| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2025-Apr-08 18:45:09 |
| Detected languages |
English - United States
|
| TLS Callbacks | 2 callback(s) detected. |
| Debug artifacts |
C:\build\output\unity\unity\artifacts\UnityCrashHandler\Win_x64_VS2022_VB_nondev_i_m\UnityCrashHandler64.pdb
|
| Info | Interesting strings found in the binary: |
Contains domain names:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to MD5 Uses constants related to SHA1 Uses constants related to SHA256 |
| Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
| Info | The PE is digitally signed. |
Signer: Unity Technologies SF
Issuer: DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 |
| Safe | VirusTotal score: 0/72 (Scanned on 2026-02-20 12:04:13) | All the AVs think this file is safe. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x118 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 7 |
| TimeDateStamp | 2025-Apr-08 18:45:09 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x76a00 |
| SizeOfInitializedData | 0x100c00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x000000000004FFC8 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x17b000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0x17d21e |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| api-ms-win-core-synch-l1-2-0.dll |
WakeByAddressSingle
WaitOnAddress |
|---|---|
| USER32.dll |
SetWindowPos
SetForegroundWindow LookupIconIdFromDirectoryEx OffsetRect AdjustWindowRect GetWindowLongA DialogBoxParamA SetWindowTextW GetDlgItem EndDialog SendMessageW UnionRect SendDlgItemMessageA GetIconInfo LoadImageA CreateIconFromResourceEx InflateRect |
| KERNEL32.dll |
GetEnvironmentStringsW
GetCommandLineA GetOEMCP GetACP IsValidCodePage HeapQueryInformation HeapSize HeapReAlloc EnumSystemLocalesW GetUserDefaultLCID IsValidLocale GetLocaleInfoW LCMapStringW FlsFree FlsSetValue FlsGetValue FlsAlloc SetConsoleCtrlHandler GetFileType SetStdHandle GetConsoleMode GetConsoleOutputCP GetModuleHandleExW ExitProcess InitializeCriticalSectionAndSpinCount RaiseException RtlPcToFileHeader RtlUnwindEx GetCPInfo CompareStringEx DecodePointer EncodePointer InitializeCriticalSectionEx GetSystemTimeAsFileTime GetModuleFileNameA SetWaitableTimer SetLastError RtlCaptureContext GetCurrentProcess OutputDebugStringA RtlVirtualUnwind RtlLookupFunctionEntry GetEnvironmentVariableA SuspendThread GetCurrentDirectoryA ResumeThread MultiByteToWideChar GetLastError GetFileAttributesA GetCurrentThread LoadLibraryA WaitForSingleObjectEx CloseHandle LoadLibraryW GetThreadContext GetProcAddress ReadProcessMemory GetModuleHandleW FreeLibrary WideCharToMultiByte SleepEx CreateWaitableTimerExW OpenThread HeapFree Thread32Next Thread32First WaitForSingleObject CreateToolhelp32Snapshot FormatMessageW CreateThread HeapAlloc SwitchToThread LocalFree VerSetConditionMask GetCurrentProcessId GetProcessHeap VerifyVersionInfoW CreateEventW CreateDirectoryW ReadFile FindFirstFileW GetFileSizeEx FindFirstFileExW TlsSetValue GetFullPathNameW FindNextFileW WriteFile RemoveDirectoryW SetFileTime GetModuleFileNameW SetFilePointer SetEndOfFile FindClose CreateFileW GetFileAttributesW SetFileAttributesW GetFileAttributesExW GetDiskFreeSpaceExW DeleteFileW SetFilePointerEx MoveFileExW ReplaceFileW SystemTimeToFileTime CopyFileW TlsGetValue GetTempFileNameW GetSystemTime FlushFileBuffers GetStdHandle TerminateProcess GetProcessId GetTempPathW WaitForMultipleObjectsEx OpenProcess Sleep SetEvent GetThreadId GetFileSize CreateProcessW CopyFileExW AllocConsole GetExitCodeProcess SizeofResource EnterCriticalSection GetCommandLineW EnumResourceNamesA LeaveCriticalSection InitializeCriticalSection SetErrorMode FindResourceA GetModuleHandleA GetExitCodeThread TerminateThread LockResource LoadResource DeleteCriticalSection CreateEventA LoadLibraryExW TlsAlloc QueryPerformanceFrequency TlsFree QueryPerformanceCounter IsDebuggerPresent LCMapStringEx TryAcquireSRWLockExclusive GetStringTypeW InitializeSListHead IsProcessorFeaturePresent GetStartupInfoW SetUnhandledExceptionFilter UnhandledExceptionFilter SleepConditionVariableSRW WakeAllConditionVariable AcquireSRWLockExclusive ReleaseSRWLockExclusive FreeEnvironmentStringsW WriteConsoleW GetCurrentThreadId |
| dbghelp.dll |
SymLoadModuleEx
SymRegisterFunctionEntryCallback64 |
| SHELL32.dll |
CommandLineToArgvW
SHFileOperationW SHCreateDirectoryExW SHGetKnownFolderPath |
| ole32.dll |
CoInitializeEx
CoCreateGuid CoTaskMemFree |
| SHLWAPI.dll |
PathCanonicalizeW
|
| PSAPI.DLL |
GetModuleFileNameExW
|
| ADVAPI32.dll |
GetUserNameA
|
| WININET.dll |
HttpSendRequestA
InternetCloseHandle InternetOpenA InternetCrackUrlA HttpOpenRequestA HttpQueryInfoA InternetConnectA |
| GDI32.dll |
GetObjectA
|
| VERSION.dll |
GetFileVersionInfoSizeA
VerQueryValueA GetFileVersionInfoA |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Apr-08 18:45:09 |
| Version | 0.0 |
| SizeofData | 133 |
| AddressOfRawData | 0x8bd64 |
| PointerToRawData | 0x8ab64 |
| Referenced File | C:\build\output\unity\unity\artifacts\UnityCrashHandler\Win_x64_VS2022_VB_nondev_i_m\UnityCrashHandler64.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Apr-08 18:45:09 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0x8bdec |
| PointerToRawData | 0x8abec |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Apr-08 18:45:09 |
| Version | 0.0 |
| SizeofData | 1128 |
| AddressOfRawData | 0x8be00 |
| PointerToRawData | 0x8ac00 |
| StartAddressOfRawData | 0x14008c2b0 |
|---|---|
| EndAddressOfRawData | 0x14008c3f0 |
| AddressOfIndex | 0x1400979f8 |
| AddressOfCallbacks | 0x140078800 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_16BYTES
|
| Callbacks |
0x000000014004FBC8
0x000000014004FC30 |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x140096040 |
| XOR Key | 0x31ad84dd |
|---|---|
| Unmarked objects | 0 |
| ASM objects (28900) | 8 |
| C++ objects (28900) | 188 |
| C objects (28900) | 24 |
| Unmarked objects (#2) | 1 |
| 253 (33218) | 1 |
| C++ objects (33218) | 87 |
| C objects (33218) | 19 |
| ASM objects (33218) | 18 |
| C objects (CVTCIL) (28900) | 1 |
| Imports (VS2008 SP1 build 30729) | 2 |
| Imports (28900) | 29 |
| Total imports | 294 |
| C++ objects (LTCG) (33523) | 64 |
| Resource objects (33523) | 1 |
| Linker (33523) | 1 |