bc11649afa0295cdb87080a634f7c2e235ce1d0bc495873151e6a02c4580adaa

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 2026-Jan-25 11:46:31
Detected languages English - United States
Debug artifacts C:\Users\fivem\Desktop\cleaner\SpooferUI(1)\SpooferUI(1)\x64\Release\Dominate.pdb

Plugin Output

Suspicious Strings found in the binary may indicate undesirable behavior: Tries to detect virtualized environments:
  • HARDWARE\DESCRIPTION\System
Accesses the WMI:
  • ROOT\CIMV2
Contains another PE executable:
  • This program cannot be run in DOS mode.
Miscellaneous malware strings:
  • virus
Contains domain names:
  • crl.globalsign.com
  • crl.globalsign.net
  • crl.microsoft.com
  • example.com
  • github.com
  • globalsign.com
  • globalsign.net
  • http://crl.globalsign.com
  • http://crl.globalsign.com/gs/gscodesigng2.crl0
  • http://crl.globalsign.com/gs/gstimestampingg2.crl0T
  • http://crl.globalsign.net
  • http://crl.globalsign.net/root.crl0
  • http://crl.microsoft.com
  • http://crl.microsoft.com/pki/crl/products/MicrosoftCodeVerifRoot.crl0
  • http://ocsp2.globalsign.com
  • http://ocsp2.globalsign.com/gscodesigng20
  • http://secure.globalsign.com
  • http://secure.globalsign.com/cacert/gscodesigng2.crt04
  • http://secure.globalsign.com/cacert/gstimestampingg2.crt0
  • https://curl.se
  • https://fonts.floriankarsten.comFlorian
  • https://github.com
  • https://indiantypefoundry.comNinad
  • https://keyauth.win
  • https://mkhlwalukqqenzmgcrrn.supabase.co
  • https://mkhlwalukqqenzmgcrrn.supabase.co/storage/v1/object/public/uploads/public/1769341536705-ol5bk.bat?download
  • https://mkhlwalukqqenzmgcrrn.supabase.co/storage/v1/object/public/uploads/public/1769341541342-m3sszs.bat?download
  • https://scripts.sil.org
  • https://scripts.sil.org/OFLThis
  • https://scripts.sil.org/OFLhttps
  • https://www.globalsign.com
  • https://www.globalsign.com/repository/0
  • https://www.globalsign.com/repository/03
  • microsoft.com
  • ocsp2.globalsign.com
  • scripts.sil.org
  • secure.globalsign.com
  • www.globalsign.com
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Uses constants related to SHA1
Uses constants related to SHA256
Uses constants related to SHA512
Uses known Mersenne Twister constants
Microsoft's Cryptography API
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryW
  • GetProcAddress
  • LoadLibraryA
Can access the registry:
  • RegOpenKeyExA
  • RegQueryValueExA
  • RegCloseKey
  • RegCreateKeyExA
  • RegDeleteKeyA
Possibly launches other programs:
  • ShellExecuteA
  • system
Uses Microsoft's cryptographic API:
  • CryptImportKey
  • CryptAcquireContextW
  • CryptReleaseContext
  • CryptGetHashParam
  • CryptCreateHash
  • CryptHashData
  • CryptEncrypt
  • CryptDestroyHash
  • CryptDestroyKey
  • CryptQueryObject
  • CryptDecodeObjectEx
  • CryptStringToBinaryW
Has Internet access capabilities:
  • URLDownloadToFileA
Leverages the raw socket API to access the Internet:
  • WS2_32.dll
Functions related to the privilege level:
  • OpenProcessToken
Changes object ACLs:
  • SetSecurityInfo
Reads the contents of the clipboard:
  • GetClipboardData
Interacts with the certificate store:
  • CertAddCertificateContextToStore
  • CertOpenStore
Malicious VirusTotal score: 42/61 (Scanned on 2026-09-13 18:26:40) ALYac: Gen:Variant.Tedy.886234
APEX: Malicious
AhnLab-V3: Trojan/Win.Lazy.R767773
Alibaba: Trojan:Win64/GenKryptik.6c375b31
Antiy-AVL: Trojan/Win64.Lazy
Arcabit: Trojan.Tedy.DD85DA
Avira: TR/W64.MalwareX
BitDefender: Gen:Variant.Tedy.886234
Bkav: W32.Malware.B6B6F3C0
CTX: exe.trojan.lazy
CrowdStrike: win/malicious_confidence_90% (W)
Cylance: Unsafe
Cynet: Malicious (score: 100)
DeepInstinct: MALICIOUS
Elastic: malicious (high confidence)
Emsisoft: Gen:Variant.Tedy.886234 (B)
F-Secure: Trojan.TR/W64.MalwareX
Fortinet: W64/GenKryptik.WS!tr
GData: Gen:Variant.Tedy.886234
K7AntiVirus: Trojan ( 005cf36f1 )
K7GW: Trojan ( 005cf36f1 )
Kingsoft: Win64.Troj.lazy.v
Lionic: Trojan.Win32.Lazy.4!c
Malwarebytes: Generic.Malware/Suspicious
McAfeeD: Trojan:Win/GenericY.FJJ
MicroWorld-eScan: Gen:Variant.Tedy.886234
Microsoft: Trojan:Win64/Lazy.ETL!MTB
Paloalto: generic.ml
Panda: Trj/CI.A
Rising: Trojan.Lazy!8.8EC3 (TFE:5:qc2WV77PKFR)
Sangfor: Trojan.Win32.Save.a
SentinelOne: Static AI - Malicious PE
Sophos: Mal/Generic-S
Symantec: ML.Attribute.HighConfidence
Tencent: Trojan.Win64.Kryptik.16002199
TrellixENS: Artemis!32E113D5F4EC
TrendMicro: Trojan.Win32.ZYX.USBLGF26
VIPRE: Gen:Variant.Tedy.886234
VirIT: Trojan.Win64.GenPSW.JAV
Zillya: Trojan.GenKryptik.Win64.66229
alibabacloud: Trojan:Win/Lazy.ESA2XJC
huorong: Exploit/CVE-2019-16098.a

Hashes

MD5 32e113d5f4ec5de5d99a41e393798922 🔍
SHA1 23686795d4c6547b01b08305ad4e744fa4021552 🔍
SHA256 bc11649afa0295cdb87080a634f7c2e235ce1d0bc495873151e6a02c4580adaa 🔍
SHA3 90fe841d191f3cf7a8629b4ae72a99a9168fde071890fa90172f094e51309789 🔍
SSDeep 49152:gzs+qdwsOH2VWRnjFfJuGBsuf9iP1VRs+Ea0ErvNnPZgmJaEPi3:3LInjFfJuGBsuf9i9VOBa5Z1aEO 🔍
Imports Hash 0e4574cad9c8f95803b9e4fcc238d134 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x130

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 6
TimeDateStamp 2026-Jan-25 11:46:31
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x154a00
SizeOfInitializedData 0xed000
SizeOfUninitializedData 0
AddressOfEntryPoint 0x00000000000F05FC (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x245000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 f04bb1c192b4681bc54e78158123bee5 🔍
SHA1 7bc2f95883e0325fa87284edfaea30463fde4e93 🔍
SHA256 392eb36b0c3db66ce82a2df8addd724239d96ddfbabea1eb34edc0ed182481a9 🔍
SHA3 a90d3a7c65ca471c68b341c4d3579398759e95f640882ac8b6995ceb8b3085d6 🔍
VirtualSize 0x15482c
VirtualAddress 0x1000
SizeOfRawData 0x154a00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.53315

.rdata

MD5 5bf0776415e9d82f57cd8ee6f97580ec 🔍
SHA1 4d65e28a5832245f7af1732d693b36d405bf7c21 🔍
SHA256 96143a10cfcbe4858a24876472160cfb16dcf66d6105a9b4eac6ca8fea69f471 🔍
SHA3 566ad43905628f3a306a70111a45f98f2197145b98df934fa5669289babf1aa4 🔍
VirtualSize 0x9cfb2
VirtualAddress 0x156000
SizeOfRawData 0x9d000
PointerToRawData 0x154e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.80198

.data

MD5 c8e07dfdebe4a3ce8e2bc74f232ccf60 🔍
SHA1 bd3b1b7f7d9c3326473eb5dc9acffd2157965f09 🔍
SHA256 c5aab8f7bbe7adf5cd7a1b62cfe6a9c4bf93432d31d9a9bf1538368d1196f8f6 🔍
SHA3 7e5622be0130a955c32cecfdee96236aab43399e8531d6c9fcae2cfee7546515 🔍
VirtualSize 0x3f570
VirtualAddress 0x1f3000
SizeOfRawData 0x3e200
PointerToRawData 0x1f1e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 6.52668

.pdata

MD5 fdc66bc021187e076d07b16750b30fb5 🔍
SHA1 a5ccffd5a15490b04d27b274df292e1dc6132c8b 🔍
SHA256 0fa7af651c95592090faac2f1a540fbe2c3651d37b4856019d9ec0b3bd0f267a 🔍
SHA3 a8fb93d21949c2cc68cc10ffa96b710ea87a86a607324fbd4b77464d1928571b 🔍
VirtualSize 0xef28
VirtualAddress 0x233000
SizeOfRawData 0xf000
PointerToRawData 0x230000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.18734

.rsrc

MD5 350390251473fa26ff21f7f9bb2d2299 🔍
SHA1 f6b812d07bdef0fa38854566c7a5633f8095ce4c 🔍
SHA256 d93f0a7e6174767e471d4560d05abdf567e3734f0b348a245f66464d1c76e187 🔍
SHA3 9c458ab7166f3a36710816e1572fdf36a9cc35baac1bfb5b8b0060a6dad24dd0 🔍
VirtualSize 0x1e8
VirtualAddress 0x242000
SizeOfRawData 0x200
PointerToRawData 0x23f000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.75872

.reloc

MD5 1d3eb83a0aedb880de78e48d639e91a7 🔍
SHA1 9370e41a5adc8d58483e7c5d944e1b14d3c7c9c1 🔍
SHA256 fda043404b2d26c70e4a9c00c08459a21e93f300decf3c9f95a58878a4412072 🔍
SHA3 1ee4e79d79b276223133d8e2acac223de04305bffb50ef6e7088e4a99d1d58a2 🔍
VirtualSize 0x1670
VirtualAddress 0x243000
SizeOfRawData 0x1800
PointerToRawData 0x23f200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.33055

Imports

d3d11.dll D3D11CreateDeviceAndSwapChain
D3DCOMPILER_43.dll D3DCompile
ADVAPI32.dll CryptImportKey
OpenProcessToken
AddAccessAllowedAce
GetLengthSid
RegOpenKeyExA
RegQueryValueExA
RegCloseKey
GetTokenInformation
InitializeAcl
IsValidSid
RegCreateKeyExA
RegDeleteKeyA
SetSecurityInfo
CopySid
ConvertSidToStringSidA
CryptAcquireContextW
CryptReleaseContext
CryptGetHashParam
CryptCreateHash
CryptHashData
CryptEncrypt
CryptDestroyHash
SystemFunction036
CryptDestroyKey
KERNEL32.dll SetFileInformationByHandle
GetConsoleWindow
GetModuleHandleW
GetModuleFileNameW
GetLastError
CreateFileW
SetLastError
GetCurrentProcessId
GetCurrentThreadId
GlobalMemoryStatusEx
GetDiskFreeSpaceExW
CreateDirectoryA
LocalFree
CloseHandle
Sleep
WaitForSingleObject
GetFileAttributesExW
FindFirstFileW
FindClose
AddVectoredExceptionHandler
HeapDestroy
HeapAlloc
HeapReAlloc
HeapFree
HeapSize
GetProcessHeap
InitializeCriticalSectionEx
DeleteCriticalSection
GetCurrentProcess
CreateThread
GetFileInformationByHandleEx
VirtualProtect
CreateFileMappingW
MapViewOfFile
UnmapViewOfFile
GetModuleFileNameA
QueryFullProcessImageNameW
FormatMessageW
WakeAllConditionVariable
ReleaseSRWLockExclusive
AcquireSRWLockExclusive
InitializeCriticalSection
EnterCriticalSection
LeaveCriticalSection
GetSystemDirectoryW
LoadLibraryW
SleepEx
GetSystemInfo
GetTickCount
MoveFileExW
WaitForSingleObjectEx
GetEnvironmentVariableA
GetStdHandle
GetFileType
SetUnhandledExceptionFilter
ReadFile
PeekNamedPipe
WaitForMultipleObjects
VerifyVersionInfoW
GetFileSizeEx
FormatMessageA
GetLocaleInfoEx
GetSystemTimeAsFileTime
QueryPerformanceCounter
FreeLibrary
VerSetConditionMask
GetProcAddress
QueryPerformanceFrequency
LoadLibraryA
GetModuleHandleA
GlobalUnlock
WideCharToMultiByte
InitializeSListHead
IsDebuggerPresent
OutputDebugStringW
SleepConditionVariableSRW
GetCurrentDirectoryW
CreateDirectoryW
GlobalLock
GlobalFree
GlobalAlloc
MultiByteToWideChar
AreFileApisANSI
CreateFile2
USER32.dll GetForegroundWindow
SetCursor
ClientToScreen
LoadCursorW
GetCapture
TrackMouseEvent
MessageBoxA
GetClientRect
IsWindowUnicode
ReleaseCapture
SetCursorPos
GetCursorPos
OpenClipboard
CloseClipboard
EmptyClipboard
GetClipboardData
SetClipboardData
SetCapture
ScreenToClient
GetWindowLongW
GetKeyState
DestroyWindow
CreateWindowExW
GetSystemMetrics
UnregisterClassW
RegisterClassExW
DispatchMessageW
SetWindowLongA
PeekMessageW
SetLayeredWindowAttributes
TranslateMessage
PostQuitMessage
UpdateWindow
EnumDisplayDevicesW
GetWindowRect
GetActiveWindow
ShowWindow
MoveWindow
DefWindowProcW
SHELL32.dll ShellExecuteA
ShellExecuteExW
ole32.dll CoUninitialize
CoInitializeEx
CoInitializeSecurity
CoSetProxyBlanket
CoCreateInstance
OLEAUT32.dll VariantClear
SysAllocString
SysFreeString
MSVCP140.dll ?_Getcat@?$codecvt@DDU_Mbstatet@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z
?in@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z
?out@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z
??1?$basic_ostream@DU?$char_traits@D@std@@@std@@UEAA@XZ
?getloc@ios_base@std@@QEBA?AVlocale@2@XZ
??7ios_base@std@@QEBA_NXZ
?_Getcat@?$ctype@D@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z
?always_noconv@codecvt_base@std@@QEBA_NXZ
_Query_perf_frequency
_Query_perf_counter
?_Xinvalid_argument@std@@YAXPEBD@Z
_Xtime_get_ticks
?_Syserror_map@std@@YAPEBDH@Z
?_Winerror_map@std@@YAHH@Z
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@_J@Z
?put@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@D@Z
?_Random_device@std@@YAIXZ
?cerr@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A
?unshift@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEAD1AEAPEAD@Z
?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXXZ
?getloc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEBA?AVlocale@2@XZ
?id@?$ctype@D@std@@2V0locale@2@A
?_Fiopen@std@@YAPEAU_iobuf@@PEBDHH@Z
?id@?$codecvt@DDU_Mbstatet@@@std@@2V0locale@2@A
?_Id_cnt@id@locale@std@@0HA
?_Getgloballocale@locale@std@@CAPEAV_Locimp@12@XZ
??0_Lockit@std@@QEAA@H@Z
??1_Lockit@std@@QEAA@XZ
??Bios_base@std@@QEBA_NXZ
??1?$basic_istream@DU?$char_traits@D@std@@@std@@UEAA@XZ
?uncaught_exceptions@std@@YAHXZ
?_Xbad_alloc@std@@YAXXZ
?_Xout_of_range@std@@YAXPEBD@Z
?setw@std@@YA?AU?$_Smanip@_J@1@_J@Z
?_Xlength_error@std@@YAXPEBD@Z
??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA@XZ
?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ
??0?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z
?widen@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADD@Z
?snextc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
?sgetc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ
?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z
?sbumpc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
?_Ipfx@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA_N_N@Z
_Thrd_detach
_Cnd_do_broadcast_at_thread_exit
?_Throw_Cpp_error@std@@YAXH@Z
?_Xbad_function_call@std@@YAXXZ
?good@ios_base@std@@QEBA_NXZ
??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA@XZ
?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z
?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z
?setg@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXPEAD00@Z
?setp@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXPEAD00@Z
??0?$basic_iostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@@Z
??1?$basic_ios@DU?$char_traits@D@std@@@std@@UEAA@XZ
??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAA@XZ
?_Lock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ
?_Unlock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ
?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JXZ
??0?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z
?uflow@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ
?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEAD_J@Z
??1?$basic_iostream@DU?$char_traits@D@std@@@std@@UEAA@XZ
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@H@Z
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAVios_base@1@AEAV21@@Z@Z
?imbue@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAXAEBVlocale@2@@Z
?sync@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ
?setbuf@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAPEAV12@PEAD_J@Z
?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEBD_J@Z
IPHLPAPI.DLL GetAdaptersInfo
IMM32.dll ImmSetCompositionWindow
ImmGetContext
ImmReleaseContext
ImmSetCandidateWindow
dwmapi.dll DwmExtendFrameIntoClientArea
urlmon.dll URLDownloadToFileA
PSAPI.DLL GetModuleInformation
SHLWAPI.dll PathFindFileNameW
USERENV.dll UnloadUserProfile
bcrypt.dll BCryptGenRandom
VCRUNTIME140_1.dll __CxxFrameHandler4
VCRUNTIME140.dll __std_exception_destroy
__std_exception_copy
__std_terminate
strstr
strchr
_CxxThrowException
memchr
memcmp
memcpy
memmove
memset
strrchr
wcschr
__C_specific_handler
__current_exception
__current_exception_context
longjmp
__intrinsic_setjmp
api-ms-win-crt-heap-l1-1-0.dll calloc
free
realloc
_callnewh
_set_new_mode
malloc
api-ms-win-crt-string-l1-1-0.dll tolower
strcpy_s
_wcsdup
strcspn
wcslen
wcspbrk
strspn
strcmp
wcsncmp
strpbrk
wcsncpy
strncmp
strncpy
_strdup
strlen
isalnum
api-ms-win-crt-stdio-l1-1-0.dll _get_stream_buffer_pointers
ungetc
fgets
setvbuf
fgetpos
_pclose
fsetpos
fgetc
fputs
fputc
feof
_wopen
_lseeki64
_popen
fopen
_close
_fileno
_write
_read
__p__commode
__stdio_common_vsscanf
fread
_set_fmode
__stdio_common_vsprintf
_fseeki64
fwrite
__stdio_common_vfprintf
fseek
fclose
fflush
__acrt_iob_func
ftell
_wfopen
api-ms-win-crt-utility-l1-1-0.dll qsort
api-ms-win-crt-convert-l1-1-0.dll atoi
strtoul
wcstombs
strtoull
strtoll
strtol
strtod
api-ms-win-crt-runtime-l1-1-0.dll _exit
system
__p___argv
exit
_resetstkoflw
_invalid_parameter_noinfo
abort
_configure_narrow_argv
_initterm_e
__sys_nerr
__sys_errlist
_beginthreadex
_initialize_onexit_table
_register_onexit_function
_crt_atexit
terminate
_initterm
_get_initial_narrow_environment
_c_exit
_set_app_type
_seh_filter_exe
_register_thread_local_exe_atexit_callback
_errno
_invalid_parameter_noinfo_noreturn
_initialize_narrow_environment
__p___argc
_cexit
api-ms-win-crt-filesystem-l1-1-0.dll _lock_file
_fstat64
_wstat64
_unlock_file
_unlink
api-ms-win-crt-time-l1-1-0.dll _time64
_gmtime64
strftime
_localtime64
api-ms-win-crt-environment-l1-1-0.dll getenv
api-ms-win-crt-math-l1-1-0.dll acosf
_dsign
__setusermatherr
roundf
powf
ceilf
fmodf
_fdopen
sinf
cosf
sqrtf
api-ms-win-crt-locale-l1-1-0.dll _configthreadlocale
localeconv
___lc_codepage_func
WS2_32.dll inet_pton
WSAGetLastError
WSASetLastError
closesocket
WSAWaitForMultipleEvents
WSAResetEvent
ntohs
WSAEventSelect
gethostname
ioctlsocket
sendto
recvfrom
freeaddrinfo
WSAEnumNetworkEvents
getaddrinfo
listen
htonl
accept
socket
select
__WSAFDIsSet
WSAIoctl
WSACreateEvent
setsockopt
recv
htons
getsockname
getpeername
connect
bind
WSACleanup
WSAStartup
getsockopt
send
WSACloseEvent
inet_ntop
CRYPT32.dll CertFreeCertificateChain
CertGetCertificateChain
CertFreeCertificateChainEngine
CertCreateCertificateChainEngine
CryptQueryObject
CertGetNameStringW
CertFindExtension
CertAddCertificateContextToStore
CryptDecodeObjectEx
PFXImportCertStore
CryptStringToBinaryW
CertFreeCertificateContext
CertFindCertificateInStore
CertEnumCertificatesInStore
CertCloseStore
CertOpenStore

Delayed Imports

1

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x188
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.89623
MD5 b8e76ddb52d0eb41e972599ff3ca431b 🔍
SHA1 fc12d7ad112ddabfcd8f82f290d84e637a4d62f8 🔍
SHA256 165c5c883fd4fd36758bcba6baf2faffb77d2f4872ffd5ee918a16f91de5a8a8 🔍
SHA3 37f83338b28cb102b1b14f27280ba1aa3fffb17f7bf165cb7b675b7e8eb7cddd 🔍

Version Info

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2026-Jan-25 11:46:31
Version 0.0
SizeofData 106
AddressOfRawData 0x1d9aa4
PointerToRawData 0x1d88a4
Referenced File C:\Users\fivem\Desktop\cleaner\SpooferUI(1)\SpooferUI(1)\x64\Release\Dominate.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2026-Jan-25 11:46:31
Version 0.0
SizeofData 20
AddressOfRawData 0x1d9b10
PointerToRawData 0x1d8910

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-Jan-25 11:46:31
Version 0.0
SizeofData 912
AddressOfRawData 0x1d9b24
PointerToRawData 0x1d8924

IMAGE_DEBUG_TYPE_ILTCG

Characteristics 0
TimeDateStamp 2026-Jan-25 11:46:31
Version 0.0
SizeofData 0
AddressOfRawData 0
PointerToRawData 0

TLS Callbacks

StartAddressOfRawData 0x1401d9ed8
EndAddressOfRawData 0x1401d9ee0
AddressOfIndex 0x140231428
AddressOfCallbacks 0x140157050
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_4BYTES
Callbacks (EMPTY)

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x1401f3f40

RICH Header

XOR Key 0x8536db45
Unmarked objects 0
Imports (VS2008 SP1 build 30729) 22
C objects (VS2022 Update 6 (17.6.4) compiler 32537) 24
253 (35403) 8
ASM objects (35403) 4
C objects (35403) 10
C objects (33145) 1
C++ objects (35403) 45
Imports (35403) 6
C objects (33523) 43
C objects (VS2022 Update 6 (17.6.4) compiler 32535) 129
C++ objects (34436) 5
Imports (33145) 40
Imports (21202) 5
Total imports 558
C++ objects (LTCG) (35721) 18
Resource objects (35721) 1
Linker (35721) 1

Errors

Leave a comment

No comments yet.