| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2020-Jul-29 14:53:46 |
| Detected languages |
English - United States
|
| Debug artifacts |
C:\buildslave\unity\build\artifacts\UnityPlayer\Win64_nondev_i_r\UnityPlayer_Win64_il2cpp_x64.pdb
|
| FileVersion | 2019.4.7.15307441 |
| ProductVersion | 2019.4.7.15307441 |
| Unity Version | 2019.4.7f1_e992b1a16e65 |
| Info | Matching compiler(s): | MASM/TASM - sig1(h) |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains references to system / monitoring tools:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to MD5 Uses constants related to SHA1 Uses constants related to SHA256 Uses constants related to SHA512 Uses constants related to AES Uses constants related to Blowfish Microsoft's Cryptography API |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Info | The PE is digitally signed. |
Signer: Facepunch Studios Ltd
Issuer: Go Daddy Secure Certificate Authority - G2 |
| Suspicious | VirusTotal score: 1/48 (Scanned on 2026-04-19 05:32:08) | MaxSecure: Spy.W32.Stealer.pef_237171 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x168 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 8 |
| TimeDateStamp | 2020-Jul-29 14:53:46 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x141f400 |
| SizeOfInitializedData | 0x573800 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00000000013B7D68 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x180000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x1998000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0x18b910c |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
SetFilePointer
SetFilePointerEx SetFileTime GetCurrentThreadId OpenThread SuspendThread ResumeThread LocalFree FormatMessageW CopyFileW MoveFileExW ReplaceFileW SystemTimeToFileTime Thread32First Thread32Next CreateMutexA RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind GetEnvironmentVariableA GetCurrentDirectoryA GetCurrentDirectoryW GetFileAttributesA DebugBreak SetUnhandledExceptionFilter SetLastError GetErrorMode TerminateProcess CreateThread GetThreadContext ReadProcessMemory GetModuleFileNameA LocalAlloc GetOverlappedResult CancelIo ResetEvent GetTickCount GetStartupInfoA SetConsoleCtrlHandler GetSystemInfo SetDllDirectoryW SleepEx RaiseException GetThreadTimes SwitchToThread SetThreadPriority GetThreadPriority InitializeCriticalSection EnterCriticalSection LeaveCriticalSection DeleteCriticalSection FormatMessageA QueryPerformanceCounter QueryPerformanceFrequency GetWindowsDirectoryW CreateIoCompletionPort GetQueuedCompletionStatus AttachConsole InitializeCriticalSectionAndSpinCount TryEnterCriticalSection ReleaseSemaphore GetLocalTime GetTimeZoneInformation IsDebuggerPresent CreateSemaphoreExW TlsAlloc TlsFree GetNativeSystemInfo VirtualQuery GetFileSize GetSystemPowerStatus GetComputerNameW LoadLibraryW GetModuleHandleW GetModuleFileNameW VirtualFree VirtualProtect VirtualAlloc GetProcessId CreateProcessW GetExitCodeProcess WaitForMultipleObjects CreateEventW WriteConsoleW SetEnvironmentVariableW GetTempFileNameW GetEnvironmentStringsW GetCommandLineA GetOEMCP GetACP IsValidCodePage SetEndOfFile SetConsoleMode SetStdHandle GetProcessHeap EnumSystemLocalesW GetUserDefaultLCID IsValidLocale HeapAlloc HeapFree FileTimeToSystemTime SystemTimeToTzSpecificLocalTime PeekNamedPipe GetFileInformationByHandle GetDriveTypeW ReadConsoleW GetConsoleMode GetConsoleCP HeapQueryInformation HeapSize HeapReAlloc GetModuleHandleExW ExitProcess RtlPcToFileHeader RtlUnwindEx UnregisterWaitEx QueryDepthSList GetVersionExW FreeLibraryAndExitThread UnregisterWait RegisterWaitForSingleObject GetProcessAffinityMask GetNumaHighestNodeNumber DeleteTimerQueueTimer ChangeTimerQueueTimer CreateTimerQueueTimer GetLogicalProcessorInformation SignalObjectAndWait CreateTimerQueue GetStartupInfoW IsProcessorFeaturePresent UnhandledExceptionFilter GetCPInfo GetStringTypeW GetLocaleInfoW LCMapStringW CompareStringW DecodePointer EncodePointer DuplicateHandle VerifyVersionInfoA ExpandEnvironmentStringsA InitializeCriticalSectionEx GetTickCount64 GlobalMemoryStatus GetFileType ExitThread InterlockedFlushSList InterlockedPushEntrySList InterlockedPopEntrySList InitializeSListHead CreateWaitableTimerA SetWaitableTimer OpenEventA ReadConsoleInputW FlushConsoleInputBuffer SetThreadAffinityMask GetStdHandle CreatePipe SetHandleInformation OutputDebugStringA GetTempPathW WriteFile FlushFileBuffers CreateFileA GetFullPathNameW GetFileAttributesExW GetFileAttributesW GetDiskFreeSpaceExW FindNextFileW FindFirstFileExW FindFirstFileW FindClose DeleteFileW CreateFileW CreateDirectoryW ExpandEnvironmentStringsW GetSystemTimeAsFileTime GetSystemTime GlobalLock SetFileAttributesW RemoveDirectoryW GetCommandLineW GetLogicalProcessorInformationEx GetSystemDirectoryA ReadFile RtlUnwind GlobalUnlock GlobalAlloc CreateToolhelp32Snapshot GetUserDefaultLocaleName FreeEnvironmentStringsW GlobalMemoryStatusEx SetErrorMode LoadLibraryExW GetCurrentThread GetCurrentProcess GetLastError GetModuleHandleA MultiByteToWideChar WaitForSingleObject Sleep CreateEventA WaitForSingleObjectEx VerifyVersionInfoW CloseHandle CreateEventExW WaitForMultipleObjectsEx SetEvent VerSetConditionMask WideCharToMultiByte LoadLibraryA GetProcAddress FreeLibrary GetCurrentProcessId TlsSetValue TlsGetValue |
|---|---|
| USER32.dll |
EnumDisplaySettingsA
GetCaretBlinkTime DestroyWindow CreateWindowExW ShowWindow UpdateWindow GetDesktopWindow EnumDisplayDevicesA MonitorFromWindow ReleaseDC PeekMessageA MsgWaitForMultipleObjects AllowSetForegroundWindow GetUserObjectInformationW GetProcessWindowStation MessageBoxW TrackMouseEvent OpenClipboard CloseClipboard SetClipboardData GetClipboardData EmptyClipboard IsClipboardFormatAvailable GetSystemMetrics EnumDisplaySettingsW SetWindowLongA AdjustWindowRectEx GetWindowPlacement EnumDisplayMonitors GetMonitorInfoW GetMonitorInfoA MonitorFromRect SetWindowLongPtrW GetDC SetCursor LoadCursorA DestroyCursor DestroyIcon CreateIconIndirect DefWindowProcW SetWindowPos GetClientRect GetWindowRect ScreenToClient GetWindowLongA SetWindowLongPtrA GetParent GetThreadDesktop GetUserObjectInformationA RegisterWindowMessageA SendMessageTimeoutA IsIconic SetForegroundWindow EnumWindows UnregisterClassW RegisterClassExW DialogBoxParamW EndDialog SetDlgItemTextA SetDlgItemTextW SendDlgItemMessageW MessageBoxA CopyRect OffsetRect LoadIconA GetKeyboardLayoutNameW TranslateMessage DispatchMessageA GetMessagePos GetMessageTime GetMessageExtraInfo RegisterDeviceNotificationW UnregisterDeviceNotification GetDoubleClickTime IsWindowVisible GetKeyState GetAsyncKeyState GetKeyNameTextW GetWindowLongPtrW ClipCursor SetCapture SetWindowTextW ValidateRect DragDetect KillTimer SetTimer GetFocus GetActiveWindow SetFocus RegisterClassW PostQuitMessage SendMessageW GetMessageA GetRawInputDeviceList RegisterRawInputDevices GetRawInputDeviceInfoW GetRawInputData SystemParametersInfoW PtInRect ClientToScreen GetCursorPos SetCursorPos ReleaseCapture ShowCursor |
| VERSION.dll |
GetFileVersionInfoSizeA
GetFileVersionInfoA VerQueryValueA |
| ole32.dll |
CoCreateFreeThreadedMarshaler
CoInitialize CoUninitialize PropVariantCopy PropVariantClear CoTaskMemAlloc CoCreateGuid StringFromGUID2 CoCreateInstance CoSetProxyBlanket CoTaskMemFree |
| SHLWAPI.dll |
PathCanonicalizeW
PathFileExistsW SHDeleteKeyW |
| SETUPAPI.dll |
SetupDiGetClassDevsA
SetupDiGetDeviceInterfaceDetailW SetupDiEnumDeviceInterfaces SetupDiDestroyDeviceInfoList SetupDiEnumDeviceInfo |
| ADVAPI32.dll |
CryptImportKey
CryptDestroyKey ReportEventW RegisterEventSourceW DeregisterEventSource CryptDestroyHash CryptHashData CryptCreateHash CryptGenRandom CryptReleaseContext CryptAcquireContextA RegSetValueExA RegQueryValueExA RegDeleteValueA RegCreateKeyW GetUserNameA GetTokenInformation GetSidSubAuthority OpenProcessToken RegSetValueExW RegQueryValueExW RegOpenKeyExW RegCreateKeyExW RegCloseKey CryptGetHashParam CryptEncrypt |
| GDI32.dll |
DeleteObject
CreateDIBSection ChoosePixelFormat SetPixelFormat GetDeviceCaps CreateBitmap SwapBuffers |
| SHELL32.dll |
SHGetFolderPathW
CommandLineToArgvW SHFileOperationW ShellExecuteW |
| OPENGL32.dll |
wglCreateContext
wglDeleteContext wglGetCurrentContext wglMakeCurrent wglGetProcAddress wglGetCurrentDC |
| WINMM.dll |
waveOutGetPosition
waveOutReset waveOutWrite waveOutUnprepareHeader waveOutPrepareHeader waveInGetNumDevs waveOutOpen waveOutGetDevCapsW waveOutGetDevCapsA waveOutGetNumDevs timeGetTime timeBeginPeriod waveInGetDevCapsA waveInOpen waveInGetDevCapsW waveInClose waveInPrepareHeader waveInUnprepareHeader waveInAddBuffer waveInReset waveInStart waveOutClose timeEndPeriod |
| OLEAUT32.dll |
VariantChangeType
VariantClear VariantInit SysAllocString SysFreeString |
| IMM32.dll |
ImmSetCompositionStringW
ImmGetCompositionStringW ImmAssociateContextEx ImmAssociateContext ImmReleaseContext ImmGetConversionStatus ImmSetOpenStatus ImmGetContext |
| WINHTTP.dll |
WinHttpGetIEProxyConfigForCurrentUser
|
| bcrypt.dll |
BCryptGenRandom
|
| HID.DLL |
HidP_SetUsageValue
HidP_SetUsages HidP_GetData HidP_MaxDataListLength HidP_GetValueCaps HidP_GetButtonCaps HidP_GetCaps HidD_GetHidGuid HidD_GetPreparsedData HidD_FreePreparsedData HidD_GetProductString HidD_GetManufacturerString HidD_GetSerialNumberString HidD_GetAttributes |
| CRYPT32.dll |
CertCloseStore
CertFreeCertificateContext CertAddEncodedCertificateToStore CertGetCertificateChain CertOpenStore CertVerifyCertificateChainPolicy CertFreeCertificateChain |
| WS2_32.dll |
WSASocketA
WSAGetLastError WSASetLastError send select recv ntohs listen inet_addr htons getsockname ioctlsocket connect closesocket bind accept recvfrom sendto setsockopt shutdown socket gethostname WSAStartup WSACleanup getsockopt WSASendDisconnect gethostbyaddr WSACancelAsyncRequest WSAAsyncGetHostByName WSASetEvent WSAResetEvent __WSAFDIsSet WSAIoctl getaddrinfo WSAEventSelect WSAEnumNetworkEvents WSAWaitForMultipleEvents WSASocketW WSACreateEvent WSACloseEvent WSARecvFrom htonl freeaddrinfo getnameinfo ntohl getpeername gethostbyname getprotobyname |
| Ordinal | 1 |
|---|---|
| Address | 0x5463b0 |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 2019.4.7.37553 |
| ProductVersion | 2019.4.7.37553 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
| FileType |
VFT_UNKNOWN
|
| Language | English - United States |
| FileVersion (#2) | 2019.4.7.15307441 |
| ProductVersion (#2) | 2019.4.7.15307441 |
| Unity Version | 2019.4.7f1_e992b1a16e65 |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2020-Jul-29 14:53:46 |
| Version | 0.0 |
| SizeofData | 122 |
| AddressOfRawData | 0x164ceec |
| PointerToRawData | 0x164b6ec |
| Referenced File | C:\buildslave\unity\build\artifacts\UnityPlayer\Win64_nondev_i_r\UnityPlayer_Win64_il2cpp_x64.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2020-Jul-29 14:53:46 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0x164cf68 |
| PointerToRawData | 0x164b768 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2020-Jul-29 14:53:46 |
| Version | 0.0 |
| SizeofData | 972 |
| AddressOfRawData | 0x164cf7c |
| PointerToRawData | 0x164b77c |
| StartAddressOfRawData | 0x18164d368 |
|---|---|
| EndAddressOfRawData | 0x18164d37c |
| AddressOfIndex | 0x1818743b8 |
| AddressOfCallbacks | 0x181427f68 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_8BYTES
|
| Callbacks | (EMPTY) |
| Size | 0x100 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x18178c7c8 |
| XOR Key | 0x6f2be95 |
|---|---|
| Unmarked objects | 0 |
| ASM objects (VS2015/2017 runtime 25711) | 36 |
| ASM objects (VS 2015/2017 runtime 26706) | 31 |
| C objects (VS 2015/2017 runtime 26706) | 37 |
| C objects (VS2012 build 50727 / VS2005 build 50727) | 1 |
| C++ objects (VS2015 UPD3 build 24210) | 111 |
| C objects (VS2008 SP1 build 30729) | 9 |
| C objects (VS2015 UPD2 build 23918) | 542 |
| C++ objects (VS2015 UPD2 build 23918) | 123 |
| Imports (VS2008 SP1 build 30729) | 2 |
| 173 (VS2010 build 30319) | 1 |
| C++ objects (VS2015 build 23026) | 9 |
| C++ objects (VS2015/2017 runtime 25711) | 219 |
| C objects (CVTCIL) (VS2015/2017 runtime 25711) | 2 |
| C objects (VS2015/2017 runtime 25711) | 62 |
| Imports (VS2015/2017 runtime 25711) | 39 |
| Total imports | 550 |
| 199 (41118) | 7 |
| C++ objects (VS 2015/2017 runtime 26706) | 120 |
| C objects (VS 2015/2017 runtime 27012) | 265 |
| Unmarked objects (#2) | 59 |
| C++ objects (VS 2015/2017 runtime 27012) | 778 |
| Exports (VS 2015/2017 runtime 27012) | 1 |
| Resource objects (VS 2015/2017 runtime 27012) | 1 |
| Linker (VS 2015/2017 runtime 27012) | 1 |
No comments yet.