5e900b827e927b2c1d3a7f23c7e7eb185de50fb9807a4eb56759707cc5be3c7b

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2024-Feb-12 11:15:38
Detected languages English - United States
Debug artifacts C:\build\output\unity\unity\artifacts\WindowsPlayer\Win64_VS2019_nondev_i_r\WindowsPlayer_player_Master_il2cpp_x64.pdb
FileVersion 2022.3.20.6406910
LegalCopyright (c) 2005-2024 Unity Technologies. All rights reserved.
ProductVersion 2022.3.20f1 (61c2feb0970d)

Plugin Output

Info The PE contains common functions which appear in legitimate applications. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryExW
Suspicious The PE is possibly a dropper. Resources amount for 84.749% of the executable.
Safe VirusTotal score: 0/72 (Scanned on 2025-07-23 08:40:47) All the AVs think this file is safe.

Hashes

MD5 3c8cb92fafa54390a3aab6670b34cf5e
SHA1 0ed049a4d5257c4352196398d3de21ae9c89c797
SHA256 5e900b827e927b2c1d3a7f23c7e7eb185de50fb9807a4eb56759707cc5be3c7b
SHA3 c74031af0d7c608faf6d3a9a3c8b819ac04a716b11b1379496a9ab840f324b86
SSDeep 12288:m/744aOD8yWmNXwtHOs+Yo8N3Kv34jPyHyA:k9aOS2wIlYopvP
Imports Hash ce1183cc150987a99aef5749f22af81e

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x110

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 7
TimeDateStamp 2024-Feb-12 11:15:38
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0xca00
SizeOfInitializedData 0x97000
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000001260 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0xa8000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 c908b9c0303dc1f82726ca4dae00b772
SHA1 e81e70cb017880d2883f88a85d9a5ba6176ebcc1
SHA256 6e577d9deae653a5181b5a961bc5d68133d0e0c5371dc8bf2e7a30f6ef4d5cb2
SHA3 deefbce421cada627162918879ac6eda8099d036762180ad5ebfb4cbd66be7e2
VirtualSize 0xc8b0
VirtualAddress 0x1000
SizeOfRawData 0xca00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.41078

.rdata

MD5 b34f86987e44f11a133f165672e49689
SHA1 9d817a7b2ee622d52c09060073b2b126bf15e2a2
SHA256 d62194c130eb5c17111d33956a0b4cce7c646ddb8cf80457c6fd16aa1e3cec64
SHA3 22853ea1e0ca1bbae2b9834041aeee6e134934dd6bf0a91767dda16a32173944
VirtualSize 0x948a
VirtualAddress 0xe000
SizeOfRawData 0x9600
PointerToRawData 0xce00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.65331

.data

MD5 90815aa5dc65a7dd3f93bad1bd78a77e
SHA1 608f3e69047b216dda6b0df73c30912e2fef5544
SHA256 435cb9af1df25f501f68a9700182c4d25de99c3f8e8c1ba6b16c0ca98911ff87
SHA3 e5ea90d4dd767bfa3d88e3fa2e107c2e40cac10f43498d5abd74f15888477d18
VirtualSize 0x1d38
VirtualAddress 0x18000
SizeOfRawData 0xc00
PointerToRawData 0x16400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 1.87032

.pdata

MD5 c69bce38ac69d0b835120a5590e69f0c
SHA1 c063139b665bfd43ee632f0741b4b5279a71f404
SHA256 1d79cfdb10b0e6f61968ed084c55a6ae07421354bf9072b12d090926728f3852
SHA3 5b320838ebff98a9e30dc5b9258ca4079fcb7cde4304c61cfe2dd57bb750842e
VirtualSize 0xef4
VirtualAddress 0x1a000
SizeOfRawData 0x1000
PointerToRawData 0x17000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.62843

_RDATA

MD5 f87f407c2a1cab208757ad1d23a2de6f
SHA1 cd739c36958f9ba7505883ae868f1a6ca71e880f
SHA256 6e4ba525d12ef66132e0738191d3a928ba74c0091a6f82bc48f892a41e2fc242
SHA3 0611ad194d9c623281cb358dbc2f2d28bb01b6eab682677ec8d16136d74414ab
VirtualSize 0x94
VirtualAddress 0x1b000
SizeOfRawData 0x200
PointerToRawData 0x18000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 1.11888

.rsrc

MD5 f9523b8d00aab6f8ea4930af1c593f54
SHA1 ddfba0eb7908dd464cb010a02f724df905a872d1
SHA256 7138db67377c99a7a4783ce182518ff379e7512faf2158ff5bfb7a3538115208
SHA3 7ca7ac2b6b47a754a9a51f4f3e572048c6637020247c1e323b82a1e47311c104
VirtualSize 0x8a198
VirtualAddress 0x1c000
SizeOfRawData 0x8a200
PointerToRawData 0x18200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.98885

.reloc

MD5 ef1e558d46106d87320dd822be1ddc48
SHA1 10f7b05d107451bd01cf446da512c619fc35bf50
SHA256 34d7b771018e478ba05cd24ec377fd34919d65ec63c43f49e1ab319785368929
SHA3 cc295f58e62efe5c59cad1febf1ce620404450135f442c20ba55235b492ddac9
VirtualSize 0x654
VirtualAddress 0xa7000
SizeOfRawData 0x800
PointerToRawData 0xa2400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 4.84209

Imports

UnityPlayer.dll UnityMain
KERNEL32.dll HeapAlloc
WriteConsoleW
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
IsDebuggerPresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetStartupInfoW
IsProcessorFeaturePresent
GetModuleHandleW
CloseHandle
RtlUnwindEx
GetLastError
SetLastError
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
GetProcAddress
LoadLibraryExW
EncodePointer
RaiseException
RtlPcToFileHeader
GetStdHandle
WriteFile
GetModuleFileNameW
GetCurrentProcess
ExitProcess
TerminateProcess
GetModuleHandleExW
HeapFree
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
GetCommandLineA
GetCommandLineW
MultiByteToWideChar
WideCharToMultiByte
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetStdHandle
GetFileType
GetStringTypeW
FlsAlloc
FlsGetValue
FlsSetValue
FlsFree
LCMapStringW
GetProcessHeap
HeapSize
HeapReAlloc
FlushFileBuffers
GetConsoleOutputCP
GetConsoleMode
SetFilePointerEx
CreateFileW

Delayed Imports

AmdPowerXpressRequestHighPerformance

Ordinal 1
Address 0x18004

NvOptimusEnablement

Ordinal 2
Address 0x18000

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x42028
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.93773
MD5 df9ac82c941e0983274dde54e85bfe65
SHA1 d6e946d558f17bc84b5bfd9eb17fcf9dcf1bacfb
SHA256 54fbf82048cc34199a9018a75a1ef84d3f41bc99e7b5395155b0043d2fe82bba
SHA3 e262e6f8436999918231201b31c2a0cb636b69fbe8658cbe628e62e2f7e13fcf

2

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.97587
MD5 9b4fb009d950a85d56d70a2e2b951293
SHA1 3f355f298f1a85c741ef1bcf33a8f1c3c3c27136
SHA256 1cefad4b35e0f516542bb196ae267fd23999cdefa54930e7447f14f4bdf56f9f
SHA3 013e51d5b613008edbda95b157d68c1ccf341c69632f933356573afa9d2a03fd

3

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10828
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.99186
MD5 21aed36af4fc8d5d0db393532773670b
SHA1 185cad6d98ff7fbdcedece0150841cef71e9c16c
SHA256 b123ee0cd8228a61f5fc8cfe85002fe0537f4ffc7cf21760a5964fb3f7555237
SHA3 6854f876e70794b644364cc80f701409216a1904d5e208c00e99b639dfd8c2f6

4

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x94a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.99907
MD5 e78ff58064b45eb365ab4fa83518c377
SHA1 97d2059ae2b1e4c4ee7e7ff52bc621779a0cdfd5
SHA256 0e34ad23adcb4d650f6829a0b92790e0896a07963921fe0395933363fb9393a5
SHA3 8de46bbae0b380e4dea225749d42923b1384630141f70e459643439bcf8ed7db

5

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x4228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.00723
MD5 26253e8e40fa81edeefd2d5b67165fd8
SHA1 cbdf77b9e2781d5d9856eaed0f7f4e5d5f001b1f
SHA256 bd4ea69ff7c28d79a1ed4d69fb75da06b72430bf9d376bf82822cb874b6f1744
SHA3 0c023a5e9a3697a98f97a73b90a1fe50790f1d6fc245c11de9a75777b3031d36

6

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.98095
MD5 61f3e1789b9aa10b131ea350b8aaacb9
SHA1 33c1b8f989413f7575ca3c3712fdb6390a885948
SHA256 407c14f0279b154b6813651095ba623d0b85c3b6d90ee87260103d1c74d83840
SHA3 11afcad89765189e01a5f3ae4f9a8e18b32ce3db11ccd579aadaacbb3fb51651

7

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.98233
MD5 4cc2c8017f268da3e2003de0e60d279a
SHA1 f2d7711f6c5413851941efb886dec2abb58ec6f4
SHA256 b056908554bf94f1428e988d610e38af9ae91a98110cda1db4775d80b6aab8fb
SHA3 b79f55de2faae6c3fa84245f403d20e701d95abb1d3abad40c237cc6c9e830e9

8

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x988
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.94562
MD5 64ec48897ce6505ed9dc3f9f33465801
SHA1 34803543f5b6dddffe0b3a81433f14d550e0e75f
SHA256 1cfa081bc6fd0296e72fc928c935a7f9457e9c442ed2ee96132d3a8e1f120d95
SHA3 fd5e3b47ee8791aaafc6867555a66d556e5e8ba7da7bf2021338203c5f95806a

9

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.84366
MD5 aa991328b3b208dbce2090fbb19a1640
SHA1 dab8953faa257de441a9d93569ec23e57e516a42
SHA256 b76c7c1af2fb487faa78494ac7a3dc918682f7eb403be4de4487c2cff24aeb4b
SHA3 be22985e34f4b469b3a6c1bf25e6377911da3eda2a05cc390e9b932007fbecb8

103

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x84
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.04448
Detected Filetype Icon file
MD5 f7731730720cfe035cf030b40d0e2eb6
SHA1 d046e23f2ee2b93ad96be8e1dc9120ecf3915091
SHA256 5c92a41adaf3265071482fd1a182ae8702c168636a7d9ff51798ee3a1dfc8500
SHA3 6f2d12e4c63c131a3f7f48293996e2be05da351536d013affe5d2265965ce657

1 (#2)

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x210
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.54216
MD5 2fdc2c1b2d94467c5737bee7842a8984
SHA1 ec99c8df771fce94e72fee92455ff296c2e3a106
SHA256 8f229574579155911675ccf7243d9a8b113e9247df190ebe528e4184686fd858
SHA3 45e20f3ddfbc0ba11076713421f910cecc231037b2c9e6d36b55e2d6a8bab167

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x6c1
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.37708
MD5 aab7e8aafe7b06ab3d003b54ab5e18ed
SHA1 dccf0408f43059df37b755f3241a8b4b35c728af
SHA256 fb88b19523afd8fed48eddfd10805a3a0a45997bbf8fac04d595ddf93c1a88a8
SHA3 a981b8e907b79cd9448766ace938dfd96560d11c29e6ba165912a8508bd52ca7

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 2022.3.20.49918
ProductVersion 2022.3.20.49918
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_UNKNOWN
Language English - United States
FileVersion (#2) 2022.3.20.6406910
LegalCopyright (c) 2005-2024 Unity Technologies. All rights reserved.
ProductVersion (#2) 2022.3.20f1 (61c2feb0970d)
Resource LangID English - United States

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2024-Feb-12 11:15:38
Version 0.0
SizeofData 143
AddressOfRawData 0x15aec
PointerToRawData 0x148ec
Referenced File C:\build\output\unity\unity\artifacts\WindowsPlayer\Win64_VS2019_nondev_i_r\WindowsPlayer_player_Master_il2cpp_x64.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2024-Feb-12 11:15:38
Version 0.0
SizeofData 20
AddressOfRawData 0x15b7c
PointerToRawData 0x1497c

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2024-Feb-12 11:15:38
Version 0.0
SizeofData 768
AddressOfRawData 0x15b90
PointerToRawData 0x14990

TLS Callbacks

Load Configuration

Size 0x138
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x140018030

RICH Header

XOR Key 0xe5e06b0d
Unmarked objects 0
ASM objects (28900) 5
C++ objects (28900) 138
C objects (28900) 10
Imports (28900) 2
C++ objects (VS 2015/2017/2019 runtime 29118) 39
C objects (VS 2015/2017/2019 runtime 29118) 16
ASM objects (VS 2015/2017/2019 runtime 29118) 9
Imports (VS2019 Update 8 (16.8.0-1) compiler 29333) 3
Total imports 89
C++ objects (VS2019 Update 8 (16.8.0-1) compiler 29333) 3
Exports (VS2019 Update 8 (16.8.0-1) compiler 29333) 1
Resource objects (VS2019 Update 8 (16.8.0-1) compiler 29333) 1
Linker (VS2019 Update 8 (16.8.0-1) compiler 29333) 1

Errors

Leave a comment

No comments yet.