194afd639e1a60a24e476b67a8843ffe516ea2bfc33269bddb7a35b0f984650a

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2025-May-21 16:24:14
Detected languages English - United States
Debug artifacts C:\build\output\unity\unity\artifacts\WindowsPlayer\Win_x64_VS2022_VB_nondev_i_r\WindowsPlayer_player_Master_il2cpp_x64.pdb
FileVersion 6000.0.50.15855389
LegalCopyright (c) 2005-2025 Unity Technologies. All rights reserved.
ProductVersion 6000.0.50f1 (f1ef1dca8bff)

Plugin Output

Info The PE contains common functions which appear in legitimate applications. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryExW
Suspicious The PE is possibly a dropper. Resources amount for 83.983% of the executable.
Suspicious No VirusTotal score. This file has never been scanned on VirusTotal.

Hashes

MD5 cf4527269aaaa87b72527450bb807205
SHA1 e7acd9ce11e2708ee351bb5f5ea2afef2ef51ee5
SHA256 194afd639e1a60a24e476b67a8843ffe516ea2bfc33269bddb7a35b0f984650a
SHA3 b0eecc544af6448d484d9333832cef6c3ac88891283a7d5cf58f47502be3fdaa
SSDeep 12288:i2NCD1Jr3des1A6bAIyMbfl3r83/T7uNhEQKXgvbNArShaytplK26:ObdreMb9b8rnQKXjrfAplx6
Imports Hash ce1183cc150987a99aef5749f22af81e

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x110

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 7
TimeDateStamp 2025-May-21 16:24:14
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0xde00
SizeOfInitializedData 0x97200
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000001260 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0xa9000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 a5e0bf1e14a18380e4aa8fcfecd45cfd
SHA1 320e758c261b51cdf475ac1fe2d2b8b0f65ee37a
SHA256 9f9a743b5e5c12b459f7533a90382644af884df3aef68c9d7ac7d662735f193e
SHA3 0371197b472ffeeb91e1e7c7a9605222c7eee7431b878edcb558990adc374905
VirtualSize 0xdc70
VirtualAddress 0x1000
SizeOfRawData 0xde00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.46141

.rdata

MD5 75ba5b1b1b6aee94c24949c5bbd0cd16
SHA1 be4b811f666410e91741399a0547b1807aa768ab
SHA256 1819315bbda54e8119075434c1406559fcc378f8087d5913171fd97b58cf8741
SHA3 0c1ed5a1d973367630788c4435100c1a6b9692814f68e395b6f9ea268ed23e45
VirtualSize 0x977a
VirtualAddress 0xf000
SizeOfRawData 0x9800
PointerToRawData 0xe200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.70098

.data

MD5 d284f7b260ed119794375a6998c5083c
SHA1 0944c690e2b7841e681f55d2a731910f8019f2ef
SHA256 79ebad17e73900bd4dd43a932cc832e1d907346973e16ac0af549524fa4b88b3
SHA3 0c023444d7239a9582798618879cf6e165fcae6d6eec1051c77592814b4894ad
VirtualSize 0x1d78
VirtualAddress 0x19000
SizeOfRawData 0xc00
PointerToRawData 0x17a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 1.89847

.pdata

MD5 583bf012d5970545541b47ad6f1b2dc4
SHA1 ed34342900f8481a1f09e9f73fe8bb0d1e528eb6
SHA256 a7a9a284c12beceaf69e80c98bb9708078c1ee29e3581bf7c44e24e7535c04eb
SHA3 e57cf3023698fe8882221ba469ca26d236b8a3d44b7d67f42d621316177425fe
VirtualSize 0xf24
VirtualAddress 0x1b000
SizeOfRawData 0x1000
PointerToRawData 0x18600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.67239

_RDATA

MD5 dd297010ea596c9b749ddc72fe421330
SHA1 3213e7a4b99366f1367f1b5dc97aa4853369a784
SHA256 420a70f17663b392f63eb448853ebc800a3f7cf9c6e0b78b7e421d671dd927fd
SHA3 f4660bd566f5561530bb0e40a752616d5a8180b7180fcf869790d48f9fb6e9bf
VirtualSize 0x1f4
VirtualAddress 0x1c000
SizeOfRawData 0x200
PointerToRawData 0x19600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 3.71477

.rsrc

MD5 0d3f5a90448d40b453ab0784b207b8a4
SHA1 f925e4b3dffae763b22c84da4c159c30cb25c31b
SHA256 1c3e27ddfeaee9aa4608a12bbb313b805af254e5762e3c6daafea1e8705f5059
SHA3 60c92dff7bd88a2a1669418d8196d71f94bcd1bdd2e061762fbf8ffb8dbaa062
VirtualSize 0x8a020
VirtualAddress 0x1d000
SizeOfRawData 0x8a200
PointerToRawData 0x19800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.53912

.reloc

MD5 79918e2814a23b917e4a5494067a35d5
SHA1 eab8dd05e160cbff9fa1c348b6c35e7f161cf459
SHA256 cccb376562c958fee6ec06051a48d2c5c0232065e1000ce2d4b0775e46737238
SHA3 0fcd95a99b9b4e77c2e23089f450965a4028a243ef56d1928fdcfcebcc4b7120
VirtualSize 0x658
VirtualAddress 0xa8000
SizeOfRawData 0x800
PointerToRawData 0xa3a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 4.87002

Imports

UnityPlayer.dll UnityMain
KERNEL32.dll HeapAlloc
WriteConsoleW
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
IsDebuggerPresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetStartupInfoW
IsProcessorFeaturePresent
GetModuleHandleW
CloseHandle
RtlUnwindEx
GetLastError
SetLastError
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
GetProcAddress
LoadLibraryExW
EncodePointer
RaiseException
RtlPcToFileHeader
GetStdHandle
WriteFile
GetModuleFileNameW
GetCurrentProcess
ExitProcess
TerminateProcess
GetModuleHandleExW
HeapFree
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
GetCommandLineA
GetCommandLineW
MultiByteToWideChar
WideCharToMultiByte
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetStdHandle
GetFileType
GetStringTypeW
FlsAlloc
FlsGetValue
FlsSetValue
FlsFree
LCMapStringW
GetProcessHeap
HeapSize
HeapReAlloc
FlushFileBuffers
GetConsoleOutputCP
GetConsoleMode
SetFilePointerEx
CreateFileW

Delayed Imports

AmdPowerXpressRequestHighPerformance

Ordinal 1
Address 0x19004

D3D12SDKPath

Ordinal 2
Address 0x19008

D3D12SDKVersion

Ordinal 3
Address 0xf320

NvOptimusEnablement

Ordinal 4
Address 0x19000

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.92398
MD5 91545c3b20a81f82b60cdb2d24dc7168
SHA1 805f822bf3914f523a3f3f1d206a7497a82699d4
SHA256 d67bf1a922b03c26bc33bc7dec4622b2cdc3f82b1a075d07e9634f8a91be4add
SHA3 0a5f539238c5a1e9172b6e8ccdcbb345d81bff4624d656067ec19c500c8fe25b

2

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x988
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.297
MD5 4b0f6f6e253a01d19ad4f5cc02c173d3
SHA1 10da75150eb9ec200628f4585919e39139322d3f
SHA256 841e209e1d285ccd32bf33712c197b708708bffca541008f209d916d078fe141
SHA3 563379529c2cccec90922143b5d8196d33048c737a3f0d67dfc792289212bc74

3

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.45993
MD5 2bdd8ca54612dc06a3cc1fb01abe1379
SHA1 545aade27dff6f410be41aaf569604628ca5bdc0
SHA256 31b1115ebc1ac3bb14b6e502762419846a69b52340eb0297aabb22f50c237ed1
SHA3 12537d7b8e3bdb696764f44f3d0e284e93ba09d5cff4a085d640bb3257a0fa6d

4

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.46523
MD5 f5b93c4faf09c6b61a2ebac9fe070d29
SHA1 6217983ed5212a72c5a32db44481e69eb6c0f89c
SHA256 f50aad61f907351c69f2d1352839314b7716548995c39f64abcf8e162ceb0388
SHA3 9097a4d9e39a9da065c065be4d4e8d407699ab56813c4cd5ead8760d88212720

5

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x4228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.52902
MD5 a7052c84a47ecf45f03d626d5828a342
SHA1 829c20312b4717a3ba87285ed9778705b7086a6e
SHA256 0fbb2d9260fc99d2476314a6a485461717fe4cf0dd08d344ade434948ef12d30
SHA3 12e31c1c0c48f60d2b0116a8c663e52bd198422298d124e09e434c3034d29c91

6

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x94a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.53798
MD5 324697cbd15cacd4f491ece57d9b950c
SHA1 688db96c1589c27dd68ec46330da174fc5032ad3
SHA256 f76791754613e450c75c4b8842cb14a33c55d4a6f19e125a192c5451f59a4d4c
SHA3 12015230623634134e8b62316f5b6566e1f10a794d94b6d08e529383b762c69b

7

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10828
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.53572
MD5 cd98afe3f9131aa6046a3fc630a96bb9
SHA1 ebf6c414e4ccb6d324c8069c2c38cb847a051613
SHA256 fdd47059ad6117b0a00494b35fe538c6ba52814daf8ad6d1d884ab610058c7cf
SHA3 89cb5f2206e8a6f1fedd2bc78b55120a5b423dd2c389bc488d41b06b7f62765e

8

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.53559
MD5 ad5aad20622501492bf90da3c8967a23
SHA1 7247a5ac6b143a171fd139dc290417b950487519
SHA256 ce18324229e3af73f82f79bb9d62eef38fbe4d8906e928a1525c8adea3b97efe
SHA3 56dece5c81243fe03b4954f02b78c59ea51abbfd009c694d5ca8fe9c2b9b74b1

9

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x42028
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.53147
MD5 2809fe61d1db24f2df2c0025c8efd682
SHA1 0baf6e754b68b707957a1aca2144d303b37a1eee
SHA256 4fbab4156a7c5dff30464237f3d7ac9da8466c16d9240328d58df6c9c4e92b02
SHA3 25d01fe97b2dce661fbe0e29024356cd611d926db95b22ee50d698edafdea765

103

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x84
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.04448
Detected Filetype Icon file
MD5 3bf2dac037ce87794e66ff7f054e913f
SHA1 52ca961fd37ad960905a681d1db5157508ef1602
SHA256 2a87b1f32c5d0435090c72c392b75394f706e5750eff64fd85d25e1c622ee581
SHA3 8454d3273522657b5926068082b2cb88f6dbf352e7e9568008c0e33c792f349b

1 (#2)

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x214
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.48133
MD5 ec465238d41a9fa449c3aabae24c1eb0
SHA1 bb3b4c2e02668547459469b90b24b30a5c5c7d34
SHA256 13677e31673551699cc34c73d27f33148ae1adc391c35729c5e8ecf45e27e4c8
SHA3 9e481f61531af715d2b24d2a585cfabbd8174816898a2d9195f204aff3d85ff7

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x545
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.24993
MD5 9df530c2f4fbe460da74e130d5d351a9
SHA1 f8719b6c74e0179556c1a18f214d6c1bbff8f823
SHA256 3c357bd1125971bda05bc59eaeca279da41715741e2535e9e75c94273b1c3a1f
SHA3 ce3dd46f87bd462f8730fca18daea6df444422f8d88b810aefbd7b2e62536dee

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 6000.0.50.61213
ProductVersion 6000.0.50.61213
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_UNKNOWN
Language English - United States
FileVersion (#2) 6000.0.50.15855389
LegalCopyright (c) 2005-2025 Unity Technologies. All rights reserved.
ProductVersion (#2) 6000.0.50f1 (f1ef1dca8bff)
Resource LangID English - United States

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2025-May-21 16:24:14
Version 0.0
SizeofData 148
AddressOfRawData 0x16d58
PointerToRawData 0x15f58
Referenced File C:\build\output\unity\unity\artifacts\WindowsPlayer\Win_x64_VS2022_VB_nondev_i_r\WindowsPlayer_player_Master_il2cpp_x64.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2025-May-21 16:24:14
Version 0.0
SizeofData 20
AddressOfRawData 0x16dec
PointerToRawData 0x15fec

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2025-May-21 16:24:14
Version 0.0
SizeofData 852
AddressOfRawData 0x16e00
PointerToRawData 0x16000

TLS Callbacks

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x140019040

RICH Header

XOR Key 0x7139305b
Unmarked objects 0
ASM objects (28900) 5
C++ objects (28900) 138
C objects (28900) 10
Unmarked objects (#2) 1
Imports (28900) 2
C++ objects (33218) 40
C objects (33218) 16
ASM objects (33218) 17
Imports (33523) 3
Total imports 89
C++ objects (33523) 2
Exports (33523) 1
Resource objects (33523) 1
Linker (33523) 1

Errors

Leave a comment

No comments yet.