{"id":"5fa693aad94069d036c7b381e077f4a2","title":"DDOSAgent — DDOSAgent · botnet · ELF","md5":"5fa693aad94069d036c7b381e077f4a2","sha256":"49886b11ba85aef3f41d4a1e94cd9056ea12e927a47ef1853c7449028dcba22e","family":"DDOSAgent","apt":null,"verdict":"malicious","sample_type":"botnet","lang":"Go","file_format":"ELF","compiler":"gc","published_at":"2026-07-30T10:29:33.236Z","summary":"该样本为 Go 编译的 Linux ELF64 僵尸网络客户端，社区沙箱标记为 TR/LINUX.DDOSAgent 家族，多引擎情报 27/63 引擎判定恶意（0 误报）。字符串揭示完整 C2 框架：DoH TXT 记录解析 C2 地址、BotID 注册与系统信息上报、SOCKS 代理、文件上传及 cron 持久化。导入表为空（import-less），脱壳尝试失败，需运行时 dump 恢复符号。综合判定恶意，置信度 90。","url":"https://zseceye.com/report/5fa693aad94069d036c7b381e077f4a2","json_url":"https://zseceye.com/report/5fa693aad94069d036c7b381e077f4a2.json","html_url":"https://zseceye.com/report/5fa693aad94069d036c7b381e077f4a2","hash_urls":{"md5":"https://zseceye.com/hash/5fa693aad94069d036c7b381e077f4a2","sha256":"https://zseceye.com/hash/49886b11ba85aef3f41d4a1e94cd9056ea12e927a47ef1853c7449028dcba22e"},"search_urls":{"md5":"https://zseceye.com/?q=5fa693aad94069d036c7b381e077f4a2","sha256":"https://zseceye.com/?q=49886b11ba85aef3f41d4a1e94cd9056ea12e927a47ef1853c7449028dcba22e"},"sample_download_url":"https://zseceye.com/report/5fa693aad94069d036c7b381e077f4a2/sample","sample_filename":"sample.zip","iocs":[{"type":"filename","value":"49886b11ba85aef3f41d4a1e94cd9056ea12e927a47ef1853c7449028dcba22e.elf","description":"当前提交文件名"},{"type":"filename","value":"h30ez.exe","description":"多引擎情报收录的传播用文件名（伪装 Windows 可执行体）"},{"type":"filename","value":"zswap_shrinkd","description":"多引擎情报收录的传播用文件名（伪装系统守护进程）"},{"type":"md5","value":"5fa693aad94069d036c7b381e077f4a2","description":"样本 MD5 哈希"},{"type":"other","value":"Vision/bot/","description":"恶意代码模块根路径"},{"type":"other","value":"anonymousSudan","description":"Bot 注册标识名称"},{"type":"other","value":"main.botCaps","description":"静态能力集注册入口函数"},{"type":"sha256","value":"49886b11ba85aef3f41d4a1e94cd9056ea12e927a47ef1853c7449028dcba22e","description":"样本 SHA256 哈希"}],"ips":[]}