efedb085ccdfca74554118953ec287ed3f803bee7fc6d1e6cdd63078cdc86a2a

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2020-Nov-25 05:15:07
Detected languages English - United States
Debug artifacts C:\buildslave\unity\build\artifacts\WindowsPlayer\Win64_nondev_m_r\WindowsPlayer_Master_mono_x64.pdb
FileVersion 2019.4.16.14703470
ProductVersion 2019.4.16.14703470
Unity Version 2019.4.16f1_e05b6e02d63e

Plugin Output

Info The PE contains common functions which appear in legitimate applications. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryExW
Suspicious The PE is possibly a dropper. Resources amount for 86.7884% of the executable.
Safe VirusTotal score: 0/66 (Scanned on 2022-04-10 06:01:37) All the AVs think this file is safe.

Hashes

MD5 f0ca2f8b792c64cb0b6b82a437e571c7
SHA1 ba3821b3389eeffcccbb2fe684f1ff2f342fea02
SHA256 efedb085ccdfca74554118953ec287ed3f803bee7fc6d1e6cdd63078cdc86a2a
SHA3 9f0320d062c50ab6ee6fe65ed93f157e00e230b20fa1dfba13de6222ecca62e6
SSDeep 6144:x/7oYfSHQPWTUg4xWHyS0nz5eAbYUWvt1HfL+5Strk:N7qTUBWHyS0npytN+ak
Imports Hash fd60dddc87379c239e8ac49516966c3e

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x110

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 6
TimeDateStamp 2020-Nov-25 05:15:07
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x9e00
SizeOfInitializedData 0x95e00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000001260 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0xa3000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 396787b09c7084619fd353ed4d4aa25a
SHA1 10bbf1d12fd72a6f2490dae0fb34b3e3c37d0397
SHA256 84c4f4af681e7c55e04955e3244214c6a39406c9ff283dac14b45179c7344fd2
SHA3 2dbc41d4fcc7f9459799c1f273cc7d0b29a65a800004b70b2d8024daf74dfc23
VirtualSize 0x9d70
VirtualAddress 0x1000
SizeOfRawData 0x9e00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.39606

.rdata

MD5 3ebfc6c636595b4efe84b14e0f440f74
SHA1 f2f8cb1341b677da874800d1335e590fc69fd606
SHA256 0b6e793063c372a21744226a801ef8c8b5a92a93d27de01229d91a37f439d5fb
SHA3 6953c380d6211bfaf37216217049993fd0f7bd15236725492d2f353f2a3da032
VirtualSize 0x88de
VirtualAddress 0xb000
SizeOfRawData 0x8a00
PointerToRawData 0xa200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.72673

.data

MD5 db32eedebac3d09a8db683fdd7266183
SHA1 9d3ad2e8f784250c149bc0545875f3347c1e07d5
SHA256 63a977bb7df30209d66ab0ee3c2587394d2d84b87cfabab13902a80a9f8ac2bb
SHA3 f60fb1eaea0dc406d8fd8219c5b9519256c10cea02ce9801f2b262cdde729c42
VirtualSize 0x1bc8
VirtualAddress 0x14000
SizeOfRawData 0xa00
PointerToRawData 0x12c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 1.81338

.pdata

MD5 3ce1bc4528abab2f9296f6de2d66eb13
SHA1 236a9014dd4163c9bea0d3216c4339b71336ac60
SHA256 846c816328ade2f569bd6d1755940b260f0c1dc44653c50fa0b693d81cdc395f
SHA3 78586f62c74b7328c23e5e427db6af1753665224f815fabb19547b4c15db1d67
VirtualSize 0xc18
VirtualAddress 0x16000
SizeOfRawData 0xe00
PointerToRawData 0x13600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.30914

.rsrc

MD5 69e7eb4cf0c67e17fbf3c416ba7da61d
SHA1 cad486b73091d607cf41aceaf80fcfa7e8aea0f1
SHA256 d80fdf5951d8d0a3e981d04ebdc36aa0e9bdf934488b6ac3247727b3f739572d
SHA3 7b3b9379678ec87d6a515c59f18dc70a8406a5c6acc786cf89f30e7b37f4656e
VirtualSize 0x8a0e0
VirtualAddress 0x17000
SizeOfRawData 0x8a200
PointerToRawData 0x14400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 3.5518

.reloc

MD5 15c60be0054361c5f282b9c542c4b5cd
SHA1 3414732e68613e7ee32812f73810341e1aa3c9b2
SHA256 1597710aaca61843fdb13da316d06290830148f7e34074bef548abcbffa3b72c
SHA3 dba1e0d3f98cd89e8c35eb26f42dfaa9d0746b81262aa44f970150cf3cd45691
VirtualSize 0x614
VirtualAddress 0xa2000
SizeOfRawData 0x800
PointerToRawData 0x9e600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 4.75713

Imports

UnityPlayer.dll UnityMain
KERNEL32.dll GetModuleHandleExW
WriteConsoleW
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
IsDebuggerPresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetStartupInfoW
IsProcessorFeaturePresent
GetModuleHandleW
CloseHandle
RtlUnwindEx
GetLastError
SetLastError
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
GetProcAddress
LoadLibraryExW
RaiseException
GetStdHandle
WriteFile
GetModuleFileNameW
GetCurrentProcess
ExitProcess
TerminateProcess
HeapAlloc
HeapFree
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
GetCommandLineA
GetCommandLineW
MultiByteToWideChar
WideCharToMultiByte
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetStdHandle
GetFileType
GetStringTypeW
LCMapStringW
GetProcessHeap
HeapSize
HeapReAlloc
FlushFileBuffers
GetConsoleCP
GetConsoleMode
SetFilePointerEx
CreateFileW

Delayed Imports

AmdPowerXpressRequestHighPerformance

Ordinal 1
Address 0x14004

NvOptimusEnablement

Ordinal 2
Address 0x14000

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x42028
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.1408
MD5 865ae6229024931f2179937cce1007f3
SHA1 d7090c6fd11143a5ff57c8663fc8ca84af1554fc
SHA256 445482272d4a22f2b9e2594ee4205b2060ad0584eddda4a0f57af5015848bcc9
SHA3 8820fd5d5a7135256c453393b0d405307198d43f2b747d8e7b9979a04cae3317

2

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.62659
MD5 a0c62999903886b573327dcbd29b189e
SHA1 d4ad081b398ddaa6a7aaf98659e0a83f398d810e
SHA256 798b6664a25a7a898a3f84533db82277dfda824d17c9df778557bcdf44239347
SHA3 159f51908b3f6d6e85d7358d572ff35b09d20bc55b496b6c3d2a9b465df497cb

3

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10828
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.76704
MD5 bae6356bd58e3c21f21bd8e223fdeb1c
SHA1 e21e2fda13a5857ad28171ab1726d0737b8eda84
SHA256 fa76d2756010d323038d088d9351d5927c7b2af31c807234a568ae8c4db020ab
SHA3 b369f86ece086006c21f3a41a55ade2389b7d4b6c4a99e6a63e7f10a48d34273

4

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x94a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.86981
MD5 f2baff3dd25e01497f9a13073d51f1b8
SHA1 b4673d59780091ad7ade9eed67431823f6cd2fcf
SHA256 9587d0fc62483ec6fa1b06ffd70e65a8fdd9776199bbafc37492029d171251d4
SHA3 3ba37b053836873a326fa2c53157b4b059064f5c56ec73d07c5f7c1a9eaca2c7

5

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x4228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.03604
MD5 29b02be7a0d7f6a2011fafa40dacc061
SHA1 2a073a56fbb5b439e8374ee7ecf522d1c95a917d
SHA256 96551c10dc3ca9a47122a9c90ab12982fa111344799806ac293c0873a883d1a7
SHA3 ad498c68b0f5dcb033fb7540711fd36e3d403268073fe0c7eb7af5a43cf0cfc2

6

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.13238
MD5 729f9fb64811fb6b75e5be568d3ffe74
SHA1 61a56a8defeed2e2ef8cdbfc21e480a14c992e70
SHA256 dac2dee20b6ff66826615f4add6bfc51e797849a98f65a3caf18cfe5d0287353
SHA3 05f564789aee0cd762a4ab0d255d1995a1a2e83cad337648234aba116f9ec762

7

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.21587
MD5 320929d449678de25cd07c74b176ed5b
SHA1 1892fbb8369df027d42d617a44b82a08368d2868
SHA256 016be05e5af9d8dc65bc4b1511183cd864c0a5bbdb5096d38f9ebade82b9de97
SHA3 5a92236ce75c4e30d94345b5a5cd6418d4f614d30028722527db4b8d48215d4c

8

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x988
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.31905
MD5 4622e6119a76c04bcb1e1f4fa8475557
SHA1 355b9ceafc7e5ae6beacf5f1e0f176b95fb72136
SHA256 cc2fd629002e7c14104ab8364330e32e8601f3c7359d8dd615d53a283d023d57
SHA3 38001f71d0cfc22a5e91e6271042ff655c7630901ea59cae313cef05f2457db3

9

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.27908
MD5 127df708cee2a035a77992a7e085ac31
SHA1 81354ad03817c6ef3d6a0fa86bc6b523114c780f
SHA256 ef13b93a073997b19b471621a5fcf68e8e3ab5753e353d241509e07eebd17651
SHA3 23f1aab4aa862d3767dc0b7e86c792a05971106faa8c51ed3dcfdcfce19b7563

103

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x84
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.04448
Detected Filetype Icon file
MD5 f7731730720cfe035cf030b40d0e2eb6
SHA1 d046e23f2ee2b93ad96be8e1dc9120ecf3915091
SHA256 5c92a41adaf3265071482fd1a182ae8702c168636a7d9ff51798ee3a1dfc8500
SHA3 6f2d12e4c63c131a3f7f48293996e2be05da351536d013affe5d2265965ce657

1 (#2)

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x1c8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.37036
MD5 384e38c61edfebc8991c14ca1bd09c56
SHA1 5f839013ab0c33667d8aea00a5393994bedd897f
SHA256 fe8e375da7c9be00c7114f43c62bee7307a3008cf3dab42fd2909392c6408a79
SHA3 016348887a1b23cf2bfa85d873497854fc1ae212ddec60271b3b12435435c195

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x655
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.37545
MD5 e64f0e3051453730fcd59e3487fff82c
SHA1 881f9506d98c7244ee2e6cc48de59fb5fe9394a0
SHA256 cc5206d924557aebbb34ea990bff63d51f03f95c9618f11ba16f5bd0d969f3b2
SHA3 e68e9754b0692216d6b7991ec0b28f737203d4f0979404b4bfd5728ed3214e3d

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 2019.4.16.23406
ProductVersion 2019.4.16.23406
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_UNKNOWN
Language English - United States
FileVersion (#2) 2019.4.16.14703470
ProductVersion (#2) 2019.4.16.14703470
Unity Version 2019.4.16f1_e05b6e02d63e
Resource LangID English - United States

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2020-Nov-25 05:15:07
Version 0.0
SizeofData 125
AddressOfRawData 0x123d0
PointerToRawData 0x115d0
Referenced File C:\buildslave\unity\build\artifacts\WindowsPlayer\Win64_nondev_m_r\WindowsPlayer_Master_mono_x64.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2020-Nov-25 05:15:07
Version 0.0
SizeofData 20
AddressOfRawData 0x12450
PointerToRawData 0x11650

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2020-Nov-25 05:15:07
Version 0.0
SizeofData 696
AddressOfRawData 0x12464
PointerToRawData 0x11664

TLS Callbacks

Load Configuration

Size 0x100
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x140014028

RICH Header

XOR Key 0x2a1ac2b2
Unmarked objects 0
C objects (VS2015/2017 runtime 25711) 10
ASM objects (VS2015/2017 runtime 25711) 5
C++ objects (VS2015/2017 runtime 25711) 141
Imports (VS2015/2017 runtime 25711) 2
C++ objects (VS 2015/2017 runtime 26706) 38
C objects (VS 2015/2017 runtime 26706) 16
ASM objects (VS 2015/2017 runtime 26706) 8
Imports (VS 2015/2017 runtime 27012) 3
Total imports 82
C++ objects (VS 2015/2017 runtime 27012) 2
Exports (VS 2015/2017 runtime 27012) 1
Resource objects (VS 2015/2017 runtime 27012) 1
Linker (VS 2015/2017 runtime 27012) 1

Errors

Leave a comment

No comments yet.