
1JV_.v?w
6/q)ey
gN[52x
UQqhHt
DafQ_A|
w]u1(T2
IUn#>yr
)C2XJN
\ SyE
6amuwe
X^8GT0
'Y*Zh%o^
^>TGhfh
Y^,fnQ
:IrU\
tCf>LL
@>xK=$]
gM;|YB?
1z/v"
'!o#!_
=(]b6l
b&C-$,
:_Gn y
x%X^2r-
O:h%\8
W9$9s
D|M@'c
Em#E(y
J~AxYI
NYV:[N
R9Se7O
EQnZ"T
~_y;d;
p^S,(B
!d3`Jeo
^Su}k`
x%#7U (
ue6cCpg
yLz?c"
U;m-;{
}[!Tpj
f(3q5e
h@a<y
iv8O~^
v4.0.30319
#Strings
tik.exe
mscorlib
System.Windows.Forms
System
Qucrja
System.Drawing
System.Web
Hlkdxlsfgbsjipcehilclt.d.resources
Hlkdxlsfgbsjipcehilclt.e.resources
Hlkdxlsfgbsjipcehilclt.f.resources
Hlkdxlsfgbsjipcehilclt.Properties.Resources.resources
Hlkdxlsfgbsjipcehilclt.Qucrja.dll
ClassLibrary
AppDomain
ArgumentNullException
Boolean
GeneratedCodeAttribute
System.CodeDom.Compiler
IList`1
System.Collections.Generic
IContainer
System.ComponentModel
ApplicationSettingsBase
System.Configuration
SettingsBase
DateTime
DebuggerNonUserCodeAttribute
System.Diagnostics
Process
ProcessStartInfo
ProcessWindowStyle
EventArgs
EventHandler
Exception
CultureInfo
System.Globalization
IDisposable
BufferedStream
System.IO
CompressionMode
System.IO.Compression
GZipStream
FileInfo
FileSystemInfo
MemoryStream
Stream
IntPtr
Object
Random
Assembly
System.Reflection
AssemblyCompanyAttribute
AssemblyConfigurationAttribute
AssemblyCopyrightAttribute
AssemblyDescriptionAttribute
AssemblyFileVersionAttribute
AssemblyProductAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
ResolveEventArgs
ResolveEventHandler
ResourceManager
System.Resources
CompilationRelaxationsAttribute
System.Runtime.CompilerServices
CompilerGeneratedAttribute
RuntimeCompatibilityAttribute
SuppressIldasmAttribute
ComVisibleAttribute
System.Runtime.InteropServices
GuidAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
RuntimeTypeHandle
STAThreadAttribute
Single
String
Capture
System.Text.RegularExpressions
RegexOptions
Thread
System.Threading
ThreadStart
HttpContext
HttpServerUtility
Application
AutoScaleMode
Button
ButtonBase
ContainerControl
Control
ControlCollection
TextBox
<Module>
Settings
Hlkdxlsfgbsjipcehilclt.Properties
Hlkdxlsfgbsjipcehilclt
.cctor
Dispose
Synchronized
get_Name
Contains
GetExecutingAssembly
GetManifestResourceStream
CopyTo
ToArray
get_Current
get_Server
MapPath
GetFileNameWithoutExtension
ToString
Concat
set_FileName
Format
set_Arguments
set_CreateNoWindow
set_UseShellExecute
set_StartInfo
WaitForExit
get_Message
PerformClick
set_Location
set_Name
set_Size
set_TabIndex
set_Text
set_UseVisualStyleBackColor
add_Click
set_AutoScaleDimensions
set_AutoScaleMode
set_ClientSize
get_Controls
add_Load
ResumeLayout
SuspendLayout
set_AutoSize
add_TextChanged
PerformLayout
get_CurrentDomain
add_AssemblyResolve
set_WindowStyle
IsNullOrWhiteSpace
get_Success
get_Value
ToUpper
op_Equality
EnableVisualStyles
SetCompatibleTextRenderingDefault
GetTypeFromHandle
get_Assembly
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
11.0.0.0
3System.Resources.Tools.StronglyTypedResourceBuilder
16.0.0.0
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
WrapNonExceptionThrows
$08bcb5fb-1b4e-4648-9260-7d62744fa055
0.0.0.0
_CorExeMain
mscoree.dll
KIDATx
u{oj8g
r[p2zh
Pdk0>>
$D*D@a
kI0BH?
D ZN R
I:!+m6
BJ@xB>z
Ra(@H?
ytTQFP
<?xml version="1.0" encoding="utf-8" standalone="yes"?><assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><assemblyIdentity version="1.0.0.0" name="MyApplication.app" /><trustInfo xmlns="urn:schemas-microsoft-com:asm.v2"><security><requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3"><requestedExecutionLevel level="asInvoker" uiAccess="false" /></requestedPrivileges></security></trustInfo></assembly>PADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGX
tbcdefghijk
Qucrja
Hlkdxlsfgbsjipcehilclt.Qucrja.dll
/video/
/video/ffmpeg.exe
-ss {0} -i {1} -f image2 -vframes 1 -y {2}
button1
button18
button19
label1
textBox1
powershell
Test-Connection -ComputerName google.com
(?<=rel=").+?(?=")
(?<=<).+?(?=>)
Hlkdxlsfgbsjipcehilclt.Properties.Resources
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
FileDescription
FileVersion
0.0.0.0
InternalName
tik.exe
LegalCopyright
LegalTrademarks
OriginalFilename
tik.exe
ProductName
ProductVersion
0.0.0.0
Assembly Version
0.0.0.0
Antivirus Signature
Bkav Clean
Lionic Trojan.Multi.Generic.4!c
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.GenericKD.37531067
FireEye Generic.mg.2436aadd7124bfff
CAT-QuickHeal Clean
ALYac Trojan.GenericKD.37531067
Cylance Unsafe
VIPRE Clean
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Trojan ( 00581c861 )
BitDefender Trojan.GenericKD.37531067
K7GW Trojan ( 00581c861 )
CrowdStrike win/malicious_confidence_90% (W)
Arcabit Trojan.Generic.D23CADBB
BitDefenderTheta Gen:NN.ZemsilF.34126.Am0@aOhYNLf
Cyren W32/MSIL_Kryptik.EXX.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of MSIL/Kryptik.ACQW
Baidu Clean
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky HEUR:Trojan-Spy.MSIL.Noon.gen
Alibaba TrojanSpy:MSIL/Kryptik.7bccfd13
NANO-Antivirus Clean
ViRobot Clean
Avast Win32:PWSX-gen [Trj]
Rising Clean
Ad-Aware Trojan.GenericKD.37531067
Sophos Mal/Generic-S
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.gc
CMC Clean
Emsisoft Trojan.Crypt (A)
Ikarus Trojan.MSIL.Crypt
Jiangmin Clean
eGambit Unsafe.AI_Score_75%
Avira TR/Kryptik.utgaw
MAX malware (ai score=88)
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Microsoft Trojan:Script/Phonzy.C!ml
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-Spy.MSIL.Noon.gen
GData MSIL.Trojan-Stealer.AgentTesla.N9BUH4
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win.Generic.C4624351
Acronis Clean
McAfee RDN/Generic.rp
TACHYON Clean
VBA32 Clean
Malwarebytes Spyware.AgentTesla
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Win32.Trojan.Inject.Auto
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet MSIL/Kryptik.ACNM!tr
Webroot Clean
AVG Win32:PWSX-gen [Trj]
Cybereason malicious.a79e74
Panda Trj/GdSda.A
No IRMA results available.