Static | ZeroBOX

PE Compile Time

2024-06-28 12:30:30

PDB Path

C:\Users\Lenovo\Desktop\XieBro-v3.3\x64\Release\cldapi.pdb

PE Imphash

dbd2cf4e72a93457ba687ec4bfc994e8

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00010f06 0x00011000 6.36116786841
.rdata 0x00012000 0x0000609c 0x00006200 4.87435534159
.data 0x00019000 0x00001498 0x00000800 3.53211613
.pdata 0x0001b000 0x00001278 0x00001400 4.6943364093
.00cfg 0x0001d000 0x00000038 0x00000200 0.43246719153
.retplne 0x0001e000 0x0000008c 0x00000200 1.05058324797
.tls 0x0001f000 0x00000a09 0x00000c00 0.0196541427986
.rsrc 0x00020000 0x000001a8 0x00000200 4.16938341801
.reloc 0x00021000 0x00000268 0x00000400 3.87260908159

Resources

Name Offset Size Language Sub-language File type
RT_MANIFEST 0x00020060 0x00000143 LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document, ASCII text

Imports

Library KERNEL32.dll:
0x180015960 AcquireSRWLockExclusive
0x180015968 CloseHandle
0x180015970 CreateToolhelp32Snapshot
0x180015978 DecodePointer
0x180015980 DeleteCriticalSection
0x180015988 EncodePointer
0x180015990 EnterCriticalSection
0x180015998 ExitProcess
0x1800159a0 FormatMessageW
0x1800159a8 FreeLibrary
0x1800159b0 GetCurrentProcess
0x1800159b8 GetCurrentProcessId
0x1800159c0 GetCurrentThreadId
0x1800159c8 GetLastError
0x1800159d0 GetLocaleInfoEx
0x1800159d8 GetModuleHandleA
0x1800159e0 GetModuleHandleExW
0x1800159e8 GetModuleHandleW
0x1800159f0 GetProcAddress
0x1800159f8 GetStringTypeW
0x180015a00 GetSystemTimeAsFileTime
0x180015a10 InitializeSListHead
0x180015a18 InterlockedFlushSList
0x180015a20 IsDebuggerPresent
0x180015a30 LCIDToLocaleName
0x180015a38 LCMapStringEx
0x180015a40 LeaveCriticalSection
0x180015a48 LocalFree
0x180015a50 MultiByteToWideChar
0x180015a58 Process32FirstW
0x180015a60 Process32NextW
0x180015a68 QueryPerformanceCounter
0x180015a70 RaiseException
0x180015a78 ReleaseSRWLockExclusive
0x180015a80 RtlCaptureContext
0x180015a88 RtlLookupFunctionEntry
0x180015a90 RtlUnwindEx
0x180015a98 RtlVirtualUnwind
0x180015aa8 Sleep
0x180015ab8 TerminateProcess
0x180015ac0 UnhandledExceptionFilter
0x180015ac8 VirtualAlloc
0x180015ad0 VirtualFree
0x180015ad8 VirtualProtect
0x180015ae0 VirtualQuery
0x180015ae8 WakeAllConditionVariable
0x180015af0 WideCharToMultiByte
Library USER32.dll:
0x180015b00 MessageBoxA
Library WININET.dll:
0x180015b10 HttpQueryInfoW
0x180015b18 InternetCloseHandle
0x180015b20 InternetOpenUrlA
0x180015b28 InternetOpenW
0x180015b30 InternetReadFile
Library msvcrt.dll:
0x180015b40 ?terminate@@YAXXZ
0x180015b48 _CxxThrowException
0x180015b50 __C_specific_handler
0x180015b58 __CppXcptFilter
0x180015b60 __CxxFrameHandler3
0x180015b70 ___lc_codepage_func
0x180015b78 ___lc_handle_func
0x180015b80 ___mb_cur_max_func
0x180015b88 __getmainargs
0x180015b90 __pctype_func
0x180015b98 __uncaught_exception
0x180015ba0 _amsg_exit
0x180015ba8 _callnewh
0x180015bb0 _clearfp
0x180015bb8 _errno
0x180015bc0 _fileno
0x180015bc8 _fseeki64
0x180015bd0 _initterm
0x180015bd8 _initterm_e
0x180015be0 _iob
0x180015be8 _isatty
0x180015bf0 _local_unwind
0x180015bf8 _lock
0x180015c00 _msize
0x180015c08 _unlock
0x180015c10 _wcsdup
0x180015c18 abort
0x180015c20 calloc
0x180015c28 ceil
0x180015c30 fclose
0x180015c38 fflush
0x180015c40 fgetc
0x180015c48 fgetpos
0x180015c50 fgetwc
0x180015c58 free
0x180015c60 fsetpos
0x180015c68 log10
0x180015c70 malloc
0x180015c78 memcpy
0x180015c80 memmove
0x180015c88 memset
0x180015c90 perror
0x180015c98 realloc
0x180015ca0 setvbuf
0x180015ca8 strchr
0x180015cb0 strcmp
0x180015cb8 strcpy_s
0x180015cc0 strlen
0x180015cc8 strnlen
0x180015cd0 strrchr
0x180015cd8 strtol
0x180015ce0 tolower
0x180015ce8 ungetc
0x180015cf0 ungetwc
0x180015cf8 wcslen
0x180015d00 wcsnlen
0x180015d08 wcsrchr
0x180015d10 wctomb_s

!This program cannot be run in DOS mode.$
`.rdata
@.data
.pdata
@.00cfg
@.retplne
@.reloc
AVVWSH
)ffff.
HfF;TLTu
UAWAVATVWSH
"fffff.
[_^A\A^A_]
UAWAVATVWSH
[_^A\A^A_]
UAWAVATVWSH
UAWAVATVWSH
[_^A\A^A_]
UAWAVATVWSH
[_^A\A^A_]
UAWAVVWSH
[_^A^A_]
UAWAVVWSH
8[_^A^A_]
UAWAVVWSH
8[_^A^A_]
UAWAVVWSH
8[_^A^A_]
AWAVAUATVWUSH
uTHcF<
fffff.
([]_^A\A]A^A_
AWAVVWSH
am errorH
[_^A^A_
UAWAVATVWSH
`[_^A\A^A_]
UAWAVATVWSH
[_^A\A^A_]
AWAVVWSH
[_^A^A_
UAVVWSH
`[_^A^]
UAVVWSH
0[_^A^]
UAVVWSH
0[_^A^]
AWAVAUATVWUSH
([]_^A\A]A^A_
UAVVWSH
P[_^A^]
UAVVWSH
[_^A^]
UAVVWSH
[_^A^]
AVVWSH
([_^A^
AVVWSH
([_^A^
AWAVAUATVWSH
P[_^A\A]A^A_
AWAVATVWUSH
@[]_^A\A^A_
l$ VWATAUAVH
A^A]A\_^
UVWAVAWH
0A_A^_^]
x ATAVAWH
0A_A^A\
WATAUAVAWH
A_A^A]A\_
WATAUAVAWH
A_A^A]A\_
WATAUAVAWH
A_A^A]A\_
t$ UWAVH
taL9Chu
L90u$H
@SUVWAVH
A^_^][
x ATAVAWH
A_A^A\
f#D$@H
T$`A9r
|$ AVH
H;\$(u$H
|$ AVH
t$ WATAUAVAWH
A_A^A]A\_
|$ ATAVAWH
A_A^A\
k4+kPA+
|$P@8sTtm9sP~hL
|$X,GH
WAVAWH
S0HcC8H
A_A^_
|$ UATAUAVAWH
A_A^A]A\]
D9l$lu
u3HcH<H
l$ WATAVH
A^A\_
SVWATAUAVAWH
PA_A^A]A\_^[
PA_A^A]A\_^[
t$ AVH
d$@H9C tQH
G(H9C(tQH
G0H9C0tTH
G@H9C@tTH
GHH9CHtRH
t7A80u
D$ I;R
@SVWATAUAVAWH
|$hHcC
d$pfff
A_A^A]A\_^[
@SVWATAUAVAWH
D$@L9wXt
A_A^A]A\_^[
B(I9A(A
|$ AVH
|$ AVH
AUAVAWH
0A_A^A]
|$ AVH
@USVWATAUAVAWH
A_A^A]A\_^[]
USVWATAUH
\$h=RCC
A]A\_^[]
\$ WATAWH
0A_A\_
0A_A\_
gfffffffH
|$ AVH
|$ AVH
|$ AVHcA
@USVWAUAWH
A_A]_^[]
iostream stream error
0123456789abcdefghijklmnopqrstuvwxyz
0123456789abcdefghijklmnopqrstuvwxyz
`h````
xpxxxx
[aOni*{
~ $s%r
@b;zO]
v2!L.2
Failed to allocate memory
LdrFastFailInLoaderCallout
bad cast
ios_base::failbit set
ios_base::eofbit set
ios_base::badbit set
note process
Unknown exception
Failed to change memory protection
RtlLeaveCriticalSection
iostream
ntdll.dll
bad array new length
string too long
bad locale name
LdrGetDllFullName
Failed to allocate memory with VirtualAlloc
Error: %s
fwrite
fputwc
1#SNAN
1#QNAN
(null)
directory not empty
text file busy
device or resource busy
no such file or directory
not a directory
is a directory
AddDllDirectory
not enough memory
localeconv
stream timeout
timed out
invalid argument
connection reset
network reset
ios_base::failbit set
ios_base::eofbit set
ios_base::badbit set
not a socket
file exists
connection already in progress
operation in progress
no such device or address
bad address
no such process
no child process
CorExitProcess
success
too many symbolic link levels
too many links
no stream resources
resource deadlock would occur
bad file descriptor
executable format error
io error
unknown error
protocol error
network down
no protocol option
bad exception
inappropriate io control operation
bad allocation
argument out of domain
resource unavailable try again
too many files open
too many files open in system
read only file system
not a stream
no link
cross device link
invalid seek
operation would block
bad array new length
argument list too long
filename too long
message size
address in use
wrong protocol type
broken pipe
state not recoverable
address not available
no lock available
no message available
host unreachable
network unreachable
setlocale
value too large
file too large
result out of range
no message
bad message
illegal byte sequence
no space on device
no such device
no buffer space
identifier removed
operation not permitted
address family not supported
function not supported
operation not supported
protocol not supported
not supported
connection aborted
interrupted
already connected
not connected
connection refused
destination address required
operation canceled
permission denied
owner dead
nan(snan)
nan(ind)
NAN(SNAN)
NAN(IND)
\LLD PDB.
C:\Users\Lenovo\Desktop\XieBro-v3.3\x64\Release\cldapi.pdb
AcquireSRWLockExclusive
CloseHandle
CreateToolhelp32Snapshot
DecodePointer
DeleteCriticalSection
EncodePointer
EnterCriticalSection
ExitProcess
FormatMessageW
FreeLibrary
GetCurrentProcess
GetCurrentProcessId
GetCurrentThreadId
GetLastError
GetLocaleInfoEx
GetModuleHandleA
GetModuleHandleExW
GetModuleHandleW
GetProcAddress
GetStringTypeW
GetSystemTimeAsFileTime
InitializeCriticalSectionEx
InitializeSListHead
InterlockedFlushSList
IsDebuggerPresent
IsProcessorFeaturePresent
LCIDToLocaleName
LCMapStringEx
LeaveCriticalSection
LocalFree
MultiByteToWideChar
Process32FirstW
Process32NextW
QueryPerformanceCounter
RaiseException
ReleaseSRWLockExclusive
RtlCaptureContext
RtlLookupFunctionEntry
RtlUnwindEx
RtlVirtualUnwind
SetUnhandledExceptionFilter
SleepConditionVariableSRW
TerminateProcess
UnhandledExceptionFilter
VirtualAlloc
VirtualFree
VirtualProtect
VirtualQuery
WakeAllConditionVariable
WideCharToMultiByte
MessageBoxA
HttpQueryInfoW
InternetCloseHandle
InternetOpenUrlA
InternetOpenW
InternetReadFile
?terminate@@YAXXZ
_CxxThrowException
__C_specific_handler
__CppXcptFilter
__CxxFrameHandler3
__DestructExceptionObject
___lc_codepage_func
___lc_handle_func
___mb_cur_max_func
__getmainargs
__pctype_func
__uncaught_exception
_amsg_exit
_callnewh
_clearfp
_errno
_fileno
_fseeki64
_initterm
_initterm_e
_isatty
_local_unwind
_msize
_unlock
_wcsdup
calloc
fclose
fflush
fgetpos
fgetwc
fsetpos
malloc
memcpy
memmove
memset
perror
realloc
setvbuf
strchr
strcmp
strcpy_s
strlen
strnlen
strrchr
strtol
tolower
ungetc
ungetwc
wcslen
wcsnlen
wcsrchr
wctomb_s
KERNEL32.dll
USER32.dll
WININET.dll
msvcrt.dll
https://zn-download-2023.s3.amazonaws.com/ytr/w.png
.?AVfailure@ios_base@std@@
.?AVsystem_error@std@@
.?AV_System_error@std@@
.?AVruntime_error@std@@
.?AVexception@std@@
.?AV_Iostream_error_category2@std@@
.?AVerror_category@std@@
.?AVbad_array_new_length@std@@
.?AVbad_alloc@std@@
.?AV?$ctype@_W@std@@
.?AUctype_base@std@@
.?AVfacet@locale@std@@
.?AV_Facet_base@std@@
.?AU_Crt_new_delete@std@@
.?AVbad_cast@std@@
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVbad_exception@std@@
.?AVtype_info@@
.?AV_Locimp@locale@std@@
.?AVios_base@std@@
.?AV?$_Iosb@H@std@@
.?AV?$basic_ios@_WU?$char_traits@_W@std@@@std@@
.?AV?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@
.?AV?$basic_ostream@_WU?$char_traits@_W@std@@@std@@
.?AV?$basic_filebuf@_WU?$char_traits@_W@std@@@std@@
.?AVcodecvt_base@std@@
.?AV?$codecvt@_WDU_Mbstatet@@@std@@
RetpolineV1
RetpolineV1
RetpolineV1
RetpolineV1
<?xml version="1.0" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1"
manifestVersion="1.0">
<trustInfo>
<security>
<requestedPrivileges>
<requestedExecutionLevel level='asInvoker' uiAccess='false'/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
OneDriveStandaloneUpdater.exe
explorer.exe
OneDrive.exe
HTTP Example
Failed to get first process in the snapshot.
Failed to create snapshot of the processes.
Neither OneDrive, Explorer, nor OneDriveStandaloneUpdater is running. Exiting...
OneDriveStandaloneUpdater Running:
Explorer Running:
OneDrive Running:
msvcrt.dll
mscoree.dll
kernel32
advapi32
(null)
Antivirus Signature
Bkav W64.AIDetectMalware
Lionic Clean
tehtris Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
Skyhigh Clean
ALYac Clean
Cylance Clean
Zillya Clean
Sangfor Clean
K7AntiVirus Clean
Alibaba Clean
K7GW Clean
Cybereason Clean
Baidu Clean
VirIT Clean
Symantec Clean
Elastic Clean
ESET-NOD32 Clean
APEX Clean
Avast Clean
Cynet Malicious (score: 100)
Kaspersky Backdoor.MSIL.DCRat.ccj
BitDefender Clean
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Clean
Tencent Clean
Sophos Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfeeD ti!96C237048743
Trapmine Clean
FireEye Clean
Emsisoft Clean
Paloalto Clean
GData Clean
Jiangmin Clean
Webroot Clean
Varist Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Backdoor.MSIL.DCRat.ccj
Microsoft Clean
Google Clean
AhnLab-V3 Clean
Acronis Clean
McAfee Clean
TACHYON Clean
VBA32 Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Clean
Yandex Clean
Ikarus Clean
MaxSecure Clean
Fortinet Clean
BitDefenderTheta Clean
AVG Clean
DeepInstinct MALICIOUS
CrowdStrike win/malicious_confidence_70% (D)
alibabacloud Clean
No IRMA results available.