| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2026-Aug-18 06:01:22 |
| TLS Callbacks | 2 callback(s) detected. |
| Debug artifacts |
rustup_init.pdb
|
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Looks for VMWare presence:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to MD5 Uses constants related to SHA1 Uses constants related to SHA256 Uses constants related to SHA512 Microsoft's Cryptography API |
| Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
| Safe | VirusTotal score: 0/71 (Scanned on 2026-09-28 10:04:47) | All the AVs think this file is safe. |
| MD5 | b147221215f594041ddb4a583ba63f5a 🔍 |
|---|---|
| SHA1 | b36e70f54ebe5d0b3b4eb3b700b847b802fe7b36 🔍 |
| SHA256 | 6f4bef66261261fcb43131be8720bab817d403a09edec7455c371974b90bdb7e 🔍 |
| SHA3 | ff965a32631beca8f409f443ad40de9c7623aa1e5ee9318ea74875cf9fe7733e 🔍 |
| SSDeep | 98304:UkKjHueMNY0FloeUb3eXzVp+DOJb2s8PaX8h3dYBFoIvOji9/zRj+7Ma43LiVRL:/LweUbO1gVh3dYBFoIvOjiJRjW7Y6 🔍 |
| Imports Hash | 3dd378db218c8dce9833ec31ae758868 🔍 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x100 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 6 |
| TimeDateStamp | 2026-Aug-18 06:01:22 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x8c8800 |
| SizeOfInitializedData | 0x35d400 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0000000000870BE0 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0xc2b000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x200000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| MD5 | 0e63d5f84028dc7563889176d8aa8bbb 🔍 |
|---|---|
| SHA1 | 202a6f9095937b31070bb3f9dd0a5ce597658ef5 🔍 |
| SHA256 | 4fd19b75e34d0a5c5256b22cc275759d901ea9d66350ad482b6249e5a0fe62ad 🔍 |
| SHA3 | 58d9af3fd18e322a79f3b36d756842bb4a90e22fb1f196a47ea78398eeb67dd9 🔍 |
| VirtualSize | 0x8c8730 |
| VirtualAddress | 0x1000 |
| SizeOfRawData | 0x8c8800 |
| PointerToRawData | 0x400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
|
| Entropy | 6.31407 |
| MD5 | 6cb1e8c5043f485ea34b1c9c50b86a18 🔍 |
|---|---|
| SHA1 | 6409079cc43160b8074c1a048891e0de1f8b04a4 🔍 |
| SHA256 | 76c8c6400dcb736ed5b98d7d1da925e6f7a807e8bc9af5bd9cbb5506d27a902d 🔍 |
| SHA3 | 12e89612edc0d655bffbd72d175fca45c9ecfba71c0607fdefecaf319499386c 🔍 |
| VirtualSize | 0x2f1794 |
| VirtualAddress | 0x8ca000 |
| SizeOfRawData | 0x2f1800 |
| PointerToRawData | 0x8c8c00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 6.02544 |
| MD5 | de631958ce94c6e927fb86846c744a49 🔍 |
|---|---|
| SHA1 | a29573c2dc13afb5c9f6dd44865b5bc4ff3524d8 🔍 |
| SHA256 | 3f7649bf04aa88ee36398f2d689094c9b12ab4671b5ad2cc112e3ec19273c316 🔍 |
| SHA3 | fcaff114d12ac898c4948ebab59e7730ce9d28b0648f558c1e19b3a91aea25a5 🔍 |
| VirtualSize | 0x9478 |
| VirtualAddress | 0xbbc000 |
| SizeOfRawData | 0x5400 |
| PointerToRawData | 0xbba400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 2.14129 |
| MD5 | 41b86a75f8565612786001712c4fea7c 🔍 |
|---|---|
| SHA1 | 630c2c7a49463baa086ac67187f5728e6b594fb4 🔍 |
| SHA256 | 4ca8acf1140ed0a6a8d99d95199cd9afd5e5d5bf6eeee0b10e16098d95cd7827 🔍 |
| SHA3 | ebacd34165944a3d03328f7844f0b57fd411bbd7e695b5e070dce756b06b9326 🔍 |
| VirtualSize | 0x530b8 |
| VirtualAddress | 0xbc6000 |
| SizeOfRawData | 0x53200 |
| PointerToRawData | 0xbbf800 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 6.55219 |
| MD5 | bf619eac0cdf3f68d496ea9344137e8b 🔍 |
|---|---|
| SHA1 | 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5 🔍 |
| SHA256 | 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560 🔍 |
| SHA3 | 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59 🔍 |
| VirtualSize | 0x100 |
| VirtualAddress | 0xc1a000 |
| SizeOfRawData | 0x200 |
| PointerToRawData | 0xc12a00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 0 |
| MD5 | 3a83baea5f724b69e545215fa2a93b01 🔍 |
|---|---|
| SHA1 | 78ebe7df7cae84c0f0978cd65395e7ab2bab7432 🔍 |
| SHA256 | 40017d9c829846f2d93e62c0832bf05b2c087ea55d89a3af903291279cc63548 🔍 |
| SHA3 | 3b5e6667c19611c653e2f920f492cfe9ae9a25c25439d643de7724c40cc677aa 🔍 |
| VirtualSize | 0xf07c |
| VirtualAddress | 0xc1b000 |
| SizeOfRawData | 0xf200 |
| PointerToRawData | 0xc12c00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
|
| Entropy | 5.45872 |
| bcryptprimitives.dll |
ProcessPrng
|
|---|---|
| kernel32.dll |
CancelIoEx
WriteFile SetFileCompletionNotificationModes HeapReAlloc GetSystemInfo GetCurrentProcessId CreateFileW DeviceIoControl CreateIoCompletionPort PostQueuedCompletionStatus GetOverlappedResult ReadFile CreateJobObjectW SetInformationJobObject GetCurrentProcess AssignProcessToJobObject GetSystemTimePreciseAsFileTime HeapSize SetEndOfFile SwitchToThread GetModuleHandleA TerminateProcess GetExitCodeProcess SleepEx ReadFileEx GetFileInformationByHandle MoveFileExW SetConsoleCtrlHandler IsProcessInJob QueryInformationJobObject SetStdHandle CreateToolhelp32Snapshot Process32First Process32Next OpenProcess GetFileSizeEx GetCurrentThreadId SetLastError WaitForSingleObjectEx CreateMutexA ReleaseMutex GetConsoleOutputCP LoadLibraryExW WriteConsoleW WriteFileEx IsProcessorFeaturePresent SetHandleInformation SetFileTime GetFullPathNameW PeekNamedPipe ReadConsoleW CreateEventW LockFileEx LoadLibraryExA ExitProcess CancelIo GetSystemDirectoryW GetWindowsDirectoryW CreateProcessW GetFileAttributesW GetModuleFileNameW GetQueuedCompletionStatusEx WaitForMultipleObjects GetTempPathW RemoveDirectoryW DeleteFileW GetFinalPathNameByHandleW CopyFileExW CreateSymbolicLinkW CreateHardLinkW CreateWaitableTimerExW SetWaitableTimer Sleep GetFileType GetDriveTypeW GetModuleHandleExW FindNextFileW FlsFree FlsSetValue FlsGetValue GlobalMemoryStatusEx ReleaseSRWLockExclusive AcquireSRWLockExclusive FlsAlloc GetStartupInfoW EnterCriticalSection LeaveCriticalSection InitializeCriticalSectionEx DeleteCriticalSection InitializeSListHead GetSystemTimeAsFileTime FreeLibrary VirtualQuery VirtualProtect FindFirstFileExW DuplicateHandle MoveFileExA CreateThread WaitForSingleObject VerSetConditionMask VerifyVersionInfoW FormatMessageW GetLastError SetFileInformationByHandle SetConsoleCursorPosition FillConsoleOutputAttribute FillConsoleOutputCharacterA GetFileInformationByHandleEx HeapAlloc CloseHandle HeapFree SetFilePointerEx InitializeConditionVariable LocalFree LoadLibraryA GetProcessHeap FindClose GetProcAddress WakeConditionVariable SleepConditionVariableCS InitializeSRWLock ReleaseSRWLockShared AcquireSRWLockShared InitOnceExecuteOnce TlsAlloc TlsGetValue TlsSetValue LoadLibraryW FlushFileBuffers CreateDirectoryW SetDefaultDllDirectories GetStdHandle SetThreadStackGuarantee GetModuleHandleW GetCurrentThread GetConsoleMode GetNativeSystemInfo SetConsoleTextAttribute GetConsoleScreenBufferInfo SetConsoleMode |
| advapi32.dll |
RegDeleteTreeW
CryptReleaseContext RegOpenKeyExW RegCloseKey RegSetValueExW RegCreateKeyExW RegDeleteValueW RegQueryValueExW CryptDestroyHash CryptHashData CryptCreateHash CryptGetHashParam CryptAcquireContextA |
| oleaut32.dll |
SysStringLen
SysFreeString |
| ws2_32.dll |
getaddrinfo
freeaddrinfo WSAStartup recv send WSASend getsockopt connect htons ntohs socket shutdown setsockopt WSASetLastError WSACloseEvent WSACreateEvent WSAEnumNetworkEvents WSAEventSelect WSAResetEvent WSAIoctl WSAWaitForMultipleEvents closesocket __WSAFDIsSet getpeername select htonl accept WSASocketW ioctlsocket bind listen getsockname WSAGetLastError WSACleanup |
| crypt32.dll |
CertGetNameStringA
CertFindExtension CryptDecodeObjectEx CryptQueryObject CryptStringToBinaryA CertFindCertificateInStore CertEnumCertificatesInStore CertDuplicateCertificateContext PFXImportCertStore CertFreeCertificateChainEngine CertCreateCertificateChainEngine CertAddEncodedCertificateToStore CertGetEnhancedKeyUsage CertOpenStore CertSetCertificateContextProperty CertVerifyCertificateChainPolicy CertFreeCertificateChain CertDuplicateCertificateChain CertGetCertificateChain CertCloseStore CertDuplicateStore CertAddCertificateContextToStore CertFreeCertificateContext |
| ole32.dll |
CoCreateInstance
CoInitializeEx |
| ntdll.dll |
NtCreateNamedPipeFile
NtDeviceIoControlFile NtCancelIoFileEx NtWriteFile NtOpenFile RtlNtStatusToDosError RtlInitUnicodeString NtCreateFile NtReadFile |
| shell32.dll |
SHGetKnownFolderPath
ShellExecuteW |
| combase.dll |
CoTaskMemFree
|
| secur32.dll |
DecryptMessage
ApplyControlToken FreeContextBuffer InitSecurityInterfaceA AcquireCredentialsHandleA FreeCredentialsHandle AcceptSecurityContext InitializeSecurityContextW QueryContextAttributesW EncryptMessage DeleteSecurityContext |
| user32.dll |
SendMessageTimeoutA
|
| KERNEL32.dll |
RtlUnwind
GetTimeZoneInformation GetStringTypeW SetEnvironmentVariableW GetCPInfo AddVectoredExceptionHandler RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind GetOEMCP GetCurrentDirectoryW lstrlenW WideCharToMultiByte GetACP MultiByteToWideChar IsValidCodePage LCMapStringW CompareStringW GetTimeFormatW GetDateFormatW OutputDebugStringW UnhandledExceptionFilter IsDebuggerPresent GetCommandLineA FileTimeToSystemTime SystemTimeToTzSpecificLocalTime EncodePointer RtlPcToFileHeader RtlUnwindEx SetUnhandledExceptionFilter RaiseException GetEnvironmentVariableW GetEnvironmentVariableA FormatMessageA GetCommandLineW FreeEnvironmentStringsW GetEnvironmentStringsW CompareStringOrdinal QueryPerformanceCounter QueryPerformanceFrequency |
| iphlpapi.dll |
if_nametoindex
|
| api-ms-win-core-synch-l1-2-0.dll (delay-loaded) |
WaitOnAddress
WakeByAddressAll WakeByAddressSingle |
| Attributes | 0x1 |
|---|---|
| Name | api-ms-win-core-synch-l1-2-0.dll |
| ModuleHandle | 0xbc4810 |
| DelayImportAddressTable | 0xbc1248 |
| DelayImportNameTable | 0xbb9220 |
| BoundDelayImportTable | 0xbb92a0 |
| UnloadDelayImportTable | 0 |
| TimeStamp | 1970-Jan-01 00:00:00 |
| Ordinal | 1 |
|---|---|
| Address | 0x862860 |
| Ordinal | 2 |
|---|---|
| Address | 0x8628e0 |
| Ordinal | 3 |
|---|---|
| Address | 0x862960 |
| Ordinal | 4 |
|---|---|
| Address | 0x8629a0 |
| Ordinal | 5 |
|---|---|
| Address | 0x862a30 |
| Ordinal | 6 |
|---|---|
| Address | 0x8623a0 |
| Ordinal | 7 |
|---|---|
| Address | 0x862550 |
| Ordinal | 8 |
|---|---|
| Address | 0x862a00 |
| Ordinal | 9 |
|---|---|
| Address | 0x862a20 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Aug-18 06:01:22 |
| Version | 0.0 |
| SizeofData | 40 |
| AddressOfRawData | 0xaa539c |
| PointerToRawData | 0xaa3f9c |
| Referenced File | rustup_init.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Aug-18 06:01:22 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0xaa53c4 |
| PointerToRawData | 0xaa3fc4 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Aug-18 06:01:22 |
| Version | 0.0 |
| SizeofData | 1148 |
| AddressOfRawData | 0xaa53d8 |
| PointerToRawData | 0xaa3fd8 |
| StartAddressOfRawData | 0x140aa58a0 |
|---|---|
| EndAddressOfRawData | 0x140aa5b38 |
| AddressOfIndex | 0x140bc484c |
| AddressOfCallbacks | 0x1408ca9f0 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_8BYTES
|
| Callbacks |
0x000000014069AFB0
0x000000014085BF80 |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0x800 |
| EditList | 0 |
| SecurityCookie | 0x140bc0580 |
| XOR Key | 0xd5fd147a |
|---|---|
| Unmarked objects | 0 |
| C++ objects (33145) | 192 |
| C objects (33145) | 22 |
| ASM objects (33145) | 11 |
| ASM objects (35721) | 10 |
| C objects (35721) | 18 |
| C++ objects (35721) | 44 |
| Imports (33145) | 5 |
| Total imports | 300 |
| C objects (36252) | 233 |
| Unmarked objects (#2) | 62 |
| Exports (36252) | 1 |
| Linker (36252) | 1 |
No comments yet.