> no winhttp.dll, wininet.dll, or ws2_32.dll. offline validation only. all crypto is local, so theoretically extractable.
You can't possibly know that by the mere lack of these DLLs from the import directory.
You can't possibly know that by the mere lack of these DLLs from the import directory.
I suppose they could LoadLibrary/GetProcAddress at runtime, but that'd be a lot of effort for obfuscation.