s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.xorddos

📛 Threat Title

Malware family: XOR DDoS

Category: XOR DDoS First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.xorddos`. Printable name: XOR DDoS. Aliases: XORDDOS.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.xorddos VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.xorddos

IOC database

Type
domain
Value
elf.xorddos
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.xorddos

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.xorddos

References (1)

Remediations (10)

  • web:blog.talosintelligence.com

    Cisco Talos observed an existing distributed denial-of-service ( DDoS ) malware known as XorDDoS , continuing to spread globally between November 2023 and February 2025. A significant finding shows that over 70 percent of attacks using XorDDoS targeted the United States from Nov. 2023 to Feb. 2025. The language settings of the muti-layer controller, XorDDoS builder and controller binding tool ...

  • web:cybersecuritynews.com

    A significant evolution in distributed denial-of-service ( DDoS ) malware has been detected, with the latest version of XorDDoS continuing to spread globally between November 2023 and February 2025. This Linux-targeting trojan transforms compromised machines into "zombie bots" that can be coordinated to execute powerful DDoS attacks against specified targets. The malware primarily propagates ...

  • web:cymulate.com

    The Linux Attacker In recent years, XorDDOS has become a notorious malware family that targets Linux systems. Notable for the use of extensive scripting to implement itself after an initial compromise, this malware has shown great resistance to detection in its various variants.

  • web:en.wikipedia.org

    XOR DDoS is a Linux Trojan malware with rootkit capabilities that was used to launch large-scale DDoS attacks. Its name stems from the heavy usage of XOR encryption in both malware and network communication to the C&Cs.

  • web:malpedia.caad.fkie.fraunhofer.de

    XOR DDoS 2015-09-25 ⋅ Blaze's Security Blog ⋅ BartBlaze Notes on Linux/ Xor . DDoS XOR DDoS 2015-09-01 ⋅ Virus Bulletin ⋅ Jaromír Hořejší, Peter Kálnai DDOS TROJAN: A MALICIOUS CONCEPT THAT CONQUERED THE ELF FORMAT Bashlite MrBlack XOR DDoS BillGates 2015-02-05 ⋅ FireEye ⋅ Derek Gooley, Michael Lin

  • web:research.splunk.com

    Description XorDdos is a sophisticated Linux malware that compromises devices to conduct high-capacity Distributed Denial of Service ( DDoS ) attacks. It employs XOR -based encryption to conceal its communications and utilizes rootkit capabilities to evade detection.

  • web:success.trendmicro.com

    XOR DDoS is a Linux Trojan malware with rootkit capabilities that was used to launch large-scale DDoS attacks. Its name stems from the heavy usage of XOR encryption in both malware and network communication to the C&Cs.

  • web:thehackernews.com

    Cybersecurity researchers are warning of continued risks posed by a distributed denial-of-service ( DDoS ) malware known as XorDDoS , with 71.3 percent of the attacks between November 2023 and February 2025 targeting the United States. "From 2020 to 2023, the XorDDoS trojan has increased significantly ...

  • web:unit42.paloaltonetworks.com

    They then downloaded malware from remote servers and deployed it on the victim machines. Malware Behavior Analysis As implied by its name, the XorDDoS Trojan uses an XOR encryption key (BB2FA36AAA9541F0) to encrypt all the data related to its execution. Figure 3 shows that the threat invokes a decryption function to retrieve the hard-coded strings.

  • web:www.microsoft.com

    XorDdos depicts the trend of malware increasingly targeting Linux-based operating systems, which are commonly deployed on cloud infrastructures and Internet of Things (IoT) devices. By compromising IoT and other internet-connected devices, XorDdos amasses botnets that can be used to carry out distributed denial-of-service ( DDoS ) attacks.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.