{"id":"af241fb458af533000e082486980c6db","title":"VB6 InfoStealer (UPX) — VB6 InfoStealer (UPX) · 木马/恶意软件 · PE32","md5":"af241fb458af533000e082486980c6db","sha256":"d8fc6ab0c070118651ca85c03f6da9ce8d56a607147b4de9e5b69689ba362adc","family":"VB6 InfoStealer (UPX)","apt":null,"verdict":null,"sample_type":"木马/恶意软件","lang":"Visual","file_format":"PE32","compiler":"Visual Basic 6.00 Native + UPX 3.03","published_at":"2026-08-09T16:00:00.000Z","summary":"该样本为 Visual Basic 6.00 原生编译的 PE32 可执行文件，使用 UPX 3.03 加壳。字符串分析发现对浏览器数据目录的引用 (AVAST Software, BraveSoftware, Microsoft)，结合 wininet.dll 网络通信和 ShellExecuteA 执行能力，判定为浏览器信息窃取器。UPX 段 (UPX0/UPX1) 确认加壳。MSVBVM60.DLL 运行时依赖确认 VB6 编译。","url":"https://zseceye.com/report/af241fb458af533000e082486980c6db","json_url":"https://zseceye.com/report/af241fb458af533000e082486980c6db.json","html_url":"https://zseceye.com/report/af241fb458af533000e082486980c6db","hash_urls":{"md5":"https://zseceye.com/hash/af241fb458af533000e082486980c6db","sha256":"https://zseceye.com/hash/d8fc6ab0c070118651ca85c03f6da9ce8d56a607147b4de9e5b69689ba362adc"},"search_urls":{"md5":"https://zseceye.com/?q=af241fb458af533000e082486980c6db","sha256":"https://zseceye.com/?q=d8fc6ab0c070118651ca85c03f6da9ce8d56a607147b4de9e5b69689ba362adc"},"sample_download_url":"https://zseceye.com/report/af241fb458af533000e082486980c6db/sample","sample_filename":"d8fc6ab0c0701186.zip","iocs":[],"ips":[]}