s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-69c45cca395549bf1f9ff360edbe09cda646c0b511c513e6d91515085da9694b high

📛 Threat Title

DDoSAgent: mipsel

Category: DDoSAgent Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: elf. Size: 8126679 bytes. Tags: DDoSAgent. Reporter: BlinkzSec. First seen: 2026-05-14 17:00:10.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 69c45cca395549bf1f9ff360edbe09cda646c0b511c513e6d91515085da9694b VT 36 / 75 1 feed

IOC database

Type
hash_sha256
Value
69c45cca395549bf1f9ff360edbe09cda646c0b511c513e6d91515085da9694b
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
DDoSAgent

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Flagged by 36 of 75 VirusTotal vendors

VendorVerdictDetection
alibabacloud malicious DDoS:Linux/Agent.JJ
ALYac malicious Trojan.Linux.GenericKD.79376
Antiy-AVL malicious Trojan/Linux.Agent
Arcabit malicious Trojan.Linux.DDoS.308
Avast malicious ELF:DDOSAgent-FN [Rtk]
AVG malicious ELF:DDOSAgent-FN [Rtk]
Avira malicious TR/LINUX.DDOSAgent.GA
BitDefender malicious Trojan.Linux.DDoS.308
ClamAV malicious Unix.Trojan.Mirai-10056451-0
CTX malicious elf.trojan.generic
Cynet malicious Malicious (score: 99)
DrWeb malicious Linux.DDoS.2749
Emsisoft malicious Trojan.Linux.DDoS.308 (B)
ESET-NOD32 malicious Linux/DDoS.Agent.JH trojan
F-Secure malicious Trojan.TR/LINUX.DDOSAgent.GA
Fortinet malicious Linux/DDoS_Agent.JH!tr
GData malicious Trojan.Linux.DDoS.308
Google malicious Detected
huorong malicious Trojan/Linux.DDos.bv
K7GW malicious Trojan ( 00410f2e1 )
Kaspersky malicious HEUR:Trojan-DDoS.Linux.Agent.av
Kingsoft malicious Linux.Trojan-DDoS.Agent.av
Lionic malicious Trojan.Linux.DDoS.9!c
McAfeeD malicious Trojan:Script/GenericY.FB
Microsoft malicious Trojan:Linux/Multiverze!rfn
MicroWorld-eScan malicious Trojan.Linux.DDoS.308
Rising malicious Trojan.DDoS/Linux!8.1337A (TFE:28:zVzjNSQU6wB)
SentinelOne malicious Static AI - Malicious ELF
Skyhigh malicious Artemis!Trojan
Sophos malicious Mal/Generic-S
Symantec malicious Trojan.Gen.NPE
Tencent malicious Malware.Linux.Generic.1c0818a5
TrendMicro malicious TROJ_GEN.R011C0DEI26
TrendMicro-HouseCall malicious TROJ_GEN.R011C0DEI26
Varist malicious E32/ABmRisk.UOIP-
VIPRE malicious Trojan.Linux.DDoS.308

Details From VirusTotal

Basic Properties
MD5f2408c794e63d2e1cf76a50e70e18d6b
SHA-11b95966364c569ca195918c3a035e86062fa7734
SHA-25669c45cca395549bf1f9ff360edbe09cda646c0b511c513e6d91515085da9694b
VHash1a9619329a0d05b10bb80eb19efc89c1
SSDEEP49152:Tmh61NZIdMpVriMF/0CQhx8wBAJxCaIE17Il8ZkFc05EI:+sLQhx8ImDOFxEI
TLSHT1BB860905ADC53BE6C42C5E7444EACA6122B06D140AF2463A26A4FFE9BC772757F478CC
File typeELF
File type tagelf
MagicELF 32-bit LSB executable, MIPS, MIPS32 version 1 (SYSV), statically linked, BuildID[sha1]=f14e264ce7d6e7686ded7f015de7fa7026b27852, stripped
File size7.8 MB
History
First seen on VirusTotal2026-05-14 17:00 UTC
Last submission2026-05-14 17:18 UTC
Last analysis2026-06-15 11:07 UTC
Last modified on VirusTotal2026-06-15 13:18 UTC
Known Names
  • 69c45cca395549bf1f9ff360edbe09cda646c0b511c513e6d91515085da9694b.elf
  • 0pyu
  • nc7qev
  • 81.29.156.127_sample.bin
  • toxfsg
  • mipsel
  • evd2wwgm9.exe
  • _69c45cca395549bf1f9ff360edbe09cda646c0b511c513e6d91515085da9694b.elf
hash_sha1 1b95966364c569ca195918c3a035e86062fa7734 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/1b95966364c569ca195918c3a035e86062fa7734
1 feed

IOC database

Type
hash_sha1
Value
1b95966364c569ca195918c3a035e86062fa7734
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/1b95966364c569ca195918c3a035e86062fa7734

hash_md5 f2408c794e63d2e1cf76a50e70e18d6b VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/f2408c794e63d2e1cf76a50e70e18d6b
2 feeds

IOC database

Type
hash_md5
Value
f2408c794e63d2e1cf76a50e70e18d6b
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/f2408c794e63d2e1cf76a50e70e18d6b

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: elf. Size: 8126679 bytes. Tags: DDoSAgent. Reporter: BlinkzSec. First seen: 2026-05-14 17:00:10.

Remediations (10)

  • web:www.cisa.gov

    This joint guide, Understanding and Responding to Distributed Denial-Of-Service Attacks, addresses the specific needs and challenges faced by organizations in defending against DDoS attacks. The guidance now includes detailed insight into three different types of DDoS techniques: Volumetric, attacks aiming to consume available bandwidth. Protocol, attacks which exploit vulnerabilities in ...

  • web:www.cloudflare.com

    When evaluating cloud-based mitigation services, it is important to look beyond capacity or transfer and filtering speeds, and consider network intelligence. The larger and more robust the mitigation network, the richer the intelligence it can provide on evolving attack patterns—and the more proactive protection will become.

  • web:www.enterprisenetworkingplanet.com

    By following these ten best practices, you can significantly reduce the risk and impact of these attacks. But remember, the key to effective DDoS mitigation is not just preparation and quick response, but also the ongoing commitment to adapt and evolve your strategies in line with the changing threat landscape.

  • web:www.fastly.com

    Discover the best DDoS mitigation providers of 2025-2026 with in-depth comparisons on capacity, automation, visibility, and integration.

  • web:www.fortinet.com

    A DDoS mitigation strategy is necessary to protect organizations from potentially devastating DDoS attacks. Learn the steps to DDoS mitigation and what to look for in a mitigation provider.

  • web:www.gartner.com

    Find the top DDoS Mitigation Solutions with Gartner. Compare and filter by verified product reviews and choose the software that's right for your organization.

  • web:www.joesandbox.com

    General Information Sample name: mipsel .elf Analysis ID: 1913978 Has dependencies: false MD5: de05abe41135837bebace0c77e4f7320 SHA1: 6fc3d027ab1411a66a9348c701b20a2ddd94fc36 SHA256: 4004b8630bd06be6be05dcfe4a19de67ba67a61da32981ed216470aa8c6a3c2b Tags: DDoSAgent , elf Infos:

  • web:www.microsoft.com

    Understand how this virus or malware spreads and how its payloads affects your computer. Protect against this threat, identify symptoms, and clean up or remove infections.

  • web:www.nist.gov

    Advanced DDoS Mitigation Techniques ... Summary NIST is working with DHS S&T and industry to research and develop novel approaches to DDoS detection and mitigation , techniques to test and measure the effectiveness and impact of DDoS / spoofing mitigation techniques, and to develop deployment guidance for such techniques.

  • web:www.radware.com

    DDoS (Distributed Denial of Service) mitigation is a set of tools and techniques that protect networks and systems from distributed denial-of-service (DDoS) attacks. DDoS attacks aim to disrupt the normal functioning of a target, such as a network, server, or web application.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.