uhhhh i just found something
for anyone that doesnt know, if you go to a .dll on virus total and then go to details, scroll down and find urlmon.dll that probably means its a rat, to make sure press the plus next to and if it says "URLDownloadToFileA" that means its a rat and i just found that in the dopium.dll aka the one in this thread, stay safe and check the virus total before injecting a dll, btw you can find these details by scrolling down and looking for imports.
View attachment 6452