thefinal.dll

Description:

Authors:

Version:

Architecture: 64-bit

Operating System:

SHA256: 0ee6bc20a7f855d881cce962de09c779

File Size: 300.0 KB

Uploaded At: Aug. 28, 2026, 4:31 p.m.

Views: 9

Security Warning

This file has been flagged as potentially dangerous.


Reason: Detected potentially dangerous functions used for process injection: CreateRemoteThread, WriteProcessMemory, OpenProcess, VirtualAllocEx

Exported Functions

  • ReflectiveLoader (Ordinal: 1, Address: 0x194d4)

Imported DLLs & Functions

ADVAPI32.dll
  • AdjustTokenPrivileges (Address: 0x180032098)
  • AllocateAndInitializeSid (Address: 0x180032050)
  • CheckTokenMembership (Address: 0x180032028)
  • CreateProcessAsUserA (Address: 0x180032080)
  • CreateProcessWithLogonW (Address: 0x180032078)
  • CreateProcessWithTokenW (Address: 0x180032070)
  • CryptAcquireContextA (Address: 0x180032018)
  • CryptGenRandom (Address: 0x180032020)
  • CryptReleaseContext (Address: 0x180032010)
  • DuplicateTokenEx (Address: 0x180032030)
  • FreeSid (Address: 0x180032048)
  • GetTokenInformation (Address: 0x180032000)
  • GetUserNameA (Address: 0x180032068)
  • ImpersonateLoggedOnUser (Address: 0x180032088)
  • ImpersonateNamedPipeClient (Address: 0x180032058)
  • LogonUserA (Address: 0x180032038)
  • LookupAccountSidA (Address: 0x180032040)
  • LookupPrivilegeValueA (Address: 0x180032090)
  • OpenProcessToken (Address: 0x180032008)
  • OpenThreadToken (Address: 0x1800320a0)
  • RevertToSelf (Address: 0x180032060)
KERNEL32.dll
  • AreFileApisANSI (Address: 0x180032468)
  • CloseHandle (Address: 0x180032268)
  • CompareStringW (Address: 0x180032398)
  • ConnectNamedPipe (Address: 0x180032238)
  • CopyFileA (Address: 0x180032118)
  • CreateDirectoryW (Address: 0x1800323d8)
  • CreateFileA (Address: 0x180032188)
  • CreateFileMappingA (Address: 0x180032288)
  • CreateFileW (Address: 0x180032370)
  • CreateNamedPipeA (Address: 0x1800320b0)
  • CreatePipe (Address: 0x1800322e0)
  • CreateProcessA (Address: 0x1800320c0)
  • CreateRemoteThread (Address: 0x180032230)
  • CreateThread (Address: 0x180032130)
  • CreateToolhelp32Snapshot (Address: 0x180032138)
  • DecodePointer (Address: 0x180032458)
  • DeleteCriticalSection (Address: 0x1800324c8)
  • DeleteFileW (Address: 0x1800323e0)
  • DeleteProcThreadAttributeList (Address: 0x1800321d0)
  • DisconnectNamedPipe (Address: 0x1800322d8)
  • DuplicateHandle (Address: 0x180032270)
  • EncodePointer (Address: 0x180032450)
  • EnterCriticalSection (Address: 0x1800324b0)
  • ExitProcess (Address: 0x180032290)
  • ExitThread (Address: 0x180032298)
  • ExpandEnvironmentStringsA (Address: 0x1800320f8)
  • FileTimeToSystemTime (Address: 0x1800320f0)
  • FindClose (Address: 0x1800320e0)
  • FindFirstFileA (Address: 0x180032108)
  • FindNextFileA (Address: 0x180032110)
  • FlushFileBuffers (Address: 0x1800322f8)
  • FreeEnvironmentStringsW (Address: 0x1800323b8)
  • FreeLibrary (Address: 0x180032448)
  • GetACP (Address: 0x1800321b0)
  • GetCommandLineA (Address: 0x180032480)
  • GetComputerNameA (Address: 0x1800321a0)
  • GetComputerNameExA (Address: 0x180032200)
  • GetConsoleCP (Address: 0x180032410)
  • GetConsoleMode (Address: 0x180032408)
  • GetCPInfo (Address: 0x180032420)
  • GetCurrentDirectoryA (Address: 0x1800322c0)
  • GetCurrentDirectoryW (Address: 0x1800320c8)
  • GetCurrentProcess (Address: 0x1800322b0)
  • GetCurrentProcessId (Address: 0x180032128)
  • GetCurrentThread (Address: 0x1800322a8)
  • GetCurrentThreadId (Address: 0x180032488)
  • GetEnvironmentStringsW (Address: 0x1800323c0)
  • GetFileAttributesA (Address: 0x180032100)
  • GetFileType (Address: 0x1800323e8)
  • GetFullPathNameA (Address: 0x1800320d0)
  • GetLastError (Address: 0x180032328)
  • GetLocalTime (Address: 0x1800322f0)
  • GetLogicalDrives (Address: 0x1800320d8)
  • GetModuleFileNameA (Address: 0x180032198)
  • GetModuleFileNameW (Address: 0x180032498)
  • GetModuleHandleA (Address: 0x180032318)
  • GetModuleHandleExW (Address: 0x180032460)
  • GetModuleHandleW (Address: 0x180032520)
  • GetOEMCP (Address: 0x1800321b8)
  • GetProcAddress (Address: 0x180032438)
  • GetProcessHeap (Address: 0x1800321c0)
  • GetStartupInfoA (Address: 0x1800322d0)
  • GetStartupInfoW (Address: 0x180032518)
  • GetStdHandle (Address: 0x180032490)
  • GetStringTypeW (Address: 0x180032388)
  • GetSystemTimeAsFileTime (Address: 0x180032470)
  • GetThreadContext (Address: 0x180032250)
  • GetTickCount (Address: 0x1800322e8)
  • GetVersionExA (Address: 0x1800321a8)
  • HeapAlloc (Address: 0x180032350)
  • HeapCreate (Address: 0x180032360)
  • HeapDestroy (Address: 0x180032358)
  • HeapFree (Address: 0x180032330)
  • HeapReAlloc (Address: 0x180032478)
  • HeapSize (Address: 0x1800323a0)
  • InitializeCriticalSectionAndSpinCount (Address: 0x1800324c0)
  • InitializeProcThreadAttributeList (Address: 0x1800321c8)
  • IsDebuggerPresent (Address: 0x1800324a0)
  • IsProcessorFeaturePresent (Address: 0x1800324a8)
  • IsValidCodePage (Address: 0x180032428)
  • LCMapStringW (Address: 0x180032390)
  • LeaveCriticalSection (Address: 0x1800324b8)
  • LoadLibraryA (Address: 0x180032320)
  • LoadLibraryExW (Address: 0x180032528)
  • LoadLibraryW (Address: 0x1800323a8)
  • MapViewOfFile (Address: 0x180032278)
  • MoveFileA (Address: 0x180032120)
  • MultiByteToWideChar (Address: 0x1800322b8)
  • OpenProcess (Address: 0x180032228)
  • OpenThread (Address: 0x180032440)
  • OutputDebugStringW (Address: 0x1800323b0)
  • PeekNamedPipe (Address: 0x180032180)
  • Process32First (Address: 0x1800321f0)
  • Process32Next (Address: 0x1800321f8)
  • ProcessIdToSessionId (Address: 0x1800321e8)
  • QueryPerformanceCounter (Address: 0x1800323c8)
  • RaiseException (Address: 0x180032338)
  • ReadConsoleW (Address: 0x180032400)
  • ReadFile (Address: 0x1800322a0)
  • ReadProcessMemory (Address: 0x180032240)
  • RemoveDirectoryW (Address: 0x1800323d0)
  • ResumeThread (Address: 0x180032260)
  • RtlCaptureContext (Address: 0x1800324d0)
  • RtlLookupFunctionEntry (Address: 0x1800324d8)
  • RtlUnwindEx (Address: 0x180032430)
  • RtlVirtualUnwind (Address: 0x1800324e0)
  • SetCurrentDirectoryA (Address: 0x1800322c8)
  • SetEndOfFile (Address: 0x180032368)
  • SetEnvironmentVariableA (Address: 0x180032348)
  • SetEnvironmentVariableW (Address: 0x180032340)
  • SetErrorMode (Address: 0x1800321d8)
  • SetFilePointer (Address: 0x1800323f8)
  • SetFilePointerEx (Address: 0x1800323f0)
  • SetLastError (Address: 0x180032170)
  • SetNamedPipeHandleState (Address: 0x180032178)
  • SetStdHandle (Address: 0x180032380)
  • SetThreadContext (Address: 0x180032258)
  • SetUnhandledExceptionFilter (Address: 0x1800324f0)
  • Sleep (Address: 0x180032310)
  • SystemTimeToTzSpecificLocalTime (Address: 0x1800320e8)
  • TerminateProcess (Address: 0x1800320b8)
  • Thread32First (Address: 0x180032140)
  • Thread32Next (Address: 0x180032148)
  • TlsAlloc (Address: 0x1800324f8)
  • TlsFree (Address: 0x180032510)
  • TlsGetValue (Address: 0x180032500)
  • TlsSetValue (Address: 0x180032508)
  • UnhandledExceptionFilter (Address: 0x1800324e8)
  • UnmapViewOfFile (Address: 0x180032280)
  • UpdateProcThreadAttribute (Address: 0x1800321e0)
  • VirtualAlloc (Address: 0x180032160)
  • VirtualAllocEx (Address: 0x180032218)
  • VirtualFree (Address: 0x180032208)
  • VirtualProtect (Address: 0x180032168)
  • VirtualProtectEx (Address: 0x180032220)
  • VirtualQuery (Address: 0x180032210)
  • WaitForSingleObject (Address: 0x180032308)
  • WaitNamedPipeA (Address: 0x180032190)
  • WideCharToMultiByte (Address: 0x180032418)
  • Wow64GetThreadContext (Address: 0x180032150)
  • Wow64SetThreadContext (Address: 0x180032158)
  • WriteConsoleW (Address: 0x180032378)
  • WriteFile (Address: 0x180032300)
  • WriteProcessMemory (Address: 0x180032248)
WININET.dll
  • HttpAddRequestHeadersA (Address: 0x180032578)
  • HttpOpenRequestA (Address: 0x180032570)
  • HttpQueryInfoA (Address: 0x180032588)
  • HttpSendRequestA (Address: 0x180032580)
  • InternetCloseHandle (Address: 0x180032540)
  • InternetConnectA (Address: 0x180032548)
  • InternetOpenA (Address: 0x180032590)
  • InternetQueryDataAvailable (Address: 0x180032550)
  • InternetQueryOptionA (Address: 0x180032558)
  • InternetReadFile (Address: 0x180032538)
  • InternetSetOptionA (Address: 0x180032560)
  • InternetSetStatusCallback (Address: 0x180032568)
WS2_32.dll
  • __WSAFDIsSet (Address: 0x180032620)
  • accept (Address: 0x180032628)
  • bind (Address: 0x180032630)
  • closesocket (Address: 0x1800325e8)
  • connect (Address: 0x1800325c0)
  • gethostbyname (Address: 0x1800325a8)
  • htonl (Address: 0x180032600)
  • htons (Address: 0x1800325f8)
  • inet_addr (Address: 0x180032638)
  • ioctlsocket (Address: 0x1800325c8)
  • listen (Address: 0x180032640)
  • ntohl (Address: 0x1800325f0)
  • ntohs (Address: 0x1800325a0)
  • recv (Address: 0x180032608)
  • recvfrom (Address: 0x180032648)
  • select (Address: 0x180032650)
  • send (Address: 0x1800325b8)
  • sendto (Address: 0x180032658)
  • shutdown (Address: 0x180032610)
  • socket (Address: 0x1800325b0)
  • WSACleanup (Address: 0x1800325d8)
  • WSAGetLastError (Address: 0x180032618)
  • WSAIoctl (Address: 0x1800325d0)
  • WSASocketA (Address: 0x180032660)
  • WSAStartup (Address: 0x1800325e0)