Hostile 92% windows Download

file

obfuscated Go loader, abused cert

Go PE hides path and resolves Win32 via SyscallNGo PE signed by abused TLS server certificate
SHA-2566230782e1c843f6ccc0727a26c039dfd0965cddd6fc6cbf19bbeff0639cb33cb

Evidence

Go types with concatenated-word obfuscation 0x16568a–0x1657ba
⋯5 more rows
0x1656da2e75707869627273645d696e7401162a.upxibrsd]int..*
0x1656ea6d61696e2e586d6f64657373736b7a61main.Xmodessskza
0x1656fa736d6e6a7100162a5b325d6d61696e2esmnjq..*[2]main.
0x16570a6f6f6479696d6776776d62777000162aoodyimgvwmbwp..*
⋯11 more rows
Go PE hides build path with SyscallN dispatch 0x2c7918–0x2c7ad8
⋯7 more rows
0x2c7988616473797374656d6c69627261727900adsystemlibrary.
0x2c799873797363616c6c2e53797363616c6c4esyscall.SyscallN
0x2c79a80073797363616c6c2e6c6f61646c6962.syscall.loadlib
0x2c79b8726172790073797363616c6c2e676574rary.syscall.get
0x2c79c870726f63616464726573730073797363procaddress.sysc
0x2c79d8616c6c2e53797363616c6c0073797363all.Syscall.sysc
0x2c79e8616c6c2e53797363616c6c3600737973all.Syscall6.sys
⋯15 more rows
Go PE hides path and resolves Win32 via SyscallN 0x2ca73d–0x2ca84d
⋯3 more rows
0x2ca76d4c6f61642e6465666572777261703100Load.deferwrap1.
0x2ca77d73797363616c6c2e282a4c617a795072syscall.(*LazyPr
0x2ca78d6f63292e46696e640073797363616c6coc).Find.syscall
0x2ca79d2e282a4c617a7950726f63292e46696e.(*LazyProc).Fin
0x2ca7ad642e6465666572777261703100737973d.deferwrap1.sys
0x2ca7bd63616c6c2e282a4c617a7950726f6329call.(*LazyProc)
0x2ca7cd2e43616c6c0073797363616c6c2e282a.Call.syscall.(*
0x2ca7dd4c617a7950726f63292e6d7573744669LazyProc).mustFi
⋯7 more rows
Go PE with retained symbol metadata 0x36f1c0–0x36f280
⋯3 more rows
0x36f1f000000000000000000000000000000000................
0x36f20000000000040000000000000001002000.............. .
0x36f2100300000000001100000030e415000100..........0.....
⋯7 more rows
Go PE signed by abused TLS server certificate 0x38bb89–0x38bd09
⋯7 more rows
0x38bbf9756e74696d652e697461626c696e6b00untime.itablink.
0x38bc09676f3a6275696c64696e666f00676f3ago:buildinfo.go:
0x38bc196275696c64696e666f2e726566007275buildinfo.ref.ru
⋯15 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.