MB-0060027211cbd1cbbb1b74d19392fc4c20a40ad1663a186984ec89569c0b9ccf
high
📛 Threat Title
Unknown: new.txt
Description
File type: elf. Size: 114144 bytes. Tags: elf. Reporter: abuse_ch. First seen: 2026-09-25 11:05:46.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
0060027211cbd1cbbb1b74d19392fc4c20a40ad1663a186984ec89569c0b9ccf
VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/0060027211cbd1cbbb1b74d19392fc4c20a40ad1663a186984ec89569c0b9ccf
IOC database
- Type
- hash_sha256
- Value
0060027211cbd1cbbb1b74d19392fc4c20a40ad1663a186984ec89569c0b9ccf- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Unknown
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/0060027211cbd1cbbb1b74d19392fc4c20a40ad1663a186984ec89569c0b9ccf
hash_sha1
33d8cdcfe78808b1d722fad1f4b50a10429405d8
VT 38 / 74
IOC database
- Type
- hash_sha1
- Value
33d8cdcfe78808b1d722fad1f4b50a10429405d8- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 38 of 74 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| AhnLab-V3 | malicious | Linux/Xarcen.Gen |
| alibabacloud | malicious | DDoS:Linux/Xorddos.A |
| ALYac | malicious | Trojan.Generic.40116911 |
| Antiy-AVL | malicious | Trojan/Linux.Xorddos |
| Arcabit | malicious | Trojan.Generic.D26422AF |
| Avast | malicious | ELF:DDOSAgent-AP [Trj] |
| AVG | malicious | ELF:DDOSAgent-AP [Trj] |
| Avira | malicious | TR/LINUX.DDOSAgent.AP |
| BitDefender | malicious | Trojan.Generic.40116911 |
| CAT-QuickHeal | malicious | Elf.Trojan.A26202757 |
| ClamAV | malicious | Unix.Malware.Xorddos-9856891-0 |
| CTX | malicious | elf.trojan.generic |
| Cynet | malicious | Malicious (score: 99) |
| DrWeb | malicious | Linux.Siggen.12838 |
| Elastic | malicious | Linux.Trojan.Xorddos |
| Emsisoft | malicious | Trojan.Generic.40116911 (B) |
| ESET-NOD32 | malicious | Linux/Xorddos.Y trojan |
| F-Secure | malicious | Trojan.TR/LINUX.DDOSAgent.AP |
| Fortinet | malicious | ELF/Xorddos.Y!tr |
| GData | malicious | Trojan.Generic.40116911 |
| huorong | malicious | Trojan/Linux.Xorddos.d |
| Kaspersky | malicious | HEUR:Trojan.Linux.Agent.ja |
| Kingsoft | malicious | Linux.Trojan.Agent.ja |
| Lionic | malicious | Trojan.Linux.Xorddos.4!c |
| McAfeeD | malicious | ti!0060027211CB |
| Microsoft | malicious | Trojan:Linux/Xorddos.A!xp |
| MicroWorld-eScan | malicious | Trojan.Generic.40116911 |
| Rising | malicious | Trojan.XorDDoS/Linux!1.A3E4 (CLASSIC) |
| Sangfor | malicious | Suspicious.Linux.Save.a |
| Skyhigh | malicious | Artemis!Trojan |
| Sophos | malicious | Mal/Generic-S |
| Symantec | malicious | Linux.Xorddos |
| Tencent | malicious | Trojan.Linux.Agent.gqtra |
| TrellixENS | malicious | ELF/Xorddos-JAUP!4DD24EF92A5C |
| TrendMicro | malicious | Trojan.Win32.ZYX.USBLF226 |
| TrendMicro-HouseCall | malicious | Trojan.Win32.ZYX.USBLF226 |
| Varist | malicious | E32/Xorddos.AU |
| VIPRE | malicious | Trojan.Generic.40116911 |
Details From VirusTotal
Basic Properties
| MD5 | 4dd24ef92a5cfb9e1bb9e7a1607e25d3 |
| SHA-1 | 33d8cdcfe78808b1d722fad1f4b50a10429405d8 |
| SHA-256 | 0060027211cbd1cbbb1b74d19392fc4c20a40ad1663a186984ec89569c0b9ccf |
| VHash | 8df611b3c38c97f6fa31c9ee21bdffd1 |
| SSDEEP | 1536:8XrNgHgiazHcx6Xm53kReH5HUrpF/X0VtvmUeqLkokJwIo54ZHYQT33q7KzFVll9:8b6giaABk7FduQwMWQT33q7MkS |
| TLSH | T1C4B33901F742EBB4E68318F1487BE724FF354D1F026088EBFBC166B07991A9158E665E |
| File type | ELF |
| File type tag | elf |
| File extension | so |
| Magic | ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, stripped |
| File size | 111.5 KB |
History
| First seen on VirusTotal | 2026-06-02 13:06 UTC |
| Last submission | 2026-09-24 22:00 UTC |
| Last analysis | 2026-07-03 11:07 UTC |
| Last modified on VirusTotal | 2026-09-25 18:09 UTC |
Known Names
d369fiug.exenew.txtnew.phplibudev.so9wvufg.exe
hash_md5
4dd24ef92a5cfb9e1bb9e7a1607e25d3
VT 38 / 74
IOC database
- Type
- hash_md5
- Value
4dd24ef92a5cfb9e1bb9e7a1607e25d3- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 38 of 74 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| AhnLab-V3 | malicious | Linux/Xarcen.Gen |
| alibabacloud | malicious | DDoS:Linux/Xorddos.A |
| ALYac | malicious | Trojan.Generic.40116911 |
| Antiy-AVL | malicious | Trojan/Linux.Xorddos |
| Arcabit | malicious | Trojan.Generic.D26422AF |
| Avast | malicious | ELF:DDOSAgent-AP [Trj] |
| AVG | malicious | ELF:DDOSAgent-AP [Trj] |
| Avira | malicious | TR/LINUX.DDOSAgent.AP |
| BitDefender | malicious | Trojan.Generic.40116911 |
| CAT-QuickHeal | malicious | Elf.Trojan.A26202757 |
| ClamAV | malicious | Unix.Malware.Xorddos-9856891-0 |
| CTX | malicious | elf.trojan.generic |
| Cynet | malicious | Malicious (score: 99) |
| DrWeb | malicious | Linux.Siggen.12838 |
| Elastic | malicious | Linux.Trojan.Xorddos |
| Emsisoft | malicious | Trojan.Generic.40116911 (B) |
| ESET-NOD32 | malicious | Linux/Xorddos.Y trojan |
| F-Secure | malicious | Trojan.TR/LINUX.DDOSAgent.AP |
| Fortinet | malicious | ELF/Xorddos.Y!tr |
| GData | malicious | Trojan.Generic.40116911 |
| huorong | malicious | Trojan/Linux.Xorddos.d |
| Kaspersky | malicious | HEUR:Trojan.Linux.Agent.ja |
| Kingsoft | malicious | Linux.Trojan.Agent.ja |
| Lionic | malicious | Trojan.Linux.Xorddos.4!c |
| McAfeeD | malicious | ti!0060027211CB |
| Microsoft | malicious | Trojan:Linux/Xorddos.A!xp |
| MicroWorld-eScan | malicious | Trojan.Generic.40116911 |
| Rising | malicious | Trojan.XorDDoS/Linux!1.A3E4 (CLASSIC) |
| Sangfor | malicious | Suspicious.Linux.Save.a |
| Skyhigh | malicious | Artemis!Trojan |
| Sophos | malicious | Mal/Generic-S |
| Symantec | malicious | Linux.Xorddos |
| Tencent | malicious | Trojan.Linux.Agent.gqtra |
| TrellixENS | malicious | ELF/Xorddos-JAUP!4DD24EF92A5C |
| TrendMicro | malicious | Trojan.Win32.ZYX.USBLF226 |
| TrendMicro-HouseCall | malicious | Trojan.Win32.ZYX.USBLF226 |
| Varist | malicious | E32/Xorddos.AU |
| VIPRE | malicious | Trojan.Generic.40116911 |
Details From VirusTotal
Basic Properties
| MD5 | 4dd24ef92a5cfb9e1bb9e7a1607e25d3 |
| SHA-1 | 33d8cdcfe78808b1d722fad1f4b50a10429405d8 |
| SHA-256 | 0060027211cbd1cbbb1b74d19392fc4c20a40ad1663a186984ec89569c0b9ccf |
| VHash | 8df611b3c38c97f6fa31c9ee21bdffd1 |
| SSDEEP | 1536:8XrNgHgiazHcx6Xm53kReH5HUrpF/X0VtvmUeqLkokJwIo54ZHYQT33q7KzFVll9:8b6giaABk7FduQwMWQT33q7MkS |
| TLSH | T1C4B33901F742EBB4E68318F1487BE724FF354D1F026088EBFBC166B07991A9158E665E |
| File type | ELF |
| File type tag | elf |
| File extension | so |
| Magic | ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, stripped |
| File size | 111.5 KB |
History
| First seen on VirusTotal | 2026-06-02 13:06 UTC |
| Last submission | 2026-09-24 22:00 UTC |
| Last analysis | 2026-07-03 11:07 UTC |
| Last modified on VirusTotal | 2026-09-25 18:09 UTC |
Known Names
d369fiug.exenew.txtnew.phplibudev.so9wvufg.exe
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: elf. Size: 114144 bytes. Tags: elf. Reporter: abuse_ch. First seen: 2026-09-25 11:05:46.
Remediations (10)
-
web:github.com
A comprehensive collection of Microsoft Intune remediation scripts and configurations designed for enterprise endpoint management, device compliance enforcement, and automated system fixes. This repository provides production-ready PowerShell scripts that integrate seamlessly with Intune's remediation framework.
-
web:github.com
Contribute to thmrevenant/tryhackme development by creating an account on GitHub.
-
web:learn.microsoft.com
Learn how to deal with unwanted mitigations in Windows Security, including a process to remove all mitigations and import a baseline configuration file instead.
-
web:learn.microsoft.com
Microsoft Defender Vulnerability Management allows you to remediate vulnerabilities discovered in your environment through actionable security recommendations. You can create remediation requests that your IT administrator team can use to remediate vulnerabilities using Microsoft Intune.
-
web:msrc.microsoft.com
Access Microsoft Security Response Center's guide to address vulnerabilities, manage security risks, and keep your systems protected with the latest updates.
-
web:windowsforum.com
Practical mitigation and remediation guidance If you're responsible for a PC, workstation fleet, or enterprise environment, the following prioritized actions will reduce risk quickly.
-
web:windowsforum.com
If you're running Windows 11, update now — Microsoft has closed a high‑severity remote code execution flaw in the modern Notepad app that could let a single click in a Markdown file turn into code execution under your user account.
-
web:www.fortra.com
Security Updates on Vulnerabilities in robot (s).txt Detection Given that this is one of the most frequently found vulnerabilities, there is ample information regarding mitigation online and very good reason to get it fixed.
-
web:www.microsoft.com
Microsoft Threat Intelligence Center (MSTIC) and Microsoft Security Response Center (MSRC) have discovered post-compromise exploitation of a newly discovered zero-day vulnerability in the Windows Common Log File System (CLFS) against a small number of targets. Microsoft released security updates to address the vulnerability, tracked as CVE 2025-29824, on April 8, 2025.
-
web:www.neowin.net
Microsoft has shared a PowerShell script in case you mistakenly deleted a system folder believing it was malicious. The company recommends "immediate remediation ."
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.