Benign Download

instrumentation.go

Imports Go's unsafe packageSource names ntdll virtual-memory syscall stubs
SHA-2567b6d1bebf836576266575c0a019973f28f6e80f56be1bd2c4a18e11f3ab40ed0
MaleculeH₂(DbOs)

Evidence

Imports Go's unsafe package lines 1–16
⋯4 lines
5import (
6 "fmt"
7 "unsafe"
8
9 "github.com/VoidSecSoftwares/voidsyscall/syscallwin"
⋯7 lines
Converts a Go pointer through unsafe.Pointer lines 48–58
48:5… oldProtect uint32
49 regionSize := uintptr(64)
50 err = syscallwin.NtProtectVirtualMemory(
51 uintptr(0xffffffffffffffff),
52 (*uintptr)(unsafe.Pointer(&baseAddr)),
53 &regionSize,
54 syscallwin.PAGE_EXECUTE_READWRITE,
⋯4 lines

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.