MB-129f0c1c7baccd24623d99d7f5cde280d364404abe940ec4a3eeaa3a15f07318
high
📛 Threat Title
DDoSAgent: mips
Description
File type: elf. Size: 8126679 bytes. Tags: DDoSAgent. Reporter: BlinkzSec. First seen: 2026-05-14 17:00:10.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
129f0c1c7baccd24623d99d7f5cde280d364404abe940ec4a3eeaa3a15f07318
1 feed
IOC database
- Type
- hash_sha256
- Value
129f0c1c7baccd24623d99d7f5cde280d364404abe940ec4a3eeaa3a15f07318- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- DDoSAgent
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha1
6ac0d74872efdd2bde345e01f0d328539350aff8
VT 35 / 75
1 feed
IOC database
- Type
- hash_sha1
- Value
6ac0d74872efdd2bde345e01f0d328539350aff8- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Flagged by 35 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| alibabacloud | malicious | DDoS:Linux/Agent.JJ |
| ALYac | malicious | Trojan.Linux.GenericKD.79375 |
| Antiy-AVL | malicious | Trojan/Linux.Multiverze |
| Arcabit | malicious | Trojan.Linux.Generic.D1360F |
| Avast | malicious | ELF:DDOSAgent-FN [Rtk] |
| AVG | malicious | ELF:DDOSAgent-FN [Rtk] |
| Avira | malicious | TR/LINUX.DDOSAgent.GA |
| BitDefender | malicious | Trojan.Linux.GenericKD.79375 |
| CAT-QuickHeal | malicious | Elf.Trojan.A25560239 |
| ClamAV | malicious | Unix.Trojan.Mirai-10056451-0 |
| CTX | malicious | elf.trojan.multiverze |
| Cynet | malicious | Malicious (score: 99) |
| Emsisoft | malicious | Trojan.Linux.GenericKD.79375 (B) |
| ESET-NOD32 | malicious | Linux/DDoS.Agent.JH trojan |
| F-Secure | malicious | Trojan.TR/LINUX.DDOSAgent.GA |
| Fortinet | malicious | Linux/DDoS_Agent.JH!tr |
| GData | malicious | Trojan.Linux.GenericKD.79375 |
| malicious | Detected |
|
| huorong | malicious | Trojan/Linux.DDos.bv |
| Ikarus | malicious | Trojan.Linux.DDoS |
| K7GW | malicious | Trojan ( 00410f2e1 ) |
| Kaspersky | malicious | HEUR:Trojan-DDoS.Linux.Agent.av |
| Kingsoft | malicious | Linux.Trojan-DDoS.Agent.av |
| Lionic | malicious | Trojan.Linux.DDoS.4!c |
| McAfeeD | malicious | Trojan:Script/GenericY.FB |
| Microsoft | malicious | Trojan:Linux/Multiverze!rfn |
| MicroWorld-eScan | malicious | Trojan.Linux.GenericKD.79375 |
| Rising | malicious | Trojan.DDoS/Linux!8.1337A (CLOUD) |
| SentinelOne | malicious | Static AI - Malicious ELF |
| Sophos | malicious | Mal/Generic-S |
| Symantec | malicious | Trojan.Gen.NPE |
| Tencent | malicious | Malware.Linux.Generic.1c0818b7 |
| TrendMicro-HouseCall | malicious | Trojan.Linux.Gen.TL0101EF26ZZ |
| Varist | malicious | E32/ABmRisk.REII-1 |
| VIPRE | malicious | Trojan.Linux.GenericKD.79375 |
Details From VirusTotal
Basic Properties
| MD5 | d9c8c69b00c619f07518c112fd39f3a4 |
| SHA-1 | 6ac0d74872efdd2bde345e01f0d328539350aff8 |
| SHA-256 | 129f0c1c7baccd24623d99d7f5cde280d364404abe940ec4a3eeaa3a15f07318 |
| VHash | 08acdad33a14a4424ad814b23ab88a86 |
| SSDEEP | 49152:wlVZvmsNoaASox/PGQa/jtDf5xaount+fqECXKEuXngHYJ/7FTsdiraia5pp0Zkw:WtzV0RiQ0kcP+rSi6NbnUjEr |
| TLSH | T118864A137A29EB0FC62821300DB2CA942B691C9642D7911BB745F309F9F21BD5DAECF5 |
| File type | ELF |
| File type tag | elf |
| Magic | ELF 32-bit MSB executable, MIPS, MIPS32 version 1 (SYSV), statically linked, BuildID[sha1]=89c83a2219f6471606a521483aa4841f84f5499c, stripped |
| File size | 7.8 MB |
History
| First seen on VirusTotal | 2026-05-14 17:00 UTC |
| Last submission | 2026-05-14 17:18 UTC |
| Last analysis | 2026-05-20 06:04 UTC |
| Last modified on VirusTotal | 2026-05-20 08:08 UTC |
Known Names
129f0c1c7baccd24623d99d7f5cde280d364404abe940ec4a3eeaa3a15f07318.elf81.29.156.127_sample.bins3auzpmips8mpdgctd.exe_129f0c1c7baccd24623d99d7f5cde280d364404abe940ec4a3eeaa3a15f07318.elf
hash_md5
d9c8c69b00c619f07518c112fd39f3a4
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/d9c8c69b00c619f07518c112fd39f3a4
2 feeds
IOC database
- Type
- hash_md5
- Value
d9c8c69b00c619f07518c112fd39f3a4- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/d9c8c69b00c619f07518c112fd39f3a4
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: elf. Size: 8126679 bytes. Tags: DDoSAgent. Reporter: BlinkzSec. First seen: 2026-05-14 17:00:10.
Remediations (10)
-
web:developer.okta.com
How to Mitigate DoS Attacks Now that you know what DoS attacks are and why attackers perform them, let's discuss how you can protect yourself and your services. Most common mitigation techniques work by detecting illegitimate traffic and blocking it at the routing level, managing and analyzing the bandwidth of the services, and being mindful when architecting your APIs, so they're able to ...
-
web:microsoft.github.io
This capability supports the "Assume Breach" principle of Zero Trust by ensuring continuous detection and mitigation of weaknesses. Reference Remediate machine vulnerability findings - Microsoft Defender for Cloud Vulnerability scanning in Defender for Servers Remediate vulnerabilities with Microsoft Defender Vulnerability Management
-
web:www.cisa.gov
Include improvements drawn from any lessons learned regarding communication, mitigation , and recovery. Continue to regularly test your DDoS response plan. • Proactively monitor your network to quickly identify DDoS attacks. Monitoring allows your organization to create a baseline of normal activity on network, storage, and computer systems.
-
web:www.cloudflare.com
When evaluating cloud-based mitigation services, it is important to look beyond capacity or transfer and filtering speeds, and consider network intelligence. The larger and more robust the mitigation network, the richer the intelligence it can provide on evolving attack patterns—and the more proactive protection will become.
-
web:www.enterprisenetworkingplanet.com
By following these ten best practices, you can significantly reduce the risk and impact of these attacks. But remember, the key to effective DDoS mitigation is not just preparation and quick response, but also the ongoing commitment to adapt and evolve your strategies in line with the changing threat landscape.
-
web:www.fastly.com
Discover the best DDoS mitigation providers of 2025-2026 with in-depth comparisons on capacity, automation, visibility, and integration.
-
web:www.fortinet.com
A DDoS mitigation strategy is necessary to protect organizations from potentially devastating DDoS attacks. Learn the steps to DDoS mitigation and what to look for in a mitigation provider.
-
web:www.gartner.com
Find the top DDoS Mitigation Solutions with Gartner. Compare and filter by verified product reviews and choose the software that's right for your organization.
-
web:www.microsoft.com
Understand how this virus or malware spreads and how its payloads affects your computer. Protect against this threat, identify symptoms, and clean up or remove infections.
-
web:www.nist.gov
Advanced DDoS Mitigation Techniques ... Summary NIST is working with DHS S&T and industry to research and develop novel approaches to DDoS detection and mitigation , techniques to test and measure the effectiveness and impact of DDoS / spoofing mitigation techniques, and to develop deployment guidance for such techniques.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.