16fb2f4bd736802a14c342346c2b3486

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2025-Jan-20 11:09:29
Detected languages English - United States
Debug artifacts C:\build\output\unity\unity\artifacts\WindowsPlayer\Win_x64_VS2022_VB_nondev_m_r\WindowsPlayer_player_Master_mono_x64.pdb
FileVersion 6000.0.35.10107846
LegalCopyright (c) 2005-2025 Unity Technologies. All rights reserved.
ProductVersion 6000.0.35f1 (9a3bc604008a)

Plugin Output

Info The PE contains common functions which appear in legitimate applications. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryExW
Suspicious The PE is possibly a dropper. Resources amount for 83.983% of the executable.
Safe VirusTotal score: 0/72 (Scanned on 2026-02-04 05:56:54) All the AVs think this file is safe.

Hashes

MD5 16fb2f4bd736802a14c342346c2b3486
SHA1 1a3c13b123cb292757fb326a1cc3907e3666543d
SHA256 7fd9eb10a18a5110c38d2175c60406c4a3eec9f8086bd8fd03f8f90a7cc0bee1
SHA3 d07e4e6c92c66b44379e3f0de7825516bc3d5a8d8dc5b9f9f9172f13fb48a034
SSDeep 12288:z2NCD1Jr3dnXgpppZXX7M9ggyimPb75idyVP35kvQlRR:hbyXbM9QrPYdYP35kvQ
Imports Hash ce1183cc150987a99aef5749f22af81e

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x110

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 7
TimeDateStamp 2025-Jan-20 11:09:29
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0xde00
SizeOfInitializedData 0x97200
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000001260 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0xa9000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 a5e0bf1e14a18380e4aa8fcfecd45cfd
SHA1 320e758c261b51cdf475ac1fe2d2b8b0f65ee37a
SHA256 9f9a743b5e5c12b459f7533a90382644af884df3aef68c9d7ac7d662735f193e
SHA3 0371197b472ffeeb91e1e7c7a9605222c7eee7431b878edcb558990adc374905
VirtualSize 0xdc70
VirtualAddress 0x1000
SizeOfRawData 0xde00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.46141

.rdata

MD5 bc14a290bfc65815bd5c8f6e7616a711
SHA1 f81d8c6f8f5d2eb2ed54e68e3056ba97a722562f
SHA256 a4c8d513d1337b02fefb01173ab842710d8b37074d8d6d12897be71191188563
SHA3 ddcf3d65ea385bdcdaa55e70bddefbbe3864bedfb46467ccb105068ea184d43b
VirtualSize 0x977a
VirtualAddress 0xf000
SizeOfRawData 0x9800
PointerToRawData 0xe200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.70079

.data

MD5 d284f7b260ed119794375a6998c5083c
SHA1 0944c690e2b7841e681f55d2a731910f8019f2ef
SHA256 79ebad17e73900bd4dd43a932cc832e1d907346973e16ac0af549524fa4b88b3
SHA3 0c023444d7239a9582798618879cf6e165fcae6d6eec1051c77592814b4894ad
VirtualSize 0x1d78
VirtualAddress 0x19000
SizeOfRawData 0xc00
PointerToRawData 0x17a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 1.89847

.pdata

MD5 583bf012d5970545541b47ad6f1b2dc4
SHA1 ed34342900f8481a1f09e9f73fe8bb0d1e528eb6
SHA256 a7a9a284c12beceaf69e80c98bb9708078c1ee29e3581bf7c44e24e7535c04eb
SHA3 e57cf3023698fe8882221ba469ca26d236b8a3d44b7d67f42d621316177425fe
VirtualSize 0xf24
VirtualAddress 0x1b000
SizeOfRawData 0x1000
PointerToRawData 0x18600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.67239

_RDATA

MD5 dd297010ea596c9b749ddc72fe421330
SHA1 3213e7a4b99366f1367f1b5dc97aa4853369a784
SHA256 420a70f17663b392f63eb448853ebc800a3f7cf9c6e0b78b7e421d671dd927fd
SHA3 f4660bd566f5561530bb0e40a752616d5a8180b7180fcf869790d48f9fb6e9bf
VirtualSize 0x1f4
VirtualAddress 0x1c000
SizeOfRawData 0x200
PointerToRawData 0x19600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 3.71477

.rsrc

MD5 fcac5bc0e1ffaa7de3708f09c58f965a
SHA1 6454309209d1ecf263475fb4af9f87f8acc32464
SHA256 96d41b792aa34faecbae5723091d37e9d4ed5c89b1c12a9831bf84bf08d171ac
SHA3 5bfd48ea02136581356dad6d80cc61d42815cad4813dde436a905551efa73249
VirtualSize 0x8a020
VirtualAddress 0x1d000
SizeOfRawData 0x8a200
PointerToRawData 0x19800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.95058

.reloc

MD5 79918e2814a23b917e4a5494067a35d5
SHA1 eab8dd05e160cbff9fa1c348b6c35e7f161cf459
SHA256 cccb376562c958fee6ec06051a48d2c5c0232065e1000ce2d4b0775e46737238
SHA3 0fcd95a99b9b4e77c2e23089f450965a4028a243ef56d1928fdcfcebcc4b7120
VirtualSize 0x658
VirtualAddress 0xa8000
SizeOfRawData 0x800
PointerToRawData 0xa3a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 4.87002

Imports

UnityPlayer.dll UnityMain
KERNEL32.dll HeapAlloc
WriteConsoleW
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
IsDebuggerPresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetStartupInfoW
IsProcessorFeaturePresent
GetModuleHandleW
CloseHandle
RtlUnwindEx
GetLastError
SetLastError
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
GetProcAddress
LoadLibraryExW
EncodePointer
RaiseException
RtlPcToFileHeader
GetStdHandle
WriteFile
GetModuleFileNameW
GetCurrentProcess
ExitProcess
TerminateProcess
GetModuleHandleExW
HeapFree
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
GetCommandLineA
GetCommandLineW
MultiByteToWideChar
WideCharToMultiByte
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetStdHandle
GetFileType
GetStringTypeW
FlsAlloc
FlsGetValue
FlsSetValue
FlsFree
LCMapStringW
GetProcessHeap
HeapSize
HeapReAlloc
FlushFileBuffers
GetConsoleOutputCP
GetConsoleMode
SetFilePointerEx
CreateFileW

Delayed Imports

AmdPowerXpressRequestHighPerformance

Ordinal 1
Address 0x19004

D3D12SDKPath

Ordinal 2
Address 0x19008

D3D12SDKVersion

Ordinal 3
Address 0xf320

NvOptimusEnablement

Ordinal 4
Address 0x19000

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.19928
MD5 226d7e16d2edf0f8dd78c0d5809f07df
SHA1 02e6eef7df38e53391b118a41c7c4259688864ad
SHA256 e6d35b9888a4b0025a87edc1c4e312223984c237ba3dcc63c8523b2542fc737b
SHA3 c4211904f6193baff67c8f5138965fd489d787c14a7fc3d2ac56c6af561b7a0b

2

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x988
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.42805
MD5 ee8655c6ce937ac2eec9d86f0a06a77b
SHA1 c5d39faecc42957f8fb503c16e583777417630dc
SHA256 4c1e573e43fe72f4ba031d975f0932ae779f5309dcc62ba3c32a40fec077ba8b
SHA3 45647813827658ebbd25d1f474b67051902102d249fd53e1624380dcabb81396

3

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.41941
MD5 c70b84c3d69aa1c53e753f8b90c118e7
SHA1 569d85504c541f2bae388280f381e0120c1fd670
SHA256 000ad72af1ab14c77a64639502e2097f545dc7955f218d1c776788d45ff78e2b
SHA3 5dac4c037a7ee0af7d8e44e882cddf0ec17ea1466db3c3eb0754916aaf2ad28c

4

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.27629
MD5 946f195ba53e187812931991a5a1e60f
SHA1 2997a0171c6a4eae7bb009679705a93dc78f6f13
SHA256 32a78cd0025c3decf092f6fc29acdebdb9c5a65b0d864ef4226ab2796117c692
SHA3 3167db8a57360eda12d43fbfaccbdfa6e4dceac471a796990f96510c07e58295

5

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x4228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.21172
MD5 c16983fc12a7f353251d6d57a12a44b3
SHA1 9927bcca75e35afdbcf54ec7559b5b43aa94a4dd
SHA256 9e0a24122bddd5cae63be43403b6948f0630ea8b00b6b459c088322a0d31fb16
SHA3 979d54061c303a003f19ee246e19dbcf47b5b09124d6937749431e46c278e6ef

6

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x94a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.10522
MD5 1d7ac68295df7213c8fcab0050fc3dff
SHA1 a813a5355de29cd0e17bdc09566dbd3b0167e934
SHA256 2319a8ac1cac04df69d896dfc4d3677ba9321c048975271a48201ad09aab0e97
SHA3 96c2f2e52263cab7621eb846d3d3321b73ca2ba1c45b22b08dfd2ea9f38ffe27

7

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10828
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.997
MD5 f5b3555e84f76d522e2c522c387bf5f8
SHA1 e7eb4f6d8bf09aaa34b0b56327944d93683d7c25
SHA256 c51c6dc3a97ae5ce7ee0e0ead06536073be712c764c29d3cf3e79a89063867ce
SHA3 900e3a10798b3ca7c955e40e3d639ec10e9bf631faa4edfb18fffcf6e1d40ed6

8

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.90772
MD5 69af40a815a33418cce6abfff472bd92
SHA1 b8441ea9f90a5557f91eb84387fcf09ddc527000
SHA256 ba18565bbe890f18d7a8e3a9f9e734810d3b46ee89126f017820629bb25cb08c
SHA3 78b3978678851eb470823d69170d38fea90e4f3a73725ef642f975a290f254c0

9

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x42028
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.86407
MD5 ba02e5343ba666f99abaa06131fccdbd
SHA1 bb6cc88c20fbe37ca758e23c1b79412d2938e692
SHA256 431d1f6a6c829e241b61d8925ba118c9719f7f6939398fd9b92a80775969812e
SHA3 92fcf4df4dc1b1609ddd5e129ea0f4e629645c5856534421f742bf1bbb44ef99

103

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x84
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.04448
Detected Filetype Icon file
MD5 3bf2dac037ce87794e66ff7f054e913f
SHA1 52ca961fd37ad960905a681d1db5157508ef1602
SHA256 2a87b1f32c5d0435090c72c392b75394f706e5750eff64fd85d25e1c622ee581
SHA3 8454d3273522657b5926068082b2cb88f6dbf352e7e9568008c0e33c792f349b

1 (#2)

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x214
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.49527
MD5 b68951f92ae8914dd670d1882bf09778
SHA1 02b76dd51f8d332629dacac61c9e58bc27b1cd73
SHA256 4078a0c244e08591d65ceec64728c8e747c965a1dec2ef50d880e32756576660
SHA3 03d7b58d8e46b06a487e40ba346906c67a608866bc9ac55067b646a990f9895c

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x545
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.24993
MD5 9df530c2f4fbe460da74e130d5d351a9
SHA1 f8719b6c74e0179556c1a18f214d6c1bbff8f823
SHA256 3c357bd1125971bda05bc59eaeca279da41715741e2535e9e75c94273b1c3a1f
SHA3 ce3dd46f87bd462f8730fca18daea6df444422f8d88b810aefbd7b2e62536dee

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 6000.0.35.15302
ProductVersion 6000.0.35.15302
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_UNKNOWN
Language English - United States
FileVersion (#2) 6000.0.35.10107846
LegalCopyright (c) 2005-2025 Unity Technologies. All rights reserved.
ProductVersion (#2) 6000.0.35f1 (9a3bc604008a)
Resource LangID English - United States

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2025-Jan-20 11:09:29
Version 0.0
SizeofData 146
AddressOfRawData 0x16d58
PointerToRawData 0x15f58
Referenced File C:\build\output\unity\unity\artifacts\WindowsPlayer\Win_x64_VS2022_VB_nondev_m_r\WindowsPlayer_player_Master_mono_x64.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2025-Jan-20 11:09:29
Version 0.0
SizeofData 20
AddressOfRawData 0x16dec
PointerToRawData 0x15fec

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2025-Jan-20 11:09:29
Version 0.0
SizeofData 852
AddressOfRawData 0x16e00
PointerToRawData 0x16000

TLS Callbacks

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x140019040

RICH Header

XOR Key 0x7139305b
Unmarked objects 0
ASM objects (28900) 5
C++ objects (28900) 138
C objects (28900) 10
Unmarked objects (#2) 1
Imports (28900) 2
C++ objects (33218) 40
C objects (33218) 16
ASM objects (33218) 17
Imports (33523) 3
Total imports 89
C++ objects (33523) 2
Exports (33523) 1
Resource objects (33523) 1
Linker (33523) 1

Errors