AuthBroker.dll

Description: Web Authentication WinRT API

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.6033

Architecture: 32-bit

Operating System: Windows NT

SHA256: d5ef252122bb53bbe29566e5f8ba11f4

File Size: 164.5 KB

Uploaded At: Dec. 1, 2025, 7:53 a.m.

Views: 9

Security Warning

This file has been flagged as potentially dangerous.


Reason: Detected potentially dangerous functions used for process injection: OpenProcess

Exported Functions

  • FindCallingThreadImmersiveWindow (Ordinal: 1, Address: 0x17cb0)
  • AuthBrokerClearThreadClientContext (Ordinal: 2, Address: 0x1acd0)
  • AuthBrokerCreateClientContext (Ordinal: 3, Address: 0x92b0)
  • AuthBrokerFreeClientContext (Ordinal: 4, Address: 0x93b0)
  • AuthBrokerSetThreadClientContext (Ordinal: 5, Address: 0x1ad90)
  • DllCanUnloadNow (Ordinal: 6, Address: 0x17b80)
  • DllGetActivationFactory (Ordinal: 7, Address: 0x17bc0)
  • DllGetClassObject (Ordinal: 8, Address: 0x17be0)
  • DllInstall (Ordinal: 9, Address: 0x1aea0)
  • DllRegisterServer (Ordinal: 10, Address: 0x95c0)
  • PurgeAuthHostSsoCache (Ordinal: 11, Address: 0x1af00)

Imported DLLs & Functions

api-ms-win-core-apiquery-l1-1-0.dll
  • ApiSetQueryApiSetPresence (Address: 0x1002607c)
api-ms-win-core-com-midlproxystub-l1-1-0.dll
  • CStdStubBuffer2_Connect (Address: 0x100260a4)
  • CStdStubBuffer2_CountRefs (Address: 0x10026088)
  • CStdStubBuffer2_Disconnect (Address: 0x10026084)
  • CStdStubBuffer2_QueryInterface (Address: 0x1002608c)
  • NdrProxyForwardingFunction3 (Address: 0x1002609c)
  • NdrProxyForwardingFunction4 (Address: 0x10026090)
  • NdrProxyForwardingFunction5 (Address: 0x10026098)
  • ObjectStublessClient10 (Address: 0x100260b8)
  • ObjectStublessClient11 (Address: 0x100260a0)
  • ObjectStublessClient12 (Address: 0x100260d4)
  • ObjectStublessClient13 (Address: 0x100260e0)
  • ObjectStublessClient14 (Address: 0x100260d0)
  • ObjectStublessClient15 (Address: 0x100260e8)
  • ObjectStublessClient16 (Address: 0x100260a8)
  • ObjectStublessClient17 (Address: 0x100260c0)
  • ObjectStublessClient18 (Address: 0x100260ac)
  • ObjectStublessClient19 (Address: 0x100260d8)
  • ObjectStublessClient20 (Address: 0x100260b0)
  • ObjectStublessClient21 (Address: 0x100260b4)
  • ObjectStublessClient3 (Address: 0x100260bc)
  • ObjectStublessClient4 (Address: 0x10026094)
  • ObjectStublessClient5 (Address: 0x100260dc)
  • ObjectStublessClient6 (Address: 0x100260cc)
  • ObjectStublessClient7 (Address: 0x100260e4)
  • ObjectStublessClient8 (Address: 0x100260c8)
  • ObjectStublessClient9 (Address: 0x100260c4)
api-ms-win-core-debug-l1-1-0.dll
  • DebugBreak (Address: 0x100260f0)
  • IsDebuggerPresent (Address: 0x100260f4)
  • OutputDebugStringW (Address: 0x100260f8)
api-ms-win-core-delayload-l1-1-0.dll
  • DelayLoadFailureHook (Address: 0x10026100)
api-ms-win-core-delayload-l1-1-1.dll
  • ResolveDelayLoadedAPI (Address: 0x10026108)
api-ms-win-core-errorhandling-l1-1-0.dll
  • GetLastError (Address: 0x10026120)
  • RaiseException (Address: 0x10026118)
  • SetLastError (Address: 0x1002611c)
  • SetUnhandledExceptionFilter (Address: 0x10026114)
  • UnhandledExceptionFilter (Address: 0x10026110)
api-ms-win-core-file-l1-1-0.dll
  • CreateFileW (Address: 0x10026128)
api-ms-win-core-handle-l1-1-0.dll
  • CloseHandle (Address: 0x10026134)
  • DuplicateHandle (Address: 0x10026130)
api-ms-win-core-heap-l1-1-0.dll
  • GetProcessHeap (Address: 0x10026140)
  • HeapAlloc (Address: 0x10026144)
  • HeapFree (Address: 0x1002613c)
api-ms-win-core-heap-l2-1-0.dll
  • LocalAlloc (Address: 0x10026154)
  • LocalFree (Address: 0x10026150)
  • LocalReAlloc (Address: 0x1002614c)
api-ms-win-core-libraryloader-l1-2-0.dll
  • GetModuleFileNameA (Address: 0x10026168)
  • GetModuleHandleExW (Address: 0x10026164)
  • GetModuleHandleW (Address: 0x1002616c)
  • GetProcAddress (Address: 0x1002615c)
  • LoadStringW (Address: 0x10026160)
api-ms-win-core-localization-l1-2-0.dll
  • FormatMessageW (Address: 0x10026174)
api-ms-win-core-marshal-l1-1-0.dll
  • HWND_UserFree (Address: 0x1002617c)
  • HWND_UserMarshal (Address: 0x10026188)
  • HWND_UserSize (Address: 0x10026180)
  • HWND_UserUnmarshal (Address: 0x10026184)
api-ms-win-core-processthreads-l1-1-0.dll
  • CreateProcessW (Address: 0x100261a0)
  • CreateThread (Address: 0x100261b4)
  • DeleteProcThreadAttributeList (Address: 0x1002619c)
  • GetCurrentProcess (Address: 0x100261d4)
  • GetCurrentProcessId (Address: 0x100261cc)
  • GetCurrentThread (Address: 0x100261c0)
  • GetCurrentThreadId (Address: 0x100261c8)
  • GetExitCodeProcess (Address: 0x10026190)
  • GetProcessId (Address: 0x100261bc)
  • GetProcessIdOfThread (Address: 0x100261e0)
  • InitializeProcThreadAttributeList (Address: 0x100261a8)
  • OpenProcessToken (Address: 0x10026198)
  • OpenThread (Address: 0x100261e4)
  • OpenThreadToken (Address: 0x100261c4)
  • ResumeThread (Address: 0x100261b8)
  • SetThreadToken (Address: 0x10026194)
  • TerminateProcess (Address: 0x100261d8)
  • TlsAlloc (Address: 0x100261ac)
  • TlsFree (Address: 0x100261d0)
  • TlsGetValue (Address: 0x100261b0)
  • TlsSetValue (Address: 0x100261dc)
  • UpdateProcThreadAttribute (Address: 0x100261a4)
api-ms-win-core-processthreads-l1-1-1.dll
  • OpenProcess (Address: 0x100261ec)
api-ms-win-core-profile-l1-1-0.dll
  • QueryPerformanceCounter (Address: 0x100261f4)
api-ms-win-core-registry-l1-1-0.dll
  • RegCloseKey (Address: 0x1002620c)
  • RegCreateKeyExW (Address: 0x10026210)
  • RegDeleteValueW (Address: 0x1002621c)
  • RegEnumKeyExW (Address: 0x10026204)
  • RegGetValueW (Address: 0x10026218)
  • RegOpenKeyExW (Address: 0x10026200)
  • RegQueryInfoKeyW (Address: 0x10026208)
  • RegQueryValueExW (Address: 0x100261fc)
  • RegSetValueExW (Address: 0x10026214)
api-ms-win-core-synch-l1-1-0.dll
  • AcquireSRWLockExclusive (Address: 0x10026224)
  • AcquireSRWLockShared (Address: 0x10026244)
  • CreateEventExW (Address: 0x1002622c)
  • CreateEventW (Address: 0x1002625c)
  • CreateMutexExW (Address: 0x10026240)
  • CreateMutexW (Address: 0x1002623c)
  • CreateSemaphoreExW (Address: 0x10026230)
  • DeleteCriticalSection (Address: 0x10026250)
  • EnterCriticalSection (Address: 0x10026268)
  • InitializeCriticalSectionEx (Address: 0x10026264)
  • LeaveCriticalSection (Address: 0x10026248)
  • OpenSemaphoreW (Address: 0x10026238)
  • ReleaseMutex (Address: 0x10026260)
  • ReleaseSemaphore (Address: 0x10026228)
  • ReleaseSRWLockExclusive (Address: 0x10026234)
  • ReleaseSRWLockShared (Address: 0x10026270)
  • SetEvent (Address: 0x10026258)
  • WaitForMultipleObjectsEx (Address: 0x10026254)
  • WaitForSingleObject (Address: 0x1002626c)
  • WaitForSingleObjectEx (Address: 0x1002624c)
api-ms-win-core-synch-l1-2-0.dll
  • InitOnceBeginInitialize (Address: 0x10026284)
  • InitOnceComplete (Address: 0x10026278)
  • InitOnceExecuteOnce (Address: 0x1002627c)
  • Sleep (Address: 0x10026280)
api-ms-win-core-synch-l1-2-1.dll
  • WaitForMultipleObjects (Address: 0x1002628c)
api-ms-win-core-sysinfo-l1-1-0.dll
  • GetSystemTime (Address: 0x10026298)
  • GetSystemTimeAsFileTime (Address: 0x1002629c)
  • GetTickCount (Address: 0x10026294)
api-ms-win-core-threadpool-l1-2-0.dll
  • CloseThreadpoolTimer (Address: 0x100262b4)
  • CloseThreadpoolWork (Address: 0x100262b0)
  • CreateThreadpoolTimer (Address: 0x100262ac)
  • CreateThreadpoolWork (Address: 0x100262bc)
  • FreeLibraryWhenCallbackReturns (Address: 0x100262b8)
  • SetThreadpoolTimer (Address: 0x100262c0)
  • SubmitThreadpoolWork (Address: 0x100262a4)
  • WaitForThreadpoolTimerCallbacks (Address: 0x100262a8)
api-ms-win-core-url-l1-1-0.dll
  • ParseURLW (Address: 0x100262c8)
api-ms-win-core-util-l1-1-0.dll
  • DecodePointer (Address: 0x100262d4)
  • EncodePointer (Address: 0x100262d0)
api-ms-win-core-winrt-error-l1-1-0.dll
  • GetRestrictedErrorInfo (Address: 0x100262dc)
  • RoOriginateError (Address: 0x100262e0)
  • RoOriginateErrorW (Address: 0x100262e4)
  • RoTransformError (Address: 0x100262e8)
  • SetRestrictedErrorInfo (Address: 0x100262ec)
api-ms-win-core-winrt-error-l1-1-1.dll
  • IsErrorPropagationEnabled (Address: 0x100262f4)
  • RoGetMatchingRestrictedErrorInfo (Address: 0x100262fc)
  • RoReportFailedDelegate (Address: 0x100262f8)
api-ms-win-core-winrt-l1-1-0.dll
  • RoActivateInstance (Address: 0x10026308)
  • RoGetActivationFactory (Address: 0x10026310)
  • RoInitialize (Address: 0x10026304)
  • RoUninitialize (Address: 0x1002630c)
api-ms-win-core-winrt-string-l1-1-0.dll
  • HSTRING_UserFree (Address: 0x10026344)
  • HSTRING_UserMarshal (Address: 0x1002633c)
  • HSTRING_UserSize (Address: 0x10026340)
  • HSTRING_UserUnmarshal (Address: 0x1002631c)
  • WindowsCompareStringOrdinal (Address: 0x10026348)
  • WindowsCreateString (Address: 0x10026338)
  • WindowsCreateStringReference (Address: 0x10026318)
  • WindowsDeleteString (Address: 0x10026328)
  • WindowsDuplicateString (Address: 0x10026324)
  • WindowsGetStringLen (Address: 0x10026320)
  • WindowsGetStringRawBuffer (Address: 0x10026330)
  • WindowsIsStringEmpty (Address: 0x1002632c)
  • WindowsStringHasEmbeddedNull (Address: 0x10026334)
api-ms-win-core-wow64-l1-1-0.dll
  • IsWow64Process (Address: 0x10026358)
  • Wow64DisableWow64FsRedirection (Address: 0x10026354)
  • Wow64RevertWow64FsRedirection (Address: 0x10026350)
api-ms-win-eventing-classicprovider-l1-1-0.dll
  • GetTraceEnableFlags (Address: 0x10026360)
  • GetTraceEnableLevel (Address: 0x10026374)
  • GetTraceLoggerHandle (Address: 0x10026364)
  • RegisterTraceGuidsW (Address: 0x10026368)
  • TraceMessage (Address: 0x10026370)
  • UnregisterTraceGuids (Address: 0x1002636c)
api-ms-win-eventing-provider-l1-1-0.dll
  • EventActivityIdControl (Address: 0x1002637c)
  • EventRegister (Address: 0x10026384)
  • EventSetInformation (Address: 0x10026380)
  • EventUnregister (Address: 0x10026388)
  • EventWriteTransfer (Address: 0x1002638c)
api-ms-win-security-appcontainer-l1-1-0.dll
  • GetAppContainerNamedObjectPath (Address: 0x10026394)
api-ms-win-security-base-l1-1-0.dll
  • AllocateAndInitializeSid (Address: 0x100263b0)
  • CopySid (Address: 0x100263ac)
  • FreeSid (Address: 0x100263b4)
  • GetLengthSid (Address: 0x100263a4)
  • GetSidSubAuthorityCount (Address: 0x1002639c)
  • GetTokenInformation (Address: 0x100263a8)
  • ImpersonateLoggedOnUser (Address: 0x100263a0)
api-ms-win-security-base-l1-2-0.dll
  • CheckTokenCapability (Address: 0x100263bc)
api-ms-win-security-provider-l1-1-0.dll
  • GetSecurityInfo (Address: 0x100263c4)
AUTHZ.dll
  • AuthzAccessCheck (Address: 0x10026004)
  • AuthzFreeContext (Address: 0x1002600c)
  • AuthzFreeResourceManager (Address: 0x10026008)
  • AuthzInitializeContextFromSid (Address: 0x10026000)
  • AuthzInitializeResourceManager (Address: 0x10026010)
combase.dll
  • (Address: 0x100263cc)
msvcrt.dll
  • __CxxFrameHandler3 (Address: 0x100263d4)
  • __dllonexit (Address: 0x100263f0)
  • _amsg_exit (Address: 0x100263fc)
  • _callnewh (Address: 0x10026418)
  • _except_handler4_common (Address: 0x10026400)
  • _initterm (Address: 0x10026414)
  • _lock (Address: 0x100263f4)
  • _onexit (Address: 0x100263ec)
  • _purecall (Address: 0x1002640c)
  • _unlock (Address: 0x10026408)
  • _vsnwprintf (Address: 0x100263dc)
  • _XcptFilter (Address: 0x100263d8)
  • free (Address: 0x100263e0)
  • malloc (Address: 0x100263f8)
  • memcmp (Address: 0x100263e4)
  • memcpy (Address: 0x100263e8)
  • memcpy_s (Address: 0x10026410)
  • memmove_s (Address: 0x10026404)
  • memset (Address: 0x1002641c)
netutils.dll
  • NetApiBufferFree (Address: 0x10026424)
ntdll.dll
  • _wcsicmp (Address: 0x10026448)
  • _wcsnicmp (Address: 0x10026440)
  • RtlAllocateAndInitializeSidEx (Address: 0x1002644c)
  • RtlDeleteCriticalSection (Address: 0x1002642c)
  • RtlDeriveCapabilitySidsFromName (Address: 0x10026450)
  • RtlEnterCriticalSection (Address: 0x10026430)
  • RtlEqualSid (Address: 0x10026438)
  • RtlInitializeCriticalSection (Address: 0x10026458)
  • RtlInitUnicodeString (Address: 0x10026454)
  • RtlIsStateSeparationEnabled (Address: 0x10026444)
  • RtlLeaveCriticalSection (Address: 0x10026434)
  • wcstoul (Address: 0x1002645c)
  • WinSqmAddToStream (Address: 0x1002643c)
RPCRT4.dll
  • CStdStubBuffer_AddRef (Address: 0x10026050)
  • CStdStubBuffer_Connect (Address: 0x10026034)
  • CStdStubBuffer_CountRefs (Address: 0x10026030)
  • CStdStubBuffer_DebugServerQueryInterface (Address: 0x10026060)
  • CStdStubBuffer_DebugServerRelease (Address: 0x10026018)
  • CStdStubBuffer_Disconnect (Address: 0x1002601c)
  • CStdStubBuffer_Invoke (Address: 0x10026054)
  • CStdStubBuffer_IsIIDSupported (Address: 0x10026058)
  • CStdStubBuffer_QueryInterface (Address: 0x10026024)
  • I_RpcBindingInqLocalClientPID (Address: 0x1002605c)
  • IUnknown_AddRef_Proxy (Address: 0x1002602c)
  • IUnknown_QueryInterface_Proxy (Address: 0x10026028)
  • IUnknown_Release_Proxy (Address: 0x1002603c)
  • NdrCStdStubBuffer_Release (Address: 0x1002604c)
  • NdrCStdStubBuffer2_Release (Address: 0x10026040)
  • NdrDllCanUnloadNow (Address: 0x10026048)
  • NdrDllGetClassObject (Address: 0x10026044)
  • NdrOleAllocate (Address: 0x10026020)
  • NdrOleFree (Address: 0x10026068)
  • NdrStubCall2 (Address: 0x10026064)
  • NdrStubForwardingFunction (Address: 0x10026038)
WINHTTP.dll
  • WinHttpCrackUrl (Address: 0x10026070)
  • WinHttpCreateUrl (Address: 0x10026074)
wkscli.dll
  • NetGetJoinInformation (Address: 0x10026464)