d98bd2961a66a3a549b04081aaff3397bae43227551b3312994ceb95a033862b

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2025-Sep-17 13:22:52
Detected languages English - United States
Debug artifacts C:\build\output\unity\unity\artifacts\WindowsPlayer\Win_x64_VS2022_VB_nondev_i_r\WindowsPlayer_player_Master_il2cpp_x64.pdb
FileVersion 6000.2.6.4869578
LegalCopyright (c) 2005-2025 Unity Technologies. All rights reserved.
ProductVersion 6000.2.6f2 (4a4dcaec6541)

Plugin Output

Info The PE contains common functions which appear in legitimate applications. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryExW
Suspicious The PE is possibly a dropper. Resources amount for 84.5615% of the executable.
Suspicious No VirusTotal score. This file has never been scanned on VirusTotal.

Hashes

MD5 1d2a65a8d647bbf5c45c2e5e8845a67f
SHA1 e76df1b998f500516f2a4642d9837c9e6c01512c
SHA256 d98bd2961a66a3a549b04081aaff3397bae43227551b3312994ceb95a033862b
SHA3 131ae5788cb69f3d430d0a1cadfc86e205a976e8c24377a58651beb6fda82ec9
SSDeep 12288:CtVwZpUhJU+5xgcEtDdiOUT8BLLoqdduf:C/pCjtDdYT8xLorf
Imports Hash a136217cdd3247ff6a8766561064ca0b

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x110

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 6
TimeDateStamp 2025-Sep-17 13:22:52
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0xce00
SizeOfInitializedData 0x97000
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000001264 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0xa7000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 457fb5274ed18adc024e01b603e258a4
SHA1 159fdb99c377edc82c57d34217a711578edb0e63
SHA256 336709c08beca21a675f029c2d588ac0cae8cc8f42422039cbb827b6284374e5
SHA3 7d6db62af5f0503638e32b2c5a2ebd94056e5e490598ebed73cb0495875d3499
VirtualSize 0xcdb0
VirtualAddress 0x1000
SizeOfRawData 0xce00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.45019

.rdata

MD5 f8d55f88803f218340b80eb3c9969b29
SHA1 6dcdeb027fdeb6973daadcc8ef63960bd7bf6be0
SHA256 638765f2d99233e40d0843c84cf60a68f333fa3ca078f99c1046ead51c373711
SHA3 87db75c68010e4773575b9248f7841c0fbcfbef548c52a325005659e7663b8e8
VirtualSize 0x977c
VirtualAddress 0xe000
SizeOfRawData 0x9800
PointerToRawData 0xd200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.69242

.data

MD5 0822db25bce65451a1219de812eea533
SHA1 bf4c918ff2184dfeba8cd4f98b21e11d75de05e7
SHA256 8987031a7fb9e9ffe2b44dad568693d86af933f2b44447b6f5c1159bd0750a79
SHA3 83fbc2d299cd2e5b71ce2f669f319b95fcab94178c620dd04d72a1071efde7b0
VirtualSize 0x1d88
VirtualAddress 0x18000
SizeOfRawData 0xc00
PointerToRawData 0x16a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 1.90767

.pdata

MD5 017f81338461c6b246bdb8ce1bf5fc08
SHA1 aa79861d4dea94c5fd283f1359435734dfb03517
SHA256 d1cc88f6e981b629ad1f47d33507ac8b71f82346871b690375752ffc69c6063d
SHA3 e197cfb7530afb455ed4ebbd26984d4562c62ea8c9c65f07f5d04c80970ee830
VirtualSize 0xec4
VirtualAddress 0x1a000
SizeOfRawData 0x1000
PointerToRawData 0x17600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.60208

.rsrc

MD5 3b7a31aae48656e2f5c1d6bb937dd78f
SHA1 6a367df05e2ef19fef645bf878ffae657b7bd624
SHA256 845b8cd5188b1a5919c87931a3c78730ee5700e5da4152f67401948edcb602e4
SHA3 2500b288bee8df887d63ab1f5ace4d43787099d4f21de299cdd520f191d45d81
VirtualSize 0x8a018
VirtualAddress 0x1b000
SizeOfRawData 0x8a200
PointerToRawData 0x18600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.503

.reloc

MD5 3ab8a3a955e5040e25556085e21a2be2
SHA1 f29b173f0ea430d70ff0803cbaa89fa1d4d024d9
SHA256 119eed3c019ffdb0bba4cee06b80d85e78a679f1bb17317cbb6a352bb4102d7a
SHA3 a5c3cb0725d2fd68e14265c6e03629d6270e73c1f049eb78b3e40b7b2535d802
VirtualSize 0x658
VirtualAddress 0xa6000
SizeOfRawData 0x800
PointerToRawData 0xa2800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 4.86735

Imports

UnityPlayer.dll UnityMain2
KERNEL32.dll HeapAlloc
WriteConsoleW
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
IsDebuggerPresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetStartupInfoW
IsProcessorFeaturePresent
GetModuleHandleW
CloseHandle
RtlUnwindEx
GetLastError
SetLastError
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
GetProcAddress
LoadLibraryExW
EncodePointer
RaiseException
RtlPcToFileHeader
GetStdHandle
WriteFile
GetModuleFileNameW
GetCurrentProcess
ExitProcess
TerminateProcess
GetModuleHandleExW
HeapFree
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
GetCommandLineA
GetCommandLineW
MultiByteToWideChar
WideCharToMultiByte
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetStdHandle
GetFileType
GetStringTypeW
FlsAlloc
FlsGetValue
FlsSetValue
FlsFree
LCMapStringW
GetProcessHeap
HeapSize
HeapReAlloc
FlushFileBuffers
GetConsoleOutputCP
GetConsoleMode
SetFilePointerEx
CreateFileW

Delayed Imports

AmdPowerXpressRequestHighPerformance

Ordinal 1
Address 0x18004

D3D12SDKPath

Ordinal 2
Address 0x18008

D3D12SDKVersion

Ordinal 3
Address 0xe320

NvOptimusEnablement

Ordinal 4
Address 0x18000

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.5109
MD5 8bce957434da6ebc656b75e6757cca99
SHA1 b4b9f132e5314a91682c1cc169684e681df544b9
SHA256 3f55265e09ce34fbe9bef46ab00a3b2ecc7821a5e261f21256065bbbcbb04f76
SHA3 bdea2ec26864535026bef85475dc0538e14376bac4bd6e0aae774d62180af34a

2

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x988
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.68463
MD5 5dd9b2c18850b09abac98885c85bc17d
SHA1 de39cc3e63ace0826443e58a47445f96abf27189
SHA256 bd03111aceb53f4625d167f1841bfa42d924468a87313e4329b771736c1a63c6
SHA3 bf14c37de9744b063479bf3ec3344e26f3acf2a2f14ac463d3e658d1e89dd2bc

3

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.74868
MD5 1b008942e31c67ab940e6210792b236a
SHA1 6ccdf58f1307face977a83ad06f3e17ac999a1a8
SHA256 ce8d4e097ab400c82c106e502e4ac4f6b233c1f9170fd40733c77fc371c102e0
SHA3 ec9419739667256a704f02ac8455d405ea4270523403f4dfca3151b4d8b2036b

4

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.70133
MD5 9ac151c23383fd0ba41eee59f3431745
SHA1 fd9c150be5c4bb49573843e3964a76c795d1cf2f
SHA256 e427857cb8865195b8e3510cbd746e63d9304876c61af9405754e7e390cc7f37
SHA3 2a9ac95b1445475dbc1ea2159874bc22dd6dae920001f893b3d8626327f261d4

5

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x4228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.70031
MD5 f3da5409146f7f4917748e690bcc5878
SHA1 d2fdb542f5cc40b4e735d679a675d886f15a0f26
SHA256 99c33442c4c945d4fdfd0697c05deffd62a666ccb469470d5233c5c21b1584b6
SHA3 e91cdb3a0f9397aabce0cb353446c23b5ad7799be3374d26b13819c7229e2b59

6

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x94a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.6793
MD5 606f2f5f6e017ea3b26ad9b2f194bb0d
SHA1 5150525f60c618043736bd6605b88ace5bf55e1b
SHA256 bbe8da014b106091872fe78f4b717994b23ddaf328d142d8bb031657daae2009
SHA3 0815c4c847e616863039f85208998b565d4dc40abe4008a516b4da3a2e4d8a1c

7

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10828
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.64363
MD5 cecc4bdc5e4cc064e3d1fb76be6a2fbe
SHA1 30c2e2b4c6e2fc1f1b16dcb8cf7a3d1404c4aa87
SHA256 f06948fe20a7fdadbbd7a5c3e2502f2fa3a7c204fc4d0a9531b15433eb048da3
SHA3 3732119487d109c27ecbc26e030dd07d1785529e83d657d9d678564d1e4127c7

8

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.60118
MD5 112d181fcbbdd68c72bdb39b513a1cfc
SHA1 3bb056d7824aa9095b2a1d86e376063b143031c5
SHA256 e12f5ca719e949754c5e9a3c8784170638b2dcb4830c6c5dc82461c515a6700d
SHA3 b54e638e82c4d3301bc98b88fb8c68ee0d861367ffdfccbefee4699f3010c3ec

9

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x42028
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.15891
MD5 e573ccce085e457f7cc21b73d2fd7afd
SHA1 3932f8c17d1db5f73a3aebb778bca06d752177e3
SHA256 b82aba523e9fef4c15e46368c7fe71b44e7a5b985d33a96b94b857f9f3b55524
SHA3 4696872aea20c7fdb0b160a69d33014b3a59987bcac7947a0e8c63e27eb35a73

103

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x84
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.04448
Detected Filetype Icon file
MD5 3bf2dac037ce87794e66ff7f054e913f
SHA1 52ca961fd37ad960905a681d1db5157508ef1602
SHA256 2a87b1f32c5d0435090c72c392b75394f706e5750eff64fd85d25e1c622ee581
SHA3 8454d3273522657b5926068082b2cb88f6dbf352e7e9568008c0e33c792f349b

1 (#2)

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x20c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.54399
MD5 4275a4136c6f7b44f16ed56a53a338fd
SHA1 c4c3730074b61b0b4badf299d6447ad364b7d7d5
SHA256 2a03cd50f50381ae902aeb2122281a0dd52c9c3ac08bf03a67fa1cb81bf2d349
SHA3 5d8386dd221f72895fb87e1339cef7da174a28c08a1bb80a3f78f717fb675497

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x545
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.24993
MD5 9df530c2f4fbe460da74e130d5d351a9
SHA1 f8719b6c74e0179556c1a18f214d6c1bbff8f823
SHA256 3c357bd1125971bda05bc59eaeca279da41715741e2535e9e75c94273b1c3a1f
SHA3 ce3dd46f87bd462f8730fca18daea6df444422f8d88b810aefbd7b2e62536dee

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 6000.2.6.19914
ProductVersion 6000.2.6.19914
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_UNKNOWN
Language English - United States
FileVersion (#2) 6000.2.6.4869578
LegalCopyright (c) 2005-2025 Unity Technologies. All rights reserved.
ProductVersion (#2) 6000.2.6f2 (4a4dcaec6541)
Resource LangID English - United States

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2025-Sep-17 13:22:52
Version 0.0
SizeofData 148
AddressOfRawData 0x15d68
PointerToRawData 0x14f68
Referenced File C:\build\output\unity\unity\artifacts\WindowsPlayer\Win_x64_VS2022_VB_nondev_i_r\WindowsPlayer_player_Master_il2cpp_x64.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2025-Sep-17 13:22:52
Version 0.0
SizeofData 20
AddressOfRawData 0x15dfc
PointerToRawData 0x14ffc

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2025-Sep-17 13:22:52
Version 0.0
SizeofData 836
AddressOfRawData 0x15e10
PointerToRawData 0x15010

TLS Callbacks

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x140018040

RICH Header

XOR Key 0x7914df52
Unmarked objects 0
ASM objects (28900) 5
C++ objects (28900) 138
C objects (28900) 10
Imports (28900) 2
ASM objects (34321) 9
C objects (34321) 16
C++ objects (34321) 40
Imports (34433) 3
Total imports 89
C++ objects (34433) 2
Exports (34433) 1
Resource objects (34433) 1
Linker (34433) 1

Errors

Leave a comment

No comments yet.