91ba22cfdde8dd83e4dbacd994d79c25b40041e92aa7460271fcc8b0583a1efc

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2025-Dec-16 21:44:33
Detected languages English - United States
Debug artifacts C:\build\output\unity\unity\artifacts\WindowsPlayer\Win_x64_VS2022_VB_nondev_i_r\WindowsPlayer_player_Master_il2cpp_x64.pdb
FileVersion 6000.0.65.10587682
LegalCopyright (c) 2005-2025 Unity Technologies. All rights reserved.
ProductVersion 6000.0.65f1 (a18e2220bd50)

Plugin Output

Info The PE contains common functions which appear in legitimate applications. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryExW
Suspicious The PE is possibly a dropper. Resources amount for 83.983% of the executable.
Safe VirusTotal score: 0/71 (Scanned on 2026-04-28 06:44:52) All the AVs think this file is safe.

Hashes

MD5 cd02c7787839e92a8c2765d3d026ea05
SHA1 a537c6bc86ae6c2298935fefaadcbf0797c61dd4
SHA256 91ba22cfdde8dd83e4dbacd994d79c25b40041e92aa7460271fcc8b0583a1efc
SHA3 b3f8bc54a423e4c559373426dd3f5969a4d7f7bafa248c385911fc4e18ee3d60
SSDeep 6144:d2E4CD20ZB4Gr34QiHJley3+2BVI77DWdr+p5fy:d2NCDdJr3d4ZO2BQXWd0
Imports Hash a136217cdd3247ff6a8766561064ca0b

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x110

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 7
TimeDateStamp 2025-Dec-16 21:44:33
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0xde00
SizeOfInitializedData 0x97200
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000001264 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0xa9000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 2775a5a7c1fa856e6a29a4f5a5229c31
SHA1 3e9ae8fdb588fe4aae22d549f8569008c887c898
SHA256 195697288171c6371920514965e3625060b55abd960ee1903baa797ef5e0bbfb
SHA3 fb39403bbfb970d14fc395dd6c3593ca3d0aec333b14d9249010a0924d269e75
VirtualSize 0xdc70
VirtualAddress 0x1000
SizeOfRawData 0xde00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.46162

.rdata

MD5 4982953cdbf83f96b70747049ee42cf4
SHA1 a91256dc4c20b28d9b7c3f9be7dbebd4e701f104
SHA256 92246b72cc642eb9a62f77e1b741bf913293353a15319c85f77c8ba994ae7f8e
SHA3 969593e7b18f7cbc80a6cefa0cc907f1b19abe027ed4a701fee2a2ec7aebf7c8
VirtualSize 0x977c
VirtualAddress 0xf000
SizeOfRawData 0x9800
PointerToRawData 0xe200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.70202

.data

MD5 d284f7b260ed119794375a6998c5083c
SHA1 0944c690e2b7841e681f55d2a731910f8019f2ef
SHA256 79ebad17e73900bd4dd43a932cc832e1d907346973e16ac0af549524fa4b88b3
SHA3 0c023444d7239a9582798618879cf6e165fcae6d6eec1051c77592814b4894ad
VirtualSize 0x1d78
VirtualAddress 0x19000
SizeOfRawData 0xc00
PointerToRawData 0x17a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 1.89847

.pdata

MD5 d67581e7561b613930fcc4c3ee52cdc5
SHA1 a43e835342a8235efb9f656bba5c170d21641a61
SHA256 4eaf2a70ebe02f5f76d3b133d8a74d7c7eee9267519fd6a6951de4bcb2ad617b
SHA3 0ccfeafaf338d1bcb9c719ffca72875595bea8d6aea16bd26baa2a4685e84170
VirtualSize 0xf24
VirtualAddress 0x1b000
SizeOfRawData 0x1000
PointerToRawData 0x18600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.67172

_RDATA

MD5 dd297010ea596c9b749ddc72fe421330
SHA1 3213e7a4b99366f1367f1b5dc97aa4853369a784
SHA256 420a70f17663b392f63eb448853ebc800a3f7cf9c6e0b78b7e421d671dd927fd
SHA3 f4660bd566f5561530bb0e40a752616d5a8180b7180fcf869790d48f9fb6e9bf
VirtualSize 0x1f4
VirtualAddress 0x1c000
SizeOfRawData 0x200
PointerToRawData 0x19600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 3.71477

.rsrc

MD5 2f47caa34035ce4e6e6686da7af53b5e
SHA1 6fdd8636c6ac60f2fc2ddb4be4eee639a754563f
SHA256 292f121ac51e0cd83a5a44c1d9b7f1defd8aa5089740f6e0c6d56496508a0969
SHA3 867548646b14644730990d7c80ca0c19b41acb686d17a837b56101ca9130f4af
VirtualSize 0x8a020
VirtualAddress 0x1d000
SizeOfRawData 0x8a200
PointerToRawData 0x19800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 3.70712

.reloc

MD5 79918e2814a23b917e4a5494067a35d5
SHA1 eab8dd05e160cbff9fa1c348b6c35e7f161cf459
SHA256 cccb376562c958fee6ec06051a48d2c5c0232065e1000ce2d4b0775e46737238
SHA3 0fcd95a99b9b4e77c2e23089f450965a4028a243ef56d1928fdcfcebcc4b7120
VirtualSize 0x658
VirtualAddress 0xa8000
SizeOfRawData 0x800
PointerToRawData 0xa3a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 4.87002

Imports

UnityPlayer.dll UnityMain2
KERNEL32.dll HeapAlloc
WriteConsoleW
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
IsDebuggerPresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetStartupInfoW
IsProcessorFeaturePresent
GetModuleHandleW
CloseHandle
RtlUnwindEx
GetLastError
SetLastError
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
GetProcAddress
LoadLibraryExW
EncodePointer
RaiseException
RtlPcToFileHeader
GetStdHandle
WriteFile
GetModuleFileNameW
GetCurrentProcess
ExitProcess
TerminateProcess
GetModuleHandleExW
HeapFree
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
GetCommandLineA
GetCommandLineW
MultiByteToWideChar
WideCharToMultiByte
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetStdHandle
GetFileType
GetStringTypeW
FlsAlloc
FlsGetValue
FlsSetValue
FlsFree
LCMapStringW
GetProcessHeap
HeapSize
HeapReAlloc
FlushFileBuffers
GetConsoleOutputCP
GetConsoleMode
SetFilePointerEx
CreateFileW

Delayed Imports

AmdPowerXpressRequestHighPerformance

Ordinal 1
Address 0x19004

D3D12SDKPath

Ordinal 2
Address 0x19008

D3D12SDKVersion

Ordinal 3
Address 0xf320

NvOptimusEnablement

Ordinal 4
Address 0x19000

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.79265
MD5 7170d44eb84f7daf679d5dcc6955b144
SHA1 3178577ca9d104e0dedd128f2c6f9e85e8d79a1e
SHA256 32902c88469b77622e1a0d736511957fd29ee488c4deb0065b15d30967e68f2e
SHA3 83630c9c829c8e55c2d686eee83581f5b9cb13876d02f76057bd7a0e355f98cd

2

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x988
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.58454
MD5 bb0cdd75cd6a534bafe0514ce7cf476f
SHA1 76aa336b087680b5c4118b5fbd49112070112ff5
SHA256 d5d542848b4999a105fc9cbfe4241f7d9744d675f5af032f04833c62d1d96e27
SHA3 1eb1208fedc0ddbba15377ca88171298ad4b2799c40121b21ca97d8a3f932d01

3

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.23688
MD5 61cee6294d8d67a1a4c25f9a558dceb0
SHA1 18af8d70f0d5f6cee2e43c0572e1464557e4cc53
SHA256 76582350d969c888bd0c10367f8bb416c1f63a2a07153370e42ba09facacb5f6
SHA3 b463c6f2836e1176227004edc3779fa34f50ad31720c007144ddc58b9184352f

4

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.708
MD5 6de12b6b1954fd621f2e7d1dfb9ceb14
SHA1 2b780ee5d5f6a4e297f49d46cf8ce8f2919a79cf
SHA256 91a98d117e19085538c452d4d03b2eb9c6e050c31bb1bf2adb8f3b802b358ad0
SHA3 ce11bdb91e8b74a64cefafd8bdf9d4b948b470c9e16fe7880ef1199b37e85529

5

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x4228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.43297
MD5 be3092cc0cc6cf242f5c19e5bfe62c52
SHA1 d564ea0801f3eb858411ce4f04936136fbf698ba
SHA256 3197f72017f91f1bf0597f1f46bbf34b920d26e33c2a0e07c6780d5725836dfd
SHA3 67b16ba3f3d126930b88135a050ac4f0a697612af82dff59903c04b04d194796

6

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x94a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.06184
MD5 86af6e3348aa641172f0734eaadf10ae
SHA1 cd8e267dde85105a08a356facdc6785a9dc8fbe8
SHA256 6d9b8e20f0ca02dee2bc8c3654405c8061e617678f39095aa6e8de7c22181d09
SHA3 891c7ba2aa585e246583184a24a0da65dc010c196225503647821a25402596dd

7

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10828
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.83505
MD5 a73dff8575af2478f83f41bb25e9aa36
SHA1 1dd71e3e3ff4d8b79077881d397e2a218e159426
SHA256 78140b50fbfa0bbb94d35b995b1b2e0d28d00cb351f668ee8e9d6dcd4710e3d9
SHA3 bc033685f108d255a25e26a7d9e2be8dfc61a23c892705d9c365a742355cf707

8

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.60288
MD5 135ae91457e496431d82a93835c44381
SHA1 d48205fa1069e89f53a3286fd4b04c5c4a59e0d6
SHA256 efb6502cdb7c03cdfa1fa521fa3b6a55f1bbd0add034adb61b641631a884b129
SHA3 0008e75f8da55905dc5cc201d9e34a08684e998daba09e5a67d552aa8e1b8f67

9

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x42028
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.45935
MD5 27bd6bf1bfd252b07437ea061058151e
SHA1 ed1c262d10696df075716cf8e0ffe07bb558d704
SHA256 6a33e502bb9e29a0c01af1b86118918ea6dec7eb877d46b03a92c0c02d90424d
SHA3 8ec4cdaac8eaf6672331ee2619de737ce013bca431f0f27963fe52168ced9147

103

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x84
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.04448
Detected Filetype Icon file
MD5 3bf2dac037ce87794e66ff7f054e913f
SHA1 52ca961fd37ad960905a681d1db5157508ef1602
SHA256 2a87b1f32c5d0435090c72c392b75394f706e5750eff64fd85d25e1c622ee581
SHA3 8454d3273522657b5926068082b2cb88f6dbf352e7e9568008c0e33c792f349b

1 (#2)

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x214
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.4819
MD5 821c08699e0a594bcebe22ecbba51b9d
SHA1 1a4ad4dfe005e75b7438a246c2df0b601bf7852b
SHA256 dd8922d904754e599a297275c958f55089e289a4fe14e2941bb27e5fc4e56714
SHA3 65510b52d493b760b1456718882621b435d69c7c07807ee8407f832d0cbc5f73

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x545
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.24993
MD5 9df530c2f4fbe460da74e130d5d351a9
SHA1 f8719b6c74e0179556c1a18f214d6c1bbff8f823
SHA256 3c357bd1125971bda05bc59eaeca279da41715741e2535e9e75c94273b1c3a1f
SHA3 ce3dd46f87bd462f8730fca18daea6df444422f8d88b810aefbd7b2e62536dee

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 6000.0.65.36386
ProductVersion 6000.0.65.36386
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_UNKNOWN
Language English - United States
FileVersion (#2) 6000.0.65.10587682
LegalCopyright (c) 2005-2025 Unity Technologies. All rights reserved.
ProductVersion (#2) 6000.0.65f1 (a18e2220bd50)
Resource LangID English - United States

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2025-Dec-16 21:44:33
Version 0.0
SizeofData 148
AddressOfRawData 0x16d58
PointerToRawData 0x15f58
Referenced File C:\build\output\unity\unity\artifacts\WindowsPlayer\Win_x64_VS2022_VB_nondev_i_r\WindowsPlayer_player_Master_il2cpp_x64.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2025-Dec-16 21:44:33
Version 0.0
SizeofData 20
AddressOfRawData 0x16dec
PointerToRawData 0x15fec

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2025-Dec-16 21:44:33
Version 0.0
SizeofData 852
AddressOfRawData 0x16e00
PointerToRawData 0x16000

TLS Callbacks

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x140019040

RICH Header

XOR Key 0x7139305b
Unmarked objects 0
ASM objects (28900) 5
C++ objects (28900) 138
C objects (28900) 10
Unmarked objects (#2) 1
Imports (28900) 2
C++ objects (33218) 40
C objects (33218) 16
ASM objects (33218) 17
Imports (33523) 3
Total imports 89
C++ objects (33523) 2
Exports (33523) 1
Resource objects (33523) 1
Linker (33523) 1

Errors

Leave a comment

No comments yet.