XblAuthManager.dll

Description: Xbox Live Auth Manager

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.5794

Architecture: 64-bit

Operating System: Windows NT

SHA256: 77c45619934e5ce58a72f81ba1691219

File Size: 1.0 MB

Uploaded At: Dec. 1, 2025, 7:46 a.m.

Views: 6

Security Warning

This file has been flagged as potentially dangerous.


Reason: Detected potentially dangerous functions used for process injection: OpenProcess

Exported Functions

  • ServiceMain (Ordinal: 1, Address: 0x98b0)

Imported DLLs & Functions

api-ms-win-appmodel-identity-l1-2-0.dll
  • AppContainerDeriveSidFromMoniker (Address: 0x1800d66e8)
api-ms-win-appmodel-runtime-l1-1-0.dll
  • GetPackageFamilyName (Address: 0x1800d6700)
  • GetPackagesByPackageFamily (Address: 0x1800d66f8)
api-ms-win-core-apiquery-l1-1-0.dll
  • ApiSetQueryApiSetPresence (Address: 0x1800d6710)
api-ms-win-core-com-l1-1-0.dll
  • CoAddRefServerProcess (Address: 0x1800d6780)
  • CoCreateFreeThreadedMarshaler (Address: 0x1800d67b0)
  • CoCreateGuid (Address: 0x1800d6758)
  • CoCreateInstance (Address: 0x1800d6750)
  • CoDecrementMTAUsage (Address: 0x1800d6738)
  • CoDisconnectContext (Address: 0x1800d6790)
  • CoGetCallContext (Address: 0x1800d6740)
  • CoGetStandardMarshal (Address: 0x1800d67a0)
  • CoImpersonateClient (Address: 0x1800d6748)
  • CoInitializeSecurity (Address: 0x1800d6720)
  • CoRegisterClassObject (Address: 0x1800d6728)
  • CoReleaseServerProcess (Address: 0x1800d6768)
  • CoResumeClassObjects (Address: 0x1800d67a8)
  • CoRevertToSelf (Address: 0x1800d6788)
  • CoRevokeClassObject (Address: 0x1800d6798)
  • CoTaskMemAlloc (Address: 0x1800d6760)
  • CoTaskMemFree (Address: 0x1800d6730)
  • CoWaitForMultipleHandles (Address: 0x1800d6770)
  • StringFromGUID2 (Address: 0x1800d6778)
api-ms-win-core-debug-l1-1-0.dll
  • DebugBreak (Address: 0x1800d67d0)
  • IsDebuggerPresent (Address: 0x1800d67c0)
  • OutputDebugStringW (Address: 0x1800d67c8)
api-ms-win-core-delayload-l1-1-0.dll
  • DelayLoadFailureHook (Address: 0x1800d67e0)
api-ms-win-core-delayload-l1-1-1.dll
  • ResolveDelayLoadedAPI (Address: 0x1800d67f0)
api-ms-win-core-errorhandling-l1-1-0.dll
  • GetLastError (Address: 0x1800d6800)
  • RaiseException (Address: 0x1800d6820)
  • SetLastError (Address: 0x1800d6810)
  • SetUnhandledExceptionFilter (Address: 0x1800d6818)
  • UnhandledExceptionFilter (Address: 0x1800d6808)
api-ms-win-core-file-l1-1-0.dll
  • CreateDirectoryW (Address: 0x1800d6850)
  • CreateFileW (Address: 0x1800d6860)
  • DeleteFileW (Address: 0x1800d6858)
  • FindClose (Address: 0x1800d6878)
  • FindFirstFileW (Address: 0x1800d6870)
  • FindNextFileW (Address: 0x1800d6880)
  • GetFileAttributesExW (Address: 0x1800d6830)
  • GetFileAttributesW (Address: 0x1800d6848)
  • GetFileSize (Address: 0x1800d6840)
  • ReadFile (Address: 0x1800d6868)
  • WriteFile (Address: 0x1800d6838)
api-ms-win-core-handle-l1-1-0.dll
  • CloseHandle (Address: 0x1800d6890)
api-ms-win-core-heap-l1-1-0.dll
  • GetProcessHeap (Address: 0x1800d68a8)
  • HeapAlloc (Address: 0x1800d68a0)
  • HeapFree (Address: 0x1800d68b0)
api-ms-win-core-heap-l2-1-0.dll
  • LocalFree (Address: 0x1800d68c0)
api-ms-win-core-interlocked-l1-1-0.dll
  • InitializeSListHead (Address: 0x1800d68d0)
api-ms-win-core-libraryloader-l1-2-0.dll
  • DisableThreadLibraryCalls (Address: 0x1800d6900)
  • GetModuleFileNameA (Address: 0x1800d68f8)
  • GetModuleHandleExW (Address: 0x1800d68e8)
  • GetModuleHandleW (Address: 0x1800d68e0)
  • GetProcAddress (Address: 0x1800d68f0)
api-ms-win-core-localization-l1-2-0.dll
  • FormatMessageW (Address: 0x1800d6910)
api-ms-win-core-memory-l1-1-0.dll
  • CreateFileMappingW (Address: 0x1800d6928)
  • MapViewOfFile (Address: 0x1800d6930)
  • UnmapViewOfFile (Address: 0x1800d6920)
api-ms-win-core-processenvironment-l1-1-0.dll
  • ExpandEnvironmentStringsW (Address: 0x1800d6940)
api-ms-win-core-processthreads-l1-1-0.dll
  • GetCurrentProcess (Address: 0x1800d6950)
  • GetCurrentProcessId (Address: 0x1800d6968)
  • GetCurrentThread (Address: 0x1800d6970)
  • GetCurrentThreadId (Address: 0x1800d6960)
  • OpenProcessToken (Address: 0x1800d6978)
  • OpenThreadToken (Address: 0x1800d6988)
  • SetThreadToken (Address: 0x1800d6980)
  • TerminateProcess (Address: 0x1800d6958)
api-ms-win-core-processthreads-l1-1-1.dll
  • IsProcessorFeaturePresent (Address: 0x1800d6998)
  • OpenProcess (Address: 0x1800d69a0)
api-ms-win-core-profile-l1-1-0.dll
  • QueryPerformanceCounter (Address: 0x1800d69b8)
  • QueryPerformanceFrequency (Address: 0x1800d69b0)
api-ms-win-core-psapi-l1-1-0.dll
  • K32GetModuleFileNameExW (Address: 0x1800d69c8)
api-ms-win-core-registry-l1-1-0.dll
  • RegCloseKey (Address: 0x1800d69f0)
  • RegCreateKeyExW (Address: 0x1800d6a18)
  • RegDeleteKeyExW (Address: 0x1800d69d8)
  • RegDeleteTreeW (Address: 0x1800d6a38)
  • RegDeleteValueW (Address: 0x1800d69e8)
  • RegEnumKeyExW (Address: 0x1800d6a10)
  • RegEnumValueW (Address: 0x1800d6a30)
  • RegGetValueW (Address: 0x1800d6a28)
  • RegOpenCurrentUser (Address: 0x1800d69e0)
  • RegOpenKeyExW (Address: 0x1800d6a00)
  • RegQueryInfoKeyW (Address: 0x1800d6a08)
  • RegQueryValueExW (Address: 0x1800d69f8)
  • RegSetValueExW (Address: 0x1800d6a20)
api-ms-win-core-registry-l1-1-1.dll
  • RegDeleteKeyValueW (Address: 0x1800d6a48)
  • RegSetKeyValueW (Address: 0x1800d6a50)
api-ms-win-core-rtlsupport-l1-1-0.dll
  • RtlCaptureContext (Address: 0x1800d6a70)
  • RtlLookupFunctionEntry (Address: 0x1800d6a60)
  • RtlVirtualUnwind (Address: 0x1800d6a68)
api-ms-win-core-shutdown-l1-1-0.dll
  • InitiateSystemShutdownExW (Address: 0x1800d6a80)
api-ms-win-core-string-l1-1-0.dll
  • CompareStringOrdinal (Address: 0x1800d6a98)
  • MultiByteToWideChar (Address: 0x1800d6aa0)
  • WideCharToMultiByte (Address: 0x1800d6a90)
api-ms-win-core-synch-l1-1-0.dll
  • AcquireSRWLockExclusive (Address: 0x1800d6ae8)
  • AcquireSRWLockShared (Address: 0x1800d6b08)
  • CreateEventExW (Address: 0x1800d6ae0)
  • CreateEventW (Address: 0x1800d6b28)
  • CreateMutexExW (Address: 0x1800d6b00)
  • CreateSemaphoreExW (Address: 0x1800d6ab8)
  • DeleteCriticalSection (Address: 0x1800d6b30)
  • EnterCriticalSection (Address: 0x1800d6b20)
  • InitializeCriticalSection (Address: 0x1800d6b50)
  • InitializeCriticalSectionAndSpinCount (Address: 0x1800d6b40)
  • InitializeCriticalSectionEx (Address: 0x1800d6b48)
  • InitializeSRWLock (Address: 0x1800d6ab0)
  • LeaveCriticalSection (Address: 0x1800d6b18)
  • OpenSemaphoreW (Address: 0x1800d6ac8)
  • ReleaseMutex (Address: 0x1800d6ad8)
  • ReleaseSemaphore (Address: 0x1800d6ac0)
  • ReleaseSRWLockExclusive (Address: 0x1800d6b10)
  • ReleaseSRWLockShared (Address: 0x1800d6af0)
  • ResetEvent (Address: 0x1800d6b38)
  • SetEvent (Address: 0x1800d6af8)
  • WaitForMultipleObjectsEx (Address: 0x1800d6b58)
  • WaitForSingleObject (Address: 0x1800d6ad0)
  • WaitForSingleObjectEx (Address: 0x1800d6b60)
api-ms-win-core-synch-l1-2-0.dll
  • InitOnceExecuteOnce (Address: 0x1800d6b78)
  • Sleep (Address: 0x1800d6b70)
api-ms-win-core-sysinfo-l1-1-0.dll
  • GetSystemTime (Address: 0x1800d6b98)
  • GetSystemTimeAsFileTime (Address: 0x1800d6b88)
  • GetTickCount64 (Address: 0x1800d6b90)
api-ms-win-core-threadpool-l1-2-0.dll
  • CloseThreadpoolTimer (Address: 0x1800d6ba8)
  • CreateThreadpoolTimer (Address: 0x1800d6bc0)
  • SetThreadpoolTimer (Address: 0x1800d6bb0)
  • WaitForThreadpoolTimerCallbacks (Address: 0x1800d6bb8)
api-ms-win-core-threadpool-legacy-l1-1-0.dll
  • ChangeTimerQueueTimer (Address: 0x1800d6be0)
  • CreateTimerQueueTimer (Address: 0x1800d6bd8)
  • DeleteTimerQueueTimer (Address: 0x1800d6bd0)
  • QueueUserWorkItem (Address: 0x1800d6be8)
api-ms-win-core-util-l1-1-0.dll
  • DecodePointer (Address: 0x1800d6bf8)
  • EncodePointer (Address: 0x1800d6c00)
api-ms-win-core-winrt-error-l1-1-0.dll
  • RoOriginateError (Address: 0x1800d6c20)
  • RoOriginateErrorW (Address: 0x1800d6c10)
  • RoTransformError (Address: 0x1800d6c18)
api-ms-win-core-winrt-l1-1-0.dll
  • RoActivateInstance (Address: 0x1800d6c30)
  • RoGetActivationFactory (Address: 0x1800d6c50)
  • RoInitialize (Address: 0x1800d6c38)
  • RoRegisterActivationFactories (Address: 0x1800d6c58)
  • RoRevokeActivationFactories (Address: 0x1800d6c48)
  • RoUninitialize (Address: 0x1800d6c40)
api-ms-win-core-winrt-string-l1-1-0.dll
  • WindowsCompareStringOrdinal (Address: 0x1800d6c80)
  • WindowsCreateString (Address: 0x1800d6c90)
  • WindowsCreateStringReference (Address: 0x1800d6c68)
  • WindowsDeleteString (Address: 0x1800d6ca0)
  • WindowsDuplicateString (Address: 0x1800d6c70)
  • WindowsGetStringLen (Address: 0x1800d6ca8)
  • WindowsGetStringRawBuffer (Address: 0x1800d6c98)
  • WindowsIsStringEmpty (Address: 0x1800d6c78)
  • WindowsStringHasEmbeddedNull (Address: 0x1800d6c88)
api-ms-win-crt-private-l1-1-0.dll
  • __C_specific_handler (Address: 0x1800d6d78)
  • __CxxFrameHandler3 (Address: 0x1800d6d80)
  • __CxxFrameHandler4 (Address: 0x1800d6e18)
  • __std_terminate (Address: 0x1800d6e10)
  • _CxxThrowException (Address: 0x1800d6d88)
  • _o___std_exception_copy (Address: 0x1800d6e08)
  • _o___std_exception_destroy (Address: 0x1800d6e00)
  • _o___std_type_info_destroy_list (Address: 0x1800d6df8)
  • _o___stdio_common_vsnprintf_s (Address: 0x1800d6df0)
  • _o___stdio_common_vswprintf (Address: 0x1800d6de8)
  • _o__callnewh (Address: 0x1800d6db8)
  • _o__cexit (Address: 0x1800d6db0)
  • _o__configure_narrow_argv (Address: 0x1800d6da0)
  • _o__crt_atexit (Address: 0x1800d6d90)
  • _o__errno (Address: 0x1800d6da8)
  • _o__execute_onexit_table (Address: 0x1800d6d98)
  • _o__i64tow_s (Address: 0x1800d6cb8)
  • _o__initialize_narrow_environment (Address: 0x1800d6cc0)
  • _o__initialize_onexit_table (Address: 0x1800d6cc8)
  • _o__invalid_parameter_noinfo (Address: 0x1800d6cd0)
  • _o__invalid_parameter_noinfo_noreturn (Address: 0x1800d6cd8)
  • _o__mkgmtime64 (Address: 0x1800d6ce0)
  • _o__purecall (Address: 0x1800d6ce8)
  • _o__register_onexit_function (Address: 0x1800d6cf0)
  • _o__seh_filter_dll (Address: 0x1800d6cf8)
  • _o__wcsicmp (Address: 0x1800d6d00)
  • _o__wcsnicmp (Address: 0x1800d6d08)
  • _o__wcstoui64 (Address: 0x1800d6d10)
  • _o__wctime64_s (Address: 0x1800d6d18)
  • _o__wtoi64 (Address: 0x1800d6d28)
  • _o_free (Address: 0x1800d6d30)
  • _o_iswdigit (Address: 0x1800d6d38)
  • _o_malloc (Address: 0x1800d6d40)
  • _o_realloc (Address: 0x1800d6d48)
  • _o_terminate (Address: 0x1800d6d50)
  • _o_towlower (Address: 0x1800d6d58)
  • _o_towupper (Address: 0x1800d6d60)
  • _o_wcstol (Address: 0x1800d6d68)
  • _o_wcstoul (Address: 0x1800d6d70)
  • memcmp (Address: 0x1800d6e20)
  • memcpy (Address: 0x1800d6e28)
  • memmove (Address: 0x1800d6d20)
  • strchr (Address: 0x1800d6dd8)
  • strrchr (Address: 0x1800d6dc0)
  • wcschr (Address: 0x1800d6dd0)
  • wcsrchr (Address: 0x1800d6de0)
  • wcsstr (Address: 0x1800d6dc8)
api-ms-win-crt-runtime-l1-1-0.dll
  • _initterm (Address: 0x1800d6e38)
  • _initterm_e (Address: 0x1800d6e40)
api-ms-win-crt-string-l1-1-0.dll
  • memset (Address: 0x1800d6e68)
  • wcscmp (Address: 0x1800d6e50)
  • wcsncmp (Address: 0x1800d6e58)
  • wcsnlen (Address: 0x1800d6e60)
api-ms-win-crt-time-l1-1-0.dll
  • _time64 (Address: 0x1800d6e78)
api-ms-win-eventing-provider-l1-1-0.dll
  • EventRegister (Address: 0x1800d6e90)
  • EventSetInformation (Address: 0x1800d6e98)
  • EventUnregister (Address: 0x1800d6ea0)
  • EventWriteTransfer (Address: 0x1800d6e88)
api-ms-win-power-setting-l1-1-0.dll
  • PowerSettingRegisterNotification (Address: 0x1800d6eb8)
  • PowerSettingUnregisterNotification (Address: 0x1800d6eb0)
api-ms-win-security-base-l1-1-0.dll
  • AdjustTokenPrivileges (Address: 0x1800d6ef0)
  • DuplicateToken (Address: 0x1800d6ef8)
  • DuplicateTokenEx (Address: 0x1800d6ee8)
  • GetTokenInformation (Address: 0x1800d6ee0)
  • ImpersonateLoggedOnUser (Address: 0x1800d6ed0)
  • MakeAbsoluteSD (Address: 0x1800d6ed8)
  • RevertToSelf (Address: 0x1800d6ec8)
api-ms-win-security-capability-l1-1-0.dll
  • CapabilityCheck (Address: 0x1800d6f08)
api-ms-win-security-credentials-l1-1-0.dll
  • CredDeleteW (Address: 0x1800d6f20)
  • CredFree (Address: 0x1800d6f28)
  • CredReadW (Address: 0x1800d6f30)
  • CredWriteW (Address: 0x1800d6f18)
api-ms-win-security-lsalookup-l2-1-0.dll
  • LookupPrivilegeValueW (Address: 0x1800d6f40)
api-ms-win-security-sddl-l1-1-0.dll
  • ConvertSidToStringSidW (Address: 0x1800d6f58)
  • ConvertStringSecurityDescriptorToSecurityDescriptorW (Address: 0x1800d6f50)
api-ms-win-service-core-l1-1-0.dll
  • RegisterServiceCtrlHandlerExW (Address: 0x1800d6f70)
  • SetServiceStatus (Address: 0x1800d6f68)
api-ms-win-service-management-l1-1-0.dll
  • CloseServiceHandle (Address: 0x1800d6f98)
  • OpenSCManagerW (Address: 0x1800d6f90)
  • OpenServiceW (Address: 0x1800d6f88)
  • StartServiceW (Address: 0x1800d6f80)
api-ms-win-service-management-l2-1-0.dll
  • QueryServiceStatusEx (Address: 0x1800d6fa8)
api-ms-win-service-winsvc-l1-1-0.dll
  • ControlService (Address: 0x1800d6fc0)
  • QueryServiceStatus (Address: 0x1800d6fb8)
api-ms-win-stateseparation-helpers-l1-1-0.dll
  • GetPersistedRegistryLocationW (Address: 0x1800d6fd0)
AppXAllUserStore.dll
  • FamilyMonikerStringToSid (Address: 0x1800d6530)
bcrypt.dll
  • BCryptCloseAlgorithmProvider (Address: 0x1800d7028)
  • BCryptCreateHash (Address: 0x1800d7018)
  • BCryptDestroyHash (Address: 0x1800d7030)
  • BCryptDestroyKey (Address: 0x1800d6ff8)
  • BCryptExportKey (Address: 0x1800d7008)
  • BCryptFinalizeKeyPair (Address: 0x1800d6fe0)
  • BCryptFinishHash (Address: 0x1800d7038)
  • BCryptGenerateKeyPair (Address: 0x1800d6fe8)
  • BCryptGetProperty (Address: 0x1800d7010)
  • BCryptHashData (Address: 0x1800d7020)
  • BCryptImportKeyPair (Address: 0x1800d7040)
  • BCryptOpenAlgorithmProvider (Address: 0x1800d6ff0)
  • BCryptSignHash (Address: 0x1800d7000)
combase.dll
  • (Address: 0x1800d7050)
  • (Address: 0x1800d7058)
  • (Address: 0x1800d7060)
  • (Address: 0x1800d7068)
CRYPT32.dll
  • CertAddCertificateContextToStore (Address: 0x1800d6558)
  • CertAddEncodedCertificateToStore (Address: 0x1800d6540)
  • CertCloseStore (Address: 0x1800d6560)
  • CertCompareCertificate (Address: 0x1800d6578)
  • CertDeleteCertificateFromStore (Address: 0x1800d6580)
  • CertDuplicateCertificateContext (Address: 0x1800d6588)
  • CertEnumCertificatesInStore (Address: 0x1800d6568)
  • CertFindCertificateInStore (Address: 0x1800d6548)
  • CertFreeCertificateContext (Address: 0x1800d6570)
  • CertGetCertificateContextProperty (Address: 0x1800d6598)
  • CertOpenStore (Address: 0x1800d6550)
  • CryptQueryObject (Address: 0x1800d6590)
IPHLPAPI.DLL
  • GetAdaptersAddresses (Address: 0x1800d65a8)
msvcp_win.dll
  • _Wcscoll (Address: 0x1800d70f8)
  • _Wcsxfrm (Address: 0x1800d7100)
  • ?_Decref@facet@locale@std@@UEAAPEAV_Facet_base@3@XZ (Address: 0x1800d7090)
  • ?_Getcat@?$ctype@G@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z (Address: 0x1800d70c0)
  • ?_Getcoll@_Locinfo@std@@QEBA?AU_Collvec@@XZ (Address: 0x1800d70e0)
  • ?_Getgloballocale@locale@std@@CAPEAV_Locimp@12@XZ (Address: 0x1800d7118)
  • ?_Incref@facet@locale@std@@UEAAXXZ (Address: 0x1800d7088)
  • ?_Init@locale@std@@CAPEAV_Locimp@12@_N@Z (Address: 0x1800d70a8)
  • ?_Xbad_alloc@std@@YAXXZ (Address: 0x1800d7078)
  • ?_Xlength_error@std@@YAXPEBD@Z (Address: 0x1800d70b0)
  • ?_Xout_of_range@std@@YAXPEBD@Z (Address: 0x1800d7098)
  • ?_Xregex_error@std@@YAXW4error_type@regex_constants@1@@Z (Address: 0x1800d70b8)
  • ??0_Locinfo@std@@QEAA@PEBD@Z (Address: 0x1800d70e8)
  • ??0_Lockit@std@@QEAA@H@Z (Address: 0x1800d70f0)
  • ??0facet@locale@std@@IEAA@_K@Z (Address: 0x1800d7110)
  • ??1_Locinfo@std@@QEAA@XZ (Address: 0x1800d70d0)
  • ??1_Lockit@std@@QEAA@XZ (Address: 0x1800d70d8)
  • ??1facet@locale@std@@MEAA@XZ (Address: 0x1800d7108)
  • ??Bid@locale@std@@QEAA_KXZ (Address: 0x1800d7128)
  • ?id@?$collate@G@std@@2V0locale@2@A (Address: 0x1800d7130)
  • ?id@?$ctype@G@std@@2V0locale@2@A (Address: 0x1800d7120)
  • ?is@?$ctype@G@std@@QEBA_NFG@Z (Address: 0x1800d70c8)
  • ?tolower@?$ctype@G@std@@QEBAGG@Z (Address: 0x1800d70a0)
  • ?tolower@?$ctype@G@std@@QEBAPEBGPEAGPEBG@Z (Address: 0x1800d7080)
ncrypt.dll
  • NCryptCloseProtectionDescriptor (Address: 0x1800d7148)
  • NCryptCreateProtectionDescriptor (Address: 0x1800d7160)
  • NCryptStreamClose (Address: 0x1800d7150)
  • NCryptStreamOpenToProtect (Address: 0x1800d7168)
  • NCryptStreamOpenToUnprotect (Address: 0x1800d7140)
  • NCryptStreamUpdate (Address: 0x1800d7158)
ntdll.dll
  • DbgPrintEx (Address: 0x1800d7180)
  • NtQueryInformationToken (Address: 0x1800d7188)
  • RtlFreeSid (Address: 0x1800d7178)
  • RtlIpv4AddressToStringW (Address: 0x1800d7190)
  • RtlPublishWnfStateData (Address: 0x1800d71a8)
  • RtlQueryWnfStateData (Address: 0x1800d71a0)
  • RtlSubscribeWnfStateChangeNotification (Address: 0x1800d7198)
  • RtlUnsubscribeWnfStateChangeNotification (Address: 0x1800d71b0)
OLEAUT32.dll
  • SysFreeString (Address: 0x1800d65b8)
RPCRT4.dll
  • Ndr64AsyncClientCall (Address: 0x1800d6610)
  • RpcAsyncCancelCall (Address: 0x1800d6608)
  • RpcAsyncCompleteCall (Address: 0x1800d65d0)
  • RpcAsyncInitializeHandle (Address: 0x1800d65e8)
  • RpcBindingFree (Address: 0x1800d65f8)
  • RpcBindingFromStringBindingW (Address: 0x1800d65d8)
  • RpcBindingSetAuthInfoExW (Address: 0x1800d6600)
  • RpcSsDestroyClientContext (Address: 0x1800d65c8)
  • RpcStringBindingComposeW (Address: 0x1800d65e0)
  • RpcStringFreeW (Address: 0x1800d65f0)
SspiCli.dll
  • LogonUserExExW (Address: 0x1800d6620)
urlmon.dll
  • CreateUri (Address: 0x1800d71c0)
USERENV.dll
  • ExpandEnvironmentStringsForUserW (Address: 0x1800d6630)
WINHTTP.dll
  • WinHttpCloseHandle (Address: 0x1800d6688)
  • WinHttpConnect (Address: 0x1800d6648)
  • WinHttpCrackUrl (Address: 0x1800d66a0)
  • WinHttpOpen (Address: 0x1800d6658)
  • WinHttpOpenRequest (Address: 0x1800d6650)
  • WinHttpQueryHeaders (Address: 0x1800d6678)
  • WinHttpReadData (Address: 0x1800d6680)
  • WinHttpReceiveResponse (Address: 0x1800d6670)
  • WinHttpSendRequest (Address: 0x1800d6698)
  • WinHttpSetDefaultProxyConfiguration (Address: 0x1800d6668)
  • WinHttpSetOption (Address: 0x1800d6690)
  • WinHttpSetStatusCallback (Address: 0x1800d6660)
  • WinHttpSetTimeouts (Address: 0x1800d6640)
WININET.dll
  • InternetQueryOptionW (Address: 0x1800d66b8)
  • InternetSetOptionW (Address: 0x1800d66b0)
WS2_32.dll
  • htonl (Address: 0x1800d66c8)
  • InetPtonW (Address: 0x1800d66d8)
  • WSAGetLastError (Address: 0x1800d66d0)