TF-MAL-elf.xorddos
📛 Threat Title
Malware family: XOR DDoS
Description
ThreatFox malware family `elf.xorddos`. Printable name: XOR DDoS. Aliases: XORDDOS.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
elf.xorddos
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.xorddos
IOC database
- Type
- domain
- Value
elf.xorddos- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-elf.xorddos
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.xorddos
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:blog.talosintelligence.com
Cisco Talos observed an existing distributed denial-of-service ( DDoS ) malware known as XorDDoS , continuing to spread globally between November 2023 and February 2025. A significant finding shows that over 70 percent of attacks using XorDDoS targeted the United States from Nov. 2023 to Feb. 2025. The language settings of the muti-layer controller, XorDDoS builder and controller binding tool ...
-
web:cybersecuritynews.com
A significant evolution in distributed denial-of-service ( DDoS ) malware has been detected, with the latest version of XorDDoS continuing to spread globally between November 2023 and February 2025. This Linux-targeting trojan transforms compromised machines into "zombie bots" that can be coordinated to execute powerful DDoS attacks against specified targets. The malware primarily propagates ...
-
web:cymulate.com
The Linux Attacker In recent years, XorDDOS has become a notorious malware family that targets Linux systems. Notable for the use of extensive scripting to implement itself after an initial compromise, this malware has shown great resistance to detection in its various variants.
-
web:en.wikipedia.org
XOR DDoS is a Linux Trojan malware with rootkit capabilities that was used to launch large-scale DDoS attacks. Its name stems from the heavy usage of XOR encryption in both malware and network communication to the C&Cs.
-
web:malpedia.caad.fkie.fraunhofer.de
XOR DDoS 2015-09-25 ⋅ Blaze's Security Blog ⋅ BartBlaze Notes on Linux/ Xor . DDoS XOR DDoS 2015-09-01 ⋅ Virus Bulletin ⋅ Jaromír Hořejší, Peter Kálnai DDOS TROJAN: A MALICIOUS CONCEPT THAT CONQUERED THE ELF FORMAT Bashlite MrBlack XOR DDoS BillGates 2015-02-05 ⋅ FireEye ⋅ Derek Gooley, Michael Lin
-
web:research.splunk.com
Description XorDdos is a sophisticated Linux malware that compromises devices to conduct high-capacity Distributed Denial of Service ( DDoS ) attacks. It employs XOR -based encryption to conceal its communications and utilizes rootkit capabilities to evade detection.
-
web:success.trendmicro.com
XOR DDoS is a Linux Trojan malware with rootkit capabilities that was used to launch large-scale DDoS attacks. Its name stems from the heavy usage of XOR encryption in both malware and network communication to the C&Cs.
-
web:thehackernews.com
Cybersecurity researchers are warning of continued risks posed by a distributed denial-of-service ( DDoS ) malware known as XorDDoS , with 71.3 percent of the attacks between November 2023 and February 2025 targeting the United States. "From 2020 to 2023, the XorDDoS trojan has increased significantly ...
-
web:unit42.paloaltonetworks.com
They then downloaded malware from remote servers and deployed it on the victim machines. Malware Behavior Analysis As implied by its name, the XorDDoS Trojan uses an XOR encryption key (BB2FA36AAA9541F0) to encrypt all the data related to its execution. Figure 3 shows that the threat invokes a decryption function to retrieve the hard-coded strings.
-
web:www.microsoft.com
XorDdos depicts the trend of malware increasingly targeting Linux-based operating systems, which are commonly deployed on cloud infrastructures and Internet of Things (IoT) devices. By compromising IoT and other internet-connected devices, XorDdos amasses botnets that can be used to carry out distributed denial-of-service ( DDoS ) attacks.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.