{"id":"1ea34dcd75eafc5dfd58c7a1f3f5570c","title":"Go-HTTP-Flooder — Go-HTTP-Flooder · DDoS攻击工具 · ELF64","md5":"1ea34dcd75eafc5dfd58c7a1f3f5570c","sha256":"b7d0ce1014da1bd04bfc8f04175daa5c8e26e86b2bb27a5be05f12ac1a7d6684","family":"Go-HTTP-Flooder","apt":null,"verdict":null,"sample_type":"DDoS攻击工具","lang":"Go","file_format":"ELF64","compiler":"Go","published_at":"2026-08-10T16:00:00.000Z","summary":"该样本为 Go 1.25.0 编译的 HTTP 洪水（Layer 7 DDoS）攻击工具，且带完整调试符号（not stripped），可直接读取函数名。核心函数：① main.flooder（洪水攻击主循环）；② main.connectProxy + main.parseProxies + main.proxyIndex（代理池管理，通过代理匿名发起攻击）；③ main.establishTls（TLS 连接建立，攻击 HTTPS 目标）；④ main.genRandStr（随机字符串生成，随机化 URL 路径绕过缓存/CDN）；⑤ main.useFullMode + main.useLegitHeaders（完整模式 + 合法请求头伪装）；⑥ main.threads/main.rate/main.secs（攻击线程数/速率/时长参数）。C2 服务器为 http://pc10211.ch/10211scripts.php，用于下发攻击目标与代理列表。","url":"https://zseceye.com/report/1ea34dcd75eafc5dfd58c7a1f3f5570c","json_url":"https://zseceye.com/report/1ea34dcd75eafc5dfd58c7a1f3f5570c.json","html_url":"https://zseceye.com/report/1ea34dcd75eafc5dfd58c7a1f3f5570c","hash_urls":{"md5":"https://zseceye.com/hash/1ea34dcd75eafc5dfd58c7a1f3f5570c","sha256":"https://zseceye.com/hash/b7d0ce1014da1bd04bfc8f04175daa5c8e26e86b2bb27a5be05f12ac1a7d6684"},"search_urls":{"md5":"https://zseceye.com/?q=1ea34dcd75eafc5dfd58c7a1f3f5570c","sha256":"https://zseceye.com/?q=b7d0ce1014da1bd04bfc8f04175daa5c8e26e86b2bb27a5be05f12ac1a7d6684"},"sample_download_url":"https://zseceye.com/report/1ea34dcd75eafc5dfd58c7a1f3f5570c/sample","sample_filename":"b7d0ce10.zip","iocs":[],"ips":[]}