{"id":"6daa27df6d8e3f5895976033dde7f341","title":"FlyLegit — FlyLegit · 木马/恶意软件 · ELF32","md5":"6daa27df6d8e3f5895976033dde7f341","sha256":"014bbcf2d56904052a3f82d384d92d6146e5b903bbc0f09b265aa84571455f2e","family":"FlyLegit","apt":null,"verdict":null,"sample_type":"木马/恶意软件","lang":"Rust","file_format":"ELF32","compiler":"Rust","published_at":"2026-08-09T16:00:00.000Z","summary":"该样本为 FlyLegit DDoS 僵尸网络的 ARM 架构客户端，Rust 编译，静态链接，stripped。FlyLegit 是一个通过 Telegram 频道 (t.me/flylegit) 运营的 DDoS 出租服务。 核心恶意能力： HTTP DDoS 攻击：完整的 HTTP/1.1 请求构造（Accept、Accept-Encoding、Accept-Language、Host、Connection、User-Agent 头部伪造），HEAD/POST 方法 UDP 洪水攻击：udpplain 命令，原始 UDP 数据包发送 远程更新机制：wget 下载 updaterros.%s → 写入 /tmp/.b → chmod +x → 执行 反 AV 检测：通过 /etc/hosts 将 avast.com、avg.com、virustotal.com 指向 0.0.0.0 日志清理：清空 /var/log/auth.log、/var/log/secure、/var/log/messages 进程信息收集：读取 /proc/self/status、/proc/self/maps、/proc/self/exe 攻击命令：!update、!kill、udpplain、method=、port= C2 基础设施：83.168.110[.]191 和 83.168.69[.]141（瑞典），使用自定义 TCP 文本协议通信。","url":"https://zseceye.com/report/6daa27df6d8e3f5895976033dde7f341","json_url":"https://zseceye.com/report/6daa27df6d8e3f5895976033dde7f341.json","html_url":"https://zseceye.com/report/6daa27df6d8e3f5895976033dde7f341","hash_urls":{"md5":"https://zseceye.com/hash/6daa27df6d8e3f5895976033dde7f341","sha256":"https://zseceye.com/hash/014bbcf2d56904052a3f82d384d92d6146e5b903bbc0f09b265aa84571455f2e"},"search_urls":{"md5":"https://zseceye.com/?q=6daa27df6d8e3f5895976033dde7f341","sha256":"https://zseceye.com/?q=014bbcf2d56904052a3f82d384d92d6146e5b903bbc0f09b265aa84571455f2e"},"sample_download_url":"https://zseceye.com/report/6daa27df6d8e3f5895976033dde7f341/sample","sample_filename":"014bbcf2d5690405.zip","iocs":[],"ips":[]}