familyunclassified-mingw64-https-stagerconfidencemediumcreated2026-07-26
SHA-256: 60996777bf4f37e0eec2a99d450664278f103077f12a4b59178ff240ccb1b803

60996777bf4f — MinGW-w64 HTTPS Stage-1 Downloader / Reflective PE Loader

Build / RE

Toolchain: MinGW-w64 GCC 8.x (LinkVersion 2.36), PE32+ x64, 11 sections, 1c67179f5185105599a045f76bdfcd56.exe. Compiled Sun May 17 20:09:57 2026 UTC — recent build. ^[rabin2-info.txt] ^[pefile.txt:34]

CRT artefacts: __shmem3_winpthreads_tdm_ string and build path C:/crossdev/src/mingw-w64-v8-git/mingw-w64-libraries/winpthreads/src/rwlock.c confirm MinGW-w64 winpthreads runtime. ^[floss.txt:966] ^[strings.txt:970]

Stripped, no overlay: IMAGE_FILE_DEBUG_STRIPPED | LOCAL_SYMS_STRIPPED, overlay: false, signed: false. ^[rabin2-info.txt]

Cryptography: Three linked primitives in .text:

  • fcn.140012570 — standard SHA-256 (initial constants 0x6a09e667…0x5be0cd19, 64-round schedule). ^[r2:fcn.140012570]
  • fcn.140012000 — HMAC-SHA256 (XOR pads 0x36/0x5c, 0x40 block size, nested invocation of SHA-256). ^[r2:fcn.140012000]
  • fcn.140010980 — bit-manipulation routine (bitstream extraction / shift-and-mask) called by crypto layer. Likely part of AES-GCM or Base64 decode pipeline. ^[r2:fcn.140010980]

String ChainingModeGCM confirms AES-GCM via BCryptSetProperty. ^[strings.txt:260] BCryptEncrypt, BCryptDecrypt, BCryptGenerateSymmetricKey imports via bcrypt.dll complete the primitive set. ^[r2:imports]

Base64: Standard alphabet ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/ present in strings. ^[strings.txt:273]

Anti-analysis / VM detection (fcn.1400121c0):

  • Registry query: RegOpenKeyExA → RegQueryValueExA on SYSTEM\CurrentControlSet\Services\Disk\Enum, searching for VBOX, VMWARE, QEMU. ^[strings.txt:236] ^[r2:fcn.1400121c0]
  • Timing trap: GetCursorPos → Sleep(0x1f4) → GetTickCount delta check against 0x9c3 (2499 ms threshold). ^[r2:fcn.1400121c0]
  • IsDebuggerPresent imported. ^[r2:imports]

Payload delivery (fcn.140011e70 — downloader, fcn.1400123a0 — PE loader):

  • HTTPS download: InternetOpenA with Mozilla/5.0 UA, InternetOpenUrlA → https://77.110.123.164/api/stage1, InternetReadFile into 0x100000-byte buffer. ^[r2:fcn.140011e70] ^[strings.txt:238-240]
  • In-memory PE loader: VirtualAlloc RWX (flProtect = 0x40), memcpy sections, process relocations, resolve imports via LoadLibraryA/GetProcAddress. ^[r2:fcn.1400123a0]

Orchestrator (fcn.140011640): VM check → downloader → if payload > 0x3f bytes, pass to PE loader. Entry chain: entry0 → startup/Sleep → fcn.140011640. ^[r2:fcn.140011640] ^[r2:entry0]

Deploy / ATT&CK

Technique Evidence Confidence
T1071.001 — Application Layer Protocol: Web Protocols HTTPS GET to 77.110.123.164/api/stage1 via WININET, Mozilla/5.0 UA high
T1105 — Ingress Tool Transfer Downloads payload then executes in-memory without disk write high
T1055 — Process Injection In-memory PE loader maps downloaded payload as RWX and transfers execution; no CreateRemoteThread observed statically medium
T1497.001 — Virtualization/Sandbox Evasion: System Checks Registry Disk\Enum scan for VBOX/VMWARE/QEMU; GetCursorPos/Sleep/GetTickCount timing gate high
T1622 — Data Obfuscation AES-GCM (via bcrypt.dll) + HMAC-SHA256 integrity on downloaded payload medium
T1027.002 — Obfuscated Files or Information No file-system persistence of payload; all execution in-memory high
T1587.001 — Malicious Link Stage-1 binary fetches stage-2 from hardcoded IP high

C2: https://77.110.123.164/api/stage1. No domain, no DGA — direct IP over TLS. Likely self-signed or compromised cert.

Attribution: No code reuse signatures, no PDB path, no language artefacts beyond MinGW-w64 CRT. Unattributed — singleton or n=1 cluster. Low confidence.

Static-only caveats: CAPE skipped (no Windows guest). All TTPs inferred from decompilation and strings. Network behaviour is reconstructed from WININET API usage, not observed traffic. Payload decryption key not recovered statically. No persistence mechanism observed in stage-1 — expected to live in stage-2.


Report written 2026-07-26. Static-only analysis; no dynamic detonation available.