7968661d3d7922fb3bfeb0c594dce9239edab40e3c060d81fd96dc6aae6a33f7

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2025-Oct-01 12:05:08
Detected languages English - United States
Debug artifacts C:\build\output\unity\unity\artifacts\WindowsPlayer\Win_x64_VS2022_VB_nondev_m_r\WindowsPlayer_player_Master_mono_x64.pdb
FileVersion 6000.0.59.15673372
LegalCopyright (c) 2005-2025 Unity Technologies. All rights reserved.
ProductVersion 6000.0.59f2 (ef281c76c3c1)

Plugin Output

Info The PE contains common functions which appear in legitimate applications. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryExW
Suspicious The PE is possibly a dropper. Resources amount for 83.983% of the executable.
Suspicious No VirusTotal score. This file has never been scanned on VirusTotal.

Hashes

MD5 f80b007de9f7ce8c46057a801345c02e
SHA1 fc7d37da48eb8c456ab558de119a1340c1336710
SHA256 7968661d3d7922fb3bfeb0c594dce9239edab40e3c060d81fd96dc6aae6a33f7
SHA3 8e12a848a7e992439ccbf60652ae9fc2c2695d35b952b2a3e8199b11145ec55b
SSDeep 6144:p2E4CD20ZB4Gr34QiHqCo0TJwu5EuEnyIn+uLJnRz1bfzU3My:p2NCDdJr3d4zoH+uLN
Imports Hash a136217cdd3247ff6a8766561064ca0b

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x110

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 7
TimeDateStamp 2025-Oct-01 12:05:08
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0xde00
SizeOfInitializedData 0x97200
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000001264 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0xa9000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 2775a5a7c1fa856e6a29a4f5a5229c31
SHA1 3e9ae8fdb588fe4aae22d549f8569008c887c898
SHA256 195697288171c6371920514965e3625060b55abd960ee1903baa797ef5e0bbfb
SHA3 fb39403bbfb970d14fc395dd6c3593ca3d0aec333b14d9249010a0924d269e75
VirtualSize 0xdc70
VirtualAddress 0x1000
SizeOfRawData 0xde00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.46162

.rdata

MD5 e275c560039ba46c3b13c577d363386d
SHA1 ed7d58ff98824680db0fa63e415eebe47f26ff55
SHA256 9e38d095a74df6856cbaddb225f9888b9a54d0168c3cf2e27f079c060ad5f62d
SHA3 ccf6ae682cfe38f5a99c62e21c10d2e0c9c15ce768dbb22a6e0adcdeaa2a0ae2
VirtualSize 0x977c
VirtualAddress 0xf000
SizeOfRawData 0x9800
PointerToRawData 0xe200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.70157

.data

MD5 d284f7b260ed119794375a6998c5083c
SHA1 0944c690e2b7841e681f55d2a731910f8019f2ef
SHA256 79ebad17e73900bd4dd43a932cc832e1d907346973e16ac0af549524fa4b88b3
SHA3 0c023444d7239a9582798618879cf6e165fcae6d6eec1051c77592814b4894ad
VirtualSize 0x1d78
VirtualAddress 0x19000
SizeOfRawData 0xc00
PointerToRawData 0x17a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 1.89847

.pdata

MD5 d67581e7561b613930fcc4c3ee52cdc5
SHA1 a43e835342a8235efb9f656bba5c170d21641a61
SHA256 4eaf2a70ebe02f5f76d3b133d8a74d7c7eee9267519fd6a6951de4bcb2ad617b
SHA3 0ccfeafaf338d1bcb9c719ffca72875595bea8d6aea16bd26baa2a4685e84170
VirtualSize 0xf24
VirtualAddress 0x1b000
SizeOfRawData 0x1000
PointerToRawData 0x18600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.67172

_RDATA

MD5 dd297010ea596c9b749ddc72fe421330
SHA1 3213e7a4b99366f1367f1b5dc97aa4853369a784
SHA256 420a70f17663b392f63eb448853ebc800a3f7cf9c6e0b78b7e421d671dd927fd
SHA3 f4660bd566f5561530bb0e40a752616d5a8180b7180fcf869790d48f9fb6e9bf
VirtualSize 0x1f4
VirtualAddress 0x1c000
SizeOfRawData 0x200
PointerToRawData 0x19600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 3.71477

.rsrc

MD5 720827c73ca71f41fef5f7f763a560eb
SHA1 4eadb5bc91e878cb53ebda023a2a360c83fdae2c
SHA256 885804473476d715fed6e505686c69a394dd7c89ceb01a1901d64e1b72ef2adb
SHA3 52ee077705052c6d5376f649f90fade108ca2abc2c8c8dede7a5400c0f3c48e8
VirtualSize 0x8a020
VirtualAddress 0x1d000
SizeOfRawData 0x8a200
PointerToRawData 0x19800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 1.83715

.reloc

MD5 79918e2814a23b917e4a5494067a35d5
SHA1 eab8dd05e160cbff9fa1c348b6c35e7f161cf459
SHA256 cccb376562c958fee6ec06051a48d2c5c0232065e1000ce2d4b0775e46737238
SHA3 0fcd95a99b9b4e77c2e23089f450965a4028a243ef56d1928fdcfcebcc4b7120
VirtualSize 0x658
VirtualAddress 0xa8000
SizeOfRawData 0x800
PointerToRawData 0xa3a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 4.87002

Imports

UnityPlayer.dll UnityMain2
KERNEL32.dll HeapAlloc
WriteConsoleW
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
IsDebuggerPresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetStartupInfoW
IsProcessorFeaturePresent
GetModuleHandleW
CloseHandle
RtlUnwindEx
GetLastError
SetLastError
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
GetProcAddress
LoadLibraryExW
EncodePointer
RaiseException
RtlPcToFileHeader
GetStdHandle
WriteFile
GetModuleFileNameW
GetCurrentProcess
ExitProcess
TerminateProcess
GetModuleHandleExW
HeapFree
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
GetCommandLineA
GetCommandLineW
MultiByteToWideChar
WideCharToMultiByte
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetStdHandle
GetFileType
GetStringTypeW
FlsAlloc
FlsGetValue
FlsSetValue
FlsFree
LCMapStringW
GetProcessHeap
HeapSize
HeapReAlloc
FlushFileBuffers
GetConsoleOutputCP
GetConsoleMode
SetFilePointerEx
CreateFileW

Delayed Imports

AmdPowerXpressRequestHighPerformance

Ordinal 1
Address 0x19004

D3D12SDKPath

Ordinal 2
Address 0x19008

D3D12SDKVersion

Ordinal 3
Address 0xf320

NvOptimusEnablement

Ordinal 4
Address 0x19000

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.40143
MD5 3b8a1ff4e26a4b32f66d224395e62b53
SHA1 c8ba39edcc487ebcb60ac573a9919479fa961fb4
SHA256 72cbf9b21cc4c646c8a932e1f3d176f827d1313a37758514e8d5cf78fc28688d
SHA3 cfe10b7be0739f6c6d6442802a7f596f3d57fb5d832ca5c6e51d5611647cdb13

2

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x988
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.21266
MD5 d84723fbf83ae85e5289879e73d648ff
SHA1 1538d8a5e685515d444628ccb66e184f8b642d6b
SHA256 64203b8ad6d31009d7f5642ceb3eed846aa01f7e4d909b4790f1efecf4d1f138
SHA3 ddb68e833d445cf659159a9fd87bb141b20f92f5efa856c28cd20d94209ffe1a

3

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.03669
MD5 d0afc6502ca09d898d8574b7c00e6096
SHA1 c8b4aa349e1c78f84f44d6373a601cb242cef665
SHA256 415af88adf8aa5cdeb405c18eb691e4ebb3c41d4fa5f554e001cccb1fbeb2d59
SHA3 97e89831fae3892461ca4b2dc00cd859f8b01f97f35979fcbf9dc02e9924a796

4

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.0648
MD5 d79717eaff5c96b95ed73797eca926e4
SHA1 9748c1e67cc38daac31aa06af44d854a7844b785
SHA256 0471552d38e370cfa0d6c5dd2ec2a68d68dc6e258688972a1f85c3938f205517
SHA3 afc9531bcb11b22aeb012cc3626ada6dd43ceb00c0f36386b455f1c0735af746

5

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x4228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.76777
MD5 539de405877400d34d049e8484401b88
SHA1 6b5b019cf14f000f15cc3c8bd30af639bccc2c66
SHA256 b19e24cae66d9447fc311c2197b3c8c00f535a51ff9a800ac51e27280493039f
SHA3 a0384c87dc3d667e3ff4e15cc52e64b50a8736974d197b855fe9db0e13362323

6

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x94a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.76876
MD5 7da30349b48c57b1b92c219eea5fd5d7
SHA1 74524f6a39e574871d3b039f4dd4c0645814199a
SHA256 1ea7ce50e556a04e772ae106869a8536d4e2b456665915347a12d1cb9917e054
SHA3 2237f686b76104f254350557e2032ad7b4d2df9547638aa6cbca4a05550c057f

7

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10828
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.73905
MD5 888d6e6287b4286482b973ac3f119773
SHA1 fe25075e4add9d2cccad93f59084d78ad5bce662
SHA256 ffcc90d74a8dde8f08a3dbdb406efb33bc542c4bbfde72ef4c00d2891dd7a0f8
SHA3 d91a05f9bc9d30b1a0fd7a77d76c929775c7025a0b3d628ca7bb4463d0091425

8

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.75793
MD5 cd5bd804681871d53392b70d8ee43699
SHA1 42be6266cdafdcf0fbe4492233a98b1307057a4f
SHA256 59eb79a7a314e6a0cf00d6cbab5880610d87fdb1a042150a93d855e13c210c9b
SHA3 aa5aa1d83cd92e89cc31c520e345f8d9ec4e05d797a9238beb6bdf6035654651

9

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x42028
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.76552
MD5 99013b49f04a9f4194defa7e442e88d3
SHA1 7d682e5298be3431f513d7aec242a11c6e25c141
SHA256 0f07697505e2e65b5ff4ff62876dda859a11bd95d9c14f7db8b9bf38d854867e
SHA3 b241cd2e68ed51412c9c7da5898ec62372070543b503234846fc872d134341a9

103

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x84
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.04448
Detected Filetype Icon file
MD5 3bf2dac037ce87794e66ff7f054e913f
SHA1 52ca961fd37ad960905a681d1db5157508ef1602
SHA256 2a87b1f32c5d0435090c72c392b75394f706e5750eff64fd85d25e1c622ee581
SHA3 8454d3273522657b5926068082b2cb88f6dbf352e7e9568008c0e33c792f349b

1 (#2)

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x214
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.50159
MD5 0bf618b928eea2aab89146a1e4e53a95
SHA1 7fe6411f8bbd703125ea6c83f3e41b36a465b952
SHA256 8ce08fafa1b40a4a5056f7d29a9bf7a4b9dcfd6576e1ec7021ff2faddc5c67d1
SHA3 999e95df705895b36dbf037acdc5af2cbf4aeda4720e2128a0e9e1888c8e7d8b

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x545
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.24993
MD5 9df530c2f4fbe460da74e130d5d351a9
SHA1 f8719b6c74e0179556c1a18f214d6c1bbff8f823
SHA256 3c357bd1125971bda05bc59eaeca279da41715741e2535e9e75c94273b1c3a1f
SHA3 ce3dd46f87bd462f8730fca18daea6df444422f8d88b810aefbd7b2e62536dee

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 6000.0.59.10268
ProductVersion 6000.0.59.10268
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_UNKNOWN
Language English - United States
FileVersion (#2) 6000.0.59.15673372
LegalCopyright (c) 2005-2025 Unity Technologies. All rights reserved.
ProductVersion (#2) 6000.0.59f2 (ef281c76c3c1)
Resource LangID English - United States

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2025-Oct-01 12:05:08
Version 0.0
SizeofData 146
AddressOfRawData 0x16d58
PointerToRawData 0x15f58
Referenced File C:\build\output\unity\unity\artifacts\WindowsPlayer\Win_x64_VS2022_VB_nondev_m_r\WindowsPlayer_player_Master_mono_x64.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2025-Oct-01 12:05:08
Version 0.0
SizeofData 20
AddressOfRawData 0x16dec
PointerToRawData 0x15fec

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2025-Oct-01 12:05:08
Version 0.0
SizeofData 852
AddressOfRawData 0x16e00
PointerToRawData 0x16000

TLS Callbacks

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x140019040

RICH Header

XOR Key 0x7139305b
Unmarked objects 0
ASM objects (28900) 5
C++ objects (28900) 138
C objects (28900) 10
Unmarked objects (#2) 1
Imports (28900) 2
C++ objects (33218) 40
C objects (33218) 16
ASM objects (33218) 17
Imports (33523) 3
Total imports 89
C++ objects (33523) 2
Exports (33523) 1
Resource objects (33523) 1
Linker (33523) 1

Errors

Leave a comment

No comments yet.