{"id":"7f35f37546899c2bcc2f0e97248c925f","title":"WinHTTP Downloader — WinHTTP Downloader · 木马/恶意软件 · PE64","md5":"7f35f37546899c2bcc2f0e97248c925f","sha256":"04171247bc9c2c317951debf194b3b80ce37d015131e8c569aaf9d39b810b9f2","family":"WinHTTP Downloader","apt":null,"verdict":null,"sample_type":"木马/恶意软件","lang":"C++","file_format":"PE64","compiler":"MSVC 2022","published_at":"2026-08-09T16:00:00.000Z","summary":"该样本为 MSVC 2022 编译的极小型 64 位 Windows 下载器（仅 13KB）。所有敏感 API 字符串使用 XOR 0xDA 密钥加密，运行时动态解密。 核心恶意行为： XOR 0xDA 字符串混淆：所有 API 名称（WinHTTP、文件操作、进程创建）均经 XOR 加密 WinHTTP 下载：完整的 WinHTTP API 链 — WinHttpOpen → WinHttpConnect → WinHttpOpenRequest → WinHttpSendRequest → WinHttpReceiveResponse → WinHttpReadData 文件写入：CreateFileA → WriteFile，将下载的 DLL 写入磁盘 载荷执行：rundll32.exe 执行下载的 DLL 内存分配：VirtualAlloc 分配可执行内存 反调试：rdtsc 指令检测调试器时间开销 自删除：DeleteFileA + MoveFileExA 删除自身痕迹 XOR 解密 API 字符串（密钥 0xDA）：winhttp.dll, WinHttpOpen, WinHttpConnect, WinHttpOpenRequest, WinHttpSendRequest, WinHttpReceiveResponse, WinHttpReadData, WinHttpQueryHeaders, WinHttpSetOption, WinHttpCloseHandle, rundll32.exe, kernel32.dll, shell32.dll, CreateFileA, WriteFile, CloseHandle, VirtualAlloc, VirtualFree, CreateProcessA, DeleteFileA, MoveFileExA, GetModuleFileNameA, CreateDirectoryA, SHGetFolderPathA","url":"https://zseceye.com/report/7f35f37546899c2bcc2f0e97248c925f","json_url":"https://zseceye.com/report/7f35f37546899c2bcc2f0e97248c925f.json","html_url":"https://zseceye.com/report/7f35f37546899c2bcc2f0e97248c925f","hash_urls":{"md5":"https://zseceye.com/hash/7f35f37546899c2bcc2f0e97248c925f","sha256":"https://zseceye.com/hash/04171247bc9c2c317951debf194b3b80ce37d015131e8c569aaf9d39b810b9f2"},"search_urls":{"md5":"https://zseceye.com/?q=7f35f37546899c2bcc2f0e97248c925f","sha256":"https://zseceye.com/?q=04171247bc9c2c317951debf194b3b80ce37d015131e8c569aaf9d39b810b9f2"},"sample_download_url":"https://zseceye.com/report/7f35f37546899c2bcc2f0e97248c925f/sample","sample_filename":"04171247bc9c2c31.zip","iocs":[],"ips":[]}