| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2080-Sep-08 20:23:28 |
| Detected languages |
English - United States
|
| TLS Callbacks | 2 callback(s) detected. |
| CompanyName | LargestBoi |
| FileDescription | UBZig UnityFS bundle utility (Public) |
| FileVersion | 2.1.8-Public |
| InternalName | ubzig |
| OriginalFilename | ubzig.exe |
| ProductName | UBZig |
| ProductVersion | 2.1.8-Public |
| Comments | Author: LargestBoi |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Miscellaneous malware strings:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to SHA256
Uses constants related to SHA512 Uses constants related to RC5 or RC6 |
| Suspicious | The PE is possibly packed. | Unusual section name found: .buildid |
| Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
| Suspicious | VirusTotal score: 1/71 (Scanned on 2026-09-26 17:05:41) | Elastic: malicious (moderate confidence) |
| MD5 | bdd4ba7d1f2ea2320e93814c55df81d9 🔍 |
|---|---|
| SHA1 | e15faad82ebe00dcac19cd543d28559fa887349f 🔍 |
| SHA256 | 81afad485dca8207115a13be0f41358fe54a8f2ac14490efb4c9e1ad7708fe31 🔍 |
| SHA3 | 2ad96cd5bd192dbdbde04140a58ee0680ab3130518ef0e6cac4a7a2986eb92f9 🔍 |
| SSDeep | 49152:Q6UdLoftdgjyFzgLzMJRlnzip51kacIc3QrwkTojDkXbIs:QifjFzl73QrKUrR 🔍 |
| Imports Hash | 90f06397f7cd8fb56373430f9fcaa9c9 🔍 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x78 |
| e_cp | 0x1 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0 |
| e_ss | 0 |
| e_sp | 0 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x78 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 8 |
| TimeDateStamp | 2080-Sep-08 20:23:28 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x11ba00 |
| SizeOfInitializedData | 0xc8000 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00000000000DD0D0 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x1ea000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x1000000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| MD5 | c4c3f0bf4bbe32418fe2535e0b7257da 🔍 |
|---|---|
| SHA1 | c999056d387351e3024db486f950477b2c870d65 🔍 |
| SHA256 | 99f67b365e278279be1519addc575592b075f6620183fc89d23d7eedd44dcd3d 🔍 |
| SHA3 | 45001c11bb4e9980bb2fcf64e6c693d04aedc5e5a778de224c44ef966b5758e3 🔍 |
| VirtualSize | 0x11b8d6 |
| VirtualAddress | 0x1000 |
| SizeOfRawData | 0x11ba00 |
| PointerToRawData | 0x400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
|
| Entropy | 6.24924 |
| MD5 | c45a0fdb208cd0085030a338258ce20a 🔍 |
|---|---|
| SHA1 | 7c1d871b6dcbf0fb6184081afcb413ca937acbc2 🔍 |
| SHA256 | f85d5533c1bbf593fce052f39dad5f8fe3d87434097c5e32bb3945bd9623d3e1 🔍 |
| SHA3 | 989f1438699135539fc3df3ad1b90ca849d28eb7f0e785eeabb3804d3d74fea4 🔍 |
| VirtualSize | 0xb7cd8 |
| VirtualAddress | 0x11d000 |
| SizeOfRawData | 0xb7e00 |
| PointerToRawData | 0x11be00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 6.93463 |
| MD5 | 1e3b89fb08d80ffd947647dd72feee33 🔍 |
|---|---|
| SHA1 | d3b9d136376757ada9a001ddedd66edf89200855 🔍 |
| SHA256 | 94140b9eeba46f0a37fbaee7a69ad0e48d9ce588f230300cde01335e50bd28fc 🔍 |
| SHA3 | af646f76785e47a2f63bb628de2ccf47fdfa7536f792c0461ac9a7e2ba5120c8 🔍 |
| VirtualSize | 0x1c |
| VirtualAddress | 0x1d5000 |
| SizeOfRawData | 0x200 |
| PointerToRawData | 0x1d3c00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 0.0980042 |
| MD5 | 5109c83d2b2baaba271664b9ccaf222a 🔍 |
|---|---|
| SHA1 | 2edd3bc670c6b7c967f573079cf7b1ca6a15afa2 🔍 |
| SHA256 | d32dae62abbdab2e05b931e43387593bd3f9ccde054d4e7d94b399fe2074217d 🔍 |
| SHA3 | 874705c47b8b523181e914261729e7b089de2b053ca3e581d9b8e0109f41a609 🔍 |
| VirtualSize | 0xd020 |
| VirtualAddress | 0x1d6000 |
| SizeOfRawData | 0xd000 |
| PointerToRawData | 0x1d3e00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 0.0808671 |
| MD5 | 510c9f1b441d00a4267d4c30fb60f540 🔍 |
|---|---|
| SHA1 | e6c6ee6f3187eb3075cc6363e9974ab1b8d95c6d 🔍 |
| SHA256 | 2398cef44e6534d2d81f8027c838bd6437dfd3a81331dca1588ed2120cd6335b 🔍 |
| SHA3 | b6e2112418815f8f61e4ff2898a2297600dee66d2c70c8b0b8c17d027ef101ee 🔍 |
| VirtualSize | 0x258c |
| VirtualAddress | 0x1e4000 |
| SizeOfRawData | 0x2600 |
| PointerToRawData | 0x1e0e00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 5.90144 |
| MD5 | bf619eac0cdf3f68d496ea9344137e8b 🔍 |
|---|---|
| SHA1 | 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5 🔍 |
| SHA256 | 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560 🔍 |
| SHA3 | 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59 🔍 |
| VirtualSize | 0x20 |
| VirtualAddress | 0x1e7000 |
| SizeOfRawData | 0x200 |
| PointerToRawData | 0x1e3400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 0 |
| MD5 | cdd3d252a707816c59e94c819cc0a9bf 🔍 |
|---|---|
| SHA1 | f041c0734b9370db98e040f110057b794cbb885c 🔍 |
| SHA256 | a13b07f51d6ca88b39216b68c3b8f49ac71e84ddeed21d8b6a07512d28ccf3dc 🔍 |
| SHA3 | ba91692c829942655121b60eb5a84b5c4d6ebacfaeb630307ad3aaf95e60fd99 🔍 |
| VirtualSize | 0x338 |
| VirtualAddress | 0x1e8000 |
| SizeOfRawData | 0x400 |
| PointerToRawData | 0x1e3600 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 2.77397 |
| MD5 | 9dbf1c89b7d13c1d5c75dc806fce44ff 🔍 |
|---|---|
| SHA1 | f00eae772d374eec68a9f5ca512e7a045493c66f 🔍 |
| SHA256 | b5b8f3361a27fd44e5b098e49a52bd15d98cc233ae4df8b314a4b322ff14f75f 🔍 |
| SHA3 | 0e1c1b4cce9620b1922c57e2a37b95397505ae2a182f7e0737b6949e30a73b23 🔍 |
| VirtualSize | 0x2c0 |
| VirtualAddress | 0x1e9000 |
| SizeOfRawData | 0x400 |
| PointerToRawData | 0x1e3a00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
|
| Entropy | 4.14592 |
| api-ms-win-crt-heap-l1-1-0.dll |
_msize
_set_new_mode calloc free malloc realloc |
|---|---|
| api-ms-win-crt-private-l1-1-0.dll |
__C_specific_handler
|
| api-ms-win-crt-runtime-l1-1-0.dll |
__p___argc
__p___argv _beginthreadex _cexit _configure_narrow_argv _crt_atexit _exit _initialize_narrow_environment _initterm _initterm_e _set_app_type _set_invalid_parameter_handler abort exit signal |
| api-ms-win-crt-stdio-l1-1-0.dll |
__acrt_iob_func
__p__commode __p__fmode __stdio_common_vfprintf __stdio_common_vsprintf fclose fflush fopen fputc fread fseek ftell fwrite getchar |
| KERNEL32.dll |
CloseHandle
CreateEventW CreateProcessW CreateSemaphoreW DeleteCriticalSection EnterCriticalSection GetLastError GetModuleHandleW GetProcAddress InitializeCriticalSection IsProcessorFeaturePresent LeaveCriticalSection ReleaseSemaphore ResetEvent ResumeThread SetEvent SetThreadAffinityMask SetUnhandledExceptionFilter Sleep TlsGetValue VirtualProtect VirtualQuery WaitForSingleObject |
| ntdll.dll |
LdrGetProcedureAddress
LdrLoadDll LdrUnloadDll NtAlertThread NtAlertThreadByThreadId NtAllocateVirtualMemory NtCancelIoFileEx NtCancelSynchronousIoFile NtClose NtCreateFile NtCreateNamedPipeFile NtCreateSection NtCreateThreadEx NtDelayExecution NtDeviceIoControlFile NtFlushBuffersFile NtFreeVirtualMemory NtFsControlFile NtLockFile NtMapViewOfSection NtOpenFile NtOpenThread NtQueryAttributesFile NtQueryDirectoryFile NtQueryInformationFile NtQueryInformationProcess NtQueryInformationThread NtQueryObject NtQuerySystemInformation NtQueryVolumeInformationFile NtReadFile NtResumeThread NtSetInformationFile NtTerminateProcess NtUnlockFile NtUnmapViewOfSection NtWaitForAlertByThreadId NtWaitForSingleObject NtWriteFile RtlActivateActivationContextEx RtlAllocateHeap RtlEnterCriticalSection RtlEqualUnicodeString RtlExitUserProcess RtlFreeHeap RtlGetActiveActivationContext RtlGetCurrentDirectory_U RtlGetFullPathName_U RtlGetSystemTimePrecise RtlLeaveCriticalSection RtlQueryPerformanceCounter RtlQueryPerformanceFrequency RtlReleaseActivationContext RtlReportSilentProcessExit RtlSetCurrentDirectory_U RtlUpcaseUnicodeChar |
| api-ms-win-crt-time-l1-1-0.dll |
_time64
|
| api-ms-win-crt-environment-l1-1-0.dll |
__p__environ
|
| api-ms-win-crt-math-l1-1-0.dll |
__setusermatherr
|
| Type |
RT_VERSION
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x2d8 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 3.43411 |
| MD5 | 186d0ca5459ef7ce5b5c4392bf369e27 🔍 |
| SHA1 | 7ae451882395a0731561243496faa8bc1bd6a451 🔍 |
| SHA256 | 12751b3fc175a147402fef5ed77721c72bb12f602906280cc8e72ad04e3641bd 🔍 |
| SHA3 | 4d4c9748796cbf4fad5655ff2fd942db0d99a0985853ac501903661258a6e175 🔍 |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 2.1.8.0 |
| ProductVersion | 2.1.8.0 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | English - United States |
| CompanyName | LargestBoi |
| FileDescription | UBZig UnityFS bundle utility (Public) |
| FileVersion (#2) | 2.1.8-Public |
| InternalName | ubzig |
| OriginalFilename | ubzig.exe |
| ProductName | UBZig |
| ProductVersion (#2) | 2.1.8-Public |
| Comments | Author: LargestBoi |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2080-Sep-08 20:23:28 |
| Version | 0.0 |
| SizeofData | 0 |
| AddressOfRawData | 0 |
| PointerToRawData | 0 |
| StartAddressOfRawData | 0x1401e7000 |
|---|---|
| EndAddressOfRawData | 0x1401e7018 |
| AddressOfIndex | 0x1401e2fd0 |
| AddressOfCallbacks | 0x1401cfc80 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_8BYTES
|
| Callbacks |
0x00000001400FF440
0x00000001400FF4C0 |
No comments yet.