Struct malwaredb_types::exec::elf::Elf
source · pub struct Elf<'a> {
pub is64bit: bool,
pub arch: Architecture,
pub has_overlay: Option<bool>,
pub ordering: Ordering,
pub executable_type: ExecutableType,
pub os: OperatingSystem,
pub sections: Option<Vec<Section<'a>>>,
pub imports: Option<Imports>,
pub interpreter: Option<String>,
pub contents: &'a [u8],
}
Expand description
The struct to partially represent the ELF (Executable and Linkable File) format
This is the file type used for Linux, *BSD (FreeBSD, OpenBSD, NetBSD, etc), Haiku, Solaris, and possibly some others.
Effort is made to fail gracefully, since malware may not obey all the rules, and some information is better than none because some part of the data wasn’t parsed correctly.
Fields§
§is64bit: bool
If the program is 64-bit
arch: Architecture
Instruction set architecture for this binary
has_overlay: Option<bool>
If the binary has extra data after the last section, could be used to hide something
ordering: Ordering
Byte ordering for this binary
executable_type: ExecutableType
Executable subtype: Program, Library, or Core file?
os: OperatingSystem
Operating System for this binary
sections: Option<Vec<Section<'a>>>
Sections of this binary
imports: Option<Imports>
External libraries used by this application or library
interpreter: Option<String>
The path for the ELF loader (or interpreter)
contents: &'a [u8]
The array containing the raw bytes used to parse this program
Implementations§
Trait Implementations§
source§impl<'a> ExecutableFile for Elf<'a>
impl<'a> ExecutableFile for Elf<'a>
source§fn architecture(&self) -> Architecture
fn architecture(&self) -> Architecture
source§fn pointer_size(&self) -> usize
fn pointer_size(&self) -> usize
source§fn operating_system(&self) -> OperatingSystem
fn operating_system(&self) -> OperatingSystem
source§fn compiled_timestamp(&self) -> Option<DateTime<Utc>>
fn compiled_timestamp(&self) -> Option<DateTime<Utc>>
source§fn num_sections(&self) -> u32
fn num_sections(&self) -> u32
source§fn import_hash(&self) -> Option<String>
fn import_hash(&self) -> Option<String>
source§fn fuzzy_imports(&self) -> Option<String>
fn fuzzy_imports(&self) -> Option<String>
source§impl<'a> SpecimenFile for Elf<'a>
impl<'a> SpecimenFile for Elf<'a>
Auto Trait Implementations§
impl<'a> Freeze for Elf<'a>
impl<'a> RefUnwindSafe for Elf<'a>
impl<'a> Send for Elf<'a>
impl<'a> Sync for Elf<'a>
impl<'a> Unpin for Elf<'a>
impl<'a> UnwindSafe for Elf<'a>
Blanket Implementations§
source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
source§unsafe fn clone_to_uninit(&self, dst: *mut T)
unsafe fn clone_to_uninit(&self, dst: *mut T)
clone_to_uninit
)source§impl<T> Instrument for T
impl<T> Instrument for T
source§fn instrument(self, span: Span) -> Instrumented<Self>
fn instrument(self, span: Span) -> Instrumented<Self>
source§fn in_current_span(self) -> Instrumented<Self>
fn in_current_span(self) -> Instrumented<Self>
source§impl<T> IntoEither for T
impl<T> IntoEither for T
source§fn into_either(self, into_left: bool) -> Either<Self, Self>
fn into_either(self, into_left: bool) -> Either<Self, Self>
self
into a Left
variant of Either<Self, Self>
if into_left
is true
.
Converts self
into a Right
variant of Either<Self, Self>
otherwise. Read moresource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
self
into a Left
variant of Either<Self, Self>
if into_left(&self)
returns true
.
Converts self
into a Right
variant of Either<Self, Self>
otherwise. Read more