The provided vulnerability information indicates hidden functionality (protestware) was added in versions 9.17.4-10.0.0, but no specific function names or file paths are disclosed in the advisory or linked resources. The GitHub release notes mention a 'STOP WAR message for Russians' implementation, but this reference points to v11.4.9 (a later version outside the vulnerable range). Without access to the actual code changes in the 9.17.4-10.0.0 range or explicit commit diffs, we cannot confidently identify specific vulnerable functions. The vulnerability manifests through domain-checking and message injection logic, but insufficient technical details are provided to map this to concrete function implementations.