s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

MB-0060027211cbd1cbbb1b74d19392fc4c20a40ad1663a186984ec89569c0b9ccf high

📛 Threat Title

Unknown: new.txt

Category: Unknown Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: elf. Size: 114144 bytes. Tags: elf. Reporter: abuse_ch. First seen: 2026-09-25 11:05:46.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 0060027211cbd1cbbb1b74d19392fc4c20a40ad1663a186984ec89569c0b9ccf VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/0060027211cbd1cbbb1b74d19392fc4c20a40ad1663a186984ec89569c0b9ccf

IOC database

Type
hash_sha256
Value
0060027211cbd1cbbb1b74d19392fc4c20a40ad1663a186984ec89569c0b9ccf
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Unknown

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/0060027211cbd1cbbb1b74d19392fc4c20a40ad1663a186984ec89569c0b9ccf

hash_sha1 33d8cdcfe78808b1d722fad1f4b50a10429405d8 VT 38 / 74

IOC database

Type
hash_sha1
Value
33d8cdcfe78808b1d722fad1f4b50a10429405d8
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 38 of 74 VirusTotal vendors

VendorVerdictDetection
AhnLab-V3 malicious Linux/Xarcen.Gen
alibabacloud malicious DDoS:Linux/Xorddos.A
ALYac malicious Trojan.Generic.40116911
Antiy-AVL malicious Trojan/Linux.Xorddos
Arcabit malicious Trojan.Generic.D26422AF
Avast malicious ELF:DDOSAgent-AP [Trj]
AVG malicious ELF:DDOSAgent-AP [Trj]
Avira malicious TR/LINUX.DDOSAgent.AP
BitDefender malicious Trojan.Generic.40116911
CAT-QuickHeal malicious Elf.Trojan.A26202757
ClamAV malicious Unix.Malware.Xorddos-9856891-0
CTX malicious elf.trojan.generic
Cynet malicious Malicious (score: 99)
DrWeb malicious Linux.Siggen.12838
Elastic malicious Linux.Trojan.Xorddos
Emsisoft malicious Trojan.Generic.40116911 (B)
ESET-NOD32 malicious Linux/Xorddos.Y trojan
F-Secure malicious Trojan.TR/LINUX.DDOSAgent.AP
Fortinet malicious ELF/Xorddos.Y!tr
GData malicious Trojan.Generic.40116911
huorong malicious Trojan/Linux.Xorddos.d
Kaspersky malicious HEUR:Trojan.Linux.Agent.ja
Kingsoft malicious Linux.Trojan.Agent.ja
Lionic malicious Trojan.Linux.Xorddos.4!c
McAfeeD malicious ti!0060027211CB
Microsoft malicious Trojan:Linux/Xorddos.A!xp
MicroWorld-eScan malicious Trojan.Generic.40116911
Rising malicious Trojan.XorDDoS/Linux!1.A3E4 (CLASSIC)
Sangfor malicious Suspicious.Linux.Save.a
Skyhigh malicious Artemis!Trojan
Sophos malicious Mal/Generic-S
Symantec malicious Linux.Xorddos
Tencent malicious Trojan.Linux.Agent.gqtra
TrellixENS malicious ELF/Xorddos-JAUP!4DD24EF92A5C
TrendMicro malicious Trojan.Win32.ZYX.USBLF226
TrendMicro-HouseCall malicious Trojan.Win32.ZYX.USBLF226
Varist malicious E32/Xorddos.AU
VIPRE malicious Trojan.Generic.40116911

Details From VirusTotal

Basic Properties
MD54dd24ef92a5cfb9e1bb9e7a1607e25d3
SHA-133d8cdcfe78808b1d722fad1f4b50a10429405d8
SHA-2560060027211cbd1cbbb1b74d19392fc4c20a40ad1663a186984ec89569c0b9ccf
VHash8df611b3c38c97f6fa31c9ee21bdffd1
SSDEEP1536:8XrNgHgiazHcx6Xm53kReH5HUrpF/X0VtvmUeqLkokJwIo54ZHYQT33q7KzFVll9:8b6giaABk7FduQwMWQT33q7MkS
TLSHT1C4B33901F742EBB4E68318F1487BE724FF354D1F026088EBFBC166B07991A9158E665E
File typeELF
File type tagelf
File extensionso
MagicELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, stripped
File size111.5 KB
History
First seen on VirusTotal2026-06-02 13:06 UTC
Last submission2026-09-24 22:00 UTC
Last analysis2026-07-03 11:07 UTC
Last modified on VirusTotal2026-09-25 18:09 UTC
Known Names
  • d369fiug.exe
  • new.txt
  • new.php
  • libudev.so
  • 9wvufg.exe
hash_md5 4dd24ef92a5cfb9e1bb9e7a1607e25d3 VT 38 / 74

IOC database

Type
hash_md5
Value
4dd24ef92a5cfb9e1bb9e7a1607e25d3
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 38 of 74 VirusTotal vendors

VendorVerdictDetection
AhnLab-V3 malicious Linux/Xarcen.Gen
alibabacloud malicious DDoS:Linux/Xorddos.A
ALYac malicious Trojan.Generic.40116911
Antiy-AVL malicious Trojan/Linux.Xorddos
Arcabit malicious Trojan.Generic.D26422AF
Avast malicious ELF:DDOSAgent-AP [Trj]
AVG malicious ELF:DDOSAgent-AP [Trj]
Avira malicious TR/LINUX.DDOSAgent.AP
BitDefender malicious Trojan.Generic.40116911
CAT-QuickHeal malicious Elf.Trojan.A26202757
ClamAV malicious Unix.Malware.Xorddos-9856891-0
CTX malicious elf.trojan.generic
Cynet malicious Malicious (score: 99)
DrWeb malicious Linux.Siggen.12838
Elastic malicious Linux.Trojan.Xorddos
Emsisoft malicious Trojan.Generic.40116911 (B)
ESET-NOD32 malicious Linux/Xorddos.Y trojan
F-Secure malicious Trojan.TR/LINUX.DDOSAgent.AP
Fortinet malicious ELF/Xorddos.Y!tr
GData malicious Trojan.Generic.40116911
huorong malicious Trojan/Linux.Xorddos.d
Kaspersky malicious HEUR:Trojan.Linux.Agent.ja
Kingsoft malicious Linux.Trojan.Agent.ja
Lionic malicious Trojan.Linux.Xorddos.4!c
McAfeeD malicious ti!0060027211CB
Microsoft malicious Trojan:Linux/Xorddos.A!xp
MicroWorld-eScan malicious Trojan.Generic.40116911
Rising malicious Trojan.XorDDoS/Linux!1.A3E4 (CLASSIC)
Sangfor malicious Suspicious.Linux.Save.a
Skyhigh malicious Artemis!Trojan
Sophos malicious Mal/Generic-S
Symantec malicious Linux.Xorddos
Tencent malicious Trojan.Linux.Agent.gqtra
TrellixENS malicious ELF/Xorddos-JAUP!4DD24EF92A5C
TrendMicro malicious Trojan.Win32.ZYX.USBLF226
TrendMicro-HouseCall malicious Trojan.Win32.ZYX.USBLF226
Varist malicious E32/Xorddos.AU
VIPRE malicious Trojan.Generic.40116911

Details From VirusTotal

Basic Properties
MD54dd24ef92a5cfb9e1bb9e7a1607e25d3
SHA-133d8cdcfe78808b1d722fad1f4b50a10429405d8
SHA-2560060027211cbd1cbbb1b74d19392fc4c20a40ad1663a186984ec89569c0b9ccf
VHash8df611b3c38c97f6fa31c9ee21bdffd1
SSDEEP1536:8XrNgHgiazHcx6Xm53kReH5HUrpF/X0VtvmUeqLkokJwIo54ZHYQT33q7KzFVll9:8b6giaABk7FduQwMWQT33q7MkS
TLSHT1C4B33901F742EBB4E68318F1487BE724FF354D1F026088EBFBC166B07991A9158E665E
File typeELF
File type tagelf
File extensionso
MagicELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, stripped
File size111.5 KB
History
First seen on VirusTotal2026-06-02 13:06 UTC
Last submission2026-09-24 22:00 UTC
Last analysis2026-07-03 11:07 UTC
Last modified on VirusTotal2026-09-25 18:09 UTC
Known Names
  • d369fiug.exe
  • new.txt
  • new.php
  • libudev.so
  • 9wvufg.exe

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: elf. Size: 114144 bytes. Tags: elf. Reporter: abuse_ch. First seen: 2026-09-25 11:05:46.

Remediations (10)

  • web:github.com

    A comprehensive collection of Microsoft Intune remediation scripts and configurations designed for enterprise endpoint management, device compliance enforcement, and automated system fixes. This repository provides production-ready PowerShell scripts that integrate seamlessly with Intune's remediation framework.

  • web:github.com

    Contribute to thmrevenant/tryhackme development by creating an account on GitHub.

  • web:learn.microsoft.com

    Learn how to deal with unwanted mitigations in Windows Security, including a process to remove all mitigations and import a baseline configuration file instead.

  • web:learn.microsoft.com

    Microsoft Defender Vulnerability Management allows you to remediate vulnerabilities discovered in your environment through actionable security recommendations. You can create remediation requests that your IT administrator team can use to remediate vulnerabilities using Microsoft Intune.

  • web:msrc.microsoft.com

    Access Microsoft Security Response Center's guide to address vulnerabilities, manage security risks, and keep your systems protected with the latest updates.

  • web:windowsforum.com

    Practical mitigation and remediation guidance If you're responsible for a PC, workstation fleet, or enterprise environment, the following prioritized actions will reduce risk quickly.

  • web:windowsforum.com

    If you're running Windows 11, update now — Microsoft has closed a high‑severity remote code execution flaw in the modern Notepad app that could let a single click in a Markdown file turn into code execution under your user account.

  • web:www.fortra.com

    Security Updates on Vulnerabilities in robot (s).txt Detection Given that this is one of the most frequently found vulnerabilities, there is ample information regarding mitigation online and very good reason to get it fixed.

  • web:www.microsoft.com

    Microsoft Threat Intelligence Center (MSTIC) and Microsoft Security Response Center (MSRC) have discovered post-compromise exploitation of a newly discovered zero-day vulnerability in the Windows Common Log File System (CLFS) against a small number of targets. Microsoft released security updates to address the vulnerability, tracked as CVE 2025-29824, on April 8, 2025.

  • web:www.neowin.net

    Microsoft has shared a PowerShell script in case you mistakenly deleted a system folder believing it was malicious. The company recommends "immediate remediation ."

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.