CAPEv2 icon indicating copy to clipboard operation
CAPEv2 copied to clipboard

CAPEv2 cannot handle with GoLang go-clr-based droppers

Open yevhenprotsenko opened this issue 3 years ago • 1 comments

GoLang_ServHelper.zip

The password is infected. The final payload should be ServHelper RAT. The dropper should load the .NET ServHelper dropper into memory to execute it.

yevhenprotsenko avatar Dec 24 '21 13:12 yevhenprotsenko

Thanks - it's a well known issue that golang samples do not work well in cape. I'm actively researching the issues which are related to golang's use of its own stack which causes issues with api hooking. Watch this space.

kevoreilly avatar Dec 24 '21 15:12 kevoreilly