4346414622a3b2b968d6bc598e93657fe917751019d7a62a54c61de7a762caff

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2025-Oct-24 11:11:06
Detected languages English - United States
Debug artifacts C:\build\output\unity\unity\artifacts\WindowsPlayer\Win64_VS2019_nondev_i_r\WindowsPlayer_player_Master_il2cpp_x64.pdb
FileVersion 2022.3.62.9860879
LegalCopyright (c) 2005-2025 Unity Technologies. All rights reserved.
ProductVersion 2022.3.62f3 (96770f904ca7)

Plugin Output

Info The PE contains common functions which appear in legitimate applications. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryExW
Suspicious The PE is possibly a dropper. Resources amount for 84.749% of the executable.
Safe VirusTotal score: 0/71 (Scanned on 2026-01-15 16:29:56) All the AVs think this file is safe.

Hashes

MD5 d4d35f3dd535750f8eebbec435b00400
SHA1 a82cbfb609cabfdfcb962bd8bfdfb0e37b14234a
SHA256 4346414622a3b2b968d6bc598e93657fe917751019d7a62a54c61de7a762caff
SHA3 86c2a778961945d26c3b4cfa93501033b24e6d0e58f7450000c9d4ac63a0027a
SSDeep 12288:5/7g4aOD8zFFsvDXOLb7sbAfMYClsWMdF1Bdecd6Jwx:hFaOmFFsvTOk3E/1Bdec4Jwx
Imports Hash a136217cdd3247ff6a8766561064ca0b

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x110

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 7
TimeDateStamp 2025-Oct-24 11:11:06
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0xca00
SizeOfInitializedData 0x97000
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000001264 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0xa8000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 e1ace82cc0f3d159779f5c95aa7e575b
SHA1 e4a5358996f267c921e5d996de44f3525bb042ed
SHA256 bec109031034001337c9be3c07e16f6fab9c862313fc1f8fb0699672e09c63a4
SHA3 449bef44a9ee4a68767a70da31c7ceb6aa3d1da49237a84227bbfb02c7e428a2
VirtualSize 0xc8b0
VirtualAddress 0x1000
SizeOfRawData 0xca00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.41019

.rdata

MD5 d70b2ddbfeb95da00930b91e68599514
SHA1 350472061d5a6c8d322298399cd5b20dfaea8eda
SHA256 6340660908af8cc3cde7478ee400cc2b9f37ed1a360ea8f0e5e20a4d68bede54
SHA3 80874b5ffc06e7dd7643664c5db56a570fd0b6f471885989e1f90ba81f0fedf2
VirtualSize 0x948c
VirtualAddress 0xe000
SizeOfRawData 0x9600
PointerToRawData 0xce00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.65465

.data

MD5 90815aa5dc65a7dd3f93bad1bd78a77e
SHA1 608f3e69047b216dda6b0df73c30912e2fef5544
SHA256 435cb9af1df25f501f68a9700182c4d25de99c3f8e8c1ba6b16c0ca98911ff87
SHA3 e5ea90d4dd767bfa3d88e3fa2e107c2e40cac10f43498d5abd74f15888477d18
VirtualSize 0x1d38
VirtualAddress 0x18000
SizeOfRawData 0xc00
PointerToRawData 0x16400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 1.87032

.pdata

MD5 6e619149c26d436c6f07193ff1e8032b
SHA1 70aea7c26eff6d7619bd6a5a97ab259d68dd24f5
SHA256 48cb5fb202e79c0b8da5091cb440a9068502b37c8e4200eb78df617ae99fd024
SHA3 196183a21caf69a7292ff77b288d707ce7d63e2b887053ae1bc258b99d1e36f0
VirtualSize 0xef4
VirtualAddress 0x1a000
SizeOfRawData 0x1000
PointerToRawData 0x17000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.62125

_RDATA

MD5 f87f407c2a1cab208757ad1d23a2de6f
SHA1 cd739c36958f9ba7505883ae868f1a6ca71e880f
SHA256 6e4ba525d12ef66132e0738191d3a928ba74c0091a6f82bc48f892a41e2fc242
SHA3 0611ad194d9c623281cb358dbc2f2d28bb01b6eab682677ec8d16136d74414ab
VirtualSize 0x94
VirtualAddress 0x1b000
SizeOfRawData 0x200
PointerToRawData 0x18000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 1.11888

.rsrc

MD5 c668e285f90c460dd1c97843ce51aed4
SHA1 3cfb6053d2ad1129838b24ca6447df113cc5ec0f
SHA256 3b326c4b7bb15cd88b9c39831f6885fd4086c64f61ce435b900292f535721a21
SHA3 bc97b869bacb48e44dbd508a6afdee15468cc659f187f2389d5d94f3ba0ea80c
VirtualSize 0x8a198
VirtualAddress 0x1c000
SizeOfRawData 0x8a200
PointerToRawData 0x18200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.63415

.reloc

MD5 ef1e558d46106d87320dd822be1ddc48
SHA1 10f7b05d107451bd01cf446da512c619fc35bf50
SHA256 34d7b771018e478ba05cd24ec377fd34919d65ec63c43f49e1ab319785368929
SHA3 cc295f58e62efe5c59cad1febf1ce620404450135f442c20ba55235b492ddac9
VirtualSize 0x654
VirtualAddress 0xa7000
SizeOfRawData 0x800
PointerToRawData 0xa2400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 4.84209

Imports

UnityPlayer.dll UnityMain2
KERNEL32.dll HeapAlloc
WriteConsoleW
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
IsDebuggerPresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetStartupInfoW
IsProcessorFeaturePresent
GetModuleHandleW
CloseHandle
RtlUnwindEx
GetLastError
SetLastError
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
GetProcAddress
LoadLibraryExW
EncodePointer
RaiseException
RtlPcToFileHeader
GetStdHandle
WriteFile
GetModuleFileNameW
GetCurrentProcess
ExitProcess
TerminateProcess
GetModuleHandleExW
HeapFree
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
GetCommandLineA
GetCommandLineW
MultiByteToWideChar
WideCharToMultiByte
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetStdHandle
GetFileType
GetStringTypeW
FlsAlloc
FlsGetValue
FlsSetValue
FlsFree
LCMapStringW
GetProcessHeap
HeapSize
HeapReAlloc
FlushFileBuffers
GetConsoleOutputCP
GetConsoleMode
SetFilePointerEx
CreateFileW

Delayed Imports

AmdPowerXpressRequestHighPerformance

Ordinal 1
Address 0x18004

NvOptimusEnablement

Ordinal 2
Address 0x18000

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x42028
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.57233
MD5 ded2aa163ab34287b7fc0047a5ad7dde
SHA1 89623fb79260ff2818c1ad4095de6cbd51cbb1f0
SHA256 e9fa1e0b485b392431e258aac295974e98c1afda04f1b4d5e2cdd91c802d8b20
SHA3 68e07923b7f92bdcb67c02ff083b398bdd019fe74af33ae2385ae9bb83d1b341

2

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.61374
MD5 11d8a26d2d2087654e0f524b8f009e43
SHA1 f5dadec8d10dce1e83b3eee9c00bc049e5d35461
SHA256 74d4c4fdd4c1ea8c71a7decdd5714bf038fefbc3dd1afe44330b61537b311937
SHA3 a556ba05377b6bec5844607367e6c1c41fcd04e50f22b0db9021f2206858d915

3

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10828
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.66096
MD5 5be15724f39865bbc7b426b9994406f9
SHA1 136b5eab5a679f6a39f869476c23e653d876a480
SHA256 799b2153a57693b0be5a9709265644599df996ddae5977e9775eaec7b4ecad66
SHA3 df8ebedc7c49e4bd6fb98fb6f3e6673f73c3a6a50c56ecce6d2b687683514e6b

4

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x94a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.71628
MD5 1d399da7fbdd873b03979469bea4766d
SHA1 4ee3e9c673649aafed206b140b9163c94067977f
SHA256 5812210b4bc0afcb2b74ea657f85e21c464005bdfbda236cbefc2ec55b23ef72
SHA3 35ce27cbbb5f65422f69b3eaddd0db25b9ba8ac5fd3cdad66ea2c7a3b7ba0aae

5

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x4228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.78876
MD5 be0d91252171e9723fb468139658be4b
SHA1 cf703b1ad9ff85795c6cd1f1707eaba26ca5550f
SHA256 8b57cbe02aa4716cdfaae1498eed3f66de136d90d4befd22374a9d9ab9b636ab
SHA3 945046897fb6e2a04f4db3c611fa537043eed476529cba5ac49c091976787923

6

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.82499
MD5 b0c1506c40a8d2ec07eba88409c2072d
SHA1 0bbb889e7d7cec74dcf98aedf84b34988531a220
SHA256 669636ad8595c2094df092cdd83a14e967d09037dfb4c8c78c73050d0dfa8d38
SHA3 3c2ff9886afbdf1603320622125ee2b1c29dbac04d761e5b97c7564416c482e7

7

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.95615
MD5 9e24f6b58ce2ff9b20d1ca9d64f34751
SHA1 a5b6565e1491a7f56037a8565da3ff9714f672f6
SHA256 520105c81ca521823af67a4eaa2407ffdb2dc7d6d888917a8da733e9f1272412
SHA3 ca2f08dfb2e9b1dc3e626356cedc3c96a8ba015aadb631aafe9df15f98b74eb5

8

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x988
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.96261
MD5 43ab6825df11a34175a54b385ab4c5cf
SHA1 3d1ae239e7830f14ae0be3e22d6a43921387c34d
SHA256 2dc325f25ce75a0bbab7fc5ab52610488fecfbe80b815bbc2020c6acba24331f
SHA3 d39cbf9e9bae2a6cd38d4b06e56b729d8356c421d8609fda64b4b58f2dc42d8f

9

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.9137
MD5 937178ed5f66f977e1f6e989ad786bee
SHA1 b0a29fc0f56b4175dcd1b876ca1ad533a38d12a6
SHA256 5626dea880140f081a2073d9f07c7a0bc4bd1bfd5b930c2c39c0e0c0536b6aa2
SHA3 f075248946afdf663f2bcfd4a6914ebd50a8ef14639fab337c52f5a054235d94

103

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x84
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.04448
Detected Filetype Icon file
MD5 f7731730720cfe035cf030b40d0e2eb6
SHA1 d046e23f2ee2b93ad96be8e1dc9120ecf3915091
SHA256 5c92a41adaf3265071482fd1a182ae8702c168636a7d9ff51798ee3a1dfc8500
SHA3 6f2d12e4c63c131a3f7f48293996e2be05da351536d013affe5d2265965ce657

1 (#2)

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x210
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.5636
MD5 b1896eb56c83e3d5bda752f7877f6007
SHA1 97f0feebce60693f5e9fedc0b6315e05d622c812
SHA256 d47790db30a8476cc148d07cdf009ad8cd39e133770a6ef588406deb63b5abb0
SHA3 8b4890a75f1d58cb0c54ebf85722125e36d0219bb82586dba8fe638d54362119

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x6c1
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.37708
MD5 aab7e8aafe7b06ab3d003b54ab5e18ed
SHA1 dccf0408f43059df37b755f3241a8b4b35c728af
SHA256 fb88b19523afd8fed48eddfd10805a3a0a45997bbf8fac04d595ddf93c1a88a8
SHA3 a981b8e907b79cd9448766ace938dfd96560d11c29e6ba165912a8508bd52ca7

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 2022.3.62.30479
ProductVersion 2022.3.62.30479
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_UNKNOWN
Language English - United States
FileVersion (#2) 2022.3.62.9860879
LegalCopyright (c) 2005-2025 Unity Technologies. All rights reserved.
ProductVersion (#2) 2022.3.62f3 (96770f904ca7)
Resource LangID English - United States

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2025-Oct-24 11:11:06
Version 0.0
SizeofData 143
AddressOfRawData 0x15aec
PointerToRawData 0x148ec
Referenced File C:\build\output\unity\unity\artifacts\WindowsPlayer\Win64_VS2019_nondev_i_r\WindowsPlayer_player_Master_il2cpp_x64.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2025-Oct-24 11:11:06
Version 0.0
SizeofData 20
AddressOfRawData 0x15b7c
PointerToRawData 0x1497c

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2025-Oct-24 11:11:06
Version 0.0
SizeofData 768
AddressOfRawData 0x15b90
PointerToRawData 0x14990

TLS Callbacks

Load Configuration

Size 0x138
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x140018030

RICH Header

XOR Key 0xe5e06b0d
Unmarked objects 0
ASM objects (28900) 5
C++ objects (28900) 138
C objects (28900) 10
Imports (28900) 2
C++ objects (VS 2015/2017/2019 runtime 29118) 39
C objects (VS 2015/2017/2019 runtime 29118) 16
ASM objects (VS 2015/2017/2019 runtime 29118) 9
Imports (VS2019 Update 8 (16.8.0-1) compiler 29333) 3
Total imports 89
C++ objects (VS2019 Update 8 (16.8.0-1) compiler 29333) 3
Exports (VS2019 Update 8 (16.8.0-1) compiler 29333) 1
Resource objects (VS2019 Update 8 (16.8.0-1) compiler 29333) 1
Linker (VS2019 Update 8 (16.8.0-1) compiler 29333) 1

Errors

Leave a comment

No comments yet.