fb8d367b9c30fb69832e52ad2b9b4e462c0d966daf702d66b2c3fc589cdbdc07

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2019-Sep-10 10:04:31
Detected languages English - United States
Debug artifacts C:\buildslave\unity\build\artifacts\WindowsPlayer\Win64_nondev_m_r\WindowsPlayer_Master_mono_x64.pdb
FileVersion 2018.4.9.13252388
ProductVersion 2018.4.9.13252388
Unity Version 2018.4.9f1_ca372476eaba

Plugin Output

Info The PE contains common functions which appear in legitimate applications. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryExW
Suspicious The PE is possibly a dropper. Resources amount for 86.7865% of the executable.
Safe VirusTotal score: 0/72 (Scanned on 2025-06-03 21:30:10) All the AVs think this file is safe.

Hashes

MD5 91dd73eee230a840cc4c498c462a7b45
SHA1 6877690acca5a5ecfeb6cb68f6cf85a0366a6cae
SHA256 fb8d367b9c30fb69832e52ad2b9b4e462c0d966daf702d66b2c3fc589cdbdc07
SHA3 e9ca0041d47ba0c3e12808abf1d9e34dc3ab83fb770e79dd1335284f7a951df1
SSDeep 6144:vBCic2D7kN3QDU4bxzXELg6rHU/0D9Rbx70tYrn+oQK4CA2B6NLR:pLkNmNz46t7
Imports Hash 2903938ebca26120e91d0905dbfde587

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x110

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 6
TimeDateStamp 2019-Sep-10 10:04:31
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0xa000
SizeOfInitializedData 0x95c00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000001268 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0xa3000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 e3959a3353a0c73333174f549d388e74
SHA1 ddd6e2efb0cca809074dfd5597e3c51a0b74fc6d
SHA256 40308324ce0101e9106893e9c2aa57981cbb7d275d154727ad8e54657eff05cd
SHA3 3bc5704bfa603c12d782251d650603bfe76d880487157a0efbb3c52ddd367f21
VirtualSize 0x9e80
VirtualAddress 0x1000
SizeOfRawData 0xa000
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.37547

.rdata

MD5 d0055cd9eab2f6d13226fe1958219f10
SHA1 b239a2f23f4f818422266b026e40574b616e1248
SHA256 158b250875a8419c681c434170d79041945e386d33c339d7334ce2e00e9a997a
SHA3 16a39285b3ed936aa36faa5ae021b66086ffebc3e9399273fcbaf2868c6b867f
VirtualSize 0x87ce
VirtualAddress 0xb000
SizeOfRawData 0x8800
PointerToRawData 0xa400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.75447

.data

MD5 e5723f0a96548881b4089bde74a34fc6
SHA1 1cc548e1b83bbe5f362a98ca6da244de6dade3bc
SHA256 ecf3f7a52f8a031db5c7ce8d9d8e05965b7fbde8e543ba56ea1662fdcd093dd7
SHA3 ea9bf9671edf6c6262b017ec3e6f18e282e6e1b832a5a96fc43b0d53d5a18c97
VirtualSize 0x1bb8
VirtualAddress 0x14000
SizeOfRawData 0xa00
PointerToRawData 0x12c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 1.81096

.pdata

MD5 e66db456ae04138dcb237c5291e8eee0
SHA1 cf319e03da59e0027dbc745063b4877b4751f613
SHA256 a430de6014c7ac4e917ef44bfb3056041eaa1826bfc3fd9b5ae49854754fae8f
SHA3 f88e3bb467530326a62ce7d52572c594e43178feffb8a762d40420b094a4a5e2
VirtualSize 0xc30
VirtualAddress 0x16000
SizeOfRawData 0xe00
PointerToRawData 0x13600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.31128

.rsrc

MD5 0f36b0cb3cacbdf7af854a870e74369a
SHA1 96b46e8797076c0a1f5500ac0672d7c241bbf1af
SHA256 85a70fbd6a6ecb5f85082a933c7f9c7942edd60b9d76aff2d85e28fba98ce428
SHA3 a5170c1f0cefd0b381be996c26a64624ca12a417da2a5909f6da898d8bc7c44c
VirtualSize 0x8a0d8
VirtualAddress 0x17000
SizeOfRawData 0x8a200
PointerToRawData 0x14400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.37364

.reloc

MD5 e3aac30c773e88c2700a0e0f950592be
SHA1 2bf91fe5fe83ccb77977059ad2d6dbfefb19c443
SHA256 ced816cb4e98622677b5ca96407ddb8fddd97a04969717422058fd431560654a
SHA3 1e658d88e531b0977ab24a26bba64dd18e03ef3c7db199c804c3a262c9ffb89e
VirtualSize 0x614
VirtualAddress 0xa2000
SizeOfRawData 0x800
PointerToRawData 0x9e600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 4.74269

Imports

UnityPlayer.dll UnityMain
KERNEL32.dll TerminateProcess
CloseHandle
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
IsDebuggerPresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetStartupInfoW
IsProcessorFeaturePresent
GetModuleHandleW
CreateFileW
RtlUnwindEx
GetLastError
SetLastError
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
GetProcAddress
LoadLibraryExW
RaiseException
GetStdHandle
WriteFile
GetModuleFileNameW
GetCurrentProcess
ExitProcess
WriteConsoleW
GetModuleHandleExW
HeapFree
HeapAlloc
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
GetCommandLineA
GetCommandLineW
MultiByteToWideChar
WideCharToMultiByte
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetStdHandle
GetFileType
GetStringTypeW
LCMapStringW
GetProcessHeap
HeapSize
HeapReAlloc
FlushFileBuffers
GetConsoleCP
GetConsoleMode
SetFilePointerEx

Delayed Imports

AmdPowerXpressRequestHighPerformance

Ordinal 1
Address 0x14004

NvOptimusEnablement

Ordinal 2
Address 0x14000

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.53367
MD5 a36d5dd34d801a80a054132ddaaa3ef7
SHA1 000c937b322f94f894e268d9f2d145b8067092dc
SHA256 2f751c5f3494f41331508d55e51c9b1401e19613959f8aa105e526838817a039
SHA3 31a222f9951e543fe360e122283535781ea29170be0f57b6549eaf86b44d1dde

2

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x988
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.69364
MD5 7ec7415dd5567c2a6c5076977b325dd8
SHA1 ed013f6e5023af280a184b95f54ab6b70911fe60
SHA256 ec867fadb90d7cf0c0747c45bc9ee60f2eeadbf69420d967151a1351b17c3246
SHA3 87783754340f8c309f9d28a11251c6dcde0f842cfb50be0e945950e06fb50054

3

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.74994
MD5 bcf6ccf6fb4efe836cfd8661c16880a1
SHA1 502b3df85b6a2908f4e3225fde1658f78776e2b5
SHA256 5a5da04169cfe41e0f5d9085b6250761b37cfa51715d449bca003728e5a4cb22
SHA3 373ad431de026a491aec8a149d6c5c5032af45cdd4bb524885e3f35029d4f5ef

4

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.71146
MD5 d5cf51363f05ce752a75e9d1d5c9f952
SHA1 7d7ab44f91bd923841d6ae905d9d32ad693646e0
SHA256 8d8b125fe8e8e3b88620e2dc582d4310702d586dba73a6e41832868fc50f9a1d
SHA3 208fd234e48852a351abfcd24ccc2f438d3a63016a374e3d7c4e9480b025ffb5

5

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x4228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.70193
MD5 26305a2dad80df2fdf53570ecc13d1d6
SHA1 72bd448d0d0263185bd428e63712682c8c2c9573
SHA256 40a445781f0f4e1e809d070495ae0714bbd7bb3ccc3191626f7885b24f333eb1
SHA3 1c345279822542bceee43df1be6f24663e98559ee03ef382e37e778f8fdd2286

6

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x94a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.6272
MD5 8c3e18509d7255a58a6750a8c2e36542
SHA1 0f09b5b415a1fc0c2e41d9780863d170f55b9852
SHA256 2860dd28ae2812db434d63d7d13ca628c6d2562cb1a097fe6d93f6686c73e09b
SHA3 1af0121b2595c0c28283b71d0e7eb7b58cf89638c720c1ef287bde3f2774c84b

7

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10828
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.57515
MD5 c50f757a29da30dffa19c955a2afffd8
SHA1 f322e262383d8aa5bdca53af44252aaa0c2c099a
SHA256 1697ac916418a984757e441020e98bfeafc3a0d019f27e00afbe46e6a9a94a59
SHA3 cd7638b9fef2dd451f80113172aeaa014a934c941926622bf6b5dd963760c747

8

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.48946
MD5 e2ed146f23792cc3f8a97b79cf0230bb
SHA1 17ea49d3cf34ce8ed0bd05dbc7d66880d50d5c16
SHA256 13513816f176e2b70984adadeb87c65ad4c942c29d6f7f0d32b5c4cad2f31140
SHA3 9a78871199ea2572ada8fd75c3dfc6b01527e3beb83c3f3724456a084c6bc3fa

9

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x42028
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.87725
MD5 50a3da595a0210a39390155e5867b817
SHA1 7b36de40a701559f1217854c1d1d5f69b25ade58
SHA256 50b0a76a1d021e14b25b73591b3a10acc009567a3e5ba7fb3e902de659715632
SHA3 e29543c0dd2b97e8937aedecbee35e0c4d24c8120bf43d6f0702269f68bbe225

103

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x84
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.04448
Detected Filetype Icon file
MD5 3bf2dac037ce87794e66ff7f054e913f
SHA1 52ca961fd37ad960905a681d1db5157508ef1602
SHA256 2a87b1f32c5d0435090c72c392b75394f706e5750eff64fd85d25e1c622ee581
SHA3 8454d3273522657b5926068082b2cb88f6dbf352e7e9568008c0e33c792f349b

1 (#2)

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x1bc
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.42748
MD5 409c45b94e3a21d0b2119cafc26938d6
SHA1 ab30050a54a9917367dff8e1467527b3cd6100cc
SHA256 3ce3f710bdd912b225b8d2743dc68361f41fe14b06d3066eb2dc77c7bea191f6
SHA3 8ca9fa224961c2fc31d7efbb31d48cea12ea18dc46de73cae5b41944b9ab7771

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x655
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.37545
MD5 e64f0e3051453730fcd59e3487fff82c
SHA1 881f9506d98c7244ee2e6cc48de59fb5fe9394a0
SHA256 cc5206d924557aebbb34ea990bff63d51f03f95c9618f11ba16f5bd0d969f3b2
SHA3 e68e9754b0692216d6b7991ec0b28f737203d4f0979404b4bfd5728ed3214e3d

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 2018.4.9.14116
ProductVersion 2018.4.9.14116
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_UNKNOWN
Language English - United States
FileVersion (#2) 2018.4.9.13252388
ProductVersion (#2) 2018.4.9.13252388
Unity Version 2018.4.9f1_ca372476eaba
Resource LangID English - United States

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2019-Sep-10 10:04:31
Version 0.0
SizeofData 125
AddressOfRawData 0x122b0
PointerToRawData 0x116b0
Referenced File C:\buildslave\unity\build\artifacts\WindowsPlayer\Win64_nondev_m_r\WindowsPlayer_Master_mono_x64.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2019-Sep-10 10:04:31
Version 0.0
SizeofData 20
AddressOfRawData 0x12330
PointerToRawData 0x11730

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2019-Sep-10 10:04:31
Version 0.0
SizeofData 696
AddressOfRawData 0x12344
PointerToRawData 0x11744

TLS Callbacks

Load Configuration

Size 0x100
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x140014020

RICH Header

XOR Key 0x5bef5e40
Unmarked objects 0
C objects (VS2015/2017 runtime 25711) 10
ASM objects (VS2015/2017 runtime 25711) 5
C++ objects (VS2015/2017 runtime 25711) 140
Imports (VS2015/2017 runtime 25711) 2
ASM objects (VS2017 v15.?.? build 25930) 9
C++ objects (VS2017 v15.?.? build 25930) 34
C objects (VS2017 v15.?.? build 25930) 19
Imports (VS2017 v15.6 compiler 26128) 3
Total imports 81
C++ objects (VS2017 v15.6 compiler 26128) 2
Exports (VS2017 v15.6 compiler 26128) 1
Resource objects (VS2017 v15.6 compiler 26128) 1
Linker (VS2017 v15.6 compiler 26128) 1

Errors

Leave a comment

No comments yet.