受 golang_loader_assist 和 jeb-golang-analyzer 启发,本菜为 IDAPro 写了一个更完备的 Go 二进制文件解析工具。现开源出来:
GitHub Repo: 041K9s2c8@1M7s2y4Q4x3@1q4Q4x3V1k6Q4x3V1k6Y4K9i4c8Z5N6h3u0Q4x3X3g2U0L8$3#2Q4x3V1j5H3P5r3A6A6j5i4W2#2i4K6u0r3k6$3!0Q4y4h3k6H3j5i4u0K6k6i4t1`.
关于 PIE mode,多说一句。很多人编译 Go 程序时没注意过 go buildmode,其中一个比较特殊的 buildmode=pie,可以生成地址无关的二进制文件,进而结合 ASLR 技术加强自身安全性。这对 Go 自身的内存安全机制来说,是个锦上添花的特性。详情参考:
其实这个 buildmode 还有一个鲜为人知的效果:在用此模式编译出的二进制文件面前,当前业界公开的 Go binary parse script/plugin for disassemblers 就跪了,分析不了。连鄙人眼中曾经最强的 Go 二进制逆向解析工具 redress( hxxps://go-re.tk/redress/ ) 也无能为力:
使用 GoParser 在 IDA 中分析 DDGMiner v5029 (MD5: 95199e8f1ab987cd8179a60834644663) 样本中核心的配置文件 struct 解析结果示例如下:
样本源码文件列表:
[培训]科锐逆向工程师培训第53期2025年7月8日开班!
大佬,与它(65dK9s2c8@1M7s2y4Q4x3@1q4Q4x3V1k6Q4x3V1k6Y4K9i4c8Z5N6h3u0Q4x3X3g2U0L8$3#2Q4x3V1k6K6K9h3u0W2j5i4u0K6i4K6u0r3d9f1c8m8c8$3!0D9j5h3&6Y4d9r3g2D9M7r3g2J5i4@1g2r3i4@1u0o6i4K6R3&6i4@1f1%4i4K6W2n7i4@1t1^5i4@1f1$3i4@1q4r3i4K6V1@1i4@1g2r3i4@1u0o6i4K6S2o6i4@1f1@1i4@1u0o6i4K6V1^5i4@1f1%4i4@1u0o6i4@1u0m8i4@1f1%4i4K6R3J5i4@1t1&6i4@1f1#2i4@1p5$3i4K6R3J5i4@1f1@1i4@1u0p5i4K6V1#2i4@1f1#2i4K6V1I4i4@1p5J5i4@1g2r3i4@1u0o6i4K6W2r3
CuteMiyu 請問DDGS是什麼項目? O_O
DDG 是一个核心样本由 Go 语言编写的挖矿僵尸网络,详情戳:66dK9s2c8@1M7s2y4Q4x3@1q4Q4x3V1k6Q4x3V1k6T1L8r3!0Y4i4K6u0W2L8X3g2@1L8r3q4T1i4K6u0W2x3K6j5H3i4K6u0W2j5$3!0E0i4K6u0r3N6r3q4Y4i4K6u0r3k6r3c8Y4i4K6u0r3
xmhwws 大佬,与它(2f9K9s2c8@1M7s2y4Q4x3@1q4Q4x3V1k6Q4x3V1k6Y4K9i4c8Z5N6h3u0Q4x3X3g2U0L8$3#2Q4x3V1k6K6K9h3u0W2j5i4u0K6i4K6u0r3d9f1c8m8c8$3!0D9j5h3&6Y4d9r3g2D9M7r3g2J5i4@1g2r3i4@1u0o6i4K6R3&6i4@1f1%4i4K6W2n7i4@1t1^5i4@1f1$3i4@1q4r3i4K6V1@1i4@1g2r3i4@1u0o6i4K6S2o6i4@1f1@1i4@1u0o6i4K6V1^5i4@1f1%4i4@1u0o6i4@1u0m8i4@1f1%4i4K6R3J5i4@1t1&6i4@1f1#2i4@1p5$3i4K6R3J5i4@1f1@1i4@1u0p5i4K6V1#2i4@1f1#2i4K6V1I4i4@1p5J5i4@1g2r3i4@1u0o6i4K6W2r3
xmhwws 大佬,与它(f86K9s2c8@1M7s2y4Q4x3@1q4Q4x3V1k6Q4x3V1k6Y4K9i4c8Z5N6h3u0Q4x3X3g2U0L8$3#2Q4x3V1k6K6K9h3u0W2j5i4u0K6i4K6u0r3d9f1c8m8c8$3!0D9j5h3&6Y4d9r3g2D9M7r3g2J5i4@1g2r3i4@1u0o6i4K6R3&6i4@1f1%4i4K6W2n7i4@1t1^5i4@1f1$3i4@1q4r3i4K6V1@1i4@1g2r3i4@1u0o6i4K6S2o6i4@1f1@1i4@1u0o6i4K6V1^5i4@1f1%4i4@1u0o6i4@1u0m8i4@1f1%4i4K6R3J5i4@1t1&6i4@1f1#2i4@1p5$3i4K6R3J5i4@1f1@1i4@1u0p5i4K6V1#2i4@1f1#2i4K6V1I4i4@1p5J5i4@1g2r3i4@1u0o6i4K6W2r3