b7f2d07a3eafd5e030e7f3e98e9529f60e07696bab50aa79afe1155f4ebd43e5

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2024-Oct-12 16:54:51
Detected languages English - United States
Debug artifacts C:\build\output\unity\unity\artifacts\WindowsPlayer\Win64_VS2019_nondev_i_r\WindowsPlayer_player_Master_il2cpp_x64.pdb
FileVersion 2021.3.45.895135
LegalCopyright (c) 2005-2024 Unity Technologies. All rights reserved.
ProductVersion 2021.3.45f1 (0da89fac8e79)

Plugin Output

Info The PE contains common functions which appear in legitimate applications. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryExW
Suspicious The PE is possibly a dropper. Resources amount for 86.4081% of the executable.
Safe VirusTotal score: 0/72 (Scanned on 2026-04-21 07:21:37) All the AVs think this file is safe.

Hashes

MD5 4b3db09f3fc5acc349fda5ce81da9aeb
SHA1 e094ebd10bb6ae94b735ffae30a9af994e9ae83e
SHA256 b7f2d07a3eafd5e030e7f3e98e9529f60e07696bab50aa79afe1155f4ebd43e5
SHA3 0eba072d5eed4db6ed0b885ac1d69f299d8ede73adeb3ffbac76fbd1f018046a
SSDeep 12288:boCCE/ktDWmK0sxbpIRLZeh+O/9ALMJIXFQjh5:k+ktDWmK0SpIRLZeh+OWwWXQh5
Imports Hash 5f74a5c747508e2822fdb9b687deaf42

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x118

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 7
TimeDateStamp 2024-Oct-12 16:54:51
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0xa200
SizeOfInitializedData 0x96600
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000001260 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0xa5000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 4190b7be9f5f4eb52c040a688e61a250
SHA1 ee3a1c75987c1b0e5e4ed015cbe0c92530bdad11
SHA256 7d92c29b88ce9a3c69a11f70fbc73e302f5d8d66766589406274d31e97ed920b
SHA3 0e04178fbb1a5d03ab267f800a38d342bb9f4a2bb6441604af8a9b52ecb4c4c6
VirtualSize 0xa140
VirtualAddress 0x1000
SizeOfRawData 0xa200
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.39724

.rdata

MD5 c1c8cbb99dcac7917c2a332ed3e72543
SHA1 74f84b6e9d453ba859e9ed814d909f9c0a3b6ef4
SHA256 16852da26c4b4c5573454d3cc178e7e0a8414ae78ff36b1eadc09c529cd2a7d5
SHA3 e81431b0a40850615e746272f673bd00933579a53483df8dfdb372b7ea9ae17e
VirtualSize 0x8cce
VirtualAddress 0xc000
SizeOfRawData 0x8e00
PointerToRawData 0xa600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.65364

.data

MD5 2e9924c581c86e57e2e2b0ac87e1aa45
SHA1 a1a176fc5c54e8c996a328e810c15c16cdb5b73d
SHA256 90b0d83be28bc06320f7b2ce10f056ecd17badc2e84e2b1533c0454096a1e5a0
SHA3 8c3bb6dfd1204e833639461f26a41ad45e7fa68dcdc97aa4908992d272dc2237
VirtualSize 0x1ce8
VirtualAddress 0x15000
SizeOfRawData 0xc00
PointerToRawData 0x13400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 1.6801

.pdata

MD5 2717431295e555cdae3fb602e2bd957e
SHA1 408d09336a1192e50edb78d3e7795fbc547ac381
SHA256 d927fd3b2aebd7b714861d2fede4d4929f356363e518385fd3c95e3262524631
SHA3 bbf9f4f071095b27e2349d9a28e1c01b5066c00143b8c5f7a393d2267f8178a5
VirtualSize 0xc54
VirtualAddress 0x17000
SizeOfRawData 0xe00
PointerToRawData 0x14000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.34687

_RDATA

MD5 1960efd573f3d23522c840210d59fb7e
SHA1 47057bb39ae6c80b68d90c47f0cfd7d6bf123ad2
SHA256 ad5bd98e9035110e2e2e7b82ed2fe49ec0fae2d89e05400528a6b48804c441a4
SHA3 225389cba41c0a9e2c3319b0921ec1ef9962e8af175fca30c67bde60763834d4
VirtualSize 0x94
VirtualAddress 0x18000
SizeOfRawData 0x200
PointerToRawData 0x14e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 1.08512

.rsrc

MD5 9954a81d5c27b3a91f99d3b55cc5ea7c
SHA1 d28e956f96a16d074da3974b8968369798970e65
SHA256 fc8d2d6b5f19dd0011468c51dbf80cff298c20826a4f7f1f089a3448ce190c38
SHA3 37fb020b05f61dcf80def904dc81ad334cde457eb4bdbdc956ad2a79a08f8013
VirtualSize 0x8a198
VirtualAddress 0x19000
SizeOfRawData 0x8a200
PointerToRawData 0x15000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.73384

.reloc

MD5 687aa942cda2e64adc67a829f1587240
SHA1 26058e365b4fef9cae39c529017700cd0ccfedb7
SHA256 e5b51406ab27a5065a374454ac72e242a50072d670957430f820af90f479b506
SHA3 8a51aae6ca0ea13d9513cba0336e2446957914c5ba6561a337c3afdf42f3c689
VirtualSize 0x638
VirtualAddress 0xa4000
SizeOfRawData 0x800
PointerToRawData 0x9f200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 4.79086

Imports

UnityPlayer.dll UnityMain
KERNEL32.dll WriteConsoleW
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
IsDebuggerPresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetStartupInfoW
IsProcessorFeaturePresent
GetModuleHandleW
CloseHandle
RtlUnwindEx
GetLastError
SetLastError
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
GetProcAddress
LoadLibraryExW
RaiseException
GetStdHandle
WriteFile
GetModuleFileNameW
GetCurrentProcess
ExitProcess
TerminateProcess
GetModuleHandleExW
HeapAlloc
HeapFree
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
GetCommandLineA
GetCommandLineW
MultiByteToWideChar
WideCharToMultiByte
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetStdHandle
GetFileType
GetStringTypeW
LCMapStringW
GetProcessHeap
HeapSize
HeapReAlloc
FlushFileBuffers
GetConsoleCP
GetConsoleMode
SetFilePointerEx
CreateFileW

Delayed Imports

AmdPowerXpressRequestHighPerformance

Ordinal 1
Address 0x15004

NvOptimusEnablement

Ordinal 2
Address 0x15000

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x42028
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.58062
MD5 9f215fa2d04e7a266eec093271822dc6
SHA1 9a67ebd99ce2d4d4b2a0dfe5dbc1d1dc3b53a187
SHA256 6cd1b343c69727d4dc21d2c55b29a9d1ab53ef58c39c034fcde288ff315ee69e
SHA3 98bb6b811de364ae695797ad90f4ae258125a49feaf3a291d9b331b742cfe3cc

2

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.68605
MD5 1be9cc38ddbd3b6e6818b592be2f03ed
SHA1 b99aff71bdf4db7ed008675a6650aa4983bdfe9c
SHA256 13763b98c2a53a2929d6bd00dc31591d1ac5982ea8317b2947d7f20a980a9675
SHA3 d4856776f07a88961470df9cb3335c7d1dfa3461308e4ad51f488ecca8bb186d

3

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10828
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.83214
MD5 1738535af615f8d9a4435a97ff98efb4
SHA1 b37be32e923ec9166d2d187195309156b9738e19
SHA256 d0f2f0dc581cd42f7ff5a125e9679bca01a0657d8549d8d494f5e32aced090d7
SHA3 0131b08466df5beeb549433e14d62054f8ac6bdfbc426aa1b2713ecb570e637f

4

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x94a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.95214
MD5 dfe94013289349b17108fde47d83b938
SHA1 0dbb6ce0f3f9bc4f597e68b5255c980829f3fb5b
SHA256 25eeddae49be0eb344ecd23567cd0681070499598edaa5dab4456af6cb183d7c
SHA3 f484823327c279cfcb4d1be549d9eb13f8249b2bdb13826d2490a6bdcc9925de

5

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x4228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.17776
MD5 03c8c0e28fbe2e09285360a1cc9da525
SHA1 16f532efd1b78036a5e013c731ea571f57c13f41
SHA256 cd9e6f0ebf564e9bb2cdd3b1229d2b20e9719c838bef68ac8aec8cf634c750e0
SHA3 bf7d8ac69b874e0d24bcb31664edda12e7b3cfb75dd8b689294ea91e46c04e44

6

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.33984
MD5 02131614d8e7de130eab05f83ba05c21
SHA1 02f6c40997d4771fac56fc0b3c4d451b10b1eee9
SHA256 5e49ee089b43a24a5229426688fca09fbaa1c8df92f6c5c672ab336c26e0fe49
SHA3 3c2e8537168d4d16bcf5f08c78a462020d18bb513f410210de3775e3e97b5940

7

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.57723
MD5 9882c354a38ba03a126c28049bec63c3
SHA1 9f50117e1f628417aaa5afeb76029d6dd26ba73f
SHA256 2b05b5730e5d6ee6ab903adb6ee0e3dde26f527b69e1aff8b5806c89cdb14fd6
SHA3 0e47bb1185867047002a05b3658a62d31ec5120a13b4b20e571b1b8263331965

8

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x988
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.62354
MD5 f2a0ef307192a4f7ef54a7e48b6eed79
SHA1 1dd2a369ece8ce7103955e4df7c4032a7cff3157
SHA256 f27f8be9bdf084f978a072774976d6dbf13dfbf93da7ab99c8ecb06516406aca
SHA3 5756a8adb8345450a76a17fed6d212a8f85374dc315b600bb7fdf09e0dc16bd9

9

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.52238
MD5 d1b88820d49ada068ad4e492fb09c74b
SHA1 e0a2ba7acf7bf2d2f43676d8e6d94ce0812099aa
SHA256 f1c87e3b9b827051182f8efbf064929fe4336eb62c0800c51172fefbe504bc6e
SHA3 5d5b2d78cd2af2768f222af9b120e1c4ae46554f1b8ac1f07ac5b95e19e1d817

103

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x84
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.04448
Detected Filetype Icon file
MD5 f7731730720cfe035cf030b40d0e2eb6
SHA1 d046e23f2ee2b93ad96be8e1dc9120ecf3915091
SHA256 5c92a41adaf3265071482fd1a182ae8702c168636a7d9ff51798ee3a1dfc8500
SHA3 6f2d12e4c63c131a3f7f48293996e2be05da351536d013affe5d2265965ce657

1 (#2)

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x210
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.56276
MD5 f9c3ee8b26914415826e025fb49e2bf0
SHA1 a11e12599683af88fc9cee2127de3ae1e36f5b7c
SHA256 01efa3675ccae1a659cd8e560838109f5236853661a2f017df7af60fb1008892
SHA3 eb4b39ac9b38b4dbbd944fb719748448f860424e6803ace4d727560e74f94b2d

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x6c1
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.37708
MD5 aab7e8aafe7b06ab3d003b54ab5e18ed
SHA1 dccf0408f43059df37b755f3241a8b4b35c728af
SHA256 fb88b19523afd8fed48eddfd10805a3a0a45997bbf8fac04d595ddf93c1a88a8
SHA3 a981b8e907b79cd9448766ace938dfd96560d11c29e6ba165912a8508bd52ca7

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 2021.3.45.43167
ProductVersion 2021.3.45.43167
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_UNKNOWN
Language English - United States
FileVersion (#2) 2021.3.45.895135
LegalCopyright (c) 2005-2024 Unity Technologies. All rights reserved.
ProductVersion (#2) 2021.3.45f1 (0da89fac8e79)
Resource LangID English - United States

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2024-Oct-12 16:54:51
Version 0.0
SizeofData 143
AddressOfRawData 0x13780
PointerToRawData 0x11d80
Referenced File C:\build\output\unity\unity\artifacts\WindowsPlayer\Win64_VS2019_nondev_i_r\WindowsPlayer_player_Master_il2cpp_x64.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2024-Oct-12 16:54:51
Version 0.0
SizeofData 20
AddressOfRawData 0x13810
PointerToRawData 0x11e10

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2024-Oct-12 16:54:51
Version 0.0
SizeofData 712
AddressOfRawData 0x13824
PointerToRawData 0x11e24

TLS Callbacks

Load Configuration

Size 0x138
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x140015030

RICH Header

XOR Key 0x735735a6
Unmarked objects 0
C objects (VS2017 v14.15 compiler 26715) 10
ASM objects (VS2017 v14.15 compiler 26715) 5
C++ objects (VS2017 v14.15 compiler 26715) 136
Imports (VS2017 v14.15 compiler 26715) 2
C++ objects (VS 2015/2017/2019 runtime 29118) 37
C objects (VS 2015/2017/2019 runtime 29118) 16
ASM objects (VS 2015/2017/2019 runtime 29118) 9
Imports (VS2019 Update 8 (16.8.0-1) compiler 29333) 3
Total imports 85
C++ objects (VS2019 Update 8 (16.8.0-1) compiler 29333) 3
Exports (VS2019 Update 8 (16.8.0-1) compiler 29333) 1
Resource objects (VS2019 Update 8 (16.8.0-1) compiler 29333) 1
Linker (VS2019 Update 8 (16.8.0-1) compiler 29333) 1

Errors

Leave a comment

No comments yet.