da25e41103de64e0c3b5bfe0b146545cce09b194fa98a0f03876ed92c0159f74

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2020-Sep-22 13:40:52
Detected languages English - United States
Debug artifacts C:\buildslave\unity\build\artifacts\WindowsPlayer\Win64_nondev_m_r\WindowsPlayer_Master_mono_x64.pdb
FileVersion 2019.4.11.2988036
ProductVersion 2019.4.11.2988036
Unity Version 2019.4.11f1_2d9804dddde7

Plugin Output

Info The PE contains common functions which appear in legitimate applications. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryExW
Suspicious The PE is possibly a dropper. Resources amount for 86.7871% of the executable.
Safe VirusTotal score: 0/69 (Scanned on 2023-02-25 15:28:52) All the AVs think this file is safe.

Hashes

MD5 687b554af6664e0aa8f592acaa1e3c9b
SHA1 861c6595ea05643a7d15ffad107ce10e52b04d23
SHA256 da25e41103de64e0c3b5bfe0b146545cce09b194fa98a0f03876ed92c0159f74
SHA3 c471c310b97deb38ff0b61d2d4231272125355230f63bd6ad49371a66423aff6
SSDeep 3072:2ys7oYfSbbQTLWuiUg7VsS4jMsN0m7jLGb6:2/7oYfSHQPWTUg42m7jLGb6
Imports Hash fd60dddc87379c239e8ac49516966c3e

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x110

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 6
TimeDateStamp 2020-Sep-22 13:40:52
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x9e00
SizeOfInitializedData 0x95e00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000001260 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0xa3000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 396787b09c7084619fd353ed4d4aa25a
SHA1 10bbf1d12fd72a6f2490dae0fb34b3e3c37d0397
SHA256 84c4f4af681e7c55e04955e3244214c6a39406c9ff283dac14b45179c7344fd2
SHA3 2dbc41d4fcc7f9459799c1f273cc7d0b29a65a800004b70b2d8024daf74dfc23
VirtualSize 0x9d70
VirtualAddress 0x1000
SizeOfRawData 0x9e00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.39606

.rdata

MD5 83965db3e0c9a9772f900dedac5e36ae
SHA1 d00ee8a52003951bb4a226b26af4d69b5702ede3
SHA256 36cddf654fa8649b47ac26a9708eed748eb61c9030d2e9d67664ab36df2fb0e1
SHA3 4eee95e08e51298b5eff31d7f2efe26cc443c154fe89f4dcfdb53ed5902c20f0
VirtualSize 0x88de
VirtualAddress 0xb000
SizeOfRawData 0x8a00
PointerToRawData 0xa200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.72632

.data

MD5 db32eedebac3d09a8db683fdd7266183
SHA1 9d3ad2e8f784250c149bc0545875f3347c1e07d5
SHA256 63a977bb7df30209d66ab0ee3c2587394d2d84b87cfabab13902a80a9f8ac2bb
SHA3 f60fb1eaea0dc406d8fd8219c5b9519256c10cea02ce9801f2b262cdde729c42
VirtualSize 0x1bc8
VirtualAddress 0x14000
SizeOfRawData 0xa00
PointerToRawData 0x12c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 1.81338

.pdata

MD5 3ce1bc4528abab2f9296f6de2d66eb13
SHA1 236a9014dd4163c9bea0d3216c4339b71336ac60
SHA256 846c816328ade2f569bd6d1755940b260f0c1dc44653c50fa0b693d81cdc395f
SHA3 78586f62c74b7328c23e5e427db6af1753665224f815fabb19547b4c15db1d67
VirtualSize 0xc18
VirtualAddress 0x16000
SizeOfRawData 0xe00
PointerToRawData 0x13600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.30914

.rsrc

MD5 24ae80ea76788d9f1a04bc0471777dbf
SHA1 bb326e0e3645666b05e4a36f340326e7fce0f712
SHA256 99ae2b4edd9fab30bc63acdb3536c10a83dfd0cbd05dab6172482d0fc38e2cfd
SHA3 fee763b20cb59430dc970a31f347a76ab1e5330c52dfe8e8f34d802357da5b26
VirtualSize 0x8a0d8
VirtualAddress 0x17000
SizeOfRawData 0x8a200
PointerToRawData 0x14400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 1.32431

.reloc

MD5 15c60be0054361c5f282b9c542c4b5cd
SHA1 3414732e68613e7ee32812f73810341e1aa3c9b2
SHA256 1597710aaca61843fdb13da316d06290830148f7e34074bef548abcbffa3b72c
SHA3 dba1e0d3f98cd89e8c35eb26f42dfaa9d0746b81262aa44f970150cf3cd45691
VirtualSize 0x614
VirtualAddress 0xa2000
SizeOfRawData 0x800
PointerToRawData 0x9e600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 4.75713

Imports

UnityPlayer.dll UnityMain
KERNEL32.dll GetModuleHandleExW
WriteConsoleW
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
IsDebuggerPresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetStartupInfoW
IsProcessorFeaturePresent
GetModuleHandleW
CloseHandle
RtlUnwindEx
GetLastError
SetLastError
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
GetProcAddress
LoadLibraryExW
RaiseException
GetStdHandle
WriteFile
GetModuleFileNameW
GetCurrentProcess
ExitProcess
TerminateProcess
HeapAlloc
HeapFree
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
GetCommandLineA
GetCommandLineW
MultiByteToWideChar
WideCharToMultiByte
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetStdHandle
GetFileType
GetStringTypeW
LCMapStringW
GetProcessHeap
HeapSize
HeapReAlloc
FlushFileBuffers
GetConsoleCP
GetConsoleMode
SetFilePointerEx
CreateFileW

Delayed Imports

AmdPowerXpressRequestHighPerformance

Ordinal 1
Address 0x14004

NvOptimusEnablement

Ordinal 2
Address 0x14000

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x42028
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.18632
MD5 e56ca460096b58e9d593feff93365827
SHA1 4884308693216600916331a8a4d4d629f918cf02
SHA256 93661bba6fe664bddd4a49779e9663356a5e80bb8de63a12e1141444f5d3a521
SHA3 6018fdf983c14e16736d0a8d523c31a1028fd4b89b9cd8e775f8135a0fc6ce47

2

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.22024
MD5 d29d212cf1392d03496711f51878be9b
SHA1 8842665e1e55b6ea1297b96b15aebd9feb7e402f
SHA256 d93b26971fd6c8a06d7cf23ecb6a88d2a2855d9d7016d45244747e04225a2bed
SHA3 8acc8495c620a3d7dcbd3de06ba7589018376cc74a8a91afcbce45b8af0535dd

3

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10828
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.33168
MD5 8c532e92b3b8563a419c391cc5237b3c
SHA1 075c4b23ac57416a7d919668e1fbbdffb904ec1b
SHA256 826076ccc93fea7457da63dcd8c5944621754b42006750a2868a1989d0879465
SHA3 8a3955b4735d1efc904dcfff607f33d62a52cce478ee830b6172c29dd134adcb

4

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x94a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.42174
MD5 6678fd92f040260714675f3b302678ec
SHA1 2f1971e8efd4f00031041603a190d7b8af1c8492
SHA256 65a853e29f8263e2394cc9f79aa498b0f1628dfc9f54c64b245f715afbc28eeb
SHA3 f5319662dcd3ed68e05fa2fe749393d6065d3f3c8451914b655872572ba9a021

5

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x4228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.55919
MD5 c261ea949419f50ba2302307be4de315
SHA1 92b17930f9604c984cd39162db4724055daf843e
SHA256 675ed916df03979fa0d8603b55a43dd14ebf38c67fc82fdbaca80d8cbcf4bed0
SHA3 53058ec1f97fc8fd9dfe2142d58a23a6993d1746f87a6c1ce9b2aa21b423bf9b

6

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.72175
MD5 11a88a215bda0cfefc087b8997bb7481
SHA1 f10e4fbd1f3067fca4d7646ee5234b0f7b2bba5c
SHA256 bcb3be603ed8582e65172fa2f9caa28316820cd2a7d58d09924cf63a26e16053
SHA3 5bba00eacfbc1043fae515afedd3c27f056f54a8456acbb5492614fb2e942479

7

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.03228
MD5 8908a3b6e77149ce3c16bec31835bfc3
SHA1 887fbc202fcb23fe8acbd257a2b62e8a3acf5141
SHA256 2abc60f9e2601c00875e29171d5cca5dca35b938ae8e742c6a998c05dcd20f1f
SHA3 554584fa86f3e57b939d9c029a09468790cd0ad560a950b6bde45e510a20dc48

8

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x988
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.24979
MD5 5974781f81e0be9434b55791be42ff71
SHA1 0304db13df82841d92953c469f9bbe1842efc632
SHA256 e0cf138dc41f4afe0581c6faadb44c1eec6453c2a13f3ba81c67e7b99b6d8025
SHA3 f5e7f4bec8385774ee1373adb0225ec7521024d05339d35cf7b927483200ab05

9

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.70933
MD5 a0e430dc67f48a76bd2ce5cbc14ddaac
SHA1 3ade1477114e11499ae912b184dd43b24a6ba9cb
SHA256 8caa993765f934547233f4734e719145a5ba35ed77d7ec266545ced283a5fa58
SHA3 904a9df603f39437cb8fe2dd0b0a40832bbcacbd275039499bba8326992cefba

103

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x84
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.04448
Detected Filetype Icon file
MD5 f7731730720cfe035cf030b40d0e2eb6
SHA1 d046e23f2ee2b93ad96be8e1dc9120ecf3915091
SHA256 5c92a41adaf3265071482fd1a182ae8702c168636a7d9ff51798ee3a1dfc8500
SHA3 6f2d12e4c63c131a3f7f48293996e2be05da351536d013affe5d2265965ce657

1 (#2)

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x1c0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.39183
MD5 96f21833376f0c074b3ef0291a073702
SHA1 15887355c143bf6b3c86a89f3b82c97c655ed2ca
SHA256 de5c86e9fcb78f8c542a9789eba793086be228449fa6ad1a6e7d0ad932d0309f
SHA3 769fedb4db376d21ff15561d4c0d3c1d067f8ce0715fd516a0cfce1311eb07eb

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x655
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.37545
MD5 e64f0e3051453730fcd59e3487fff82c
SHA1 881f9506d98c7244ee2e6cc48de59fb5fe9394a0
SHA256 cc5206d924557aebbb34ea990bff63d51f03f95c9618f11ba16f5bd0d969f3b2
SHA3 e68e9754b0692216d6b7991ec0b28f737203d4f0979404b4bfd5728ed3214e3d

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 2019.4.11.38916
ProductVersion 2019.4.11.38916
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_UNKNOWN
Language English - United States
FileVersion (#2) 2019.4.11.2988036
ProductVersion (#2) 2019.4.11.2988036
Unity Version 2019.4.11f1_2d9804dddde7
Resource LangID English - United States

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2020-Sep-22 13:40:52
Version 0.0
SizeofData 125
AddressOfRawData 0x123d0
PointerToRawData 0x115d0
Referenced File C:\buildslave\unity\build\artifacts\WindowsPlayer\Win64_nondev_m_r\WindowsPlayer_Master_mono_x64.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2020-Sep-22 13:40:52
Version 0.0
SizeofData 20
AddressOfRawData 0x12450
PointerToRawData 0x11650

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2020-Sep-22 13:40:52
Version 0.0
SizeofData 696
AddressOfRawData 0x12464
PointerToRawData 0x11664

TLS Callbacks

Load Configuration

Size 0x100
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x140014028

RICH Header

XOR Key 0x2a1ac2b2
Unmarked objects 0
C objects (VS2015/2017 runtime 25711) 10
ASM objects (VS2015/2017 runtime 25711) 5
C++ objects (VS2015/2017 runtime 25711) 141
Imports (VS2015/2017 runtime 25711) 2
C++ objects (VS 2015/2017 runtime 26706) 38
C objects (VS 2015/2017 runtime 26706) 16
ASM objects (VS 2015/2017 runtime 26706) 8
Imports (VS 2015/2017 runtime 27012) 3
Total imports 82
C++ objects (VS 2015/2017 runtime 27012) 2
Exports (VS 2015/2017 runtime 27012) 1
Resource objects (VS 2015/2017 runtime 27012) 1
Linker (VS 2015/2017 runtime 27012) 1

Errors

Leave a comment

No comments yet.