4251079f3f6c9fcf846e692a6ec63532fa3c14e7834b0ea19cba8321fe6d2905

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2025-Oct-01 12:05:08
Detected languages English - United States
Debug artifacts C:\build\output\unity\unity\artifacts\WindowsPlayer\Win_x64_VS2022_VB_nondev_m_r\WindowsPlayer_player_Master_mono_x64.pdb
FileVersion 6000.0.59.15673372
LegalCopyright (c) 2005-2025 Unity Technologies. All rights reserved.
ProductVersion 6000.0.59f2 (ef281c76c3c1)

Plugin Output

Info The PE contains common functions which appear in legitimate applications. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryExW
Suspicious The PE is possibly a dropper. Resources amount for 83.983% of the executable.
Safe VirusTotal score: 0/71 (Scanned on 2026-04-02 13:57:18) All the AVs think this file is safe.

Hashes

MD5 cc8f5fe7621e6c5ea8fd52543061b2d4
SHA1 b12ba0240f1a3ce70bc1ef2ef484addd02a003af
SHA256 4251079f3f6c9fcf846e692a6ec63532fa3c14e7834b0ea19cba8321fe6d2905
SHA3 82c49d917380fd12085ce6d4f54e8063299d0264d20dbcc04b017dfcb48edfab
SSDeep 12288:p2NCDdJr3d4avRRe6ocyYskmBO1q/KHy3yyZy8yZDPLxmaonQGd87:/jXe/O1IQD
Imports Hash a136217cdd3247ff6a8766561064ca0b

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x110

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 7
TimeDateStamp 2025-Oct-01 12:05:08
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0xde00
SizeOfInitializedData 0x97200
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000001264 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0xa9000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 2775a5a7c1fa856e6a29a4f5a5229c31
SHA1 3e9ae8fdb588fe4aae22d549f8569008c887c898
SHA256 195697288171c6371920514965e3625060b55abd960ee1903baa797ef5e0bbfb
SHA3 fb39403bbfb970d14fc395dd6c3593ca3d0aec333b14d9249010a0924d269e75
VirtualSize 0xdc70
VirtualAddress 0x1000
SizeOfRawData 0xde00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.46162

.rdata

MD5 e275c560039ba46c3b13c577d363386d
SHA1 ed7d58ff98824680db0fa63e415eebe47f26ff55
SHA256 9e38d095a74df6856cbaddb225f9888b9a54d0168c3cf2e27f079c060ad5f62d
SHA3 ccf6ae682cfe38f5a99c62e21c10d2e0c9c15ce768dbb22a6e0adcdeaa2a0ae2
VirtualSize 0x977c
VirtualAddress 0xf000
SizeOfRawData 0x9800
PointerToRawData 0xe200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.70157

.data

MD5 d284f7b260ed119794375a6998c5083c
SHA1 0944c690e2b7841e681f55d2a731910f8019f2ef
SHA256 79ebad17e73900bd4dd43a932cc832e1d907346973e16ac0af549524fa4b88b3
SHA3 0c023444d7239a9582798618879cf6e165fcae6d6eec1051c77592814b4894ad
VirtualSize 0x1d78
VirtualAddress 0x19000
SizeOfRawData 0xc00
PointerToRawData 0x17a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 1.89847

.pdata

MD5 d67581e7561b613930fcc4c3ee52cdc5
SHA1 a43e835342a8235efb9f656bba5c170d21641a61
SHA256 4eaf2a70ebe02f5f76d3b133d8a74d7c7eee9267519fd6a6951de4bcb2ad617b
SHA3 0ccfeafaf338d1bcb9c719ffca72875595bea8d6aea16bd26baa2a4685e84170
VirtualSize 0xf24
VirtualAddress 0x1b000
SizeOfRawData 0x1000
PointerToRawData 0x18600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.67172

_RDATA

MD5 dd297010ea596c9b749ddc72fe421330
SHA1 3213e7a4b99366f1367f1b5dc97aa4853369a784
SHA256 420a70f17663b392f63eb448853ebc800a3f7cf9c6e0b78b7e421d671dd927fd
SHA3 f4660bd566f5561530bb0e40a752616d5a8180b7180fcf869790d48f9fb6e9bf
VirtualSize 0x1f4
VirtualAddress 0x1c000
SizeOfRawData 0x200
PointerToRawData 0x19600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 3.71477

.rsrc

MD5 27a254690f5e3eaa455b82727fdaa675
SHA1 b9b6d353051bc25c1bbba12cb3d524cafd80b5a0
SHA256 350b8f42505ae4c3249ffd33d6f18cd36d30d825788d25b55b27ecf9cff08fd5
SHA3 f9b82e810b65a81cfb2f475c28d87eca8bb8acaef297a8332933726fc880a8c7
VirtualSize 0x8a020
VirtualAddress 0x1d000
SizeOfRawData 0x8a200
PointerToRawData 0x19800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 3.64253

.reloc

MD5 79918e2814a23b917e4a5494067a35d5
SHA1 eab8dd05e160cbff9fa1c348b6c35e7f161cf459
SHA256 cccb376562c958fee6ec06051a48d2c5c0232065e1000ce2d4b0775e46737238
SHA3 0fcd95a99b9b4e77c2e23089f450965a4028a243ef56d1928fdcfcebcc4b7120
VirtualSize 0x658
VirtualAddress 0xa8000
SizeOfRawData 0x800
PointerToRawData 0xa3a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 4.87002

Imports

UnityPlayer.dll UnityMain2
KERNEL32.dll HeapAlloc
WriteConsoleW
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
IsDebuggerPresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetStartupInfoW
IsProcessorFeaturePresent
GetModuleHandleW
CloseHandle
RtlUnwindEx
GetLastError
SetLastError
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
GetProcAddress
LoadLibraryExW
EncodePointer
RaiseException
RtlPcToFileHeader
GetStdHandle
WriteFile
GetModuleFileNameW
GetCurrentProcess
ExitProcess
TerminateProcess
GetModuleHandleExW
HeapFree
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
GetCommandLineA
GetCommandLineW
MultiByteToWideChar
WideCharToMultiByte
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetStdHandle
GetFileType
GetStringTypeW
FlsAlloc
FlsGetValue
FlsSetValue
FlsFree
LCMapStringW
GetProcessHeap
HeapSize
HeapReAlloc
FlushFileBuffers
GetConsoleOutputCP
GetConsoleMode
SetFilePointerEx
CreateFileW

Delayed Imports

AmdPowerXpressRequestHighPerformance

Ordinal 1
Address 0x19004

D3D12SDKPath

Ordinal 2
Address 0x19008

D3D12SDKVersion

Ordinal 3
Address 0xf320

NvOptimusEnablement

Ordinal 4
Address 0x19000

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.17741
MD5 4a0ee95bb65f1a113d19eccf430f3375
SHA1 fd01ba536989fa518639168c9fbb5041fb0d697c
SHA256 bbd4654d0f816423a97cf5c7db5778c858c4028f4d8f68538946ff0c30e5366e
SHA3 73d9ef0f219c5dbe03443611d5d38e80ae2b3e3d82faf94b521e680ae9909d7a

2

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x988
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.05347
MD5 1e3907b7aab018458f6bec490073dd7d
SHA1 c1cc252e02a7ce174e267da21e75c3320c943c13
SHA256 b801ea4d9e80f0fd6b93a11bd6ea267493ad770b0956ea4e8cdb9e45d5bd8d97
SHA3 e2ca7b51d8b6822f7d60134bc2a3730a99d4ab7071af4b11bd9bd9a59a3cc06d

3

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.00208
MD5 0733de831099e301011a902cbf39786e
SHA1 0d26a1e2f58b5185fa0cab8b0d1b794d24c622dd
SHA256 cd5381f4a5e223469de4ac7c3f301b1fe55121cbc058d1cb4ef6193ab5e19f31
SHA3 ec5ce42dfcc8fc2afa4a7000bab595337aca0d2b5d68cd4aa7e1ed2e15ba5dbc

4

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.83976
MD5 4048a818810c8983dfa37a5e5ccd34a2
SHA1 87471f145c2a67438abba6d67e9bdc5b9db31577
SHA256 a286785c141815d595748d0cbf32047ec4edd7a738ca37c41c8f5a1ce5b89fed
SHA3 3ec95f9f1fbc96856aa56c2ad5a12caf972ed33f3c04962ce41b533c517d7af7

5

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x4228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.79917
MD5 8be5eb202b0ae50b51dcabe10257ecd1
SHA1 5062122a957696e4bd7c8fc3841ed9cd035ed1ca
SHA256 5632f3c4fab1ab8c065412496fda88fda54b42ba14a54cd95ae63c77964c04c0
SHA3 ee6e3d8af876245c27429faab82b7baf4cafbd81b7fed2b62778d8f83c3eb97a

6

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x94a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.70751
MD5 abf6da49ad4617757b8206961c0db36d
SHA1 d154754bab7a33c0d2bc244bee41e4b932e42d76
SHA256 981cd1062e78ba7f3afcbd070bc59ca41fead60b694e3bf29cf7adc9fb5bc960
SHA3 1dde19ae86fbbd1d46d0967c8fcee7c050856436a7fe1c119182e5172b4d67e9

7

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10828
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.65292
MD5 da4421344b8a7d1d9a8d9e7d3355358d
SHA1 8ccabb4ec5105710c35a6fe4fc2a76d83a66c1cd
SHA256 320aa26d20fe64e1a9f9fffb5a12d5265c8ea39443087901c61a285a69dd6005
SHA3 f834213013aa8ee032338be817d907880337452e015fb0baae4927f9a46c525d

8

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.60233
MD5 6961cbdd6919a2d2bde41728d6ea57e1
SHA1 9f387485a5592f202a3755c93bce084cee4f01a2
SHA256 2dcec03417ad8c4cedc6cf180bfe2b2f88fda0db8a5a09ad47587814361cce6f
SHA3 582a18961101c05dc45071182710e36f607815464cbe9e20673f1038f4771e5d

9

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x42028
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.57191
MD5 81c798d088279145f75f7a44e1572486
SHA1 dd92090739afc2b3b5a792b25bdaa389982ec0b8
SHA256 1e3e972d73d64f38198331c2c6214c884c23ffcfc10f2b919ff5875ecc8a3eae
SHA3 babf4d602581f01443f121ff27a4baf80f98a4fd819c4f239c90e15e5ba66ce4

103

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x84
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.04448
Detected Filetype Icon file
MD5 3bf2dac037ce87794e66ff7f054e913f
SHA1 52ca961fd37ad960905a681d1db5157508ef1602
SHA256 2a87b1f32c5d0435090c72c392b75394f706e5750eff64fd85d25e1c622ee581
SHA3 8454d3273522657b5926068082b2cb88f6dbf352e7e9568008c0e33c792f349b

1 (#2)

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x214
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.50159
MD5 0bf618b928eea2aab89146a1e4e53a95
SHA1 7fe6411f8bbd703125ea6c83f3e41b36a465b952
SHA256 8ce08fafa1b40a4a5056f7d29a9bf7a4b9dcfd6576e1ec7021ff2faddc5c67d1
SHA3 999e95df705895b36dbf037acdc5af2cbf4aeda4720e2128a0e9e1888c8e7d8b

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x545
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.24993
MD5 9df530c2f4fbe460da74e130d5d351a9
SHA1 f8719b6c74e0179556c1a18f214d6c1bbff8f823
SHA256 3c357bd1125971bda05bc59eaeca279da41715741e2535e9e75c94273b1c3a1f
SHA3 ce3dd46f87bd462f8730fca18daea6df444422f8d88b810aefbd7b2e62536dee

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 6000.0.59.10268
ProductVersion 6000.0.59.10268
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_UNKNOWN
Language English - United States
FileVersion (#2) 6000.0.59.15673372
LegalCopyright (c) 2005-2025 Unity Technologies. All rights reserved.
ProductVersion (#2) 6000.0.59f2 (ef281c76c3c1)
Resource LangID English - United States

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2025-Oct-01 12:05:08
Version 0.0
SizeofData 146
AddressOfRawData 0x16d58
PointerToRawData 0x15f58
Referenced File C:\build\output\unity\unity\artifacts\WindowsPlayer\Win_x64_VS2022_VB_nondev_m_r\WindowsPlayer_player_Master_mono_x64.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2025-Oct-01 12:05:08
Version 0.0
SizeofData 20
AddressOfRawData 0x16dec
PointerToRawData 0x15fec

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2025-Oct-01 12:05:08
Version 0.0
SizeofData 852
AddressOfRawData 0x16e00
PointerToRawData 0x16000

TLS Callbacks

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x140019040

RICH Header

XOR Key 0x7139305b
Unmarked objects 0
ASM objects (28900) 5
C++ objects (28900) 138
C objects (28900) 10
Unmarked objects (#2) 1
Imports (28900) 2
C++ objects (33218) 40
C objects (33218) 16
ASM objects (33218) 17
Imports (33523) 3
Total imports 89
C++ objects (33523) 2
Exports (33523) 1
Resource objects (33523) 1
Linker (33523) 1

Errors

Leave a comment

No comments yet.