Suspicious 86% windows Download

SosomLab.NexaDir.Portable

Unsigned, embedded secrets, clipboard access

Dense x64 TLS-array pointer accessRepeated x64 stack-table indirect calls

Evidence

Dense x64 TLS-array pointer access 0x1bc9–0x1cc9
⋯7 more rows
0x1c39cccccccccccccc564883ec308b055546.......VH..0..UF
0x1c49390065488b0c2558000000488b04c1489.eH..%X...H...H
0x1c598db0a801000080b8b801000001751448.............u.H
⋯7 more rows
Load PAGE_READWRITE (0x04) into r8d/r9d 0x36d45–0x36e05
⋯3 more rows
0x36d75b7bf14008b46188944242c488d54242c.....F..D$,H.T$,
0x36d8541b8040000004889f9e89dbf14008b46A.....H........F
0x36d951c8944242c488d54242c41b804000000..D$,H.T$,A.....
⋯7 more rows
References Windows cmd.exe interpreter 0xd214d–0xd220d
⋯3 more rows
0xd217d0f84123900004989c6c740032e657865[email protected]
0xd218dc700636d642e41bf070000004d01f74c..cmd.A.....M..L
0xd219d89b5500300004c89bd5803000066c785..P...L..X...f..
⋯7 more rows
Repeated x64 stack-table indirect calls 0x1602f3–0x1603b3
⋯3 more rows
0x1603234885d27531488b8c24d80000004c89e2H..u1H..$....L..
0x160333ff9424e0000000488b8424e80000000f..$....H..$.....
0x160343b60084c00f840affffffe9ddfeffff48...............H
⋯7 more rows
Embedded ZSTD compressed data 0x17746d–0x17752d
⋯3 more rows
0x17749d440fb742044183f05a4109c87432813aD..B.A..ZA..t2.:
0x1774ad28b52ffd742a813a04224d187422813a(./.t*.:."M.t".:
0x1774bd4c5a4950741a0fb70a83f15d440fb642LZIPt......]D..B
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.