thefinal.dll
Description:
Authors:
Version:
Architecture: 64-bit
Operating System:
SHA256: 0ee6bc20a7f855d881cce962de09c779
File Size: 300.0 KB
Uploaded At: Aug. 28, 2026, 4:31 p.m.
Views: 9
Security Warning
This file has been flagged as potentially dangerous.
Reason: Detected potentially dangerous functions used for process injection: CreateRemoteThread, WriteProcessMemory, OpenProcess, VirtualAllocEx
Exported Functions
- ReflectiveLoader (Ordinal: 1, Address: 0x194d4)
Imported DLLs & Functions
ADVAPI32.dll
- AdjustTokenPrivileges (Address: 0x180032098)
- AllocateAndInitializeSid (Address: 0x180032050)
- CheckTokenMembership (Address: 0x180032028)
- CreateProcessAsUserA (Address: 0x180032080)
- CreateProcessWithLogonW (Address: 0x180032078)
- CreateProcessWithTokenW (Address: 0x180032070)
- CryptAcquireContextA (Address: 0x180032018)
- CryptGenRandom (Address: 0x180032020)
- CryptReleaseContext (Address: 0x180032010)
- DuplicateTokenEx (Address: 0x180032030)
- FreeSid (Address: 0x180032048)
- GetTokenInformation (Address: 0x180032000)
- GetUserNameA (Address: 0x180032068)
- ImpersonateLoggedOnUser (Address: 0x180032088)
- ImpersonateNamedPipeClient (Address: 0x180032058)
- LogonUserA (Address: 0x180032038)
- LookupAccountSidA (Address: 0x180032040)
- LookupPrivilegeValueA (Address: 0x180032090)
- OpenProcessToken (Address: 0x180032008)
- OpenThreadToken (Address: 0x1800320a0)
- RevertToSelf (Address: 0x180032060)
KERNEL32.dll
- AreFileApisANSI (Address: 0x180032468)
- CloseHandle (Address: 0x180032268)
- CompareStringW (Address: 0x180032398)
- ConnectNamedPipe (Address: 0x180032238)
- CopyFileA (Address: 0x180032118)
- CreateDirectoryW (Address: 0x1800323d8)
- CreateFileA (Address: 0x180032188)
- CreateFileMappingA (Address: 0x180032288)
- CreateFileW (Address: 0x180032370)
- CreateNamedPipeA (Address: 0x1800320b0)
- CreatePipe (Address: 0x1800322e0)
- CreateProcessA (Address: 0x1800320c0)
- CreateRemoteThread (Address: 0x180032230)
- CreateThread (Address: 0x180032130)
- CreateToolhelp32Snapshot (Address: 0x180032138)
- DecodePointer (Address: 0x180032458)
- DeleteCriticalSection (Address: 0x1800324c8)
- DeleteFileW (Address: 0x1800323e0)
- DeleteProcThreadAttributeList (Address: 0x1800321d0)
- DisconnectNamedPipe (Address: 0x1800322d8)
- DuplicateHandle (Address: 0x180032270)
- EncodePointer (Address: 0x180032450)
- EnterCriticalSection (Address: 0x1800324b0)
- ExitProcess (Address: 0x180032290)
- ExitThread (Address: 0x180032298)
- ExpandEnvironmentStringsA (Address: 0x1800320f8)
- FileTimeToSystemTime (Address: 0x1800320f0)
- FindClose (Address: 0x1800320e0)
- FindFirstFileA (Address: 0x180032108)
- FindNextFileA (Address: 0x180032110)
- FlushFileBuffers (Address: 0x1800322f8)
- FreeEnvironmentStringsW (Address: 0x1800323b8)
- FreeLibrary (Address: 0x180032448)
- GetACP (Address: 0x1800321b0)
- GetCommandLineA (Address: 0x180032480)
- GetComputerNameA (Address: 0x1800321a0)
- GetComputerNameExA (Address: 0x180032200)
- GetConsoleCP (Address: 0x180032410)
- GetConsoleMode (Address: 0x180032408)
- GetCPInfo (Address: 0x180032420)
- GetCurrentDirectoryA (Address: 0x1800322c0)
- GetCurrentDirectoryW (Address: 0x1800320c8)
- GetCurrentProcess (Address: 0x1800322b0)
- GetCurrentProcessId (Address: 0x180032128)
- GetCurrentThread (Address: 0x1800322a8)
- GetCurrentThreadId (Address: 0x180032488)
- GetEnvironmentStringsW (Address: 0x1800323c0)
- GetFileAttributesA (Address: 0x180032100)
- GetFileType (Address: 0x1800323e8)
- GetFullPathNameA (Address: 0x1800320d0)
- GetLastError (Address: 0x180032328)
- GetLocalTime (Address: 0x1800322f0)
- GetLogicalDrives (Address: 0x1800320d8)
- GetModuleFileNameA (Address: 0x180032198)
- GetModuleFileNameW (Address: 0x180032498)
- GetModuleHandleA (Address: 0x180032318)
- GetModuleHandleExW (Address: 0x180032460)
- GetModuleHandleW (Address: 0x180032520)
- GetOEMCP (Address: 0x1800321b8)
- GetProcAddress (Address: 0x180032438)
- GetProcessHeap (Address: 0x1800321c0)
- GetStartupInfoA (Address: 0x1800322d0)
- GetStartupInfoW (Address: 0x180032518)
- GetStdHandle (Address: 0x180032490)
- GetStringTypeW (Address: 0x180032388)
- GetSystemTimeAsFileTime (Address: 0x180032470)
- GetThreadContext (Address: 0x180032250)
- GetTickCount (Address: 0x1800322e8)
- GetVersionExA (Address: 0x1800321a8)
- HeapAlloc (Address: 0x180032350)
- HeapCreate (Address: 0x180032360)
- HeapDestroy (Address: 0x180032358)
- HeapFree (Address: 0x180032330)
- HeapReAlloc (Address: 0x180032478)
- HeapSize (Address: 0x1800323a0)
- InitializeCriticalSectionAndSpinCount (Address: 0x1800324c0)
- InitializeProcThreadAttributeList (Address: 0x1800321c8)
- IsDebuggerPresent (Address: 0x1800324a0)
- IsProcessorFeaturePresent (Address: 0x1800324a8)
- IsValidCodePage (Address: 0x180032428)
- LCMapStringW (Address: 0x180032390)
- LeaveCriticalSection (Address: 0x1800324b8)
- LoadLibraryA (Address: 0x180032320)
- LoadLibraryExW (Address: 0x180032528)
- LoadLibraryW (Address: 0x1800323a8)
- MapViewOfFile (Address: 0x180032278)
- MoveFileA (Address: 0x180032120)
- MultiByteToWideChar (Address: 0x1800322b8)
- OpenProcess (Address: 0x180032228)
- OpenThread (Address: 0x180032440)
- OutputDebugStringW (Address: 0x1800323b0)
- PeekNamedPipe (Address: 0x180032180)
- Process32First (Address: 0x1800321f0)
- Process32Next (Address: 0x1800321f8)
- ProcessIdToSessionId (Address: 0x1800321e8)
- QueryPerformanceCounter (Address: 0x1800323c8)
- RaiseException (Address: 0x180032338)
- ReadConsoleW (Address: 0x180032400)
- ReadFile (Address: 0x1800322a0)
- ReadProcessMemory (Address: 0x180032240)
- RemoveDirectoryW (Address: 0x1800323d0)
- ResumeThread (Address: 0x180032260)
- RtlCaptureContext (Address: 0x1800324d0)
- RtlLookupFunctionEntry (Address: 0x1800324d8)
- RtlUnwindEx (Address: 0x180032430)
- RtlVirtualUnwind (Address: 0x1800324e0)
- SetCurrentDirectoryA (Address: 0x1800322c8)
- SetEndOfFile (Address: 0x180032368)
- SetEnvironmentVariableA (Address: 0x180032348)
- SetEnvironmentVariableW (Address: 0x180032340)
- SetErrorMode (Address: 0x1800321d8)
- SetFilePointer (Address: 0x1800323f8)
- SetFilePointerEx (Address: 0x1800323f0)
- SetLastError (Address: 0x180032170)
- SetNamedPipeHandleState (Address: 0x180032178)
- SetStdHandle (Address: 0x180032380)
- SetThreadContext (Address: 0x180032258)
- SetUnhandledExceptionFilter (Address: 0x1800324f0)
- Sleep (Address: 0x180032310)
- SystemTimeToTzSpecificLocalTime (Address: 0x1800320e8)
- TerminateProcess (Address: 0x1800320b8)
- Thread32First (Address: 0x180032140)
- Thread32Next (Address: 0x180032148)
- TlsAlloc (Address: 0x1800324f8)
- TlsFree (Address: 0x180032510)
- TlsGetValue (Address: 0x180032500)
- TlsSetValue (Address: 0x180032508)
- UnhandledExceptionFilter (Address: 0x1800324e8)
- UnmapViewOfFile (Address: 0x180032280)
- UpdateProcThreadAttribute (Address: 0x1800321e0)
- VirtualAlloc (Address: 0x180032160)
- VirtualAllocEx (Address: 0x180032218)
- VirtualFree (Address: 0x180032208)
- VirtualProtect (Address: 0x180032168)
- VirtualProtectEx (Address: 0x180032220)
- VirtualQuery (Address: 0x180032210)
- WaitForSingleObject (Address: 0x180032308)
- WaitNamedPipeA (Address: 0x180032190)
- WideCharToMultiByte (Address: 0x180032418)
- Wow64GetThreadContext (Address: 0x180032150)
- Wow64SetThreadContext (Address: 0x180032158)
- WriteConsoleW (Address: 0x180032378)
- WriteFile (Address: 0x180032300)
- WriteProcessMemory (Address: 0x180032248)
WININET.dll
- HttpAddRequestHeadersA (Address: 0x180032578)
- HttpOpenRequestA (Address: 0x180032570)
- HttpQueryInfoA (Address: 0x180032588)
- HttpSendRequestA (Address: 0x180032580)
- InternetCloseHandle (Address: 0x180032540)
- InternetConnectA (Address: 0x180032548)
- InternetOpenA (Address: 0x180032590)
- InternetQueryDataAvailable (Address: 0x180032550)
- InternetQueryOptionA (Address: 0x180032558)
- InternetReadFile (Address: 0x180032538)
- InternetSetOptionA (Address: 0x180032560)
- InternetSetStatusCallback (Address: 0x180032568)
WS2_32.dll
- __WSAFDIsSet (Address: 0x180032620)
- accept (Address: 0x180032628)
- bind (Address: 0x180032630)
- closesocket (Address: 0x1800325e8)
- connect (Address: 0x1800325c0)
- gethostbyname (Address: 0x1800325a8)
- htonl (Address: 0x180032600)
- htons (Address: 0x1800325f8)
- inet_addr (Address: 0x180032638)
- ioctlsocket (Address: 0x1800325c8)
- listen (Address: 0x180032640)
- ntohl (Address: 0x1800325f0)
- ntohs (Address: 0x1800325a0)
- recv (Address: 0x180032608)
- recvfrom (Address: 0x180032648)
- select (Address: 0x180032650)
- send (Address: 0x1800325b8)
- sendto (Address: 0x180032658)
- shutdown (Address: 0x180032610)
- socket (Address: 0x1800325b0)
- WSACleanup (Address: 0x1800325d8)
- WSAGetLastError (Address: 0x180032618)
- WSAIoctl (Address: 0x1800325d0)
- WSASocketA (Address: 0x180032660)
- WSAStartup (Address: 0x1800325e0)