s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-129f0c1c7baccd24623d99d7f5cde280d364404abe940ec4a3eeaa3a15f07318 high

📛 Threat Title

DDoSAgent: mips

Category: DDoSAgent Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: elf. Size: 8126679 bytes. Tags: DDoSAgent. Reporter: BlinkzSec. First seen: 2026-05-14 17:00:10.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 129f0c1c7baccd24623d99d7f5cde280d364404abe940ec4a3eeaa3a15f07318 1 feed

IOC database

Type
hash_sha256
Value
129f0c1c7baccd24623d99d7f5cde280d364404abe940ec4a3eeaa3a15f07318
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
DDoSAgent

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 6ac0d74872efdd2bde345e01f0d328539350aff8 VT 35 / 75 1 feed

IOC database

Type
hash_sha1
Value
6ac0d74872efdd2bde345e01f0d328539350aff8
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Flagged by 35 of 75 VirusTotal vendors

VendorVerdictDetection
alibabacloud malicious DDoS:Linux/Agent.JJ
ALYac malicious Trojan.Linux.GenericKD.79375
Antiy-AVL malicious Trojan/Linux.Multiverze
Arcabit malicious Trojan.Linux.Generic.D1360F
Avast malicious ELF:DDOSAgent-FN [Rtk]
AVG malicious ELF:DDOSAgent-FN [Rtk]
Avira malicious TR/LINUX.DDOSAgent.GA
BitDefender malicious Trojan.Linux.GenericKD.79375
CAT-QuickHeal malicious Elf.Trojan.A25560239
ClamAV malicious Unix.Trojan.Mirai-10056451-0
CTX malicious elf.trojan.multiverze
Cynet malicious Malicious (score: 99)
Emsisoft malicious Trojan.Linux.GenericKD.79375 (B)
ESET-NOD32 malicious Linux/DDoS.Agent.JH trojan
F-Secure malicious Trojan.TR/LINUX.DDOSAgent.GA
Fortinet malicious Linux/DDoS_Agent.JH!tr
GData malicious Trojan.Linux.GenericKD.79375
Google malicious Detected
huorong malicious Trojan/Linux.DDos.bv
Ikarus malicious Trojan.Linux.DDoS
K7GW malicious Trojan ( 00410f2e1 )
Kaspersky malicious HEUR:Trojan-DDoS.Linux.Agent.av
Kingsoft malicious Linux.Trojan-DDoS.Agent.av
Lionic malicious Trojan.Linux.DDoS.4!c
McAfeeD malicious Trojan:Script/GenericY.FB
Microsoft malicious Trojan:Linux/Multiverze!rfn
MicroWorld-eScan malicious Trojan.Linux.GenericKD.79375
Rising malicious Trojan.DDoS/Linux!8.1337A (CLOUD)
SentinelOne malicious Static AI - Malicious ELF
Sophos malicious Mal/Generic-S
Symantec malicious Trojan.Gen.NPE
Tencent malicious Malware.Linux.Generic.1c0818b7
TrendMicro-HouseCall malicious Trojan.Linux.Gen.TL0101EF26ZZ
Varist malicious E32/ABmRisk.REII-1
VIPRE malicious Trojan.Linux.GenericKD.79375

Details From VirusTotal

Basic Properties
MD5d9c8c69b00c619f07518c112fd39f3a4
SHA-16ac0d74872efdd2bde345e01f0d328539350aff8
SHA-256129f0c1c7baccd24623d99d7f5cde280d364404abe940ec4a3eeaa3a15f07318
VHash08acdad33a14a4424ad814b23ab88a86
SSDEEP49152:wlVZvmsNoaASox/PGQa/jtDf5xaount+fqECXKEuXngHYJ/7FTsdiraia5pp0Zkw:WtzV0RiQ0kcP+rSi6NbnUjEr
TLSHT118864A137A29EB0FC62821300DB2CA942B691C9642D7911BB745F309F9F21BD5DAECF5
File typeELF
File type tagelf
MagicELF 32-bit MSB executable, MIPS, MIPS32 version 1 (SYSV), statically linked, BuildID[sha1]=89c83a2219f6471606a521483aa4841f84f5499c, stripped
File size7.8 MB
History
First seen on VirusTotal2026-05-14 17:00 UTC
Last submission2026-05-14 17:18 UTC
Last analysis2026-05-20 06:04 UTC
Last modified on VirusTotal2026-05-20 08:08 UTC
Known Names
  • 129f0c1c7baccd24623d99d7f5cde280d364404abe940ec4a3eeaa3a15f07318.elf
  • 81.29.156.127_sample.bin
  • s3auzp
  • mips
  • 8mpdgctd.exe
  • _129f0c1c7baccd24623d99d7f5cde280d364404abe940ec4a3eeaa3a15f07318.elf
hash_md5 d9c8c69b00c619f07518c112fd39f3a4 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/d9c8c69b00c619f07518c112fd39f3a4
2 feeds

IOC database

Type
hash_md5
Value
d9c8c69b00c619f07518c112fd39f3a4
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/d9c8c69b00c619f07518c112fd39f3a4

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: elf. Size: 8126679 bytes. Tags: DDoSAgent. Reporter: BlinkzSec. First seen: 2026-05-14 17:00:10.

Remediations (10)

  • web:developer.okta.com

    How to Mitigate DoS Attacks Now that you know what DoS attacks are and why attackers perform them, let's discuss how you can protect yourself and your services. Most common mitigation techniques work by detecting illegitimate traffic and blocking it at the routing level, managing and analyzing the bandwidth of the services, and being mindful when architecting your APIs, so they're able to ...

  • web:microsoft.github.io

    This capability supports the "Assume Breach" principle of Zero Trust by ensuring continuous detection and mitigation of weaknesses. Reference Remediate machine vulnerability findings - Microsoft Defender for Cloud Vulnerability scanning in Defender for Servers Remediate vulnerabilities with Microsoft Defender Vulnerability Management

  • web:www.cisa.gov

    Include improvements drawn from any lessons learned regarding communication, mitigation , and recovery. Continue to regularly test your DDoS response plan. • Proactively monitor your network to quickly identify DDoS attacks. Monitoring allows your organization to create a baseline of normal activity on network, storage, and computer systems.

  • web:www.cloudflare.com

    When evaluating cloud-based mitigation services, it is important to look beyond capacity or transfer and filtering speeds, and consider network intelligence. The larger and more robust the mitigation network, the richer the intelligence it can provide on evolving attack patterns—and the more proactive protection will become.

  • web:www.enterprisenetworkingplanet.com

    By following these ten best practices, you can significantly reduce the risk and impact of these attacks. But remember, the key to effective DDoS mitigation is not just preparation and quick response, but also the ongoing commitment to adapt and evolve your strategies in line with the changing threat landscape.

  • web:www.fastly.com

    Discover the best DDoS mitigation providers of 2025-2026 with in-depth comparisons on capacity, automation, visibility, and integration.

  • web:www.fortinet.com

    A DDoS mitigation strategy is necessary to protect organizations from potentially devastating DDoS attacks. Learn the steps to DDoS mitigation and what to look for in a mitigation provider.

  • web:www.gartner.com

    Find the top DDoS Mitigation Solutions with Gartner. Compare and filter by verified product reviews and choose the software that's right for your organization.

  • web:www.microsoft.com

    Understand how this virus or malware spreads and how its payloads affects your computer. Protect against this threat, identify symptoms, and clean up or remove infections.

  • web:www.nist.gov

    Advanced DDoS Mitigation Techniques ... Summary NIST is working with DHS S&T and industry to research and develop novel approaches to DDoS detection and mitigation , techniques to test and measure the effectiveness and impact of DDoS / spoofing mitigation techniques, and to develop deployment guidance for such techniques.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.