launcher.dll

Description:

Authors:

Version:

Architecture: 64-bit

Operating System:

SHA256: 05c5f03ac600f4dfe5999c93c19dbb4c

File Size: 14.6 MB

Uploaded At: May 24, 2026, 12:54 a.m.

Views: 39

Security Warning

This file has been flagged as potentially dangerous.


Reason: Detected potentially dangerous functions used for process injection: OpenProcess, CreateRemoteThread, WriteProcessMemory, VirtualAllocEx

Exported Functions

  • Init (Ordinal: 1, Address: 0x22ff20)
  • get_hostfxr_path (Ordinal: 2, Address: 0x63a080)

Imported DLLs & Functions

ADVAPI32.dll
  • AdjustTokenPrivileges (Address: 0x180875008)
  • CryptAcquireContextA (Address: 0x180875118)
  • CryptAcquireContextW (Address: 0x180875060)
  • CryptCreateHash (Address: 0x1808750f8)
  • CryptDecrypt (Address: 0x1808750a8)
  • CryptDestroyHash (Address: 0x1808750e8)
  • CryptDestroyKey (Address: 0x1808750e0)
  • CryptEncrypt (Address: 0x1808750d0)
  • CryptEnumProvidersW (Address: 0x1808750b8)
  • CryptExportKey (Address: 0x1808750a0)
  • CryptGenRandom (Address: 0x180875108)
  • CryptGetHashParam (Address: 0x180875100)
  • CryptGetProvParam (Address: 0x180875070)
  • CryptGetUserKey (Address: 0x180875078)
  • CryptHashData (Address: 0x1808750f0)
  • CryptImportKey (Address: 0x1808750d8)
  • CryptReleaseContext (Address: 0x180875110)
  • CryptSetHashParam (Address: 0x180875068)
  • CryptSignHashW (Address: 0x1808750b0)
  • DeregisterEventSource (Address: 0x180875048)
  • LookupPrivilegeValueW (Address: 0x180875010)
  • OpenProcessToken (Address: 0x180875000)
  • RegCloseKey (Address: 0x180875018)
  • RegCreateKeyA (Address: 0x180875020)
  • RegDeleteKeyA (Address: 0x180875028)
  • RegEnumKeyExA (Address: 0x180875088)
  • RegGetValueA (Address: 0x1808750c8)
  • RegGetValueW (Address: 0x180875040)
  • RegisterEventSourceW (Address: 0x180875050)
  • RegOpenKeyA (Address: 0x180875030)
  • RegOpenKeyExA (Address: 0x180875098)
  • RegOpenKeyExW (Address: 0x1808750c0)
  • RegQueryValueExA (Address: 0x180875090)
  • RegSetValueExA (Address: 0x180875038)
  • ReportEventW (Address: 0x180875058)
  • SystemFunction036 (Address: 0x180875080)
bcrypt.dll
  • BCryptCloseAlgorithmProvider (Address: 0x180875c48)
  • BCryptCreateHash (Address: 0x180875c28)
  • BCryptDecrypt (Address: 0x180875c68)
  • BCryptDestroyHash (Address: 0x180875c38)
  • BCryptDestroyKey (Address: 0x180875c30)
  • BCryptFinishHash (Address: 0x180875c18)
  • BCryptGenerateSymmetricKey (Address: 0x180875c40)
  • BCryptGenRandom (Address: 0x180875c70)
  • BCryptGetProperty (Address: 0x180875c58)
  • BCryptHashData (Address: 0x180875c20)
  • BCryptOpenAlgorithmProvider (Address: 0x180875c60)
  • BCryptSetProperty (Address: 0x180875c50)
CRYPT32.dll
  • CertCloseStore (Address: 0x180875140)
  • CertDuplicateCertificateContext (Address: 0x180875138)
  • CertEnumCertificatesInStore (Address: 0x180875158)
  • CertFindCertificateInStore (Address: 0x180875148)
  • CertFreeCertificateContext (Address: 0x180875130)
  • CertGetCertificateContextProperty (Address: 0x180875128)
  • CertOpenStore (Address: 0x180875150)
d3d11.dll
  • D3D11CreateDevice (Address: 0x180875c88)
  • D3D11CreateDeviceAndSwapChain (Address: 0x180875c80)
D3DCOMPILER_47.dll
  • D3DCompile (Address: 0x180875168)
d3dx11_43.dll
  • D3DX11CreateShaderResourceViewFromMemory (Address: 0x180875c98)
dbghelp.dll
  • ImageNtHeader (Address: 0x180875cd0)
  • SymCleanup (Address: 0x180875cb0)
  • SymFromAddr (Address: 0x180875cd8)
  • SymGetTypeFromNameW (Address: 0x180875cc8)
  • SymGetTypeInfo (Address: 0x180875cc0)
  • SymInitialize (Address: 0x180875ca8)
  • SymLoadModuleEx (Address: 0x180875cb8)
dwmapi.dll
  • DwmExtendFrameIntoClientArea (Address: 0x180875ce8)
GDI32.dll
  • BitBlt (Address: 0x180875178)
  • CreateCompatibleBitmap (Address: 0x180875180)
  • CreateCompatibleDC (Address: 0x180875188)
  • CreateRoundRectRgn (Address: 0x1808751b8)
  • CreateSolidBrush (Address: 0x1808751b0)
  • DeleteDC (Address: 0x180875190)
  • DeleteObject (Address: 0x1808751c0)
  • GetDIBits (Address: 0x180875198)
  • GetObjectA (Address: 0x1808751a8)
  • SelectObject (Address: 0x1808751a0)
IMM32.dll
  • ImmGetContext (Address: 0x1808751e8)
  • ImmReleaseContext (Address: 0x1808751e0)
  • ImmSetCandidateWindow (Address: 0x1808751d8)
  • ImmSetCompositionWindow (Address: 0x1808751d0)
IPHLPAPI.DLL
  • FreeMibTable (Address: 0x180875208)
  • GetAdaptersAddresses (Address: 0x180875210)
  • GetBestRoute2 (Address: 0x1808751f8)
  • GetUnicastIpAddressTable (Address: 0x180875200)
KERNEL32.dll
  • AcquireSRWLockExclusive (Address: 0x180875798)
  • AcquireSRWLockShared (Address: 0x180875748)
  • AreFileApisANSI (Address: 0x180875570)
  • CloseHandle (Address: 0x180875240)
  • CloseThreadpoolWork (Address: 0x180875520)
  • CompareStringEx (Address: 0x1808754c8)
  • CompareStringW (Address: 0x1808757c0)
  • ConvertFiberToThread (Address: 0x1808756b0)
  • ConvertThreadToFiberEx (Address: 0x1808756a8)
  • CreateDirectoryA (Address: 0x180875338)
  • CreateEventA (Address: 0x1808756d0)
  • CreateEventW (Address: 0x1808754a0)
  • CreateFiberEx (Address: 0x1808756d8)
  • CreateFileW (Address: 0x180875658)
  • CreateIoCompletionPort (Address: 0x180875768)
  • CreateMutexA (Address: 0x180875418)
  • CreatePipe (Address: 0x1808753c0)
  • CreateProcessA (Address: 0x180875368)
  • CreateProcessW (Address: 0x1808753d8)
  • CreateRemoteThread (Address: 0x180875360)
  • CreateThread (Address: 0x1808752d8)
  • CreateThreadpoolWork (Address: 0x180875530)
  • CreateToolhelp32Snapshot (Address: 0x180875278)
  • DecodePointer (Address: 0x1808753b0)
  • DeleteCriticalSection (Address: 0x1808753d0)
  • DeleteFiber (Address: 0x1808756e0)
  • EncodePointer (Address: 0x180875508)
  • EnterCriticalSection (Address: 0x180875430)
  • EnumSystemLocalesW (Address: 0x180875818)
  • ExitProcess (Address: 0x180875708)
  • ExitThread (Address: 0x180875598)
  • ExpandEnvironmentStringsA (Address: 0x1808752a8)
  • FileTimeToSystemTime (Address: 0x1808755c0)
  • FindClose (Address: 0x180875680)
  • FindFirstFileExW (Address: 0x180875650)
  • FindFirstFileW (Address: 0x180875678)
  • FindNextFileW (Address: 0x180875670)
  • FlsAlloc (Address: 0x1808754f8)
  • FlsFree (Address: 0x1808754e0)
  • FlsGetValue (Address: 0x1808754f0)
  • FlsSetValue (Address: 0x1808754e8)
  • FlushFileBuffers (Address: 0x180875810)
  • FormatMessageA (Address: 0x180875458)
  • FreeEnvironmentStringsW (Address: 0x1808757f0)
  • FreeLibrary (Address: 0x1808752c0)
  • FreeLibraryAndExitThread (Address: 0x1808755a0)
  • FreeLibraryWhenCallbackReturns (Address: 0x180875538)
  • GetACP (Address: 0x1808756c8)
  • GetCommandLineA (Address: 0x180875480)
  • GetCommandLineW (Address: 0x1808757b0)
  • GetConsoleMode (Address: 0x1808756a0)
  • GetConsoleOutputCP (Address: 0x180875720)
  • GetConsoleWindow (Address: 0x180875420)
  • GetCPInfo (Address: 0x1808754c0)
  • GetCurrentDirectoryW (Address: 0x180875660)
  • GetCurrentProcess (Address: 0x1808752b0)
  • GetCurrentProcessId (Address: 0x1808756c0)
  • GetCurrentProcessorNumber (Address: 0x1808754d8)
  • GetCurrentThreadId (Address: 0x180875778)
  • GetDateFormatW (Address: 0x180875728)
  • GetDriveTypeW (Address: 0x1808755b0)
  • GetEnvironmentStringsW (Address: 0x1808757e8)
  • GetEnvironmentVariableA (Address: 0x180875770)
  • GetEnvironmentVariableW (Address: 0x1808756f0)
  • GetFileAttributesExA (Address: 0x1808752e0)
  • GetFileAttributesExW (Address: 0x180875648)
  • GetFileAttributesW (Address: 0x1808755e0)
  • GetFileInformationByHandle (Address: 0x1808755d8)
  • GetFileInformationByHandleEx (Address: 0x180875568)
  • GetFileSizeEx (Address: 0x180875640)
  • GetFileType (Address: 0x180875468)
  • GetFullPathNameW (Address: 0x180875638)
  • GetLastError (Address: 0x180875290)
  • GetLocaleInfoEx (Address: 0x1808755e8)
  • GetLocaleInfoW (Address: 0x1808757d0)
  • GetLogicalProcessorInformation (Address: 0x180875828)
  • GetModuleFileNameW (Address: 0x180875298)
  • GetModuleHandleA (Address: 0x180875268)
  • GetModuleHandleExW (Address: 0x180875618)
  • GetModuleHandleW (Address: 0x1808753e0)
  • GetOEMCP (Address: 0x180875220)
  • GetProcAddress (Address: 0x180875270)
  • GetProcessHeap (Address: 0x180875350)
  • GetProcessId (Address: 0x1808753f8)
  • GetQueuedCompletionStatus (Address: 0x180875760)
  • GetStartupInfoW (Address: 0x180875230)
  • GetStdHandle (Address: 0x1808753a0)
  • GetStringTypeW (Address: 0x180875510)
  • GetSystemDirectoryA (Address: 0x180875448)
  • GetSystemInfo (Address: 0x1808756f8)
  • GetSystemTime (Address: 0x180875608)
  • GetSystemTimeAsFileTime (Address: 0x1808756b8)
  • GetTempPathW (Address: 0x180875630)
  • GetTickCount (Address: 0x1808752d0)
  • GetTickCount64 (Address: 0x180875250)
  • GetTimeFormatW (Address: 0x1808757b8)
  • GetTimeZoneInformation (Address: 0x1808755c8)
  • GetUserDefaultLCID (Address: 0x180875820)
  • GetVersionExA (Address: 0x180875830)
  • GetWindowsDirectoryA (Address: 0x1808752e8)
  • GlobalAlloc (Address: 0x1808752f0)
  • GlobalFree (Address: 0x180875308)
  • GlobalLock (Address: 0x180875300)
  • GlobalUnlock (Address: 0x1808752f8)
  • HeapAlloc (Address: 0x180875340)
  • HeapFree (Address: 0x180875348)
  • HeapReAlloc (Address: 0x180875808)
  • HeapSize (Address: 0x1808757f8)
  • InitializeConditionVariable (Address: 0x180875790)
  • InitializeCriticalSection (Address: 0x180875628)
  • InitializeCriticalSectionAndSpinCount (Address: 0x1808754b8)
  • InitializeCriticalSectionEx (Address: 0x1808753c8)
  • InitializeSListHead (Address: 0x180875228)
  • InitializeSRWLock (Address: 0x1808757a8)
  • InitOnceBeginInitialize (Address: 0x180875548)
  • InitOnceComplete (Address: 0x180875540)
  • InterlockedFlushSList (Address: 0x180875588)
  • IsDebuggerPresent (Address: 0x180875238)
  • IsProcessorFeaturePresent (Address: 0x180875518)
  • IsValidCodePage (Address: 0x1808754d0)
  • IsValidLocale (Address: 0x1808757d8)
  • IsWow64Process (Address: 0x180875620)
  • K32EnumDeviceDrivers (Address: 0x1808753e8)
  • K32GetDeviceDriverBaseNameA (Address: 0x1808753f0)
  • LCMapStringEx (Address: 0x180875500)
  • LCMapStringW (Address: 0x1808757c8)
  • LeaveCriticalSection (Address: 0x180875438)
  • LoadLibraryA (Address: 0x180875330)
  • LoadLibraryExA (Address: 0x1808752c8)
  • LoadLibraryExW (Address: 0x180875610)
  • LocalFree (Address: 0x1808755f0)
  • Module32First (Address: 0x180875408)
  • Module32FirstW (Address: 0x180875390)
  • Module32Next (Address: 0x180875410)
  • Module32NextW (Address: 0x180875398)
  • MultiByteToWideChar (Address: 0x180875310)
  • OpenProcess (Address: 0x180875370)
  • OutputDebugStringW (Address: 0x180875668)
  • PeekNamedPipe (Address: 0x180875478)
  • PostQueuedCompletionStatus (Address: 0x180875758)
  • Process32First (Address: 0x180875280)
  • Process32Next (Address: 0x180875288)
  • QueryPerformanceCounter (Address: 0x180875320)
  • QueryPerformanceFrequency (Address: 0x180875328)
  • RaiseException (Address: 0x180875550)
  • ReadConsoleA (Address: 0x180875690)
  • ReadConsoleW (Address: 0x180875688)
  • ReadFile (Address: 0x180875470)
  • ReadProcessMemory (Address: 0x180875400)
  • ReleaseSRWLockExclusive (Address: 0x1808757a0)
  • ReleaseSRWLockShared (Address: 0x180875750)
  • ResetEvent (Address: 0x1808754a8)
  • RtlUnwind (Address: 0x180875590)
  • RtlUnwindEx (Address: 0x180875580)
  • SetConsoleCtrlHandler (Address: 0x180875710)
  • SetConsoleMode (Address: 0x180875698)
  • SetEndOfFile (Address: 0x180875578)
  • SetEnvironmentVariableW (Address: 0x180875718)
  • SetEvent (Address: 0x1808754b0)
  • SetFileInformationByHandle (Address: 0x1808755d0)
  • SetFilePointerEx (Address: 0x1808755a8)
  • SetHandleInformation (Address: 0x1808753b8)
  • SetLastError (Address: 0x180875428)
  • SetStdHandle (Address: 0x1808757e0)
  • SetUnhandledExceptionFilter (Address: 0x180875490)
  • Sleep (Address: 0x180875248)
  • SleepConditionVariableSRW (Address: 0x180875780)
  • SleepEx (Address: 0x180875440)
  • SubmitThreadpoolWork (Address: 0x180875528)
  • SwitchToFiber (Address: 0x1808756e8)
  • SwitchToThread (Address: 0x1808755f8)
  • SystemTimeToFileTime (Address: 0x180875600)
  • SystemTimeToTzSpecificLocalTime (Address: 0x1808755b8)
  • TerminateProcess (Address: 0x180875488)
  • TlsAlloc (Address: 0x180875740)
  • TlsFree (Address: 0x180875700)
  • TlsGetValue (Address: 0x180875738)
  • TlsSetValue (Address: 0x180875730)
  • TryAcquireSRWLockExclusive (Address: 0x180875560)
  • UnhandledExceptionFilter (Address: 0x180875498)
  • VerifyVersionInfoA (Address: 0x180875450)
  • VerSetConditionMask (Address: 0x180875318)
  • VirtualAlloc (Address: 0x180875258)
  • VirtualAllocEx (Address: 0x180875378)
  • VirtualFree (Address: 0x1808752b8)
  • VirtualFreeEx (Address: 0x180875388)
  • VirtualProtect (Address: 0x180875260)
  • WaitForMultipleObjects (Address: 0x180875838)
  • WaitForSingleObject (Address: 0x180875358)
  • WaitForSingleObjectEx (Address: 0x180875460)
  • WakeAllConditionVariable (Address: 0x180875558)
  • WakeConditionVariable (Address: 0x180875788)
  • WideCharToMultiByte (Address: 0x1808752a0)
  • WriteConsoleW (Address: 0x180875800)
  • WriteFile (Address: 0x1808753a8)
  • WriteProcessMemory (Address: 0x180875380)
Normaliz.dll
  • IdnToAscii (Address: 0x180875848)
ntdll.dll
  • NtQuerySystemInformation (Address: 0x180875cf8)
  • RtlAdjustPrivilege (Address: 0x180875d20)
  • RtlAnsiStringToUnicodeString (Address: 0x180875d28)
  • RtlCaptureContext (Address: 0x180875d08)
  • RtlInitAnsiString (Address: 0x180875d30)
  • RtlLookupFunctionEntry (Address: 0x180875d00)
  • RtlPcToFileHeader (Address: 0x180875d10)
  • RtlVirtualUnwind (Address: 0x180875d18)
ole32.dll
  • CoCreateInstance (Address: 0x180875d40)
  • CoGetApartmentType (Address: 0x180875d50)
  • CoGetObjectContext (Address: 0x180875d70)
  • CoInitializeEx (Address: 0x180875d48)
  • CoInitializeSecurity (Address: 0x180875d58)
  • CoSetProxyBlanket (Address: 0x180875d68)
  • CoUninitialize (Address: 0x180875d60)
OLEAUT32.dll
  • SysAllocString (Address: 0x180875878)
  • SysAllocStringByteLen (Address: 0x180875868)
  • SysFreeString (Address: 0x180875870)
  • SysStringByteLen (Address: 0x180875858)
  • VariantClear (Address: 0x180875860)
RPCRT4.dll
  • RpcStringFreeA (Address: 0x180875888)
  • UuidToStringA (Address: 0x180875890)
SHELL32.dll
  • (Address: 0x1808758a0)
urlmon.dll
  • URLDownloadToFileA (Address: 0x180875d80)
USER32.dll
  • ClientToScreen (Address: 0x1808758d8)
  • CloseClipboard (Address: 0x1808759d0)
  • CreateWindowExA (Address: 0x180875938)
  • DefWindowProcA (Address: 0x180875990)
  • DestroyWindow (Address: 0x180875940)
  • DispatchMessageA (Address: 0x180875900)
  • EmptyClipboard (Address: 0x1808759b8)
  • GetCapture (Address: 0x180875910)
  • GetClientRect (Address: 0x1808758b8)
  • GetClipboardData (Address: 0x1808759c0)
  • GetCursorPos (Address: 0x1808758d0)
  • GetDC (Address: 0x1808759f0)
  • GetDesktopWindow (Address: 0x180875980)
  • GetForegroundWindow (Address: 0x1808758b0)
  • GetKeyState (Address: 0x1808759a8)
  • GetProcessWindowStation (Address: 0x180875a18)
  • GetSystemMetrics (Address: 0x1808759f8)
  • GetUserObjectInformationW (Address: 0x180875998)
  • GetWindowRect (Address: 0x180875970)
  • IsWindowUnicode (Address: 0x180875918)
  • LoadCursorA (Address: 0x1808758e8)
  • MessageBoxA (Address: 0x1808759e0)
  • MessageBoxW (Address: 0x1808759a0)
  • MoveWindow (Address: 0x180875a10)
  • OpenClipboard (Address: 0x1808759d8)
  • PeekMessageA (Address: 0x180875908)
  • PostMessageA (Address: 0x180875a08)
  • PostQuitMessage (Address: 0x180875920)
  • RegisterClassExA (Address: 0x180875930)
  • ReleaseCapture (Address: 0x180875988)
  • ReleaseDC (Address: 0x1808759e8)
  • ScreenToClient (Address: 0x1808758e0)
  • SetCapture (Address: 0x180875a00)
  • SetClipboardData (Address: 0x1808759c8)
  • SetCursor (Address: 0x1808758c8)
  • SetCursorPos (Address: 0x1808758c0)
  • SetLayeredWindowAttributes (Address: 0x180875950)
  • SetProcessDPIAware (Address: 0x1808758f0)
  • SetWindowLongPtrA (Address: 0x180875978)
  • SetWindowPos (Address: 0x180875958)
  • SetWindowRgn (Address: 0x180875968)
  • ShowWindow (Address: 0x180875948)
  • TrackMouseEvent (Address: 0x1808759b0)
  • TranslateMessage (Address: 0x1808758f8)
  • UnregisterClassA (Address: 0x180875928)
  • UpdateWindow (Address: 0x180875960)
WLDAP32.dll
  • (Address: 0x180875a28)
  • (Address: 0x180875a30)
  • (Address: 0x180875a38)
  • (Address: 0x180875a40)
  • (Address: 0x180875a48)
  • (Address: 0x180875a50)
  • (Address: 0x180875a58)
  • (Address: 0x180875a60)
  • (Address: 0x180875a68)
  • (Address: 0x180875a70)
  • (Address: 0x180875a78)
  • (Address: 0x180875a80)
  • (Address: 0x180875a88)
  • (Address: 0x180875a90)
  • (Address: 0x180875a98)
  • (Address: 0x180875aa0)
WS2_32.dll
  • __WSAFDIsSet (Address: 0x180875be0)
  • accept (Address: 0x180875ad0)
  • bind (Address: 0x180875bc8)
  • closesocket (Address: 0x180875ba0)
  • connect (Address: 0x180875ac0)
  • freeaddrinfo (Address: 0x180875ac8)
  • getaddrinfo (Address: 0x180875b90)
  • gethostbyaddr (Address: 0x180875b60)
  • gethostbyname (Address: 0x180875b50)
  • gethostname (Address: 0x180875b98)
  • getpeername (Address: 0x180875bc0)
  • getservbyname (Address: 0x180875b70)
  • getservbyport (Address: 0x180875b68)
  • getsockname (Address: 0x180875bb8)
  • getsockopt (Address: 0x180875bb0)
  • htonl (Address: 0x180875ab8)
  • htons (Address: 0x180875ab0)
  • inet_addr (Address: 0x180875b80)
  • inet_ntoa (Address: 0x180875b58)
  • inet_ntop (Address: 0x180875b28)
  • inet_pton (Address: 0x180875b18)
  • ioctlsocket (Address: 0x180875c08)
  • listen (Address: 0x180875ad8)
  • ntohl (Address: 0x180875ae0)
  • ntohs (Address: 0x180875af8)
  • recv (Address: 0x180875b00)
  • recvfrom (Address: 0x180875ae8)
  • select (Address: 0x180875bd8)
  • send (Address: 0x180875b08)
  • sendto (Address: 0x180875af0)
  • setsockopt (Address: 0x180875b20)
  • shutdown (Address: 0x180875b78)
  • socket (Address: 0x180875b88)
  • WSACleanup (Address: 0x180875bf0)
  • WSAConnect (Address: 0x180875b40)
  • WSAGetLastError (Address: 0x180875be8)
  • WSAGetOverlappedResult (Address: 0x180875b10)
  • WSAIoctl (Address: 0x180875ba8)
  • WSARecv (Address: 0x180875b30)
  • WSARecvFrom (Address: 0x180875b48)
  • WSASend (Address: 0x180875b38)
  • WSASetLastError (Address: 0x180875bd0)
  • WSASocketA (Address: 0x180875c00)
  • WSAStartup (Address: 0x180875bf8)