s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-eeefa8281c00c2febd3d2ee552f2c36ae37fcc493e562147f9b5afa92774a8a2 high

📛 Threat Title

DDoSAgent: ppc64

Category: DDoSAgent Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: elf. Size: 7340216 bytes. Tags: DDoSAgent. Reporter: BlinkzSec. First seen: 2026-05-14 17:00:10.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 eeefa8281c00c2febd3d2ee552f2c36ae37fcc493e562147f9b5afa92774a8a2 VT 35 / 75 1 feed

IOC database

Type
hash_sha256
Value
eeefa8281c00c2febd3d2ee552f2c36ae37fcc493e562147f9b5afa92774a8a2
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
DDoSAgent

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Flagged by 35 of 75 VirusTotal vendors

VendorVerdictDetection
alibabacloud malicious DDoS:Linux/Agent.am
ALYac malicious Trojan.Generic.39977336
Antiy-AVL malicious Trojan/Linux.Multiverze
Arcabit malicious Trojan.Generic.D2620178
Avast malicious ELF:DDOSAgent-FN [Rtk]
AVG malicious ELF:DDOSAgent-FN [Rtk]
Avira malicious TR/LINUX.DDOSAgent.GA
BitDefender malicious Trojan.Generic.39977336
CAT-QuickHeal malicious Elf.Trojan.A25576276
ClamAV malicious Unix.Trojan.Mirai-10056451-0
CTX malicious elf.trojan.multiverze
Cynet malicious Malicious (score: 99)
Emsisoft malicious Trojan.Generic.39977336 (B)
ESET-NOD32 malicious Linux/DDoS.Agent.JP trojan
F-Secure malicious Trojan.TR/LINUX.DDOSAgent.GA
Fortinet malicious PossibleThreat
GData malicious Trojan.Generic.39977336
Google malicious Detected
huorong malicious Trojan/Linux.DDos.bv
Ikarus malicious Trojan.LINUX.DDOSAgent
Kaspersky malicious HEUR:Trojan-DDoS.Linux.Agent.av
Kingsoft malicious Linux.Trojan-DDoS.Agent.av
Lionic malicious Trojan.Linux.DDOSAgent.9!c
McAfeeD malicious ti!EEEFA8281C00
Microsoft malicious Trojan:Linux/Multiverze!rfn
MicroWorld-eScan malicious Trojan.Generic.39977336
Rising malicious Trojan.Agent/Linux!8.13268 (TFE:28:SP8LlZOgbQG)
SentinelOne malicious Static AI - Malicious ELF
Sophos malicious Mal/Generic-S
Symantec malicious Trojan.Gen.NPE
Tencent malicious Malware.Linux.Generic.1c081894
TrendMicro malicious Trojan.Win32.ZYX.USBLEH26
TrendMicro-HouseCall malicious Trojan.Win32.ZYX.USBLEH26
Varist malicious E64/ABTrojan.FUKG-
VIPRE malicious Trojan.Generic.39977336

Details From VirusTotal

Basic Properties
MD59bcfc59510f4209dd6b93b25481b8889
SHA-1698aa3dc75826d55f000d3dd25d49baa6864af40
SHA-256eeefa8281c00c2febd3d2ee552f2c36ae37fcc493e562147f9b5afa92774a8a2
VHash6f176afb59265d61c6131ca65ed70fde
SSDEEP49152:wYZ/SdCnVxNaPnN9a0dqNHWkyIQlTyUp5YIUiXK8PwyESHMEwOMHHUt5ER:NZnrgN9r8HWn+wTxK8PsSsEwOMnUjER
TLSHT15D767C91FB48A136DA460A3248A70B30B3915D82C1F4C96F970AF72F59B26F7594FED0
File typeELF
File type tagelf
MagicELF 64-bit MSB executable, 64-bit PowerPC or cisco 7500, Power ELF V1 ABI, version 1 (SYSV), statically linked, BuildID[sha1]=f968847d15756a9d8bdc8977d983fc69ca1c826f, stripped
File size7.0 MB
History
First seen on VirusTotal2026-05-14 17:00 UTC
Last submission2026-05-14 17:18 UTC
Last analysis2026-05-22 11:00 UTC
Last modified on VirusTotal2026-05-22 13:03 UTC
Known Names
  • eeefa8281c00c2febd3d2ee552f2c36ae37fcc493e562147f9b5afa92774a8a2.elf
  • ppc64
  • 81.29.156.127_sample.bin
  • 57ojvm.exe
  • _eeefa8281c00c2febd3d2ee552f2c36ae37fcc493e562147f9b5afa92774a8a2.elf
hash_sha1 698aa3dc75826d55f000d3dd25d49baa6864af40 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/698aa3dc75826d55f000d3dd25d49baa6864af40
1 feed

IOC database

Type
hash_sha1
Value
698aa3dc75826d55f000d3dd25d49baa6864af40
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/698aa3dc75826d55f000d3dd25d49baa6864af40

hash_md5 9bcfc59510f4209dd6b93b25481b8889 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/9bcfc59510f4209dd6b93b25481b8889
2 feeds

IOC database

Type
hash_md5
Value
9bcfc59510f4209dd6b93b25481b8889
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/9bcfc59510f4209dd6b93b25481b8889

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: elf. Size: 7340216 bytes. Tags: DDoSAgent. Reporter: BlinkzSec. First seen: 2026-05-14 17:00:10.

Remediations (10)

  • web:askubuntu.com

    9 Update: Kernel 6.8.-117.117 is released now and features a kernel-level fix for CVE-2026-31431. While the website may be down, the security email list continues to work apparently and they have emailed about a mitigation there in an email from 30.04.2026 18:06 CET. The issue should be mitigated for now thanks to USN-8226-1 and USN-8226-2.

  • web:github.com

    Contribute to SSGAalto/sgx-branch-shadowing- mitigation development by creating an account on GitHub.

  • web:microsoft.github.io

    This capability supports the "Assume Breach" principle of Zero Trust by ensuring continuous detection and mitigation of weaknesses. Reference Remediate machine vulnerability findings - Microsoft Defender for Cloud Vulnerability scanning in Defender for Servers Remediate vulnerabilities with Microsoft Defender Vulnerability Management

  • web:panorays.com

    Discover the difference between remediation and mitigation in risk management and how each strategy impacts security and resilience.

  • web:urlhaus.abuse.ch

    Payload delivery The table below documents all payloads that URLhaus retrieved from this particular URL.

  • web:www.cisa.gov

    This joint guide, Understanding and Responding to Distributed Denial-Of-Service Attacks, addresses the specific needs and challenges faced by organizations in defending against DDoS attacks. The guidance now includes detailed insight into three different types of DDoS techniques: Volumetric, attacks aiming to consume available bandwidth. Protocol, attacks which exploit vulnerabilities in ...

  • web:www.esd.whs.mil

    Ensure configuration, asset, remediation , and mitigation management supports vulnerability management within the DODIN in accordance with DoD Instruction (DoDI) 8510.01. Support all systems, subsystems, and system components owned by or operated on behalf of DoD with efficient vulnerability assessment techniques, procedures, and capabilities.

  • web:www.joesandbox.com

    General Information Sample name: ppc64 .elf Analysis ID: 1915051 Has dependencies: false MD5: bc811d11d9fa037ed1f05ba3b62f7e48 SHA1: e9770a98a2aa4d1956b949c0f7d4f5762d080f73 SHA256: 4bb2133f6943ade2dec29e265691e97a7742838331279da387c57727ee1045ad Tags: DDoSAgent , elf Infos:

  • web:www.microsoft.com

    Understand how this virus or malware spreads and how its payloads affects your computer. Protect against this threat, identify symptoms, and clean up or remove infections.

  • web:www.sentinelone.com

    A vulnerability remediation program helps you identify, analyze, prioritize, and eliminate security weaknesses before cyber attackers could exploit them.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.