Helper.dll

Description: ChasePlane 2024

Authors: (C) Copyright 2025 PARALLEL 42, LLC.

Version: 1.0.0.4

Architecture: 64-bit

Operating System: Windows

SHA256: 2fdc8d828be80e3c6da755f79025e68c

File Size: 767.3 KB

Uploaded At: May 22, 2026, 4:12 p.m.

Views: 9

Security Warning

This file has been flagged as potentially dangerous.


Reason: Detected potentially dangerous functions used for process injection: OpenProcess, WriteProcessMemory, VirtualAllocEx

Exported Functions

  • Disconnect (Ordinal: 1, Address: 0x45740)
  • Connect (Ordinal: 2, Address: 0x458b0)
  • DisConnect (Ordinal: 3, Address: 0x45830)
  • GetBuffer (Ordinal: 4, Address: 0x38680)
  • QueryStatus (Ordinal: 5, Address: 0x45570)
  • SetDebugMode (Ordinal: 6, Address: 0x45720)

Imported DLLs & Functions

api-ms-win-crt-convert-l1-1-0.dll
  • strtol (Address: 0x180053350)
api-ms-win-crt-filesystem-l1-1-0.dll
  • remove (Address: 0x180053360)
api-ms-win-crt-heap-l1-1-0.dll
  • _aligned_free (Address: 0x180053388)
  • _aligned_malloc (Address: 0x1800533a0)
  • _callnewh (Address: 0x180053378)
  • calloc (Address: 0x180053380)
  • free (Address: 0x180053390)
  • malloc (Address: 0x180053398)
  • realloc (Address: 0x180053370)
api-ms-win-crt-locale-l1-1-0.dll
  • _create_locale (Address: 0x1800533b8)
  • _free_locale (Address: 0x1800533b0)
api-ms-win-crt-math-l1-1-0.dll
  • ceilf (Address: 0x1800533c8)
api-ms-win-crt-runtime-l1-1-0.dll
  • _cexit (Address: 0x1800533e8)
  • _configure_narrow_argv (Address: 0x180053428)
  • _crt_atexit (Address: 0x1800533e0)
  • _errno (Address: 0x180053430)
  • _execute_onexit_table (Address: 0x1800533d8)
  • _initialize_narrow_environment (Address: 0x180053418)
  • _initialize_onexit_table (Address: 0x180053410)
  • _initterm (Address: 0x180053400)
  • _initterm_e (Address: 0x180053408)
  • _invoke_watson (Address: 0x180053420)
  • _register_onexit_function (Address: 0x1800533f0)
  • _seh_filter_dll (Address: 0x180053438)
  • terminate (Address: 0x1800533f8)
api-ms-win-crt-stdio-l1-1-0.dll
  • __acrt_iob_func (Address: 0x180053488)
  • __stdio_common_vfprintf (Address: 0x180053480)
  • __stdio_common_vsprintf (Address: 0x180053470)
  • fclose (Address: 0x180053460)
  • fopen (Address: 0x180053468)
  • fread (Address: 0x180053450)
  • fseek (Address: 0x180053448)
  • ftell (Address: 0x180053478)
  • fwrite (Address: 0x180053458)
  • rewind (Address: 0x180053490)
api-ms-win-crt-string-l1-1-0.dll
  • _stricmp (Address: 0x1800534a8)
  • strcmp (Address: 0x1800534a0)
  • strncpy (Address: 0x1800534b0)
dbghelp.dll
  • MiniDumpWriteDump (Address: 0x1800534c0)
KERNEL32.dll
  • CloseHandle (Address: 0x180053058)
  • CreateFileA (Address: 0x1800530d8)
  • CreateFileMappingW (Address: 0x180053060)
  • CreateThread (Address: 0x180053128)
  • CreateToolhelp32Snapshot (Address: 0x1800530a8)
  • DeleteCriticalSection (Address: 0x180053028)
  • EnterCriticalSection (Address: 0x180053010)
  • FindResourceA (Address: 0x180053108)
  • GetCurrentProcess (Address: 0x180053158)
  • GetCurrentProcessId (Address: 0x180053178)
  • GetCurrentThreadId (Address: 0x180053168)
  • GetExitCodeProcess (Address: 0x180053148)
  • GetLastError (Address: 0x180053080)
  • GetModuleFileNameW (Address: 0x180053150)
  • GetModuleHandleExA (Address: 0x180053110)
  • GetProcAddress (Address: 0x180053090)
  • GetSystemInfo (Address: 0x180053000)
  • GetSystemTimeAsFileTime (Address: 0x1800531c0)
  • GetThreadId (Address: 0x180053170)
  • InitializeCriticalSection (Address: 0x180053020)
  • InitializeSListHead (Address: 0x180053188)
  • IsDebuggerPresent (Address: 0x180053190)
  • IsProcessorFeaturePresent (Address: 0x180053198)
  • K32EnumProcessModules (Address: 0x1800530f0)
  • K32EnumProcessModulesEx (Address: 0x1800530c0)
  • K32GetModuleBaseNameA (Address: 0x1800530e0)
  • K32GetModuleFileNameExA (Address: 0x1800530d0)
  • K32GetModuleInformation (Address: 0x1800530e8)
  • LeaveCriticalSection (Address: 0x180053018)
  • LoadLibraryA (Address: 0x180053088)
  • LoadResource (Address: 0x180053130)
  • LockResource (Address: 0x180053120)
  • MapViewOfFile (Address: 0x180053068)
  • OpenProcess (Address: 0x180053078)
  • OutputDebugStringA (Address: 0x180053008)
  • Process32FirstW (Address: 0x1800530b8)
  • Process32NextW (Address: 0x1800530b0)
  • QueryFullProcessImageNameA (Address: 0x180053118)
  • QueryPerformanceCounter (Address: 0x180053038)
  • QueryPerformanceFrequency (Address: 0x180053030)
  • ReadProcessMemory (Address: 0x180053098)
  • RtlCaptureContext (Address: 0x1800531c8)
  • RtlLookupFunctionEntry (Address: 0x1800531b8)
  • RtlVirtualUnwind (Address: 0x1800531b0)
  • SetUnhandledExceptionFilter (Address: 0x180053180)
  • SizeofResource (Address: 0x180053100)
  • Sleep (Address: 0x1800530c8)
  • TerminateProcess (Address: 0x1800531a0)
  • UnhandledExceptionFilter (Address: 0x1800531a8)
  • UnmapViewOfFile (Address: 0x180053050)
  • VirtualAlloc (Address: 0x180053048)
  • VirtualAllocEx (Address: 0x180053138)
  • VirtualFree (Address: 0x180053040)
  • VirtualFreeEx (Address: 0x180053140)
  • VirtualQueryEx (Address: 0x1800530f8)
  • WaitForSingleObject (Address: 0x180053160)
  • WideCharToMultiByte (Address: 0x1800530a0)
  • WriteProcessMemory (Address: 0x180053070)
MSVCP140.dll
  • ?_Addfac@_Locimp@locale@std@@AEAAXPEAVfacet@23@_K@Z (Address: 0x180053218)
  • ?_Decref@facet@locale@std@@UEAAPEAV_Facet_base@3@XZ (Address: 0x180053230)
  • ?_Getcvt@_Locinfo@std@@QEBA?AU_Cvtvec@@XZ (Address: 0x1800531d8)
  • ?_Getfalse@_Locinfo@std@@QEBAPEBDXZ (Address: 0x180053248)
  • ?_Getlconv@_Locinfo@std@@QEBAPEBUlconv@@XZ (Address: 0x180053250)
  • ?_Gettrue@_Locinfo@std@@QEBAPEBDXZ (Address: 0x180053240)
  • ?_Id_cnt@id@locale@std@@0HA (Address: 0x180053200)
  • ?_Incref@facet@locale@std@@UEAAXXZ (Address: 0x180053238)
  • ?_New_Locimp@_Locimp@locale@std@@CAPEAV123@AEBV123@@Z (Address: 0x1800531f0)
  • ?_Xbad_alloc@std@@YAXXZ (Address: 0x180053280)
  • ?_Xinvalid_argument@std@@YAXPEBD@Z (Address: 0x180053270)
  • ?_Xlength_error@std@@YAXPEBD@Z (Address: 0x180053278)
  • ?_Xout_of_range@std@@YAXPEBD@Z (Address: 0x180053268)
  • ??0_Locinfo@std@@QEAA@PEBD@Z (Address: 0x180053260)
  • ??0_Lockit@std@@QEAA@H@Z (Address: 0x1800531e8)
  • ??0facet@locale@std@@IEAA@_K@Z (Address: 0x180053228)
  • ??1_Locinfo@std@@QEAA@XZ (Address: 0x180053258)
  • ??1_Lockit@std@@QEAA@XZ (Address: 0x1800531e0)
  • ??1facet@locale@std@@MEAA@XZ (Address: 0x180053220)
  • ??4?$_Yarn@D@std@@QEAAAEAV01@PEBD@Z (Address: 0x180053210)
  • ?classic@locale@std@@SAAEBV12@XZ (Address: 0x1800531f8)
  • ?id@?$numpunct@D@std@@2V0locale@2@A (Address: 0x180053208)
USER32.dll
  • EnumWindows (Address: 0x1800532a0)
  • FindWindowExA (Address: 0x1800532b0)
  • GetClassNameA (Address: 0x180053298)
  • GetWindowTextA (Address: 0x1800532a8)
  • GetWindowThreadProcessId (Address: 0x180053290)
VCRUNTIME140_1.dll
  • __CxxFrameHandler4 (Address: 0x180053340)
VCRUNTIME140.dll
  • __C_specific_handler (Address: 0x180053320)
  • __current_exception (Address: 0x1800532d8)
  • __current_exception_context (Address: 0x1800532c8)
  • __std_exception_copy (Address: 0x1800532e0)
  • __std_exception_destroy (Address: 0x1800532c0)
  • __std_terminate (Address: 0x1800532d0)
  • __std_type_info_destroy_list (Address: 0x1800532e8)
  • _CxxThrowException (Address: 0x180053310)
  • _purecall (Address: 0x180053330)
  • memcmp (Address: 0x1800532f8)
  • memcpy (Address: 0x180053308)
  • memmove (Address: 0x180053300)
  • memset (Address: 0x1800532f0)
  • strstr (Address: 0x180053328)
  • wcsstr (Address: 0x180053318)