{"id":"db0bfc75dd4b63ea35f103186e35c648","title":"Downloader — Downloader · 下载器/投放器 · PE64","md5":"db0bfc75dd4b63ea35f103186e35c648","sha256":"5c1c6ec40d70b1e67b864c8a55c7ad9c2384ff4b34fb52ba0509bd31311cd730","family":"Downloader","apt":null,"verdict":null,"sample_type":"下载器/投放器","lang":"C++","file_format":"PE64","compiler":"MinGW","published_at":"2026-08-10T16:00:00.000Z","summary":"该样本为典型下载执行木马（Downloader）。① 通过 wininet（InternetOpenA/InternetOpenUrlA/InternetReadFile）从硬编码 C2 http://172.98.23.179/811.b 下载二级载荷（Mozilla/5.0 UA）；② 使用 GetProcAddress 动态解析 VirtualAlloc/CreateThread/WaitForSingleObject 等 API（API 哈希/名称解析规避静态导入检测）；③ 将下载载荷通过 VirtualAlloc + VirtualProtect(PAGE_EXECUTE) + CreateThread 无文件执行（fileless shellcode）；④ 通过 regopenkeyexa/regsetvalueexa 写入 Software\\Microsoft\\Windows\\CurrentVersion\\Run 实现持久化；⑤ 使用 psapi EnumProcessModules 枚举进程模块。CAPA 确认 persist via Run registry key、allocate RWX memory、change memory protection、reference HTTP User-Agent string 等能力。","url":"https://zseceye.com/report/db0bfc75dd4b63ea35f103186e35c648","json_url":"https://zseceye.com/report/db0bfc75dd4b63ea35f103186e35c648.json","html_url":"https://zseceye.com/report/db0bfc75dd4b63ea35f103186e35c648","hash_urls":{"md5":"https://zseceye.com/hash/db0bfc75dd4b63ea35f103186e35c648","sha256":"https://zseceye.com/hash/5c1c6ec40d70b1e67b864c8a55c7ad9c2384ff4b34fb52ba0509bd31311cd730"},"search_urls":{"md5":"https://zseceye.com/?q=db0bfc75dd4b63ea35f103186e35c648","sha256":"https://zseceye.com/?q=5c1c6ec40d70b1e67b864c8a55c7ad9c2384ff4b34fb52ba0509bd31311cd730"},"sample_download_url":"https://zseceye.com/report/db0bfc75dd4b63ea35f103186e35c648/sample","sample_filename":"5c1c6ec4.zip","iocs":[],"ips":[]}