7e51b599512452729e084105765a2f6e6e16e1d6b35161501670e0ae4465c6cc

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2025-Sep-26 11:37:03
Detected languages English - United States
Debug artifacts C:\build\output\unity\unity\artifacts\WindowsPlayer\Win64_VS2019_nondev_m_r\WindowsPlayer_player_Master_mono_x64.pdb
FileVersion 2022.3.62.7762112
LegalCopyright (c) 2005-2025 Unity Technologies. All rights reserved.
ProductVersion 2022.3.62f2 (7670c08855a9)

Plugin Output

Info The PE contains common functions which appear in legitimate applications. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryExW
Suspicious The PE is possibly a dropper. Resources amount for 84.749% of the executable.
Safe VirusTotal score: 0/70 (Scanned on 2026-04-02 20:48:43) All the AVs think this file is safe.

Hashes

MD5 bdcdec8928b9de324ec95070c77f45b8
SHA1 2a2c4092449761e7cec469dece67e57c70f7789a
SHA256 7e51b599512452729e084105765a2f6e6e16e1d6b35161501670e0ae4465c6cc
SHA3 49010db0c2701c12f1ad2dc0e95a75cfb5e86fe0bdaa31da028793523a17295d
SSDeep 6144:R/7Fu9mpcJ/OD8hpkZYhBkYSMMMMMMMMMMMMMgdcE/:R/7g4aOD83SMMMMMMMMMMMMMoN
Imports Hash a136217cdd3247ff6a8766561064ca0b

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x110

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 7
TimeDateStamp 2025-Sep-26 11:37:03
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0xca00
SizeOfInitializedData 0x97000
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000001264 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0xa8000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 e1ace82cc0f3d159779f5c95aa7e575b
SHA1 e4a5358996f267c921e5d996de44f3525bb042ed
SHA256 bec109031034001337c9be3c07e16f6fab9c862313fc1f8fb0699672e09c63a4
SHA3 449bef44a9ee4a68767a70da31c7ceb6aa3d1da49237a84227bbfb02c7e428a2
VirtualSize 0xc8b0
VirtualAddress 0x1000
SizeOfRawData 0xca00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.41019

.rdata

MD5 3968e717f74350a1e572417731491393
SHA1 900495159060a8bdd1d091ffc28d69a62786a219
SHA256 b85ddb43cdfcf1d57aeef685f86b2443b5d2ee1e4e539cd1c9b99fd7c69f07c4
SHA3 626b582315f0c8dfccfed470c899340f9a4904c7a804563fe1b36454f6b4ec2b
VirtualSize 0x948c
VirtualAddress 0xe000
SizeOfRawData 0x9600
PointerToRawData 0xce00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.65435

.data

MD5 90815aa5dc65a7dd3f93bad1bd78a77e
SHA1 608f3e69047b216dda6b0df73c30912e2fef5544
SHA256 435cb9af1df25f501f68a9700182c4d25de99c3f8e8c1ba6b16c0ca98911ff87
SHA3 e5ea90d4dd767bfa3d88e3fa2e107c2e40cac10f43498d5abd74f15888477d18
VirtualSize 0x1d38
VirtualAddress 0x18000
SizeOfRawData 0xc00
PointerToRawData 0x16400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 1.87032

.pdata

MD5 6e619149c26d436c6f07193ff1e8032b
SHA1 70aea7c26eff6d7619bd6a5a97ab259d68dd24f5
SHA256 48cb5fb202e79c0b8da5091cb440a9068502b37c8e4200eb78df617ae99fd024
SHA3 196183a21caf69a7292ff77b288d707ce7d63e2b887053ae1bc258b99d1e36f0
VirtualSize 0xef4
VirtualAddress 0x1a000
SizeOfRawData 0x1000
PointerToRawData 0x17000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.62125

_RDATA

MD5 f87f407c2a1cab208757ad1d23a2de6f
SHA1 cd739c36958f9ba7505883ae868f1a6ca71e880f
SHA256 6e4ba525d12ef66132e0738191d3a928ba74c0091a6f82bc48f892a41e2fc242
SHA3 0611ad194d9c623281cb358dbc2f2d28bb01b6eab682677ec8d16136d74414ab
VirtualSize 0x94
VirtualAddress 0x1b000
SizeOfRawData 0x200
PointerToRawData 0x18000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 1.11888

.rsrc

MD5 5d2349297435a32d119a076138b82248
SHA1 d3d6d76f5cd700ab76db84d8dfd500f5af62ca0b
SHA256 a9ba4bcee93a58d43d1b144a621cc86b1e8c3d7a199ba14ccdaf3309c4ad6c51
SHA3 9dad2ccd1451a39feef39f8b94a07aed6caeeb69b0dfce0b61cd94dbd2a58afc
VirtualSize 0x8a198
VirtualAddress 0x1c000
SizeOfRawData 0x8a200
PointerToRawData 0x18200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 3.1769

.reloc

MD5 ef1e558d46106d87320dd822be1ddc48
SHA1 10f7b05d107451bd01cf446da512c619fc35bf50
SHA256 34d7b771018e478ba05cd24ec377fd34919d65ec63c43f49e1ab319785368929
SHA3 cc295f58e62efe5c59cad1febf1ce620404450135f442c20ba55235b492ddac9
VirtualSize 0x654
VirtualAddress 0xa7000
SizeOfRawData 0x800
PointerToRawData 0xa2400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 4.84209

Imports

UnityPlayer.dll UnityMain2
KERNEL32.dll HeapAlloc
WriteConsoleW
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
IsDebuggerPresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetStartupInfoW
IsProcessorFeaturePresent
GetModuleHandleW
CloseHandle
RtlUnwindEx
GetLastError
SetLastError
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
GetProcAddress
LoadLibraryExW
EncodePointer
RaiseException
RtlPcToFileHeader
GetStdHandle
WriteFile
GetModuleFileNameW
GetCurrentProcess
ExitProcess
TerminateProcess
GetModuleHandleExW
HeapFree
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
GetCommandLineA
GetCommandLineW
MultiByteToWideChar
WideCharToMultiByte
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetStdHandle
GetFileType
GetStringTypeW
FlsAlloc
FlsGetValue
FlsSetValue
FlsFree
LCMapStringW
GetProcessHeap
HeapSize
HeapReAlloc
FlushFileBuffers
GetConsoleOutputCP
GetConsoleMode
SetFilePointerEx
CreateFileW

Delayed Imports

AmdPowerXpressRequestHighPerformance

Ordinal 1
Address 0x18004

NvOptimusEnablement

Ordinal 2
Address 0x18000

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x42028
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.92459
MD5 4b00c89e947008a2ae1276c08d7bc470
SHA1 a099dec5c4972bfdd8e8bb0c659e899e357f66dd
SHA256 ef66e0cc9b4b41744aa583a2e0727f73c9d3c2940405611478f526d1bbb4b4db
SHA3 96c6e2941f72ce1beb8c3eefc1f28bfd1bc6e4881ca16f7a32569d2d6e1384c7

2

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.18049
MD5 d6e200593cb86c4e17f7c9d00ff5cecf
SHA1 197ea2c941558e32c0a447a9739002705671778b
SHA256 6a8c742d2b5f1a53e796b79171b849e1b4e37ea8f1df223f5e426e0ab4f65330
SHA3 70dc1113f8c8a6c263260e623e38b970bc64064082d2a43778983ad24e171690

3

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10828
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.24009
MD5 a83c50bd4aa0c2636edf24b4102e4432
SHA1 aabb827a1e9f01b3ebbbb6bf17aa9c8e78c3d5cb
SHA256 af91c2d23865c4a18819b0f54eb5aff492ede6c388f3263872b3facba1fd4389
SHA3 152065e21c2a61c50c9a4b8a4596c9b97064099ee3941961ed4916ff934beb41

4

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x94a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.29863
MD5 66b722b01e090db8ca313e1c4a27b7af
SHA1 47fff85e79f2c084788e62b2a563f344a6bd48cc
SHA256 c6cd15aabf7e3765885db2bf298c0c09bd6d5874f35957f391a74099b92ddace
SHA3 a5b4e5b15403991df7c710d710826243a681a24b4ec36fe2cf378a97d3bc368e

5

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x4228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.40182
MD5 4685fb93c4158c0ed54609aabf282d1d
SHA1 56c9a2be1a83a4480b5b290223cc0e777123948a
SHA256 9de6900d666f5e5d13f256a76f23f653bd8059daa9e5f3c5fbc8324596b13f2f
SHA3 48dd10b4535d3b2f95afebbed237a8119485ab248637af5f9cbb3bb41fb22351

6

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.49863
MD5 7df4bb3bdb1c105bfcd5670885d98eda
SHA1 176a2831325f26294d325362f9c41efa5ba7285c
SHA256 fb07776069796756a5924dcc72ce18243ed0f2e4ced91bdb1cd563c02e1b6bf0
SHA3 a6521c52a5a22a989928b4f2c5b2e3d1b23a9d5111267dc09ee8ee0c0cedff35

7

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.67915
MD5 0a8501e2c6931df6f392c7d4e42f26dc
SHA1 566e7c59aa2d0b1792902d3e3eeca4874a041ec4
SHA256 1a542e1c69d340e9dae78ac31b73dfe9b465bbe2966c77498616a40f931264b1
SHA3 62cc1bae6f9859f2cbc502e1d83b5289b28b1fe2f20270c16f1a4dd8035ab764

8

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x988
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.76407
MD5 f7861f1ca6466e1e100e805c26de1911
SHA1 1ad07abe007db2f076424ba825c3ad38d0e84495
SHA256 e8653a80499718cab67a7d09393bcadecd54c463ec59b3cfad3d3378d26a1c33
SHA3 a152e138534c4608333fb70f7bc47d12d2cbdbf3451c27cbf047c520a2f11b36

9

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.76415
MD5 5eae9c47eaa2403369e969fd3565c78b
SHA1 bd0691fda69d9f1afba9ae4effac943ca91a0683
SHA256 5bc5136e203e5994b468c5e9f939701e748a8ed43bd0c081480d64d5ec8a5147
SHA3 1ed6fe42eaff610dd6398c98501f6f1a68d4bca0c251a9c1780757fd50252add

103

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x84
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.04448
Detected Filetype Icon file
MD5 f7731730720cfe035cf030b40d0e2eb6
SHA1 d046e23f2ee2b93ad96be8e1dc9120ecf3915091
SHA256 5c92a41adaf3265071482fd1a182ae8702c168636a7d9ff51798ee3a1dfc8500
SHA3 6f2d12e4c63c131a3f7f48293996e2be05da351536d013affe5d2265965ce657

1 (#2)

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x210
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.55946
MD5 a817f5c1ee4993dc4fb84fbfc5cbd0bb
SHA1 ffb6bbc9ea4d9108b994b5b4d71fc558827c88a6
SHA256 4a7fde3055000864489cc4abddfe9a8c5dfbd3b0129f76c59e1b5068b2c8459d
SHA3 86d49d4ea4b0e3900b5aa666f910c3aff9973b8e17aa1aac4a9b04dc06fd3953

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x6c1
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.37708
MD5 aab7e8aafe7b06ab3d003b54ab5e18ed
SHA1 dccf0408f43059df37b755f3241a8b4b35c728af
SHA256 fb88b19523afd8fed48eddfd10805a3a0a45997bbf8fac04d595ddf93c1a88a8
SHA3 a981b8e907b79cd9448766ace938dfd96560d11c29e6ba165912a8508bd52ca7

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 2022.3.62.28864
ProductVersion 2022.3.62.28864
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_UNKNOWN
Language English - United States
FileVersion (#2) 2022.3.62.7762112
LegalCopyright (c) 2005-2025 Unity Technologies. All rights reserved.
ProductVersion (#2) 2022.3.62f2 (7670c08855a9)
Resource LangID English - United States

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2025-Sep-26 11:37:03
Version 0.0
SizeofData 141
AddressOfRawData 0x15aec
PointerToRawData 0x148ec
Referenced File C:\build\output\unity\unity\artifacts\WindowsPlayer\Win64_VS2019_nondev_m_r\WindowsPlayer_player_Master_mono_x64.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2025-Sep-26 11:37:03
Version 0.0
SizeofData 20
AddressOfRawData 0x15b7c
PointerToRawData 0x1497c

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2025-Sep-26 11:37:03
Version 0.0
SizeofData 768
AddressOfRawData 0x15b90
PointerToRawData 0x14990

TLS Callbacks

Load Configuration

Size 0x138
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x140018030

RICH Header

XOR Key 0xe5e06b0d
Unmarked objects 0
ASM objects (28900) 5
C++ objects (28900) 138
C objects (28900) 10
Imports (28900) 2
C++ objects (VS 2015/2017/2019 runtime 29118) 39
C objects (VS 2015/2017/2019 runtime 29118) 16
ASM objects (VS 2015/2017/2019 runtime 29118) 9
Imports (VS2019 Update 8 (16.8.0-1) compiler 29333) 3
Total imports 89
C++ objects (VS2019 Update 8 (16.8.0-1) compiler 29333) 3
Exports (VS2019 Update 8 (16.8.0-1) compiler 29333) 1
Resource objects (VS2019 Update 8 (16.8.0-1) compiler 29333) 1
Linker (VS2019 Update 8 (16.8.0-1) compiler 29333) 1

Errors

Leave a comment

No comments yet.