0528fcb02ee6ce4a66b4dd401f3d8541493af540cd7b86c7962c8168302a3ce2

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2025-Sep-26 11:16:27
Detected languages English - United States
Debug artifacts C:\build\output\unity\unity\artifacts\WindowsPlayer\Win64_VS2019_nondev_i_r\WindowsPlayer_player_Master_il2cpp_x64.pdb
FileVersion 2022.3.62.7762112
LegalCopyright (c) 2005-2025 Unity Technologies. All rights reserved.
ProductVersion 2022.3.62f2 (7670c08855a9)

Plugin Output

Info The PE contains common functions which appear in legitimate applications. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryExW
Suspicious The PE is possibly a dropper. Resources amount for 84.749% of the executable.
Safe VirusTotal score: 0/72 (Scanned on 2026-03-21 12:58:40) All the AVs think this file is safe.

Hashes

MD5 3047bb3d01c742fe14e59c2dd95eaae4
SHA1 ae5453454409a0b3d24c6f4a48ca494e84f835cf
SHA256 0528fcb02ee6ce4a66b4dd401f3d8541493af540cd7b86c7962c8168302a3ce2
SHA3 da9a40128e7e3dcef3133839ceadfc6f9a77834171fb999ba040ac1969fae131
SSDeep 3072:AQd/VdFg4W9mYucJ/OD8JOsI9VRAGJNUvK3rDbmiwJjQsfLfrGdZ9zxA3:R/7Fu9mpcJ/OD81GMvKujQIrrGtzx2
Imports Hash a136217cdd3247ff6a8766561064ca0b

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x110

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 7
TimeDateStamp 2025-Sep-26 11:16:27
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0xca00
SizeOfInitializedData 0x97000
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000001264 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0xa8000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 e1ace82cc0f3d159779f5c95aa7e575b
SHA1 e4a5358996f267c921e5d996de44f3525bb042ed
SHA256 bec109031034001337c9be3c07e16f6fab9c862313fc1f8fb0699672e09c63a4
SHA3 449bef44a9ee4a68767a70da31c7ceb6aa3d1da49237a84227bbfb02c7e428a2
VirtualSize 0xc8b0
VirtualAddress 0x1000
SizeOfRawData 0xca00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.41019

.rdata

MD5 7d256bd52aef67d03e7c7253271192ec
SHA1 3ab37b847e25d6e4133478969795874663fdc77d
SHA256 8f02eaeead5b682bb4c8e1c2ed04fbaf9370103f3c335eaef21a55266bb3d95a
SHA3 82acbccd494473dd61dc80491d7cae47ae2b8aa97cef2557e30f527bd4b9de10
VirtualSize 0x948c
VirtualAddress 0xe000
SizeOfRawData 0x9600
PointerToRawData 0xce00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.65457

.data

MD5 90815aa5dc65a7dd3f93bad1bd78a77e
SHA1 608f3e69047b216dda6b0df73c30912e2fef5544
SHA256 435cb9af1df25f501f68a9700182c4d25de99c3f8e8c1ba6b16c0ca98911ff87
SHA3 e5ea90d4dd767bfa3d88e3fa2e107c2e40cac10f43498d5abd74f15888477d18
VirtualSize 0x1d38
VirtualAddress 0x18000
SizeOfRawData 0xc00
PointerToRawData 0x16400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 1.87032

.pdata

MD5 6e619149c26d436c6f07193ff1e8032b
SHA1 70aea7c26eff6d7619bd6a5a97ab259d68dd24f5
SHA256 48cb5fb202e79c0b8da5091cb440a9068502b37c8e4200eb78df617ae99fd024
SHA3 196183a21caf69a7292ff77b288d707ce7d63e2b887053ae1bc258b99d1e36f0
VirtualSize 0xef4
VirtualAddress 0x1a000
SizeOfRawData 0x1000
PointerToRawData 0x17000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.62125

_RDATA

MD5 f87f407c2a1cab208757ad1d23a2de6f
SHA1 cd739c36958f9ba7505883ae868f1a6ca71e880f
SHA256 6e4ba525d12ef66132e0738191d3a928ba74c0091a6f82bc48f892a41e2fc242
SHA3 0611ad194d9c623281cb358dbc2f2d28bb01b6eab682677ec8d16136d74414ab
VirtualSize 0x94
VirtualAddress 0x1b000
SizeOfRawData 0x200
PointerToRawData 0x18000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 1.11888

.rsrc

MD5 06b3330c0cf036605af9f1aaa40b4214
SHA1 cbc39dfb8ee36d2ede5f6f070ad983a73004c5d6
SHA256 c99b6fe738eb102358a4aacb8a593d6c36c669180241eefce1fc97f06a2600c7
SHA3 eed9aad3af4cd90ba544698a57d57dee3958ad87d9460d13f5ad1f0daf9b4924
VirtualSize 0x8a198
VirtualAddress 0x1c000
SizeOfRawData 0x8a200
PointerToRawData 0x18200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 3.71348

.reloc

MD5 ef1e558d46106d87320dd822be1ddc48
SHA1 10f7b05d107451bd01cf446da512c619fc35bf50
SHA256 34d7b771018e478ba05cd24ec377fd34919d65ec63c43f49e1ab319785368929
SHA3 cc295f58e62efe5c59cad1febf1ce620404450135f442c20ba55235b492ddac9
VirtualSize 0x654
VirtualAddress 0xa7000
SizeOfRawData 0x800
PointerToRawData 0xa2400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 4.84209

Imports

UnityPlayer.dll UnityMain2
KERNEL32.dll HeapAlloc
WriteConsoleW
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
IsDebuggerPresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetStartupInfoW
IsProcessorFeaturePresent
GetModuleHandleW
CloseHandle
RtlUnwindEx
GetLastError
SetLastError
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
GetProcAddress
LoadLibraryExW
EncodePointer
RaiseException
RtlPcToFileHeader
GetStdHandle
WriteFile
GetModuleFileNameW
GetCurrentProcess
ExitProcess
TerminateProcess
GetModuleHandleExW
HeapFree
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
GetCommandLineA
GetCommandLineW
MultiByteToWideChar
WideCharToMultiByte
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetStdHandle
GetFileType
GetStringTypeW
FlsAlloc
FlsGetValue
FlsSetValue
FlsFree
LCMapStringW
GetProcessHeap
HeapSize
HeapReAlloc
FlushFileBuffers
GetConsoleOutputCP
GetConsoleMode
SetFilePointerEx
CreateFileW

Delayed Imports

AmdPowerXpressRequestHighPerformance

Ordinal 1
Address 0x18004

NvOptimusEnablement

Ordinal 2
Address 0x18000

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x42028
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.55291
MD5 20dfc21f8d3a87a16964c334d0e7bc85
SHA1 fbde1cf74f15fea819882eda27fd230867974a4e
SHA256 0dc45c66b6bb1b222c0ded3aa88a6092c4761415f8f7fef62aeb68fd7fb450c5
SHA3 9c7b708f914b1d7203bc89b50a66979f48a6053be64729069ae4149997aa3eea

2

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.62626
MD5 f044690ff03d1a7f68c5989ef48faa2b
SHA1 96f7425ebd8bac485df83b2bbecf5b70f36efdad
SHA256 9554feccb318086f93c17c533fb04b671c918e2b7b3c9619b512605b9ce770de
SHA3 df59fe81e551f19c9f4a8771af2e2c3d8d4c67514f86e9b111ea196fe3d6e33d

3

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10828
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.75825
MD5 239c3225efb58b0f31cb2584476f16f6
SHA1 d78f643d87c62dedca433df0b2258f260303c917
SHA256 44f68bc14a831bc4e4a30a6616a526eaa2a19ae301242b969ee32b5f12c2c66c
SHA3 5e4fe613ad7dda6ca150cec33efe39cfbed3a76b235d0a3c320d4bf712ad9b6e

4

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x94a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.90922
MD5 90849b94a050411ef20bebdd1af29f75
SHA1 e09cf7667308af551b1bda796b0b73f0158e27fd
SHA256 54d90d88de0fc9013177c7a79d75747957ae179873f99ed3ea23cb062cc1876d
SHA3 91979b62518835b1f586b56b87ed023b6364f5d720ba9e8a5a9a5c8deed6443b

5

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x4228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.15409
MD5 69d49834e0b9a68899afb8d2f8a7f56c
SHA1 5c208d68350a0f2101fcae4e7e54b577d90531ec
SHA256 f5068e169d02712713800dc5079d28c7206df61691f4ea911413d089bf4b36ed
SHA3 56962fe14cb31f388ea7da507fa6cc8c51675571c127162fd283ae853756e7e1

6

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.32716
MD5 0b03acf186a6551113369e35a20f458d
SHA1 c151a54c0f5bc406bc193ef36105b9ecbe539270
SHA256 3a495a68cab05f5a8e0ac0346426e4a9fef15ab7877e2643739e83b0681d91d9
SHA3 069445c3137f2d0115c2cb3d90a4bf91b76d32b1171ea65d4fea77d4893c9416

7

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.6478
MD5 0e1b1e6814901e60c8349c0596b32e83
SHA1 dee387318308bfba9a6c94aae2deb5f480c1a0bb
SHA256 ca1ada3f0fb415938c34d487b58ea9032a376d1210cfe7712a070f72edf0d61f
SHA3 5ca40f07f5a3dfaae25fea54d24c1755d9c92ecef2341ff6ef8338e63766cb0b

8

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x988
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.83599
MD5 0611cd55d3021100df6cf8dba550e939
SHA1 4ce4d7a7f2fb7b95a3aced93297b021b25d0ecb1
SHA256 7bc5c5f1de8b7c2cc2aef819b32b9f33577f2cfaeec78dc4a6e47de181ea953a
SHA3 6617caf4aca0e369c5e61f881b5f18b7d74b2d0a51cbed62877099e4c6572f28

9

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.0815
MD5 f5912a07b9d6c7abd13cbe1f7969fea8
SHA1 440e353f34a8680e18418528fb5deb26bca29701
SHA256 b92ffbb1104c1f6e83aece0f4e4782440c62ceee27b5e2f364e745f5d0340615
SHA3 9dae0706ec79b91cb788bf74a4310a124dd3e23be3bd8d23a7cbc763c147ff06

103

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x84
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.04448
Detected Filetype Icon file
MD5 f7731730720cfe035cf030b40d0e2eb6
SHA1 d046e23f2ee2b93ad96be8e1dc9120ecf3915091
SHA256 5c92a41adaf3265071482fd1a182ae8702c168636a7d9ff51798ee3a1dfc8500
SHA3 6f2d12e4c63c131a3f7f48293996e2be05da351536d013affe5d2265965ce657

1 (#2)

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x210
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.55946
MD5 a817f5c1ee4993dc4fb84fbfc5cbd0bb
SHA1 ffb6bbc9ea4d9108b994b5b4d71fc558827c88a6
SHA256 4a7fde3055000864489cc4abddfe9a8c5dfbd3b0129f76c59e1b5068b2c8459d
SHA3 86d49d4ea4b0e3900b5aa666f910c3aff9973b8e17aa1aac4a9b04dc06fd3953

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x6c1
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.37708
MD5 aab7e8aafe7b06ab3d003b54ab5e18ed
SHA1 dccf0408f43059df37b755f3241a8b4b35c728af
SHA256 fb88b19523afd8fed48eddfd10805a3a0a45997bbf8fac04d595ddf93c1a88a8
SHA3 a981b8e907b79cd9448766ace938dfd96560d11c29e6ba165912a8508bd52ca7

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 2022.3.62.28864
ProductVersion 2022.3.62.28864
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_UNKNOWN
Language English - United States
FileVersion (#2) 2022.3.62.7762112
LegalCopyright (c) 2005-2025 Unity Technologies. All rights reserved.
ProductVersion (#2) 2022.3.62f2 (7670c08855a9)
Resource LangID English - United States

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2025-Sep-26 11:16:27
Version 0.0
SizeofData 143
AddressOfRawData 0x15aec
PointerToRawData 0x148ec
Referenced File C:\build\output\unity\unity\artifacts\WindowsPlayer\Win64_VS2019_nondev_i_r\WindowsPlayer_player_Master_il2cpp_x64.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2025-Sep-26 11:16:27
Version 0.0
SizeofData 20
AddressOfRawData 0x15b7c
PointerToRawData 0x1497c

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2025-Sep-26 11:16:27
Version 0.0
SizeofData 768
AddressOfRawData 0x15b90
PointerToRawData 0x14990

TLS Callbacks

Load Configuration

Size 0x138
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x140018030

RICH Header

XOR Key 0xe5e06b0d
Unmarked objects 0
ASM objects (28900) 5
C++ objects (28900) 138
C objects (28900) 10
Imports (28900) 2
C++ objects (VS 2015/2017/2019 runtime 29118) 39
C objects (VS 2015/2017/2019 runtime 29118) 16
ASM objects (VS 2015/2017/2019 runtime 29118) 9
Imports (VS2019 Update 8 (16.8.0-1) compiler 29333) 3
Total imports 89
C++ objects (VS2019 Update 8 (16.8.0-1) compiler 29333) 3
Exports (VS2019 Update 8 (16.8.0-1) compiler 29333) 1
Resource objects (VS2019 Update 8 (16.8.0-1) compiler 29333) 1
Linker (VS2019 Update 8 (16.8.0-1) compiler 29333) 1

Errors

Leave a comment

No comments yet.