60996777bf4f37e0eec2a99d450664278f103077f12a4b59178ff240ccb1b80360996777bf4f — MinGW-w64 HTTPS Stage-1 Downloader / Reflective PE Loader
Build / RE
Toolchain: MinGW-w64 GCC 8.x (LinkVersion 2.36), PE32+ x64, 11 sections, 1c67179f5185105599a045f76bdfcd56.exe. Compiled Sun May 17 20:09:57 2026 UTC — recent build. ^[rabin2-info.txt] ^[pefile.txt:34]
CRT artefacts: __shmem3_winpthreads_tdm_ string and build path C:/crossdev/src/mingw-w64-v8-git/mingw-w64-libraries/winpthreads/src/rwlock.c confirm MinGW-w64 winpthreads runtime. ^[floss.txt:966] ^[strings.txt:970]
Stripped, no overlay: IMAGE_FILE_DEBUG_STRIPPED | LOCAL_SYMS_STRIPPED, overlay: false, signed: false. ^[rabin2-info.txt]
Cryptography: Three linked primitives in .text:
fcn.140012570— standard SHA-256 (initial constants0x6a09e667…0x5be0cd19, 64-round schedule). ^[r2:fcn.140012570]fcn.140012000— HMAC-SHA256 (XOR pads0x36/0x5c, 0x40 block size, nested invocation of SHA-256). ^[r2:fcn.140012000]fcn.140010980— bit-manipulation routine (bitstream extraction / shift-and-mask) called by crypto layer. Likely part of AES-GCM or Base64 decode pipeline. ^[r2:fcn.140010980]
String ChainingModeGCM confirms AES-GCM via BCryptSetProperty. ^[strings.txt:260] BCryptEncrypt, BCryptDecrypt, BCryptGenerateSymmetricKey imports via bcrypt.dll complete the primitive set. ^[r2:imports]
Base64: Standard alphabet ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/ present in strings. ^[strings.txt:273]
Anti-analysis / VM detection (fcn.1400121c0):
- Registry query:
RegOpenKeyExA→RegQueryValueExAonSYSTEM\CurrentControlSet\Services\Disk\Enum, searching forVBOX,VMWARE,QEMU. ^[strings.txt:236] ^[r2:fcn.1400121c0] - Timing trap:
GetCursorPos→Sleep(0x1f4)→GetTickCountdelta check against0x9c3(2499 ms threshold). ^[r2:fcn.1400121c0] IsDebuggerPresentimported. ^[r2:imports]
Payload delivery (fcn.140011e70 — downloader, fcn.1400123a0 — PE loader):
- HTTPS download:
InternetOpenAwithMozilla/5.0UA,InternetOpenUrlA→https://77.110.123.164/api/stage1,InternetReadFileinto 0x100000-byte buffer. ^[r2:fcn.140011e70] ^[strings.txt:238-240] - In-memory PE loader:
VirtualAllocRWX (flProtect = 0x40), memcpy sections, process relocations, resolve imports viaLoadLibraryA/GetProcAddress. ^[r2:fcn.1400123a0]
Orchestrator (fcn.140011640): VM check → downloader → if payload > 0x3f bytes, pass to PE loader. Entry chain: entry0 → startup/Sleep → fcn.140011640. ^[r2:fcn.140011640] ^[r2:entry0]
Deploy / ATT&CK
| Technique | Evidence | Confidence |
|---|---|---|
| T1071.001 — Application Layer Protocol: Web Protocols | HTTPS GET to 77.110.123.164/api/stage1 via WININET, Mozilla/5.0 UA |
high |
| T1105 — Ingress Tool Transfer | Downloads payload then executes in-memory without disk write | high |
| T1055 — Process Injection | In-memory PE loader maps downloaded payload as RWX and transfers execution; no CreateRemoteThread observed statically |
medium |
| T1497.001 — Virtualization/Sandbox Evasion: System Checks | Registry Disk\Enum scan for VBOX/VMWARE/QEMU; GetCursorPos/Sleep/GetTickCount timing gate |
high |
| T1622 — Data Obfuscation | AES-GCM (via bcrypt.dll) + HMAC-SHA256 integrity on downloaded payload |
medium |
| T1027.002 — Obfuscated Files or Information | No file-system persistence of payload; all execution in-memory | high |
| T1587.001 — Malicious Link | Stage-1 binary fetches stage-2 from hardcoded IP | high |
C2: https://77.110.123.164/api/stage1. No domain, no DGA — direct IP over TLS. Likely self-signed or compromised cert.
Attribution: No code reuse signatures, no PDB path, no language artefacts beyond MinGW-w64 CRT. Unattributed — singleton or n=1 cluster. Low confidence.
Static-only caveats: CAPE skipped (no Windows guest). All TTPs inferred from decompilation and strings. Network behaviour is reconstructed from WININET API usage, not observed traffic. Payload decryption key not recovered statically. No persistence mechanism observed in stage-1 — expected to live in stage-2.
Report written 2026-07-26. Static-only analysis; no dynamic detonation available.