| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2014-May-26 08:27:05 |
| Detected languages |
English - United States
|
| Debug artifacts |
C:\BuildAgent\temp\buildTmp\UnityPlayer_Symbols.pdb
|
| FileVersion | 4.5.0.149807 |
| ProductVersion | 4.5.0.149807 |
| Unity Version | 4.5.0f6_fd4616464986 |
| Info | Matching compiler(s): |
Microsoft Visual C++ v6.0 DLL
Microsoft Visual C++ 6.0 - 8.0 MASM/TASM - sig1(h) Microsoft Visual C++ Microsoft Visual C++ v6.0 |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains references to system / monitoring tools:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to MD5 Uses constants related to SHA1 Uses constants related to SHA256 Uses constants related to SHA512 Uses constants related to AES Uses constants related to Blowfish Uses known Mersenne Twister constants Microsoft's Cryptography API |
| Suspicious | The PE is possibly packed. | Unusual section name found: .trace |
| Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
| Safe | VirusTotal score: 0/70 (Scanned on 2023-05-26 21:59:58) | All the AVs think this file is safe. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x140 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 7 |
| TimeDateStamp | 2014-May-26 08:27:05 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 10.0 |
| SizeOfCode | 0x850400 |
| SizeOfInitializedData | 0x34ba00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00491843 (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x852000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 5.1 |
| ImageVersion | 0.0 |
| SubsystemVersion | 5.1 |
| Win32VersionValue | 0 |
| SizeOfImage | 0xba1000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| HID.DLL |
HidP_GetButtonCaps
HidP_GetCaps HidD_GetProductString HidP_GetValueCaps HidP_MaxDataListLength HidP_GetData HidD_GetPreparsedData HidD_FreePreparsedData HidD_GetHidGuid |
|---|---|
| WS2_32.dll |
htonl
inet_addr closesocket WSACleanup getsockname connect gethostbyname htons WSAStartup WSAAsyncGetHostByName WSACancelAsyncRequest gethostbyaddr getaddrinfo freeaddrinfo getpeername getsockopt send recv shutdown listen accept ntohs bind recvfrom sendto __WSAFDIsSet WSASetLastError select setsockopt inet_ntoa ioctlsocket gethostname socket WSAGetLastError |
| KERNEL32.dll |
WriteFile
FindClose DeleteFileW RemoveDirectoryW FindNextFileW FindFirstFileW GetModuleFileNameW lstrcpynA lstrcpyA lstrcpynW FreeLibrary GetCommandLineW GetProcAddress LoadLibraryW CancelIo GetOverlappedResult CreateEventW ExpandEnvironmentStringsA CreateMutexA GetCurrentThreadId RaiseException GetCurrentProcess GetModuleHandleA GetSystemInfo GlobalMemoryStatusEx GetUserDefaultLangID GetVersionExA GetComputerNameW LoadLibraryA GetTempPathW GetModuleHandleW GetCurrentProcessId SetUnhandledExceptionFilter WaitForSingleObject CreateThread OutputDebugStringA SetLastError GetEnvironmentVariableA GetFileAttributesA GetModuleFileNameA GetCurrentDirectoryA ResumeThread GetThreadContext SuspendThread GetCurrentThread IsBadReadPtr GetWindowsDirectoryA GetFullPathNameW CreateSemaphoreA Sleep WaitForSingleObjectEx ReleaseSemaphore InterlockedCompareExchange SleepEx InitializeCriticalSection DeleteCriticalSection EnterCriticalSection LeaveCriticalSection TryEnterCriticalSection SetThreadPriority CreateEventA GlobalAlloc SetEvent ResetEvent FileTimeToDosDateTime FileTimeToLocalFileTime lstrlenA GetFileTime VirtualQuery GlobalMemoryStatus GetSystemTimeAsFileTime MoveFileExW CreateDirectoryW SetErrorMode WritePrivateProfileStringW HeapAlloc HeapReAlloc HeapFree RtlUnwind EncodePointer DecodePointer ExitProcess SetConsoleCtrlHandler ExitThread DuplicateHandle GetCommandLineA HeapSetInformation GetStartupInfoW GetStdHandle HeapCreate IsProcessorFeaturePresent InterlockedIncrement InterlockedDecrement HeapSize GetLocaleInfoW UnhandledExceptionFilter TerminateProcess GetCPInfo GetACP GetOEMCP IsValidCodePage InitializeCriticalSectionAndSpinCount InterlockedExchange GetConsoleCP GetConsoleMode FlushFileBuffers SetHandleCount GetFileType SetStdHandle LCMapStringW FreeEnvironmentStringsW GetEnvironmentStringsW GetTickCount GetStringTypeW GetUserDefaultLCID GetLocaleInfoA EnumSystemLocalesA IsValidLocale CompareStringW SetEnvironmentVariableA CreateFileA WriteConsoleW GetProcessHeap GetFullPathNameA lstrcmpiA MapViewOfFile CreateFileMappingA UnmapViewOfFile VirtualFree VirtualAlloc GetProcessAffinityMask OpenEventA GetSystemDirectoryA GetDateFormatA GetTimeFormatA CreateSemaphoreW CreateMutexW SignalObjectAndWait ReleaseMutex FlushConsoleInputBuffer GetVersion GetFileAttributesW CreateProcessW SetFileAttributesW GlobalLock GlobalUnlock GetFileSize ReadFile CreateFileW SetEndOfFile SetFilePointer CloseHandle IsDebuggerPresent WideCharToMultiByte FormatMessageA LocalFree MultiByteToWideChar QueryPerformanceCounter QueryPerformanceFrequency GetLastError TlsSetValue TlsGetValue TlsFree TlsAlloc InterlockedExchangeAdd FileTimeToSystemTime GetFileInformationByHandle PeekNamedPipe GetDriveTypeA FindFirstFileExA GetTimeZoneInformation ReadConsoleInputA SetConsoleMode GetCurrentDirectoryW GetDriveTypeW WaitForMultipleObjects TerminateThread SetThreadAffinityMask HeapValidate CopyFileW HeapWalk |
| USER32.dll |
EnumWindows
SendMessageA SetForegroundWindow ShowWindow IsIconic RegisterWindowMessageA GetUserObjectInformationA GetThreadDesktop GetParent GetWindowRect GetWindowLongA SetWindowPos SendMessageTimeoutA CreateDialogParamA SetWindowLongA GetDlgItem ChangeDisplaySettingsA AdjustWindowRectEx EnumDisplaySettingsA GetDesktopWindow UnregisterClassW GetAncestor wsprintfA GetKeyState GetRawInputDeviceList GetRawInputDeviceInfoW GetRawInputData GetClientRect RegisterRawInputDevices OpenClipboard EmptyClipboard CloseClipboard SetClipboardData CreateWindowExW CopyRect DestroyWindow DefWindowProcW DestroyCursor LoadCursorA SetCursor GetSystemMetrics GetDC GetCursorPos CreateIconIndirect GetUserObjectInformationW GetProcessWindowStation wvsprintfA MonitorFromWindow EnumDisplayDevicesA GetCaretBlinkTime PeekMessageA GetMessageA DispatchMessageA ValidateRect LoadImageA DialogBoxParamA IsDlgButtonChecked CheckDlgButton CreateDialogParamW EnableWindow PeekMessageW IsDialogMessageW TranslateMessage DispatchMessageW MsgWaitForMultipleObjects SetWindowTextW RegisterClassW PostQuitMessage SetWindowLongW GetWindowLongW SetCursorPos IsWindowVisible ScreenToClient GetClipboardData IsClipboardFormatAvailable SetCapture ReleaseCapture RegisterDeviceNotificationW UnregisterDeviceNotification SystemParametersInfoW ClientToScreen GetAsyncKeyState ClipCursor ShowCursor GetFocus SetFocus WindowFromPoint MessageBoxW RegisterClassExW DialogBoxParamW OffsetRect LoadIconA SendDlgItemMessageW SetDlgItemTextA SetDlgItemTextW MessageBoxA ReleaseDC EndDialog |
| VERSION.dll |
GetFileVersionInfoW
GetFileVersionInfoSizeW GetFileVersionInfoA GetFileVersionInfoSizeA VerQueryValueA |
| ole32.dll |
CoCreateInstance
CoTaskMemFree CoTaskMemAlloc StringFromGUID2 CoCreateGuid CoInitialize CoUninitialize CoSetProxyBlanket |
| SHLWAPI.dll |
PathIsDirectoryW
PathCanonicalizeW SHDeleteKeyA PathFileExistsW |
| ADVAPI32.dll |
CryptGetHashParam
CryptImportKey CryptVerifySignatureA CryptDestroyKey RegDeleteValueA GetUserNameA RegCreateKeyExW RegQueryValueExW CryptDestroyHash CryptHashData CryptReleaseContext RegOpenKeyExW RegSetValueExW RegCreateKeyA RegSetValueExA RegOpenKeyExA RegQueryValueExA RegCloseKey RegisterEventSourceA ReportEventA DeregisterEventSource CryptCreateHash CryptAcquireContextA |
| GDI32.dll |
SwapBuffers
GetObjectA GetDeviceCaps ChoosePixelFormat SetPixelFormat DeleteObject CreateBitmap CreateDIBSection |
| SHELL32.dll |
SHGetFolderPathW
CommandLineToArgvW ShellExecuteW |
| OPENGL32.dll |
glIsTexture
glGetTexParameteriv glTexSubImage2D glPixelStorei glCopyTexSubImage2D glDrawBuffer glReadBuffer glDrawArrays wglDeleteContext glTexParameteri glBegin glVertex3f glNormal3f glColor4f glEnd glHint glLightModelf glLoadIdentity glMaterialfv glMaterialf glGenTextures glBindTexture glTexImage2D glReadPixels glDeleteTextures glFinish glFogi glFogf glFogfv glLightModelfv glLightf glLightfv glTexGeni glTexGenfv glTexEnvfv glScissor glColor4fv glLightModeli glColorMaterial glGetFloatv glMultMatrixf glMatrixMode glLoadMatrixf glPolygonMode glFrontFace glClearColor glClearDepth glClearStencil glClear glIsEnabled glStencilFunc glStencilOp glStencilMask glDepthFunc glDepthMask glCullFace glPolygonOffset glColorMask glDisable glBlendFunc glEnable glAlphaFunc glTexEnvi glTexEnvf glDisableClientState glEnableClientState glColorPointer glVertexPointer glNormalPointer glTexCoordPointer glDrawElements glGetString glGetError wglGetProcAddress glGetIntegerv wglShareLists wglGetCurrentDC wglGetCurrentContext wglMakeCurrent wglCreateContext glViewport |
| WINMM.dll |
waveInOpen
waveInStart waveInGetDevCapsW waveInGetDevCapsA waveInUnprepareHeader waveInPrepareHeader waveInAddBuffer waveOutGetPosition waveOutReset waveOutWrite waveInClose waveOutOpen waveOutClose waveOutGetDevCapsW waveOutGetDevCapsA waveOutGetNumDevs waveInGetNumDevs timeBeginPeriod timeEndPeriod timeGetTime waveInReset waveOutUnprepareHeader waveOutPrepareHeader |
| OLEAUT32.dll |
SysStringLen
SysAllocString VariantChangeType VariantClear VariantInit SysFreeString |
| MSACM32.dll |
acmStreamConvert
acmStreamUnprepareHeader acmFormatSuggest acmStreamOpen acmStreamSize acmStreamPrepareHeader |
| IMM32.dll |
ImmReleaseContext
ImmSetOpenStatus ImmGetConversionStatus ImmGetCompositionStringW ImmAssociateContextEx ImmAssociateContext ImmGetContext ImmSetCompositionStringW |
| DNSAPI.dll |
DnsQuery_A
DnsFree |
| IPHLPAPI.DLL |
GetIpAddrTable
|
| WINHTTP.dll |
WinHttpGetIEProxyConfigForCurrentUser
|
| Ordinal | 1 |
|---|---|
| Address | 0x342f50 |
| Ordinal | 2 |
|---|---|
| Address | 0xec4f0 |
| Ordinal | 3 |
|---|---|
| Address | 0xbcc0 |
| Ordinal | 4 |
|---|---|
| Address | 0xf070 |
| Ordinal | 5 |
|---|---|
| Address | 0xd05f0 |
| Ordinal | 6 |
|---|---|
| Address | 0xd05f0 |
| Ordinal | 7 |
|---|---|
| Address | 0x13320 |
| Ordinal | 8 |
|---|---|
| Address | 0x80ada0 |
| Ordinal | 9 |
|---|---|
| Address | 0xeaa20 |
| Ordinal | 10 |
|---|---|
| Address | 0x342e70 |
| Ordinal | 11 |
|---|---|
| Address | 0xec4a0 |
| Ordinal | 12 |
|---|---|
| Address | 0xb630 |
| Ordinal | 13 |
|---|---|
| Address | 0xef60 |
| Ordinal | 14 |
|---|---|
| Address | 0xd05f0 |
| Ordinal | 15 |
|---|---|
| Address | 0xd05f0 |
| Ordinal | 16 |
|---|---|
| Address | 0x132a0 |
| Ordinal | 17 |
|---|---|
| Address | 0x80ada0 |
| Ordinal | 18 |
|---|---|
| Address | 0xea890 |
| Ordinal | 19 |
|---|---|
| Address | 0x342ab0 |
| Ordinal | 20 |
|---|---|
| Address | 0xec660 |
| Ordinal | 21 |
|---|---|
| Address | 0xbcf0 |
| Ordinal | 22 |
|---|---|
| Address | 0xdfb0 |
| Ordinal | 23 |
|---|---|
| Address | 0xd05f0 |
| Ordinal | 24 |
|---|---|
| Address | 0xd05f0 |
| Ordinal | 25 |
|---|---|
| Address | 0x133c0 |
| Ordinal | 26 |
|---|---|
| Address | 0x80ada0 |
| Ordinal | 27 |
|---|---|
| Address | 0xeabc0 |
| Ordinal | 28 |
|---|---|
| Address | 0x342b90 |
| Ordinal | 29 |
|---|---|
| Address | 0xec450 |
| Ordinal | 30 |
|---|---|
| Address | 0xc760 |
| Ordinal | 31 |
|---|---|
| Address | 0xebe0 |
| Ordinal | 32 |
|---|---|
| Address | 0xd05f0 |
| Ordinal | 33 |
|---|---|
| Address | 0xd05f0 |
| Ordinal | 34 |
|---|---|
| Address | 0x13180 |
| Ordinal | 35 |
|---|---|
| Address | 0x80ada0 |
| Ordinal | 36 |
|---|---|
| Address | 0xeb270 |
| Ordinal | 37 |
|---|---|
| Address | 0x3427f0 |
| Ordinal | 38 |
|---|---|
| Address | 0x64720 |
| Ordinal | 39 |
|---|---|
| Address | 0xb150 |
| Ordinal | 40 |
|---|---|
| Address | 0xcd40 |
| Ordinal | 41 |
|---|---|
| Address | 0xd05f0 |
| Ordinal | 42 |
|---|---|
| Address | 0xd05f0 |
| Ordinal | 43 |
|---|---|
| Address | 0x13400 |
| Ordinal | 44 |
|---|---|
| Address | 0x80ada0 |
| Ordinal | 45 |
|---|---|
| Address | 0xea810 |
| Ordinal | 46 |
|---|---|
| Address | 0x342c90 |
| Ordinal | 47 |
|---|---|
| Address | 0xec5c0 |
| Ordinal | 48 |
|---|---|
| Address | 0xc7b0 |
| Ordinal | 49 |
|---|---|
| Address | 0xee10 |
| Ordinal | 50 |
|---|---|
| Address | 0xd05f0 |
| Ordinal | 51 |
|---|---|
| Address | 0xd05f0 |
| Ordinal | 52 |
|---|---|
| Address | 0x13260 |
| Ordinal | 53 |
|---|---|
| Address | 0x80ada0 |
| Ordinal | 54 |
|---|---|
| Address | 0xeb540 |
| Ordinal | 55 |
|---|---|
| Address | 0x8415a0 |
| Ordinal | 56 |
|---|---|
| Address | 0x841600 |
| Ordinal | 57 |
|---|---|
| Address | 0x841620 |
| Ordinal | 58 |
|---|---|
| Address | 0x8415e0 |
| Ordinal | 59 |
|---|---|
| Address | 0x717010 |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 4.5.0.18735 |
| ProductVersion | 4.5.0.18735 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
| FileType |
VFT_UNKNOWN
|
| Language | English - United States |
| FileVersion (#2) | 4.5.0.149807 |
| ProductVersion (#2) | 4.5.0.149807 |
| Unity Version | 4.5.0f6_fd4616464986 |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2014-May-26 08:27:05 |
| Version | 0.0 |
| SizeofData | 76 |
| AddressOfRawData | 0x9c8ac0 |
| PointerToRawData | 0x9c72c0 |
| Referenced File | C:\BuildAgent\temp\buildTmp\UnityPlayer_Symbols.pdb |
No comments yet.