621dbd6e6d375051331af90d3c88e4c13cb82861abce4e800c09e0fb2557f39e

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2025-Sep-12 10:30:53
Detected languages English - United States
Debug artifacts C:\build\output\unity\unity\artifacts\WindowsPlayer\Win_x64_VS2022_VB_nondev_m_r\WindowsPlayer_player_Master_mono_x64.pdb
FileVersion 6000.0.58.9625317
LegalCopyright (c) 2005-2025 Unity Technologies. All rights reserved.
ProductVersion 6000.0.58f2 (92dee566b325)

Plugin Output

Info The PE contains common functions which appear in legitimate applications. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryExW
Suspicious The PE is possibly a dropper. Resources amount for 83.9824% of the executable.
Safe VirusTotal score: 0/72 (Scanned on 2026-03-14 02:12:45) All the AVs think this file is safe.

Hashes

MD5 51889bdc037836d4c19244225f2b7c67
SHA1 5bc172fe5b92ecf77113ff66c5ff9de9d420f8d8
SHA256 621dbd6e6d375051331af90d3c88e4c13cb82861abce4e800c09e0fb2557f39e
SHA3 d2df7cd070903f4508ce1b907fb08400cfc45ff00c2843f659bf294457c0973d
SSDeep 6144:82E4CD20ZB4Gr34QiHmsYCnNYeB+X3aZ7llKxp4Bbf//qcTCBT:82NCDdJr3d4lYCNJ0X3iJYx+/qQC
Imports Hash a136217cdd3247ff6a8766561064ca0b

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x110

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 7
TimeDateStamp 2025-Sep-12 10:30:53
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0xde00
SizeOfInitializedData 0x97200
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000001264 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0xa9000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 2775a5a7c1fa856e6a29a4f5a5229c31
SHA1 3e9ae8fdb588fe4aae22d549f8569008c887c898
SHA256 195697288171c6371920514965e3625060b55abd960ee1903baa797ef5e0bbfb
SHA3 fb39403bbfb970d14fc395dd6c3593ca3d0aec333b14d9249010a0924d269e75
VirtualSize 0xdc70
VirtualAddress 0x1000
SizeOfRawData 0xde00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.46162

.rdata

MD5 98e8550d448edf5e7ab1b8f0ae443b86
SHA1 6115012608b7d6a80374d7dfa27cef12e629957c
SHA256 0fab178353a8bf13f4eddb644efb1a40a7ee50bc0fc332142c5d7b9ed4e825e7
SHA3 474333948ae551bf531be250acb5038ec1cf24477cc324b2b88eeedf444595dd
VirtualSize 0x977c
VirtualAddress 0xf000
SizeOfRawData 0x9800
PointerToRawData 0xe200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.70159

.data

MD5 d284f7b260ed119794375a6998c5083c
SHA1 0944c690e2b7841e681f55d2a731910f8019f2ef
SHA256 79ebad17e73900bd4dd43a932cc832e1d907346973e16ac0af549524fa4b88b3
SHA3 0c023444d7239a9582798618879cf6e165fcae6d6eec1051c77592814b4894ad
VirtualSize 0x1d78
VirtualAddress 0x19000
SizeOfRawData 0xc00
PointerToRawData 0x17a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 1.89847

.pdata

MD5 d67581e7561b613930fcc4c3ee52cdc5
SHA1 a43e835342a8235efb9f656bba5c170d21641a61
SHA256 4eaf2a70ebe02f5f76d3b133d8a74d7c7eee9267519fd6a6951de4bcb2ad617b
SHA3 0ccfeafaf338d1bcb9c719ffca72875595bea8d6aea16bd26baa2a4685e84170
VirtualSize 0xf24
VirtualAddress 0x1b000
SizeOfRawData 0x1000
PointerToRawData 0x18600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.67172

_RDATA

MD5 dd297010ea596c9b749ddc72fe421330
SHA1 3213e7a4b99366f1367f1b5dc97aa4853369a784
SHA256 420a70f17663b392f63eb448853ebc800a3f7cf9c6e0b78b7e421d671dd927fd
SHA3 f4660bd566f5561530bb0e40a752616d5a8180b7180fcf869790d48f9fb6e9bf
VirtualSize 0x1f4
VirtualAddress 0x1c000
SizeOfRawData 0x200
PointerToRawData 0x19600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 3.71477

.rsrc

MD5 88030e2eebf5900984ca19b104ad7db2
SHA1 5e7f5f91ffc1302c74798f9bc40c00a628ca59a4
SHA256 6fdec0e90b27e1de6729c44c4138f5af3253e04cfce66234044f5272975de1ef
SHA3 8f9746c70f5b758a620b6629446dd6a79a521abcc2eafd3c14c4f2e567ebaeb6
VirtualSize 0x8a018
VirtualAddress 0x1d000
SizeOfRawData 0x8a200
PointerToRawData 0x19800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.56262

.reloc

MD5 79918e2814a23b917e4a5494067a35d5
SHA1 eab8dd05e160cbff9fa1c348b6c35e7f161cf459
SHA256 cccb376562c958fee6ec06051a48d2c5c0232065e1000ce2d4b0775e46737238
SHA3 0fcd95a99b9b4e77c2e23089f450965a4028a243ef56d1928fdcfcebcc4b7120
VirtualSize 0x658
VirtualAddress 0xa8000
SizeOfRawData 0x800
PointerToRawData 0xa3a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 4.87002

Imports

UnityPlayer.dll UnityMain2
KERNEL32.dll HeapAlloc
WriteConsoleW
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
IsDebuggerPresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetStartupInfoW
IsProcessorFeaturePresent
GetModuleHandleW
CloseHandle
RtlUnwindEx
GetLastError
SetLastError
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
GetProcAddress
LoadLibraryExW
EncodePointer
RaiseException
RtlPcToFileHeader
GetStdHandle
WriteFile
GetModuleFileNameW
GetCurrentProcess
ExitProcess
TerminateProcess
GetModuleHandleExW
HeapFree
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
GetCommandLineA
GetCommandLineW
MultiByteToWideChar
WideCharToMultiByte
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetStdHandle
GetFileType
GetStringTypeW
FlsAlloc
FlsGetValue
FlsSetValue
FlsFree
LCMapStringW
GetProcessHeap
HeapSize
HeapReAlloc
FlushFileBuffers
GetConsoleOutputCP
GetConsoleMode
SetFilePointerEx
CreateFileW

Delayed Imports

AmdPowerXpressRequestHighPerformance

Ordinal 1
Address 0x19004

D3D12SDKPath

Ordinal 2
Address 0x19008

D3D12SDKVersion

Ordinal 3
Address 0xf320

NvOptimusEnablement

Ordinal 4
Address 0x19000

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.61485
MD5 bdb5a508a8471f64080dadb855a1f262
SHA1 80445f9619304dd2977cc3062000f9cced8cb80b
SHA256 cd85f2c904a66604d48d4d7194126af5a8bd8ca2793fc91cf1d7db73e65f98c9
SHA3 d7cff7e5d408cefe9a359dd5401113ed2a6e2be89f0e21c39c0bf3884c87ef88

2

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x988
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.62141
MD5 c4a43a4148b77dc0a9f45d7135dc6117
SHA1 b8f96e962cd00cb9054337ec5eb5773752072456
SHA256 b954f3f1556b284c40b61372fd51a2a5467f0c5217aa2d6c3655d179e95aac0e
SHA3 7a538475dd3d60c8b2ce1924c9e776828669ddcb17c73382e5e2d9ec575f5e77

3

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.55554
MD5 b3af6f8bf9b6dd833f74fd440285a98e
SHA1 e2722556d4c073314808350a92aba80892c4040e
SHA256 22814adb804e8ad3638b6dbe61051fc1369f710ed01f756b183199ab13e0a2f1
SHA3 cced37fe92d86eecf931af2844170e76da7fd5c9f0964f7015d176998719bbae

4

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.21104
MD5 cbcc5d56eae7de7fc6799e8cb62ad66f
SHA1 299cd7ad10a92b983a43214d82e25b1380fd909c
SHA256 a7cde2f9f4dbf0a39d16db7924f5d93eb1db43e7f4487fd4e8b8dc80c4bbc350
SHA3 f1a32f6b6b08288df96bd873837b7eb799860c76854ef2573840579d31f7e86e

5

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x4228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.05557
MD5 0ff7278cdbc8a28271397bc4230060c0
SHA1 c77cdea96fa8d255ad8e2f45b7c2b20243d052bc
SHA256 09254e527e3a897d6b5196126587701b2386b04580f85ff471160c07626fb1e3
SHA3 5430c56443aad61bbbc55888d7db029a7d23b2a404f8a14fe0caf6a33dfaf704

6

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x94a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.6834
MD5 3e1fb4fb07001910ceb6ef39f53c962d
SHA1 f85328bbe6d706b12f07feb2600d9545fa0a158f
SHA256 b460e742b7742b02b6fb3799ff5a124a52c3d1e764c0adf2cef7a0a3f9dd5420
SHA3 35397c935865e1deaf4178a50d33668ee7fa1e3a38d26463d107e915f53d2e8c

7

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10828
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.4382
MD5 019e521e09b49b88015c2a226164b8cd
SHA1 ee69e69d65483d6d09b1f9730d8251713cb0e7eb
SHA256 e550bdec1e4e7eaa3a647223190ea929376260ff64ad66dc09d89169aa749bb5
SHA3 cb9900030fe4a3530f0190b92762ce003a09260dcff26d42a3027275a4250f6b

8

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.46441
MD5 a7de367e6aa45556120088851ce86d04
SHA1 a4d9ecd830a2e0200fe7201b46c5ce8cc92319d3
SHA256 cca015affeb71dfc07fb498123bb80337351ad4aae296bd10e31ee7d3b9293c2
SHA3 b342e2fbc510313b0df91e5cfc5631de48835e7bee133cd80611bb53a6a63757

9

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x42028
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.463
MD5 402d38e248e93e16e2c276162c378613
SHA1 81ed1604eea5b3a58a1dbe609991d0e2f04ac443
SHA256 c02374e129938fab014389f9935764a05b17f265506c5df00a597a246c28ef28
SHA3 bcd1766d9f73e0e16b272476bca4a08efc40b564d54f73ff0129ff35d95cbe5c

103

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x84
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.04448
Detected Filetype Icon file
MD5 3bf2dac037ce87794e66ff7f054e913f
SHA1 52ca961fd37ad960905a681d1db5157508ef1602
SHA256 2a87b1f32c5d0435090c72c392b75394f706e5750eff64fd85d25e1c622ee581
SHA3 8454d3273522657b5926068082b2cb88f6dbf352e7e9568008c0e33c792f349b

1 (#2)

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x210
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.51922
MD5 0d36dbf87b1992367848f0d9ed62868b
SHA1 b08da1f0e736ec51259a9e0e26080fb5bc3dd597
SHA256 ffb923486883d783c736706624a7afa3bd76056ccf715e8720e76a0fbac83bbe
SHA3 1fd94d5e30e784ef6bcbeebcea0c90dcdccf21433ca3e8c2acf871dfe8fb473b

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x545
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.24993
MD5 9df530c2f4fbe460da74e130d5d351a9
SHA1 f8719b6c74e0179556c1a18f214d6c1bbff8f823
SHA256 3c357bd1125971bda05bc59eaeca279da41715741e2535e9e75c94273b1c3a1f
SHA3 ce3dd46f87bd462f8730fca18daea6df444422f8d88b810aefbd7b2e62536dee

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 6000.0.58.57061
ProductVersion 6000.0.58.57061
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_UNKNOWN
Language English - United States
FileVersion (#2) 6000.0.58.9625317
LegalCopyright (c) 2005-2025 Unity Technologies. All rights reserved.
ProductVersion (#2) 6000.0.58f2 (92dee566b325)
Resource LangID English - United States

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2025-Sep-12 10:30:53
Version 0.0
SizeofData 146
AddressOfRawData 0x16d58
PointerToRawData 0x15f58
Referenced File C:\build\output\unity\unity\artifacts\WindowsPlayer\Win_x64_VS2022_VB_nondev_m_r\WindowsPlayer_player_Master_mono_x64.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2025-Sep-12 10:30:53
Version 0.0
SizeofData 20
AddressOfRawData 0x16dec
PointerToRawData 0x15fec

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2025-Sep-12 10:30:53
Version 0.0
SizeofData 852
AddressOfRawData 0x16e00
PointerToRawData 0x16000

TLS Callbacks

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x140019040

RICH Header

XOR Key 0x7139305b
Unmarked objects 0
ASM objects (28900) 5
C++ objects (28900) 138
C objects (28900) 10
Unmarked objects (#2) 1
Imports (28900) 2
C++ objects (33218) 40
C objects (33218) 16
ASM objects (33218) 17
Imports (33523) 3
Total imports 89
C++ objects (33523) 2
Exports (33523) 1
Resource objects (33523) 1
Linker (33523) 1

Errors

Leave a comment

No comments yet.