@endrift@social.treehouse.systems
Post #1705127
2026-04-16 06:47 UTC
The program itself is heavily Windows-specific to a degree I don't understand. It appears to inject a block of machine code (I see a nop sled at the beginning of the bytestring) into something but I'm out of my depth here. SHA-256 of the file is e86c0415e102c0e72265f7145b472e85e537135866e33e8d865d536f6e569c1c and I've uploaded it to VirusTotal: https://www.virustotal.com/gui/file/e86c0415e102c0e72265f7145b472e85e537135866e33e8d865d536f6e569c1c
Replies (1)
-
@endrift@social.treehouse.systems 2026-04-16 06:48
I will provide the deobfuscated virus on request if any malware analysts want it.