{"id":"4339992a31aaee2ca8802cff5a40c43b","title":"PE Loader / Dropper (MinGW-w64) — PE Loader / Dropper (MinGW-w64) · 下载器/投放器 · PE64","md5":"4339992a31aaee2ca8802cff5a40c43b","sha256":"3260d94ea8b51c306f506eff40997055b9cefd0a79c2b6fda4c8c8aea8e8dbc1","family":"PE Loader / Dropper (MinGW-w64)","apt":null,"verdict":null,"sample_type":"下载器/投放器","lang":"C++","file_format":"PE64","compiler":"MinGW-w64 GCC 15.2.0","published_at":"2026-08-05T16:00:00.000Z","summary":"本样本是由 MinGW-w64 GCC 15.2.0 编译的两阶段反射式 PE 加载器（Dropper），采用内存反射加载 + 管道 IPC + HTTP C2 的复合攻击架构。Stage 1 通过 VirtualAlloc(RWX) 将内嵌的 file.dll (111KB, 266 函数) 加载到内存执行。Stage 2 的 DLL 通过 TLS 回调反调试激活，创建双命名管道建立父子进程隐蔽通信，ConnectorHTTP 类实现 HTTP C2 远程控制。CAPA 检出 8 条恶意能力规则，Ghidra 反编译 266 函数，QEMU 动态执行确认样本成功运行。","url":"https://zseceye.com/report/4339992a31aaee2ca8802cff5a40c43b","json_url":"https://zseceye.com/report/4339992a31aaee2ca8802cff5a40c43b.json","html_url":"https://zseceye.com/report/4339992a31aaee2ca8802cff5a40c43b","hash_urls":{"md5":"https://zseceye.com/hash/4339992a31aaee2ca8802cff5a40c43b","sha256":"https://zseceye.com/hash/3260d94ea8b51c306f506eff40997055b9cefd0a79c2b6fda4c8c8aea8e8dbc1"},"search_urls":{"md5":"https://zseceye.com/?q=4339992a31aaee2ca8802cff5a40c43b","sha256":"https://zseceye.com/?q=3260d94ea8b51c306f506eff40997055b9cefd0a79c2b6fda4c8c8aea8e8dbc1"},"sample_download_url":"https://zseceye.com/report/4339992a31aaee2ca8802cff5a40c43b/sample","sample_filename":"3260d94e.zip","iocs":[],"ips":[]}