Hostile 92% windows Download

QuickFetch.exe

obfuscated Go loader, abused cert

Go PE hides path and resolves Win32 via SyscallNGo PE signed by abused TLS server certificate
SHA-256e6d68f489e840cfd04b764b40adf3d41820d0c9d979d7af21edddc8295aaf1e2

Evidence

Go types with concatenated-word obfuscation 0x13f517–0x13f647
⋯5 more rows
0x13f56772756e74696d6553746465727201172aruntimeStderr..*
0x13f5776d61696e2e506f687968697862797774main.Pohyhixbywt
0x13f5876f707968736f00172a6d61696e2e636bopyhso..*main.ck
0x13f59777716b71676f6b747079716c66636800wqkqgoktpyqlfch.
⋯11 more rows
Go PE hides build path with SyscallN dispatch 0x24ef40–0x24f100
⋯7 more rows
0x24efb0616473797374656d6c69627261727900adsystemlibrary.
0x24efc073797363616c6c2e53797363616c6c4esyscall.SyscallN
0x24efd00073797363616c6c2e6c6f61646c6962.syscall.loadlib
0x24efe0726172790073797363616c6c2e676574rary.syscall.get
0x24eff070726f63616464726573730073797363procaddress.sysc
0x24f000616c6c2e53797363616c6c0073797363all.Syscall.sysc
0x24f010616c6c2e53797363616c6c3600737973all.Syscall6.sys
⋯15 more rows
Go PE hides path and resolves Win32 via SyscallN 0x251d65–0x251e75
⋯3 more rows
0x251d954c6f61642e6465666572777261703100Load.deferwrap1.
0x251da573797363616c6c2e282a4c617a795072syscall.(*LazyPr
0x251db56f63292e46696e640073797363616c6coc).Find.syscall
0x251dc52e282a4c617a7950726f63292e46696e.(*LazyProc).Fin
0x251dd5642e6465666572777261703100737973d.deferwrap1.sys
0x251de563616c6c2e282a4c617a7950726f6329call.(*LazyProc)
0x251df52e43616c6c0073797363616c6c2e282a.Call.syscall.(*
0x251e054c617a7950726f63292e6d7573744669LazyProc).mustFi
⋯7 more rows
Go PE with retained symbol metadata 0x2f2bc0–0x2f2c80
⋯3 more rows
0x2f2bf000000000000000000000000000000000................
0x2f2c0000000000040000000000000001002000.............. .
0x2f2c1003000000000011000000708713000100..........p.....
⋯7 more rows
Go PE signed by abused TLS server certificate 0x30f5ee–0x30f76e
⋯7 more rows
0x30f65e756e74696d652e697461626c696e6b00untime.itablink.
0x30f66e676f3a6275696c64696e666f00676f3ago:buildinfo.go:
0x30f67e6275696c64696e666f2e726566007275buildinfo.ref.ru
⋯15 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.