version.dll

Description: https://github.com/acidicoala/Koaloader

Authors: Fuck the copyright \ud83d\udd95

Version: 3.0.2.0

Architecture: 32-bit

Operating System: Windows NT

SHA256: 2665a951793eac577c89d9115aff15b3

File Size: 2.1 MB

Uploaded At: June 6, 2026, 6:38 p.m.

Views: 41

Security Warning

This file has been flagged as potentially dangerous.


Reason: Detected potentially dangerous functions used for process injection: WriteProcessMemory

Exported Functions

  • GetFileVersionInfoA (Ordinal: 1, Address: 0x1fd51c)
  • GetFileVersionInfoByHandle (Ordinal: 2, Address: 0x1fd567)
  • GetFileVersionInfoExA (Ordinal: 3, Address: 0x1fd5b4)
  • GetFileVersionInfoExW (Ordinal: 4, Address: 0x1fd5fc)
  • GetFileVersionInfoSizeA (Ordinal: 5, Address: 0x1fd646)
  • GetFileVersionInfoSizeExA (Ordinal: 6, Address: 0x1fd694)
  • GetFileVersionInfoSizeExW (Ordinal: 7, Address: 0x1fd6e4)
  • GetFileVersionInfoSizeW (Ordinal: 8, Address: 0x1fd732)
  • GetFileVersionInfoW (Ordinal: 9, Address: 0x1fd77a)
  • VerFindFileA (Ordinal: 10, Address: 0x1fd7b7)
  • VerFindFileW (Ordinal: 11, Address: 0x1fd7ed)
  • VerInstallFileA (Ordinal: 12, Address: 0x1fd826)
  • VerInstallFileW (Ordinal: 13, Address: 0x1fd862)
  • VerLanguageNameA (Ordinal: 14, Address: 0x1fd89f)
  • VerLanguageNameW (Ordinal: 15, Address: 0x1fd8dd)
  • VerQueryValueA (Ordinal: 16, Address: 0x1fd919)
  • VerQueryValueW (Ordinal: 17, Address: 0x1fd953)
  • _DllMain@12 (Ordinal: 18, Address: 0x251e0)

Imported DLLs & Functions

ADVAPI32.dll
  • CryptAcquireContextA (Address: 0x10170000)
  • CryptCreateHash (Address: 0x1017000c)
  • CryptDestroyHash (Address: 0x10170014)
  • CryptGenRandom (Address: 0x10170008)
  • CryptGetHashParam (Address: 0x10170004)
  • CryptHashData (Address: 0x10170010)
  • CryptReleaseContext (Address: 0x10170018)
CRYPT32.dll
  • CertAddCertificateContextToStore (Address: 0x10170040)
  • CertCloseStore (Address: 0x10170038)
  • CertCreateCertificateChainEngine (Address: 0x1017004c)
  • CertEnumCertificatesInStore (Address: 0x10170034)
  • CertFindCertificateInStore (Address: 0x10170030)
  • CertFindExtension (Address: 0x1017002c)
  • CertFreeCertificateChain (Address: 0x1017005c)
  • CertFreeCertificateChainEngine (Address: 0x10170050)
  • CertFreeCertificateContext (Address: 0x10170058)
  • CertGetCertificateChain (Address: 0x10170054)
  • CertGetNameStringA (Address: 0x10170044)
  • CertOpenStore (Address: 0x1017003c)
  • CryptDecodeObjectEx (Address: 0x10170020)
  • CryptQueryObject (Address: 0x10170048)
  • CryptStringToBinaryA (Address: 0x10170028)
  • PFXImportCertStore (Address: 0x10170024)
KERNEL32.dll
  • AcquireSRWLockExclusive (Address: 0x101702b0)
  • AreFileApisANSI (Address: 0x10170288)
  • CloseHandle (Address: 0x101700fc)
  • CloseThreadpoolTimer (Address: 0x10170334)
  • CloseThreadpoolWait (Address: 0x10170340)
  • CloseThreadpoolWork (Address: 0x10170324)
  • CompareStringEx (Address: 0x101702e0)
  • CompareStringW (Address: 0x10170090)
  • ConnectNamedPipe (Address: 0x10170104)
  • CopyFileW (Address: 0x10170294)
  • CreateDirectoryExW (Address: 0x10170290)
  • CreateDirectoryW (Address: 0x10170248)
  • CreateEventExW (Address: 0x10170304)
  • CreateEventW (Address: 0x10170210)
  • CreateFileA (Address: 0x101701a4)
  • CreateFileW (Address: 0x1017024c)
  • CreateHardLinkW (Address: 0x1017029c)
  • CreateNamedPipeW (Address: 0x1017010c)
  • CreateSemaphoreExW (Address: 0x10170308)
  • CreateSymbolicLinkW (Address: 0x101702a4)
  • CreateThread (Address: 0x101701fc)
  • CreateThreadpoolTimer (Address: 0x10170328)
  • CreateThreadpoolWait (Address: 0x10170338)
  • CreateThreadpoolWork (Address: 0x1017031c)
  • DecodePointer (Address: 0x101702dc)
  • DeleteCriticalSection (Address: 0x10170168)
  • DeleteFileW (Address: 0x101700b4)
  • DeviceIoControl (Address: 0x1017028c)
  • DisableThreadLibraryCalls (Address: 0x101700ec)
  • DisconnectNamedPipe (Address: 0x10170108)
  • EncodePointer (Address: 0x101702d8)
  • EnterCriticalSection (Address: 0x1017015c)
  • EnumResourceNamesW (Address: 0x1017014c)
  • EnumSystemLocalesW (Address: 0x101700a4)
  • ExitProcess (Address: 0x10170368)
  • ExitThread (Address: 0x101701f8)
  • FileTimeToSystemTime (Address: 0x1017007c)
  • FindClose (Address: 0x10170250)
  • FindFirstFileExW (Address: 0x10170258)
  • FindFirstFileW (Address: 0x10170254)
  • FindNextFileW (Address: 0x1017025c)
  • FindResourceW (Address: 0x10170144)
  • FlsAlloc (Address: 0x101702ec)
  • FlsFree (Address: 0x101702f8)
  • FlsGetValue (Address: 0x101702f0)
  • FlsSetValue (Address: 0x101702f4)
  • FlushFileBuffers (Address: 0x101700f0)
  • FlushProcessWriteBuffers (Address: 0x1017030c)
  • FormatMessageA (Address: 0x10170238)
  • FormatMessageW (Address: 0x10170150)
  • FreeEnvironmentStringsW (Address: 0x101700d0)
  • FreeLibrary (Address: 0x10170128)
  • FreeLibraryAndExitThread (Address: 0x101701f0)
  • FreeLibraryWhenCallbackReturns (Address: 0x10170318)
  • GetACP (Address: 0x101700bc)
  • GetCommandLineA (Address: 0x101700c4)
  • GetCommandLineW (Address: 0x101700c8)
  • GetConsoleMode (Address: 0x101701d8)
  • GetConsoleOutputCP (Address: 0x10170070)
  • GetConsoleScreenBufferInfo (Address: 0x101701e0)
  • GetCPInfo (Address: 0x101702e4)
  • GetCurrentDirectoryW (Address: 0x10170244)
  • GetCurrentProcess (Address: 0x1017011c)
  • GetCurrentProcessId (Address: 0x101701c8)
  • GetCurrentProcessorNumber (Address: 0x10170310)
  • GetCurrentThread (Address: 0x1017006c)
  • GetCurrentThreadId (Address: 0x101701cc)
  • GetDateFormatW (Address: 0x10170088)
  • GetDiskFreeSpaceExW (Address: 0x10170260)
  • GetDriveTypeW (Address: 0x101701e8)
  • GetDynamicTimeZoneInformation (Address: 0x101701d0)
  • GetEnvironmentStringsW (Address: 0x101700cc)
  • GetEnvironmentVariableA (Address: 0x10170180)
  • GetExitCodeThread (Address: 0x101702d0)
  • GetFileAttributesA (Address: 0x101701c4)
  • GetFileAttributesExW (Address: 0x10170268)
  • GetFileAttributesW (Address: 0x10170264)
  • GetFileInformationByHandle (Address: 0x1017026c)
  • GetFileInformationByHandleEx (Address: 0x101702a0)
  • GetFileSizeEx (Address: 0x101701a8)
  • GetFileType (Address: 0x101701ec)
  • GetFinalPathNameByHandleW (Address: 0x10170270)
  • GetFullPathNameW (Address: 0x10170274)
  • GetLastError (Address: 0x10170100)
  • GetLocaleInfoEx (Address: 0x1017023c)
  • GetLocaleInfoW (Address: 0x10170098)
  • GetModuleFileNameW (Address: 0x1017012c)
  • GetModuleHandleA (Address: 0x10170178)
  • GetModuleHandleExW (Address: 0x10170200)
  • GetModuleHandleW (Address: 0x10170130)
  • GetNativeSystemInfo (Address: 0x101702d4)
  • GetOEMCP (Address: 0x101700c0)
  • GetProcAddress (Address: 0x10170134)
  • GetProcessHeap (Address: 0x101700d8)
  • GetStartupInfoW (Address: 0x10170228)
  • GetStdHandle (Address: 0x101701d4)
  • GetStringTypeW (Address: 0x10170344)
  • GetSystemDirectoryA (Address: 0x10170174)
  • GetSystemDirectoryW (Address: 0x10170120)
  • GetSystemInfo (Address: 0x101701b4)
  • GetSystemTimeAsFileTime (Address: 0x1017022c)
  • GetTempPathW (Address: 0x10170284)
  • GetTickCount (Address: 0x10170194)
  • GetTickCount64 (Address: 0x10170314)
  • GetTimeFormatW (Address: 0x1017008c)
  • GetTimeZoneInformation (Address: 0x101700b0)
  • GetUserDefaultLCID (Address: 0x101700a0)
  • HeapAlloc (Address: 0x10170064)
  • HeapFree (Address: 0x10170068)
  • HeapReAlloc (Address: 0x10170074)
  • HeapSize (Address: 0x10170208)
  • InitializeConditionVariable (Address: 0x101702bc)
  • InitializeCriticalSectionAndSpinCount (Address: 0x10170204)
  • InitializeCriticalSectionEx (Address: 0x10170164)
  • InitializeSListHead (Address: 0x10170230)
  • InitializeSRWLock (Address: 0x101702a8)
  • InitOnceExecuteOnce (Address: 0x101702fc)
  • InterlockedFlushSList (Address: 0x10170350)
  • InterlockedPushEntrySList (Address: 0x1017034c)
  • IsDebuggerPresent (Address: 0x10170224)
  • IsProcessorFeaturePresent (Address: 0x10170220)
  • IsValidCodePage (Address: 0x101700b8)
  • IsValidLocale (Address: 0x1017009c)
  • K32GetModuleInformation (Address: 0x10170158)
  • LCMapStringEx (Address: 0x101702e8)
  • LCMapStringW (Address: 0x10170094)
  • LeaveCriticalSection (Address: 0x10170160)
  • LoadLibraryA (Address: 0x1017017c)
  • LoadLibraryExW (Address: 0x10170364)
  • LoadLibraryW (Address: 0x10170148)
  • LoadResource (Address: 0x10170138)
  • LocalFree (Address: 0x10170234)
  • LockResource (Address: 0x1017013c)
  • MoveFileExA (Address: 0x1017018c)
  • MoveFileExW (Address: 0x10170298)
  • MultiByteToWideChar (Address: 0x10170114)
  • OutputDebugStringW (Address: 0x101700e0)
  • PeekNamedPipe (Address: 0x10170084)
  • QueryPerformanceCounter (Address: 0x10170190)
  • QueryPerformanceFrequency (Address: 0x10170170)
  • RaiseException (Address: 0x101702b8)
  • ReadConsoleW (Address: 0x101700e4)
  • ReadFile (Address: 0x101700f4)
  • ReadProcessMemory (Address: 0x101701b0)
  • RegisterApplicationRestart (Address: 0x10170154)
  • ReleaseSRWLockExclusive (Address: 0x101702ac)
  • ResetEvent (Address: 0x1017020c)
  • ResumeThread (Address: 0x101701f4)
  • RtlUnwind (Address: 0x10170348)
  • SetConsoleCtrlHandler (Address: 0x101700dc)
  • SetConsoleTextAttribute (Address: 0x101701e4)
  • SetCurrentDirectoryW (Address: 0x10170240)
  • SetEndOfFile (Address: 0x101700ac)
  • SetEnvironmentVariableW (Address: 0x101700d4)
  • SetEvent (Address: 0x101700e8)
  • SetFileAttributesW (Address: 0x10170278)
  • SetFileInformationByHandle (Address: 0x1017027c)
  • SetFilePointerEx (Address: 0x101700a8)
  • SetFileTime (Address: 0x10170280)
  • SetLastError (Address: 0x10170184)
  • SetStdHandle (Address: 0x10170078)
  • SetThreadpoolTimer (Address: 0x1017032c)
  • SetThreadpoolWait (Address: 0x1017033c)
  • SetUnhandledExceptionFilter (Address: 0x10170218)
  • SizeofResource (Address: 0x10170140)
  • Sleep (Address: 0x10170188)
  • SleepConditionVariableCS (Address: 0x10170300)
  • SleepConditionVariableSRW (Address: 0x101702c8)
  • SleepEx (Address: 0x1017016c)
  • SubmitThreadpoolWork (Address: 0x10170320)
  • SwitchToThread (Address: 0x101702cc)
  • SystemTimeToTzSpecificLocalTime (Address: 0x10170080)
  • TerminateProcess (Address: 0x1017021c)
  • TlsAlloc (Address: 0x10170354)
  • TlsFree (Address: 0x10170360)
  • TlsGetValue (Address: 0x10170358)
  • TlsSetValue (Address: 0x1017035c)
  • TryAcquireSRWLockExclusive (Address: 0x101702b4)
  • UnhandledExceptionFilter (Address: 0x10170214)
  • VerifyVersionInfoW (Address: 0x101701a0)
  • VerSetConditionMask (Address: 0x1017019c)
  • VirtualAlloc (Address: 0x101701b8)
  • VirtualFree (Address: 0x101701bc)
  • VirtualProtect (Address: 0x101701ac)
  • VirtualQuery (Address: 0x10170110)
  • WaitForSingleObjectEx (Address: 0x10170198)
  • WaitForThreadpoolTimerCallbacks (Address: 0x10170330)
  • WakeAllConditionVariable (Address: 0x101702c4)
  • WakeConditionVariable (Address: 0x101702c0)
  • WideCharToMultiByte (Address: 0x10170118)
  • WriteConsoleA (Address: 0x101701dc)
  • WriteConsoleW (Address: 0x101701c0)
  • WriteFile (Address: 0x101700f8)
  • WriteProcessMemory (Address: 0x10170124)
USER32.dll
  • MessageBoxW (Address: 0x10170370)
VERSION.dll
  • GetFileVersionInfoSizeW (Address: 0x10170378)
  • GetFileVersionInfoW (Address: 0x1017037c)
  • VerQueryValueW (Address: 0x10170380)
WS2_32.dll
  • __WSAFDIsSet (Address: 0x101703a0)
  • accept (Address: 0x10170398)
  • bind (Address: 0x101703e0)
  • closesocket (Address: 0x101703ec)
  • connect (Address: 0x101703dc)
  • freeaddrinfo (Address: 0x101703a4)
  • getaddrinfo (Address: 0x101703a8)
  • getpeername (Address: 0x101703d8)
  • getsockname (Address: 0x101703d4)
  • getsockopt (Address: 0x101703d0)
  • htonl (Address: 0x10170394)
  • htons (Address: 0x101703cc)
  • inet_pton (Address: 0x101703b4)
  • ioctlsocket (Address: 0x1017038c)
  • listen (Address: 0x10170390)
  • ntohs (Address: 0x101703c8)
  • recv (Address: 0x101703e4)
  • select (Address: 0x1017039c)
  • send (Address: 0x10170408)
  • setsockopt (Address: 0x101703c4)
  • socket (Address: 0x101703c0)
  • WSACleanup (Address: 0x101703ac)
  • WSACloseEvent (Address: 0x10170388)
  • WSACreateEvent (Address: 0x10170404)
  • WSAEnumNetworkEvents (Address: 0x10170400)
  • WSAEventSelect (Address: 0x101703fc)
  • WSAGetLastError (Address: 0x101703e8)
  • WSAIoctl (Address: 0x101703b8)
  • WSAResetEvent (Address: 0x101703f8)
  • WSASetEvent (Address: 0x101703f4)
  • WSASetLastError (Address: 0x101703bc)
  • WSAStartup (Address: 0x101703b0)
  • WSAWaitForMultipleEvents (Address: 0x101703f0)