{"id":"e0237c113159b6d69863ff5e74602e5c","title":"SocGholish FakeUpdate Dropper — SocGholish FakeUpdate Dropper · 下载器/投放器 · JS","md5":"e0237c113159b6d69863ff5e74602e5c","sha256":"87c810154b32fa5f61dfbe3c00a4fea700282b1588a03416e1ee7bb54c7e398e","family":"SocGholish FakeUpdate Dropper","apt":null,"verdict":null,"sample_type":"下载器/投放器","lang":"N","file_format":"JS","compiler":"N/A (Script)","published_at":"2026-08-09T16:00:00.000Z","summary":"SocGholish FakeUpdate Dropper — SocGholish (TA569) 风格的虚假浏览器更新投放器。使用 $HOLLY* 函数包装器和 ${JSON:BEGIN} 嵌入式 JSON 载荷，通过混淆的 JavaScript 代码投放恶意 PowerShell 载荷。该家族共发现 9 个变种，代表样本 SHA256: 867e698f133f0dfd...。脚本使用多种混淆技术隐藏恶意逻辑，通过 WScript/CScript 宿主执行，最终投放远程载荷或执行系统命令。","url":"https://zseceye.com/report/e0237c113159b6d69863ff5e74602e5c","json_url":"https://zseceye.com/report/e0237c113159b6d69863ff5e74602e5c.json","html_url":"https://zseceye.com/report/e0237c113159b6d69863ff5e74602e5c","hash_urls":{"md5":"https://zseceye.com/hash/e0237c113159b6d69863ff5e74602e5c","sha256":"https://zseceye.com/hash/87c810154b32fa5f61dfbe3c00a4fea700282b1588a03416e1ee7bb54c7e398e"},"search_urls":{"md5":"https://zseceye.com/?q=e0237c113159b6d69863ff5e74602e5c","sha256":"https://zseceye.com/?q=87c810154b32fa5f61dfbe3c00a4fea700282b1588a03416e1ee7bb54c7e398e"},"sample_download_url":"https://zseceye.com/report/e0237c113159b6d69863ff5e74602e5c/sample","sample_filename":"867e698f.zip","iocs":[],"ips":[]}