{"id":"b77855a61780a32b0a49e035f38438d2","title":"Mirai — Mirai · 僵尸网络/DDoS · ELF32","md5":"b77855a61780a32b0a49e035f38438d2","sha256":"1dfa46e7c90d88401770795ff748b87bb657c22223fdcfbde199b2fc82412e97","family":"Mirai","apt":"Mirai-Botnet","verdict":null,"sample_type":"僵尸网络/DDoS","lang":"C++","file_format":"ELF32","compiler":"GCC","published_at":"2026-08-10T16:00:00.000Z","summary":"该样本为 Mirai 家族僵尸网络客户端（ARM 大端架构），具备：① 连接硬编码 C2 服务器 94.154.43.12 接收攻击指令；② 通过 /dev/ptmx、/proc/cpuinfo 等实现进程隐藏与系统侦察；③ 内置 Shell 执行能力（/bin/bash、/bin/sh、/bin/busybox 等多种 shell 路径）；④ 具备 /tmp/.Kdat_tmp 临时文件落地与 /wget、/curl、/echo、/printf 下载执行能力。字符串 kernfailure 是 Mirai 内核模块加载器的标志性失败信息，armv4eb 为架构标识，GCC 3.3.2 + 4.2.1 为 Mirai 标志性交叉编译工具链。","url":"https://zseceye.com/report/b77855a61780a32b0a49e035f38438d2","json_url":"https://zseceye.com/report/b77855a61780a32b0a49e035f38438d2.json","html_url":"https://zseceye.com/report/b77855a61780a32b0a49e035f38438d2","hash_urls":{"md5":"https://zseceye.com/hash/b77855a61780a32b0a49e035f38438d2","sha256":"https://zseceye.com/hash/1dfa46e7c90d88401770795ff748b87bb657c22223fdcfbde199b2fc82412e97"},"search_urls":{"md5":"https://zseceye.com/?q=b77855a61780a32b0a49e035f38438d2","sha256":"https://zseceye.com/?q=1dfa46e7c90d88401770795ff748b87bb657c22223fdcfbde199b2fc82412e97"},"sample_download_url":"https://zseceye.com/report/b77855a61780a32b0a49e035f38438d2/sample","sample_filename":"1dfa46e7.zip","iocs":[],"ips":[]}