{"id":"82155c301753f48474b18cba9a1c9389","title":"AES-Encrypted-HTTP-C2-Implant — AES-Encrypted-HTTP-C2-Implant · 木马/恶意软件 · PE64","md5":"82155c301753f48474b18cba9a1c9389","sha256":"b6d9f6a54c598edff79ce18b3ed4ee349134eaec2d9c012b7608829660e0880e","family":"AES-Encrypted-HTTP-C2-Implant","apt":null,"verdict":null,"sample_type":"木马/恶意软件","lang":"C++","file_format":"PE64","compiler":"MinGW GCC (libtomcrypt-1.18.2)","published_at":"2026-08-05T16:00:00.000Z","summary":"该样本为 MinGW GCC 编译的加密 C2 植入物（Implant），静态链接 libtomcrypt-1.18.2 密码库。使用 AES-CBC 加密 C2 通信，RSA 公钥加密进行密钥交换，Base64 编码传输数据。通过 WinINet API (InternetConnectA/HttpOpenRequestA/HttpSendRequestA) 建立 HTTP C2 通道，支持命名管道 (Named Pipe) 本地 IPC 通信和 WSASocketA 原始 Socket。具备 TLS 回调、延迟执行等反分析能力。极高的威胁等级。","url":"https://zseceye.com/report/82155c301753f48474b18cba9a1c9389","json_url":"https://zseceye.com/report/82155c301753f48474b18cba9a1c9389.json","html_url":"https://zseceye.com/report/82155c301753f48474b18cba9a1c9389","hash_urls":{"md5":"https://zseceye.com/hash/82155c301753f48474b18cba9a1c9389","sha256":"https://zseceye.com/hash/b6d9f6a54c598edff79ce18b3ed4ee349134eaec2d9c012b7608829660e0880e"},"search_urls":{"md5":"https://zseceye.com/?q=82155c301753f48474b18cba9a1c9389","sha256":"https://zseceye.com/?q=b6d9f6a54c598edff79ce18b3ed4ee349134eaec2d9c012b7608829660e0880e"},"sample_download_url":"https://zseceye.com/report/82155c301753f48474b18cba9a1c9389/sample","sample_filename":"b6d9f6a54c598edf.zip","iocs":[],"ips":[]}