ad1bd47bca653dbf4fbb6efe67b67a87d2d79005aa7f4b66a86f50fec2e3fe9e

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2024-Nov-13 02:04:52
Detected languages English - United States
Debug artifacts C:\build\output\unity\unity\artifacts\WindowsPlayer\Win_x64_VS2022_VB_nondev_m_r\WindowsPlayer_player_Master_mono_x64.pdb
FileVersion 6000.0.28.15939244
LegalCopyright (c) 2005-2024 Unity Technologies. All rights reserved.
ProductVersion 6000.0.28f1 (f336aca0cab5)

Plugin Output

Info The PE contains common functions which appear in legitimate applications. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryExW
Suspicious The PE is possibly a dropper. Resources amount for 83.983% of the executable.
Suspicious No VirusTotal score. This file has never been scanned on VirusTotal.

Hashes

MD5 656758ff58deb2baabf8696a062e9382
SHA1 540dfc5af9b08ab2beab245dd974f1f29a747f3d
SHA256 ad1bd47bca653dbf4fbb6efe67b67a87d2d79005aa7f4b66a86f50fec2e3fe9e
SHA3 be1912289bc884d932c5b2384be2d7934149f407c46fb2f8f9998a3a47682775
SSDeep 6144:R2E4CD20ZB4Gr34QHHZSmwQijOk8+RjfgunQJyLclDkXqBP064t0F8AJT0Oa9T8:R2NCD1Jr3dnIF+28CV0QE
Imports Hash ce1183cc150987a99aef5749f22af81e

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x110

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 7
TimeDateStamp 2024-Nov-13 02:04:52
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0xde00
SizeOfInitializedData 0x97200
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000001260 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0xa9000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 a5e0bf1e14a18380e4aa8fcfecd45cfd
SHA1 320e758c261b51cdf475ac1fe2d2b8b0f65ee37a
SHA256 9f9a743b5e5c12b459f7533a90382644af884df3aef68c9d7ac7d662735f193e
SHA3 0371197b472ffeeb91e1e7c7a9605222c7eee7431b878edcb558990adc374905
VirtualSize 0xdc70
VirtualAddress 0x1000
SizeOfRawData 0xde00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.46141

.rdata

MD5 3e5ca867a8777abebeaf8928fcd35960
SHA1 e009cdbd5d59a6077417fc787a83ebbab23c1be3
SHA256 84ed2b47ef50759b6066ef6ec5706385b540e104cc7a3fbb483393608d918a3c
SHA3 63f6e1ecddfea03b6cfe07c9ac83a11d6205ff344f2df6c5dcddffa0ad260ade
VirtualSize 0x977a
VirtualAddress 0xf000
SizeOfRawData 0x9800
PointerToRawData 0xe200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.70078

.data

MD5 d284f7b260ed119794375a6998c5083c
SHA1 0944c690e2b7841e681f55d2a731910f8019f2ef
SHA256 79ebad17e73900bd4dd43a932cc832e1d907346973e16ac0af549524fa4b88b3
SHA3 0c023444d7239a9582798618879cf6e165fcae6d6eec1051c77592814b4894ad
VirtualSize 0x1d78
VirtualAddress 0x19000
SizeOfRawData 0xc00
PointerToRawData 0x17a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 1.89847

.pdata

MD5 583bf012d5970545541b47ad6f1b2dc4
SHA1 ed34342900f8481a1f09e9f73fe8bb0d1e528eb6
SHA256 a7a9a284c12beceaf69e80c98bb9708078c1ee29e3581bf7c44e24e7535c04eb
SHA3 e57cf3023698fe8882221ba469ca26d236b8a3d44b7d67f42d621316177425fe
VirtualSize 0xf24
VirtualAddress 0x1b000
SizeOfRawData 0x1000
PointerToRawData 0x18600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.67239

_RDATA

MD5 dd297010ea596c9b749ddc72fe421330
SHA1 3213e7a4b99366f1367f1b5dc97aa4853369a784
SHA256 420a70f17663b392f63eb448853ebc800a3f7cf9c6e0b78b7e421d671dd927fd
SHA3 f4660bd566f5561530bb0e40a752616d5a8180b7180fcf869790d48f9fb6e9bf
VirtualSize 0x1f4
VirtualAddress 0x1c000
SizeOfRawData 0x200
PointerToRawData 0x19600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 3.71477

.rsrc

MD5 2e073e99e0bb5b0d58eeb71fc89046ef
SHA1 c738250f95e3061cb9c01d34b1fffd932c7c6502
SHA256 c652c88239f8ac7c9106ab4ded87b0b2642fe6d6e5f935253f953667cd0fc910
SHA3 8980c832abf98ef9b80dd395a9016d74950b7988bb031a8bf58312e290bcc505
VirtualSize 0x8a020
VirtualAddress 0x1d000
SizeOfRawData 0x8a200
PointerToRawData 0x19800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.84781

.reloc

MD5 79918e2814a23b917e4a5494067a35d5
SHA1 eab8dd05e160cbff9fa1c348b6c35e7f161cf459
SHA256 cccb376562c958fee6ec06051a48d2c5c0232065e1000ce2d4b0775e46737238
SHA3 0fcd95a99b9b4e77c2e23089f450965a4028a243ef56d1928fdcfcebcc4b7120
VirtualSize 0x658
VirtualAddress 0xa8000
SizeOfRawData 0x800
PointerToRawData 0xa3a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 4.87002

Imports

UnityPlayer.dll UnityMain
KERNEL32.dll HeapAlloc
WriteConsoleW
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
IsDebuggerPresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetStartupInfoW
IsProcessorFeaturePresent
GetModuleHandleW
CloseHandle
RtlUnwindEx
GetLastError
SetLastError
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
GetProcAddress
LoadLibraryExW
EncodePointer
RaiseException
RtlPcToFileHeader
GetStdHandle
WriteFile
GetModuleFileNameW
GetCurrentProcess
ExitProcess
TerminateProcess
GetModuleHandleExW
HeapFree
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
GetCommandLineA
GetCommandLineW
MultiByteToWideChar
WideCharToMultiByte
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetStdHandle
GetFileType
GetStringTypeW
FlsAlloc
FlsGetValue
FlsSetValue
FlsFree
LCMapStringW
GetProcessHeap
HeapSize
HeapReAlloc
FlushFileBuffers
GetConsoleOutputCP
GetConsoleMode
SetFilePointerEx
CreateFileW

Delayed Imports

AmdPowerXpressRequestHighPerformance

Ordinal 1
Address 0x19004

D3D12SDKPath

Ordinal 2
Address 0x19008

D3D12SDKVersion

Ordinal 3
Address 0xf320

NvOptimusEnablement

Ordinal 4
Address 0x19000

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.5717
MD5 a91900dc6f3d2cbc1755ae90d2dda11f
SHA1 5d2a0a2fca828d3c531f6ad07fe618371016840f
SHA256 6d95f08bdab670d0d5c833e61391c6262376b2e9a68168ca1741f435889b1164
SHA3 664ae0df15a51dd0f54bc53ca8e742235ff135919dbfa99020cd617487f90f52

2

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x988
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.40557
MD5 98a3c583a3c81a9f1825095f17feeb36
SHA1 fbcdf90acfb2bf034af5f981be70740a4501a98a
SHA256 a04f26fff9d6f660aad3de89f71e0baba77bf36e8bd1d198e37a91e5a5c26a40
SHA3 d96258794e7db9b49e77fc3dfbf3e27261e6ff59dd251704b89a04dee1100058

3

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.27112
MD5 6d5f6782e94f079f15701c68ad537300
SHA1 b943cf6f26ad2ab469defcb19d0837457b548b32
SHA256 02aa87b9a6c75173158eb9f2e7dec9fcbe51c346741a7f58898b8e185aeb4b60
SHA3 746d98b1334c2290300be6175e5a2e56233d78bd5c086f5e15dabc581690e250

4

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.01831
MD5 f12461e272b7886d7a278f75a9ad0739
SHA1 aebc322300c90de83984815d00d95596b9501a96
SHA256 0c67c954f210bfc7c493b619d6288082df5cc5570554b321f42f43733421052f
SHA3 32fe77899b87a1c57ae11bbd4136235d2da9867aa383b7cbfbd01da2f698af8d

5

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x4228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.93975
MD5 b6dfb82c269b72bed9904ad61fd2d895
SHA1 662bf07df52055c34f39a9fc59e0e9b178c25e53
SHA256 91379258521c5045d16d63bd5ef48fa57f10338d64ebd8c30f5aede6faeb8415
SHA3 8547af43f8b93af2390657872d23a9dca7940b8d980a4a2ea2e4d7fbacd1b2ae

6

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x94a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.79266
MD5 4f2f6f49ac78cae41cba81c1c208acda
SHA1 105f0dd4ee06e2ffbe4263a6c8c9fdb035ee1693
SHA256 aff9eb836112e2121641c831d2cb3348a653f23829527712f3b0cb6c457824ce
SHA3 23d596c7bfee2b7838c6bbf2e248e7999f5183c300746f9c846c6ba7fbf98ef7

7

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10828
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.77987
MD5 dc1abe0caca06e6e9adaf2c5465fd87f
SHA1 8abbe33dfa95ae4b59a64af84d682021dd855140
SHA256 44a307a7f798d67a1c979ad66a34f736f4e45f8c22d39079f1dcd8f5c4b8c263
SHA3 e40923a611f0bcab073920a62561f23d57e446042889b81f8cb992aef0cd1d41

8

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.78657
MD5 f7b6e287f55296f6a8ba1ebb71eeabda
SHA1 0f9304b1771b8c531fff2aef8bdc88aa1c8b9bdd
SHA256 4458ace1833f971f2057b9f8220811bdadcc9971d2f718810e6403ee1055c696
SHA3 1da04baa5bab4a928a73e6b9eb4ab419110f5da7c41c4ccc3884bc59ae6fb0b9

9

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x42028
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.79023
MD5 9362c8d9e672264d837eee15ba9484b7
SHA1 90483790c348b042367304987b5e17e407808167
SHA256 73cbbc2ababffe77694d63641a241e41793f517be7967b2525bee869654bb50e
SHA3 9cdf33c7e7c96f92074040867bdf37ea1ed9a5318508e3ef26732f010823510c

103

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x84
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.04448
Detected Filetype Icon file
MD5 3bf2dac037ce87794e66ff7f054e913f
SHA1 52ca961fd37ad960905a681d1db5157508ef1602
SHA256 2a87b1f32c5d0435090c72c392b75394f706e5750eff64fd85d25e1c622ee581
SHA3 8454d3273522657b5926068082b2cb88f6dbf352e7e9568008c0e33c792f349b

1 (#2)

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x214
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.49607
MD5 47c5b9abe14faabfcf0e8fa03ab0d38c
SHA1 ed260f1a344f5e9f3a2652f4cf66a730d8b6db0b
SHA256 483245f3546aef5e2f83eac7eae0b8aebc2732b55f4ba0951bf03d8088047fdd
SHA3 3517fdcc995b57917d82885b14500fcac27c98a6748eb5455c49ebe1a4f1d7a9

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x545
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.24993
MD5 9df530c2f4fbe460da74e130d5d351a9
SHA1 f8719b6c74e0179556c1a18f214d6c1bbff8f823
SHA256 3c357bd1125971bda05bc59eaeca279da41715741e2535e9e75c94273b1c3a1f
SHA3 ce3dd46f87bd462f8730fca18daea6df444422f8d88b810aefbd7b2e62536dee

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 6000.0.28.13996
ProductVersion 6000.0.28.13996
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_UNKNOWN
Language English - United States
FileVersion (#2) 6000.0.28.15939244
LegalCopyright (c) 2005-2024 Unity Technologies. All rights reserved.
ProductVersion (#2) 6000.0.28f1 (f336aca0cab5)
Resource LangID English - United States

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2024-Nov-13 02:04:52
Version 0.0
SizeofData 146
AddressOfRawData 0x16d58
PointerToRawData 0x15f58
Referenced File C:\build\output\unity\unity\artifacts\WindowsPlayer\Win_x64_VS2022_VB_nondev_m_r\WindowsPlayer_player_Master_mono_x64.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2024-Nov-13 02:04:52
Version 0.0
SizeofData 20
AddressOfRawData 0x16dec
PointerToRawData 0x15fec

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2024-Nov-13 02:04:52
Version 0.0
SizeofData 852
AddressOfRawData 0x16e00
PointerToRawData 0x16000

TLS Callbacks

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x140019040

RICH Header

XOR Key 0x7139305b
Unmarked objects 0
ASM objects (28900) 5
C++ objects (28900) 138
C objects (28900) 10
Unmarked objects (#2) 1
Imports (28900) 2
C++ objects (33218) 40
C objects (33218) 16
ASM objects (33218) 17
Imports (33523) 3
Total imports 89
C++ objects (33523) 2
Exports (33523) 1
Resource objects (33523) 1
Linker (33523) 1

Errors

Leave a comment

No comments yet.