Hostile 93% Download

2026-08-22_4d5ecca69a506cac11c3b226439ad138_frostygoop_hive_luca-stealer_salatstealer_sliver

Named stealer, obfuscated Go, C2

Go PE hides path and resolves Win32 via SyscallNObfuscated Go PE with renamed main symbols
SHA-256178fd830163f46b127955422415f10d5f5a337212940ecfbb16f715b8ab2a711

Evidence

Obfuscated Go PE with renamed main symbols 0x176f5f–0x17707f
⋯5 more rows
0x176faf000b2a66756e63282920696e74000b2a..*func() int..*
0x176fbf6d61696e2e67334b5134000b2a5b325dmain.g3KQ4..*[2]
0x176fcf75696e74707472000b2a5b345d75696euintptr..*[4]uin
⋯11 more rows
Randomized Go main package symbol names 0x2d0d2f–0x2d0f5f
⋯5 more rows
0x2d0d7f56444b446963732e57756f6c62423000VDKDics.WuolbB0.
0x2d0d8f6d61696e2e58535962787a6f45526200main.XSYbxzoERb.
0x2d0d9f6d61696e2e282a4f78464a4f4e6c3451main.(*OxFJONl4Q
⋯6 more rows
0x2d0e0f457371472e4a6663486d5049536d4b42EsqG.JfcHmPISmKB
0x2d0e1f6b5663006d61696e2e6879336b4a4e00kVc.main.hy3kJN.
0x2d0e2f6d61696e2e6d314742554545006d6169main.m1GBUEE.mai
0x2d0e3f6e2e72507545346d526e6a5a31536400n.rPuE4mRnjZ1Sd.
0x2d0e4f6d61696e2e6f676561714b4f6e6e006dmain.ogeaqKOnn.m
0x2d0e5f61696e2e6276696865443774006d6169ain.bviheD7t.mai
0x2d0e6f6e2e72614a77684375436f52006d6169n.raJwhCuCoR.mai
0x2d0e7f6e2e6c6843656735416e3532006d6169n.lhCeg5An52.mai
0x2d0e8f6e2e755241666b006d61696e2e6d6f44n.uRAfk.main.moD
0x2d0e9f514255516c4542006d61696e2e7a4355QBUQlEB.main.zCU
⋯12 more rows
Go PE hides path and resolves Win32 via SyscallN 0x3450d0–0x3452b0
⋯13 more rows
0x3451a0001701001a1701001d1701002b170100............+...
0x3451b03017010046170100001801003b1801000...F.......;...
0x3451c0a0180100f2180100ff18010006190100................
0x3451d009190100091901000c19010038190100............8...
0x3451e03b190100461901005019010059190100;...F...P...Y...
0x3451f0a0190100a7190100aa190100d7190100................
0x345200da190100e4190100001a0100471a0100............G...
0x345210501a0100a21a0100b01a0100f81a0100P...............
0x345220001b0100091b0100001c0100451c0100............E...
0x345230501c01006c1c0100701c01008f1c0100P...l...p.......
⋯8 more rows
Go PE with retained symbol metadata 0x3567c0–0x356880
⋯3 more rows
0x3567f000000000000000000000000000000000................
0x35680000000000040000000000000001002000.............. .
0x356810030000000000110000001a4717000100...........G....
⋯7 more rows
Go PE hides build path with SyscallN dispatch 0x36b4b5–0x36b635
⋯7 more rows
0x36b525756e74696d652e697461626c696e6b00untime.itablink.
0x36b535676f3a6275696c64696e666f00676f3ago:buildinfo.go:
0x36b5456275696c64696e666f2e726566007275buildinfo.ref.ru
⋯15 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.