b912cce59d532f13e76725e046b8389248721db9226a4af9fdf2a2fa286873e3

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2025-Nov-07 02:11:17
Detected languages English - United States
TLS Callbacks 1 callback(s) detected.
Debug artifacts SubwaySurfersRust.pdb
ProductVersion 1.0.0
FileDescription subway-surfers-rust
FileVersion 1.0.0
ProductName subway-surfers-rust

Plugin Output

Info Interesting strings found in the binary: Contains domain names:
  • http://127.0.0.1
Suspicious The PE contains functions most legitimate programs don't use. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryW
  • LoadLibraryA
Functions which can be used for anti-debugging purposes:
  • SwitchToThread
Can access the registry:
  • RegOpenKeyExW
  • RegQueryValueExW
  • RegCloseKey
Uses Windows's Native API:
  • NtReadFile
  • NtWriteFile
Leverages the raw socket API to access the Internet:
  • WS2_32.dll
Suspicious VirusTotal score: 1/64 (Scanned on 2025-12-31 07:43:40) Trapmine: suspicious.low.ml.score

Hashes

MD5 f5688f12ba185bc3bdf29ed30c9d1f93 🔍
SHA1 302d9ab2d6dbfe79a1a2c8b7ce662b2739fe900c 🔍
SHA256 b912cce59d532f13e76725e046b8389248721db9226a4af9fdf2a2fa286873e3 🔍
SHA3 8030cf58c3885772813ad80a3067bd0083903bf7dd856c75d7727934bb76f813 🔍
SSDeep 24576:YJm5rE1X7gE+SmQeOlljprXmPGP6gfd5:YerE1UEnDeyWW6gfd 🔍
Imports Hash 7eb51c0c23ae9f107d6a49d563a9d21e 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x110

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 6
TimeDateStamp 2025-Nov-07 02:11:17
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x6a800
SizeOfInitializedData 0x69a00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000064D34 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0xd8000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 1589e4dddfa9fd63c00a721363bbf4b0 🔍
SHA1 7573aa230a2481d453c29cf8861be53f3e31faff 🔍
SHA256 1307770a2ebaecc2ff8bd6e8582c5e877d29c2a71a72a0b132fd5cafee38b383 🔍
SHA3 9b10a893f541488252be52189dcd7a23d10eb87f8f7d91693305a49404d18b81 🔍
VirtualSize 0x6a7d4
VirtualAddress 0x1000
SizeOfRawData 0x6a800
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.33237

.rdata

MD5 0069e17f701e94446890f5d11d4432e6 🔍
SHA1 71343237358be689cd47ace48053cd5f54d861de 🔍
SHA256 229f0e1cb92077ed7b1ce73be842b28a796c292d176150e8ca7502ca8fe35fe0 🔍
SHA3 85f947f254e345bbe870717e6de482e589225a11c98ca5fcef98e4da4d1c9ac4 🔍
VirtualSize 0x2a864
VirtualAddress 0x6c000
SizeOfRawData 0x2aa00
PointerToRawData 0x6ac00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.54711

.data

MD5 ba160febc20e0517d7f421778d27fc89 🔍
SHA1 52764ce6817c1ed7cd94efc94fe1ebe5e5207c28 🔍
SHA256 27bed9561b71ff7f2fd7af2388a606959f8d45ebf855218027123bfb05087af9 🔍
SHA3 1719d400a9fdca8f6a2fde2d581a7a92e78bff4c4056ae5413a65fdae35269fd 🔍
VirtualSize 0x2118
VirtualAddress 0x97000
SizeOfRawData 0x1600
PointerToRawData 0x95600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.51891

.pdata

MD5 bed659ae67eb4ad88265eabde7eb6cbd 🔍
SHA1 6274d1abdae59fa96b1811c3ee721b0af8073830 🔍
SHA256 fb18a04a9ca6a483a512fe8f3a8da2f6e85742e36e105e6846ec077e308fa208 🔍
SHA3 19b56a863767d1145c7e936d44a4286657a259af406c050bd1272677b2e025f3 🔍
VirtualSize 0x5ea4
VirtualAddress 0x9a000
SizeOfRawData 0x6000
PointerToRawData 0x96c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.80938

.rsrc

MD5 92fadda328efabd2976abc42836bd92f 🔍
SHA1 bc46fc4e243b9f69d0095c5e2b18e58665448288 🔍
SHA256 2030fd4a7b3d1e8d9e921d7be0d872c376165a04d42d721126931ac4468a8d7c 🔍
SHA3 f55168cb94cfd0aa7a7d53c4832fbdbefc5f1d4658a2183bfb95a1949062bc25 🔍
VirtualSize 0x360e8
VirtualAddress 0xa0000
SizeOfRawData 0x36200
PointerToRawData 0x9cc00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 7.55357

.reloc

MD5 7db75ad0a24fefd93eb37a2c525baa36 🔍
SHA1 809cbb01fbfde77f89c5c7c1b41fd295cd7141e5 🔍
SHA256 1a80cf30ab2f66ea95f1167356d0017b48d49b914cf30a0a48d5affb303348ed 🔍
SHA3 2a726ba3f45c911dd194d6b4016600ccb2eb2f2fb085179b30d2f8212588db9a 🔍
VirtualSize 0xbf4
VirtualAddress 0xd7000
SizeOfRawData 0xc00
PointerToRawData 0xd2e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.43143

Imports

ADVAPI32.dll RegOpenKeyExW
RegQueryValueExW
RegCloseKey
ole32.dll CoTaskMemAlloc
CoInitializeEx
CoUninitialize
CoTaskMemFree
SHLWAPI.dll PathCombineW
PathFindFileNameW
SHELL32.dll SHGetFolderPathW
VERSION.dll GetFileVersionInfoW
GetFileVersionInfoSizeW
VerQueryValueW
USER32.dll TranslateMessage
GetMonitorInfoA
MonitorFromWindow
LoadImageA
GetParent
SetWindowLongPtrW
SetWindowLongPtrA
GetWindowLongPtrW
SetWindowLongA
CreateWindowExW
AdjustWindowRect
GetWindowRect
GetClientRect
SetWindowTextW
GetMessageW
GetSystemMetrics
GetKeyState
SetFocus
SetWindowPos
MoveWindow
DestroyWindow
RegisterClassExW
IsWindow
GetWindowLongA
UpdateWindow
CallWindowProcA
PostQuitMessage
DispatchMessageW
ShowWindow
DefWindowProcW
PostMessageW
api-ms-win-core-synch-l1-2-0.dll WakeByAddressAll
WaitOnAddress
WakeByAddressSingle
KERNEL32.dll LCMapStringEx
DeleteCriticalSection
InitializeCriticalSectionEx
LeaveCriticalSection
EnterCriticalSection
DecodePointer
EncodePointer
IsProcessorFeaturePresent
SetUnhandledExceptionFilter
UnhandledExceptionFilter
IsDebuggerPresent
InitializeSListHead
GetSystemTimeAsFileTime
SleepConditionVariableSRW
WakeAllConditionVariable
AcquireSRWLockExclusive
ReleaseSRWLockExclusive
RtlVirtualUnwind
RtlLookupFunctionEntry
RtlCaptureContext
TerminateProcess
QueryPerformanceCounter
GetSystemTimePreciseAsFileTime
CreateThread
GetConsoleOutputCP
GetStdHandle
WriteConsoleW
HeapAlloc
CloseHandle
GetLastError
Sleep
GetCurrentThreadId
FreeLibrary
GetModuleFileNameW
GetModuleHandleA
GetProcAddress
LoadLibraryW
lstrcmpW
MultiByteToWideChar
WideCharToMultiByte
GetProcessHeap
HeapFree
HeapReAlloc
lstrlenW
GetCurrentProcess
WaitForSingleObjectEx
LoadLibraryA
GetCurrentProcessId
CreateMutexA
ReleaseMutex
SetFileInformationByHandle
WaitForSingleObject
SetHandleInformation
AddVectoredExceptionHandler
SetThreadStackGuarantee
GetCurrentThread
SetLastError
GetCurrentDirectoryW
GetEnvironmentVariableW
GetFileInformationByHandleEx
SwitchToThread
CreateFileW
GetFileInformationByHandle
FindFirstFileExW
FindClose
GetConsoleMode
GetFullPathNameW
GetModuleHandleW
FormatMessageW
QueryPerformanceFrequency
ntdll.dll RtlNtStatusToDosError
NtReadFile
NtWriteFile
WS2_32.dll WSACleanup
WSAStartup
listen
bind
getsockname
getpeername
shutdown
recv
accept
freeaddrinfo
connect
getaddrinfo
closesocket
send
WSADuplicateSocketW
WSAGetLastError
WSASocketW
VCRUNTIME140.dll __std_terminate
__uncaught_exception
__current_exception_context
__current_exception
__C_specific_handler
memset
memcmp
_CxxThrowException
__std_exception_destroy
__std_exception_copy
_purecall
memcpy
memmove
__CxxFrameHandler3
VCRUNTIME140_1.dll __CxxFrameHandler4
api-ms-win-crt-runtime-l1-1-0.dll _register_thread_local_exe_atexit_callback
_c_exit
_register_onexit_function
_initialize_onexit_table
_cexit
__p___argv
__p___argc
exit
_initterm_e
_initterm
_get_initial_narrow_environment
_initialize_narrow_environment
_configure_narrow_argv
_crt_atexit
_set_app_type
_seh_filter_exe
_errno
_invoke_watson
terminate
_exit
abort
api-ms-win-crt-convert-l1-1-0.dll wcstol
api-ms-win-crt-string-l1-1-0.dll strlen
_wcsdup
isupper
wcslen
__strncnt
islower
api-ms-win-crt-math-l1-1-0.dll __setusermatherr
api-ms-win-crt-stdio-l1-1-0.dll _set_fmode
__p__commode
__acrt_iob_func
_get_stream_buffer_pointers
fclose
fflush
fgetc
fgetpos
fputc
fread
fsetpos
_fseeki64
fwrite
setvbuf
ungetc
api-ms-win-crt-locale-l1-1-0.dll _configthreadlocale
_lock_locales
_unlock_locales
setlocale
__pctype_func
___lc_locale_name_func
___lc_codepage_func
api-ms-win-crt-heap-l1-1-0.dll calloc
free
_set_new_mode
_callnewh
malloc
api-ms-win-crt-filesystem-l1-1-0.dll _unlock_file
_lock_file

Delayed Imports

run_webview

Ordinal 1
Address 0x645b0

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.53081
MD5 d48137e81331867c9034e3b1753e01e8 🔍
SHA1 2f866446f27b4ef41db74b3c0d3f3a210015f227 🔍
SHA256 70139f657be5bc2984c0fbe1fe849bb73a4012288cb4a7a269333aac08b8ccb7 🔍
SHA3 7c91a3784223efdabf5e9cfdc7ddfb0fa8d21c65c61ef316baa733ee346f54c8 🔍

2

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.7081
MD5 6cf5537d241a7d92cab8d9d5afafe534 🔍
SHA1 d3ff04463369272d4d24745b419913a5f1816c09 🔍
SHA256 066af464a0619a063c453b4362c476cb6330fcac5eccfb637e47c62dc0ce3e15 🔍
SHA3 c317005008f2f9db2559f04fe82aa71c33b117fe8092c444fe80327fd4e39b04 🔍

3

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.70122
MD5 c2277f6e63166333578c4ff79283a6be 🔍
SHA1 7567053e39fa383f2b8ee8c1f2d9ad7db1e02b4a 🔍
SHA256 82a0a9704c70b37729c484b1785b8a12ba6fbe3e71a7cb3eacf30983b19e8f4c 🔍
SHA3 1321f59f8b0bd34de0f5f080a34ef30be59d6114d27a1abe74d896ac51385426 🔍

4

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x4228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.7054
MD5 ed3a6f04aee9921dab781a30070abc2d 🔍
SHA1 4a601d97ab05c88dde0c0278645e9b85d67067f3 🔍
SHA256 e19f9aa6e31f4b949407d31b2d3f2ac2eaf11d81fe8c8bb5d0848ecc2ddb66d5 🔍
SHA3 ba589cebe78d3694e8f7dfc5497122ca405ce7c0c7f14b0be88c6cbc84ad10a1 🔍

5

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10828
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.63849
MD5 d347c86ffbf18aa56a90d97eece090d2 🔍
SHA1 44a83c532d6f3a976fc01de4ec7958a6ff85c9c0 🔍
SHA256 ce98c8e7296201f9439a665a8ab6dff317802d90e429addf280182ae079b278d 🔍
SHA3 1ece2e5dfe75ce86dab05cc0d9eb07dc576d408f3203624f6865006b22c3a9c8 🔍

6

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x1d7ca
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.99214
Detected Filetype PNG graphic file
MD5 49ffe02c80939318b269ba19f4cb92e3 🔍
SHA1 cf1c21726eedadd5366ad5ef3810fed4541731a0 🔍
SHA256 d73ecb6b509de8de57c1ff9a7f2b9b4cce2b6479f23f1d2242e35600deed72f9 🔍
SHA3 62733b3f34f8169895242710820a4ea2d600b705afeb5f8b9a540ec8e8efd100 🔍

1 (#2)

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x5a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.82454
Detected Filetype Icon file
MD5 bb5aab0d1b3164c5273427b3518219ce 🔍
SHA1 24c6d7f249d50df01f665ee1ce148a4f5ce14cb6 🔍
SHA256 3a2dba6e802d8bfb6df81b81497ad1e57202e69edfbb7d1812d124e730cb732a 🔍
SHA3 72003076448eb66596f41f505e4386462f7bb2b8c084e983470643531e7bf8a3 🔍

1 (#3)

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x1d0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.14641
MD5 018c86af9336a0bfa087cbbd223ef7a6 🔍
SHA1 6a9b846c0f5ccabdf56d6e8bb5026154be259f06 🔍
SHA256 e06374e04263ecb821f4c6786b5d4ca8d9d004fbf38bc527a5d2f6ada7218eab 🔍
SHA3 8c3512084e2e0d33e7ce252f7a7defc6870b8f68ec2e4d682d2e526647a5e9a2 🔍

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 1.0.0.0
ProductVersion 1.0.0.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
FileType VFT_APP
Language UNKNOWN
ProductVersion (#2) 1.0.0
FileDescription subway-surfers-rust
FileVersion (#2) 1.0.0
ProductName subway-surfers-rust
Resource LangID English - United States

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2025-Nov-07 02:11:17
Version 0.0
SizeofData 46
AddressOfRawData 0x82d7c
PointerToRawData 0x8197c
Referenced File SubwaySurfersRust.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2025-Nov-07 02:11:17
Version 0.0
SizeofData 20
AddressOfRawData 0x82dac
PointerToRawData 0x819ac

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2025-Nov-07 02:11:17
Version 0.0
SizeofData 988
AddressOfRawData 0x82dc0
PointerToRawData 0x819c0

TLS Callbacks

StartAddressOfRawData 0x1400831c0
EndAddressOfRawData 0x140083244
AddressOfIndex 0x140098648
AddressOfCallbacks 0x14006c7f0
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_8BYTES
Callbacks 0x000000014003FDB0

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x140097140

RICH Header

XOR Key 0xd5911636
Unmarked objects 0
Imports (VS2008 SP1 build 30729) 18
Imports (35207) 4
ASM objects (35207) 4
C objects (35207) 10
C++ objects (35207) 66
Imports (33140) 21
Total imports 309
C++ objects (35215) 1
Unmarked objects (#2) 49
Exports (35215) 1
Resource objects (35215) 1
Linker (35215) 1

Errors

Leave a comment

No comments yet.