e9878043b8516261214a0a2d5b93799ad1e4f3c0cdfda4c2f55d62f7b0911a34

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2024-Apr-10 10:25:58
Detected languages English - United States
Debug artifacts C:\build\output\unity\unity\artifacts\WindowsPlayer\Win64_VS2019_nondev_m_r\WindowsPlayer_player_Master_mono_x64.pdb
FileVersion 2022.3.25.5442272
LegalCopyright (c) 2005-2024 Unity Technologies. All rights reserved.
ProductVersion 2022.3.25f1 (530ae0ba3889)

Plugin Output

Info The PE contains common functions which appear in legitimate applications. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryExW
Suspicious The PE is possibly a dropper. Resources amount for 84.749% of the executable.
Suspicious VirusTotal score: 1/70 (Scanned on 2026-05-03 10:22:14) Trapmine: suspicious.low.ml.score

Hashes

MD5 29e4335097afd43a39f2159f2def204d
SHA1 ec14ae0a019b66aa8c2bf50e4cc48ddcc9e33976
SHA256 e9878043b8516261214a0a2d5b93799ad1e4f3c0cdfda4c2f55d62f7b0911a34
SHA3 745201f3d9dc7b82513b3f05632f493b6f4b50c4b7e2abd4914e78e61a196514
SSDeep 12288:A/744aOD8g5kvnG4DccpH9ybYooEatudLxxCO3N0ALBA:y9aO7kvn5cUdyOEa6xxC4lA
Imports Hash ce1183cc150987a99aef5749f22af81e

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x110

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 7
TimeDateStamp 2024-Apr-10 10:25:58
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0xca00
SizeOfInitializedData 0x97000
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000001260 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0xa8000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 c908b9c0303dc1f82726ca4dae00b772
SHA1 e81e70cb017880d2883f88a85d9a5ba6176ebcc1
SHA256 6e577d9deae653a5181b5a961bc5d68133d0e0c5371dc8bf2e7a30f6ef4d5cb2
SHA3 deefbce421cada627162918879ac6eda8099d036762180ad5ebfb4cbd66be7e2
VirtualSize 0xc8b0
VirtualAddress 0x1000
SizeOfRawData 0xca00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.41078

.rdata

MD5 89330964ba8f8ccadae0af8aef7c211f
SHA1 90a23f71c05b77f222cd34c5364df4e1a958f349
SHA256 d0f03643ff4d65f9284a847b90ed5eff45a34ab11238863134db3f5cd48db6bd
SHA3 4d8d8e9ca23a9383a7c5d2067c35c6039ff5375fb2f4f4d6413909c1c5e41fef
VirtualSize 0x948a
VirtualAddress 0xe000
SizeOfRawData 0x9600
PointerToRawData 0xce00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.65293

.data

MD5 90815aa5dc65a7dd3f93bad1bd78a77e
SHA1 608f3e69047b216dda6b0df73c30912e2fef5544
SHA256 435cb9af1df25f501f68a9700182c4d25de99c3f8e8c1ba6b16c0ca98911ff87
SHA3 e5ea90d4dd767bfa3d88e3fa2e107c2e40cac10f43498d5abd74f15888477d18
VirtualSize 0x1d38
VirtualAddress 0x18000
SizeOfRawData 0xc00
PointerToRawData 0x16400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 1.87032

.pdata

MD5 c69bce38ac69d0b835120a5590e69f0c
SHA1 c063139b665bfd43ee632f0741b4b5279a71f404
SHA256 1d79cfdb10b0e6f61968ed084c55a6ae07421354bf9072b12d090926728f3852
SHA3 5b320838ebff98a9e30dc5b9258ca4079fcb7cde4304c61cfe2dd57bb750842e
VirtualSize 0xef4
VirtualAddress 0x1a000
SizeOfRawData 0x1000
PointerToRawData 0x17000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.62843

_RDATA

MD5 f87f407c2a1cab208757ad1d23a2de6f
SHA1 cd739c36958f9ba7505883ae868f1a6ca71e880f
SHA256 6e4ba525d12ef66132e0738191d3a928ba74c0091a6f82bc48f892a41e2fc242
SHA3 0611ad194d9c623281cb358dbc2f2d28bb01b6eab682677ec8d16136d74414ab
VirtualSize 0x94
VirtualAddress 0x1b000
SizeOfRawData 0x200
PointerToRawData 0x18000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 1.11888

.rsrc

MD5 5010ad8c32ca135bd3f31851d8d6970c
SHA1 fad5e5cb82fc693f98a318d81d5b4866bb97af9a
SHA256 bf7cd6ff457337b01daf80fc057852fdbd589daba12495192277e0a84451788b
SHA3 48b249cee3de186dea00559acf6409a0ecfd9bc9698231d85dfbf0222a07e9e6
VirtualSize 0x8a198
VirtualAddress 0x1c000
SizeOfRawData 0x8a200
PointerToRawData 0x18200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.37144

.reloc

MD5 ef1e558d46106d87320dd822be1ddc48
SHA1 10f7b05d107451bd01cf446da512c619fc35bf50
SHA256 34d7b771018e478ba05cd24ec377fd34919d65ec63c43f49e1ab319785368929
SHA3 cc295f58e62efe5c59cad1febf1ce620404450135f442c20ba55235b492ddac9
VirtualSize 0x654
VirtualAddress 0xa7000
SizeOfRawData 0x800
PointerToRawData 0xa2400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 4.84209

Imports

UnityPlayer.dll UnityMain
KERNEL32.dll HeapAlloc
WriteConsoleW
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
IsDebuggerPresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetStartupInfoW
IsProcessorFeaturePresent
GetModuleHandleW
CloseHandle
RtlUnwindEx
GetLastError
SetLastError
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
GetProcAddress
LoadLibraryExW
EncodePointer
RaiseException
RtlPcToFileHeader
GetStdHandle
WriteFile
GetModuleFileNameW
GetCurrentProcess
ExitProcess
TerminateProcess
GetModuleHandleExW
HeapFree
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
GetCommandLineA
GetCommandLineW
MultiByteToWideChar
WideCharToMultiByte
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetStdHandle
GetFileType
GetStringTypeW
FlsAlloc
FlsGetValue
FlsSetValue
FlsFree
LCMapStringW
GetProcessHeap
HeapSize
HeapReAlloc
FlushFileBuffers
GetConsoleOutputCP
GetConsoleMode
SetFilePointerEx
CreateFileW

Delayed Imports

AmdPowerXpressRequestHighPerformance

Ordinal 1
Address 0x18004

NvOptimusEnablement

Ordinal 2
Address 0x18000

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x42028
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.36577
MD5 5489367ce90b742f357a9edcc50704b4
SHA1 11e15588a2a1facd191aec5de754a149dff4e874
SHA256 742dc5b48f15235c593f9400dcc7b373a21b632867562cce31cf9b0776ee908e
SHA3 e776bbde8257fd79493bc1c3cc1c1ec361416ae51a8c8c22b0abb4e0bac97f06

2

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.36156
MD5 1d4e8fdc536f4382bf7b1f106ef3d4c6
SHA1 74a5cea7953caf4e7e775e465dc3646d779c3577
SHA256 0f959202a0c2252db66dde5ab17374afd81705841626dbf535c37a66928ed07f
SHA3 594e60260e8d03bbf52d6b179e92c110419ea289dbc0a255af1984e10a2f0d95

3

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10828
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.36244
MD5 c78b0a451f694c6f67c29bcaf42bf4d3
SHA1 44ab9dbf95cdf23267ea2761c22c4abcb8aa00f3
SHA256 b08b6148435d5eb1426bd6e1bbc4bcbd9b2f5695a88c786f8fc0df1498094498
SHA3 a163fea8a26b949f6b936ac73867ddcef14ad63617a4247df9a9a12c8533a1ed

4

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x94a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.36144
MD5 8fbde80df208c8e510eeddfe65ae96f9
SHA1 2f6c22d2be89c99da649ae2b40b254b2d9e6c611
SHA256 a3916cf19dc2e0085470304fb0f81d48e4710bf8cb134a51e3872b9b02eb9646
SHA3 662279026bf80c4f2028c26089371e94334f9c62173da64e8a8236a3378aff24

5

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x4228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.35636
MD5 a125f7aa25916f56b1570cf6fa9ff3c3
SHA1 9a314cde6c796e8567e144faba9290dad95e2a75
SHA256 2ca8602b2fc7a263e1f5549c48c64a0a114ac4cd42534cf0c0d9fe6078585250
SHA3 a50ad735fa37380a2281509dafae367eca6303005d226100cabfc41151ad3078

6

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.30887
MD5 7c226cfe018fed297d7091512acd65be
SHA1 c6b890762071b5c10aaf5ec701e39cd1a2f205ed
SHA256 17da80d0af82f8ef28995d6357e69346f7cf260387b52e6a74c13a6354bbfa6b
SHA3 b4ec4622010f17b4af718032f412da81d7467ad4abcd09c8d74b29ef8a178336

7

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.31876
MD5 374af6532ea48c4af597ec17f1e3ce4e
SHA1 23f8b5d676b03023dd21b1ec075b75e2a21ef1e6
SHA256 732540fc18948d74dc3c684967cac8f3301f01e1512eb90d3b0ec4343b2dbbf7
SHA3 7b765300078fa62ca3295a2ecd49643d9e603b73394b0cb4b4c6c3140a19e4f9

8

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x988
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.24132
MD5 91d62398c7145ac12f77c82ed09566c5
SHA1 e5dd516f6cb079268d9c126fc0da4705bc50694e
SHA256 156d33efd6e576a5531cbde2c5035c3da36b77b24b669f6d93c49cfbe7cb21ee
SHA3 a46b33056e86eca73d36cbead2465399eb56771c55c8ef61b19f761c9cbd77cf

9

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.05094
MD5 6070e0f3bf3cb547facdfc17be3f33a1
SHA1 742d4d61ea495a21c7dc961a1929879bca5a1974
SHA256 35b676fc005c62f4a5f07129cba9f451ca13ef2ec88ba4d3031a15422b47a051
SHA3 38f4b8df64573589f35146a3837d4bbb8e5738c0e6bfeb789d717332403174ee

103

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x84
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.04448
Detected Filetype Icon file
MD5 f7731730720cfe035cf030b40d0e2eb6
SHA1 d046e23f2ee2b93ad96be8e1dc9120ecf3915091
SHA256 5c92a41adaf3265071482fd1a182ae8702c168636a7d9ff51798ee3a1dfc8500
SHA3 6f2d12e4c63c131a3f7f48293996e2be05da351536d013affe5d2265965ce657

1 (#2)

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x210
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.54881
MD5 1ba7ab91307d04e9650f48e4f53ae03b
SHA1 41a4b9f5ee169ed42671c9454d1b27fad76eb012
SHA256 831f12ea2adf21ad8a1611add0a7d5156ab7506c8fa4b0bfb26ab3712ea91ca6
SHA3 3a506adb42e761685d6cf49d7df1fd245734d1541587afbea74ce19bc2a378ba

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x6c1
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.37708
MD5 aab7e8aafe7b06ab3d003b54ab5e18ed
SHA1 dccf0408f43059df37b755f3241a8b4b35c728af
SHA256 fb88b19523afd8fed48eddfd10805a3a0a45997bbf8fac04d595ddf93c1a88a8
SHA3 a981b8e907b79cd9448766ace938dfd96560d11c29e6ba165912a8508bd52ca7

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 2022.3.25.2784
ProductVersion 2022.3.25.2784
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_UNKNOWN
Language English - United States
FileVersion (#2) 2022.3.25.5442272
LegalCopyright (c) 2005-2024 Unity Technologies. All rights reserved.
ProductVersion (#2) 2022.3.25f1 (530ae0ba3889)
Resource LangID English - United States

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2024-Apr-10 10:25:58
Version 0.0
SizeofData 141
AddressOfRawData 0x15aec
PointerToRawData 0x148ec
Referenced File C:\build\output\unity\unity\artifacts\WindowsPlayer\Win64_VS2019_nondev_m_r\WindowsPlayer_player_Master_mono_x64.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2024-Apr-10 10:25:58
Version 0.0
SizeofData 20
AddressOfRawData 0x15b7c
PointerToRawData 0x1497c

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2024-Apr-10 10:25:58
Version 0.0
SizeofData 768
AddressOfRawData 0x15b90
PointerToRawData 0x14990

TLS Callbacks

Load Configuration

Size 0x138
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x140018030

RICH Header

XOR Key 0xe5e06b0d
Unmarked objects 0
ASM objects (28900) 5
C++ objects (28900) 138
C objects (28900) 10
Imports (28900) 2
C++ objects (VS 2015/2017/2019 runtime 29118) 39
C objects (VS 2015/2017/2019 runtime 29118) 16
ASM objects (VS 2015/2017/2019 runtime 29118) 9
Imports (VS2019 Update 8 (16.8.0-1) compiler 29333) 3
Total imports 89
C++ objects (VS2019 Update 8 (16.8.0-1) compiler 29333) 3
Exports (VS2019 Update 8 (16.8.0-1) compiler 29333) 1
Resource objects (VS2019 Update 8 (16.8.0-1) compiler 29333) 1
Linker (VS2019 Update 8 (16.8.0-1) compiler 29333) 1

Errors

Leave a comment

No comments yet.