6358adc315c66a716c347d18d571306c6b6efd9572c88a7cc50343de5e7a2bba

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2025-Nov-26 14:42:16
Detected languages English - United States
Debug artifacts C:\build\output\unity\unity\artifacts\WindowsPlayer\Win_x64_VS2022_VB_nondev_i_r\WindowsPlayer_player_Master_il2cpp_x64.pdb
FileVersion 6000.2.15.460726
LegalCopyright (c) 2005-2025 Unity Technologies. All rights reserved.
ProductVersion 6000.2.15f1 (0707b6d1e918)

Plugin Output

Info The PE contains common functions which appear in legitimate applications. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryExW
Suspicious The PE is possibly a dropper. Resources amount for 84.5621% of the executable.
Safe VirusTotal score: 0/71 (Scanned on 2026-05-10 04:51:34) All the AVs think this file is safe.

Hashes

MD5 09b10d23f351980bc3b3d97fa7f1bdab
SHA1 f3a6ebed9440ce1b4d72e965505312b0c9cb1a5a
SHA256 6358adc315c66a716c347d18d571306c6b6efd9572c88a7cc50343de5e7a2bba
SHA3 4d1c191fc7edd523918c4427dcf23fedf2286504451167c7e8a9ade21218a113
SSDeep 3072:AwazAjvuMeUwZPR5YzK4GHcUIcLsdtpJ+4jF0yA78ZkU:baMjvuUwZpUUhLsTA78S
Imports Hash a136217cdd3247ff6a8766561064ca0b

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x110

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 6
TimeDateStamp 2025-Nov-26 14:42:16
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0xce00
SizeOfInitializedData 0x97000
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000001264 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0xa7000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 457fb5274ed18adc024e01b603e258a4
SHA1 159fdb99c377edc82c57d34217a711578edb0e63
SHA256 336709c08beca21a675f029c2d588ac0cae8cc8f42422039cbb827b6284374e5
SHA3 7d6db62af5f0503638e32b2c5a2ebd94056e5e490598ebed73cb0495875d3499
VirtualSize 0xcdb0
VirtualAddress 0x1000
SizeOfRawData 0xce00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.45019

.rdata

MD5 877238fc2135fb95f31fc34b728633e3
SHA1 74912e744e865595204ff59598cf13808a94bb61
SHA256 ac45f342d83c8464408c21e4823833f3c71bc31b709407eb0807161047ae2116
SHA3 96ac4ecafa392264a7f77830578cbbedc1e9eff94a617d26b28cd8214a2489ff
VirtualSize 0x977c
VirtualAddress 0xe000
SizeOfRawData 0x9800
PointerToRawData 0xd200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.69221

.data

MD5 0822db25bce65451a1219de812eea533
SHA1 bf4c918ff2184dfeba8cd4f98b21e11d75de05e7
SHA256 8987031a7fb9e9ffe2b44dad568693d86af933f2b44447b6f5c1159bd0750a79
SHA3 83fbc2d299cd2e5b71ce2f669f319b95fcab94178c620dd04d72a1071efde7b0
VirtualSize 0x1d88
VirtualAddress 0x18000
SizeOfRawData 0xc00
PointerToRawData 0x16a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 1.90767

.pdata

MD5 017f81338461c6b246bdb8ce1bf5fc08
SHA1 aa79861d4dea94c5fd283f1359435734dfb03517
SHA256 d1cc88f6e981b629ad1f47d33507ac8b71f82346871b690375752ffc69c6063d
SHA3 e197cfb7530afb455ed4ebbd26984d4562c62ea8c9c65f07f5d04c80970ee830
VirtualSize 0xec4
VirtualAddress 0x1a000
SizeOfRawData 0x1000
PointerToRawData 0x17600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.60208

.rsrc

MD5 18b5b7f6fa233120e679ad03692c19bb
SHA1 9baf0b666a205dc84082c51be5915865da505e17
SHA256 d2cc69e05e55468880825f0f95aa90d493ab4a1030a5b04c3939e913789ecb76
SHA3 f29dd7d977cdb4d90069042a1a7870ad584225ccbea357613a2afe54389cda6b
VirtualSize 0x8a018
VirtualAddress 0x1b000
SizeOfRawData 0x8a200
PointerToRawData 0x18600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.0322

.reloc

MD5 3ab8a3a955e5040e25556085e21a2be2
SHA1 f29b173f0ea430d70ff0803cbaa89fa1d4d024d9
SHA256 119eed3c019ffdb0bba4cee06b80d85e78a679f1bb17317cbb6a352bb4102d7a
SHA3 a5c3cb0725d2fd68e14265c6e03629d6270e73c1f049eb78b3e40b7b2535d802
VirtualSize 0x658
VirtualAddress 0xa6000
SizeOfRawData 0x800
PointerToRawData 0xa2800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 4.86735

Imports

UnityPlayer.dll UnityMain2
KERNEL32.dll HeapAlloc
WriteConsoleW
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
IsDebuggerPresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetStartupInfoW
IsProcessorFeaturePresent
GetModuleHandleW
CloseHandle
RtlUnwindEx
GetLastError
SetLastError
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
GetProcAddress
LoadLibraryExW
EncodePointer
RaiseException
RtlPcToFileHeader
GetStdHandle
WriteFile
GetModuleFileNameW
GetCurrentProcess
ExitProcess
TerminateProcess
GetModuleHandleExW
HeapFree
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
GetCommandLineA
GetCommandLineW
MultiByteToWideChar
WideCharToMultiByte
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetStdHandle
GetFileType
GetStringTypeW
FlsAlloc
FlsGetValue
FlsSetValue
FlsFree
LCMapStringW
GetProcessHeap
HeapSize
HeapReAlloc
FlushFileBuffers
GetConsoleOutputCP
GetConsoleMode
SetFilePointerEx
CreateFileW

Delayed Imports

AmdPowerXpressRequestHighPerformance

Ordinal 1
Address 0x18004

D3D12SDKPath

Ordinal 2
Address 0x18008

D3D12SDKVersion

Ordinal 3
Address 0xe320

NvOptimusEnablement

Ordinal 4
Address 0x18000

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.40235
MD5 9c596e11a56f222026a701f2acd41a70
SHA1 7262dc8c701bea3bf6744afc29529857dbcb7206
SHA256 6a8d3067a1e18ef7930627f60fc259e823172a93d22cf25f401f049a5c883eb5
SHA3 56223397391e46bce1b3238c3d61b51e03983c64f5fd738e14cfc6fff3556570

2

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x988
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.2516
MD5 5df2fc40dfb0665af30a50379b7970f3
SHA1 89461a689e3de4342e86650c5b87449482dfb3ec
SHA256 1c8671702b91c88cb72d5eb128c42aac30bb0e5eb1842345afe301b23ec11e66
SHA3 de008c434c080e79483330fb2b44e87d86c07eda75b0f43df95ba59c5a1e4455

3

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.01518
MD5 717453886c27121f06b9cde1dbfe224c
SHA1 ac2edbbeeba18681c103ba232ded75b178062734
SHA256 1d731e74f2936b484c52b3209fe0b457d89e4d8e638b9d23c0c11f316a60e6b9
SHA3 a49e7b9aeb334cd472e81987cece9c113c43b7df9c969fcb596a2dd7cf774350

4

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.73569
MD5 3aaaa532fa49dc0fbcfaea3fba05eb41
SHA1 e4635bcf5b69f7bdda1e624d4544dbc196c99844
SHA256 3cecfd815ee05c9504d383ee54fdc5a1baa0397ec1b4e196d9412f817da3c3ea
SHA3 308dae46562b19126f84ff5f7ccabb9524236f6368a7a5da2f72dcac82cc437a

5

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x4228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.59454
MD5 eb93d152b2ee5d86ce2265e9a2220235
SHA1 87caff40bed4d48f9a0649d0f8701a2e550fe77f
SHA256 029a7640a0a9bba7cc8d05104628778dff81514ace084bf6a47305694d71a9ab
SHA3 8971361197fb2dbb72f6180b6dd7ac93f388a0cfd9b5e6e1ddccd14e137c73b5

6

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x94a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.30462
MD5 2ce1687f1e5da4c548c4eb70e9669cce
SHA1 47ad53ae0304a0d72df949059ca59d7d47c494db
SHA256 907733a8b965d8a741747ed99ada269a98bd91ac1357f9d1e17e39480d59b40a
SHA3 5564301c9c8de53c20d3a9ddc6bb0758d5741354017e62fcbbc520f426753fea

7

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10828
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.13322
MD5 cc1df04cb7b6666d1e8f09a622233d1a
SHA1 131a61307b1ac21342ef1b8003d15f9b92d83245
SHA256 73c2513b7d115d049d5979082d5b339405626df5218294f03ee1385eb927a536
SHA3 424bfedc85509d99fc041c52094308c83e4f1b2b770899de2a55981abd958e7d

8

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.92997
MD5 346b3bcc4328c6608310407d3cad333e
SHA1 d385cdd09e114ae34117188d22ce5cb034c3a8b0
SHA256 ffbb719358d37dad14508fa0b25ac8c3143a6127f6571d6dee73680bf8ece4b2
SHA3 86c0aa0609f143ed34e57dcf00e78a6477f3cd10dff2435462bbb7394d39c24a

9

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x42028
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.81727
MD5 c49b110f75580b3190bb3992f2c2c8d8
SHA1 463f960721bc3bf088ceaa17bc379ebc0f0c5180
SHA256 68e1cd501c6488f4df83c800c027b94b2802d93ace454d0680632dbb64b68113
SHA3 54f467b2527603d040ea6cdf3a4cb706bfdd160e9f4f9d1a53bbfba429ebd36b

103

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x84
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.04448
Detected Filetype Icon file
MD5 3bf2dac037ce87794e66ff7f054e913f
SHA1 52ca961fd37ad960905a681d1db5157508ef1602
SHA256 2a87b1f32c5d0435090c72c392b75394f706e5750eff64fd85d25e1c622ee581
SHA3 8454d3273522657b5926068082b2cb88f6dbf352e7e9568008c0e33c792f349b

1 (#2)

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x210
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.53484
MD5 3660f6df2ddb20b23e33236f42223116
SHA1 2f126b6fc9a29d7220f0cb8ebb6a90777b7d678d
SHA256 31010dd863c4b7aa6b3bbcfdede465c5bc35039fa0d988c6071a10ef07daa226
SHA3 22b146762c80c2b62c724769a319db8036e77756211929fcd7efd4e1dfb44c66

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x545
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.24993
MD5 9df530c2f4fbe460da74e130d5d351a9
SHA1 f8719b6c74e0179556c1a18f214d6c1bbff8f823
SHA256 3c357bd1125971bda05bc59eaeca279da41715741e2535e9e75c94273b1c3a1f
SHA3 ce3dd46f87bd462f8730fca18daea6df444422f8d88b810aefbd7b2e62536dee

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 6000.2.15.1974
ProductVersion 6000.2.15.1974
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_UNKNOWN
Language English - United States
FileVersion (#2) 6000.2.15.460726
LegalCopyright (c) 2005-2025 Unity Technologies. All rights reserved.
ProductVersion (#2) 6000.2.15f1 (0707b6d1e918)
Resource LangID English - United States

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2025-Nov-26 14:42:16
Version 0.0
SizeofData 148
AddressOfRawData 0x15d68
PointerToRawData 0x14f68
Referenced File C:\build\output\unity\unity\artifacts\WindowsPlayer\Win_x64_VS2022_VB_nondev_i_r\WindowsPlayer_player_Master_il2cpp_x64.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2025-Nov-26 14:42:16
Version 0.0
SizeofData 20
AddressOfRawData 0x15dfc
PointerToRawData 0x14ffc

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2025-Nov-26 14:42:16
Version 0.0
SizeofData 836
AddressOfRawData 0x15e10
PointerToRawData 0x15010

TLS Callbacks

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x140018040

RICH Header

XOR Key 0x7914df52
Unmarked objects 0
ASM objects (28900) 5
C++ objects (28900) 138
C objects (28900) 10
Imports (28900) 2
ASM objects (34321) 9
C objects (34321) 16
C++ objects (34321) 40
Imports (34433) 3
Total imports 89
C++ objects (34433) 2
Exports (34433) 1
Resource objects (34433) 1
Linker (34433) 1

Errors

Leave a comment

No comments yet.