TF-MAL-elf.leethozer
📛 Threat Title
Malware family: LeetHozer
Description
ThreatFox malware family `elf.leethozer`. Printable name: LeetHozer.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
elf.leethozer
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.leethozer
IOC database
- Type
- domain
- Value
elf.leethozer- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-elf.leethozer
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.leethozer
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:cybersecuritynews.com
The malware downloader attempts to install architecture-specific variants of the botnet across multiple system types. The Flodrix botnet represents an evolution of the LeetHozer malware family , incorporating advanced stealth techniques, including self-deletion and artifact removal, to evade detection.
-
web:gbhackers.com
Flodrix is a sophisticated descendant of the LeetHozer malware family , but with enhanced stealth and attack features. It can: Launch multiple types of DDoS attacks (e.g., tcpraw, udpplain, handshake, tcplegit, ts3, udp) Perform extensive reconnaissance, dumping environment variables and scanning for network interfaces
-
web:innovirtuoso.com
Once a vulnerable server is found, the attackers exploit the flaw to deploy a botnet client known as Flodrix, which belongs to the LeetHozer malware family . This malware , once installed, establishes a connection with a command and control (C&C) server, allowing it to receive commands to launch various distributed denial-of-service (DDoS) attacks.
-
web:malpedia.caad.fkie.fraunhofer.de
Details for the LeetHozer malware family including references, samples and yara signatures.
-
web:securityaffairs.com
The payload is a new LeetHozer malware variant using stealth tactics like self-deletion, artifact removal, and string obfuscation to evade detection and analysis. "Notably, this version supports dual communication channels with its C&C infrastructure over both TCP and UDP channels.
-
web:securityonline.info
After gaining remote shell access, attackers downloaded a bash-based loader script named "docker", which fetched and deployed a new malware variant known as Flodrix. This botnet appears to be a descendant of the LeetHozer family , but with new tricks. " This variant employs multiple stealth techniques, including self-deletion and artifact removal… and uses string obfuscation to conceal ...
-
web:socradar.io
The malware is capable of achieving full system compromise, launching high-volume DDoS attacks, and potentially exfiltrating sensitive data from compromised systems. In this blog post, we will take a look at this vulnerability, the full attack chain, mitigation tactics, and the evolving capabilities of the Flodrix botnet.
-
web:undercodenews.com
The payload was discovered to be part of the LeetHozer malware family , known for its obfuscation, self-destruction, and forensic evasion techniques. To mitigate the risk, Langflow has issued a patch in version 1.3.0, which adds an authentication dependency to the vulnerable endpoint.
-
web:www.csoonline.com
Researchers from security firm Trend Micro warn that a critical remote code execution vulnerability patched in April in the Langflow AI agent framework is being exploited to deploy botnet malware ...
-
web:www.darkreading.com
The malicious payload used in the attack was a variant of the LeetHozer malware family that complicated analysis efforts due to various stealth techniques it employed, they added.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.