1e312fa8e8d17c63335ade0873f42d2b2feadfaf89c3447ca25197317d88809a

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2022-Aug-31 00:30:19
Detected languages English - United States
Debug artifacts C:\buildslave\unity\build\artifacts\WindowsPlayer\Win64_VS2019_nondev_i_r\WindowsPlayer_Master_il2cpp_x64.pdb
FileVersion 2020.3.36.7469419
ProductVersion 2020.3.36.7469419
Unity Version 2020.3.36f1_71f96b79b9f0

Plugin Output

Info The PE contains common functions which appear in legitimate applications. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryExW
Suspicious The PE is possibly a dropper. Resources amount for 86.3959% of the executable.
Safe VirusTotal score: 0/72 (Scanned on 2026-03-03 22:34:01) All the AVs think this file is safe.

Hashes

MD5 167bc514f62964bd51dc7783810f29a9
SHA1 eb882146c57fc549cfa46e11b9c025f0e5806036
SHA256 1e312fa8e8d17c63335ade0873f42d2b2feadfaf89c3447ca25197317d88809a
SHA3 73f992aba49197477767adc312f6ba48841c0bf717baa9827cf71a37deea4e04
SSDeep 6144:VpC62lkCT3A1xJhY0z9/ckZamYZ1B3PcbVJG+gULpaq9TL:V4eCR0zdt8n1B3PcbV8dsaq93
Imports Hash 5f74a5c747508e2822fdb9b687deaf42

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x108

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 7
TimeDateStamp 2022-Aug-31 00:30:19
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0xa200
SizeOfInitializedData 0x96600
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000001260 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0xa5000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 dc34d9506ae9e3616b5265da7e35b1f6
SHA1 dce8f4d17ddc08b8460b046a362a27430cbe2e75
SHA256 e80b2c4dfacb7fab649683f679231937cf85d5498d6d4b5d3a3e61149f064124
SHA3 08b3146b697934b2f68c0ed66868b3c96973ed20c4a70245a96b304f456d0106
VirtualSize 0xa120
VirtualAddress 0x1000
SizeOfRawData 0xa200
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.39574

.rdata

MD5 0012a8b376d329d1464d4476535d344a
SHA1 a1f375b88e247644a34bb5bb41af2dadb5e4fe05
SHA256 97a46e397397a4d39c07e496ddf73f892c69c1a46d694142ecd19684d00efd14
SHA3 79785a16a7b662ec79247431fb99daeac44e7821f6a0a5befe5c5833c7886152
VirtualSize 0x8c6e
VirtualAddress 0xc000
SizeOfRawData 0x8e00
PointerToRawData 0xa600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.65235

.data

MD5 a9e79420695e9bc679ca784c3876e94f
SHA1 85d68049c56be1369a584c2cef1f26bece917c8f
SHA256 a64f2a1dd771a4ddc2a8b9ebecec8d75683a19da0fcb7c92b1ca380ca540a055
SHA3 902fec18ac997b92fb99b25384f1c089fc9ae1ab1d849e846fff2b3a4d2bd9fa
VirtualSize 0x1cd8
VirtualAddress 0x15000
SizeOfRawData 0xc00
PointerToRawData 0x13400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 1.67624

.pdata

MD5 789f36f907239c1ceca2f8ec3f79fcb5
SHA1 11b2d5522be4b2558a7e492c53b4d86184702c90
SHA256 5e2c8dede33e201308d3fabb30b57b487ba34d524537e56449f854c9d6e560e4
SHA3 0b06f78c7fe1c1611e2e7abfd4a78a87cf82474f2ac5b4a8daa9c07fbbf85778
VirtualSize 0xc48
VirtualAddress 0x17000
SizeOfRawData 0xe00
PointerToRawData 0x14000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.36097

_RDATA

MD5 1960efd573f3d23522c840210d59fb7e
SHA1 47057bb39ae6c80b68d90c47f0cfd7d6bf123ad2
SHA256 ad5bd98e9035110e2e2e7b82ed2fe49ec0fae2d89e05400528a6b48804c441a4
SHA3 225389cba41c0a9e2c3319b0921ec1ef9962e8af175fca30c67bde60763834d4
VirtualSize 0x94
VirtualAddress 0x18000
SizeOfRawData 0x200
PointerToRawData 0x14e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 1.08512

.rsrc

MD5 272fc089a6f52373eb2191f67e154f9b
SHA1 04bf0281f4cbb4ee7a42f4852f3ba1e299a7ca19
SHA256 05e1cf493eb98d9ac60dcd70e9afec740628f0333b43188bb1a3994646f053a9
SHA3 66933d7ecb69a710cdd73ecfc0add436cb9a23a33d0021a0cfbfea0b5bd5a93a
VirtualSize 0x8a148
VirtualAddress 0x19000
SizeOfRawData 0x8a200
PointerToRawData 0x15000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.31321

.reloc

MD5 a9c3cf69888151777a2a472fa85313df
SHA1 a5410c074ce059a802887d8ef48a198d601aa9e3
SHA256 02d5b365a568a1cfd46be8549a8fee9793a57a8d69c3544d8232330a87a3d7ad
SHA3 874351b3eea840f9c0337e4533e9a1b535fab5c0ccdeba911f149a1902c60a44
VirtualSize 0x634
VirtualAddress 0xa4000
SizeOfRawData 0x800
PointerToRawData 0x9f200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 4.78467

Imports

UnityPlayer.dll UnityMain
KERNEL32.dll WriteConsoleW
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
IsDebuggerPresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetStartupInfoW
IsProcessorFeaturePresent
GetModuleHandleW
CloseHandle
RtlUnwindEx
GetLastError
SetLastError
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
GetProcAddress
LoadLibraryExW
RaiseException
GetStdHandle
WriteFile
GetModuleFileNameW
GetCurrentProcess
ExitProcess
TerminateProcess
GetModuleHandleExW
HeapAlloc
HeapFree
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
GetCommandLineA
GetCommandLineW
MultiByteToWideChar
WideCharToMultiByte
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetStdHandle
GetFileType
GetStringTypeW
LCMapStringW
GetProcessHeap
HeapSize
HeapReAlloc
FlushFileBuffers
GetConsoleCP
GetConsoleMode
SetFilePointerEx
CreateFileW

Delayed Imports

AmdPowerXpressRequestHighPerformance

Ordinal 1
Address 0x15004

NvOptimusEnablement

Ordinal 2
Address 0x15000

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x42028
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.3031
MD5 a4ce94d9a308fa54a6e59580137bb46e
SHA1 e36b40ac2f783721844ceda24425fd078d08f46d
SHA256 609ec3d33680144f89329b6505a673d398fa6cb66f30d5c7aadf22209c99b36c
SHA3 fc4c3beade82c0c7caa1502ba876ddf9cab395116be9c944265ccc44bcb0f184

2

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.29986
MD5 2704fa24b57c6aa0d8c21564a98e56ae
SHA1 89c986c63d9957ba558a10b823f027c7c7b867b2
SHA256 16a325dc531ed1653dcdfe25b90903eee4cf3ed684ae23a2256c50d3e471e0a0
SHA3 50ecc89fdca58b6d25136a565048990e5ad5bb63c014244b93903fd724004fb8

3

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10828
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.29986
MD5 60ced6ca130193c92a18d774c9014fab
SHA1 d006fbb04b54cfdcc3e6fd771a442ca1ee89f3d2
SHA256 e46c6e1d629628b8f0161fbba4ba615de20d5eddb602ebc581b9456c86fbdcde
SHA3 e5f4bda53f3779dd7aa8f0cdcc9ac4fd62ee2f372f0889d34524f083fa820ebb

4

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x94a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.29557
MD5 82b0d5150eb60c2184639daca2e819a8
SHA1 ad0330d0b8bd6839e0aada6e294a673a2565577b
SHA256 9270296212343afcc1f26e0e5378bb746293571aefa8eafa3a9e49710c18a9f3
SHA3 e795b3a9146e6934db6013fdc07b7cdba9bbcddca84307ae73ba898eab98e85f

5

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x4228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.27301
MD5 6a3a93cbe06eb4dac0db829105c19e3b
SHA1 b22f8318c1c95c2411a4c7dcb12ed42c6bffe025
SHA256 6e89b1343db3a23d53e7ab5526758eaa1435aab00f827d1a394634cccfc4bd80
SHA3 133fd2a7467cc56760650866fb34bde4b5e3703c5516731912d264146959d9f9

6

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.25272
MD5 dda48523f74ad2cc560af46f97438635
SHA1 ff53f55800110087ee7eb1614ec6e7d2c0fd7fb4
SHA256 647961f43d0bcbe13f14ddca5c56357f3db1e4a8c93be5bb340282daee7318c0
SHA3 8e59564e4fcb7415987c7c936e08c0ae74ac5d6a07b5485975b36d630dd8f999

7

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.9646
MD5 28f090a903fed1df19b9eace01874e1e
SHA1 5d596165cade2b7b7b55c04eefb672edfeb84c07
SHA256 007d37b6698e970c6afbe1fc7a480284efd37c1d194a95d754f597407fb58475
SHA3 c469b9537581a710144a974224d2d340476c3c048e0dad537967630fcafb5abb

8

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x988
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.15535
MD5 dae0288f94b167b9aa069e2ded0520cf
SHA1 d56a250bbfa3e36bee1b4db73905ee4d051b3696
SHA256 747f227c8e369b73b018f944b5b747152a6d0288f90c5f15a91f61724fc482a9
SHA3 7074f454cefe42d0bed41ebf46f77ea17fe4ed0c20c1218e0b8b89d613ad0067

9

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.24547
MD5 11bde6a27c4310c9b823290d641efd44
SHA1 bbec64300b91406185d360d7d7c7bd167e262c18
SHA256 14c6d912fc3e722719257e8c68e0fcd561ac48460e7f567c4bc0d23c01daf2b2
SHA3 4adb2c4b31b55d03253424dc8325583ce352377a9ad3f89ec8d6b60caebf68e2

103

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x84
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.04448
Detected Filetype Icon file
MD5 f7731730720cfe035cf030b40d0e2eb6
SHA1 d046e23f2ee2b93ad96be8e1dc9120ecf3915091
SHA256 5c92a41adaf3265071482fd1a182ae8702c168636a7d9ff51798ee3a1dfc8500
SHA3 6f2d12e4c63c131a3f7f48293996e2be05da351536d013affe5d2265965ce657

1 (#2)

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x1c0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.41601
MD5 32c08a09df32fd3224b0bdedf388eb51
SHA1 d4baec0e8555cddbddaf9f2684395727f3209ee1
SHA256 b29cf4896f7a44e4e0218dbfafcfb400aaf5c0fea16ba6bf97d5cc4c420fa9eb
SHA3 fc24775ad5cad37a434f4a291b1f48426251025f65030bfe5b37b54f62835788

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x6c1
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.37708
MD5 aab7e8aafe7b06ab3d003b54ab5e18ed
SHA1 dccf0408f43059df37b755f3241a8b4b35c728af
SHA256 fb88b19523afd8fed48eddfd10805a3a0a45997bbf8fac04d595ddf93c1a88a8
SHA3 a981b8e907b79cd9448766ace938dfd96560d11c29e6ba165912a8508bd52ca7

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 2020.3.36.63851
ProductVersion 2020.3.36.63851
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_UNKNOWN
Language English - United States
FileVersion (#2) 2020.3.36.7469419
ProductVersion (#2) 2020.3.36.7469419
Unity Version 2020.3.36f1_71f96b79b9f0
Resource LangID English - United States

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2022-Aug-31 00:30:19
Version 0.0
SizeofData 134
AddressOfRawData 0x13730
PointerToRawData 0x11d30
Referenced File C:\buildslave\unity\build\artifacts\WindowsPlayer\Win64_VS2019_nondev_i_r\WindowsPlayer_Master_il2cpp_x64.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2022-Aug-31 00:30:19
Version 0.0
SizeofData 20
AddressOfRawData 0x137b8
PointerToRawData 0x11db8

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2022-Aug-31 00:30:19
Version 0.0
SizeofData 712
AddressOfRawData 0x137cc
PointerToRawData 0x11dcc

TLS Callbacks

Load Configuration

Size 0x130
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x140015030

RICH Header

XOR Key 0x69197163
Unmarked objects 0
C objects (VS2017 v14.15 compiler 26715) 10
ASM objects (VS2017 v14.15 compiler 26715) 5
C++ objects (VS2017 v14.15 compiler 26715) 136
Imports (VS2017 v14.15 compiler 26715) 2
C++ objects (VS 2015/2017/2019 runtime 28427) 37
C objects (VS 2015/2017/2019 runtime 28427) 16
ASM objects (VS 2015/2017/2019 runtime 28427) 8
Imports (VS2019 Update 5 (16.5.4-5) compiler 28614) 3
Total imports 85
C++ objects (VS2019 Update 5 (16.5.4-5) compiler 28614) 2
Exports (VS2019 Update 5 (16.5.4-5) compiler 28614) 1
Resource objects (VS2019 Update 5 (16.5.4-5) compiler 28614) 1
Linker (VS2019 Update 5 (16.5.4-5) compiler 28614) 1

Errors

Leave a comment

No comments yet.