Hostile 93% windows Download

6ded9017cd432164a43b918aad495ca55bba80a5c0785db7f416276fbf85a135.bin

obfuscated Go malware, C2, self-signed

Go PE hides path and resolves Win32 via SyscallNGo PE signed by abused TLS server certificate
SHA-2566ded9017cd432164a43b918aad495ca55bba80a5c0785db7f416276fbf85a135

Evidence

Go PE hides build path with SyscallN dispatch 0x53b560–0x53b720
⋯7 more rows
0x53b5d0616473797374656d6c69627261727900adsystemlibrary.
0x53b5e073797363616c6c2e53797363616c6c4esyscall.SyscallN
0x53b5f00073797363616c6c2e6c6f61646c6962.syscall.loadlib
0x53b600726172790073797363616c6c2e676574rary.syscall.get
0x53b61070726f63616464726573730073797363procaddress.sysc
0x53b620616c6c2e53797363616c6c0073797363all.Syscall.sysc
0x53b630616c6c2e53797363616c6c3600737973all.Syscall6.sys
⋯15 more rows
Go PE hides path and resolves Win32 via SyscallN 0x53e373–0x53e483
⋯3 more rows
0x53e3a34c6f61642e6465666572777261703100Load.deferwrap1.
0x53e3b373797363616c6c2e282a4c617a795072syscall.(*LazyPr
0x53e3c36f63292e46696e640073797363616c6coc).Find.syscall
0x53e3d32e282a4c617a7950726f63292e46696e.(*LazyProc).Fin
0x53e3e3642e6465666572777261703100737973d.deferwrap1.sys
0x53e3f363616c6c2e282a4c617a7950726f6329call.(*LazyProc)
0x53e4032e43616c6c0073797363616c6c2e282a.Call.syscall.(*
0x53e4134c617a7950726f63292e6d7573744669LazyProc).mustFi
⋯7 more rows
Go types with concatenated-word obfuscation 0x542608–0x542738
⋯5 more rows
0x542658617a79444c4c292e4e657750726f6300azyDLL).NewProc.
0x5426686d61696e2e5070776865636777626e66main.Ppwhecgwbnf
0x542678697079636f6a006d61696e2e4d73706aipycoj.main.Mspj
0x542688736b74006d61696e2e71786e77616b6askt.main.qxnwakj
⋯11 more rows
Go PE with retained symbol metadata 0x5df9c0–0x5dfa80
⋯3 more rows
0x5df9f000000000000000000000000000000000................
0x5dfa0000000000040000000000000001002000.............. .
0x5dfa1003000000000011000000706019000100..........p`....
⋯7 more rows
Go PE signed by abused TLS server certificate 0x5fb8b0–0x5fba30
⋯7 more rows
0x5fb920756e74696d652e697461626c696e6b00untime.itablink.
0x5fb930676f3a6275696c64696e666f00676f3ago:buildinfo.go:
0x5fb9406275696c64696e666f2e726566007275buildinfo.ref.ru
⋯15 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.