{"id":"9d561b7795e92725f532497a59c308b2","title":"Linux极简植入体 — Linux极简植入体 · 木马/恶意软件 · ELF64","md5":"9d561b7795e92725f532497a59c308b2","sha256":"01dc4719944a22b0d4fc55112ed7d7366ea82773ffa178bedf472b3d66d8b3b9","family":"Linux极简植入体","apt":null,"verdict":null,"sample_type":"木马/恶意软件","lang":"未知","file_format":"ELF64","compiler":"Static Stripped","published_at":"2026-08-04T16:00:00.000Z","summary":"该样本是一个极简的ELF64 Linux植入体，大小仅45.7 KB。 特征: 静态链接: 无任何动态库依赖，独立运行 完全剥离(Stripped): 无符号表，函数名全部移除 无可读字符串: 所有字符串被编码/加密，strings输出纯寄存器保存模式 极低熵段: .text段无异常熵值(无加密混淆) CAPA无结果: 静态链接+stripped导致CAPA函数识别失败 威胁评估: 静态链接+stripped+无字符串是Linux后门/僵尸网络客户端的典型特征。46KB的极小尺寸适合传播和隐藏。 无动态库依赖使其可在最小化Linux系统(容器/IoT/嵌入式)上运行。 SHA256: 01dc4719944a22b0d4fc55112ed7d7366ea82773ffa178bedf472b3d66d8b3b9","url":"https://zseceye.com/report/9d561b7795e92725f532497a59c308b2","json_url":"https://zseceye.com/report/9d561b7795e92725f532497a59c308b2.json","html_url":"https://zseceye.com/report/9d561b7795e92725f532497a59c308b2","hash_urls":{"md5":"https://zseceye.com/hash/9d561b7795e92725f532497a59c308b2","sha256":"https://zseceye.com/hash/01dc4719944a22b0d4fc55112ed7d7366ea82773ffa178bedf472b3d66d8b3b9"},"search_urls":{"md5":"https://zseceye.com/?q=9d561b7795e92725f532497a59c308b2","sha256":"https://zseceye.com/?q=01dc4719944a22b0d4fc55112ed7d7366ea82773ffa178bedf472b3d66d8b3b9"},"sample_download_url":"https://zseceye.com/report/9d561b7795e92725f532497a59c308b2/sample","sample_filename":"01dc4719.zip","iocs":[],"ips":[]}