{"id":"bdc5d7419f69b538a77b9397c5db01b6","title":"Malicious Setup Installer — Malicious Setup Installer · 木马/恶意软件 · PE64","md5":"bdc5d7419f69b538a77b9397c5db01b6","sha256":"89f5e86a2ca62dee4ea9ea65d2235efb36528f987ba4d136326612f79cfe89a9","family":"Malicious Setup Installer","apt":null,"verdict":null,"sample_type":"木马/恶意软件","lang":"C++","file_format":"PE64","compiler":"MSVC 2012","published_at":"2026-08-05T16:00:00.000Z","summary":"该样本为 Microsoft Visual C++ 2012 编译的 PE64 恶意安装器 (1.69 MB)。核心技术特征：(1) 使用 Windows Setup API 通过 rundll32.exe InstallHinfSection 安装恶意 INF 驱动/服务，这是恶意软件规避杀软的经典手法；(2) 调用 AdjustTokenPrivileges + LookupPrivilegeValueA 获取 SeShutdownPrivilege 特权，实现系统级权限提升；(3) CreateMutexA 创建互斥体确保单实例运行，防止重复感染；(4) CheckTokenMembership 检测当前进程权限级别；(5) DefaultInstall/DoInfInstall 实现自动化 INF 安装。Ghidra 反编译 93 个函数，核心恶意逻辑集中在 FUN_140001a74 (安装器)、FUN_140001ff4 (提权)、FUN_1400030a4 (互斥体)。","url":"https://zseceye.com/report/bdc5d7419f69b538a77b9397c5db01b6","json_url":"https://zseceye.com/report/bdc5d7419f69b538a77b9397c5db01b6.json","html_url":"https://zseceye.com/report/bdc5d7419f69b538a77b9397c5db01b6","hash_urls":{"md5":"https://zseceye.com/hash/bdc5d7419f69b538a77b9397c5db01b6","sha256":"https://zseceye.com/hash/89f5e86a2ca62dee4ea9ea65d2235efb36528f987ba4d136326612f79cfe89a9"},"search_urls":{"md5":"https://zseceye.com/?q=bdc5d7419f69b538a77b9397c5db01b6","sha256":"https://zseceye.com/?q=89f5e86a2ca62dee4ea9ea65d2235efb36528f987ba4d136326612f79cfe89a9"},"sample_download_url":"https://zseceye.com/report/bdc5d7419f69b538a77b9397c5db01b6/sample","sample_filename":"89f5e86a.zip","iocs":[],"ips":[]}