| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2026-May-30 18:10:33 |
| TLS Callbacks | 1 callback(s) detected. |
| Debug artifacts |
RustynnelPE.pdb
|
| Info | Matching compiler(s): | MASM/TASM - sig1(h) |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Miscellaneous malware strings:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to MD5 Uses constants related to SHA1 Uses constants related to SHA256 Uses constants related to SHA512 Uses constants related to RC5 or RC6 |
| Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
| Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xf0 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 5 |
| TimeDateStamp | 2026-May-30 18:10:33 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x396200 |
| SizeOfInitializedData | 0x18cc00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0000000000373A3C (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x527000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| bcryptprimitives.dll |
ProcessPrng
|
|---|---|
| kernel32.dll |
CreateWaitableTimerExW
GetConsoleMode GetStdHandle FindFirstFileExW FindClose GetQueuedCompletionStatusEx Sleep SetLastError GetProcAddress SwitchToThread GetModuleHandleA FindNextFileW CreateSymbolicLinkW SetWaitableTimer WaitForSingleObject ExitProcess DeleteFileW SetHandleInformation TerminateProcess GetCurrentThread ReadConsoleW GetFileInformationByHandleEx GetFileInformationByHandle SetFileInformationByHandle SetFileTime PostQueuedCompletionStatus CreateFileW GetFullPathNameW CreateDirectoryW WriteConsoleW CloseHandle GetConsoleOutputCP ReleaseMutex CreateMutexA GetCurrentProcessId GetCurrentProcess WaitForSingleObjectEx GetCurrentThreadId GetFinalPathNameByHandleW SetFileCompletionNotificationModes CreateIoCompletionPort CreateThread GetLastError IsProcessorFeaturePresent SetThreadStackGuarantee |
| api-ms-win-core-synch-l1-2-0.dll |
WakeByAddressSingle
WakeByAddressAll WaitOnAddress |
| ws2_32.dll |
connect
send recv WSAIoctl ioctlsocket getsockname freeaddrinfo getaddrinfo WSASocketW WSACleanup WSAStartup closesocket sendto recvfrom bind WSAGetLastError |
| ntdll.dll |
NtReadFile
NtCreateFile NtDeviceIoControlFile RtlNtStatusToDosError NtCancelIoFileEx NtWriteFile |
| bcrypt.dll |
BCryptGenRandom
|
| ADVAPI32.dll |
SystemFunction036
|
| KERNEL32.dll |
GetSystemTimeAsFileTime
SetUnhandledExceptionFilter UnhandledExceptionFilter GetSystemInfo FormatMessageW GetModuleHandleW GetEnvironmentVariableW HeapAlloc MultiByteToWideChar RtlVirtualUnwind lstrlenW LoadLibraryA InitializeSListHead RtlCaptureContext GetCurrentDirectoryW AddVectoredExceptionHandler QueryPerformanceFrequency WideCharToMultiByte GetModuleFileNameW GetCommandLineW HeapReAlloc GetSystemTimePreciseAsFileTime IsDebuggerPresent HeapFree GetProcessHeap RtlLookupFunctionEntry QueryPerformanceCounter |
| VCRUNTIME140.dll |
__current_exception
memcpy __CxxFrameHandler3 memmove memset memcmp _CxxThrowException __C_specific_handler __current_exception_context |
| api-ms-win-crt-math-l1-1-0.dll |
floorf
__setusermatherr pow cosf sinf |
| api-ms-win-crt-string-l1-1-0.dll |
strlen
|
| api-ms-win-crt-heap-l1-1-0.dll |
malloc
free _set_new_mode |
| api-ms-win-crt-runtime-l1-1-0.dll |
_c_exit
_initterm_e exit _exit _initialize_narrow_environment _seh_filter_exe _initialize_onexit_table _get_initial_narrow_environment __p___argc __p___argv terminate _set_app_type _crt_atexit _cexit _wassert _register_thread_local_exe_atexit_callback _initterm _register_onexit_function _configure_narrow_argv |
| api-ms-win-crt-stdio-l1-1-0.dll |
_set_fmode
__p__commode |
| api-ms-win-crt-locale-l1-1-0.dll |
_configthreadlocale
|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-May-30 18:10:33 |
| Version | 0.0 |
| SizeofData | 40 |
| AddressOfRawData | 0x480808 |
| PointerToRawData | 0x47ee08 |
| Referenced File | RustynnelPE.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-May-30 18:10:33 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0x480830 |
| PointerToRawData | 0x47ee30 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-May-30 18:10:33 |
| Version | 0.0 |
| SizeofData | 816 |
| AddressOfRawData | 0x480844 |
| PointerToRawData | 0x47ee44 |
| StartAddressOfRawData | 0x140480b98 |
|---|---|
| EndAddressOfRawData | 0x140480de0 |
| AddressOfIndex | 0x140501040 |
| AddressOfCallbacks | 0x140398550 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_8BYTES
|
| Callbacks |
0x00000001402B19A0
|
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x1404feb80 |
| XOR Key | 0x225b947e |
|---|---|
| Unmarked objects | 0 |
| Imports (VS2008 SP1 build 30729) | 12 |
| Imports (35207) | 2 |
| ASM objects (35207) | 4 |
| C objects (35207) | 10 |
| C++ objects (35207) | 24 |
| Imports (33145) | 7 |
| Total imports | 146 |
| C objects (35219) | 53 |
| Unmarked objects (#2) | 25 |
| Linker (35219) | 1 |
No comments yet.