executor.dll

Description:

Authors:

Version:

Architecture: 32-bit

Operating System:

SHA256: eace3cd9bb3f7b2f617443d2b80ede46

File Size: 2.5 MB

Uploaded At: April 30, 2026, 6:16 p.m.

Views: 47

Security Warning

This file has been flagged as potentially dangerous.


Reason: Detected potentially dangerous functions used for process injection: OpenProcess, CreateRemoteThread, WriteProcessMemory, VirtualAllocEx

Exported Functions

  • dbkFCallWrapperAddr (Ordinal: 1, Address: 0x100640)
  • __dbk_fcall_wrapper (Ordinal: 2, Address: 0x10ccc)
  • TMethodImplementationIntercept (Ordinal: 3, Address: 0x65100)

Imported DLLs & Functions

advapi32.dll
  • RegCloseKey (Address: 0x504530)
  • RegOpenKeyExW (Address: 0x504534)
  • RegQueryValueExW (Address: 0x50452c)
kernel32.dll
  • CloseHandle (Address: 0x5042f0)
  • CompareStringW (Address: 0x504368)
  • CopyFileW (Address: 0x50436c)
  • CreateDirectoryW (Address: 0x504498)
  • CreateEventW (Address: 0x5044a8)
  • CreateFileMappingW (Address: 0x50447c)
  • CreateFileW (Address: 0x504464)
  • CreateProcessW (Address: 0x50434c)
  • CreateRemoteThread (Address: 0x504350)
  • CreateThread (Address: 0x504364)
  • DeleteCriticalSection (Address: 0x504484)
  • EnterCriticalSection (Address: 0x5043c0)
  • EnumCalendarInfoW (Address: 0x5044a0)
  • EnumSystemLocalesW (Address: 0x504334)
  • ExitProcess (Address: 0x50431c)
  • ExitThread (Address: 0x504480)
  • FindClose (Address: 0x504454)
  • FindFirstFileW (Address: 0x504430)
  • FindResourceW (Address: 0x504360)
  • FormatMessageW (Address: 0x504390)
  • FreeLibrary (Address: 0x504340)
  • FreeResource (Address: 0x504380)
  • GetACP (Address: 0x5042ec)
  • GetCommandLineW (Address: 0x5043fc)
  • GetCPInfo (Address: 0x504330)
  • GetCPInfoExW (Address: 0x504324)
  • GetCurrentProcess (Address: 0x5043ec)
  • GetCurrentThread (Address: 0x5043a0)
  • GetCurrentThreadId (Address: 0x5043ac)
  • GetDateFormatW (Address: 0x504488)
  • GetDiskFreeSpaceW (Address: 0x504428)
  • GetDriveTypeW (Address: 0x504384)
  • GetEnvironmentVariableW (Address: 0x50446c)
  • GetExitCodeThread (Address: 0x50439c)
  • GetFileAttributesW (Address: 0x5043e0)
  • GetFileSize (Address: 0x5043d8)
  • GetFullPathNameW (Address: 0x504318)
  • GetLastError (Address: 0x504354)
  • GetLocaleInfoW (Address: 0x504468)
  • GetLocalTime (Address: 0x504470)
  • GetLogicalDriveStringsW (Address: 0x504410)
  • GetModuleFileNameW (Address: 0x504358)
  • GetModuleHandleA (Address: 0x50441c)
  • GetModuleHandleW (Address: 0x50433c)
  • GetProcAddress (Address: 0x504404)
  • GetStartupInfoW (Address: 0x5043dc)
  • GetStdHandle (Address: 0x504338)
  • GetSystemDefaultUILanguage (Address: 0x50449c)
  • GetSystemInfo (Address: 0x5043f8)
  • GetThreadLocale (Address: 0x5044b0)
  • GetThreadPriority (Address: 0x5043e8)
  • GetTickCount (Address: 0x5043d0)
  • GetUserDefaultUILanguage (Address: 0x504434)
  • GetVersion (Address: 0x504388)
  • GetVersionExW (Address: 0x504414)
  • GetVolumeInformationW (Address: 0x50437c)
  • GetWindowsDirectoryW (Address: 0x504424)
  • HeapAlloc (Address: 0x504320)
  • HeapCreate (Address: 0x504420)
  • HeapDestroy (Address: 0x504344)
  • HeapFree (Address: 0x50444c)
  • InitializeCriticalSection (Address: 0x5043e4)
  • IsDebuggerPresent (Address: 0x504310)
  • IsValidLocale (Address: 0x504490)
  • LeaveCriticalSection (Address: 0x504400)
  • LoadLibraryA (Address: 0x504374)
  • LoadLibraryExW (Address: 0x5043a4)
  • LoadLibraryW (Address: 0x50445c)
  • LoadResource (Address: 0x5043c8)
  • LocalAlloc (Address: 0x5044a4)
  • LocalFree (Address: 0x5042f4)
  • LockResource (Address: 0x5043a8)
  • lstrcmpiA (Address: 0x5043d4)
  • lstrlenW (Address: 0x504440)
  • MapViewOfFile (Address: 0x504370)
  • MultiByteToWideChar (Address: 0x504458)
  • OpenProcess (Address: 0x504394)
  • QueryDosDeviceW (Address: 0x5042e8)
  • QueryPerformanceCounter (Address: 0x504444)
  • QueryPerformanceFrequency (Address: 0x50430c)
  • RaiseException (Address: 0x50438c)
  • ReadFile (Address: 0x504348)
  • ReadProcessMemory (Address: 0x504308)
  • ResetEvent (Address: 0x504378)
  • ResumeThread (Address: 0x504408)
  • RtlUnwind (Address: 0x50432c)
  • SetEndOfFile (Address: 0x504448)
  • SetEvent (Address: 0x504460)
  • SetFileAttributesW (Address: 0x5042e4)
  • SetFilePointer (Address: 0x5043c4)
  • SetLastError (Address: 0x50435c)
  • SetThreadLocale (Address: 0x5044ac)
  • SetThreadPriority (Address: 0x5043f0)
  • SizeofResource (Address: 0x5042fc)
  • Sleep (Address: 0x5043bc)
  • SuspendThread (Address: 0x5043cc)
  • SwitchToThread (Address: 0x504398)
  • TlsAlloc (Address: 0x504304)
  • TlsFree (Address: 0x504438)
  • TlsGetValue (Address: 0x50448c)
  • TlsSetValue (Address: 0x504494)
  • UnhandledExceptionFilter (Address: 0x5043b0)
  • UnmapViewOfFile (Address: 0x50443c)
  • VerifyVersionInfoW (Address: 0x504418)
  • VerSetConditionMask (Address: 0x50442c)
  • VirtualAlloc (Address: 0x5043f4)
  • VirtualAllocEx (Address: 0x50440c)
  • VirtualFree (Address: 0x504314)
  • VirtualProtect (Address: 0x504300)
  • VirtualProtectEx (Address: 0x5042f8)
  • VirtualQuery (Address: 0x5043b4)
  • VirtualQueryEx (Address: 0x5043b8)
  • WaitForSingleObject (Address: 0x504474)
  • WideCharToMultiByte (Address: 0x504450)
  • WriteFile (Address: 0x504478)
  • WriteProcessMemory (Address: 0x504328)
netapi32.dll
  • NetApiBufferFree (Address: 0x504524)
  • NetWkstaGetInfo (Address: 0x504520)
oleaut32.dll
  • SafeArrayCreate (Address: 0x504518)
  • SafeArrayGetLBound (Address: 0x5044fc)
  • SafeArrayGetUBound (Address: 0x504500)
  • SafeArrayPtrOfIndex (Address: 0x5044f4)
  • SysAllocStringLen (Address: 0x5044f0)
  • SysFreeString (Address: 0x50450c)
  • SysReAllocStringLen (Address: 0x504510)
  • VariantChangeType (Address: 0x504514)
  • VariantClear (Address: 0x504508)
  • VariantCopy (Address: 0x5044f8)
  • VariantInit (Address: 0x504504)
user32.dll
  • CharLowerBuffW (Address: 0x5044d4)
  • CharNextW (Address: 0x5044cc)
  • CharUpperBuffW (Address: 0x5044c8)
  • CharUpperW (Address: 0x5044dc)
  • GetSystemMetrics (Address: 0x5044e4)
  • LoadStringW (Address: 0x5044d8)
  • MessageBoxW (Address: 0x5044e8)
  • MsgWaitForMultipleObjects (Address: 0x5044d0)
  • PeekMessageW (Address: 0x5044e0)
version.dll
  • GetFileVersionInfoSizeW (Address: 0x5044b8)
  • GetFileVersionInfoW (Address: 0x5044c0)
  • VerQueryValueW (Address: 0x5044bc)