6f4bef66261261fcb43131be8720bab817d403a09edec7455c371974b90bdb7e

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 2026-Aug-18 06:01:22
TLS Callbacks 2 callback(s) detected.
Debug artifacts rustup_init.pdb

Plugin Output

Suspicious Strings found in the binary may indicate undesirable behavior: Looks for VMWare presence:
  • vmx86
Miscellaneous malware strings:
  • cmd.exe
Contains domain names:
  • dev-guide.rust-lang.org
  • doc.rust-lang.org
  • example.com
  • github.com
  • guide.rust-lang.org
  • https://aka.ms
  • https://curl.se
  • https://doc.rust-lang.org
  • https://doc.rust-lang.org/nightly/rustc/platform-support.html
  • https://docs.rs
  • https://github.com
  • https://rust-lang.github.io
  • https://rust-lang.github.io/rustup-components-history
  • https://rust-lang.github.io/rustup/devel/concepts/components.html#previous-components
  • https://rust-lang.github.io/rustup/devel/environment-variables.html
  • https://rust-lang.github.io/rustup/installation/already-installed-rust.html
  • https://rust-lang.github.io/rustup/installation/windows-msvc.html
  • https://rustc-dev-guide.rust-lang.org
  • https://rustc-dev-guide.rust-lang.org/building/new-target.html
  • https://static.rp
  • https://static.rust-lang.org
  • https://static.rust-lang.org/rustup%USERPROFILE%\.cargo
  • https://visualstudio.microsoft.com
  • https://visualstudio.microsoft.com/downloads/
  • microsoft.com
  • openssl.org
  • rust-lang.org
  • rustc-dev-guide.rust-lang.org
  • static.rust-lang.org
  • visualstudio.microsoft.com
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Uses constants related to MD5
Uses constants related to SHA1
Uses constants related to SHA256
Uses constants related to SHA512
Microsoft's Cryptography API
Suspicious The PE contains functions most legitimate programs don't use. [!] The program may be hiding some of its imports:
  • LoadLibraryExW
  • LoadLibraryExA
  • LoadLibraryA
  • GetProcAddress
  • LoadLibraryW
Functions which can be used for anti-debugging purposes:
  • SwitchToThread
  • CreateToolhelp32Snapshot
Can access the registry:
  • RegOpenKeyExW
  • RegCloseKey
  • RegSetValueExW
  • RegCreateKeyExW
  • RegDeleteValueW
  • RegQueryValueExW
Possibly launches other programs:
  • CreateProcessW
  • ShellExecuteW
Uses Windows's Native API:
  • ntohs
  • NtCreateNamedPipeFile
  • NtDeviceIoControlFile
  • NtCancelIoFileEx
  • NtWriteFile
  • NtOpenFile
  • NtCreateFile
  • NtReadFile
Uses Microsoft's cryptographic API:
  • CryptReleaseContext
  • CryptDestroyHash
  • CryptHashData
  • CryptCreateHash
  • CryptGetHashParam
  • CryptAcquireContextA
  • CryptDecodeObjectEx
  • CryptQueryObject
  • CryptStringToBinaryA
Can create temporary files:
  • CreateFileW
  • GetTempPathW
Leverages the raw socket API to access the Internet:
  • ws2_32.dll
Enumerates local disk drives:
  • GetDriveTypeW
Manipulates other processes:
  • Process32First
  • Process32Next
  • OpenProcess
Interacts with the certificate store:
  • CertAddEncodedCertificateToStore
  • CertOpenStore
  • CertAddCertificateContextToStore
Safe VirusTotal score: 0/71 (Scanned on 2026-09-28 10:04:47) All the AVs think this file is safe.

Hashes

MD5 b147221215f594041ddb4a583ba63f5a 🔍
SHA1 b36e70f54ebe5d0b3b4eb3b700b847b802fe7b36 🔍
SHA256 6f4bef66261261fcb43131be8720bab817d403a09edec7455c371974b90bdb7e 🔍
SHA3 ff965a32631beca8f409f443ad40de9c7623aa1e5ee9318ea74875cf9fe7733e 🔍
SSDeep 98304:UkKjHueMNY0FloeUb3eXzVp+DOJb2s8PaX8h3dYBFoIvOji9/zRj+7Ma43LiVRL:/LweUbO1gVh3dYBFoIvOjiJRjW7Y6 🔍
Imports Hash 3dd378db218c8dce9833ec31ae758868 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x100

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 6
TimeDateStamp 2026-Aug-18 06:01:22
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x8c8800
SizeOfInitializedData 0x35d400
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000870BE0 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0xc2b000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x200000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 0e63d5f84028dc7563889176d8aa8bbb 🔍
SHA1 202a6f9095937b31070bb3f9dd0a5ce597658ef5 🔍
SHA256 4fd19b75e34d0a5c5256b22cc275759d901ea9d66350ad482b6249e5a0fe62ad 🔍
SHA3 58d9af3fd18e322a79f3b36d756842bb4a90e22fb1f196a47ea78398eeb67dd9 🔍
VirtualSize 0x8c8730
VirtualAddress 0x1000
SizeOfRawData 0x8c8800
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.31407

.rdata

MD5 6cb1e8c5043f485ea34b1c9c50b86a18 🔍
SHA1 6409079cc43160b8074c1a048891e0de1f8b04a4 🔍
SHA256 76c8c6400dcb736ed5b98d7d1da925e6f7a807e8bc9af5bd9cbb5506d27a902d 🔍
SHA3 12e89612edc0d655bffbd72d175fca45c9ecfba71c0607fdefecaf319499386c 🔍
VirtualSize 0x2f1794
VirtualAddress 0x8ca000
SizeOfRawData 0x2f1800
PointerToRawData 0x8c8c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.02544

.data

MD5 de631958ce94c6e927fb86846c744a49 🔍
SHA1 a29573c2dc13afb5c9f6dd44865b5bc4ff3524d8 🔍
SHA256 3f7649bf04aa88ee36398f2d689094c9b12ab4671b5ad2cc112e3ec19273c316 🔍
SHA3 fcaff114d12ac898c4948ebab59e7730ce9d28b0648f558c1e19b3a91aea25a5 🔍
VirtualSize 0x9478
VirtualAddress 0xbbc000
SizeOfRawData 0x5400
PointerToRawData 0xbba400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 2.14129

.pdata

MD5 41b86a75f8565612786001712c4fea7c 🔍
SHA1 630c2c7a49463baa086ac67187f5728e6b594fb4 🔍
SHA256 4ca8acf1140ed0a6a8d99d95199cd9afd5e5d5bf6eeee0b10e16098d95cd7827 🔍
SHA3 ebacd34165944a3d03328f7844f0b57fd411bbd7e695b5e070dce756b06b9326 🔍
VirtualSize 0x530b8
VirtualAddress 0xbc6000
SizeOfRawData 0x53200
PointerToRawData 0xbbf800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.55219

.fptable

MD5 bf619eac0cdf3f68d496ea9344137e8b 🔍
SHA1 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5 🔍
SHA256 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560 🔍
SHA3 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59 🔍
VirtualSize 0x100
VirtualAddress 0xc1a000
SizeOfRawData 0x200
PointerToRawData 0xc12a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0

.reloc

MD5 3a83baea5f724b69e545215fa2a93b01 🔍
SHA1 78ebe7df7cae84c0f0978cd65395e7ab2bab7432 🔍
SHA256 40017d9c829846f2d93e62c0832bf05b2c087ea55d89a3af903291279cc63548 🔍
SHA3 3b5e6667c19611c653e2f920f492cfe9ae9a25c25439d643de7724c40cc677aa 🔍
VirtualSize 0xf07c
VirtualAddress 0xc1b000
SizeOfRawData 0xf200
PointerToRawData 0xc12c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.45872

Imports

bcryptprimitives.dll ProcessPrng
kernel32.dll CancelIoEx
WriteFile
SetFileCompletionNotificationModes
HeapReAlloc
GetSystemInfo
GetCurrentProcessId
CreateFileW
DeviceIoControl
CreateIoCompletionPort
PostQueuedCompletionStatus
GetOverlappedResult
ReadFile
CreateJobObjectW
SetInformationJobObject
GetCurrentProcess
AssignProcessToJobObject
GetSystemTimePreciseAsFileTime
HeapSize
SetEndOfFile
SwitchToThread
GetModuleHandleA
TerminateProcess
GetExitCodeProcess
SleepEx
ReadFileEx
GetFileInformationByHandle
MoveFileExW
SetConsoleCtrlHandler
IsProcessInJob
QueryInformationJobObject
SetStdHandle
CreateToolhelp32Snapshot
Process32First
Process32Next
OpenProcess
GetFileSizeEx
GetCurrentThreadId
SetLastError
WaitForSingleObjectEx
CreateMutexA
ReleaseMutex
GetConsoleOutputCP
LoadLibraryExW
WriteConsoleW
WriteFileEx
IsProcessorFeaturePresent
SetHandleInformation
SetFileTime
GetFullPathNameW
PeekNamedPipe
ReadConsoleW
CreateEventW
LockFileEx
LoadLibraryExA
ExitProcess
CancelIo
GetSystemDirectoryW
GetWindowsDirectoryW
CreateProcessW
GetFileAttributesW
GetModuleFileNameW
GetQueuedCompletionStatusEx
WaitForMultipleObjects
GetTempPathW
RemoveDirectoryW
DeleteFileW
GetFinalPathNameByHandleW
CopyFileExW
CreateSymbolicLinkW
CreateHardLinkW
CreateWaitableTimerExW
SetWaitableTimer
Sleep
GetFileType
GetDriveTypeW
GetModuleHandleExW
FindNextFileW
FlsFree
FlsSetValue
FlsGetValue
GlobalMemoryStatusEx
ReleaseSRWLockExclusive
AcquireSRWLockExclusive
FlsAlloc
GetStartupInfoW
EnterCriticalSection
LeaveCriticalSection
InitializeCriticalSectionEx
DeleteCriticalSection
InitializeSListHead
GetSystemTimeAsFileTime
FreeLibrary
VirtualQuery
VirtualProtect
FindFirstFileExW
DuplicateHandle
MoveFileExA
CreateThread
WaitForSingleObject
VerSetConditionMask
VerifyVersionInfoW
FormatMessageW
GetLastError
SetFileInformationByHandle
SetConsoleCursorPosition
FillConsoleOutputAttribute
FillConsoleOutputCharacterA
GetFileInformationByHandleEx
HeapAlloc
CloseHandle
HeapFree
SetFilePointerEx
InitializeConditionVariable
LocalFree
LoadLibraryA
GetProcessHeap
FindClose
GetProcAddress
WakeConditionVariable
SleepConditionVariableCS
InitializeSRWLock
ReleaseSRWLockShared
AcquireSRWLockShared
InitOnceExecuteOnce
TlsAlloc
TlsGetValue
TlsSetValue
LoadLibraryW
FlushFileBuffers
CreateDirectoryW
SetDefaultDllDirectories
GetStdHandle
SetThreadStackGuarantee
GetModuleHandleW
GetCurrentThread
GetConsoleMode
GetNativeSystemInfo
SetConsoleTextAttribute
GetConsoleScreenBufferInfo
SetConsoleMode
advapi32.dll RegDeleteTreeW
CryptReleaseContext
RegOpenKeyExW
RegCloseKey
RegSetValueExW
RegCreateKeyExW
RegDeleteValueW
RegQueryValueExW
CryptDestroyHash
CryptHashData
CryptCreateHash
CryptGetHashParam
CryptAcquireContextA
oleaut32.dll SysStringLen
SysFreeString
ws2_32.dll getaddrinfo
freeaddrinfo
WSAStartup
recv
send
WSASend
getsockopt
connect
htons
ntohs
socket
shutdown
setsockopt
WSASetLastError
WSACloseEvent
WSACreateEvent
WSAEnumNetworkEvents
WSAEventSelect
WSAResetEvent
WSAIoctl
WSAWaitForMultipleEvents
closesocket
__WSAFDIsSet
getpeername
select
htonl
accept
WSASocketW
ioctlsocket
bind
listen
getsockname
WSAGetLastError
WSACleanup
crypt32.dll CertGetNameStringA
CertFindExtension
CryptDecodeObjectEx
CryptQueryObject
CryptStringToBinaryA
CertFindCertificateInStore
CertEnumCertificatesInStore
CertDuplicateCertificateContext
PFXImportCertStore
CertFreeCertificateChainEngine
CertCreateCertificateChainEngine
CertAddEncodedCertificateToStore
CertGetEnhancedKeyUsage
CertOpenStore
CertSetCertificateContextProperty
CertVerifyCertificateChainPolicy
CertFreeCertificateChain
CertDuplicateCertificateChain
CertGetCertificateChain
CertCloseStore
CertDuplicateStore
CertAddCertificateContextToStore
CertFreeCertificateContext
ole32.dll CoCreateInstance
CoInitializeEx
ntdll.dll NtCreateNamedPipeFile
NtDeviceIoControlFile
NtCancelIoFileEx
NtWriteFile
NtOpenFile
RtlNtStatusToDosError
RtlInitUnicodeString
NtCreateFile
NtReadFile
shell32.dll SHGetKnownFolderPath
ShellExecuteW
combase.dll CoTaskMemFree
secur32.dll DecryptMessage
ApplyControlToken
FreeContextBuffer
InitSecurityInterfaceA
AcquireCredentialsHandleA
FreeCredentialsHandle
AcceptSecurityContext
InitializeSecurityContextW
QueryContextAttributesW
EncryptMessage
DeleteSecurityContext
user32.dll SendMessageTimeoutA
KERNEL32.dll RtlUnwind
GetTimeZoneInformation
GetStringTypeW
SetEnvironmentVariableW
GetCPInfo
AddVectoredExceptionHandler
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
GetOEMCP
GetCurrentDirectoryW
lstrlenW
WideCharToMultiByte
GetACP
MultiByteToWideChar
IsValidCodePage
LCMapStringW
CompareStringW
GetTimeFormatW
GetDateFormatW
OutputDebugStringW
UnhandledExceptionFilter
IsDebuggerPresent
GetCommandLineA
FileTimeToSystemTime
SystemTimeToTzSpecificLocalTime
EncodePointer
RtlPcToFileHeader
RtlUnwindEx
SetUnhandledExceptionFilter
RaiseException
GetEnvironmentVariableW
GetEnvironmentVariableA
FormatMessageA
GetCommandLineW
FreeEnvironmentStringsW
GetEnvironmentStringsW
CompareStringOrdinal
QueryPerformanceCounter
QueryPerformanceFrequency
iphlpapi.dll if_nametoindex
api-ms-win-core-synch-l1-2-0.dll (delay-loaded) WaitOnAddress
WakeByAddressAll
WakeByAddressSingle

Delayed Imports

Attributes 0x1
Name api-ms-win-core-synch-l1-2-0.dll
ModuleHandle 0xbc4810
DelayImportAddressTable 0xbc1248
DelayImportNameTable 0xbb9220
BoundDelayImportTable 0xbb92a0
UnloadDelayImportTable 0
TimeStamp 1970-Jan-01 00:00:00

aws_lc_0_44_0_jent_entropy_collector_alloc

Ordinal 1
Address 0x862860

aws_lc_0_44_0_jent_entropy_collector_free

Ordinal 2
Address 0x8628e0

aws_lc_0_44_0_jent_entropy_init

Ordinal 3
Address 0x862960

aws_lc_0_44_0_jent_entropy_init_ex

Ordinal 4
Address 0x8629a0

aws_lc_0_44_0_jent_entropy_switch_notime_impl

Ordinal 5
Address 0x862a30

aws_lc_0_44_0_jent_read_entropy

Ordinal 6
Address 0x8623a0

aws_lc_0_44_0_jent_read_entropy_safe

Ordinal 7
Address 0x862550

aws_lc_0_44_0_jent_set_fips_failure_callback

Ordinal 8
Address 0x862a00

aws_lc_0_44_0_jent_version

Ordinal 9
Address 0x862a20

Version Info

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2026-Aug-18 06:01:22
Version 0.0
SizeofData 40
AddressOfRawData 0xaa539c
PointerToRawData 0xaa3f9c
Referenced File rustup_init.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2026-Aug-18 06:01:22
Version 0.0
SizeofData 20
AddressOfRawData 0xaa53c4
PointerToRawData 0xaa3fc4

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-Aug-18 06:01:22
Version 0.0
SizeofData 1148
AddressOfRawData 0xaa53d8
PointerToRawData 0xaa3fd8

TLS Callbacks

StartAddressOfRawData 0x140aa58a0
EndAddressOfRawData 0x140aa5b38
AddressOfIndex 0x140bc484c
AddressOfCallbacks 0x1408ca9f0
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_8BYTES
Callbacks 0x000000014069AFB0
0x000000014085BF80

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0x800
EditList 0
SecurityCookie 0x140bc0580

RICH Header

XOR Key 0xd5fd147a
Unmarked objects 0
C++ objects (33145) 192
C objects (33145) 22
ASM objects (33145) 11
ASM objects (35721) 10
C objects (35721) 18
C++ objects (35721) 44
Imports (33145) 5
Total imports 300
C objects (36252) 233
Unmarked objects (#2) 62
Exports (36252) 1
Linker (36252) 1

Errors

Leave a comment

No comments yet.