Hostile 92% windows Download

ankitshuxe.Neko

Ransomware encryption indicators present

Go SyscallN dispatch referenceGo LazyProc API resolution
SHA-2564062c6dbfe0f4839fe4041f04fc465afe87db9950602867513e55c7fbfcf536c

Evidence

References the Windows user account SID 0x2c8adb–0x2c8b9b
⋯3 more rows
0x2c8b0b756e63282920282a73797363616c6c2eunc() (*syscall.
0x2c8b1b546f6b656e757365722c206572726f72Tokenuser, error
0x2c8b2b2900232a66756e63282a696e742c2073).#*func(*int, s
⋯7 more rows
Go syscall.Syscall function-pointer dispatch 0x577bdf–0x577d3f
⋯3 more rows
0x577c0f616473797374656d6c69627261727900adsystemlibrary.
0x577c1f73797363616c6c2e53797363616c6c4esyscall.SyscallN
0x577c2f0073797363616c6c2e6c6f61646c6962.syscall.loadlib
0x577c3f726172790073797363616c6c2e676574rary.syscall.get
0x577c4f70726f63616464726573730073797363procaddress.sysc
0x577c5f616c6c2e53797363616c6c0073797363all.Syscall.sysc
0x577c6f616c6c2e53797363616c6c3600737973all.Syscall6.sys
⋯13 more rows
Go binary embeds a base64 decoder symbol 0x57e2f1–0x57e561
⋯17 more rows
0x57e40175696e74382c676f2e73686170652e75uint8,go.shape.u
0x57e411696e74385d00656e636f64696e672f62int8].encoding/b
0x57e42161736536342e282a456e636f64696e67ase64.(*Encoding
0x57e431292e456e636f6465546f537472696e67).EncodeToString
0x57e44100656e636f64696e672f626173653634.encoding/base64
⋯4 more rows
0x57e491756d00656e636f64696e672f62617365um.encoding/base
0x57e4a136342e282a456e636f64696e67292e4464.(*Encoding).D
0x57e4b165636f6465537472696e6700656e636fecodeString.enco
0x57e4c164696e672f6261736536342e282a456eding/base64.(*En
0x57e4d1636f64696e67292e4465636f6465644ccoding).DecodedL
0x57e4e1656e00656e636f64696e672f62617365en.encoding/base
0x57e4f136342e6465636f6465644c656e00656e64.decodedLen.en
⋯7 more rows
Go syscall LazyProc call 0x582684–0x582794
⋯3 more rows
0x5826b44c6f61642e6465666572777261703100Load.deferwrap1.
0x5826c473797363616c6c2e282a4c617a795072syscall.(*LazyPr
0x5826d46f63292e46696e640073797363616c6coc).Find.syscall
0x5826e42e282a4c617a7950726f63292e46696e.(*LazyProc).Fin
0x5826f4642e6465666572777261703100737973d.deferwrap1.sys
0x58270463616c6c2e282a4c617a7950726f6329call.(*LazyProc)
0x5827142e43616c6c0073797363616c6c2e282a.Call.syscall.(*
0x5827244c617a7950726f63292e6d7573744669LazyProc).mustFi
⋯7 more rows
Go x/sys/windows DLL-loading API reference 0x59b94f–0x59ba1f
⋯3 more rows
0x59b97f4c4c4572726f72292e556e7772617000LLError).Unwrap.
0x59b98f676f6c616e672e6f72672f782f737973golang.org/x/sys
0x59b99f2f77696e646f77732e4c6f6164444c4c/windows.LoadDLL
0x59b9af00676f6c616e672e6f72672f782f7379.golang.org/x/sy
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.