0b6d1d6b275b51d8ecb3b2904a8b2ea13b708c58b0fc7a9bf7340627d423dca7

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2023-Jan-20 03:00:51
Detected languages English - United States
Debug artifacts C:\build\output\unity\unity\artifacts\WindowsPlayer\Win64_VS2019_nondev_i_r\WindowsPlayer_player_Master_il2cpp_x64.pdb
FileVersion 2021.3.17.4096273
LegalCopyright (c) 2023 Unity Technologies ApS. All rights reserved.
ProductVersion 2021.3.17f1 (3e8111cac19d)

Plugin Output

Info The PE contains common functions which appear in legitimate applications. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryExW
Suspicious The PE is possibly a dropper. Resources amount for 86.4075% of the executable.
Safe VirusTotal score: 0/67 (Scanned on 2025-12-28 05:01:10) All the AVs think this file is safe.

Hashes

MD5 a997c534c3fa0a16c0e595ef322ccb96
SHA1 1c66524d5bb90f890488627f5306682fa4117873
SHA256 0b6d1d6b275b51d8ecb3b2904a8b2ea13b708c58b0fc7a9bf7340627d423dca7
SHA3 7be09cf03064c3302e83d521a20f6d8d0cf57cf43a555412fe3f3ebe7668d5b4
SSDeep 3072:WQ/EJhz2WnBUCsyfYDbMFrJNO31eDELyHqWrGy8F74J:ZEbaWnBUCGTegLyHazF74J
Imports Hash 5f74a5c747508e2822fdb9b687deaf42

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x118

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 7
TimeDateStamp 2023-Jan-20 03:00:51
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0xa200
SizeOfInitializedData 0x96600
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000001260 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0xa5000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 4190b7be9f5f4eb52c040a688e61a250
SHA1 ee3a1c75987c1b0e5e4ed015cbe0c92530bdad11
SHA256 7d92c29b88ce9a3c69a11f70fbc73e302f5d8d66766589406274d31e97ed920b
SHA3 0e04178fbb1a5d03ab267f800a38d342bb9f4a2bb6441604af8a9b52ecb4c4c6
VirtualSize 0xa140
VirtualAddress 0x1000
SizeOfRawData 0xa200
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.39724

.rdata

MD5 b64ebf7b3b334da33d3dbe0bceea9dbf
SHA1 c11b90ffc429ba39a8311c14ada3a8d8d198512e
SHA256 af78d3b2647908c61c99cda436d20804d90eb2a7131b5d3e2353d6659896b3a3
SHA3 4a6ee9a5b222c29a0cc2b507a5ca5aeb6ddaa473d0c5dc34699436b05392017f
VirtualSize 0x8cce
VirtualAddress 0xc000
SizeOfRawData 0x8e00
PointerToRawData 0xa600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.65376

.data

MD5 2e9924c581c86e57e2e2b0ac87e1aa45
SHA1 a1a176fc5c54e8c996a328e810c15c16cdb5b73d
SHA256 90b0d83be28bc06320f7b2ce10f056ecd17badc2e84e2b1533c0454096a1e5a0
SHA3 8c3bb6dfd1204e833639461f26a41ad45e7fa68dcdc97aa4908992d272dc2237
VirtualSize 0x1ce8
VirtualAddress 0x15000
SizeOfRawData 0xc00
PointerToRawData 0x13400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 1.6801

.pdata

MD5 2717431295e555cdae3fb602e2bd957e
SHA1 408d09336a1192e50edb78d3e7795fbc547ac381
SHA256 d927fd3b2aebd7b714861d2fede4d4929f356363e518385fd3c95e3262524631
SHA3 bbf9f4f071095b27e2349d9a28e1c01b5066c00143b8c5f7a393d2267f8178a5
VirtualSize 0xc54
VirtualAddress 0x17000
SizeOfRawData 0xe00
PointerToRawData 0x14000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.34687

_RDATA

MD5 1960efd573f3d23522c840210d59fb7e
SHA1 47057bb39ae6c80b68d90c47f0cfd7d6bf123ad2
SHA256 ad5bd98e9035110e2e2e7b82ed2fe49ec0fae2d89e05400528a6b48804c441a4
SHA3 225389cba41c0a9e2c3319b0921ec1ef9962e8af175fca30c67bde60763834d4
VirtualSize 0x94
VirtualAddress 0x18000
SizeOfRawData 0x200
PointerToRawData 0x14e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 1.08512

.rsrc

MD5 b2f97456e7d0bc9987d616f4e1ac9046
SHA1 1fab9a332848f0c725db88153e534988647af02f
SHA256 83eea93ffb9183cc0e5740a479c81a7d43cc409ded4ace7b01617f48ae0d1b00
SHA3 99ffc6d01ac480ff9aa698c730649380a7f05b11ffb1b60467fa65247957cc93
VirtualSize 0x8a198
VirtualAddress 0x19000
SizeOfRawData 0x8a200
PointerToRawData 0x15000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 2.78318

.reloc

MD5 687aa942cda2e64adc67a829f1587240
SHA1 26058e365b4fef9cae39c529017700cd0ccfedb7
SHA256 e5b51406ab27a5065a374454ac72e242a50072d670957430f820af90f479b506
SHA3 8a51aae6ca0ea13d9513cba0336e2446957914c5ba6561a337c3afdf42f3c689
VirtualSize 0x638
VirtualAddress 0xa4000
SizeOfRawData 0x800
PointerToRawData 0x9f200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 4.79086

Imports

UnityPlayer.dll UnityMain
KERNEL32.dll WriteConsoleW
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
IsDebuggerPresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetStartupInfoW
IsProcessorFeaturePresent
GetModuleHandleW
CloseHandle
RtlUnwindEx
GetLastError
SetLastError
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
GetProcAddress
LoadLibraryExW
RaiseException
GetStdHandle
WriteFile
GetModuleFileNameW
GetCurrentProcess
ExitProcess
TerminateProcess
GetModuleHandleExW
HeapAlloc
HeapFree
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
GetCommandLineA
GetCommandLineW
MultiByteToWideChar
WideCharToMultiByte
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetStdHandle
GetFileType
GetStringTypeW
LCMapStringW
GetProcessHeap
HeapSize
HeapReAlloc
FlushFileBuffers
GetConsoleCP
GetConsoleMode
SetFilePointerEx
CreateFileW

Delayed Imports

AmdPowerXpressRequestHighPerformance

Ordinal 1
Address 0x15004

NvOptimusEnablement

Ordinal 2
Address 0x15000

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x42028
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.50509
MD5 23d1a70bed283b7ca77c6462a99f100b
SHA1 0011b0cefaf81bdc18cd8e779557faa25a371e81
SHA256 5dcf46d031f0764c9febd34a37ef547f683759401abdce829abafff0987a4aab
SHA3 07b50c560bbcc1a3f73dba087b37d81bda9158824beac1f65382a1a2ebc88e0d

2

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.80183
MD5 357a5ee0bb4e4468bef1b8223ef23273
SHA1 86c6e95a0baf4a03afbeabaa703d68c14ef07e46
SHA256 7f7922f1129975149c72d816d23552d27f6f3987aabb9359fbcbc6d2b9edd1e1
SHA3 3214bf129412f3e195a4d78996f6e1177f7e391e5137e44204e539799cb27eed

3

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10828
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.86632
MD5 7233eb110f479fed6d4e9b382400e10d
SHA1 bd48b006fb8e781454d7a0abdc2b5f563ca355fd
SHA256 542ff27722e1d4e83866d779e08f0a449fb859be71ceb0ad1a18329713b393e9
SHA3 ab39b044e31878fb6b45b8f276add0574394e58ebd213d347a7c8f68d5b00118

4

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x94a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.9023
MD5 718503b802059a12b69130ddf6d28be0
SHA1 39b199252d6e5cf1be8efcb000ea64939d2e5df6
SHA256 058abc16b355b4df7acf191a10229de16b5148eac894e163cba296a8c5a07bbb
SHA3 ea722f5477e5e98355e7eee74a02920a1aa4fcb45502607c2432e41f3c72c0b8

5

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x4228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.03987
MD5 446d3e68d9fa8776619e8e01a74ffede
SHA1 3b140cad2eca5e7b6b7c7078a27186150c6ba755
SHA256 c85345509ae334a21bb777be65a20e8155104c76c5cbdf29dbbd64446e33b3f5
SHA3 1407604f924db01bd012fb4cc33a06ee08692724a722ebf21acb6c4f4ae36816

6

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.13976
MD5 30aef1b5404df458158f4d6a9cb9571f
SHA1 b313031e5e9e541c6464275d0ca57cb7baabd31e
SHA256 0a0b07b124a2827690642c74671b225911c6f33ad2f8bf4c7c73670f4ea160fb
SHA3 17fa98c5f9d3570fa21c9873a35f4fdcaf40d37b51d96c18b47a039332ababb4

7

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.53662
MD5 16e981b1ba3e7f02e2a26712c9a58f64
SHA1 10fd995a599ca1b84fcfac90426e4e481a0e94f0
SHA256 d8c9fca5fdb7ef4f480a53aa9951ca77332724fa2da6fbd680c21c602f6cdd5b
SHA3 c7027a602dddd991d0788451afa1fc40e5911699cd1b45b76ebe0074e9b293ba

8

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x988
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.73982
MD5 45778eeb58ca20af101c347ddc65cbb6
SHA1 a9358de430f3675cf06332ea14410d7aa1232242
SHA256 a83dca5805c0892f70141ef38bd0de645d08489b4b12132e0da15b87e6146d69
SHA3 7897204ec713e9f01db3ee05c138606e226d8813c086209eb0039978d8c184c7

9

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.95704
MD5 b2e777b4f8ebd7fe9e2cb3d4b59dbbe6
SHA1 cdbc3bff3b324c2ef9c804716afb382cd3dec7be
SHA256 bd2660eb15798b9ffede7b778348e4474f68baa5c939ab6585af1e1629a3a61d
SHA3 0c2aef608c70f04bca5dd2927a4d880030eff7114b8532fc9be3d0c8aa4d417d

103

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x84
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.04448
Detected Filetype Icon file
MD5 f7731730720cfe035cf030b40d0e2eb6
SHA1 d046e23f2ee2b93ad96be8e1dc9120ecf3915091
SHA256 5c92a41adaf3265071482fd1a182ae8702c168636a7d9ff51798ee3a1dfc8500
SHA3 6f2d12e4c63c131a3f7f48293996e2be05da351536d013affe5d2265965ce657

1 (#2)

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x20c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.57179
MD5 a1da9623f84ba0673efd549fb0993fe5
SHA1 c7b9bfba338fc57786ce0e652885e48848614a9b
SHA256 94d6ecd3cd38d603b20e2ea9d169fc56498fd5c0e364a843ece24b7d2bb6e19c
SHA3 1b20059cd782bfec23405ebf870d67428b91871095186f86fc7d75c7bdc38160

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x6c1
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.37708
MD5 aab7e8aafe7b06ab3d003b54ab5e18ed
SHA1 dccf0408f43059df37b755f3241a8b4b35c728af
SHA256 fb88b19523afd8fed48eddfd10805a3a0a45997bbf8fac04d595ddf93c1a88a8
SHA3 a981b8e907b79cd9448766ace938dfd96560d11c29e6ba165912a8508bd52ca7

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 2021.3.17.33041
ProductVersion 2021.3.17.33041
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_UNKNOWN
Language English - United States
FileVersion (#2) 2021.3.17.4096273
LegalCopyright (c) 2023 Unity Technologies ApS. All rights reserved.
ProductVersion (#2) 2021.3.17f1 (3e8111cac19d)
Resource LangID English - United States

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2023-Jan-20 03:00:51
Version 0.0
SizeofData 143
AddressOfRawData 0x13780
PointerToRawData 0x11d80
Referenced File C:\build\output\unity\unity\artifacts\WindowsPlayer\Win64_VS2019_nondev_i_r\WindowsPlayer_player_Master_il2cpp_x64.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2023-Jan-20 03:00:51
Version 0.0
SizeofData 20
AddressOfRawData 0x13810
PointerToRawData 0x11e10

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2023-Jan-20 03:00:51
Version 0.0
SizeofData 712
AddressOfRawData 0x13824
PointerToRawData 0x11e24

TLS Callbacks

Load Configuration

Size 0x138
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x140015030

RICH Header

XOR Key 0x735735a6
Unmarked objects 0
C objects (VS2017 v14.15 compiler 26715) 10
ASM objects (VS2017 v14.15 compiler 26715) 5
C++ objects (VS2017 v14.15 compiler 26715) 136
Imports (VS2017 v14.15 compiler 26715) 2
C++ objects (VS 2015/2017/2019 runtime 29118) 37
C objects (VS 2015/2017/2019 runtime 29118) 16
ASM objects (VS 2015/2017/2019 runtime 29118) 9
Imports (VS2019 Update 8 (16.8.0-1) compiler 29333) 3
Total imports 85
C++ objects (VS2019 Update 8 (16.8.0-1) compiler 29333) 3
Exports (VS2019 Update 8 (16.8.0-1) compiler 29333) 1
Resource objects (VS2019 Update 8 (16.8.0-1) compiler 29333) 1
Linker (VS2019 Update 8 (16.8.0-1) compiler 29333) 1

Errors

Leave a comment

No comments yet.