client.dll

Description: [File deleted after analysis due to size limit > 20MB]

Authors:

Version:

Architecture: 64-bit

Operating System:

SHA256: 1c5344440171f60574dd2613edbeeca7

File Size: 35.6 MB

Uploaded At: July 20, 2026, 12:03 a.m.

Views: 6

Security Warning

This file has been flagged as potentially dangerous.


Reason: Detected potentially dangerous functions used for process injection: OpenProcess

Exported Functions

  • GetLCExport (Ordinal: 1, Address: 0xdb40)

Imported DLLs & Functions

ADVAPI32.dll
  • QueryServiceStatus (Address: 0x181c96020)
api-ms-win-crt-convert-l1-1-0.dll
  • _wtoi (Address: 0x181c96160)
api-ms-win-crt-environment-l1-1-0.dll
  • _putenv (Address: 0x181c96170)
api-ms-win-crt-filesystem-l1-1-0.dll
  • _unlock_file (Address: 0x181c96100)
api-ms-win-crt-heap-l1-1-0.dll
  • calloc (Address: 0x181c960e0)
api-ms-win-crt-locale-l1-1-0.dll
  • ___lc_codepage_func (Address: 0x181c96150)
api-ms-win-crt-math-l1-1-0.dll
  • _dsign (Address: 0x181c96140)
api-ms-win-crt-runtime-l1-1-0.dll
  • exit (Address: 0x181c96130)
api-ms-win-crt-stdio-l1-1-0.dll
  • _popen (Address: 0x181c960d0)
api-ms-win-crt-string-l1-1-0.dll
  • _wcsicmp (Address: 0x181c96110)
api-ms-win-crt-time-l1-1-0.dll
  • strftime (Address: 0x181c96120)
api-ms-win-crt-utility-l1-1-0.dll
  • srand (Address: 0x181c960f0)
KERNEL32.dll
  • OpenProcess (Address: 0x181c96000)
MSVCP140.dll
  • ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z (Address: 0x181c96060)
ncrypt.dll
  • NCryptFreeObject (Address: 0x181c96090)
ntdll.dll
  • LdrGetProcedureAddress (Address: 0x181c96080)
ole32.dll
  • CoInitializeSecurity (Address: 0x181c96040)
OLEAUT32.dll
  • SysAllocString (Address: 0x181c96050)
SHELL32.dll
  • (Address: 0x181c96030)
USER32.dll
  • GetWindowThreadProcessId (Address: 0x181c96010)
VCRUNTIME140_1.dll
  • __CxxFrameHandler4 (Address: 0x181c960b0)
VCRUNTIME140.dll
  • memmove (Address: 0x181c960c0)
WINHTTP.dll
  • WinHttpGetProxyForUrl (Address: 0x181c960a0)
WINMM.dll
  • timeGetTime (Address: 0x181c96070)