s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.leethozer

📛 Threat Title

Malware family: LeetHozer

Category: LeetHozer First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.leethozer`. Printable name: LeetHozer.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.leethozer VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.leethozer

IOC database

Type
domain
Value
elf.leethozer
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.leethozer

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.leethozer

References (1)

Remediations (10)

  • web:cybersecuritynews.com

    The malware downloader attempts to install architecture-specific variants of the botnet across multiple system types. The Flodrix botnet represents an evolution of the LeetHozer malware family , incorporating advanced stealth techniques, including self-deletion and artifact removal, to evade detection.

  • web:gbhackers.com

    Flodrix is a sophisticated descendant of the LeetHozer malware family , but with enhanced stealth and attack features. It can: Launch multiple types of DDoS attacks (e.g., tcpraw, udpplain, handshake, tcplegit, ts3, udp) Perform extensive reconnaissance, dumping environment variables and scanning for network interfaces

  • web:innovirtuoso.com

    Once a vulnerable server is found, the attackers exploit the flaw to deploy a botnet client known as Flodrix, which belongs to the LeetHozer malware family . This malware , once installed, establishes a connection with a command and control (C&C) server, allowing it to receive commands to launch various distributed denial-of-service (DDoS) attacks.

  • web:malpedia.caad.fkie.fraunhofer.de

    Details for the LeetHozer malware family including references, samples and yara signatures.

  • web:securityaffairs.com

    The payload is a new LeetHozer malware variant using stealth tactics like self-deletion, artifact removal, and string obfuscation to evade detection and analysis. "Notably, this version supports dual communication channels with its C&C infrastructure over both TCP and UDP channels.

  • web:securityonline.info

    After gaining remote shell access, attackers downloaded a bash-based loader script named "docker", which fetched and deployed a new malware variant known as Flodrix. This botnet appears to be a descendant of the LeetHozer family , but with new tricks. " This variant employs multiple stealth techniques, including self-deletion and artifact removal… and uses string obfuscation to conceal ...

  • web:socradar.io

    The malware is capable of achieving full system compromise, launching high-volume DDoS attacks, and potentially exfiltrating sensitive data from compromised systems. In this blog post, we will take a look at this vulnerability, the full attack chain, mitigation tactics, and the evolving capabilities of the Flodrix botnet.

  • web:undercodenews.com

    The payload was discovered to be part of the LeetHozer malware family , known for its obfuscation, self-destruction, and forensic evasion techniques. To mitigate the risk, Langflow has issued a patch in version 1.3.0, which adds an authentication dependency to the vulnerable endpoint.

  • web:www.csoonline.com

    Researchers from security firm Trend Micro warn that a critical remote code execution vulnerability patched in April in the Langflow AI agent framework is being exploited to deploy botnet malware ...

  • web:www.darkreading.com

    The malicious payload used in the attack was a variant of the LeetHozer malware family that complicated analysis efforts due to various stealth techniques it employed, they added.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.