Honeypot capture

Go DDoS botnet

VT 40/74C2 live

Fifteen attack methods, compiled from Go and shipped as a multi-architecture dropper suite. It spreads over SSH, carries IoT scanner exploits and layered persistence, and fronts a self-serve, account-gated API through which customers order attacks.

Family
Go DDoS botnet
First seen
June–July 2026
Vector
Jenkins Script Console RCE
Format
6.25 MB PE32+ x86-64 + multi-arch ELF variants (Go)
VirusTotal
40 engines: trojan.gorat/flooder; three distinct builds captured
Tags
ddos · botnet · golang · jenkins · iot
Reports
A cross-platform Go DDoS botnet-for-hire
Inside a gaming DDoS-for-hire operation
Sample
By request. Email [email protected]

SHA-256

  • 6da756970a411dade9db3c921ef4cdade550f317703d0fc12090a15d8c6778d4 Windows PE build

← All captures