| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2017-Aug-16 17:45:37 |
| Detected languages |
English - United States
|
| Debug artifacts |
C:\buildslave\unity\build\build\WindowsStandaloneSupport\Variations\win32_nondevelopment_mono\player_win_x86.pdb
|
| FileVersion | 5.6.3.10261224 |
| ProductVersion | 5.6.3.10261224 |
| Unity Version | 5.6.3p1_9c92e827232b |
| Info | Matching compiler(s): |
Microsoft Visual C++ v6.0 DLL
Microsoft Visual C++ 6.0 - 8.0 Microsoft Visual C++ Microsoft Visual C++ v6.0 |
| Suspicious | PEiD Signature: | Crunch 4 |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains references to system / monitoring tools:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to MD5 Uses constants related to SHA1 Uses constants related to SHA256 Uses constants related to SHA512 Uses constants related to AES Uses constants related to Blowfish Uses known Mersenne Twister constants Microsoft's Cryptography API |
| Suspicious | The PE is possibly packed. |
Unusual section name found: .trace
Unusual section name found: .data1 |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Safe | VirusTotal score: 0/44 (Scanned on 2025-03-15 13:00:13) | All the AVs think this file is safe. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x118 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 9 |
| TimeDateStamp | 2017-Aug-16 17:45:37 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 10.0 |
| SizeOfCode | 0xe3ca00 |
| SizeOfInitializedData | 0x3e2a00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0088B527 (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0xe3e000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 5.1 |
| ImageVersion | 0.0 |
| SubsystemVersion | 5.1 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x1225000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| HID.DLL |
HidP_GetCaps
HidD_GetPreparsedData HidD_GetProductString HidD_GetManufacturerString HidD_GetSerialNumberString HidD_GetIndexedString HidP_GetButtonCaps HidP_MaxDataListLength HidD_FreePreparsedData HidP_GetData HidP_GetValueCaps HidD_GetHidGuid |
|---|---|
| KERNEL32.dll |
InterlockedIncrement
InterlockedDecrement GetFullPathNameW GetCurrentProcessId GetCurrentProcess GetCurrentThread GetWindowsDirectoryW FormatMessageA SystemTimeToFileTime GetLocalTime GetTimeZoneInformation LocalFree GetSystemInfo GetModuleFileNameW InitializeCriticalSection ResetEvent GetTickCount ReadFile SetFilePointerEx WriteFile SetEndOfFile GetFileAttributesExW CreateFileW SetFileAttributesW GetFileAttributesW MoveFileExW FindClose FindNextFileW FindFirstFileW FindFirstFileExW SetFilePointer ReplaceFileW GetTempFileNameW LoadLibraryExW CreateEventW GlobalUnlock GlobalLock GlobalAlloc RemoveDirectoryW SetFileTime GetSystemTime GetDiskFreeSpaceExA lstrcpynA lstrcpyA lstrcpynW GetCommandLineW ExpandEnvironmentStringsW ResumeThread GetThreadContext SuspendThread OutputDebugStringA GetEnvironmentVariableA GetFileAttributesA GetModuleFileNameA GetVersionExA GetCurrentDirectoryA VerifyVersionInfoW VerSetConditionMask GetVersionExW GetSystemPowerStatus GlobalMemoryStatusEx GetUserDefaultUILanguage GetComputerNameW GetTempPathW LocalAlloc SetUnhandledExceptionFilter OpenEventW DebugBreak GetCurrentDirectoryW GetOverlappedResult CancelIo GetFileSize FileTimeToDosDateTime FileTimeToLocalFileTime lstrlenA GetFileTime VirtualQuery GlobalMemoryStatus RaiseException DecodePointer EncodePointer HeapAlloc HeapFree RtlUnwind HeapReAlloc HeapQueryInformation GetModuleHandleA GetCurrentThreadId ExitProcess SetConsoleCtrlHandler ExitThread GetCommandLineA HeapSetInformation GetStartupInfoW FileTimeToSystemTime GetDriveTypeA FindFirstFileExA IsProcessorFeaturePresent GetStdHandle GetLocaleInfoW UnhandledExceptionFilter TerminateProcess HeapCreate SetHandleCount GetFileType GetConsoleCP GetConsoleMode GetCPInfo GetACP GetOEMCP IsValidCodePage FlushFileBuffers SetStdHandle InterlockedExchange GetStringTypeW LCMapStringW FreeEnvironmentStringsW GetEnvironmentStringsW GetFullPathNameA GetFileInformationByHandle PeekNamedPipe CreateFileA WriteConsoleW GetUserDefaultLCID GetLocaleInfoA EnumSystemLocalesA IsValidLocale CompareStringW SetEnvironmentVariableA GetDriveTypeW GetProcessHeap GetProcessAffinityMask InterlockedExchangeAdd VirtualProtect VirtualAlloc VirtualFree FlushConsoleInputBuffer SwitchToThread SetThreadAffinityMask InitializeSListHead InterlockedPushEntrySList InterlockedPopEntrySList InterlockedFlushSList OpenEventA SetWaitableTimer CreateWaitableTimerA GetSystemDirectoryA SetConsoleMode ReadConsoleInputA GetDateFormatA GetTimeFormatA CreateMutexW FlushInstructionCache CreateSemaphoreW SignalObjectAndWait VerifyVersionInfoA ExpandEnvironmentStringsA GetVersion SleepEx GetQueuedCompletionStatus CreateIoCompletionPort SetHandleInformation FormatMessageW GetSystemTimeAsFileTime HeapSize InitializeCriticalSectionAndSpinCount CreateFileMappingA MapViewOfFile UnmapViewOfFile SetThreadPriority CreateThread TryEnterCriticalSection LeaveCriticalSection EnterCriticalSection DeleteCriticalSection DuplicateHandle CreateMutexA ReleaseMutex InterlockedCompareExchange GetModuleHandleW SetDllDirectoryW CreateDirectoryW WaitForSingleObject WideCharToMultiByte LoadLibraryA SetEvent IsDebuggerPresent ReleaseSemaphore WaitForSingleObjectEx CreateSemaphoreA TlsSetValue TlsGetValue TlsFree TlsAlloc DeleteFileW CopyFileW GetStartupInfoA LoadLibraryW GetProcAddress FreeLibrary CreateEventA CloseHandle Sleep SetLastError GetLastError MultiByteToWideChar QueryPerformanceFrequency QueryPerformanceCounter SetErrorMode |
| USER32.dll |
SystemParametersInfoW
GetAsyncKeyState ClientToScreen RegisterRawInputDevices GetMessageTime MapVirtualKeyExA GetMessagePos GetRawInputData GetKeyNameTextW LoadKeyboardLayoutA GetRawInputDeviceInfoW GetRawInputDeviceList wvsprintfA GetWindowLongW SetWindowLongW PostQuitMessage GetMonitorInfoA SetFocus GetFocus ShowCursor SetWindowTextW GetDlgItem IsDlgButtonChecked CopyImage SetWindowLongA KillTimer GetMessageA PeekMessageA SetWindowPos SetCursorPos RegisterDeviceNotificationW GetMessageExtraInfo PtInRect MessageBoxA DispatchMessageA UnregisterDeviceNotification ReleaseCapture DestroyIcon DestroyCursor ChangeDisplaySettingsA SetCursor GetSystemMetrics GetDC ReleaseDC CreateIconIndirect IsClipboardFormatAvailable GetClipboardData OpenClipboard EmptyClipboard CloseClipboard SetClipboardData GetCursorPos WindowFromPoint IsWindowVisible GetCaretBlinkTime MessageBoxW UpdateWindow GetKeyState LoadImageW DialogBoxParamA EndDialog SetForegroundWindow ScreenToClient CheckDlgButton GetAncestor CreateDialogParamW PeekMessageW IsDialogMessageW DispatchMessageW MsgWaitForMultipleObjects SetCapture RegisterClassExW DialogBoxParamW LoadIconA SendDlgItemMessageW SetDlgItemTextA SetDlgItemTextW CopyRect OffsetRect GetDesktopWindow AdjustWindowRectEx GetWindowPlacement ClipCursor MonitorFromWindow GetWindowRect TranslateMessage GetProcessWindowStation GetUserObjectInformationW SendMessageA UnregisterClassW DestroyWindow DefWindowProcW RegisterClassW CreateWindowExW EnumDisplayMonitors EnumDisplaySettingsA EnumDisplayDevicesA GetClientRect EnableWindow SetTimer ShowWindow GetParent ValidateRect CreateDialogParamA GetWindowLongA GetThreadDesktop GetUserObjectInformationA EnumWindows RegisterWindowMessageA SendMessageTimeoutA IsIconic LoadCursorA wsprintfA |
| VERSION.dll |
GetFileVersionInfoSizeA
GetFileVersionInfoA GetFileVersionInfoSizeW GetFileVersionInfoW VerQueryValueA |
| ole32.dll |
PropVariantClear
CoCreateGuid CoTaskMemAlloc CoTaskMemFree CoCreateInstance CoUninitialize CoSetProxyBlanket StringFromGUID2 CoInitialize |
| SHLWAPI.dll |
PathFileExistsW
SHDeleteKeyW PathCanonicalizeW |
| ADVAPI32.dll |
RegCloseKey
RegisterEventSourceA ReportEventA DeregisterEventSource CryptImportKey CryptVerifySignatureA CryptDestroyKey OpenProcessToken GetTokenInformation GetSidSubAuthority GetUserNameA RegOpenKeyExW RegCreateKeyW RegSetValueExA RegQueryValueExA RegDeleteValueA CryptGetHashParam CryptDestroyHash CryptHashData CryptReleaseContext CryptCreateHash CryptAcquireContextA RegQueryValueExW RegSetValueExW RegCreateKeyExW |
| GDI32.dll |
ChoosePixelFormat
SwapBuffers GetDeviceCaps SetPixelFormat GetObjectA DeleteObject CreateBitmap CreateDIBSection |
| SHELL32.dll |
SHFileOperationW
SHGetFolderPathW ShellExecuteW CommandLineToArgvW |
| OPENGL32.dll |
wglGetCurrentContext
wglCreateContext wglMakeCurrent wglDeleteContext wglGetProcAddress wglGetCurrentDC |
| WINMM.dll |
waveInGetNumDevs
timeGetTime timeEndPeriod waveOutGetNumDevs waveOutGetDevCapsA waveOutGetDevCapsW waveOutClose waveOutOpen waveOutUnprepareHeader waveOutWrite waveOutReset waveOutGetPosition waveInAddBuffer waveInPrepareHeader waveInUnprepareHeader waveInGetDevCapsA waveInGetDevCapsW waveInStart waveInOpen waveInClose waveInReset waveOutPrepareHeader timeBeginPeriod |
| WS2_32.dll |
WSAEnumNetworkEvents
WSAResetEvent WSAWaitForMultipleEvents WSACloseEvent WSAEventSelect WSACreateEvent WSASetEvent WSACancelAsyncRequest WSAAsyncGetHostByName WSACleanup ntohl htonl ntohs htons getpeername getprotobyname recv gethostbyname shutdown listen accept WSARecvFrom WSAIoctl getnameinfo getaddrinfo recvfrom sendto send gethostname socket connect bind inet_addr WSAStartup select __WSAFDIsSet inet_ntoa getsockname freeaddrinfo WSASocketA WSASetLastError WSAGetLastError setsockopt ioctlsocket getsockopt closesocket |
| OLEAUT32.dll |
VariantClear
SysAllocString SysFreeString VariantChangeType VariantInit |
| IMM32.dll |
ImmReleaseContext
ImmSetOpenStatus ImmGetConversionStatus ImmGetCompositionStringW ImmAssociateContextEx ImmAssociateContext ImmGetContext ImmSetCompositionStringW |
| DNSAPI.dll |
DnsQuery_A
DnsFree |
| IPHLPAPI.DLL |
GetIpAddrTable
|
| WINHTTP.dll |
WinHttpGetIEProxyConfigForCurrentUser
|
| MFPlat.DLL (delay-loaded) |
MFGetStrideForBitmapInfoHeader
MFStartup MFCreateAsyncResult MFCreateMediaType MFCreateSourceResolver MFCreateAttributes |
| Attributes | 0x1 |
|---|---|
| Name | MFPlat.DLL |
| ModuleHandle | 0x10b6fb0 |
| DelayImportAddressTable | 0x103a260 |
| DelayImportNameTable | 0xff645c |
| BoundDelayImportTable | 0xff6550 |
| UnloadDelayImportTable | 0 |
| TimeStamp | 1970-Jan-01 00:00:00 |
| Ordinal | 1 |
|---|---|
| Address | 0xffa538 |
| Ordinal | 2 |
|---|---|
| Address | 0xffa534 |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 5.6.3.37608 |
| ProductVersion | 5.6.3.37608 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
| FileType |
VFT_UNKNOWN
|
| Language | English - United States |
| FileVersion (#2) | 5.6.3.10261224 |
| ProductVersion (#2) | 5.6.3.10261224 |
| Unity Version | 5.6.3p1_9c92e827232b |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2017-Aug-16 17:45:37 |
| Version | 0.0 |
| SizeofData | 137 |
| AddressOfRawData | 0xfdac3c |
| PointerToRawData | 0xfd9a3c |
| Referenced File | C:\buildslave\unity\build\build\WindowsStandaloneSupport\Variations\win32_nondevelopment_mono\player_win_x86.pdb |
| XOR Key | 0x649597fd |
|---|---|
| Unmarked objects | 0 |
| Imports (VS2008 SP1 build 30729) | 34 |
| C++ objects (VS2008 SP1 build 30729) | 1 |
| C objects (VS2012 build 50727 / VS2005 build 50727) | 1 |
| C objects (VS2008 SP1 build 30729) | 36 |
| C++ objects (VS2010 build 30319) | 8 |
| Imports (VS2003 (.NET) build 4035) | 3 |
| Total imports | 534 |
| 152 (20115) | 6 |
| ASM objects (VS2010 SP1 build 40219) | 73 |
| Unmarked objects (#2) | 195 |
| C objects (VS2010 SP1 build 40219) | 1043 |
| C++ objects (VS2010 SP1 build 40219) | 1204 |
| Exports (VS2010 SP1 build 40219) | 1 |
| Resource objects (VS2010 SP1 build 40219) | 1 |
| Linker (VS2010 SP1 build 40219) | 1 |
No comments yet.