501eda51f329c56ccb1e68f6721911efc3509ae5052f714f8c2012e68cdf0b9b

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2025-Oct-24 11:12:51
Detected languages English - United States
Debug artifacts C:\build\output\unity\unity\artifacts\WindowsPlayer\Win64_VS2019_nondev_m_r\WindowsPlayer_player_Master_mono_x64.pdb
FileVersion 2022.3.62.9860879
LegalCopyright (c) 2005-2025 Unity Technologies. All rights reserved.
ProductVersion 2022.3.62f3 (96770f904ca7)

Plugin Output

Info The PE contains common functions which appear in legitimate applications. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryExW
Suspicious The PE is possibly a dropper. Resources amount for 84.749% of the executable.
Suspicious VirusTotal score: 1/58 (Scanned on 2026-06-05 02:58:42) Trapmine: suspicious.low.ml.score

Hashes

MD5 8f4537ee4dae8a07e5fcef5d76772658
SHA1 014cd71f0b0cfa1ddd51da86ae40f2d71aadae2d
SHA256 501eda51f329c56ccb1e68f6721911efc3509ae5052f714f8c2012e68cdf0b9b
SHA3 4f5325ed39b43e93cc165db7988afe1c4b510dd5fa08e6e4a9f9574d5791a421
SSDeep 6144:D/7Fu9mpcJ/OD8mG0isRTP+7iLbmU8udZPGlZzYP3YkYUAIF5sWKlGxgTd4M6Rs:D/7g4aOD8o+7tvMIY/3Kdn+
Imports Hash a136217cdd3247ff6a8766561064ca0b

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x110

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 7
TimeDateStamp 2025-Oct-24 11:12:51
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0xca00
SizeOfInitializedData 0x97000
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000001264 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0xa8000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 e1ace82cc0f3d159779f5c95aa7e575b
SHA1 e4a5358996f267c921e5d996de44f3525bb042ed
SHA256 bec109031034001337c9be3c07e16f6fab9c862313fc1f8fb0699672e09c63a4
SHA3 449bef44a9ee4a68767a70da31c7ceb6aa3d1da49237a84227bbfb02c7e428a2
VirtualSize 0xc8b0
VirtualAddress 0x1000
SizeOfRawData 0xca00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.41019

.rdata

MD5 cf492574fe39d1612d6ea3b6e1ab945b
SHA1 3add896e5d5fcfb8e1b5d2ec9a907918ec3f01ec
SHA256 98b7132bfc37440eb6b17fe2ce6b87a0d25f23c081b050b1919e77926b890d07
SHA3 78e8b5742565930bafc600cbe43206de2cf02dae4df0ae9ce420fcbc5484cb70
VirtualSize 0x948c
VirtualAddress 0xe000
SizeOfRawData 0x9600
PointerToRawData 0xce00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.65418

.data

MD5 90815aa5dc65a7dd3f93bad1bd78a77e
SHA1 608f3e69047b216dda6b0df73c30912e2fef5544
SHA256 435cb9af1df25f501f68a9700182c4d25de99c3f8e8c1ba6b16c0ca98911ff87
SHA3 e5ea90d4dd767bfa3d88e3fa2e107c2e40cac10f43498d5abd74f15888477d18
VirtualSize 0x1d38
VirtualAddress 0x18000
SizeOfRawData 0xc00
PointerToRawData 0x16400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 1.87032

.pdata

MD5 6e619149c26d436c6f07193ff1e8032b
SHA1 70aea7c26eff6d7619bd6a5a97ab259d68dd24f5
SHA256 48cb5fb202e79c0b8da5091cb440a9068502b37c8e4200eb78df617ae99fd024
SHA3 196183a21caf69a7292ff77b288d707ce7d63e2b887053ae1bc258b99d1e36f0
VirtualSize 0xef4
VirtualAddress 0x1a000
SizeOfRawData 0x1000
PointerToRawData 0x17000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.62125

_RDATA

MD5 f87f407c2a1cab208757ad1d23a2de6f
SHA1 cd739c36958f9ba7505883ae868f1a6ca71e880f
SHA256 6e4ba525d12ef66132e0738191d3a928ba74c0091a6f82bc48f892a41e2fc242
SHA3 0611ad194d9c623281cb358dbc2f2d28bb01b6eab682677ec8d16136d74414ab
VirtualSize 0x94
VirtualAddress 0x1b000
SizeOfRawData 0x200
PointerToRawData 0x18000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 1.11888

.rsrc

MD5 77df5c63fa85f0ce9ff9f004182ed206
SHA1 81c793bc92a332f38e663f639555cf08846e8b46
SHA256 2041b4455504da7d9618288bd4ed56e14ef9c56113e665345182dc79a1ec1bc6
SHA3 53c27a5f8472c8cd479532d539aa83f596d78cfd0b158d041c371ccba1625ce7
VirtualSize 0x8a198
VirtualAddress 0x1c000
SizeOfRawData 0x8a200
PointerToRawData 0x18200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.67061

.reloc

MD5 ef1e558d46106d87320dd822be1ddc48
SHA1 10f7b05d107451bd01cf446da512c619fc35bf50
SHA256 34d7b771018e478ba05cd24ec377fd34919d65ec63c43f49e1ab319785368929
SHA3 cc295f58e62efe5c59cad1febf1ce620404450135f442c20ba55235b492ddac9
VirtualSize 0x654
VirtualAddress 0xa7000
SizeOfRawData 0x800
PointerToRawData 0xa2400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 4.84209

Imports

UnityPlayer.dll UnityMain2
KERNEL32.dll HeapAlloc
WriteConsoleW
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
IsDebuggerPresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetStartupInfoW
IsProcessorFeaturePresent
GetModuleHandleW
CloseHandle
RtlUnwindEx
GetLastError
SetLastError
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
GetProcAddress
LoadLibraryExW
EncodePointer
RaiseException
RtlPcToFileHeader
GetStdHandle
WriteFile
GetModuleFileNameW
GetCurrentProcess
ExitProcess
TerminateProcess
GetModuleHandleExW
HeapFree
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
GetCommandLineA
GetCommandLineW
MultiByteToWideChar
WideCharToMultiByte
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetStdHandle
GetFileType
GetStringTypeW
FlsAlloc
FlsGetValue
FlsSetValue
FlsFree
LCMapStringW
GetProcessHeap
HeapSize
HeapReAlloc
FlushFileBuffers
GetConsoleOutputCP
GetConsoleMode
SetFilePointerEx
CreateFileW

Delayed Imports

AmdPowerXpressRequestHighPerformance

Ordinal 1
Address 0x18004

NvOptimusEnablement

Ordinal 2
Address 0x18000

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x42028
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.59631
MD5 1ec09a20e8dbe4dc4044841d03ca806e
SHA1 4b6da9db3aef43026b22b410ffffa4601b684373
SHA256 9494cd5c9c76d75dc373ff76866798b10cc2ae828f61721bfdc181cc4add5003
SHA3 98d28a6aed2d6d1c6f4773746f5f89e9f65f5243ef344070fa7b01a61f687f1a

2

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.63077
MD5 39ca836235bf253a1e1cafa2918a7042
SHA1 1fcc3302b8f8dfcb2837e86e693e3d39768e9008
SHA256 bf958837e4bfbdf61e04dad385dc3381a567c6359bd47e667982335b245b771b
SHA3 bcc9934205354dc225fe00806814f11fb7abaa5a3cbde5ff8d74c437abbc9d4f

3

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10828
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.67661
MD5 a1905f7d112d54ba554b5188f4e971e1
SHA1 2b46b40f74b1780455aaf78c1da12955eafddb30
SHA256 7d7aaaad81790a6a1582c42f99068aa0e4077f0952093818bb2e1bb2c9ff37f5
SHA3 704a2ce7c29e705606adb7eb04191270b3c0b2365a461ba09564c47690284751

4

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x94a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.72366
MD5 8ae211ad934be57347f6ca021e19bcc4
SHA1 a4c2e9bd4f9539f895891af9bb496b27ddcf9010
SHA256 1f1dc625e413926964d53244d1e7a33fb58bf23949339758a10129e0c19ac36c
SHA3 12902271af0b480c069ff16ef4157d2102a3cd30ce2d23817219c2dc293f0fa2

5

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x4228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.73053
MD5 eeff06065c67520ab60ac89e64f6eee4
SHA1 48a1fee7493f788d79cf70c1c1a725dfa045e11a
SHA256 28709bbc7e50779478e3079dd19a98cdda2813dd880150e885109c84ac61d84f
SHA3 96f055c4fcc62ea79e3888dbfcb321a896053d9943c2260053847471fbe0af0d

6

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.87077
MD5 e2c5a336b029119874d3e47660c0a542
SHA1 5cfa3c7070f875196990b67bbef7cc1734b36d34
SHA256 6b019a431eb3232703fb501c977bfc9b302b2aaf47049caf730b9382e2c8555c
SHA3 f97a6bdcf9b3c5c5aec1d516074b6fc54171189209f9e4e2b44e1d09a685748e

7

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.99622
MD5 71fee0642d99a61322d49f8dc31657a5
SHA1 bc740805fa4005b807f374bc0d4a107822c7b361
SHA256 ff6725461fe8b86b18867ba8f5cc40cb23d27cf7fba4bcf66d5096b82b5f935b
SHA3 da9cdfc7df975cd24518bdcc5c1a2a0e43e724cce167c35e221c7d54c9f84457

8

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x988
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.06482
MD5 3df0c9d7d0b88cd7e367ca0accd76d27
SHA1 cca1d8747a956feb1ecc951bbd56c0137820c358
SHA256 dc3756ab459e8350c0558f4094947d3b1f544d99e84e30e59dee8613dc8f1f98
SHA3 9d4ac17c923b6d01b1a61ed283c691d80ac50f3d8fcf51883837865fe27c3668

9

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.93642
MD5 93b627c07b99f344080b2f1e1a3a68c5
SHA1 efa1d270ae3f5c6390b459bee625de4347b4ee17
SHA256 806245d7ef8627ac957484969685f16ffd8a0b592fe52f348acd4e61985b4a06
SHA3 e2068da2742cc54fcace692ea7e25e7b38219882d1759e0ee830de96b6c227ec

103

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x84
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.04448
Detected Filetype Icon file
MD5 f7731730720cfe035cf030b40d0e2eb6
SHA1 d046e23f2ee2b93ad96be8e1dc9120ecf3915091
SHA256 5c92a41adaf3265071482fd1a182ae8702c168636a7d9ff51798ee3a1dfc8500
SHA3 6f2d12e4c63c131a3f7f48293996e2be05da351536d013affe5d2265965ce657

1 (#2)

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x210
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.5636
MD5 b1896eb56c83e3d5bda752f7877f6007
SHA1 97f0feebce60693f5e9fedc0b6315e05d622c812
SHA256 d47790db30a8476cc148d07cdf009ad8cd39e133770a6ef588406deb63b5abb0
SHA3 8b4890a75f1d58cb0c54ebf85722125e36d0219bb82586dba8fe638d54362119

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x6c1
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.37708
MD5 aab7e8aafe7b06ab3d003b54ab5e18ed
SHA1 dccf0408f43059df37b755f3241a8b4b35c728af
SHA256 fb88b19523afd8fed48eddfd10805a3a0a45997bbf8fac04d595ddf93c1a88a8
SHA3 a981b8e907b79cd9448766ace938dfd96560d11c29e6ba165912a8508bd52ca7

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 2022.3.62.30479
ProductVersion 2022.3.62.30479
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_UNKNOWN
Language English - United States
FileVersion (#2) 2022.3.62.9860879
LegalCopyright (c) 2005-2025 Unity Technologies. All rights reserved.
ProductVersion (#2) 2022.3.62f3 (96770f904ca7)
Resource LangID English - United States

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2025-Oct-24 11:12:51
Version 0.0
SizeofData 141
AddressOfRawData 0x15aec
PointerToRawData 0x148ec
Referenced File C:\build\output\unity\unity\artifacts\WindowsPlayer\Win64_VS2019_nondev_m_r\WindowsPlayer_player_Master_mono_x64.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2025-Oct-24 11:12:51
Version 0.0
SizeofData 20
AddressOfRawData 0x15b7c
PointerToRawData 0x1497c

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2025-Oct-24 11:12:51
Version 0.0
SizeofData 768
AddressOfRawData 0x15b90
PointerToRawData 0x14990

TLS Callbacks

Load Configuration

Size 0x138
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x140018030

RICH Header

XOR Key 0xe5e06b0d
Unmarked objects 0
ASM objects (28900) 5
C++ objects (28900) 138
C objects (28900) 10
Imports (28900) 2
C++ objects (VS 2015/2017/2019 runtime 29118) 39
C objects (VS 2015/2017/2019 runtime 29118) 16
ASM objects (VS 2015/2017/2019 runtime 29118) 9
Imports (VS2019 Update 8 (16.8.0-1) compiler 29333) 3
Total imports 89
C++ objects (VS2019 Update 8 (16.8.0-1) compiler 29333) 3
Exports (VS2019 Update 8 (16.8.0-1) compiler 29333) 1
Resource objects (VS2019 Update 8 (16.8.0-1) compiler 29333) 1
Linker (VS2019 Update 8 (16.8.0-1) compiler 29333) 1

Errors

Leave a comment

No comments yet.