b268139295f6563688d36074d9b4c09cf757ef267b24d707efe7bc53406651a7

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2021-Sep-16 18:58:59
Detected languages English - United States
Debug artifacts C:\buildslave\unity\build\artifacts\WindowsPlayer\Win64_VS2019_nondev_i_r\WindowsPlayer_Master_il2cpp_x64.pdb
FileVersion 2020.3.19.6877495
ProductVersion 2020.3.19.6877495
Unity Version 2020.3.19f1_68f137dc9bbe

Plugin Output

Info The PE contains common functions which appear in legitimate applications. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryExW
Suspicious The PE is possibly a dropper. Resources amount for 86.3959% of the executable.
Safe VirusTotal score: 0/72 (Scanned on 2025-11-13 12:03:24) All the AVs think this file is safe.

Hashes

MD5 df565835fc8ccc337761db7514c15edc
SHA1 62097cb9b3abd23d04088f5e07a8f85874c7a498
SHA256 b268139295f6563688d36074d9b4c09cf757ef267b24d707efe7bc53406651a7
SHA3 9f0b8ea9c7aca4657f2ed344cafb0f756e5ca400e41afa3f6994e22ca6f493ab
SSDeep 6144:WpC62lkCTiCpYWgSUo0QQAR5B2H5UxF0GqmM3NqMDgO9BtSQG3a6Vu:W4eCOCpY9SR1aHmxyzqMUOfsQGtVu
Imports Hash 5f74a5c747508e2822fdb9b687deaf42

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x108

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 7
TimeDateStamp 2021-Sep-16 18:58:59
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0xa200
SizeOfInitializedData 0x96600
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000001260 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0xa5000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 dc34d9506ae9e3616b5265da7e35b1f6
SHA1 dce8f4d17ddc08b8460b046a362a27430cbe2e75
SHA256 e80b2c4dfacb7fab649683f679231937cf85d5498d6d4b5d3a3e61149f064124
SHA3 08b3146b697934b2f68c0ed66868b3c96973ed20c4a70245a96b304f456d0106
VirtualSize 0xa120
VirtualAddress 0x1000
SizeOfRawData 0xa200
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.39574

.rdata

MD5 53aab4e287f86d8261f17bbba629f06e
SHA1 7332d588248e81a59f8e9f19b236c17d01516543
SHA256 6eb34c6b1cf199d57e1a86e22210d9fe9613a5c66bca4c6fb54768851e8e3328
SHA3 a01d0b15450e2c62afadd2f5fd302c3b53a0fcdcb081e0d22f8766aa8a007014
VirtualSize 0x8c6e
VirtualAddress 0xc000
SizeOfRawData 0x8e00
PointerToRawData 0xa600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.65198

.data

MD5 a9e79420695e9bc679ca784c3876e94f
SHA1 85d68049c56be1369a584c2cef1f26bece917c8f
SHA256 a64f2a1dd771a4ddc2a8b9ebecec8d75683a19da0fcb7c92b1ca380ca540a055
SHA3 902fec18ac997b92fb99b25384f1c089fc9ae1ab1d849e846fff2b3a4d2bd9fa
VirtualSize 0x1cd8
VirtualAddress 0x15000
SizeOfRawData 0xc00
PointerToRawData 0x13400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 1.67624

.pdata

MD5 789f36f907239c1ceca2f8ec3f79fcb5
SHA1 11b2d5522be4b2558a7e492c53b4d86184702c90
SHA256 5e2c8dede33e201308d3fabb30b57b487ba34d524537e56449f854c9d6e560e4
SHA3 0b06f78c7fe1c1611e2e7abfd4a78a87cf82474f2ac5b4a8daa9c07fbbf85778
VirtualSize 0xc48
VirtualAddress 0x17000
SizeOfRawData 0xe00
PointerToRawData 0x14000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.36097

_RDATA

MD5 1960efd573f3d23522c840210d59fb7e
SHA1 47057bb39ae6c80b68d90c47f0cfd7d6bf123ad2
SHA256 ad5bd98e9035110e2e2e7b82ed2fe49ec0fae2d89e05400528a6b48804c441a4
SHA3 225389cba41c0a9e2c3319b0921ec1ef9962e8af175fca30c67bde60763834d4
VirtualSize 0x94
VirtualAddress 0x18000
SizeOfRawData 0x200
PointerToRawData 0x14e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 1.08512

.rsrc

MD5 7359d44914ed464ae29e78cd7795bde4
SHA1 250fe099c6d5466ba03e9d12ccba5ec9bcf0ba4d
SHA256 f570169d70b008d7648945d76fa51800f030e88a1aa8e88776b8b8ece07d9694
SHA3 f83be8e6170190da5b06a856a8f394f501b6adf81d1805abadb8b2f144a49572
VirtualSize 0x8a148
VirtualAddress 0x19000
SizeOfRawData 0x8a200
PointerToRawData 0x15000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.88398

.reloc

MD5 a9c3cf69888151777a2a472fa85313df
SHA1 a5410c074ce059a802887d8ef48a198d601aa9e3
SHA256 02d5b365a568a1cfd46be8549a8fee9793a57a8d69c3544d8232330a87a3d7ad
SHA3 874351b3eea840f9c0337e4533e9a1b535fab5c0ccdeba911f149a1902c60a44
VirtualSize 0x634
VirtualAddress 0xa4000
SizeOfRawData 0x800
PointerToRawData 0x9f200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 4.78467

Imports

UnityPlayer.dll UnityMain
KERNEL32.dll WriteConsoleW
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
IsDebuggerPresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetStartupInfoW
IsProcessorFeaturePresent
GetModuleHandleW
CloseHandle
RtlUnwindEx
GetLastError
SetLastError
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
GetProcAddress
LoadLibraryExW
RaiseException
GetStdHandle
WriteFile
GetModuleFileNameW
GetCurrentProcess
ExitProcess
TerminateProcess
GetModuleHandleExW
HeapAlloc
HeapFree
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
GetCommandLineA
GetCommandLineW
MultiByteToWideChar
WideCharToMultiByte
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetStdHandle
GetFileType
GetStringTypeW
LCMapStringW
GetProcessHeap
HeapSize
HeapReAlloc
FlushFileBuffers
GetConsoleCP
GetConsoleMode
SetFilePointerEx
CreateFileW

Delayed Imports

AmdPowerXpressRequestHighPerformance

Ordinal 1
Address 0x15004

NvOptimusEnablement

Ordinal 2
Address 0x15000

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x42028
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.79987
MD5 2b66a5f8c367eb0f27209bb335992988
SHA1 670740b1abbb330b42266bc0919a81d043f15ac1
SHA256 e1e66c9822d9b6dd06a52cb92dd7ed84ddbdaa44a3fc6990b69b79568b34be13
SHA3 d1daba757eaa8d6e41bd5897e7bd3fbba1e18e3abdead987869d214a42c89814

2

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.84891
MD5 12d104da5ebb4f407e5d7a6395fa5c79
SHA1 37c3c1d339f1d5cdbd9355bb30cd60986a267105
SHA256 feb75db1f1f31f77df3ca5810d1e26a0e973f8b14b67b95fb048e10a58d502b7
SHA3 7ac9d517189b0e3344b869a6ced7aed58eebbed6474154d342b8a52217c4f504

3

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10828
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.87781
MD5 f84ad0486ea3f6fea03d058b1ed3ee26
SHA1 b9aa0584feeeab1b5470eca850acb1639cc07d7f
SHA256 f26c8f6b6c47495e1948225f55c3440f5d97587b111674cf46308e089ee9fd71
SHA3 787d06844679cfa95d8bfacbc126d206370edc3f0a91aee379b55a4b66fb2767

4

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x94a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.92123
MD5 f5cbc5087b65ad3280f43d2332723405
SHA1 b619f6dc8f6b8e7eb1952a7cce055935e68d5892
SHA256 274d87d0cc6ae024c7bfc443aa0628757c9441ae4153a375344da9ad0058be77
SHA3 eff0ae319aed52b21352b9cd13ccdaa65234ad4b6e7e9f7fd47953ecfa23fcac

5

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x4228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.12314
MD5 8d8c38820bee127776e1cb761239e2c8
SHA1 dbeae165872da2bb65c5f72b96b2b946552ae979
SHA256 773c0f470c22d628b2d49bec8bd7b913441dd866cfe456720e76c526f42b6b71
SHA3 692e9edd79c1f8fc89ffa01cabc5cb04fc5a05c1ea47a9336a153f8f31c74ef4

6

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.20031
MD5 abd8e0de7ac4ca0179a7365e2fb1e700
SHA1 ad28c51f92645f56ff54f8d02b28cec10282f238
SHA256 556f1bd92005e117d52f041a393cbcd840b7d1d7c91e70914d4b93983063eb7b
SHA3 27cb649439218ee4a8cb529dbe2c5f860b072799571eb7a9c345ac59bea55185

7

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.51549
MD5 0e68671dbfeb9bbaffc2c41770c86d05
SHA1 169fbec9e14045e6e96dd36f57dbad9e64e97211
SHA256 4a7f371fdbe6a0ec5ed411eab91b5a3bee7a472196923f0e6ac22b757f06adcb
SHA3 e6120921894ab0912e20b972e540a514a4a7d110edb4b29e8486c38689d19221

8

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x988
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.38008
MD5 c66501a52978fb480a6bf197d4113b01
SHA1 9c960e7743b35bffa2d75f26d01755d2dd5df075
SHA256 d1e85edb58fb861b91ccb664319ee978384a2d158d3bdc5c797cbd016697da89
SHA3 de0da94be96fbd062545f36c5851af58649cd512214520c2769412a8518f126d

9

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.56888
MD5 7df17c73529a31c519f0bf657d616db3
SHA1 6fd9f85ee747453bb2a5a5d241884d00c569e459
SHA256 6340b118f1818ced6d3ab818b4aec850dde1cdefe87a6c33e13cf77c59e78c16
SHA3 6309563e25482f0a9e4cb498a9b8362685405316d1e136ba61c59ab395aee16d

103

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x84
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.04448
Detected Filetype Icon file
MD5 f7731730720cfe035cf030b40d0e2eb6
SHA1 d046e23f2ee2b93ad96be8e1dc9120ecf3915091
SHA256 5c92a41adaf3265071482fd1a182ae8702c168636a7d9ff51798ee3a1dfc8500
SHA3 6f2d12e4c63c131a3f7f48293996e2be05da351536d013affe5d2265965ce657

1 (#2)

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x1c0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.44659
MD5 e177ee3abd26add570d31c2f66f2b6b8
SHA1 7f20c0dd1e49135b2f11c2dea8356b637c61c224
SHA256 d019a1a8361502c486f4bebe5b073284530db14e37be1039f9931ba5b5183365
SHA3 ce5a96212c5070519a895f3c03d55780dbb47fc3e5152e172bd9f901c2b56541

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x6c1
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.37708
MD5 aab7e8aafe7b06ab3d003b54ab5e18ed
SHA1 dccf0408f43059df37b755f3241a8b4b35c728af
SHA256 fb88b19523afd8fed48eddfd10805a3a0a45997bbf8fac04d595ddf93c1a88a8
SHA3 a981b8e907b79cd9448766ace938dfd96560d11c29e6ba165912a8508bd52ca7

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 2020.3.19.61751
ProductVersion 2020.3.19.61751
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_UNKNOWN
Language English - United States
FileVersion (#2) 2020.3.19.6877495
ProductVersion (#2) 2020.3.19.6877495
Unity Version 2020.3.19f1_68f137dc9bbe
Resource LangID English - United States

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2021-Sep-16 18:58:59
Version 0.0
SizeofData 134
AddressOfRawData 0x13730
PointerToRawData 0x11d30
Referenced File C:\buildslave\unity\build\artifacts\WindowsPlayer\Win64_VS2019_nondev_i_r\WindowsPlayer_Master_il2cpp_x64.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2021-Sep-16 18:58:59
Version 0.0
SizeofData 20
AddressOfRawData 0x137b8
PointerToRawData 0x11db8

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2021-Sep-16 18:58:59
Version 0.0
SizeofData 712
AddressOfRawData 0x137cc
PointerToRawData 0x11dcc

TLS Callbacks

Load Configuration

Size 0x130
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x140015030

RICH Header

XOR Key 0x69197163
Unmarked objects 0
C objects (VS2017 v14.15 compiler 26715) 10
ASM objects (VS2017 v14.15 compiler 26715) 5
C++ objects (VS2017 v14.15 compiler 26715) 136
Imports (VS2017 v14.15 compiler 26715) 2
C++ objects (VS 2015/2017/2019 runtime 28427) 37
C objects (VS 2015/2017/2019 runtime 28427) 16
ASM objects (VS 2015/2017/2019 runtime 28427) 8
Imports (VS2019 Update 5 (16.5.4-5) compiler 28614) 3
Total imports 85
C++ objects (VS2019 Update 5 (16.5.4-5) compiler 28614) 2
Exports (VS2019 Update 5 (16.5.4-5) compiler 28614) 1
Resource objects (VS2019 Update 5 (16.5.4-5) compiler 28614) 1
Linker (VS2019 Update 5 (16.5.4-5) compiler 28614) 1

Errors

Leave a comment

No comments yet.