{"id":"a6d90641e752faa105e8b402567f4922","title":"Themida-packed — Themida-packed · 木马/恶意软件(加壳) · PE64","md5":"a6d90641e752faa105e8b402567f4922","sha256":"523cc1bf764ee9e8df099d3c513cedc66e33709b7a258b80a0fade7dee7193b3","family":"Themida-packed","apt":null,"verdict":null,"sample_type":"木马/恶意软件(加壳)","lang":"C++","file_format":"PE64","compiler":"MSVC","published_at":"2026-08-10T16:00:00.000Z","summary":"该样本使用 Themida/Winlicense 3.XX 商业级加壳保护，这是恶意软件（尤其是 Cobalt Strike beacon、各类 RAT、窃密木马）规避检测的常见手段。Ghidra 反编译仅能恢复 2 个函数（加壳 stub），.themida/.boot 段熵高达 8.0/7.96（加密载荷）。字符串含大量 2 字符短 TLD 域名（q.th、lwu.sa、9y.fr、i.vn、ap.pw、7w.cf、bq2.co 等），呈 DGA（域名生成算法）特征，暗示加壳载荷为具备 DGA C2 的恶意软件。Themida 为商业强壳，静态解包超出本流程范围，需动态脱壳（内存 dump）进一步分析。","url":"https://zseceye.com/report/a6d90641e752faa105e8b402567f4922","json_url":"https://zseceye.com/report/a6d90641e752faa105e8b402567f4922.json","html_url":"https://zseceye.com/report/a6d90641e752faa105e8b402567f4922","hash_urls":{"md5":"https://zseceye.com/hash/a6d90641e752faa105e8b402567f4922","sha256":"https://zseceye.com/hash/523cc1bf764ee9e8df099d3c513cedc66e33709b7a258b80a0fade7dee7193b3"},"search_urls":{"md5":"https://zseceye.com/?q=a6d90641e752faa105e8b402567f4922","sha256":"https://zseceye.com/?q=523cc1bf764ee9e8df099d3c513cedc66e33709b7a258b80a0fade7dee7193b3"},"sample_download_url":"https://zseceye.com/report/a6d90641e752faa105e8b402567f4922/sample","sample_filename":"523cc1bf.zip","iocs":[],"ips":[]}