| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2025-Nov-07 02:11:17 |
| Detected languages |
English - United States
|
| TLS Callbacks | 1 callback(s) detected. |
| Debug artifacts |
SubwaySurfersRust.pdb
|
| ProductVersion | 1.0.0 |
| FileDescription | subway-surfers-rust |
| FileVersion | 1.0.0 |
| ProductName | subway-surfers-rust |
| Info | Interesting strings found in the binary: |
Contains domain names:
|
| Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
| Suspicious | VirusTotal score: 1/64 (Scanned on 2025-12-31 07:43:40) | Trapmine: suspicious.low.ml.score |
| MD5 | f5688f12ba185bc3bdf29ed30c9d1f93 🔍 |
|---|---|
| SHA1 | 302d9ab2d6dbfe79a1a2c8b7ce662b2739fe900c 🔍 |
| SHA256 | b912cce59d532f13e76725e046b8389248721db9226a4af9fdf2a2fa286873e3 🔍 |
| SHA3 | 8030cf58c3885772813ad80a3067bd0083903bf7dd856c75d7727934bb76f813 🔍 |
| SSDeep | 24576:YJm5rE1X7gE+SmQeOlljprXmPGP6gfd5:YerE1UEnDeyWW6gfd 🔍 |
| Imports Hash | 7eb51c0c23ae9f107d6a49d563a9d21e 🔍 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x110 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 6 |
| TimeDateStamp | 2025-Nov-07 02:11:17 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x6a800 |
| SizeOfInitializedData | 0x69a00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0000000000064D34 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0xd8000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| MD5 | 1589e4dddfa9fd63c00a721363bbf4b0 🔍 |
|---|---|
| SHA1 | 7573aa230a2481d453c29cf8861be53f3e31faff 🔍 |
| SHA256 | 1307770a2ebaecc2ff8bd6e8582c5e877d29c2a71a72a0b132fd5cafee38b383 🔍 |
| SHA3 | 9b10a893f541488252be52189dcd7a23d10eb87f8f7d91693305a49404d18b81 🔍 |
| VirtualSize | 0x6a7d4 |
| VirtualAddress | 0x1000 |
| SizeOfRawData | 0x6a800 |
| PointerToRawData | 0x400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
|
| Entropy | 6.33237 |
| MD5 | 0069e17f701e94446890f5d11d4432e6 🔍 |
|---|---|
| SHA1 | 71343237358be689cd47ace48053cd5f54d861de 🔍 |
| SHA256 | 229f0e1cb92077ed7b1ce73be842b28a796c292d176150e8ca7502ca8fe35fe0 🔍 |
| SHA3 | 85f947f254e345bbe870717e6de482e589225a11c98ca5fcef98e4da4d1c9ac4 🔍 |
| VirtualSize | 0x2a864 |
| VirtualAddress | 0x6c000 |
| SizeOfRawData | 0x2aa00 |
| PointerToRawData | 0x6ac00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 5.54711 |
| MD5 | ba160febc20e0517d7f421778d27fc89 🔍 |
|---|---|
| SHA1 | 52764ce6817c1ed7cd94efc94fe1ebe5e5207c28 🔍 |
| SHA256 | 27bed9561b71ff7f2fd7af2388a606959f8d45ebf855218027123bfb05087af9 🔍 |
| SHA3 | 1719d400a9fdca8f6a2fde2d581a7a92e78bff4c4056ae5413a65fdae35269fd 🔍 |
| VirtualSize | 0x2118 |
| VirtualAddress | 0x97000 |
| SizeOfRawData | 0x1600 |
| PointerToRawData | 0x95600 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 4.51891 |
| MD5 | bed659ae67eb4ad88265eabde7eb6cbd 🔍 |
|---|---|
| SHA1 | 6274d1abdae59fa96b1811c3ee721b0af8073830 🔍 |
| SHA256 | fb18a04a9ca6a483a512fe8f3a8da2f6e85742e36e105e6846ec077e308fa208 🔍 |
| SHA3 | 19b56a863767d1145c7e936d44a4286657a259af406c050bd1272677b2e025f3 🔍 |
| VirtualSize | 0x5ea4 |
| VirtualAddress | 0x9a000 |
| SizeOfRawData | 0x6000 |
| PointerToRawData | 0x96c00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 5.80938 |
| MD5 | 92fadda328efabd2976abc42836bd92f 🔍 |
|---|---|
| SHA1 | bc46fc4e243b9f69d0095c5e2b18e58665448288 🔍 |
| SHA256 | 2030fd4a7b3d1e8d9e921d7be0d872c376165a04d42d721126931ac4468a8d7c 🔍 |
| SHA3 | f55168cb94cfd0aa7a7d53c4832fbdbefc5f1d4658a2183bfb95a1949062bc25 🔍 |
| VirtualSize | 0x360e8 |
| VirtualAddress | 0xa0000 |
| SizeOfRawData | 0x36200 |
| PointerToRawData | 0x9cc00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 7.55357 |
| MD5 | 7db75ad0a24fefd93eb37a2c525baa36 🔍 |
|---|---|
| SHA1 | 809cbb01fbfde77f89c5c7c1b41fd295cd7141e5 🔍 |
| SHA256 | 1a80cf30ab2f66ea95f1167356d0017b48d49b914cf30a0a48d5affb303348ed 🔍 |
| SHA3 | 2a726ba3f45c911dd194d6b4016600ccb2eb2f2fb085179b30d2f8212588db9a 🔍 |
| VirtualSize | 0xbf4 |
| VirtualAddress | 0xd7000 |
| SizeOfRawData | 0xc00 |
| PointerToRawData | 0xd2e00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
|
| Entropy | 5.43143 |
| ADVAPI32.dll |
RegOpenKeyExW
RegQueryValueExW RegCloseKey |
|---|---|
| ole32.dll |
CoTaskMemAlloc
CoInitializeEx CoUninitialize CoTaskMemFree |
| SHLWAPI.dll |
PathCombineW
PathFindFileNameW |
| SHELL32.dll |
SHGetFolderPathW
|
| VERSION.dll |
GetFileVersionInfoW
GetFileVersionInfoSizeW VerQueryValueW |
| USER32.dll |
TranslateMessage
GetMonitorInfoA MonitorFromWindow LoadImageA GetParent SetWindowLongPtrW SetWindowLongPtrA GetWindowLongPtrW SetWindowLongA CreateWindowExW AdjustWindowRect GetWindowRect GetClientRect SetWindowTextW GetMessageW GetSystemMetrics GetKeyState SetFocus SetWindowPos MoveWindow DestroyWindow RegisterClassExW IsWindow GetWindowLongA UpdateWindow CallWindowProcA PostQuitMessage DispatchMessageW ShowWindow DefWindowProcW PostMessageW |
| api-ms-win-core-synch-l1-2-0.dll |
WakeByAddressAll
WaitOnAddress WakeByAddressSingle |
| KERNEL32.dll |
LCMapStringEx
DeleteCriticalSection InitializeCriticalSectionEx LeaveCriticalSection EnterCriticalSection DecodePointer EncodePointer IsProcessorFeaturePresent SetUnhandledExceptionFilter UnhandledExceptionFilter IsDebuggerPresent InitializeSListHead GetSystemTimeAsFileTime SleepConditionVariableSRW WakeAllConditionVariable AcquireSRWLockExclusive ReleaseSRWLockExclusive RtlVirtualUnwind RtlLookupFunctionEntry RtlCaptureContext TerminateProcess QueryPerformanceCounter GetSystemTimePreciseAsFileTime CreateThread GetConsoleOutputCP GetStdHandle WriteConsoleW HeapAlloc CloseHandle GetLastError Sleep GetCurrentThreadId FreeLibrary GetModuleFileNameW GetModuleHandleA GetProcAddress LoadLibraryW lstrcmpW MultiByteToWideChar WideCharToMultiByte GetProcessHeap HeapFree HeapReAlloc lstrlenW GetCurrentProcess WaitForSingleObjectEx LoadLibraryA GetCurrentProcessId CreateMutexA ReleaseMutex SetFileInformationByHandle WaitForSingleObject SetHandleInformation AddVectoredExceptionHandler SetThreadStackGuarantee GetCurrentThread SetLastError GetCurrentDirectoryW GetEnvironmentVariableW GetFileInformationByHandleEx SwitchToThread CreateFileW GetFileInformationByHandle FindFirstFileExW FindClose GetConsoleMode GetFullPathNameW GetModuleHandleW FormatMessageW QueryPerformanceFrequency |
| ntdll.dll |
RtlNtStatusToDosError
NtReadFile NtWriteFile |
| WS2_32.dll |
WSACleanup
WSAStartup listen bind getsockname getpeername shutdown recv accept freeaddrinfo connect getaddrinfo closesocket send WSADuplicateSocketW WSAGetLastError WSASocketW |
| VCRUNTIME140.dll |
__std_terminate
__uncaught_exception __current_exception_context __current_exception __C_specific_handler memset memcmp _CxxThrowException __std_exception_destroy __std_exception_copy _purecall memcpy memmove __CxxFrameHandler3 |
| VCRUNTIME140_1.dll |
__CxxFrameHandler4
|
| api-ms-win-crt-runtime-l1-1-0.dll |
_register_thread_local_exe_atexit_callback
_c_exit _register_onexit_function _initialize_onexit_table _cexit __p___argv __p___argc exit _initterm_e _initterm _get_initial_narrow_environment _initialize_narrow_environment _configure_narrow_argv _crt_atexit _set_app_type _seh_filter_exe _errno _invoke_watson terminate _exit abort |
| api-ms-win-crt-convert-l1-1-0.dll |
wcstol
|
| api-ms-win-crt-string-l1-1-0.dll |
strlen
_wcsdup isupper wcslen __strncnt islower |
| api-ms-win-crt-math-l1-1-0.dll |
__setusermatherr
|
| api-ms-win-crt-stdio-l1-1-0.dll |
_set_fmode
__p__commode __acrt_iob_func _get_stream_buffer_pointers fclose fflush fgetc fgetpos fputc fread fsetpos _fseeki64 fwrite setvbuf ungetc |
| api-ms-win-crt-locale-l1-1-0.dll |
_configthreadlocale
_lock_locales _unlock_locales setlocale __pctype_func ___lc_locale_name_func ___lc_codepage_func |
| api-ms-win-crt-heap-l1-1-0.dll |
calloc
free _set_new_mode _callnewh malloc |
| api-ms-win-crt-filesystem-l1-1-0.dll |
_unlock_file
_lock_file |
| Ordinal | 1 |
|---|---|
| Address | 0x645b0 |
| Type |
RT_ICON
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x468 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 6.53081 |
| MD5 | d48137e81331867c9034e3b1753e01e8 🔍 |
| SHA1 | 2f866446f27b4ef41db74b3c0d3f3a210015f227 🔍 |
| SHA256 | 70139f657be5bc2984c0fbe1fe849bb73a4012288cb4a7a269333aac08b8ccb7 🔍 |
| SHA3 | 7c91a3784223efdabf5e9cfdc7ddfb0fa8d21c65c61ef316baa733ee346f54c8 🔍 |
| Type |
RT_ICON
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x10a8 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 6.7081 |
| MD5 | 6cf5537d241a7d92cab8d9d5afafe534 🔍 |
| SHA1 | d3ff04463369272d4d24745b419913a5f1816c09 🔍 |
| SHA256 | 066af464a0619a063c453b4362c476cb6330fcac5eccfb637e47c62dc0ce3e15 🔍 |
| SHA3 | c317005008f2f9db2559f04fe82aa71c33b117fe8092c444fe80327fd4e39b04 🔍 |
| Type |
RT_ICON
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x25a8 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 6.70122 |
| MD5 | c2277f6e63166333578c4ff79283a6be 🔍 |
| SHA1 | 7567053e39fa383f2b8ee8c1f2d9ad7db1e02b4a 🔍 |
| SHA256 | 82a0a9704c70b37729c484b1785b8a12ba6fbe3e71a7cb3eacf30983b19e8f4c 🔍 |
| SHA3 | 1321f59f8b0bd34de0f5f080a34ef30be59d6114d27a1abe74d896ac51385426 🔍 |
| Type |
RT_ICON
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x4228 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 6.7054 |
| MD5 | ed3a6f04aee9921dab781a30070abc2d 🔍 |
| SHA1 | 4a601d97ab05c88dde0c0278645e9b85d67067f3 🔍 |
| SHA256 | e19f9aa6e31f4b949407d31b2d3f2ac2eaf11d81fe8c8bb5d0848ecc2ddb66d5 🔍 |
| SHA3 | ba589cebe78d3694e8f7dfc5497122ca405ce7c0c7f14b0be88c6cbc84ad10a1 🔍 |
| Type |
RT_ICON
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x10828 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 6.63849 |
| MD5 | d347c86ffbf18aa56a90d97eece090d2 🔍 |
| SHA1 | 44a83c532d6f3a976fc01de4ec7958a6ff85c9c0 🔍 |
| SHA256 | ce98c8e7296201f9439a665a8ab6dff317802d90e429addf280182ae079b278d 🔍 |
| SHA3 | 1ece2e5dfe75ce86dab05cc0d9eb07dc576d408f3203624f6865006b22c3a9c8 🔍 |
| Type |
RT_ICON
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x1d7ca |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 7.99214 |
| Detected Filetype | PNG graphic file |
| MD5 | 49ffe02c80939318b269ba19f4cb92e3 🔍 |
| SHA1 | cf1c21726eedadd5366ad5ef3810fed4541731a0 🔍 |
| SHA256 | d73ecb6b509de8de57c1ff9a7f2b9b4cce2b6479f23f1d2242e35600deed72f9 🔍 |
| SHA3 | 62733b3f34f8169895242710820a4ea2d600b705afeb5f8b9a540ec8e8efd100 🔍 |
| Type |
RT_GROUP_ICON
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x5a |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 2.82454 |
| Detected Filetype | Icon file |
| MD5 | bb5aab0d1b3164c5273427b3518219ce 🔍 |
| SHA1 | 24c6d7f249d50df01f665ee1ce148a4f5ce14cb6 🔍 |
| SHA256 | 3a2dba6e802d8bfb6df81b81497ad1e57202e69edfbb7d1812d124e730cb732a 🔍 |
| SHA3 | 72003076448eb66596f41f505e4386462f7bb2b8c084e983470643531e7bf8a3 🔍 |
| Type |
RT_VERSION
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x1d0 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 3.14641 |
| MD5 | 018c86af9336a0bfa087cbbd223ef7a6 🔍 |
| SHA1 | 6a9b846c0f5ccabdf56d6e8bb5026154be259f06 🔍 |
| SHA256 | e06374e04263ecb821f4c6786b5d4ca8d9d004fbf38bc527a5d2f6ada7218eab 🔍 |
| SHA3 | 8c3512084e2e0d33e7ce252f7a7defc6870b8f68ec2e4d682d2e526647a5e9a2 🔍 |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 1.0.0.0 |
| ProductVersion | 1.0.0.0 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | UNKNOWN |
| ProductVersion (#2) | 1.0.0 |
| FileDescription | subway-surfers-rust |
| FileVersion (#2) | 1.0.0 |
| ProductName | subway-surfers-rust |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Nov-07 02:11:17 |
| Version | 0.0 |
| SizeofData | 46 |
| AddressOfRawData | 0x82d7c |
| PointerToRawData | 0x8197c |
| Referenced File | SubwaySurfersRust.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Nov-07 02:11:17 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0x82dac |
| PointerToRawData | 0x819ac |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Nov-07 02:11:17 |
| Version | 0.0 |
| SizeofData | 988 |
| AddressOfRawData | 0x82dc0 |
| PointerToRawData | 0x819c0 |
| StartAddressOfRawData | 0x1400831c0 |
|---|---|
| EndAddressOfRawData | 0x140083244 |
| AddressOfIndex | 0x140098648 |
| AddressOfCallbacks | 0x14006c7f0 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_8BYTES
|
| Callbacks |
0x000000014003FDB0
|
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x140097140 |
| XOR Key | 0xd5911636 |
|---|---|
| Unmarked objects | 0 |
| Imports (VS2008 SP1 build 30729) | 18 |
| Imports (35207) | 4 |
| ASM objects (35207) | 4 |
| C objects (35207) | 10 |
| C++ objects (35207) | 66 |
| Imports (33140) | 21 |
| Total imports | 309 |
| C++ objects (35215) | 1 |
| Unmarked objects (#2) | 49 |
| Exports (35215) | 1 |
| Resource objects (35215) | 1 |
| Linker (35215) | 1 |
No comments yet.