schannel.dll
Description: TLS / SSL Security Provider
Authors: © Microsoft Corporation. All rights reserved.
Version: 10.0.19041.6328
Architecture: 32-bit
Operating System: Windows NT
SHA256: 28993ea9f311ed3b34f0c903b6ac5ad2
File Size: 478.0 KB
Uploaded At: Dec. 1, 2025, 8:03 a.m.
Views: 12
Security Warning
This file has been flagged as potentially dangerous.
Reason: Detected potentially dangerous functions used for process injection: OpenProcess
Exported Functions
- SpLsaModeInitialize (Ordinal: 1, Address: 0x25f20)
- AcceptSecurityContext (Ordinal: 2, Address: 0x6db07)
- AcquireCredentialsHandleA (Ordinal: 3, Address: 0x6db3f)
- AcquireCredentialsHandleW (Ordinal: 4, Address: 0x6db7b)
- ApplyControlToken (Ordinal: 5, Address: 0x6dbaf)
- CompleteAuthToken (Ordinal: 6, Address: 0x6dbdb)
- DeleteSecurityContext (Ordinal: 7, Address: 0x6dc0b)
- EnumerateSecurityPackagesA (Ordinal: 8, Address: 0x6dc44)
- EnumerateSecurityPackagesW (Ordinal: 9, Address: 0x6dc82)
- FreeContextBuffer (Ordinal: 10, Address: 0x6dcb7)
- FreeCredentialsHandle (Ordinal: 11, Address: 0x6dce7)
- ImpersonateSecurityContext (Ordinal: 12, Address: 0x6dd20)
- InitSecurityInterfaceA (Ordinal: 13, Address: 0x6dd5a)
- InitSecurityInterfaceW (Ordinal: 14, Address: 0x6dd90)
- InitializeSecurityContextA (Ordinal: 15, Address: 0x6ddca)
- InitializeSecurityContextW (Ordinal: 16, Address: 0x6de08)
- MakeSignature (Ordinal: 17, Address: 0x6de39)
- QueryContextAttributesA (Ordinal: 18, Address: 0x6de67)
- QueryContextAttributesW (Ordinal: 19, Address: 0x6de9f)
- QuerySecurityPackageInfoA (Ordinal: 20, Address: 0x6ded9)
- QuerySecurityPackageInfoW (Ordinal: 21, Address: 0x6df15)
- RevertSecurityContext (Ordinal: 22, Address: 0x6df4d)
- SealMessage (Ordinal: 23, Address: 0x6df77)
- SpUserModeInitialize (Ordinal: 24, Address: 0x91c0)
- SslCrackCertificate (Ordinal: 25, Address: 0x3e520)
- SslEmptyCacheA (Ordinal: 26, Address: 0x42c40)
- SslEmptyCacheW (Ordinal: 27, Address: 0x42cb0)
- SslFreeCertificate (Ordinal: 28, Address: 0x3e760)
- SslFreeCustomBuffer (Ordinal: 29, Address: 0x3d750)
- SslGenerateRandomBits (Ordinal: 30, Address: 0x3e790)
- SslGetExtensions (Ordinal: 31, Address: 0x43f30)
- SslGetMaximumKeySize (Ordinal: 32, Address: 0x3e7b0)
- SslGetServerIdentity (Ordinal: 33, Address: 0x44330)
- SslLoadCertificate (Ordinal: 34, Address: 0x1c0c0)
- UnsealMessage (Ordinal: 35, Address: 0x6e06b)
- VerifySignature (Ordinal: 36, Address: 0x6e091)
Imported DLLs & Functions
api-ms-win-core-apiquery-l1-1-0.dll
- ApiSetQueryApiSetPresence (Address: 0x58871000)
api-ms-win-core-debug-l1-1-0.dll
- DebugBreak (Address: 0x58871008)
- IsDebuggerPresent (Address: 0x5887100c)
- OutputDebugStringW (Address: 0x58871010)
api-ms-win-core-delayload-l1-1-0.dll
- DelayLoadFailureHook (Address: 0x58871018)
api-ms-win-core-delayload-l1-1-1.dll
- ResolveDelayLoadedAPI (Address: 0x58871020)
api-ms-win-core-errorhandling-l1-1-0.dll
- GetLastError (Address: 0x5887102c)
- SetLastError (Address: 0x58871028)
- SetUnhandledExceptionFilter (Address: 0x58871030)
- UnhandledExceptionFilter (Address: 0x58871034)
api-ms-win-core-file-l1-1-0.dll
- CompareFileTime (Address: 0x58871040)
- CreateDirectoryW (Address: 0x5887103c)
api-ms-win-core-file-l2-1-0.dll
- MoveFileExW (Address: 0x58871048)
api-ms-win-core-handle-l1-1-0.dll
- CloseHandle (Address: 0x58871050)
api-ms-win-core-heap-l1-1-0.dll
- GetProcessHeap (Address: 0x5887105c)
- HeapAlloc (Address: 0x58871058)
- HeapFree (Address: 0x58871060)
api-ms-win-core-heap-l2-1-0.dll
- LocalAlloc (Address: 0x58871070)
- LocalFree (Address: 0x5887106c)
- LocalReAlloc (Address: 0x58871068)
api-ms-win-core-interlocked-l1-1-0.dll
- InitializeSListHead (Address: 0x5887107c)
- InterlockedFlushSList (Address: 0x58871080)
- InterlockedPopEntrySList (Address: 0x58871084)
- InterlockedPushEntrySList (Address: 0x58871078)
api-ms-win-core-libraryloader-l1-2-0.dll
- DisableThreadLibraryCalls (Address: 0x58871090)
- FreeLibrary (Address: 0x588710a4)
- GetModuleFileNameA (Address: 0x58871098)
- GetModuleFileNameW (Address: 0x588710a0)
- GetModuleHandleExW (Address: 0x58871094)
- GetModuleHandleW (Address: 0x588710a8)
- GetProcAddress (Address: 0x5887108c)
- LoadLibraryExW (Address: 0x5887109c)
api-ms-win-core-localization-l1-2-0.dll
- FormatMessageW (Address: 0x588710b0)
api-ms-win-core-memory-l1-1-0.dll
- CreateFileMappingW (Address: 0x588710d4)
- MapViewOfFileEx (Address: 0x588710c8)
- OpenFileMappingW (Address: 0x588710b8)
- UnmapViewOfFile (Address: 0x588710c4)
- VirtualAlloc (Address: 0x588710cc)
- VirtualFree (Address: 0x588710c0)
- VirtualProtect (Address: 0x588710d0)
- VirtualQuery (Address: 0x588710bc)
api-ms-win-core-processenvironment-l1-1-0.dll
- ExpandEnvironmentStringsW (Address: 0x588710e4)
- GetCurrentDirectoryW (Address: 0x588710dc)
- SetCurrentDirectoryW (Address: 0x588710e0)
api-ms-win-core-processthreads-l1-1-0.dll
- GetCurrentProcess (Address: 0x588710fc)
- GetCurrentProcessId (Address: 0x588710ec)
- GetCurrentThread (Address: 0x588710f8)
- GetCurrentThreadId (Address: 0x588710f0)
- OpenThreadToken (Address: 0x58871104)
- SetThreadStackGuarantee (Address: 0x588710f4)
- TerminateProcess (Address: 0x58871100)
api-ms-win-core-processthreads-l1-1-1.dll
- IsProcessorFeaturePresent (Address: 0x58871110)
- OpenProcess (Address: 0x5887110c)
api-ms-win-core-profile-l1-1-0.dll
- QueryPerformanceCounter (Address: 0x58871118)
- QueryPerformanceFrequency (Address: 0x5887111c)
api-ms-win-core-psapi-l1-1-0.dll
- QueryFullProcessImageNameW (Address: 0x58871124)
api-ms-win-core-registry-l1-1-0.dll
- RegCloseKey (Address: 0x58871130)
- RegCreateKeyExW (Address: 0x58871134)
- RegFlushKey (Address: 0x5887112c)
- RegNotifyChangeKeyValue (Address: 0x5887113c)
- RegOpenKeyExA (Address: 0x58871140)
- RegOpenKeyExW (Address: 0x58871138)
- RegQueryValueExW (Address: 0x58871144)
- RegSetValueExW (Address: 0x58871148)
api-ms-win-core-rtlsupport-l1-2-0.dll
- RtlCompareMemory (Address: 0x58871150)
api-ms-win-core-string-l1-1-0.dll
- MultiByteToWideChar (Address: 0x58871158)
- WideCharToMultiByte (Address: 0x5887115c)
api-ms-win-core-string-obsolete-l1-1-0.dll
- lstrlenW (Address: 0x58871164)
api-ms-win-core-synch-l1-1-0.dll
- AcquireSRWLockExclusive (Address: 0x588711b4)
- AcquireSRWLockShared (Address: 0x5887119c)
- CreateEventA (Address: 0x588711ac)
- CreateEventW (Address: 0x5887117c)
- CreateMutexExW (Address: 0x58871194)
- CreateSemaphoreExW (Address: 0x588711c4)
- DeleteCriticalSection (Address: 0x58871188)
- EnterCriticalSection (Address: 0x58871180)
- InitializeCriticalSection (Address: 0x588711c0)
- InitializeCriticalSectionAndSpinCount (Address: 0x58871184)
- InitializeCriticalSectionEx (Address: 0x588711b8)
- InitializeSRWLock (Address: 0x588711bc)
- LeaveCriticalSection (Address: 0x58871198)
- OpenSemaphoreW (Address: 0x58871190)
- ReleaseMutex (Address: 0x58871178)
- ReleaseSemaphore (Address: 0x58871174)
- ReleaseSRWLockExclusive (Address: 0x588711a0)
- ReleaseSRWLockShared (Address: 0x5887116c)
- ResetEvent (Address: 0x588711a4)
- SetEvent (Address: 0x58871170)
- TryAcquireSRWLockExclusive (Address: 0x588711a8)
- WaitForSingleObject (Address: 0x5887118c)
- WaitForSingleObjectEx (Address: 0x588711b0)
api-ms-win-core-synch-l1-2-0.dll
- Sleep (Address: 0x588711cc)
api-ms-win-core-sysinfo-l1-1-0.dll
- GetComputerNameExW (Address: 0x588711e0)
- GetSystemInfo (Address: 0x588711ec)
- GetSystemTimeAsFileTime (Address: 0x588711d8)
- GetTickCount (Address: 0x588711e4)
- GetTickCount64 (Address: 0x588711e8)
- GetVersionExW (Address: 0x588711dc)
- GetWindowsDirectoryW (Address: 0x588711d4)
api-ms-win-core-threadpool-l1-2-0.dll
- CloseThreadpoolTimer (Address: 0x588711f8)
- CreateThreadpoolTimer (Address: 0x588711f4)
- SetThreadpoolTimer (Address: 0x588711fc)
- WaitForThreadpoolTimerCallbacks (Address: 0x58871200)
api-ms-win-core-threadpool-legacy-l1-1-0.dll
- ChangeTimerQueueTimer (Address: 0x58871214)
- CreateTimerQueueTimer (Address: 0x58871208)
- DeleteTimerQueueTimer (Address: 0x5887120c)
- UnregisterWaitEx (Address: 0x58871210)
api-ms-win-core-threadpool-private-l1-1-0.dll
- RegisterWaitForSingleObjectEx (Address: 0x5887121c)
api-ms-win-core-version-l1-1-0.dll
- GetFileVersionInfoExW (Address: 0x58871228)
- GetFileVersionInfoSizeExW (Address: 0x5887122c)
- VerQueryValueW (Address: 0x58871224)
api-ms-win-core-wow64-l1-1-1.dll
- GetSystemWow64DirectoryW (Address: 0x58871234)
api-ms-win-crt-private-l1-1-0.dll
- __CxxFrameHandler3 (Address: 0x588712ac)
- _except_handler4_common (Address: 0x58871284)
- _o___std_type_info_destroy_list (Address: 0x5887129c)
- _o___stdio_common_vsnwprintf_s (Address: 0x58871298)
- _o___stdio_common_vswprintf (Address: 0x58871294)
- _o__callnewh (Address: 0x58871290)
- _o__cexit (Address: 0x5887128c)
- _o__configure_narrow_argv (Address: 0x58871288)
- _o__crt_atexit (Address: 0x5887123c)
- _o__execute_onexit_table (Address: 0x58871240)
- _o__initialize_narrow_environment (Address: 0x58871244)
- _o__initialize_onexit_table (Address: 0x58871248)
- _o__purecall (Address: 0x5887124c)
- _o__register_onexit_function (Address: 0x58871250)
- _o__seh_filter_dll (Address: 0x58871254)
- _o__stricmp (Address: 0x58871258)
- _o__wcsicmp (Address: 0x58871260)
- _o__wcsnicmp (Address: 0x58871264)
- _o__wsplitpath_s (Address: 0x58871268)
- _o_free (Address: 0x5887126c)
- _o_malloc (Address: 0x58871270)
- _o_memcpy_s (Address: 0x58871274)
- _o_wcscat_s (Address: 0x58871278)
- _o_wcscpy_s (Address: 0x5887127c)
- _o_wcsncpy_s (Address: 0x58871280)
- memcmp (Address: 0x588712a4)
- memcpy (Address: 0x588712a8)
- memmove (Address: 0x5887125c)
- wcschr (Address: 0x588712a0)
- wcsrchr (Address: 0x588712b0)
- wcsstr (Address: 0x588712b4)
api-ms-win-crt-runtime-l1-1-0.dll
- _initterm (Address: 0x588712c0)
- _initterm_e (Address: 0x588712bc)
api-ms-win-crt-string-l1-1-0.dll
- memmove_s (Address: 0x588712d4)
- memset (Address: 0x588712c8)
- wcsncmp (Address: 0x588712d0)
- wcsnlen (Address: 0x588712cc)
api-ms-win-crt-time-l1-1-0.dll
- _time32 (Address: 0x588712dc)
api-ms-win-eventing-classicprovider-l1-1-0.dll
- TraceMessage (Address: 0x588712e4)
api-ms-win-eventing-provider-l1-1-0.dll
- EventRegister (Address: 0x588712f0)
- EventSetInformation (Address: 0x588712f4)
- EventUnregister (Address: 0x588712f8)
- EventWriteTransfer (Address: 0x588712ec)
api-ms-win-security-base-l1-1-0.dll
- AllocateLocallyUniqueId (Address: 0x58871304)
- CreateWellKnownSid (Address: 0x5887130c)
- EqualSid (Address: 0x58871310)
- GetLengthSid (Address: 0x58871308)
- GetTokenInformation (Address: 0x58871300)
- RevertToSelf (Address: 0x58871314)
ntdll.dll
- EtwEventRegister (Address: 0x58871394)
- EtwEventUnregister (Address: 0x58871390)
- EtwEventWrite (Address: 0x5887138c)
- EtwEventWriteTransfer (Address: 0x588713b8)
- EtwGetTraceEnableFlags (Address: 0x58871354)
- EtwGetTraceEnableLevel (Address: 0x58871358)
- EtwGetTraceLoggerHandle (Address: 0x5887135c)
- EtwRegisterTraceGuidsW (Address: 0x588713f8)
- EtwTraceMessage (Address: 0x588713bc)
- EtwUnregisterTraceGuids (Address: 0x588713f4)
- NtAllocateVirtualMemory (Address: 0x588713dc)
- NtClose (Address: 0x588713a4)
- NtCreateEvent (Address: 0x58871334)
- NtDuplicateObject (Address: 0x588713a8)
- NtEnumerateKey (Address: 0x588713c0)
- NtFreeVirtualMemory (Address: 0x588713e0)
- NtOpenEvent (Address: 0x58871330)
- NtOpenKey (Address: 0x5887131c)
- NtQuerySystemInformation (Address: 0x5887132c)
- NtQuerySystemTime (Address: 0x58871328)
- NtQueryValueKey (Address: 0x58871324)
- NtSetEvent (Address: 0x58871338)
- NtSetInformationThread (Address: 0x588713d8)
- NtWaitForSingleObject (Address: 0x58871340)
- RtlAcquireResourceExclusive (Address: 0x58871388)
- RtlAcquireResourceShared (Address: 0x5887139c)
- RtlAllocateHeap (Address: 0x58871360)
- RtlAnsiStringToUnicodeString (Address: 0x588713b4)
- RtlAppendUnicodeToString (Address: 0x588713d4)
- RtlCompareUnicodeString (Address: 0x588713c4)
- RtlConvertSharedToExclusive (Address: 0x588713c8)
- RtlCopySid (Address: 0x58871374)
- RtlDeleteCriticalSection (Address: 0x588713f0)
- RtlDeleteResource (Address: 0x588713e4)
- RtlDeregisterWait (Address: 0x58871408)
- RtlDuplicateUnicodeString (Address: 0x5887133c)
- RtlEnterCriticalSection (Address: 0x588713ec)
- RtlEqualUnicodeString (Address: 0x5887136c)
- RtlFreeHeap (Address: 0x58871320)
- RtlFreeUnicodeString (Address: 0x58871350)
- RtlGetNtProductType (Address: 0x58871370)
- RtlImageNtHeader (Address: 0x5887134c)
- RtlInitAnsiString (Address: 0x5887140c)
- RtlInitializeCriticalSection (Address: 0x58871364)
- RtlInitializeResource (Address: 0x58871368)
- RtlInitializeSid (Address: 0x58871380)
- RtlInitString (Address: 0x58871384)
- RtlInitUnicodeString (Address: 0x588713b0)
- RtlIpv4StringToAddressExW (Address: 0x588713d0)
- RtlIpv6StringToAddressExW (Address: 0x588713cc)
- RtlLeaveCriticalSection (Address: 0x588713e8)
- RtlLengthSid (Address: 0x58871378)
- RtlNtStatusToDosError (Address: 0x588713ac)
- RtlNtStatusToDosErrorNoTeb (Address: 0x588713a0)
- RtlPublishWnfStateData (Address: 0x588713fc)
- RtlRegisterWait (Address: 0x58871404)
- RtlReleaseResource (Address: 0x58871398)
- RtlSubAuthorityCountSid (Address: 0x58871348)
- RtlSubAuthoritySid (Address: 0x5887137c)
- RtlValidSid (Address: 0x58871344)
- WinSqmSetDWORD (Address: 0x58871400)