d4b3bb76f7cd463a49d701ca8e8fdf5987a2a522a92c98e09379ae5230494b3a

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2022-Jan-24 19:43:42
Detected languages English - United States
Debug artifacts C:\buildslave\unity\build\artifacts\WindowsPlayer\Win64_nondev_m_r\WindowsPlayer_Master_mono_x64.pdb
FileVersion 2019.4.35.287296
ProductVersion 2019.4.35.287296
Unity Version 2019.4.35f1_0462406dff2e

Plugin Output

Info The PE contains common functions which appear in legitimate applications. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryExW
Suspicious The PE is possibly a dropper. Resources amount for 86.7871% of the executable.
Safe VirusTotal score: 0/71 (Scanned on 2026-03-26 14:54:44) All the AVs think this file is safe.

Hashes

MD5 7aba35a6748ebabff16a157155cf4834
SHA1 dab8bd92ae75f755beb68efbbf7970624570f306
SHA256 d4b3bb76f7cd463a49d701ca8e8fdf5987a2a522a92c98e09379ae5230494b3a
SHA3 85f9dc41b7f04639cd0d791d6d5ac55f478411612a5ec6ac1da3c529d6432a96
SSDeep 6144:7/7oYfSHQPWTUg4wZ5rWBy3rwWPw2yC7s2:b7qTUg3yErwWd
Imports Hash fd60dddc87379c239e8ac49516966c3e

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x110

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 6
TimeDateStamp 2022-Jan-24 19:43:42
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x9e00
SizeOfInitializedData 0x95e00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000001260 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0xa3000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 396787b09c7084619fd353ed4d4aa25a
SHA1 10bbf1d12fd72a6f2490dae0fb34b3e3c37d0397
SHA256 84c4f4af681e7c55e04955e3244214c6a39406c9ff283dac14b45179c7344fd2
SHA3 2dbc41d4fcc7f9459799c1f273cc7d0b29a65a800004b70b2d8024daf74dfc23
VirtualSize 0x9d70
VirtualAddress 0x1000
SizeOfRawData 0x9e00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.39606

.rdata

MD5 8c7cb6707f8d0c07ebbf87f3a83b6a42
SHA1 4be8ef52fc250d101f45fb2faddb21e273a9be4a
SHA256 1322b09e9a8efdda6dfb939890210904762ec6fab86b1903723156d03254d8ca
SHA3 9374a5bc46dd5ca6baf0055a5f037e03b296038357c6df6ddc8aa3622c3a1d0e
VirtualSize 0x88de
VirtualAddress 0xb000
SizeOfRawData 0x8a00
PointerToRawData 0xa200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.72586

.data

MD5 db32eedebac3d09a8db683fdd7266183
SHA1 9d3ad2e8f784250c149bc0545875f3347c1e07d5
SHA256 63a977bb7df30209d66ab0ee3c2587394d2d84b87cfabab13902a80a9f8ac2bb
SHA3 f60fb1eaea0dc406d8fd8219c5b9519256c10cea02ce9801f2b262cdde729c42
VirtualSize 0x1bc8
VirtualAddress 0x14000
SizeOfRawData 0xa00
PointerToRawData 0x12c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 1.81338

.pdata

MD5 3ce1bc4528abab2f9296f6de2d66eb13
SHA1 236a9014dd4163c9bea0d3216c4339b71336ac60
SHA256 846c816328ade2f569bd6d1755940b260f0c1dc44653c50fa0b693d81cdc395f
SHA3 78586f62c74b7328c23e5e427db6af1753665224f815fabb19547b4c15db1d67
VirtualSize 0xc18
VirtualAddress 0x16000
SizeOfRawData 0xe00
PointerToRawData 0x13600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.30914

.rsrc

MD5 4f058d41e1f12b00a23b01cc8b9e57b4
SHA1 b9754568f312de94c947ab743d1f531538000789
SHA256 f67ef0a382acfdbf178878246ada9dac27207dc8bb8fe5f74b2f65c4e21c60ba
SHA3 d2733a1ac8ac69ca534d63fc85e3098bd4f559fc498a55f00390d287144945f9
VirtualSize 0x8a0d8
VirtualAddress 0x17000
SizeOfRawData 0x8a200
PointerToRawData 0x14400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 3.08531

.reloc

MD5 15c60be0054361c5f282b9c542c4b5cd
SHA1 3414732e68613e7ee32812f73810341e1aa3c9b2
SHA256 1597710aaca61843fdb13da316d06290830148f7e34074bef548abcbffa3b72c
SHA3 dba1e0d3f98cd89e8c35eb26f42dfaa9d0746b81262aa44f970150cf3cd45691
VirtualSize 0x614
VirtualAddress 0xa2000
SizeOfRawData 0x800
PointerToRawData 0x9e600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 4.75713

Imports

UnityPlayer.dll UnityMain
KERNEL32.dll GetModuleHandleExW
WriteConsoleW
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
IsDebuggerPresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetStartupInfoW
IsProcessorFeaturePresent
GetModuleHandleW
CloseHandle
RtlUnwindEx
GetLastError
SetLastError
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
GetProcAddress
LoadLibraryExW
RaiseException
GetStdHandle
WriteFile
GetModuleFileNameW
GetCurrentProcess
ExitProcess
TerminateProcess
HeapAlloc
HeapFree
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
GetCommandLineA
GetCommandLineW
MultiByteToWideChar
WideCharToMultiByte
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetStdHandle
GetFileType
GetStringTypeW
LCMapStringW
GetProcessHeap
HeapSize
HeapReAlloc
FlushFileBuffers
GetConsoleCP
GetConsoleMode
SetFilePointerEx
CreateFileW

Delayed Imports

AmdPowerXpressRequestHighPerformance

Ordinal 1
Address 0x14004

NvOptimusEnablement

Ordinal 2
Address 0x14000

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x42028
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.98882
MD5 67d37717d0359e1091ac9164fbe59a14
SHA1 a0e8cbdc8c20bf01326db5d53949a44c7e92a306
SHA256 39426ba3f037bb06e4b2e7874a822d54fea8ba0af65f4f641837e533d7de7905
SHA3 3eb15c79bbd3e409e59ec65b40f99af3db46710dc252aa3968e461b16a3deb6b

2

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.03009
MD5 f67fa6bbec2d0de10a70e04b7b0ea075
SHA1 b61c6d10bacd2a9409744534fbc36533da8423cf
SHA256 e2fe6b13ac4deb26c7fe13f3bc4aec4271a9c5ee4f1b4b2010461f24516f6b94
SHA3 b388caed8ba03f77ee168946383250de846d06b065fc6de3b14791f09d9fd80b

3

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10828
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.09396
MD5 413a4e3ca36a583a6a7df838daeb1523
SHA1 946617105cd1901604a212917e7aae686cecf271
SHA256 0f322c8631f0f564d40a739f57a93e34d98147b66ebcac1aa3006e755f7b9261
SHA3 a8003bf9103fe9d53c499868b0b2b664e96c0c293cbaf120891c841dd98fa9fd

4

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x94a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.1808
MD5 8dd25f1fe05319dc41007bdbdb024838
SHA1 8eda344ab70bc63fcf17df886d2845b9f117ac65
SHA256 d1618e5e6df99d325172d1a9fe3d7fabadbe4f3dc0f8fea99083ddc90a02d9a7
SHA3 1d1dac6a2de210817f945b190559b4d4a556347aa62ca1b7ec1a315968f6f8ed

5

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x4228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.30754
MD5 a8ed41f05610271c81bcad2c22a4cf68
SHA1 5e4fec10506f58bf78a81049bdb94c936ec48654
SHA256 3e1ba236641a71db63a537f28a7a6afabb84e26035aabbd74d07252a557ff0af
SHA3 d4bf56dfd0f50c3b625000c5d8c1f18c15f9969b4a29bdea5272ec54ddd68ce5

6

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.39446
MD5 f523c80ceccfcb940fe1b649335656be
SHA1 78003cfd44f04c3a980ea8682d89fc90e7fbd630
SHA256 ce9e5f5b5b1e198523a848783d5acd6fe9b344fdf80b1f189f1418df5bbfe1b7
SHA3 0676e37ddb7cbc8f18384dc21573a331ba5ee470077bbb1d721eef966fd033f4

7

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.65196
MD5 97a5cecaea1460ae20b8c7a71a65896e
SHA1 69f1d254e3427eefa88f2f1a92998f4670225cc4
SHA256 d3e7a397e0a1ea6fd7cda31c6ccd7f4000fae55ae87e0099801987ae76d71e80
SHA3 0b9f828fc198f12cc435b1ee6f66965b81843fa33f927ddf98d8a740b56c6cd4

8

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x988
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.85351
MD5 415afe7d10f7e5787b003bb96b216f1e
SHA1 a6161451b92772f003e8eb45f8280a84a2bfebf9
SHA256 1fc0b9f9a9ad7189f6a5a79fa144636f72c0e41a4cbeb0d95441433f3a09e492
SHA3 9f1cf2a4e77ebbf3ceaadb875d9c43fc679834f840db799e2eed93b644c6b447

9

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.0976
MD5 d4154d9f74afa61b06e5a1ecb0b58d02
SHA1 6909324a2191c38fa0fafb6bb15e21067f58b6c6
SHA256 f07d153e9890a0d52a21b21b6639528a7ed104ae355d2322a469d3a7963c2a45
SHA3 82de9946bb9c3ccf5aaf33affa45e1e41c54a984ba5e5b0153e2e32fd9bd562e

103

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x84
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.04448
Detected Filetype Icon file
MD5 f7731730720cfe035cf030b40d0e2eb6
SHA1 d046e23f2ee2b93ad96be8e1dc9120ecf3915091
SHA256 5c92a41adaf3265071482fd1a182ae8702c168636a7d9ff51798ee3a1dfc8500
SHA3 6f2d12e4c63c131a3f7f48293996e2be05da351536d013affe5d2265965ce657

1 (#2)

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x1c0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.39436
MD5 1b5ef21170bdeb43a0206e122b49031d
SHA1 cd654c462bd5210888c9adf79d580d7fb62322d6
SHA256 85e4868bfe1b86621e8e0cae5aaeabd3f37f6d929a9340da76d00f42485254ae
SHA3 e4f8a8a29e67486b87459b370219661d357018cc12f6ebb06faaf8fbe0570a4e

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x655
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.37545
MD5 e64f0e3051453730fcd59e3487fff82c
SHA1 881f9506d98c7244ee2e6cc48de59fb5fe9394a0
SHA256 cc5206d924557aebbb34ea990bff63d51f03f95c9618f11ba16f5bd0d969f3b2
SHA3 e68e9754b0692216d6b7991ec0b28f737203d4f0979404b4bfd5728ed3214e3d

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 2019.4.35.25152
ProductVersion 2019.4.35.25152
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_UNKNOWN
Language English - United States
FileVersion (#2) 2019.4.35.287296
ProductVersion (#2) 2019.4.35.287296
Unity Version 2019.4.35f1_0462406dff2e
Resource LangID English - United States

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2022-Jan-24 19:43:42
Version 0.0
SizeofData 125
AddressOfRawData 0x123d0
PointerToRawData 0x115d0
Referenced File C:\buildslave\unity\build\artifacts\WindowsPlayer\Win64_nondev_m_r\WindowsPlayer_Master_mono_x64.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2022-Jan-24 19:43:42
Version 0.0
SizeofData 20
AddressOfRawData 0x12450
PointerToRawData 0x11650

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2022-Jan-24 19:43:42
Version 0.0
SizeofData 696
AddressOfRawData 0x12464
PointerToRawData 0x11664

TLS Callbacks

Load Configuration

Size 0x100
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x140014028

RICH Header

XOR Key 0x2a1ac2b2
Unmarked objects 0
C objects (VS2015/2017 runtime 25711) 10
ASM objects (VS2015/2017 runtime 25711) 5
C++ objects (VS2015/2017 runtime 25711) 141
Imports (VS2015/2017 runtime 25711) 2
C++ objects (VS 2015/2017 runtime 26706) 38
C objects (VS 2015/2017 runtime 26706) 16
ASM objects (VS 2015/2017 runtime 26706) 8
Imports (VS 2015/2017 runtime 27012) 3
Total imports 82
C++ objects (VS 2015/2017 runtime 27012) 2
Exports (VS 2015/2017 runtime 27012) 1
Resource objects (VS 2015/2017 runtime 27012) 1
Linker (VS 2015/2017 runtime 27012) 1

Errors

Leave a comment

No comments yet.