55c571043729d688c11f4d431246a35871062135ebb9cad92f49cc04d93541a3

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2024-Nov-25 22:21:15
Detected languages English - United States
Debug artifacts C:\build\output\unity\unity\artifacts\WindowsPlayer\Win_x64_VS2022_VB_nondev_i_r\WindowsPlayer_player_Master_il2cpp_x64.pdb
FileVersion 6000.0.29.10465253
LegalCopyright (c) 2005-2024 Unity Technologies. All rights reserved.
ProductVersion 6000.0.29f1 (9fafe5c9db65)

Plugin Output

Info The PE contains common functions which appear in legitimate applications. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryExW
Suspicious The PE is possibly a dropper. Resources amount for 83.983% of the executable.
Safe VirusTotal score: 0/71 (Scanned on 2026-05-30 21:30:09) All the AVs think this file is safe.

Hashes

MD5 2e5701ef4c8e9319fbc094f5a919cfc2
SHA1 b36c3885e088359067edc353ccf597076242ca1b
SHA256 55c571043729d688c11f4d431246a35871062135ebb9cad92f49cc04d93541a3
SHA3 a937ca18fcecb0194945be212ecb714ac42c02ac54122bb30ee6d21797dfbcb8
SSDeep 12288:R2NCD1Jr3dn8YFB3QsTw8sPHZtE+qph8LK6c40i3ur:XbSYbAsTyBq0LK6c40
Imports Hash ce1183cc150987a99aef5749f22af81e

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x110

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 7
TimeDateStamp 2024-Nov-25 22:21:15
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0xde00
SizeOfInitializedData 0x97200
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000001260 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0xa9000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 a5e0bf1e14a18380e4aa8fcfecd45cfd
SHA1 320e758c261b51cdf475ac1fe2d2b8b0f65ee37a
SHA256 9f9a743b5e5c12b459f7533a90382644af884df3aef68c9d7ac7d662735f193e
SHA3 0371197b472ffeeb91e1e7c7a9605222c7eee7431b878edcb558990adc374905
VirtualSize 0xdc70
VirtualAddress 0x1000
SizeOfRawData 0xde00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.46141

.rdata

MD5 91ccc1156ecd2c23a1710391b537af61
SHA1 00719f423fbae738169ad8848c1887f22d2b3c8a
SHA256 2f603b59c15623bfbac1f22f8833b78e693e77769028e3359c29bd6db87c8551
SHA3 92083657c40d03d420cc2d07ce62bf9f74b77c84b403a1021d5ac59bddaec53a
VirtualSize 0x977a
VirtualAddress 0xf000
SizeOfRawData 0x9800
PointerToRawData 0xe200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.70122

.data

MD5 d284f7b260ed119794375a6998c5083c
SHA1 0944c690e2b7841e681f55d2a731910f8019f2ef
SHA256 79ebad17e73900bd4dd43a932cc832e1d907346973e16ac0af549524fa4b88b3
SHA3 0c023444d7239a9582798618879cf6e165fcae6d6eec1051c77592814b4894ad
VirtualSize 0x1d78
VirtualAddress 0x19000
SizeOfRawData 0xc00
PointerToRawData 0x17a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 1.89847

.pdata

MD5 583bf012d5970545541b47ad6f1b2dc4
SHA1 ed34342900f8481a1f09e9f73fe8bb0d1e528eb6
SHA256 a7a9a284c12beceaf69e80c98bb9708078c1ee29e3581bf7c44e24e7535c04eb
SHA3 e57cf3023698fe8882221ba469ca26d236b8a3d44b7d67f42d621316177425fe
VirtualSize 0xf24
VirtualAddress 0x1b000
SizeOfRawData 0x1000
PointerToRawData 0x18600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.67239

_RDATA

MD5 dd297010ea596c9b749ddc72fe421330
SHA1 3213e7a4b99366f1367f1b5dc97aa4853369a784
SHA256 420a70f17663b392f63eb448853ebc800a3f7cf9c6e0b78b7e421d671dd927fd
SHA3 f4660bd566f5561530bb0e40a752616d5a8180b7180fcf869790d48f9fb6e9bf
VirtualSize 0x1f4
VirtualAddress 0x1c000
SizeOfRawData 0x200
PointerToRawData 0x19600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 3.71477

.rsrc

MD5 32f72fede6dc8b071a785cf246b1adf5
SHA1 e739369f91d9eb24998f8079a110d3b05f737ab9
SHA256 6c67cb27791da6452de52988de9453f9aa3d19cdbe894e300a5eb6f3ee4d0ba4
SHA3 2433438a6667ea945173d616e0cbcac878c5527477f4cffab0f79191a055502a
VirtualSize 0x8a020
VirtualAddress 0x1d000
SizeOfRawData 0x8a200
PointerToRawData 0x19800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.8475

.reloc

MD5 79918e2814a23b917e4a5494067a35d5
SHA1 eab8dd05e160cbff9fa1c348b6c35e7f161cf459
SHA256 cccb376562c958fee6ec06051a48d2c5c0232065e1000ce2d4b0775e46737238
SHA3 0fcd95a99b9b4e77c2e23089f450965a4028a243ef56d1928fdcfcebcc4b7120
VirtualSize 0x658
VirtualAddress 0xa8000
SizeOfRawData 0x800
PointerToRawData 0xa3a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 4.87002

Imports

UnityPlayer.dll UnityMain
KERNEL32.dll HeapAlloc
WriteConsoleW
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
IsDebuggerPresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetStartupInfoW
IsProcessorFeaturePresent
GetModuleHandleW
CloseHandle
RtlUnwindEx
GetLastError
SetLastError
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
GetProcAddress
LoadLibraryExW
EncodePointer
RaiseException
RtlPcToFileHeader
GetStdHandle
WriteFile
GetModuleFileNameW
GetCurrentProcess
ExitProcess
TerminateProcess
GetModuleHandleExW
HeapFree
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
GetCommandLineA
GetCommandLineW
MultiByteToWideChar
WideCharToMultiByte
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetStdHandle
GetFileType
GetStringTypeW
FlsAlloc
FlsGetValue
FlsSetValue
FlsFree
LCMapStringW
GetProcessHeap
HeapSize
HeapReAlloc
FlushFileBuffers
GetConsoleOutputCP
GetConsoleMode
SetFilePointerEx
CreateFileW

Delayed Imports

AmdPowerXpressRequestHighPerformance

Ordinal 1
Address 0x19004

D3D12SDKPath

Ordinal 2
Address 0x19008

D3D12SDKVersion

Ordinal 3
Address 0xf320

NvOptimusEnablement

Ordinal 4
Address 0x19000

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.01632
MD5 aebccb75d4fd0738eae88ed5704ad64e
SHA1 fa50c42af1e4215dae6fde816270bb411804b63f
SHA256 831dd6268a4dea6fd11be0b7fddcfc4894ca9e5d2f2b9d82de88f2dc41c301bf
SHA3 665a52510750e0417c76bd55bd088d89018597af054468db76d0c963c4428b66

2

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x988
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.07804
MD5 a1d9a594cd43e7b0398b879a711e008f
SHA1 7245ff548bb304dc718db864985c5c457ceaa9db
SHA256 6f4bb46c474678aa59f8e047ec1e45b0e6dd52e23cd02c6b0574ab63cf2f236c
SHA3 488be782f9c600e76f7f3b665744c640efb7ce91f2fb0509ca94db5f3cc4fec2

3

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.07164
MD5 19cd539ff1776651f8e91f895c98cd9c
SHA1 0ca8da3ed42c924e65dec8c0a6368daa94edae2c
SHA256 ea3927aeffdec459ac6438ea75effbe82a71612cd8cd591b0ab34bdacfd57a2e
SHA3 546c35c4cfc1c98822619c6b27d78a495a164f7bc72c43c245ca5195838419ed

4

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.95229
MD5 b64ab4289ed30e674a048b824b748115
SHA1 6ae392c7efd07107d6a955f8fd05d260eafd5cba
SHA256 4ff0caf86e1dfbd772eac0c138db1215d7ab71900a7645472290b64383e71366
SHA3 c0fe59c09f4e559552257478cb084ff06c5974724989ef34d4e4b237211dbb00

5

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x4228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.90757
MD5 6ee90e3d9531f0e0c57d629352aa98ee
SHA1 f285d6ed3fbc2d49e0cee12bb0a2b371f38fc06c
SHA256 e8c6d8fffb848e76a00b393c99e3fc04cf69b66fa5794cec06ff4475a6bb6c6b
SHA3 3f928ea0c3f4b8a639ecce4b71a9381fc6a638df369ad3a4aaa2744e8687b629

6

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x94a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.82556
MD5 4cc8f7ea587c84abfc1a39bce22b182c
SHA1 96bd84b065328678bf66f0fe86a8331d74d59c34
SHA256 88e6bad45d0dfe6e444144fa16f13c129592f487d05fffbe675d835de54b565d
SHA3 5482f812bac384281e2a80ef80ca9140820bcc7d469d99d0bfba2de9524069e6

7

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10828
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.13421
MD5 2a19dad59503b071ce8abe7353735743
SHA1 fe7d3d527c28f4117ee3449246f492078b3f626c
SHA256 10fa80ec2efe20953cb6cd2f7c59a53c01475de2fa3d23aad61c6e5a46c4c55d
SHA3 12d01dfbb86c17e9baac4ef219307dfd547d9106bbf89025aef1d725f2dd7889

8

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.89039
MD5 d5336a0a5029886472239697197a28a1
SHA1 7baaed6bd16ee8eb712d362e3f18df9a04ccde57
SHA256 57f2013d61d88f86af8a05848510d18dd4407e2417644a8c0555934810b90d85
SHA3 a551a7b29569df06de32cc17546c3f001f5ef2aca844028cc791576fe6d81108

9

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x42028
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.89153
MD5 507dd134db8ce919f6b7ab4fc5215917
SHA1 27f851e38a62ec087c9ce07eb21c4c9270e8ac97
SHA256 81eeb3dc24207a6f7cbb317a4687cb5fbf6814e12cad18507eebcb2ebd9aaab8
SHA3 81b66306c40c871bac0672878c62bbebd170ffc162dc16756ed83609b1295ecb

103

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x84
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.04448
Detected Filetype Icon file
MD5 3bf2dac037ce87794e66ff7f054e913f
SHA1 52ca961fd37ad960905a681d1db5157508ef1602
SHA256 2a87b1f32c5d0435090c72c392b75394f706e5750eff64fd85d25e1c622ee581
SHA3 8454d3273522657b5926068082b2cb88f6dbf352e7e9568008c0e33c792f349b

1 (#2)

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x214
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.49395
MD5 3511e9289d0b747385d3029bf2805e4f
SHA1 3f8d4b12d420d602ac27b5b75d24fe2d887eaa24
SHA256 c3347e8e43f4cbc0795b236cc08d56a9d16d21ba084fdf53b7c4fbe416f1a4e7
SHA3 a6fd3d6e74a4f7ec09489ac0e4ebedd6dc1d2711fcb0926782a7550852bd381b

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x545
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.24993
MD5 9df530c2f4fbe460da74e130d5d351a9
SHA1 f8719b6c74e0179556c1a18f214d6c1bbff8f823
SHA256 3c357bd1125971bda05bc59eaeca279da41715741e2535e9e75c94273b1c3a1f
SHA3 ce3dd46f87bd462f8730fca18daea6df444422f8d88b810aefbd7b2e62536dee

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 6000.0.29.45029
ProductVersion 6000.0.29.45029
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_UNKNOWN
Language English - United States
FileVersion (#2) 6000.0.29.10465253
LegalCopyright (c) 2005-2024 Unity Technologies. All rights reserved.
ProductVersion (#2) 6000.0.29f1 (9fafe5c9db65)
Resource LangID English - United States

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2024-Nov-25 22:21:15
Version 0.0
SizeofData 148
AddressOfRawData 0x16d58
PointerToRawData 0x15f58
Referenced File C:\build\output\unity\unity\artifacts\WindowsPlayer\Win_x64_VS2022_VB_nondev_i_r\WindowsPlayer_player_Master_il2cpp_x64.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2024-Nov-25 22:21:15
Version 0.0
SizeofData 20
AddressOfRawData 0x16dec
PointerToRawData 0x15fec

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2024-Nov-25 22:21:15
Version 0.0
SizeofData 852
AddressOfRawData 0x16e00
PointerToRawData 0x16000

TLS Callbacks

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x140019040

RICH Header

XOR Key 0x7139305b
Unmarked objects 0
ASM objects (28900) 5
C++ objects (28900) 138
C objects (28900) 10
Unmarked objects (#2) 1
Imports (28900) 2
C++ objects (33218) 40
C objects (33218) 16
ASM objects (33218) 17
Imports (33523) 3
Total imports 89
C++ objects (33523) 2
Exports (33523) 1
Resource objects (33523) 1
Linker (33523) 1

Errors

Leave a comment

No comments yet.