c6bf863c053f190fb633a6e429fd8d74fcc185ae5f42fade85903a4bb6201773

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2024-Sep-19 21:41:15
Detected languages English - United States
Debug artifacts C:\build\output\unity\unity\artifacts\WindowsPlayer\Win64_VS2019_nondev_m_r\WindowsPlayer_player_Master_mono_x64.pdb
FileVersion 2021.3.44.9752980
LegalCopyright (c) 2005-2024 Unity Technologies. All rights reserved.
ProductVersion 2021.3.44f1 (94d194ca434d)

Plugin Output

Info The PE contains common functions which appear in legitimate applications. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryExW
Suspicious The PE is possibly a dropper. Resources amount for 86.4081% of the executable.
Safe VirusTotal score: 0/71 (Scanned on 2025-12-06 04:31:35) All the AVs think this file is safe.

Hashes

MD5 4900030768189fd4aebe6f63c7796083
SHA1 faff2129ae9b416e6504d1243d8de26962260f2f
SHA256 c6bf863c053f190fb633a6e429fd8d74fcc185ae5f42fade85903a4bb6201773
SHA3 c79a9a52e01c04af0b3706bb4ab7899e5b15e6f8b86e9331203945c63a099b7a
SSDeep 6144:jEbaWnBUCG2Jo7MBi2jO0ahybJCgo65Q:joCCbosiv0ahybQv65Q
Imports Hash 5f74a5c747508e2822fdb9b687deaf42

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x118

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 7
TimeDateStamp 2024-Sep-19 21:41:15
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0xa200
SizeOfInitializedData 0x96600
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000001260 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0xa5000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 4190b7be9f5f4eb52c040a688e61a250
SHA1 ee3a1c75987c1b0e5e4ed015cbe0c92530bdad11
SHA256 7d92c29b88ce9a3c69a11f70fbc73e302f5d8d66766589406274d31e97ed920b
SHA3 0e04178fbb1a5d03ab267f800a38d342bb9f4a2bb6441604af8a9b52ecb4c4c6
VirtualSize 0xa140
VirtualAddress 0x1000
SizeOfRawData 0xa200
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.39724

.rdata

MD5 8635743dca9d85c402e45a3d2cf8fe23
SHA1 cb418d64824965a7b4c7c38947a51e6a6a002f4c
SHA256 dc4ac1b615cbcf8011b2d3c285f965a41e92518f0523b76e1d459ce22426bc3d
SHA3 47e949e8679b7595311457515d32d14e637d9c835e724ca9d9ec64edc43ad15c
VirtualSize 0x8cce
VirtualAddress 0xc000
SizeOfRawData 0x8e00
PointerToRawData 0xa600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.65348

.data

MD5 2e9924c581c86e57e2e2b0ac87e1aa45
SHA1 a1a176fc5c54e8c996a328e810c15c16cdb5b73d
SHA256 90b0d83be28bc06320f7b2ce10f056ecd17badc2e84e2b1533c0454096a1e5a0
SHA3 8c3bb6dfd1204e833639461f26a41ad45e7fa68dcdc97aa4908992d272dc2237
VirtualSize 0x1ce8
VirtualAddress 0x15000
SizeOfRawData 0xc00
PointerToRawData 0x13400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 1.6801

.pdata

MD5 2717431295e555cdae3fb602e2bd957e
SHA1 408d09336a1192e50edb78d3e7795fbc547ac381
SHA256 d927fd3b2aebd7b714861d2fede4d4929f356363e518385fd3c95e3262524631
SHA3 bbf9f4f071095b27e2349d9a28e1c01b5066c00143b8c5f7a393d2267f8178a5
VirtualSize 0xc54
VirtualAddress 0x17000
SizeOfRawData 0xe00
PointerToRawData 0x14000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.34687

_RDATA

MD5 1960efd573f3d23522c840210d59fb7e
SHA1 47057bb39ae6c80b68d90c47f0cfd7d6bf123ad2
SHA256 ad5bd98e9035110e2e2e7b82ed2fe49ec0fae2d89e05400528a6b48804c441a4
SHA3 225389cba41c0a9e2c3319b0921ec1ef9962e8af175fca30c67bde60763834d4
VirtualSize 0x94
VirtualAddress 0x18000
SizeOfRawData 0x200
PointerToRawData 0x14e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 1.08512

.rsrc

MD5 4adef4ff20466b8cbcd055813c86cca2
SHA1 a96dc96fcc7bc1cfa495200e3c978cd7c33aeaa5
SHA256 8420bb31bcd32743ee0005a0ddfa3e1c90dcba4bdbde2badbc149f3c5f00a06e
SHA3 38230526d6f44c9d57ec2085a04a6c6ae06614183d8ceab9f6cd985be5dab021
VirtualSize 0x8a198
VirtualAddress 0x19000
SizeOfRawData 0x8a200
PointerToRawData 0x15000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 2.39908

.reloc

MD5 687aa942cda2e64adc67a829f1587240
SHA1 26058e365b4fef9cae39c529017700cd0ccfedb7
SHA256 e5b51406ab27a5065a374454ac72e242a50072d670957430f820af90f479b506
SHA3 8a51aae6ca0ea13d9513cba0336e2446957914c5ba6561a337c3afdf42f3c689
VirtualSize 0x638
VirtualAddress 0xa4000
SizeOfRawData 0x800
PointerToRawData 0x9f200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 4.79086

Imports

UnityPlayer.dll UnityMain
KERNEL32.dll WriteConsoleW
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
IsDebuggerPresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetStartupInfoW
IsProcessorFeaturePresent
GetModuleHandleW
CloseHandle
RtlUnwindEx
GetLastError
SetLastError
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
GetProcAddress
LoadLibraryExW
RaiseException
GetStdHandle
WriteFile
GetModuleFileNameW
GetCurrentProcess
ExitProcess
TerminateProcess
GetModuleHandleExW
HeapAlloc
HeapFree
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
GetCommandLineA
GetCommandLineW
MultiByteToWideChar
WideCharToMultiByte
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetStdHandle
GetFileType
GetStringTypeW
LCMapStringW
GetProcessHeap
HeapSize
HeapReAlloc
FlushFileBuffers
GetConsoleCP
GetConsoleMode
SetFilePointerEx
CreateFileW

Delayed Imports

AmdPowerXpressRequestHighPerformance

Ordinal 1
Address 0x15004

NvOptimusEnablement

Ordinal 2
Address 0x15000

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x42028
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.28355
MD5 a347df66d3f1a7c9f41d29e8b1285629
SHA1 397b1577afc93c4e9e8026396ba45b955a2418de
SHA256 87c3fd5e2016c692b1c6cd972d00f3a05de9d894e2d2f01104fd4aaac25a64e6
SHA3 75221a5b919872de8e08a63e10242a037e387170c69ad4f32e629524e961ace3

2

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.33859
MD5 355d0ea15436f86a45e9e55488b3560e
SHA1 c7e9e60b3b38171e37e750183f3d5d6e60a635af
SHA256 38c1c370a2332126202ef4f3857e829640a3b2b6e57ef2db71ec311c0f2873ec
SHA3 6300268bcb5062318b1be7f713ca0535474988d7ecfcce383b029e13c2be12b5

3

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10828
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.4082
MD5 d3ee29ad6b384ffa8db74adb7ae5360c
SHA1 7f3eda40493fa1f5ad39d4cddf4bf1e2ce481682
SHA256 a49705c4c47f362724ab38fc4461007b36c9782c86eceeed6cb795f02f6ad8c0
SHA3 e526265d3ca315ffb2e32464a910ee7d78c19331a9260494bb6fdf7ed50d892c

4

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x94a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.47519
MD5 ac0746ea72d91deac6f099885509e769
SHA1 26f3e3298d8021950b11b09a1ca1c2adac6e7114
SHA256 489afa4f3d93a7eb9f0cb9b9319920c255503d775e1dcede9720648a34524e14
SHA3 26a989c4f58a281fbc06b226133b59464408b45a23a12f58055c645f7a0dacd0

5

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x4228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.57917
MD5 5f5027e7e6e121453324adea355e41d1
SHA1 ee4153276a6b89b1243a110164c48615aa7735eb
SHA256 b0dda340f9ba7681a33a8fb4f1e94cf4be006637b3613ef60ed13ced6f119dad
SHA3 c840d59a894aeabb4a9c510ff72d8609bb913a4e2571933cbaf09106d844ee25

6

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.68527
MD5 3a11d1172c811ee93e8f4e7601e8aaa3
SHA1 ea497e618afb8c467447643ac1347f45113a63b7
SHA256 de0e6af8df5fe6c2f56c5a3de4429378719fa4f93aac406358ded491929f54c2
SHA3 81f467537cf6965b7bd1e0875a9319ead908885a46db593e734d3265a9b51c63

7

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.90219
MD5 c6ce3c41ceeb6f3c5cf6f9aae0666cc9
SHA1 683722edef0c4b1196c8d2b896ddcf87aedc47bc
SHA256 112b9ba83dde5d38ce28568a2889a514738e67d8ab5d8901e39f5aa2f87c3ceb
SHA3 c4825ec461f9e2298567c780b46546cb97c598b1c02f8d596d18034931d1a71c

8

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x988
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.00137
MD5 78a32fccc39e895ceacc16e578531d7f
SHA1 9b30fff66077bd59907c675e3292e1fdac573865
SHA256 9bc96a16d6ed7b85213798adfec1d206e8426573deb6135caaac4c5db0d64c36
SHA3 8d85418d8286d2350173ce42c6364583254c2a8bbd11741142943a3c7be405f1

9

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.15886
MD5 b9ac0e8f13347344cec5de993c52e4a6
SHA1 eed9e42711b16808cc4752df734590c22a23f033
SHA256 e805ea67f5449eb3df5ead6664aaf1a8f478e91972dd202bca0f62a4d38e1490
SHA3 b5a4484bf71d5cf29ec68edf3521b472384c315d89d5a9caa5908c3b6e629d42

103

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x84
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.04448
Detected Filetype Icon file
MD5 f7731730720cfe035cf030b40d0e2eb6
SHA1 d046e23f2ee2b93ad96be8e1dc9120ecf3915091
SHA256 5c92a41adaf3265071482fd1a182ae8702c168636a7d9ff51798ee3a1dfc8500
SHA3 6f2d12e4c63c131a3f7f48293996e2be05da351536d013affe5d2265965ce657

1 (#2)

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x210
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.55922
MD5 8f8d910583e338eb822344d2cdaab002
SHA1 fd140b64497478804dd2bb848c7fe56100e654e6
SHA256 58103ff277da5830aec5cd7e4b525c2fec65b533a16654114acaac9753b7574a
SHA3 fb2f2c05d42b69ecc33be19b53973a117b078e6a371d971529ca629a12905015

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x6c1
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.37708
MD5 aab7e8aafe7b06ab3d003b54ab5e18ed
SHA1 dccf0408f43059df37b755f3241a8b4b35c728af
SHA256 fb88b19523afd8fed48eddfd10805a3a0a45997bbf8fac04d595ddf93c1a88a8
SHA3 a981b8e907b79cd9448766ace938dfd96560d11c29e6ba165912a8508bd52ca7

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 2021.3.44.53652
ProductVersion 2021.3.44.53652
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_UNKNOWN
Language English - United States
FileVersion (#2) 2021.3.44.9752980
LegalCopyright (c) 2005-2024 Unity Technologies. All rights reserved.
ProductVersion (#2) 2021.3.44f1 (94d194ca434d)
Resource LangID English - United States

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2024-Sep-19 21:41:15
Version 0.0
SizeofData 141
AddressOfRawData 0x13780
PointerToRawData 0x11d80
Referenced File C:\build\output\unity\unity\artifacts\WindowsPlayer\Win64_VS2019_nondev_m_r\WindowsPlayer_player_Master_mono_x64.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2024-Sep-19 21:41:15
Version 0.0
SizeofData 20
AddressOfRawData 0x13810
PointerToRawData 0x11e10

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2024-Sep-19 21:41:15
Version 0.0
SizeofData 712
AddressOfRawData 0x13824
PointerToRawData 0x11e24

TLS Callbacks

Load Configuration

Size 0x138
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x140015030

RICH Header

XOR Key 0x735735a6
Unmarked objects 0
C objects (VS2017 v14.15 compiler 26715) 10
ASM objects (VS2017 v14.15 compiler 26715) 5
C++ objects (VS2017 v14.15 compiler 26715) 136
Imports (VS2017 v14.15 compiler 26715) 2
C++ objects (VS 2015/2017/2019 runtime 29118) 37
C objects (VS 2015/2017/2019 runtime 29118) 16
ASM objects (VS 2015/2017/2019 runtime 29118) 9
Imports (VS2019 Update 8 (16.8.0-1) compiler 29333) 3
Total imports 85
C++ objects (VS2019 Update 8 (16.8.0-1) compiler 29333) 3
Exports (VS2019 Update 8 (16.8.0-1) compiler 29333) 1
Resource objects (VS2019 Update 8 (16.8.0-1) compiler 29333) 1
Linker (VS2019 Update 8 (16.8.0-1) compiler 29333) 1

Errors

Leave a comment

No comments yet.