main.dll

Description:

Authors:

Version:

Architecture: 64-bit

Operating System:

SHA256: 3c669abec8032e9e29f55285300b911e

File Size: 44.5 KB

Uploaded At: July 4, 2026, 9:37 a.m.

Views: 15

Security Warning

This file has been flagged as potentially dangerous.


Reason: Detected potentially dangerous functions used for process injection: OpenProcess, CreateRemoteThread

Exported Functions

  • EzDeleteFileA (Ordinal: 1, Address: 0x1f80)
  • EzDeleteFileW (Ordinal: 2, Address: 0x20a0)
  • EzUnlockFileA (Ordinal: 3, Address: 0x1c80)
  • EzUnlockFileW (Ordinal: 4, Address: 0x1e20)

Imported DLLs & Functions

ADVAPI32.dll
  • AdjustTokenPrivileges (Address: 0x180008008)
  • LookupPrivilegeValueW (Address: 0x180008000)
  • OpenProcessToken (Address: 0x180008010)
api-ms-win-crt-heap-l1-1-0.dll
  • _callnewh (Address: 0x180008278)
  • free (Address: 0x180008280)
  • malloc (Address: 0x180008270)
  • realloc (Address: 0x180008288)
api-ms-win-crt-locale-l1-1-0.dll
  • ___lc_codepage_func (Address: 0x180008298)
api-ms-win-crt-runtime-l1-1-0.dll
  • _cexit (Address: 0x1800082e8)
  • _configure_narrow_argv (Address: 0x1800082b8)
  • _crt_atexit (Address: 0x1800082d0)
  • _execute_onexit_table (Address: 0x1800082c8)
  • _initialize_narrow_environment (Address: 0x1800082b0)
  • _initialize_onexit_table (Address: 0x1800082a8)
  • _initterm (Address: 0x1800082f0)
  • _initterm_e (Address: 0x1800082e0)
  • _invalid_parameter_noinfo_noreturn (Address: 0x1800082f8)
  • _register_onexit_function (Address: 0x1800082c0)
  • _seh_filter_dll (Address: 0x1800082d8)
api-ms-win-crt-string-l1-1-0.dll
  • _wcsicmp (Address: 0x180008310)
  • _wcsnicmp (Address: 0x180008308)
KERNEL32.dll
  • AreFileApisANSI (Address: 0x180008118)
  • CloseHandle (Address: 0x180008030)
  • CreateEventW (Address: 0x180008190)
  • CreateFileMappingW (Address: 0x180008080)
  • CreateFileW (Address: 0x180008108)
  • CreateRemoteThread (Address: 0x180008040)
  • CreateToolhelp32Snapshot (Address: 0x180008058)
  • DeleteCriticalSection (Address: 0x1800081b0)
  • DeleteFileW (Address: 0x180008110)
  • DisableThreadLibraryCalls (Address: 0x180008128)
  • DuplicateHandle (Address: 0x180008098)
  • EnterCriticalSection (Address: 0x1800081c8)
  • FormatMessageA (Address: 0x1800081e0)
  • GetCurrentProcess (Address: 0x180008090)
  • GetCurrentProcessId (Address: 0x180008140)
  • GetCurrentThreadId (Address: 0x180008138)
  • GetDriveTypeW (Address: 0x1800080a8)
  • GetExitCodeThread (Address: 0x180008020)
  • GetLastError (Address: 0x1800080f0)
  • GetLogicalDrives (Address: 0x1800080b8)
  • GetModuleHandleW (Address: 0x180008188)
  • GetNativeSystemInfo (Address: 0x1800080d8)
  • GetProcAddress (Address: 0x180008038)
  • GetSystemTimeAsFileTime (Address: 0x180008130)
  • GetWindowsDirectoryW (Address: 0x1800080a0)
  • InitializeCriticalSectionAndSpinCount (Address: 0x1800081b8)
  • InitializeSListHead (Address: 0x180008120)
  • IsDebuggerPresent (Address: 0x180008150)
  • IsProcessorFeaturePresent (Address: 0x180008158)
  • IsWow64Process (Address: 0x1800080e0)
  • K32GetMappedFileNameW (Address: 0x1800080c8)
  • K32GetProcessImageFileNameW (Address: 0x1800080e8)
  • LeaveCriticalSection (Address: 0x1800081c0)
  • LoadLibraryW (Address: 0x1800080c0)
  • LocalFree (Address: 0x1800081d8)
  • MapViewOfFile (Address: 0x180008078)
  • Module32FirstW (Address: 0x180008050)
  • Module32NextW (Address: 0x180008088)
  • MultiByteToWideChar (Address: 0x1800081d0)
  • OpenProcess (Address: 0x180008060)
  • Process32FirstW (Address: 0x180008068)
  • Process32NextW (Address: 0x1800080f8)
  • QueryDosDeviceW (Address: 0x1800080b0)
  • QueryPerformanceCounter (Address: 0x180008148)
  • ResetEvent (Address: 0x1800081a0)
  • RtlCaptureContext (Address: 0x180008180)
  • RtlLookupFunctionEntry (Address: 0x180008178)
  • RtlVirtualUnwind (Address: 0x180008170)
  • SetEvent (Address: 0x1800081a8)
  • SetFileAttributesW (Address: 0x180008100)
  • SetUnhandledExceptionFilter (Address: 0x180008160)
  • TerminateProcess (Address: 0x180008048)
  • UnhandledExceptionFilter (Address: 0x180008168)
  • UnmapViewOfFile (Address: 0x180008070)
  • VirtualQueryEx (Address: 0x1800080d0)
  • WaitForSingleObject (Address: 0x180008028)
  • WaitForSingleObjectEx (Address: 0x180008198)
MSVCP140.dll
  • ?_Syserror_map@std@@YAPEBDH@Z (Address: 0x1800081f0)
  • ?_Winerror_map@std@@YAHH@Z (Address: 0x180008200)
  • ?_Xlength_error@std@@YAXPEBD@Z (Address: 0x1800081f8)
  • ?_Xout_of_range@std@@YAXPEBD@Z (Address: 0x180008208)
VCRUNTIME140_1.dll
  • __CxxFrameHandler4 (Address: 0x180008260)
VCRUNTIME140.dll
  • __C_specific_handler (Address: 0x180008250)
  • __std_exception_copy (Address: 0x180008220)
  • __std_exception_destroy (Address: 0x180008228)
  • __std_type_info_destroy_list (Address: 0x180008248)
  • _CxxThrowException (Address: 0x180008238)
  • memcpy (Address: 0x180008218)
  • memmove (Address: 0x180008230)
  • memset (Address: 0x180008240)