Rust Windows Malware
Native Windows PE samples with high-confidence Rust compiler and runtime artifacts.
root@orderofsixangles:~$ ./open_corpus --scope windows-pe
controlled research corpus
Purpose-built Windows PE sets for reverse engineering, detector validation and malware-analysis education. Every file is hash-verified and assigned to exactly one collection.
index / 2026.08
50 samples per set · SHA-256 named · R2 delivery
Native Windows PE samples with high-confidence Rust compiler and runtime artifacts.
Go-compiled Windows executables confirmed through readable build metadata and runtime structures.
Managed Windows malware selected through structural CLR metadata in the PE optional header.
Samples carrying recognizable packer or commercial protector section signatures.
PE files selected from multiple independent entropy, import, string, section and entry-point signals.
A balanced set protected by VMProtect, Themida, WinLicense, Secure VMP, VProtect or Enigma.
Samples with direct remote-memory, thread, APC, process-hollowing or context-manipulation capabilities.
Credential-focused PE files targeting DPAPI, browser databases, LSASS or keyboard input.
Remote-access samples combining network communication with command execution and control artifacts.
File-impacting samples combining enumeration, modification and encryption with recovery inhibition.
Native-subsystem PE drivers with structural kernel characteristics and kernel import evidence.