{"id":"8fef12dc18195206082767f4fd15fe55","title":"QBotBlade/ECHOBOT IoT Botnet — QBotBlade/ECHOBOT IoT Botnet · 木马/恶意软件 · ELF32","md5":"8fef12dc18195206082767f4fd15fe55","sha256":"4169898705c73de32d18ff6cbabc18ab416450d4503ba51ad66e02d256e9e647","family":"QBotBlade/ECHOBOT IoT Botnet","apt":null,"verdict":null,"sample_type":"木马/恶意软件","lang":"C++","file_format":"ELF32","compiler":"Motorola m68k Cross-Compile GCC","published_at":"2026-08-09T16:00:00.000Z","summary":"该样本为 QBotBlade/ECHOBOT 物联网僵尸网络传播器 (Motorola m68k 架构)。内嵌 12+ 种路由器/IoT 设备漏洞利用，通过 UPnP SOAP AddPortMapping、TR-064 SetNTPServers、HNAP1、GPON、Netgear setup.cgi、D-Link board.cgi 等多种 CVE 漏洞进行蠕虫式传播。C2 服务器 185.183.34.45 托管 12 个架构特定的第二阶段载荷。包含 Discord Webhook 外泄通道。Bot 名称: QBotBladeSPOOKY / ECHOBOT。User-Agent 签名: r00ts3c-owned-you。","url":"https://zseceye.com/report/8fef12dc18195206082767f4fd15fe55","json_url":"https://zseceye.com/report/8fef12dc18195206082767f4fd15fe55.json","html_url":"https://zseceye.com/report/8fef12dc18195206082767f4fd15fe55","hash_urls":{"md5":"https://zseceye.com/hash/8fef12dc18195206082767f4fd15fe55","sha256":"https://zseceye.com/hash/4169898705c73de32d18ff6cbabc18ab416450d4503ba51ad66e02d256e9e647"},"search_urls":{"md5":"https://zseceye.com/?q=8fef12dc18195206082767f4fd15fe55","sha256":"https://zseceye.com/?q=4169898705c73de32d18ff6cbabc18ab416450d4503ba51ad66e02d256e9e647"},"sample_download_url":"https://zseceye.com/report/8fef12dc18195206082767f4fd15fe55/sample","sample_filename":"4169898705c73de3.zip","iocs":[],"ips":[]}