0_.dll
Description:
Authors:
Version:
Architecture: 64-bit
Operating System:
SHA256: dc98b14cbb25ef1937217da4fde5e2cc
File Size: 128.5 KB
Uploaded At: June 24, 2026, 4:31 p.m.
Views: 26
Security Warning
This file has been flagged as potentially dangerous.
Reason: Detected potentially dangerous functions used for process injection: OpenProcess
Exported Functions
- loader_main_thunk (Ordinal: 1, Address: 0x4cc0)
- dda_enter_privacy (Ordinal: 2, Address: 0x4cd0)
- ldr_thunk_data (Ordinal: 3, Address: 0x21620)
- loader_entry_thread_thunk (Ordinal: 4, Address: 0x2f00)
Imported DLLs & Functions
ADVAPI32.dll
- AdjustTokenPrivileges (Address: 0x180016008)
- BuildTrusteeWithSidW (Address: 0x180016030)
- CreateWellKnownSid (Address: 0x180016018)
- GetSecurityInfo (Address: 0x180016038)
- GetTokenInformation (Address: 0x180016050)
- ImpersonateLoggedOnUser (Address: 0x180016048)
- IsWellKnownSid (Address: 0x180016060)
- LookupPrivilegeValueW (Address: 0x180016010)
- OpenProcessToken (Address: 0x180016000)
- OpenThreadToken (Address: 0x180016058)
- RevertToSelf (Address: 0x180016040)
- SetEntriesInAclW (Address: 0x180016020)
- SetSecurityInfo (Address: 0x180016028)
KERNEL32.dll
- CloseHandle (Address: 0x180016228)
- CreateEventW (Address: 0x180016270)
- CreateFileW (Address: 0x1800161f0)
- CreateMutexW (Address: 0x1800161a0)
- DecodePointer (Address: 0x1800162d0)
- DeleteCriticalSection (Address: 0x180016140)
- EncodePointer (Address: 0x1800162c8)
- EnterCriticalSection (Address: 0x180016200)
- ExitProcess (Address: 0x1800160d0)
- FlsAlloc (Address: 0x180016180)
- FlsFree (Address: 0x180016190)
- FlsGetValue (Address: 0x180016198)
- FlsSetValue (Address: 0x1800162b0)
- FlushFileBuffers (Address: 0x180016348)
- FormatMessageW (Address: 0x180016258)
- FreeEnvironmentStringsW (Address: 0x180016130)
- FreeLibrary (Address: 0x180016240)
- GetACP (Address: 0x180016330)
- GetCommandLineA (Address: 0x1800162b8)
- GetConsoleCP (Address: 0x1800160f0)
- GetConsoleMode (Address: 0x1800160f8)
- GetCPInfo (Address: 0x180016328)
- GetCurrentProcess (Address: 0x1800160c8)
- GetCurrentProcessId (Address: 0x1800160a8)
- GetCurrentThread (Address: 0x1800161c8)
- GetCurrentThreadId (Address: 0x180016210)
- GetEnvironmentStringsW (Address: 0x180016128)
- GetExitCodeThread (Address: 0x180016298)
- GetFileType (Address: 0x180016150)
- GetLastError (Address: 0x1800160e0)
- GetModuleFileNameA (Address: 0x180016138)
- GetModuleFileNameW (Address: 0x180016278)
- GetModuleHandleExW (Address: 0x1800160c0)
- GetModuleHandleW (Address: 0x180016170)
- GetOEMCP (Address: 0x180016338)
- GetProcAddress (Address: 0x180016250)
- GetProcessId (Address: 0x180016280)
- GetStartupInfoW (Address: 0x180016148)
- GetStdHandle (Address: 0x180016160)
- GetStringTypeW (Address: 0x1800162e8)
- GetSystemTime (Address: 0x180016230)
- GetSystemTimeAsFileTime (Address: 0x180016110)
- GetTickCount (Address: 0x180016080)
- GetVersion (Address: 0x180016118)
- HeapAlloc (Address: 0x1800162d8)
- HeapCreate (Address: 0x180016098)
- HeapDestroy (Address: 0x180016090)
- HeapFree (Address: 0x1800162c0)
- HeapReAlloc (Address: 0x1800160e8)
- HeapSetInformation (Address: 0x180016120)
- HeapSize (Address: 0x180016078)
- InitializeCriticalSection (Address: 0x1800161d8)
- InitializeCriticalSectionAndSpinCount (Address: 0x180016158)
- IsDebuggerPresent (Address: 0x180016300)
- IsValidCodePage (Address: 0x180016340)
- LCMapStringW (Address: 0x180016070)
- LeaveCriticalSection (Address: 0x1800160a0)
- LoadLibraryW (Address: 0x180016248)
- LocalAlloc (Address: 0x1800162a0)
- LocalFree (Address: 0x180016260)
- MultiByteToWideChar (Address: 0x180016290)
- OpenProcess (Address: 0x1800160b8)
- OutputDebugStringA (Address: 0x180016208)
- ProcessIdToSessionId (Address: 0x1800160b0)
- QueryPerformanceCounter (Address: 0x180016088)
- RaiseException (Address: 0x1800161f8)
- ReadFile (Address: 0x1800161e8)
- ReleaseMutex (Address: 0x180016218)
- RtlCaptureContext (Address: 0x180016318)
- RtlLookupFunctionEntry (Address: 0x180016310)
- RtlPcToFileHeader (Address: 0x1800162e0)
- RtlUnwindEx (Address: 0x180016178)
- RtlVirtualUnwind (Address: 0x180016308)
- SetEndOfFile (Address: 0x1800161b8)
- SetEvent (Address: 0x180016268)
- SetFilePointer (Address: 0x1800161a8)
- SetHandleCount (Address: 0x180016168)
- SetLastError (Address: 0x180016188)
- SetStdHandle (Address: 0x180016100)
- SetUnhandledExceptionFilter (Address: 0x1800162f8)
- Sleep (Address: 0x1800161e0)
- TerminateProcess (Address: 0x180016320)
- TlsAlloc (Address: 0x180016220)
- TlsFree (Address: 0x180016238)
- TlsGetValue (Address: 0x1800161b0)
- UnhandledExceptionFilter (Address: 0x1800162f0)
- VirtualFree (Address: 0x1800162a8)
- VirtualProtect (Address: 0x1800160d8)
- WaitForSingleObject (Address: 0x1800161c0)
- WideCharToMultiByte (Address: 0x180016288)
- WriteConsoleW (Address: 0x180016108)
- WriteFile (Address: 0x1800161d0)
USER32.dll
- DispatchMessageW (Address: 0x180016360)
- InvalidateRect (Address: 0x180016378)
- MessageBoxA (Address: 0x180016358)
- MsgWaitForMultipleObjectsEx (Address: 0x180016388)
- PeekMessageW (Address: 0x180016380)
- PostQuitMessage (Address: 0x180016368)
- TranslateMessage (Address: 0x180016370)
- UpdateWindow (Address: 0x180016390)