MalwareBazaar Database
This page shows some basic information the YARA rule INDICATOR_TOOL_GoCLR including corresponding malware samples.
Database Entry
| YARA Rule: | INDICATOR_TOOL_GoCLR |
|---|---|
| Author: | ditekSHen |
| Description: | Detects binaries utilizing Go-CLR for hosting the CLR in a Go process and using it to execute a DLL from disk or an assembly from memory |
| Firstseen: | 2021-04-03 06:19:56 UTC |
| Lastseen: | 2025-10-30 10:48:14 UTC |
| Sightings: | 81 |
Malware Samples
The table below shows all malware samples that matching this particular YARA rule (max 1000).
| Firstseen (UTC) | SHA256 hash | Tags | Signature | Reporter |
|---|