{"id":"94d210eb70c4f5618fc8e2e42dc255fa","title":"WinHTTP 下载器 — WinHTTP 下载器 · 木马/恶意软件 · PE64","md5":"94d210eb70c4f5618fc8e2e42dc255fa","sha256":"00cc775fb18128c434bd5703f4dd29fca48b68791bbc2f9bfa8eb9c3ba7d2a5a","family":"WinHTTP 下载器","apt":null,"verdict":null,"sample_type":"木马/恶意软件","lang":"未知","file_format":"PE64","compiler":"MSVC 2022","published_at":"2026-08-09T16:00:00.000Z","summary":"该样本是一个高度混淆的 PE64 Windows 下载器（Downloader/Dropper），使用 Microsoft Visual C/C++ (VS2022) 编译。所有字符串和 API 名称均使用 XOR（密钥 0x8e）加密，并通过 GetProcAddress + LoadLibraryA 动态解析。恶意软件利用 WinHTTP API 从远程服务器 hxxps://zewaplus[.]club/files/telemetriawork/telepuz.dll 下载 DLL 载荷，将其保存为 %APPDATA%\\ElthaxTools\\mnd_knot.dll，并通过 rundll32.exe 以 SetupComponent 导出函数执行该 DLL。代码中包含大量反调试和反沙箱技术：rdtsc 时间检测、GetProfileType 域检测、WNetCloseEnum(NULL) 反沙箱技巧、GetComputerNameA 主机名检查、GetSystemDefaultLCID 区域检查、GetNativeSystemInfo CPU 检测以及多处完整性校验。","url":"https://zseceye.com/report/94d210eb70c4f5618fc8e2e42dc255fa","json_url":"https://zseceye.com/report/94d210eb70c4f5618fc8e2e42dc255fa.json","html_url":"https://zseceye.com/report/94d210eb70c4f5618fc8e2e42dc255fa","hash_urls":{"md5":"https://zseceye.com/hash/94d210eb70c4f5618fc8e2e42dc255fa","sha256":"https://zseceye.com/hash/00cc775fb18128c434bd5703f4dd29fca48b68791bbc2f9bfa8eb9c3ba7d2a5a"},"search_urls":{"md5":"https://zseceye.com/?q=94d210eb70c4f5618fc8e2e42dc255fa","sha256":"https://zseceye.com/?q=00cc775fb18128c434bd5703f4dd29fca48b68791bbc2f9bfa8eb9c3ba7d2a5a"},"sample_download_url":"https://zseceye.com/report/94d210eb70c4f5618fc8e2e42dc255fa/sample","sample_filename":"00cc775fb18128c4.zip","iocs":[],"ips":[]}