MB-69c45cca395549bf1f9ff360edbe09cda646c0b511c513e6d91515085da9694b
high
📛 Threat Title
DDoSAgent: mipsel
Description
File type: elf. Size: 8126679 bytes. Tags: DDoSAgent. Reporter: BlinkzSec. First seen: 2026-05-14 17:00:10.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
69c45cca395549bf1f9ff360edbe09cda646c0b511c513e6d91515085da9694b
VT 36 / 75
1 feed
IOC database
- Type
- hash_sha256
- Value
69c45cca395549bf1f9ff360edbe09cda646c0b511c513e6d91515085da9694b- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- DDoSAgent
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Flagged by 36 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| alibabacloud | malicious | DDoS:Linux/Agent.JJ |
| ALYac | malicious | Trojan.Linux.GenericKD.79376 |
| Antiy-AVL | malicious | Trojan/Linux.Agent |
| Arcabit | malicious | Trojan.Linux.DDoS.308 |
| Avast | malicious | ELF:DDOSAgent-FN [Rtk] |
| AVG | malicious | ELF:DDOSAgent-FN [Rtk] |
| Avira | malicious | TR/LINUX.DDOSAgent.GA |
| BitDefender | malicious | Trojan.Linux.DDoS.308 |
| ClamAV | malicious | Unix.Trojan.Mirai-10056451-0 |
| CTX | malicious | elf.trojan.generic |
| Cynet | malicious | Malicious (score: 99) |
| DrWeb | malicious | Linux.DDoS.2749 |
| Emsisoft | malicious | Trojan.Linux.DDoS.308 (B) |
| ESET-NOD32 | malicious | Linux/DDoS.Agent.JH trojan |
| F-Secure | malicious | Trojan.TR/LINUX.DDOSAgent.GA |
| Fortinet | malicious | Linux/DDoS_Agent.JH!tr |
| GData | malicious | Trojan.Linux.DDoS.308 |
| malicious | Detected |
|
| huorong | malicious | Trojan/Linux.DDos.bv |
| K7GW | malicious | Trojan ( 00410f2e1 ) |
| Kaspersky | malicious | HEUR:Trojan-DDoS.Linux.Agent.av |
| Kingsoft | malicious | Linux.Trojan-DDoS.Agent.av |
| Lionic | malicious | Trojan.Linux.DDoS.9!c |
| McAfeeD | malicious | Trojan:Script/GenericY.FB |
| Microsoft | malicious | Trojan:Linux/Multiverze!rfn |
| MicroWorld-eScan | malicious | Trojan.Linux.DDoS.308 |
| Rising | malicious | Trojan.DDoS/Linux!8.1337A (TFE:28:zVzjNSQU6wB) |
| SentinelOne | malicious | Static AI - Malicious ELF |
| Skyhigh | malicious | Artemis!Trojan |
| Sophos | malicious | Mal/Generic-S |
| Symantec | malicious | Trojan.Gen.NPE |
| Tencent | malicious | Malware.Linux.Generic.1c0818a5 |
| TrendMicro | malicious | TROJ_GEN.R011C0DEI26 |
| TrendMicro-HouseCall | malicious | TROJ_GEN.R011C0DEI26 |
| Varist | malicious | E32/ABmRisk.UOIP- |
| VIPRE | malicious | Trojan.Linux.DDoS.308 |
Details From VirusTotal
Basic Properties
| MD5 | f2408c794e63d2e1cf76a50e70e18d6b |
| SHA-1 | 1b95966364c569ca195918c3a035e86062fa7734 |
| SHA-256 | 69c45cca395549bf1f9ff360edbe09cda646c0b511c513e6d91515085da9694b |
| VHash | 1a9619329a0d05b10bb80eb19efc89c1 |
| SSDEEP | 49152:Tmh61NZIdMpVriMF/0CQhx8wBAJxCaIE17Il8ZkFc05EI:+sLQhx8ImDOFxEI |
| TLSH | T1BB860905ADC53BE6C42C5E7444EACA6122B06D140AF2463A26A4FFE9BC772757F478CC |
| File type | ELF |
| File type tag | elf |
| Magic | ELF 32-bit LSB executable, MIPS, MIPS32 version 1 (SYSV), statically linked, BuildID[sha1]=f14e264ce7d6e7686ded7f015de7fa7026b27852, stripped |
| File size | 7.8 MB |
History
| First seen on VirusTotal | 2026-05-14 17:00 UTC |
| Last submission | 2026-05-14 17:18 UTC |
| Last analysis | 2026-06-15 11:07 UTC |
| Last modified on VirusTotal | 2026-06-15 13:18 UTC |
Known Names
69c45cca395549bf1f9ff360edbe09cda646c0b511c513e6d91515085da9694b.elf0pyunc7qev81.29.156.127_sample.bintoxfsgmipselevd2wwgm9.exe_69c45cca395549bf1f9ff360edbe09cda646c0b511c513e6d91515085da9694b.elf
hash_sha1
1b95966364c569ca195918c3a035e86062fa7734
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/1b95966364c569ca195918c3a035e86062fa7734
1 feed
IOC database
- Type
- hash_sha1
- Value
1b95966364c569ca195918c3a035e86062fa7734- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/1b95966364c569ca195918c3a035e86062fa7734
hash_md5
f2408c794e63d2e1cf76a50e70e18d6b
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/f2408c794e63d2e1cf76a50e70e18d6b
2 feeds
IOC database
- Type
- hash_md5
- Value
f2408c794e63d2e1cf76a50e70e18d6b- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/f2408c794e63d2e1cf76a50e70e18d6b
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: elf. Size: 8126679 bytes. Tags: DDoSAgent. Reporter: BlinkzSec. First seen: 2026-05-14 17:00:10.
Remediations (10)
-
web:www.cisa.gov
This joint guide, Understanding and Responding to Distributed Denial-Of-Service Attacks, addresses the specific needs and challenges faced by organizations in defending against DDoS attacks. The guidance now includes detailed insight into three different types of DDoS techniques: Volumetric, attacks aiming to consume available bandwidth. Protocol, attacks which exploit vulnerabilities in ...
-
web:www.cloudflare.com
When evaluating cloud-based mitigation services, it is important to look beyond capacity or transfer and filtering speeds, and consider network intelligence. The larger and more robust the mitigation network, the richer the intelligence it can provide on evolving attack patterns—and the more proactive protection will become.
-
web:www.enterprisenetworkingplanet.com
By following these ten best practices, you can significantly reduce the risk and impact of these attacks. But remember, the key to effective DDoS mitigation is not just preparation and quick response, but also the ongoing commitment to adapt and evolve your strategies in line with the changing threat landscape.
-
web:www.fastly.com
Discover the best DDoS mitigation providers of 2025-2026 with in-depth comparisons on capacity, automation, visibility, and integration.
-
web:www.fortinet.com
A DDoS mitigation strategy is necessary to protect organizations from potentially devastating DDoS attacks. Learn the steps to DDoS mitigation and what to look for in a mitigation provider.
-
web:www.gartner.com
Find the top DDoS Mitigation Solutions with Gartner. Compare and filter by verified product reviews and choose the software that's right for your organization.
-
web:www.joesandbox.com
General Information Sample name: mipsel .elf Analysis ID: 1913978 Has dependencies: false MD5: de05abe41135837bebace0c77e4f7320 SHA1: 6fc3d027ab1411a66a9348c701b20a2ddd94fc36 SHA256: 4004b8630bd06be6be05dcfe4a19de67ba67a61da32981ed216470aa8c6a3c2b Tags: DDoSAgent , elf Infos:
-
web:www.microsoft.com
Understand how this virus or malware spreads and how its payloads affects your computer. Protect against this threat, identify symptoms, and clean up or remove infections.
-
web:www.nist.gov
Advanced DDoS Mitigation Techniques ... Summary NIST is working with DHS S&T and industry to research and develop novel approaches to DDoS detection and mitigation , techniques to test and measure the effectiveness and impact of DDoS / spoofing mitigation techniques, and to develop deployment guidance for such techniques.
-
web:www.radware.com
DDoS (Distributed Denial of Service) mitigation is a set of tools and techniques that protect networks and systems from distributed denial-of-service (DDoS) attacks. DDoS attacks aim to disrupt the normal functioning of a target, such as a network, server, or web application.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.