8d3c2905712d46526c6d8fa18bf3bb7976de61b7b4868364357c9ea9ad65b3de

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2025-Apr-10 04:28:31
Detected languages English - United States
Debug artifacts C:\build\output\unity\unity\artifacts\WindowsPlayer\Win_x64_VS2022_VB_nondev_m_r\WindowsPlayer_player_Master_mono_x64.pdb
FileVersion 6000.0.47.2806253
LegalCopyright (c) 2005-2025 Unity Technologies. All rights reserved.
ProductVersion 6000.0.47f1 (2ad1ed33fd3b)

Plugin Output

Info The PE contains common functions which appear in legitimate applications. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryExW
Suspicious The PE is possibly a dropper. Resources amount for 83.9824% of the executable.
Safe VirusTotal score: 0/72 (Scanned on 2026-04-08 14:23:29) All the AVs think this file is safe.

Hashes

MD5 27863c638d97a707a5f416fc8e7f277c
SHA1 3f33ded523d8b67e7434e67cd5baad4ac0243d37
SHA256 8d3c2905712d46526c6d8fa18bf3bb7976de61b7b4868364357c9ea9ad65b3de
SHA3 e0f881d86fd5fd865d321e45a92866032f0cc13a12a180cf8064d6907e4a6937
SSDeep 6144:i2E4CD20ZB4Gr34QwHalSh7aw8S9/tvavDXEGZBvb6LbvN8asXxng58OFz+1Idz:i2NCD1Jr3deXh7zje7f5bavNXYgY1
Imports Hash ce1183cc150987a99aef5749f22af81e

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x110

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 7
TimeDateStamp 2025-Apr-10 04:28:31
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0xde00
SizeOfInitializedData 0x97200
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000001260 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0xa9000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 a5e0bf1e14a18380e4aa8fcfecd45cfd
SHA1 320e758c261b51cdf475ac1fe2d2b8b0f65ee37a
SHA256 9f9a743b5e5c12b459f7533a90382644af884df3aef68c9d7ac7d662735f193e
SHA3 0371197b472ffeeb91e1e7c7a9605222c7eee7431b878edcb558990adc374905
VirtualSize 0xdc70
VirtualAddress 0x1000
SizeOfRawData 0xde00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.46141

.rdata

MD5 03e4a6a19eac67fa914d5dfbeebdeb2f
SHA1 38bca321737b128a9e63768646eaf204e6b3143b
SHA256 21f48d91c52193b01c25aa6e6cfaed2a6c082bc40293fe9206d83dc1060dec36
SHA3 6b637ec8873940d199b3c208966db3f8a3f613b4026c6dc387cf2e05ac048420
VirtualSize 0x977a
VirtualAddress 0xf000
SizeOfRawData 0x9800
PointerToRawData 0xe200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.70111

.data

MD5 d284f7b260ed119794375a6998c5083c
SHA1 0944c690e2b7841e681f55d2a731910f8019f2ef
SHA256 79ebad17e73900bd4dd43a932cc832e1d907346973e16ac0af549524fa4b88b3
SHA3 0c023444d7239a9582798618879cf6e165fcae6d6eec1051c77592814b4894ad
VirtualSize 0x1d78
VirtualAddress 0x19000
SizeOfRawData 0xc00
PointerToRawData 0x17a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 1.89847

.pdata

MD5 583bf012d5970545541b47ad6f1b2dc4
SHA1 ed34342900f8481a1f09e9f73fe8bb0d1e528eb6
SHA256 a7a9a284c12beceaf69e80c98bb9708078c1ee29e3581bf7c44e24e7535c04eb
SHA3 e57cf3023698fe8882221ba469ca26d236b8a3d44b7d67f42d621316177425fe
VirtualSize 0xf24
VirtualAddress 0x1b000
SizeOfRawData 0x1000
PointerToRawData 0x18600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.67239

_RDATA

MD5 dd297010ea596c9b749ddc72fe421330
SHA1 3213e7a4b99366f1367f1b5dc97aa4853369a784
SHA256 420a70f17663b392f63eb448853ebc800a3f7cf9c6e0b78b7e421d671dd927fd
SHA3 f4660bd566f5561530bb0e40a752616d5a8180b7180fcf869790d48f9fb6e9bf
VirtualSize 0x1f4
VirtualAddress 0x1c000
SizeOfRawData 0x200
PointerToRawData 0x19600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 3.71477

.rsrc

MD5 4fc6b2fc7d41f1958c1fad31a408ff60
SHA1 6b538e8b51af92382f48559e2a8919663ed5a851
SHA256 947994dd61dfee594bc8ee1959435fc8ba1152d055766b0e1a33f12e0e6d2dfd
SHA3 4c8f1c02257696d1ab635ccc1a495b421ec62c22915f2a607266c2ce803a4583
VirtualSize 0x8a018
VirtualAddress 0x1d000
SizeOfRawData 0x8a200
PointerToRawData 0x19800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.15906

.reloc

MD5 79918e2814a23b917e4a5494067a35d5
SHA1 eab8dd05e160cbff9fa1c348b6c35e7f161cf459
SHA256 cccb376562c958fee6ec06051a48d2c5c0232065e1000ce2d4b0775e46737238
SHA3 0fcd95a99b9b4e77c2e23089f450965a4028a243ef56d1928fdcfcebcc4b7120
VirtualSize 0x658
VirtualAddress 0xa8000
SizeOfRawData 0x800
PointerToRawData 0xa3a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 4.87002

Imports

UnityPlayer.dll UnityMain
KERNEL32.dll HeapAlloc
WriteConsoleW
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
IsDebuggerPresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetStartupInfoW
IsProcessorFeaturePresent
GetModuleHandleW
CloseHandle
RtlUnwindEx
GetLastError
SetLastError
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
GetProcAddress
LoadLibraryExW
EncodePointer
RaiseException
RtlPcToFileHeader
GetStdHandle
WriteFile
GetModuleFileNameW
GetCurrentProcess
ExitProcess
TerminateProcess
GetModuleHandleExW
HeapFree
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
GetCommandLineA
GetCommandLineW
MultiByteToWideChar
WideCharToMultiByte
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetStdHandle
GetFileType
GetStringTypeW
FlsAlloc
FlsGetValue
FlsSetValue
FlsFree
LCMapStringW
GetProcessHeap
HeapSize
HeapReAlloc
FlushFileBuffers
GetConsoleOutputCP
GetConsoleMode
SetFilePointerEx
CreateFileW

Delayed Imports

AmdPowerXpressRequestHighPerformance

Ordinal 1
Address 0x19004

D3D12SDKPath

Ordinal 2
Address 0x19008

D3D12SDKVersion

Ordinal 3
Address 0xf320

NvOptimusEnablement

Ordinal 4
Address 0x19000

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.48425
MD5 118d7349fddef48897dd97819864ea50
SHA1 191d18016ff2d4b180a278e1356eff61ce3772cb
SHA256 51e611bb08fed62d1e8de7dd2171671a08365bacf933c9e1edcde0e36ba7cd28
SHA3 168f5ee5fb1d510a1a4e13ecd869e83637e0f5e0f12bc7544b14f66b460f8fba

2

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x988
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.39864
MD5 c062d33e0bd3c67e94c498e77921f5f1
SHA1 1a036fe01d0ed781a3891130210a5657b9bd7411
SHA256 8dd805fb51fe100d54906342567cfca41314aeb362714bdf8f42929ff43dd8a0
SHA3 1716d95296406ef1377b7564d4762da9d5848c8956759518bd05e1de4d6a67f0

3

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.19443
MD5 7a0329d70d2b9ca3cdd5ff6f685d5a1c
SHA1 d6892dca9c130b6accae31ee23cdba643f977f64
SHA256 de832e47de35eb1f1580ab0b10f19cd351530242783e62281a45edf3a7ca93b9
SHA3 c2a7a50d2983f9bb53be139bb8f2710ec908b039fa4e0e3e638283864e5e25b8

4

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.84048
MD5 35628be976101059b7e72bef6654dba8
SHA1 2e6c7d88c520c4ec4bbb4eed8c38a1e0fe7df30d
SHA256 37dca87305669d361c248888983f1134276ae35ab2ca5eb0b90b36638881b2d4
SHA3 c01ed542d10d0bad74bb47b2af6fbd03cb22643d14ad305d2f40ec066109674c

5

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x4228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.70917
MD5 c60ebcc4894b58c6e48c0c85a68bb849
SHA1 11104b852dd6c0d421401c22db1c857fc6bcac06
SHA256 754f64ba82e393662720f0971a2b3b9cad9054de44e2fcba5b7ad8bb034d72f2
SHA3 1e3cacd1dc7820097ff9d34236f32dc99cd176a9cd6d0596de21f94536f102ca

6

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x94a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.49693
MD5 a7d543155f011cd84e73e91ee732290e
SHA1 3884f78de32d2d4cf2f5f9133a31c2a1c74053f9
SHA256 fd69e66ef925e4aa82de47a4270e743a89d9112d91a667fd5029b330b59c25a2
SHA3 edea32b7269efc7eefbaab6cef07c5f0a786f80bd411cfa73dcb3b5e60587a70

7

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10828
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.29276
MD5 94be7ff3968e8311264acec4ccb5348f
SHA1 a1b38e2842d15a5e87a733b4eef7263620ca7915
SHA256 de7c587db29432c74c49ff5d12f8edbe3d7efe3b495bd6108209024bd9bdebbb
SHA3 d4ca4e768e7d96c6d5fbf2f031119d83576d6af5d86d71b32b3d8df2d81b74d4

8

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.07267
MD5 7bf63a90ea1c83c6d8237d2495df3dfd
SHA1 3027bb2e66181c7ba79cf31cd48505a55d510e38
SHA256 db80ba92085abae3e1e503a0672838b3d3ec7f8d3617d8291c09f986ad8a9117
SHA3 0351b38635d3462a76dd8363f20017fa3db0454aec18d0e072d7def135dd4043

9

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x42028
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.96645
MD5 6eebfbf55b7d3a48eb4652fa709a055a
SHA1 e217399c3819d1135b1fdbfb91c2a9cd3b49c1d6
SHA256 662bb2acefb558f63c6f2502dd6d78aa20a8c577168e4be450bd421e742ab19f
SHA3 18caf2aec350b9f4ca972c2c2097b3a9ec999f147a5e72ea2310e186c78fa015

103

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x84
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.04448
Detected Filetype Icon file
MD5 3bf2dac037ce87794e66ff7f054e913f
SHA1 52ca961fd37ad960905a681d1db5157508ef1602
SHA256 2a87b1f32c5d0435090c72c392b75394f706e5750eff64fd85d25e1c622ee581
SHA3 8454d3273522657b5926068082b2cb88f6dbf352e7e9568008c0e33c792f349b

1 (#2)

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x210
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.52115
MD5 f695bab939bc5c4e027dcef3604715b7
SHA1 bb7fff9d840fdd7cb835604bbcf15ee280b3f6b9
SHA256 5228bfe457931a9df541f9c6767d2d8eec05f88bdf2f74ebc0fcc18d6c0b8c4f
SHA3 1feddb888019ea900c7b553934349371d6890fd1a5c54b789910f2c20305b5c3

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x545
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.24993
MD5 9df530c2f4fbe460da74e130d5d351a9
SHA1 f8719b6c74e0179556c1a18f214d6c1bbff8f823
SHA256 3c357bd1125971bda05bc59eaeca279da41715741e2535e9e75c94273b1c3a1f
SHA3 ce3dd46f87bd462f8730fca18daea6df444422f8d88b810aefbd7b2e62536dee

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 6000.0.47.53741
ProductVersion 6000.0.47.53741
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_UNKNOWN
Language English - United States
FileVersion (#2) 6000.0.47.2806253
LegalCopyright (c) 2005-2025 Unity Technologies. All rights reserved.
ProductVersion (#2) 6000.0.47f1 (2ad1ed33fd3b)
Resource LangID English - United States

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2025-Apr-10 04:28:31
Version 0.0
SizeofData 146
AddressOfRawData 0x16d58
PointerToRawData 0x15f58
Referenced File C:\build\output\unity\unity\artifacts\WindowsPlayer\Win_x64_VS2022_VB_nondev_m_r\WindowsPlayer_player_Master_mono_x64.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2025-Apr-10 04:28:31
Version 0.0
SizeofData 20
AddressOfRawData 0x16dec
PointerToRawData 0x15fec

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2025-Apr-10 04:28:31
Version 0.0
SizeofData 852
AddressOfRawData 0x16e00
PointerToRawData 0x16000

TLS Callbacks

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x140019040

RICH Header

XOR Key 0x7139305b
Unmarked objects 0
ASM objects (28900) 5
C++ objects (28900) 138
C objects (28900) 10
Unmarked objects (#2) 1
Imports (28900) 2
C++ objects (33218) 40
C objects (33218) 16
ASM objects (33218) 17
Imports (33523) 3
Total imports 89
C++ objects (33523) 2
Exports (33523) 1
Resource objects (33523) 1
Linker (33523) 1

Errors

Leave a comment

No comments yet.