executor.dll
Description:
Authors:
Version:
Architecture: 32-bit
Operating System:
SHA256: eace3cd9bb3f7b2f617443d2b80ede46
File Size: 2.5 MB
Uploaded At: April 30, 2026, 6:16 p.m.
Views: 47
Security Warning
This file has been flagged as potentially dangerous.
Reason: Detected potentially dangerous functions used for process injection: OpenProcess, CreateRemoteThread, WriteProcessMemory, VirtualAllocEx
Exported Functions
- dbkFCallWrapperAddr (Ordinal: 1, Address: 0x100640)
- __dbk_fcall_wrapper (Ordinal: 2, Address: 0x10ccc)
- TMethodImplementationIntercept (Ordinal: 3, Address: 0x65100)
Imported DLLs & Functions
advapi32.dll
- RegCloseKey (Address: 0x504530)
- RegOpenKeyExW (Address: 0x504534)
- RegQueryValueExW (Address: 0x50452c)
kernel32.dll
- CloseHandle (Address: 0x5042f0)
- CompareStringW (Address: 0x504368)
- CopyFileW (Address: 0x50436c)
- CreateDirectoryW (Address: 0x504498)
- CreateEventW (Address: 0x5044a8)
- CreateFileMappingW (Address: 0x50447c)
- CreateFileW (Address: 0x504464)
- CreateProcessW (Address: 0x50434c)
- CreateRemoteThread (Address: 0x504350)
- CreateThread (Address: 0x504364)
- DeleteCriticalSection (Address: 0x504484)
- EnterCriticalSection (Address: 0x5043c0)
- EnumCalendarInfoW (Address: 0x5044a0)
- EnumSystemLocalesW (Address: 0x504334)
- ExitProcess (Address: 0x50431c)
- ExitThread (Address: 0x504480)
- FindClose (Address: 0x504454)
- FindFirstFileW (Address: 0x504430)
- FindResourceW (Address: 0x504360)
- FormatMessageW (Address: 0x504390)
- FreeLibrary (Address: 0x504340)
- FreeResource (Address: 0x504380)
- GetACP (Address: 0x5042ec)
- GetCommandLineW (Address: 0x5043fc)
- GetCPInfo (Address: 0x504330)
- GetCPInfoExW (Address: 0x504324)
- GetCurrentProcess (Address: 0x5043ec)
- GetCurrentThread (Address: 0x5043a0)
- GetCurrentThreadId (Address: 0x5043ac)
- GetDateFormatW (Address: 0x504488)
- GetDiskFreeSpaceW (Address: 0x504428)
- GetDriveTypeW (Address: 0x504384)
- GetEnvironmentVariableW (Address: 0x50446c)
- GetExitCodeThread (Address: 0x50439c)
- GetFileAttributesW (Address: 0x5043e0)
- GetFileSize (Address: 0x5043d8)
- GetFullPathNameW (Address: 0x504318)
- GetLastError (Address: 0x504354)
- GetLocaleInfoW (Address: 0x504468)
- GetLocalTime (Address: 0x504470)
- GetLogicalDriveStringsW (Address: 0x504410)
- GetModuleFileNameW (Address: 0x504358)
- GetModuleHandleA (Address: 0x50441c)
- GetModuleHandleW (Address: 0x50433c)
- GetProcAddress (Address: 0x504404)
- GetStartupInfoW (Address: 0x5043dc)
- GetStdHandle (Address: 0x504338)
- GetSystemDefaultUILanguage (Address: 0x50449c)
- GetSystemInfo (Address: 0x5043f8)
- GetThreadLocale (Address: 0x5044b0)
- GetThreadPriority (Address: 0x5043e8)
- GetTickCount (Address: 0x5043d0)
- GetUserDefaultUILanguage (Address: 0x504434)
- GetVersion (Address: 0x504388)
- GetVersionExW (Address: 0x504414)
- GetVolumeInformationW (Address: 0x50437c)
- GetWindowsDirectoryW (Address: 0x504424)
- HeapAlloc (Address: 0x504320)
- HeapCreate (Address: 0x504420)
- HeapDestroy (Address: 0x504344)
- HeapFree (Address: 0x50444c)
- InitializeCriticalSection (Address: 0x5043e4)
- IsDebuggerPresent (Address: 0x504310)
- IsValidLocale (Address: 0x504490)
- LeaveCriticalSection (Address: 0x504400)
- LoadLibraryA (Address: 0x504374)
- LoadLibraryExW (Address: 0x5043a4)
- LoadLibraryW (Address: 0x50445c)
- LoadResource (Address: 0x5043c8)
- LocalAlloc (Address: 0x5044a4)
- LocalFree (Address: 0x5042f4)
- LockResource (Address: 0x5043a8)
- lstrcmpiA (Address: 0x5043d4)
- lstrlenW (Address: 0x504440)
- MapViewOfFile (Address: 0x504370)
- MultiByteToWideChar (Address: 0x504458)
- OpenProcess (Address: 0x504394)
- QueryDosDeviceW (Address: 0x5042e8)
- QueryPerformanceCounter (Address: 0x504444)
- QueryPerformanceFrequency (Address: 0x50430c)
- RaiseException (Address: 0x50438c)
- ReadFile (Address: 0x504348)
- ReadProcessMemory (Address: 0x504308)
- ResetEvent (Address: 0x504378)
- ResumeThread (Address: 0x504408)
- RtlUnwind (Address: 0x50432c)
- SetEndOfFile (Address: 0x504448)
- SetEvent (Address: 0x504460)
- SetFileAttributesW (Address: 0x5042e4)
- SetFilePointer (Address: 0x5043c4)
- SetLastError (Address: 0x50435c)
- SetThreadLocale (Address: 0x5044ac)
- SetThreadPriority (Address: 0x5043f0)
- SizeofResource (Address: 0x5042fc)
- Sleep (Address: 0x5043bc)
- SuspendThread (Address: 0x5043cc)
- SwitchToThread (Address: 0x504398)
- TlsAlloc (Address: 0x504304)
- TlsFree (Address: 0x504438)
- TlsGetValue (Address: 0x50448c)
- TlsSetValue (Address: 0x504494)
- UnhandledExceptionFilter (Address: 0x5043b0)
- UnmapViewOfFile (Address: 0x50443c)
- VerifyVersionInfoW (Address: 0x504418)
- VerSetConditionMask (Address: 0x50442c)
- VirtualAlloc (Address: 0x5043f4)
- VirtualAllocEx (Address: 0x50440c)
- VirtualFree (Address: 0x504314)
- VirtualProtect (Address: 0x504300)
- VirtualProtectEx (Address: 0x5042f8)
- VirtualQuery (Address: 0x5043b4)
- VirtualQueryEx (Address: 0x5043b8)
- WaitForSingleObject (Address: 0x504474)
- WideCharToMultiByte (Address: 0x504450)
- WriteFile (Address: 0x504478)
- WriteProcessMemory (Address: 0x504328)
netapi32.dll
- NetApiBufferFree (Address: 0x504524)
- NetWkstaGetInfo (Address: 0x504520)
oleaut32.dll
- SafeArrayCreate (Address: 0x504518)
- SafeArrayGetLBound (Address: 0x5044fc)
- SafeArrayGetUBound (Address: 0x504500)
- SafeArrayPtrOfIndex (Address: 0x5044f4)
- SysAllocStringLen (Address: 0x5044f0)
- SysFreeString (Address: 0x50450c)
- SysReAllocStringLen (Address: 0x504510)
- VariantChangeType (Address: 0x504514)
- VariantClear (Address: 0x504508)
- VariantCopy (Address: 0x5044f8)
- VariantInit (Address: 0x504504)
user32.dll
- CharLowerBuffW (Address: 0x5044d4)
- CharNextW (Address: 0x5044cc)
- CharUpperBuffW (Address: 0x5044c8)
- CharUpperW (Address: 0x5044dc)
- GetSystemMetrics (Address: 0x5044e4)
- LoadStringW (Address: 0x5044d8)
- MessageBoxW (Address: 0x5044e8)
- MsgWaitForMultipleObjects (Address: 0x5044d0)
- PeekMessageW (Address: 0x5044e0)
version.dll
- GetFileVersionInfoSizeW (Address: 0x5044b8)
- GetFileVersionInfoW (Address: 0x5044c0)
- VerQueryValueW (Address: 0x5044bc)