404387a93f1fb210957a24d2df1f34f9e832b9a41f5cae5535b6c740360433f9

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2022-Nov-08 06:22:05
Detected languages English - United States
Debug artifacts C:\build\output\unity\unity\artifacts\WindowsPlayer\Win64_VS2019_nondev_m_r\WindowsPlayer_player_Master_mono_x64.pdb
FileVersion 2022.1.23.9844400
LegalCopyright (c) 2022 Unity Technologies ApS. All rights reserved.
ProductVersion 2022.1.23f1 (9636b062134a)

Plugin Output

Info The PE contains common functions which appear in legitimate applications. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryExW
Suspicious The PE is possibly a dropper. Resources amount for 84.7484% of the executable.
Suspicious VirusTotal score: 1/72 (Scanned on 2024-02-24 09:04:19) Trapmine: suspicious.low.ml.score

Hashes

MD5 d19c5bb95d3dc9fbdd65fd77d45ab3aa
SHA1 6f9db8420ed1dab316379b64817d57d7be9bc1ab
SHA256 404387a93f1fb210957a24d2df1f34f9e832b9a41f5cae5535b6c740360433f9
SHA3 4112869683ae854b16caaf2c77f0819ce95f5a2f0504fd310925b8eb66ccebe5
SSDeep 12288:T/744aOD8B8tA7fVDaCu6NZfJY5LEYrSzAY:H9aO88tUflacJY5LEj
Imports Hash ce1183cc150987a99aef5749f22af81e

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x110

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 7
TimeDateStamp 2022-Nov-08 06:22:05
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0xca00
SizeOfInitializedData 0x97000
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000001260 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0xa8000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 c908b9c0303dc1f82726ca4dae00b772
SHA1 e81e70cb017880d2883f88a85d9a5ba6176ebcc1
SHA256 6e577d9deae653a5181b5a961bc5d68133d0e0c5371dc8bf2e7a30f6ef4d5cb2
SHA3 deefbce421cada627162918879ac6eda8099d036762180ad5ebfb4cbd66be7e2
VirtualSize 0xc8b0
VirtualAddress 0x1000
SizeOfRawData 0xca00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.41078

.rdata

MD5 2146fdb37fbeaa214700c1f2d0046080
SHA1 070da1163accb6c3a0c64269b32e0fbcb8bff886
SHA256 3051f2de2d45e53788393a4c1d3c0e7dccd05c7f652234862307ef9477bbc123
SHA3 03286f8023418c31f07eeb1c3683db6092b57ef21c5c947a9535da3678edddc6
VirtualSize 0x948a
VirtualAddress 0xe000
SizeOfRawData 0x9600
PointerToRawData 0xce00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.65297

.data

MD5 90815aa5dc65a7dd3f93bad1bd78a77e
SHA1 608f3e69047b216dda6b0df73c30912e2fef5544
SHA256 435cb9af1df25f501f68a9700182c4d25de99c3f8e8c1ba6b16c0ca98911ff87
SHA3 e5ea90d4dd767bfa3d88e3fa2e107c2e40cac10f43498d5abd74f15888477d18
VirtualSize 0x1d38
VirtualAddress 0x18000
SizeOfRawData 0xc00
PointerToRawData 0x16400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 1.87032

.pdata

MD5 c69bce38ac69d0b835120a5590e69f0c
SHA1 c063139b665bfd43ee632f0741b4b5279a71f404
SHA256 1d79cfdb10b0e6f61968ed084c55a6ae07421354bf9072b12d090926728f3852
SHA3 5b320838ebff98a9e30dc5b9258ca4079fcb7cde4304c61cfe2dd57bb750842e
VirtualSize 0xef4
VirtualAddress 0x1a000
SizeOfRawData 0x1000
PointerToRawData 0x17000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.62843

_RDATA

MD5 f87f407c2a1cab208757ad1d23a2de6f
SHA1 cd739c36958f9ba7505883ae868f1a6ca71e880f
SHA256 6e4ba525d12ef66132e0738191d3a928ba74c0091a6f82bc48f892a41e2fc242
SHA3 0611ad194d9c623281cb358dbc2f2d28bb01b6eab682677ec8d16136d74414ab
VirtualSize 0x94
VirtualAddress 0x1b000
SizeOfRawData 0x200
PointerToRawData 0x18000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 1.11888

.rsrc

MD5 9f20bf8ed98f8f88156c5e8ad67e8234
SHA1 5a3e0a400096c87b4d2bc6411410a4c136d6e79e
SHA256 1378342a6d1387a62fb08756183b305ac987c93494b5ebd8cf2516dea4e2666a
SHA3 d7d9115dcb44292ffab4c089a230af7aa94c82474b160ad35dc45b6f95aa990c
VirtualSize 0x8a198
VirtualAddress 0x1c000
SizeOfRawData 0x8a200
PointerToRawData 0x18200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.28398

.reloc

MD5 ef1e558d46106d87320dd822be1ddc48
SHA1 10f7b05d107451bd01cf446da512c619fc35bf50
SHA256 34d7b771018e478ba05cd24ec377fd34919d65ec63c43f49e1ab319785368929
SHA3 cc295f58e62efe5c59cad1febf1ce620404450135f442c20ba55235b492ddac9
VirtualSize 0x654
VirtualAddress 0xa7000
SizeOfRawData 0x800
PointerToRawData 0xa2400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 4.84209

Imports

UnityPlayer.dll UnityMain
KERNEL32.dll HeapAlloc
WriteConsoleW
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
IsDebuggerPresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetStartupInfoW
IsProcessorFeaturePresent
GetModuleHandleW
CloseHandle
RtlUnwindEx
GetLastError
SetLastError
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
GetProcAddress
LoadLibraryExW
EncodePointer
RaiseException
RtlPcToFileHeader
GetStdHandle
WriteFile
GetModuleFileNameW
GetCurrentProcess
ExitProcess
TerminateProcess
GetModuleHandleExW
HeapFree
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
GetCommandLineA
GetCommandLineW
MultiByteToWideChar
WideCharToMultiByte
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetStdHandle
GetFileType
GetStringTypeW
FlsAlloc
FlsGetValue
FlsSetValue
FlsFree
LCMapStringW
GetProcessHeap
HeapSize
HeapReAlloc
FlushFileBuffers
GetConsoleOutputCP
GetConsoleMode
SetFilePointerEx
CreateFileW

Delayed Imports

AmdPowerXpressRequestHighPerformance

Ordinal 1
Address 0x18004

NvOptimusEnablement

Ordinal 2
Address 0x18000

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x42028
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.26019
MD5 687b646aa0852eeca55dbddcab49f8f4
SHA1 27daef950672bb981b3fc17c0aeb33524bb2527c
SHA256 6c295d5584e8c39970d9f4d799b82376ed77411cbd6c4f9041b57259666ddf6f
SHA3 8fafb3cfc3ac06a69378e41c04122f7660fdd7bbef5b828a0b508cc0e089ae7a

2

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.26827
MD5 68ea6f975dc9c47a4c46b92bf88d0dca
SHA1 9639fa1072dfd86ecd1636bd9fbc4fe694119d04
SHA256 6b261ac20ccfe3881c958e8b22876b4d5549f656677615ac87d630551b6c131a
SHA3 125eaabbe6701095663e520c062b94faf401035f3fb692f871daa2a31e9e509c

3

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10828
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.25123
MD5 6d285a6d6bff468d39127e0a424b9ee8
SHA1 0971b996189c27f48be20dbabb11edbcf3003ebc
SHA256 a0d658a427693918b911ab9ac96cfb748e3bbffacf6e83f6a1e834dbdd4eee0d
SHA3 54884b88b12a3cf63f1257c4b6f88d9912ea8578632a8691e0d3ce653c3c1b3e

4

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x94a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.23169
MD5 399007ae5b2a0c4c44366347fdd7b82f
SHA1 ee78f2feed0c3b31d78f3ff1a13746545e91df70
SHA256 3bb3f56d7b3a9bf6426c8754d0ce1448c5c5418a8b6f589d396e7d853a1abc88
SHA3 1a6422e5fd9b9aa5ff785aaf1c6f528e51addd2643f9e0afa4ca4b64ce1a632f

5

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x4228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.21286
MD5 3303cba65b2356044041a7cb34344b49
SHA1 d4d0f4e8abf19630cc5bf1e607a3add259ef44c7
SHA256 0c9c8e7a6cea8b7a7885cb6cbc276745fa278fa32319033a18f667d0dd5c5e8c
SHA3 c2650670c9cee7382cd6221ea6e385c6d06276f75fa81f6d4ef7ae3d48d30864

6

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.9554
MD5 ef08b54b4557e6264f96e0a3eeffb50e
SHA1 10b9051a8460f93842d6b0e26bcf028590e3f5e7
SHA256 669e6950dacda14c29c0b8406847e578d2eda76de87435070363fe8e1dd5b480
SHA3 30e1466f55a36e1a9ba8ae538363f67cff2f6e39689c601e0ceb3f7710920178

7

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.51171
MD5 e03933229e5b3a93b6ffff1ad71272cb
SHA1 52ea9b0c0f3e65da67224fd79bef69fac001e070
SHA256 b09bc461540b63745c9b3e4cb113d7bab54aa476ee0999c1f62eb932ac35975f
SHA3 d683ae1b3e45fafea16b88fd4a7f81685dd7f089260fd8373f1c0d7f73c1a6f8

8

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x988
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.68565
MD5 bf37eb3410f803da471c124d51446575
SHA1 f4cd8f0bf5a144c7c5203d6605128318137dcf84
SHA256 484c9e34174113a8ad2e224ede6690ba59bc97286b2ddefe32a4e8800581f344
SHA3 6f228a7ed3275eb207115fd1b4db5d698207b9cd05b3cb6f0a7627b8a193be08

9

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.6517
MD5 0a0571c4e80b3e9edda5eca3bb78c20a
SHA1 f4a531b11ea888ef86d1967ee7513274aaf0643a
SHA256 a66d6b4286138dd5a731c34f9fd0431c86cfd7077d0f9f4a35f1a786502c878a
SHA3 19be7854bae5b5e383cc22807fae6995bcca9f40c69d6a431a83aa82c10bd6eb

103

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x84
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.04448
Detected Filetype Icon file
MD5 f7731730720cfe035cf030b40d0e2eb6
SHA1 d046e23f2ee2b93ad96be8e1dc9120ecf3915091
SHA256 5c92a41adaf3265071482fd1a182ae8702c168636a7d9ff51798ee3a1dfc8500
SHA3 6f2d12e4c63c131a3f7f48293996e2be05da351536d013affe5d2265965ce657

1 (#2)

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x20c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.5273
MD5 2aa3a09a675f2909ae4b9077e15537c8
SHA1 b8561ad07ec2948aebe9ee9bca030f3917529ccb
SHA256 9d780de4ceee04ae1a0b697c7c8579633c74761c4722e543691d844c21af8d84
SHA3 a65c117e92269c3bf4d06690ee13363dcfd29ae04fee76797966c21f8fc78a2c

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x6c1
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.37708
MD5 aab7e8aafe7b06ab3d003b54ab5e18ed
SHA1 dccf0408f43059df37b755f3241a8b4b35c728af
SHA256 fb88b19523afd8fed48eddfd10805a3a0a45997bbf8fac04d595ddf93c1a88a8
SHA3 a981b8e907b79cd9448766ace938dfd96560d11c29e6ba165912a8508bd52ca7

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 2022.1.23.14000
ProductVersion 2022.1.23.14000
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_UNKNOWN
Language English - United States
FileVersion (#2) 2022.1.23.9844400
LegalCopyright (c) 2022 Unity Technologies ApS. All rights reserved.
ProductVersion (#2) 2022.1.23f1 (9636b062134a)
Resource LangID English - United States

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2022-Nov-08 06:22:05
Version 0.0
SizeofData 141
AddressOfRawData 0x15aec
PointerToRawData 0x148ec
Referenced File C:\build\output\unity\unity\artifacts\WindowsPlayer\Win64_VS2019_nondev_m_r\WindowsPlayer_player_Master_mono_x64.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2022-Nov-08 06:22:05
Version 0.0
SizeofData 20
AddressOfRawData 0x15b7c
PointerToRawData 0x1497c

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2022-Nov-08 06:22:05
Version 0.0
SizeofData 768
AddressOfRawData 0x15b90
PointerToRawData 0x14990

TLS Callbacks

Load Configuration

Size 0x138
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x140018030

RICH Header

XOR Key 0xe5e06b0d
Unmarked objects 0
ASM objects (28900) 5
C++ objects (28900) 138
C objects (28900) 10
Imports (28900) 2
C++ objects (VS 2015/2017/2019 runtime 29118) 39
C objects (VS 2015/2017/2019 runtime 29118) 16
ASM objects (VS 2015/2017/2019 runtime 29118) 9
Imports (VS2019 Update 8 (16.8.0-1) compiler 29333) 3
Total imports 89
C++ objects (VS2019 Update 8 (16.8.0-1) compiler 29333) 3
Exports (VS2019 Update 8 (16.8.0-1) compiler 29333) 1
Resource objects (VS2019 Update 8 (16.8.0-1) compiler 29333) 1
Linker (VS2019 Update 8 (16.8.0-1) compiler 29333) 1

Errors

Leave a comment

No comments yet.