0_.dll

Description:

Authors:

Version:

Architecture: 64-bit

Operating System:

SHA256: dc98b14cbb25ef1937217da4fde5e2cc

File Size: 128.5 KB

Uploaded At: June 24, 2026, 4:31 p.m.

Views: 26

Security Warning

This file has been flagged as potentially dangerous.


Reason: Detected potentially dangerous functions used for process injection: OpenProcess

Exported Functions

  • loader_main_thunk (Ordinal: 1, Address: 0x4cc0)
  • dda_enter_privacy (Ordinal: 2, Address: 0x4cd0)
  • ldr_thunk_data (Ordinal: 3, Address: 0x21620)
  • loader_entry_thread_thunk (Ordinal: 4, Address: 0x2f00)

Imported DLLs & Functions

ADVAPI32.dll
  • AdjustTokenPrivileges (Address: 0x180016008)
  • BuildTrusteeWithSidW (Address: 0x180016030)
  • CreateWellKnownSid (Address: 0x180016018)
  • GetSecurityInfo (Address: 0x180016038)
  • GetTokenInformation (Address: 0x180016050)
  • ImpersonateLoggedOnUser (Address: 0x180016048)
  • IsWellKnownSid (Address: 0x180016060)
  • LookupPrivilegeValueW (Address: 0x180016010)
  • OpenProcessToken (Address: 0x180016000)
  • OpenThreadToken (Address: 0x180016058)
  • RevertToSelf (Address: 0x180016040)
  • SetEntriesInAclW (Address: 0x180016020)
  • SetSecurityInfo (Address: 0x180016028)
KERNEL32.dll
  • CloseHandle (Address: 0x180016228)
  • CreateEventW (Address: 0x180016270)
  • CreateFileW (Address: 0x1800161f0)
  • CreateMutexW (Address: 0x1800161a0)
  • DecodePointer (Address: 0x1800162d0)
  • DeleteCriticalSection (Address: 0x180016140)
  • EncodePointer (Address: 0x1800162c8)
  • EnterCriticalSection (Address: 0x180016200)
  • ExitProcess (Address: 0x1800160d0)
  • FlsAlloc (Address: 0x180016180)
  • FlsFree (Address: 0x180016190)
  • FlsGetValue (Address: 0x180016198)
  • FlsSetValue (Address: 0x1800162b0)
  • FlushFileBuffers (Address: 0x180016348)
  • FormatMessageW (Address: 0x180016258)
  • FreeEnvironmentStringsW (Address: 0x180016130)
  • FreeLibrary (Address: 0x180016240)
  • GetACP (Address: 0x180016330)
  • GetCommandLineA (Address: 0x1800162b8)
  • GetConsoleCP (Address: 0x1800160f0)
  • GetConsoleMode (Address: 0x1800160f8)
  • GetCPInfo (Address: 0x180016328)
  • GetCurrentProcess (Address: 0x1800160c8)
  • GetCurrentProcessId (Address: 0x1800160a8)
  • GetCurrentThread (Address: 0x1800161c8)
  • GetCurrentThreadId (Address: 0x180016210)
  • GetEnvironmentStringsW (Address: 0x180016128)
  • GetExitCodeThread (Address: 0x180016298)
  • GetFileType (Address: 0x180016150)
  • GetLastError (Address: 0x1800160e0)
  • GetModuleFileNameA (Address: 0x180016138)
  • GetModuleFileNameW (Address: 0x180016278)
  • GetModuleHandleExW (Address: 0x1800160c0)
  • GetModuleHandleW (Address: 0x180016170)
  • GetOEMCP (Address: 0x180016338)
  • GetProcAddress (Address: 0x180016250)
  • GetProcessId (Address: 0x180016280)
  • GetStartupInfoW (Address: 0x180016148)
  • GetStdHandle (Address: 0x180016160)
  • GetStringTypeW (Address: 0x1800162e8)
  • GetSystemTime (Address: 0x180016230)
  • GetSystemTimeAsFileTime (Address: 0x180016110)
  • GetTickCount (Address: 0x180016080)
  • GetVersion (Address: 0x180016118)
  • HeapAlloc (Address: 0x1800162d8)
  • HeapCreate (Address: 0x180016098)
  • HeapDestroy (Address: 0x180016090)
  • HeapFree (Address: 0x1800162c0)
  • HeapReAlloc (Address: 0x1800160e8)
  • HeapSetInformation (Address: 0x180016120)
  • HeapSize (Address: 0x180016078)
  • InitializeCriticalSection (Address: 0x1800161d8)
  • InitializeCriticalSectionAndSpinCount (Address: 0x180016158)
  • IsDebuggerPresent (Address: 0x180016300)
  • IsValidCodePage (Address: 0x180016340)
  • LCMapStringW (Address: 0x180016070)
  • LeaveCriticalSection (Address: 0x1800160a0)
  • LoadLibraryW (Address: 0x180016248)
  • LocalAlloc (Address: 0x1800162a0)
  • LocalFree (Address: 0x180016260)
  • MultiByteToWideChar (Address: 0x180016290)
  • OpenProcess (Address: 0x1800160b8)
  • OutputDebugStringA (Address: 0x180016208)
  • ProcessIdToSessionId (Address: 0x1800160b0)
  • QueryPerformanceCounter (Address: 0x180016088)
  • RaiseException (Address: 0x1800161f8)
  • ReadFile (Address: 0x1800161e8)
  • ReleaseMutex (Address: 0x180016218)
  • RtlCaptureContext (Address: 0x180016318)
  • RtlLookupFunctionEntry (Address: 0x180016310)
  • RtlPcToFileHeader (Address: 0x1800162e0)
  • RtlUnwindEx (Address: 0x180016178)
  • RtlVirtualUnwind (Address: 0x180016308)
  • SetEndOfFile (Address: 0x1800161b8)
  • SetEvent (Address: 0x180016268)
  • SetFilePointer (Address: 0x1800161a8)
  • SetHandleCount (Address: 0x180016168)
  • SetLastError (Address: 0x180016188)
  • SetStdHandle (Address: 0x180016100)
  • SetUnhandledExceptionFilter (Address: 0x1800162f8)
  • Sleep (Address: 0x1800161e0)
  • TerminateProcess (Address: 0x180016320)
  • TlsAlloc (Address: 0x180016220)
  • TlsFree (Address: 0x180016238)
  • TlsGetValue (Address: 0x1800161b0)
  • UnhandledExceptionFilter (Address: 0x1800162f0)
  • VirtualFree (Address: 0x1800162a8)
  • VirtualProtect (Address: 0x1800160d8)
  • WaitForSingleObject (Address: 0x1800161c0)
  • WideCharToMultiByte (Address: 0x180016288)
  • WriteConsoleW (Address: 0x180016108)
  • WriteFile (Address: 0x1800161d0)
USER32.dll
  • DispatchMessageW (Address: 0x180016360)
  • InvalidateRect (Address: 0x180016378)
  • MessageBoxA (Address: 0x180016358)
  • MsgWaitForMultipleObjectsEx (Address: 0x180016388)
  • PeekMessageW (Address: 0x180016380)
  • PostQuitMessage (Address: 0x180016368)
  • TranslateMessage (Address: 0x180016370)
  • UpdateWindow (Address: 0x180016390)