version.dll
Description: https://github.com/acidicoala/Koaloader
Authors: Fuck the copyright \ud83d\udd95
Version: 3.0.2.0
Architecture: 32-bit
Operating System: Windows NT
SHA256: 2665a951793eac577c89d9115aff15b3
File Size: 2.1 MB
Uploaded At: June 6, 2026, 6:38 p.m.
Views: 41
Security Warning
This file has been flagged as potentially dangerous.
Reason: Detected potentially dangerous functions used for process injection: WriteProcessMemory
Exported Functions
- GetFileVersionInfoA (Ordinal: 1, Address: 0x1fd51c)
- GetFileVersionInfoByHandle (Ordinal: 2, Address: 0x1fd567)
- GetFileVersionInfoExA (Ordinal: 3, Address: 0x1fd5b4)
- GetFileVersionInfoExW (Ordinal: 4, Address: 0x1fd5fc)
- GetFileVersionInfoSizeA (Ordinal: 5, Address: 0x1fd646)
- GetFileVersionInfoSizeExA (Ordinal: 6, Address: 0x1fd694)
- GetFileVersionInfoSizeExW (Ordinal: 7, Address: 0x1fd6e4)
- GetFileVersionInfoSizeW (Ordinal: 8, Address: 0x1fd732)
- GetFileVersionInfoW (Ordinal: 9, Address: 0x1fd77a)
- VerFindFileA (Ordinal: 10, Address: 0x1fd7b7)
- VerFindFileW (Ordinal: 11, Address: 0x1fd7ed)
- VerInstallFileA (Ordinal: 12, Address: 0x1fd826)
- VerInstallFileW (Ordinal: 13, Address: 0x1fd862)
- VerLanguageNameA (Ordinal: 14, Address: 0x1fd89f)
- VerLanguageNameW (Ordinal: 15, Address: 0x1fd8dd)
- VerQueryValueA (Ordinal: 16, Address: 0x1fd919)
- VerQueryValueW (Ordinal: 17, Address: 0x1fd953)
- _DllMain@12 (Ordinal: 18, Address: 0x251e0)
Imported DLLs & Functions
ADVAPI32.dll
- CryptAcquireContextA (Address: 0x10170000)
- CryptCreateHash (Address: 0x1017000c)
- CryptDestroyHash (Address: 0x10170014)
- CryptGenRandom (Address: 0x10170008)
- CryptGetHashParam (Address: 0x10170004)
- CryptHashData (Address: 0x10170010)
- CryptReleaseContext (Address: 0x10170018)
CRYPT32.dll
- CertAddCertificateContextToStore (Address: 0x10170040)
- CertCloseStore (Address: 0x10170038)
- CertCreateCertificateChainEngine (Address: 0x1017004c)
- CertEnumCertificatesInStore (Address: 0x10170034)
- CertFindCertificateInStore (Address: 0x10170030)
- CertFindExtension (Address: 0x1017002c)
- CertFreeCertificateChain (Address: 0x1017005c)
- CertFreeCertificateChainEngine (Address: 0x10170050)
- CertFreeCertificateContext (Address: 0x10170058)
- CertGetCertificateChain (Address: 0x10170054)
- CertGetNameStringA (Address: 0x10170044)
- CertOpenStore (Address: 0x1017003c)
- CryptDecodeObjectEx (Address: 0x10170020)
- CryptQueryObject (Address: 0x10170048)
- CryptStringToBinaryA (Address: 0x10170028)
- PFXImportCertStore (Address: 0x10170024)
KERNEL32.dll
- AcquireSRWLockExclusive (Address: 0x101702b0)
- AreFileApisANSI (Address: 0x10170288)
- CloseHandle (Address: 0x101700fc)
- CloseThreadpoolTimer (Address: 0x10170334)
- CloseThreadpoolWait (Address: 0x10170340)
- CloseThreadpoolWork (Address: 0x10170324)
- CompareStringEx (Address: 0x101702e0)
- CompareStringW (Address: 0x10170090)
- ConnectNamedPipe (Address: 0x10170104)
- CopyFileW (Address: 0x10170294)
- CreateDirectoryExW (Address: 0x10170290)
- CreateDirectoryW (Address: 0x10170248)
- CreateEventExW (Address: 0x10170304)
- CreateEventW (Address: 0x10170210)
- CreateFileA (Address: 0x101701a4)
- CreateFileW (Address: 0x1017024c)
- CreateHardLinkW (Address: 0x1017029c)
- CreateNamedPipeW (Address: 0x1017010c)
- CreateSemaphoreExW (Address: 0x10170308)
- CreateSymbolicLinkW (Address: 0x101702a4)
- CreateThread (Address: 0x101701fc)
- CreateThreadpoolTimer (Address: 0x10170328)
- CreateThreadpoolWait (Address: 0x10170338)
- CreateThreadpoolWork (Address: 0x1017031c)
- DecodePointer (Address: 0x101702dc)
- DeleteCriticalSection (Address: 0x10170168)
- DeleteFileW (Address: 0x101700b4)
- DeviceIoControl (Address: 0x1017028c)
- DisableThreadLibraryCalls (Address: 0x101700ec)
- DisconnectNamedPipe (Address: 0x10170108)
- EncodePointer (Address: 0x101702d8)
- EnterCriticalSection (Address: 0x1017015c)
- EnumResourceNamesW (Address: 0x1017014c)
- EnumSystemLocalesW (Address: 0x101700a4)
- ExitProcess (Address: 0x10170368)
- ExitThread (Address: 0x101701f8)
- FileTimeToSystemTime (Address: 0x1017007c)
- FindClose (Address: 0x10170250)
- FindFirstFileExW (Address: 0x10170258)
- FindFirstFileW (Address: 0x10170254)
- FindNextFileW (Address: 0x1017025c)
- FindResourceW (Address: 0x10170144)
- FlsAlloc (Address: 0x101702ec)
- FlsFree (Address: 0x101702f8)
- FlsGetValue (Address: 0x101702f0)
- FlsSetValue (Address: 0x101702f4)
- FlushFileBuffers (Address: 0x101700f0)
- FlushProcessWriteBuffers (Address: 0x1017030c)
- FormatMessageA (Address: 0x10170238)
- FormatMessageW (Address: 0x10170150)
- FreeEnvironmentStringsW (Address: 0x101700d0)
- FreeLibrary (Address: 0x10170128)
- FreeLibraryAndExitThread (Address: 0x101701f0)
- FreeLibraryWhenCallbackReturns (Address: 0x10170318)
- GetACP (Address: 0x101700bc)
- GetCommandLineA (Address: 0x101700c4)
- GetCommandLineW (Address: 0x101700c8)
- GetConsoleMode (Address: 0x101701d8)
- GetConsoleOutputCP (Address: 0x10170070)
- GetConsoleScreenBufferInfo (Address: 0x101701e0)
- GetCPInfo (Address: 0x101702e4)
- GetCurrentDirectoryW (Address: 0x10170244)
- GetCurrentProcess (Address: 0x1017011c)
- GetCurrentProcessId (Address: 0x101701c8)
- GetCurrentProcessorNumber (Address: 0x10170310)
- GetCurrentThread (Address: 0x1017006c)
- GetCurrentThreadId (Address: 0x101701cc)
- GetDateFormatW (Address: 0x10170088)
- GetDiskFreeSpaceExW (Address: 0x10170260)
- GetDriveTypeW (Address: 0x101701e8)
- GetDynamicTimeZoneInformation (Address: 0x101701d0)
- GetEnvironmentStringsW (Address: 0x101700cc)
- GetEnvironmentVariableA (Address: 0x10170180)
- GetExitCodeThread (Address: 0x101702d0)
- GetFileAttributesA (Address: 0x101701c4)
- GetFileAttributesExW (Address: 0x10170268)
- GetFileAttributesW (Address: 0x10170264)
- GetFileInformationByHandle (Address: 0x1017026c)
- GetFileInformationByHandleEx (Address: 0x101702a0)
- GetFileSizeEx (Address: 0x101701a8)
- GetFileType (Address: 0x101701ec)
- GetFinalPathNameByHandleW (Address: 0x10170270)
- GetFullPathNameW (Address: 0x10170274)
- GetLastError (Address: 0x10170100)
- GetLocaleInfoEx (Address: 0x1017023c)
- GetLocaleInfoW (Address: 0x10170098)
- GetModuleFileNameW (Address: 0x1017012c)
- GetModuleHandleA (Address: 0x10170178)
- GetModuleHandleExW (Address: 0x10170200)
- GetModuleHandleW (Address: 0x10170130)
- GetNativeSystemInfo (Address: 0x101702d4)
- GetOEMCP (Address: 0x101700c0)
- GetProcAddress (Address: 0x10170134)
- GetProcessHeap (Address: 0x101700d8)
- GetStartupInfoW (Address: 0x10170228)
- GetStdHandle (Address: 0x101701d4)
- GetStringTypeW (Address: 0x10170344)
- GetSystemDirectoryA (Address: 0x10170174)
- GetSystemDirectoryW (Address: 0x10170120)
- GetSystemInfo (Address: 0x101701b4)
- GetSystemTimeAsFileTime (Address: 0x1017022c)
- GetTempPathW (Address: 0x10170284)
- GetTickCount (Address: 0x10170194)
- GetTickCount64 (Address: 0x10170314)
- GetTimeFormatW (Address: 0x1017008c)
- GetTimeZoneInformation (Address: 0x101700b0)
- GetUserDefaultLCID (Address: 0x101700a0)
- HeapAlloc (Address: 0x10170064)
- HeapFree (Address: 0x10170068)
- HeapReAlloc (Address: 0x10170074)
- HeapSize (Address: 0x10170208)
- InitializeConditionVariable (Address: 0x101702bc)
- InitializeCriticalSectionAndSpinCount (Address: 0x10170204)
- InitializeCriticalSectionEx (Address: 0x10170164)
- InitializeSListHead (Address: 0x10170230)
- InitializeSRWLock (Address: 0x101702a8)
- InitOnceExecuteOnce (Address: 0x101702fc)
- InterlockedFlushSList (Address: 0x10170350)
- InterlockedPushEntrySList (Address: 0x1017034c)
- IsDebuggerPresent (Address: 0x10170224)
- IsProcessorFeaturePresent (Address: 0x10170220)
- IsValidCodePage (Address: 0x101700b8)
- IsValidLocale (Address: 0x1017009c)
- K32GetModuleInformation (Address: 0x10170158)
- LCMapStringEx (Address: 0x101702e8)
- LCMapStringW (Address: 0x10170094)
- LeaveCriticalSection (Address: 0x10170160)
- LoadLibraryA (Address: 0x1017017c)
- LoadLibraryExW (Address: 0x10170364)
- LoadLibraryW (Address: 0x10170148)
- LoadResource (Address: 0x10170138)
- LocalFree (Address: 0x10170234)
- LockResource (Address: 0x1017013c)
- MoveFileExA (Address: 0x1017018c)
- MoveFileExW (Address: 0x10170298)
- MultiByteToWideChar (Address: 0x10170114)
- OutputDebugStringW (Address: 0x101700e0)
- PeekNamedPipe (Address: 0x10170084)
- QueryPerformanceCounter (Address: 0x10170190)
- QueryPerformanceFrequency (Address: 0x10170170)
- RaiseException (Address: 0x101702b8)
- ReadConsoleW (Address: 0x101700e4)
- ReadFile (Address: 0x101700f4)
- ReadProcessMemory (Address: 0x101701b0)
- RegisterApplicationRestart (Address: 0x10170154)
- ReleaseSRWLockExclusive (Address: 0x101702ac)
- ResetEvent (Address: 0x1017020c)
- ResumeThread (Address: 0x101701f4)
- RtlUnwind (Address: 0x10170348)
- SetConsoleCtrlHandler (Address: 0x101700dc)
- SetConsoleTextAttribute (Address: 0x101701e4)
- SetCurrentDirectoryW (Address: 0x10170240)
- SetEndOfFile (Address: 0x101700ac)
- SetEnvironmentVariableW (Address: 0x101700d4)
- SetEvent (Address: 0x101700e8)
- SetFileAttributesW (Address: 0x10170278)
- SetFileInformationByHandle (Address: 0x1017027c)
- SetFilePointerEx (Address: 0x101700a8)
- SetFileTime (Address: 0x10170280)
- SetLastError (Address: 0x10170184)
- SetStdHandle (Address: 0x10170078)
- SetThreadpoolTimer (Address: 0x1017032c)
- SetThreadpoolWait (Address: 0x1017033c)
- SetUnhandledExceptionFilter (Address: 0x10170218)
- SizeofResource (Address: 0x10170140)
- Sleep (Address: 0x10170188)
- SleepConditionVariableCS (Address: 0x10170300)
- SleepConditionVariableSRW (Address: 0x101702c8)
- SleepEx (Address: 0x1017016c)
- SubmitThreadpoolWork (Address: 0x10170320)
- SwitchToThread (Address: 0x101702cc)
- SystemTimeToTzSpecificLocalTime (Address: 0x10170080)
- TerminateProcess (Address: 0x1017021c)
- TlsAlloc (Address: 0x10170354)
- TlsFree (Address: 0x10170360)
- TlsGetValue (Address: 0x10170358)
- TlsSetValue (Address: 0x1017035c)
- TryAcquireSRWLockExclusive (Address: 0x101702b4)
- UnhandledExceptionFilter (Address: 0x10170214)
- VerifyVersionInfoW (Address: 0x101701a0)
- VerSetConditionMask (Address: 0x1017019c)
- VirtualAlloc (Address: 0x101701b8)
- VirtualFree (Address: 0x101701bc)
- VirtualProtect (Address: 0x101701ac)
- VirtualQuery (Address: 0x10170110)
- WaitForSingleObjectEx (Address: 0x10170198)
- WaitForThreadpoolTimerCallbacks (Address: 0x10170330)
- WakeAllConditionVariable (Address: 0x101702c4)
- WakeConditionVariable (Address: 0x101702c0)
- WideCharToMultiByte (Address: 0x10170118)
- WriteConsoleA (Address: 0x101701dc)
- WriteConsoleW (Address: 0x101701c0)
- WriteFile (Address: 0x101700f8)
- WriteProcessMemory (Address: 0x10170124)
USER32.dll
- MessageBoxW (Address: 0x10170370)
VERSION.dll
- GetFileVersionInfoSizeW (Address: 0x10170378)
- GetFileVersionInfoW (Address: 0x1017037c)
- VerQueryValueW (Address: 0x10170380)
WS2_32.dll
- __WSAFDIsSet (Address: 0x101703a0)
- accept (Address: 0x10170398)
- bind (Address: 0x101703e0)
- closesocket (Address: 0x101703ec)
- connect (Address: 0x101703dc)
- freeaddrinfo (Address: 0x101703a4)
- getaddrinfo (Address: 0x101703a8)
- getpeername (Address: 0x101703d8)
- getsockname (Address: 0x101703d4)
- getsockopt (Address: 0x101703d0)
- htonl (Address: 0x10170394)
- htons (Address: 0x101703cc)
- inet_pton (Address: 0x101703b4)
- ioctlsocket (Address: 0x1017038c)
- listen (Address: 0x10170390)
- ntohs (Address: 0x101703c8)
- recv (Address: 0x101703e4)
- select (Address: 0x1017039c)
- send (Address: 0x10170408)
- setsockopt (Address: 0x101703c4)
- socket (Address: 0x101703c0)
- WSACleanup (Address: 0x101703ac)
- WSACloseEvent (Address: 0x10170388)
- WSACreateEvent (Address: 0x10170404)
- WSAEnumNetworkEvents (Address: 0x10170400)
- WSAEventSelect (Address: 0x101703fc)
- WSAGetLastError (Address: 0x101703e8)
- WSAIoctl (Address: 0x101703b8)
- WSAResetEvent (Address: 0x101703f8)
- WSASetEvent (Address: 0x101703f4)
- WSASetLastError (Address: 0x101703bc)
- WSAStartup (Address: 0x101703b0)
- WSAWaitForMultipleEvents (Address: 0x101703f0)