| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2017-Jun-18 07:26:00 |
| Detected languages |
English - United States
|
| Debug artifacts |
C:\buildslave\unity\build\build\WindowsStandaloneSupport\Variations\win64_nondevelopment_mono\player_win_x64.pdb
|
| FileVersion | 5.6.2.10654012 |
| ProductVersion | 5.6.2.10654012 |
| Unity Version | 5.6.2f1_a2913c821e27 |
| Info | Matching compiler(s): | MASM/TASM - sig1(h) |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains references to system / monitoring tools:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to MD5 Uses constants related to SHA1 Uses constants related to SHA256 Uses constants related to SHA512 Uses constants related to AES Uses constants related to Blowfish Uses known Mersenne Twister constants Microsoft's Cryptography API |
| Suspicious | The PE is possibly packed. |
Unusual section name found: text
Unusual section name found: data Unusual section name found: .trace Unusual section name found: .data1 |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Safe | VirusTotal score: 0/72 (Scanned on 2025-05-13 20:20:53) | All the AVs think this file is safe. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x128 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 12 |
| TimeDateStamp | 2017-Jun-18 07:26:00 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 10.0 |
| SizeOfCode | 0x10b4000 |
| SizeOfInitializedData | 0x5f4800 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0000000000A11E14 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 5.2 |
| ImageVersion | 0.0 |
| SubsystemVersion | 5.2 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x16b0000 |
| SizeOfHeaders | 0x600 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| HID.DLL |
HidP_GetCaps
HidD_GetPreparsedData HidD_GetProductString HidD_GetManufacturerString HidD_GetSerialNumberString HidD_GetIndexedString HidP_MaxDataListLength HidD_FreePreparsedData HidP_GetData HidP_GetButtonCaps HidP_GetValueCaps HidD_GetHidGuid |
|---|---|
| KERNEL32.dll |
GetSystemTimeAsFileTime
GetModuleHandleA GetFullPathNameW GetCurrentProcessId GetCurrentProcess GetCurrentThread GetWindowsDirectoryW FormatMessageA SystemTimeToFileTime GetLocalTime GetTimeZoneInformation LocalFree GetModuleFileNameW InitializeCriticalSection ResetEvent GetTickCount ReadFile SetFilePointerEx WriteFile SetEndOfFile GetFileAttributesExW CreateFileW SetFileAttributesW GetFileAttributesW MoveFileExW FindClose FindNextFileW FindFirstFileW FindFirstFileExW SetFilePointer ReplaceFileW GetTempFileNameW LoadLibraryExW CreateEventW GlobalUnlock GlobalLock GlobalAlloc RemoveDirectoryW SetFileTime GetSystemTime GetDiskFreeSpaceExA lstrcpynA lstrcpyA lstrcpynW GetCommandLineW ExpandEnvironmentStringsW RtlVirtualUnwind RtlLookupFunctionEntry ResumeThread GetThreadContext SuspendThread RtlCaptureContext OutputDebugStringA GetEnvironmentVariableA GetFileAttributesA GetModuleFileNameA GetVersionExA GetCurrentDirectoryA VerifyVersionInfoW VerSetConditionMask GetVersionExW GetSystemPowerStatus GlobalMemoryStatusEx GetUserDefaultUILanguage GetComputerNameW GetTempPathW LocalAlloc SetUnhandledExceptionFilter OpenEventW DebugBreak GetCurrentDirectoryW GetOverlappedResult CancelIo GetFileSize FileTimeToDosDateTime FileTimeToLocalFileTime lstrlenA GetFileTime VirtualQuery GetQueuedCompletionStatus SetErrorMode DecodePointer EncodePointer HeapAlloc HeapFree RtlPcToFileHeader RtlUnwindEx HeapReAlloc InitializeCriticalSectionAndSpinCount CreateThread DuplicateHandle ExitProcess SetConsoleCtrlHandler ExitThread GetCommandLineA GetStartupInfoW FileTimeToSystemTime GetDriveTypeA FindFirstFileExA GetStdHandle GetLocaleInfoW UnhandledExceptionFilter TerminateProcess HeapSetInformation GetVersion HeapCreate FlsGetValue FlsSetValue FlsFree FlsAlloc SetHandleCount GetFileType GetConsoleCP GetConsoleMode GetCPInfo GetACP GetOEMCP IsValidCodePage FlushFileBuffers SetStdHandle GetStringTypeW LCMapStringW FreeEnvironmentStringsW GetEnvironmentStringsW GetFullPathNameA GetFileInformationByHandle PeekNamedPipe CreateFileA WriteConsoleW GetUserDefaultLCID GetLocaleInfoA EnumSystemLocalesA IsValidLocale CompareStringW SetEnvironmentVariableA GetDriveTypeW GetProcessHeap FlushConsoleInputBuffer SwitchToThread SetThreadAffinityMask GetProcessAffinityMask InitializeSListHead InterlockedPushEntrySList InterlockedPopEntrySList InterlockedFlushSList OpenEventA SetWaitableTimer CreateWaitableTimerA GetSystemDirectoryA SetConsoleMode ReadConsoleInputA GetTimeFormatA GetDateFormatA CreateMutexW FlushInstructionCache CreateSemaphoreW SignalObjectAndWait GetModuleHandleExA LoadLibraryExA GetThreadLocale VerifyVersionInfoA ExpandEnvironmentStringsA CreateIoCompletionPort SetHandleInformation FormatMessageW CreateFileMappingA MapViewOfFile UnmapViewOfFile GetCurrentThreadId HeapQueryInformation SetThreadPriority CreateMutexA ReleaseMutex GetModuleHandleW TryEnterCriticalSection LeaveCriticalSection EnterCriticalSection DeleteCriticalSection RaiseException HeapSize SleepEx SetDllDirectoryW CreateDirectoryW WaitForSingleObject WideCharToMultiByte LoadLibraryA SetEvent IsDebuggerPresent ReleaseSemaphore WaitForSingleObjectEx CreateSemaphoreA TlsSetValue TlsGetValue TlsFree TlsAlloc GetSystemInfo VirtualAlloc VirtualFree VirtualProtect DeleteFileW CopyFileW GetStartupInfoA LoadLibraryW GetProcAddress FreeLibrary CreateEventA CloseHandle Sleep SetLastError GetLastError MultiByteToWideChar QueryPerformanceFrequency QueryPerformanceCounter GlobalMemoryStatus |
| USER32.dll |
GetAsyncKeyState
ClientToScreen RegisterRawInputDevices GetMessageTime MapVirtualKeyExA GetMessagePos GetRawInputData GetKeyNameTextW LoadKeyboardLayoutA GetRawInputDeviceInfoW GetRawInputDeviceList wvsprintfA GetWindowLongPtrW SetWindowLongPtrW PostQuitMessage GetMonitorInfoA SetFocus GetFocus ShowCursor SetWindowTextW GetDlgItem IsDlgButtonChecked CopyImage SetWindowLongPtrA KillTimer GetMessageA PeekMessageA SetWindowPos SetCursorPos ClipCursor SystemParametersInfoW RegisterDeviceNotificationW GetMessageExtraInfo PtInRect DispatchMessageA UnregisterDeviceNotification SendMessageTimeoutA IsIconic wsprintfA DestroyIcon MonitorFromWindow LoadCursorA SetCursor GetSystemMetrics GetDC ReleaseDC CreateIconIndirect IsClipboardFormatAvailable GetClipboardData OpenClipboard EmptyClipboard SetClipboardData CloseClipboard GetCursorPos WindowFromPoint IsWindowVisible GetCaretBlinkTime MessageBoxW UpdateWindow GetKeyState LoadImageW DialogBoxParamA EndDialog SetForegroundWindow ScreenToClient CheckDlgButton GetAncestor CreateDialogParamW PeekMessageW ReleaseCapture SetCapture RegisterClassExW DialogBoxParamW LoadIconA SendDlgItemMessageW SetDlgItemTextA SetDlgItemTextW MessageBoxA CopyRect OffsetRect GetDesktopWindow AdjustWindowRectEx GetWindowPlacement GetWindowRect SendMessageA UnregisterClassW IsDialogMessageW DestroyWindow GetProcessWindowStation GetUserObjectInformationW DefWindowProcW RegisterClassW CreateWindowExW EnumDisplayMonitors EnumDisplaySettingsA EnumDisplayDevicesA GetClientRect EnableWindow SetTimer ShowWindow GetParent ValidateRect MsgWaitForMultipleObjects DispatchMessageW TranslateMessage SetWindowLongA ChangeDisplaySettingsA CreateDialogParamA GetWindowLongPtrA GetWindowLongA GetThreadDesktop GetUserObjectInformationA EnumWindows DestroyCursor RegisterWindowMessageA |
| VERSION.dll |
GetFileVersionInfoSizeA
GetFileVersionInfoA GetFileVersionInfoSizeW GetFileVersionInfoW VerQueryValueA |
| ole32.dll |
PropVariantClear
CoCreateGuid CoTaskMemAlloc CoTaskMemFree CoCreateInstance CoUninitialize CoSetProxyBlanket StringFromGUID2 CoInitialize |
| SHLWAPI.dll |
PathCanonicalizeW
PathFileExistsW SHDeleteKeyW |
| ADVAPI32.dll |
RegCloseKey
RegisterEventSourceW ReportEventW DeregisterEventSource CryptImportKey CryptVerifySignatureA CryptDestroyKey OpenProcessToken GetTokenInformation GetSidSubAuthority GetUserNameA RegOpenKeyExW RegCreateKeyW RegSetValueExA RegQueryValueExA RegDeleteValueA CryptReleaseContext CryptDestroyHash CryptGetHashParam CryptHashData CryptCreateHash CryptAcquireContextA RegQueryValueExW RegSetValueExW RegCreateKeyExW |
| GDI32.dll |
SetPixelFormat
SwapBuffers GetDeviceCaps GetObjectA DeleteObject CreateBitmap CreateDIBSection ChoosePixelFormat |
| SHELL32.dll |
SHFileOperationW
SHGetFolderPathW ShellExecuteW CommandLineToArgvW |
| OPENGL32.dll |
wglGetCurrentDC
wglGetCurrentContext wglCreateContext wglMakeCurrent wglDeleteContext wglGetProcAddress |
| WINMM.dll |
waveOutGetNumDevs
waveOutGetDevCapsA waveOutGetDevCapsW timeEndPeriod timeBeginPeriod timeGetTime waveOutClose waveOutOpen waveOutUnprepareHeader waveOutWrite waveOutReset waveOutGetPosition waveInAddBuffer waveInPrepareHeader waveInUnprepareHeader waveInGetDevCapsA waveInGetDevCapsW waveInStart waveInOpen waveInClose waveInReset waveOutPrepareHeader waveInGetNumDevs |
| WS2_32.dll |
WSACloseEvent
WSAEventSelect WSACreateEvent getsockopt WSACancelAsyncRequest WSAAsyncGetHostByName WSAWaitForMultipleEvents setsockopt ioctlsocket closesocket WSACleanup ntohl htonl ntohs htons WSAResetEvent WSAEnumNetworkEvents WSASetEvent getpeername getprotobyname recv gethostbyname shutdown listen accept WSARecvFrom WSAIoctl getnameinfo getaddrinfo recvfrom sendto send gethostname socket connect bind inet_addr WSAStartup select __WSAFDIsSet inet_ntoa getsockname freeaddrinfo WSASocketA WSASetLastError WSAGetLastError |
| OLEAUT32.dll |
VariantClear
SysAllocString SysFreeString VariantChangeType VariantInit |
| IMM32.dll |
ImmReleaseContext
ImmSetOpenStatus ImmGetCompositionStringW ImmGetConversionStatus ImmAssociateContextEx ImmAssociateContext ImmGetContext ImmSetCompositionStringW |
| DNSAPI.dll |
DnsQuery_A
DnsFree |
| IPHLPAPI.DLL |
GetIpAddrTable
|
| WINHTTP.dll |
WinHttpGetIEProxyConfigForCurrentUser
|
| MFPlat.DLL (delay-loaded) |
MFGetStrideForBitmapInfoHeader
MFStartup MFCreateAsyncResult MFCreateMediaType MFCreateSourceResolver MFCreateAttributes |
| Attributes | 0x1 |
|---|---|
| Name | MFPlat.DLL |
| ModuleHandle | 0x14b6de0 |
| DelayImportAddressTable | 0x1426f60 |
| DelayImportNameTable | 0x1388868 |
| BoundDelayImportTable | 0x1388988 |
| UnloadDelayImportTable | 0 |
| TimeStamp | 1970-Jan-01 00:00:00 |
| Ordinal | 1 |
|---|---|
| Address | 0x138c838 |
| Ordinal | 2 |
|---|---|
| Address | 0x138c834 |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 5.6.2.37180 |
| ProductVersion | 5.6.2.37180 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
| FileType |
VFT_UNKNOWN
|
| Language | English - United States |
| FileVersion (#2) | 5.6.2.10654012 |
| ProductVersion (#2) | 5.6.2.10654012 |
| Unity Version | 5.6.2f1_a2913c821e27 |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2017-Jun-18 07:26:00 |
| Version | 0.0 |
| SizeofData | 137 |
| AddressOfRawData | 0x128f0b8 |
| PointerToRawData | 0x128e6b8 |
| Referenced File | C:\buildslave\unity\build\build\WindowsStandaloneSupport\Variations\win64_nondevelopment_mono\player_win_x64.pdb |
| XOR Key | 0xabac1e52 |
|---|---|
| Unmarked objects | 0 |
| C objects (VS2012 build 50727 / VS2005 build 50727) | 1 |
| C objects (VS2008 SP1 build 30729) | 28 |
| 173 (VS2010 build 30319) | 1 |
| Imports (VS2008 SP1 build 30729) | 37 |
| C++ objects (VS2010 build 30319) | 7 |
| 136 (VS2008 SP1 build 30729) | 1 |
| 135 (VS2008 SP1 build 30729) | 3 |
| Total imports | 541 |
| 152 (20115) | 6 |
| ASM objects (VS2010 SP1 build 40219) | 33 |
| Unmarked objects (#2) | 206 |
| C objects (VS2010 SP1 build 40219) | 1063 |
| C++ objects (VS2010 SP1 build 40219) | 1205 |
| Exports (VS2010 SP1 build 40219) | 1 |
| Resource objects (VS2010 SP1 build 40219) | 1 |
| Linker (VS2010 SP1 build 40219) | 1 |
No comments yet.