cea2debb6ba7d431748ba8943c214fa8adcf5ded268867e9c6859758c03167c8

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2025-Oct-30 04:57:04
Detected languages English - United States
Debug artifacts C:\build\output\unity\unity\artifacts\WindowsPlayer\Win_x64_VS2022_VB_nondev_m_r\WindowsPlayer_player_Master_mono_x64.pdb
FileVersion 6000.0.62.16359173
LegalCopyright (c) 2005-2025 Unity Technologies. All rights reserved.
ProductVersion 6000.0.62f1 (f99f05b3e950)

Plugin Output

Info The PE contains common functions which appear in legitimate applications. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryExW
Suspicious The PE is possibly a dropper. Resources amount for 83.983% of the executable.
Safe VirusTotal score: 0/72 (Scanned on 2026-04-03 15:37:34) All the AVs think this file is safe.

Hashes

MD5 087212ddb9f23fb194f4c53be6dd27fd
SHA1 faa9ec84523012fce006c70b1b2985cb0fe6ac7a
SHA256 cea2debb6ba7d431748ba8943c214fa8adcf5ded268867e9c6859758c03167c8
SHA3 608c8ef906e57071c0840ef05221e34cf149ca8012400c24f6788c4b2330c939
SSDeep 6144:x2E4CD20ZB4Gr34QiHbhGnupkId7W3z6Juh0udsUPBXNMomgNSFsI4kuB4iX5gW:x2NCDdJr3d4t+nd5P5tgsI4xg
Imports Hash a136217cdd3247ff6a8766561064ca0b

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x110

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 7
TimeDateStamp 2025-Oct-30 04:57:04
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0xde00
SizeOfInitializedData 0x97200
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000001264 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0xa9000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 2775a5a7c1fa856e6a29a4f5a5229c31
SHA1 3e9ae8fdb588fe4aae22d549f8569008c887c898
SHA256 195697288171c6371920514965e3625060b55abd960ee1903baa797ef5e0bbfb
SHA3 fb39403bbfb970d14fc395dd6c3593ca3d0aec333b14d9249010a0924d269e75
VirtualSize 0xdc70
VirtualAddress 0x1000
SizeOfRawData 0xde00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.46162

.rdata

MD5 7419cdd40745f97eee67e1a8fe9865f7
SHA1 7eded25b486c785c323ba6cdaa24c3ebdb643c23
SHA256 67b258d2f1a05dd7cf29a3c3062e9c4fe5af8190fd3cdc1e8daff010cbf9603f
SHA3 0751e97e508889e84b2fb10dcdb48c4553a14182d788301119a645c384b32d8e
VirtualSize 0x977c
VirtualAddress 0xf000
SizeOfRawData 0x9800
PointerToRawData 0xe200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.70126

.data

MD5 d284f7b260ed119794375a6998c5083c
SHA1 0944c690e2b7841e681f55d2a731910f8019f2ef
SHA256 79ebad17e73900bd4dd43a932cc832e1d907346973e16ac0af549524fa4b88b3
SHA3 0c023444d7239a9582798618879cf6e165fcae6d6eec1051c77592814b4894ad
VirtualSize 0x1d78
VirtualAddress 0x19000
SizeOfRawData 0xc00
PointerToRawData 0x17a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 1.89847

.pdata

MD5 d67581e7561b613930fcc4c3ee52cdc5
SHA1 a43e835342a8235efb9f656bba5c170d21641a61
SHA256 4eaf2a70ebe02f5f76d3b133d8a74d7c7eee9267519fd6a6951de4bcb2ad617b
SHA3 0ccfeafaf338d1bcb9c719ffca72875595bea8d6aea16bd26baa2a4685e84170
VirtualSize 0xf24
VirtualAddress 0x1b000
SizeOfRawData 0x1000
PointerToRawData 0x18600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.67172

_RDATA

MD5 dd297010ea596c9b749ddc72fe421330
SHA1 3213e7a4b99366f1367f1b5dc97aa4853369a784
SHA256 420a70f17663b392f63eb448853ebc800a3f7cf9c6e0b78b7e421d671dd927fd
SHA3 f4660bd566f5561530bb0e40a752616d5a8180b7180fcf869790d48f9fb6e9bf
VirtualSize 0x1f4
VirtualAddress 0x1c000
SizeOfRawData 0x200
PointerToRawData 0x19600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 3.71477

.rsrc

MD5 701577aeb8bd4f510bb686b71bb3f3d0
SHA1 1e5d19df5c662b4838d1729e53230aebad3ba9fb
SHA256 5c6048bee04613058be6c587b66d23723112fd78985a741ad9ebd560bdfaa32a
SHA3 ebbe8391c0f690a49194c904a54cdb9ee7356f0a223278b611b2931ee5eff0ff
VirtualSize 0x8a020
VirtualAddress 0x1d000
SizeOfRawData 0x8a200
PointerToRawData 0x19800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.823

.reloc

MD5 79918e2814a23b917e4a5494067a35d5
SHA1 eab8dd05e160cbff9fa1c348b6c35e7f161cf459
SHA256 cccb376562c958fee6ec06051a48d2c5c0232065e1000ce2d4b0775e46737238
SHA3 0fcd95a99b9b4e77c2e23089f450965a4028a243ef56d1928fdcfcebcc4b7120
VirtualSize 0x658
VirtualAddress 0xa8000
SizeOfRawData 0x800
PointerToRawData 0xa3a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 4.87002

Imports

UnityPlayer.dll UnityMain2
KERNEL32.dll HeapAlloc
WriteConsoleW
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
IsDebuggerPresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetStartupInfoW
IsProcessorFeaturePresent
GetModuleHandleW
CloseHandle
RtlUnwindEx
GetLastError
SetLastError
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
GetProcAddress
LoadLibraryExW
EncodePointer
RaiseException
RtlPcToFileHeader
GetStdHandle
WriteFile
GetModuleFileNameW
GetCurrentProcess
ExitProcess
TerminateProcess
GetModuleHandleExW
HeapFree
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
GetCommandLineA
GetCommandLineW
MultiByteToWideChar
WideCharToMultiByte
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetStdHandle
GetFileType
GetStringTypeW
FlsAlloc
FlsGetValue
FlsSetValue
FlsFree
LCMapStringW
GetProcessHeap
HeapSize
HeapReAlloc
FlushFileBuffers
GetConsoleOutputCP
GetConsoleMode
SetFilePointerEx
CreateFileW

Delayed Imports

AmdPowerXpressRequestHighPerformance

Ordinal 1
Address 0x19004

D3D12SDKPath

Ordinal 2
Address 0x19008

D3D12SDKVersion

Ordinal 3
Address 0xf320

NvOptimusEnablement

Ordinal 4
Address 0x19000

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.86889
MD5 952f8bb33572dc00414a85cf4c96d822
SHA1 5b95e64a9e1e05fa277dc8c417444ec8218829ae
SHA256 8d669c184756477c47d13e7562772b03ca5ac9c9fc089e80391740598e5feab4
SHA3 5f6cb0dea804d9545d7eb7a1ac74c63b9d92c666d8279bbcedf417ff16905492

2

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x988
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.6572
MD5 31803de5b976e113cd4ba8fe7b520869
SHA1 143db3482ca34ed1b19f4fb40225569ac05f10d2
SHA256 d9923aa8dedff67e280f699bc0d9fa9c01645e3f3046186d7da58cc52a62b22a
SHA3 1bb099f5a941933669edcf7cf4cbe39965740be42f640dc22fe574f2dbd0a016

3

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.59057
MD5 91a59204baa353316782c6906c2dcfd2
SHA1 f5c5305f5a5e50306ae6a2f3b5794aec1bac8e7b
SHA256 acfcba2049e515394c946f96010e5e2502c3b803424b55cb1d357fb0dc93c016
SHA3 9eddc6383b04b728c088c28bb453283b7a72590fdb4387682c8d155d43cc63ec

4

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.26324
MD5 3a8ab1a1b3e0d9c9dbc8a21c492e34b3
SHA1 bf74905666bd7eeabd59e51a730d6095905eaedd
SHA256 7bdeae2ec718c2976877e4fcc2d103d39c9bfb2443e9de3446af1e8ce9a71183
SHA3 1c114c81fc7947715ec29d344ed24fffda0c2d96b819c5c4f30ffb31e15af09f

5

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x4228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.14268
MD5 b25cb4b2d65b80d235a737513cd69b71
SHA1 14b864728b8e30014423b89ea74ce70a2812f555
SHA256 0b8da9339a713ebeba3491df85ca19907da72c903aeb0e3aec755cb68f75de01
SHA3 1b407adc6b5d09979e47035cc8aae5cbb1c66aa1d6c0d670c4a63ba71d83c94c

6

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x94a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.98582
MD5 bbc8efecddb3f094e9959feec3231399
SHA1 5bee04e400b35118a3379ca2c5b09ed864b18f6c
SHA256 f11b3c58ed25093d78a3405c39789415d4a7f45ce97ffa5395efc096d4102427
SHA3 909efad43a306b97bd4fe45654f3bfdb40190301894a89ab625c9506421176e1

7

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10828
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.90473
MD5 c0be8ffd461697a827ce210d6fd37b23
SHA1 e83d3ff9ed1de72b3be5277b13be6bace23c2f58
SHA256 0dc16c7695b8beda675ee08b8e3dc0fcbcf2ef9ece1ce06eca41e9ed9cf8b0ef
SHA3 94213bea0e25c5871db2b2d605a86be2ed375a06662790963d2cd73d5f9f73ad

8

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.75876
MD5 2da640a2a0df81e875f2eefe21fd4839
SHA1 fedce8f3e285e899e372cb1bd8fc0fb220c3ba85
SHA256 1ebb931f22ec4e30464281674829ec4c878087ecb13ab5745bcaca693fb694ac
SHA3 441b051190e195d8614b68f3ac4831bda3b94114f0ea7b67f6a81a10e74f4f0e

9

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x42028
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.66972
MD5 e573a4aee13ae10a7e7e6e6ccbef7871
SHA1 e34243724f7c6202bc0a8113b298f1e630d464a7
SHA256 779a1282fba740e3e4be0abf29c9b79b1c7a9643359598bc2980b84ebc863694
SHA3 a25f7d4e6555f1deda5969206653e77fd392446e8a7cbb9756f61d9260d774a2

103

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x84
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.04448
Detected Filetype Icon file
MD5 3bf2dac037ce87794e66ff7f054e913f
SHA1 52ca961fd37ad960905a681d1db5157508ef1602
SHA256 2a87b1f32c5d0435090c72c392b75394f706e5750eff64fd85d25e1c622ee581
SHA3 8454d3273522657b5926068082b2cb88f6dbf352e7e9568008c0e33c792f349b

1 (#2)

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x214
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.49726
MD5 104b3509752c988dbcb30103509b7780
SHA1 398f2524add68f57993c2e6ff2b01092329008f4
SHA256 a680549e894dc1c9c1857fc304f0fcdac8aa865c4944728a600862ee4dcc9bdc
SHA3 09389dbc90284d381e859219dde3621db477aa28fd0af9ffaf3640f12a3a61eb

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x545
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.24993
MD5 9df530c2f4fbe460da74e130d5d351a9
SHA1 f8719b6c74e0179556c1a18f214d6c1bbff8f823
SHA256 3c357bd1125971bda05bc59eaeca279da41715741e2535e9e75c94273b1c3a1f
SHA3 ce3dd46f87bd462f8730fca18daea6df444422f8d88b810aefbd7b2e62536dee

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 6000.0.62.40709
ProductVersion 6000.0.62.40709
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_UNKNOWN
Language English - United States
FileVersion (#2) 6000.0.62.16359173
LegalCopyright (c) 2005-2025 Unity Technologies. All rights reserved.
ProductVersion (#2) 6000.0.62f1 (f99f05b3e950)
Resource LangID English - United States

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2025-Oct-30 04:57:04
Version 0.0
SizeofData 146
AddressOfRawData 0x16d58
PointerToRawData 0x15f58
Referenced File C:\build\output\unity\unity\artifacts\WindowsPlayer\Win_x64_VS2022_VB_nondev_m_r\WindowsPlayer_player_Master_mono_x64.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2025-Oct-30 04:57:04
Version 0.0
SizeofData 20
AddressOfRawData 0x16dec
PointerToRawData 0x15fec

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2025-Oct-30 04:57:04
Version 0.0
SizeofData 852
AddressOfRawData 0x16e00
PointerToRawData 0x16000

TLS Callbacks

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x140019040

RICH Header

XOR Key 0x7139305b
Unmarked objects 0
ASM objects (28900) 5
C++ objects (28900) 138
C objects (28900) 10
Unmarked objects (#2) 1
Imports (28900) 2
C++ objects (33218) 40
C objects (33218) 16
ASM objects (33218) 17
Imports (33523) 3
Total imports 89
C++ objects (33523) 2
Exports (33523) 1
Resource objects (33523) 1
Linker (33523) 1

Errors

Leave a comment

No comments yet.