Hostile 92% windows Download

QuickFetch.exe

obfuscated Go loader, abused cert

Go PE hides path and resolves Win32 via SyscallNGo PE signed by abused TLS server certificate
SHA-256129917ed452c3eb6c19552d38ab4d2b4a741c35d8da76dd9b0313b868ef54c08

Evidence

Go types with concatenated-word obfuscation 0x14e8d1–0x14ea01
⋯5 more rows
0x14e92179536d616c6c46617374537472011a2aySmallFastStr..*
0x14e9316d61696e2e4b7766656f646f67676d6amain.Kwfeodoggmj
0x14e9416e72616b7376706571001a2a6d61696enraksvpeq..*main
0x14e9512e6369726d6361746f7a747a716f736d.cirmcatoztzqosm
⋯11 more rows
Go PE hides build path with SyscallN dispatch 0x26167f–0x26183f
⋯7 more rows
0x2616ef616473797374656d6c69627261727900adsystemlibrary.
0x2616ff73797363616c6c2e53797363616c6c4esyscall.SyscallN
0x26170f0073797363616c6c2e6c6f61646c6962.syscall.loadlib
0x26171f726172790073797363616c6c2e676574rary.syscall.get
0x26172f70726f63616464726573730073797363procaddress.sysc
0x26173f616c6c2e53797363616c6c0073797363all.Syscall.sysc
0x26174f616c6c2e53797363616c6c3600737973all.Syscall6.sys
⋯15 more rows
Go PE hides path and resolves Win32 via SyscallN 0x2644a4–0x2645b4
⋯3 more rows
0x2644d44c6f61642e6465666572777261703100Load.deferwrap1.
0x2644e473797363616c6c2e282a4c617a795072syscall.(*LazyPr
0x2644f46f63292e46696e640073797363616c6coc).Find.syscall
0x2645042e282a4c617a7950726f63292e46696e.(*LazyProc).Fin
0x264514642e6465666572777261703100737973d.deferwrap1.sys
0x26452463616c6c2e282a4c617a7950726f6329call.(*LazyProc)
0x2645342e43616c6c0073797363616c6c2e282a.Call.syscall.(*
0x2645444c617a7950726f63292e6d7573744669LazyProc).mustFi
⋯7 more rows
Go PE with retained symbol metadata 0x3073c0–0x307480
⋯3 more rows
0x3073f000000000000000000000000000000000................
0x30740000000000040000000000000001002000.............. .
0x30741003000000000011000000106814000100...........h....
⋯7 more rows
Go PE signed by abused TLS server certificate 0x323d2f–0x323eaf
⋯7 more rows
0x323d9f756e74696d652e697461626c696e6b00untime.itablink.
0x323daf676f3a6275696c64696e666f00676f3ago:buildinfo.go:
0x323dbf6275696c64696e666f2e726566007275buildinfo.ref.ru
⋯15 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.