{"id":"816f4cae1961d3a0b8cd3ad569408b9e","title":"Sora — Sora · 信息窃取器 · ELF32","md5":"816f4cae1961d3a0b8cd3ad569408b9e","sha256":"b37d1bf8dde710cae9095a46505286c689fefa1ef911b0b0709b3833749c6efc","family":"Sora","apt":"Sora-Botnet","verdict":null,"sample_type":"信息窃取器","lang":"Renesas","file_format":"ELF32","compiler":"Renesas SH Cross-Compile","published_at":"2026-08-09T16:00:00.000Z","summary":"该样本为 Sora IoT 僵尸网络的 Renesas SH (SuperH) 架构客户端，具备企业级恶意功能。使用路由器命令注入传播（board.cgi/setup.cgi/cgi-bin），SSH 暴力破解（admin:password/administrator:password），Discord Webhook 远程通知，SSH 后门植入（PermitRootLogin yes + chpasswd），HTTP DDoS 攻击。Gang 标签：1337SoraLOADER, NiGGeRD0nks69, Kuasa, FortniteDownLOLZ。","url":"https://zseceye.com/report/816f4cae1961d3a0b8cd3ad569408b9e","json_url":"https://zseceye.com/report/816f4cae1961d3a0b8cd3ad569408b9e.json","html_url":"https://zseceye.com/report/816f4cae1961d3a0b8cd3ad569408b9e","hash_urls":{"md5":"https://zseceye.com/hash/816f4cae1961d3a0b8cd3ad569408b9e","sha256":"https://zseceye.com/hash/b37d1bf8dde710cae9095a46505286c689fefa1ef911b0b0709b3833749c6efc"},"search_urls":{"md5":"https://zseceye.com/?q=816f4cae1961d3a0b8cd3ad569408b9e","sha256":"https://zseceye.com/?q=b37d1bf8dde710cae9095a46505286c689fefa1ef911b0b0709b3833749c6efc"},"sample_download_url":"https://zseceye.com/report/816f4cae1961d3a0b8cd3ad569408b9e/sample","sample_filename":"b37d1bf8dde710ca.zip","iocs":[],"ips":[]}