MinGW-w64 Build Artifacts
Distinguishing features of binaries produced by the MinGW-w64 (Minimalist GNU for Windows) GCC toolchain.
Structural Indicators
- Linker version: Major=2, Minor=0x24 (36) or similar —
ldfrom GNU Binutils, not MSVClink.exe. ^[pefile.txt:46] - Runtime strings:
__shmem3_winpthreads_tdm_,mingw-w64,winpthreaderror paths. ^[floss.txt:966] - CRT imports:
msvcrt.dllrather thanucrtbase.dll/vcruntime140.dll. - Pseudo-relocation handler:
__mingw_initltsdrot_lr/__mingw_initltsdyn_forcepresent in startup code. - No Rich header: MSVC binaries carry a Rich PE header; MinGW binaries do not.
Implications for Attribution
MinGW-w64 is common in cross-compilation environments (Linux → Windows), open-source ports, and malware builders that avoid MSVC licensing. Its presence alone is not malicious, but combined with stripped symbols, no overlay, and minimal imports it is a frequent fingerprint for custom droppers and loaders.
Pages Where Observed
- unclassified-mingw64-https-stager — stage-1 downloader with winpthreads runtime
- 9d2ca3 — Amadey-dropped MinGW-w64 encrypted
.datapayload cluster - chacha8 — MinGW-w64 ChaCha20 destructive encryptor
- esmk-crypter-loader — MinGW-w64 reflective PE loader
- uniqfile — MinGW-w64
.rdatareflective loader (e79a525e)