Hostile 92% windows Download

cx-programmer 9.1 free download full.exe

obfuscated Go loader with direct syscalls

Go PE with opaque identity and raw API dispatchGo PE with opaque build identity and dynamic API dispatch
SHA-256540b4dfb2bceb2f68f26d7173f07d195f3ed5a83942fefcb92ffb583c74ffc32

Evidence

Signed PE checksum no longer matches its content 0x0–0xd0
0x04d5a90000300000004000000ffff0000MZ..............
0x108b000000000000004000000000000000........@.......
0x2000000000000000000000000000000000................
0x3000000000000000000000000080000000................
0x400e1fba0e00b409cd21b8014ccd215468........!..L.!Th
0x5069732070726f6772616d2063616e6e6fis program canno
⋯8 more rows
Go PE with opaque build identity and dynamic API dispatch 0x1a94fa–0x1a96ba
⋯7 more rows
0x1a956a616473797374656d6c69627261727900adsystemlibrary.
0x1a957a73797363616c6c2e53797363616c6c4esyscall.SyscallN
0x1a958a0073797363616c6c2e6c6f61646c6962.syscall.loadlib
0x1a959a726172790073797363616c6c2e676574rary.syscall.get
0x1a95aa70726f63616464726573730073797363procaddress.sysc
0x1a95ba616c6c2e53797363616c6c0073797363all.Syscall.sysc
0x1a95ca616c6c2e53797363616c6c3600737973all.Syscall6.sys
⋯15 more rows
Go PE with opaque identity and raw API dispatch 0x1abd1a–0x1abe2a
⋯3 more rows
0x1abd4a4c6f61642e6465666572777261703100Load.deferwrap1.
0x1abd5a73797363616c6c2e282a4c617a795072syscall.(*LazyPr
0x1abd6a6f63292e46696e640073797363616c6coc).Find.syscall
0x1abd7a2e282a4c617a7950726f63292e46696e.(*LazyProc).Fin
0x1abd8a642e6465666572777261703100737973d.deferwrap1.sys
0x1abd9a63616c6c2e282a4c617a7950726f6329call.(*LazyProc)
0x1abdaa2e43616c6c0073797363616c6c2e282a.Call.syscall.(*
0x1abdba4c617a7950726f63292e6d7573744669LazyProc).mustFi
⋯7 more rows
Go types with concatenated-word obfuscation 0x1ae54e–0x1ae78e
⋯5 more rows
0x1ae59e68677376746e767265292e4562756b00hgsvtnvre).Ebuk.
0x1ae5ae6d61696e2e44746b75006d61696e2e28main.Dtku.main.(
0x1ae5be2a51757a7365676466726d6964716e67*Quzsegdfrmidqng
⋯13 more rows
0x1ae69e2e282a4c617a79444c4c292e4e657750.(*LazyDLL).NewP
0x1ae6ae726f63006d61696e2e5070636a61796froc.main.Ppcjayo
0x1ae6be6f666a696762636663727378006d6169ofjigbcfcrsx.mai
0x1ae6ce6e2e5664776a646c006d61696e2e7278n.Vdwjdl.main.rx
0x1ae6de646e726d6f697563726e6a6171786200dnrmoiucrnjaqxb.
⋯11 more rows
Go PE with retained symbol metadata 0x22e7c0–0x22e880
⋯3 more rows
0x22e7f000000000000000000000000000000000................
0x22e80000000000040000000000000001002000.............. .
0x22e81003000000000011000000b00510000100................
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.