MB-eeefa8281c00c2febd3d2ee552f2c36ae37fcc493e562147f9b5afa92774a8a2
high
📛 Threat Title
DDoSAgent: ppc64
Description
File type: elf. Size: 7340216 bytes. Tags: DDoSAgent. Reporter: BlinkzSec. First seen: 2026-05-14 17:00:10.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
eeefa8281c00c2febd3d2ee552f2c36ae37fcc493e562147f9b5afa92774a8a2
VT 35 / 75
1 feed
IOC database
- Type
- hash_sha256
- Value
eeefa8281c00c2febd3d2ee552f2c36ae37fcc493e562147f9b5afa92774a8a2- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- DDoSAgent
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Flagged by 35 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| alibabacloud | malicious | DDoS:Linux/Agent.am |
| ALYac | malicious | Trojan.Generic.39977336 |
| Antiy-AVL | malicious | Trojan/Linux.Multiverze |
| Arcabit | malicious | Trojan.Generic.D2620178 |
| Avast | malicious | ELF:DDOSAgent-FN [Rtk] |
| AVG | malicious | ELF:DDOSAgent-FN [Rtk] |
| Avira | malicious | TR/LINUX.DDOSAgent.GA |
| BitDefender | malicious | Trojan.Generic.39977336 |
| CAT-QuickHeal | malicious | Elf.Trojan.A25576276 |
| ClamAV | malicious | Unix.Trojan.Mirai-10056451-0 |
| CTX | malicious | elf.trojan.multiverze |
| Cynet | malicious | Malicious (score: 99) |
| Emsisoft | malicious | Trojan.Generic.39977336 (B) |
| ESET-NOD32 | malicious | Linux/DDoS.Agent.JP trojan |
| F-Secure | malicious | Trojan.TR/LINUX.DDOSAgent.GA |
| Fortinet | malicious | PossibleThreat |
| GData | malicious | Trojan.Generic.39977336 |
| malicious | Detected |
|
| huorong | malicious | Trojan/Linux.DDos.bv |
| Ikarus | malicious | Trojan.LINUX.DDOSAgent |
| Kaspersky | malicious | HEUR:Trojan-DDoS.Linux.Agent.av |
| Kingsoft | malicious | Linux.Trojan-DDoS.Agent.av |
| Lionic | malicious | Trojan.Linux.DDOSAgent.9!c |
| McAfeeD | malicious | ti!EEEFA8281C00 |
| Microsoft | malicious | Trojan:Linux/Multiverze!rfn |
| MicroWorld-eScan | malicious | Trojan.Generic.39977336 |
| Rising | malicious | Trojan.Agent/Linux!8.13268 (TFE:28:SP8LlZOgbQG) |
| SentinelOne | malicious | Static AI - Malicious ELF |
| Sophos | malicious | Mal/Generic-S |
| Symantec | malicious | Trojan.Gen.NPE |
| Tencent | malicious | Malware.Linux.Generic.1c081894 |
| TrendMicro | malicious | Trojan.Win32.ZYX.USBLEH26 |
| TrendMicro-HouseCall | malicious | Trojan.Win32.ZYX.USBLEH26 |
| Varist | malicious | E64/ABTrojan.FUKG- |
| VIPRE | malicious | Trojan.Generic.39977336 |
Details From VirusTotal
Basic Properties
| MD5 | 9bcfc59510f4209dd6b93b25481b8889 |
| SHA-1 | 698aa3dc75826d55f000d3dd25d49baa6864af40 |
| SHA-256 | eeefa8281c00c2febd3d2ee552f2c36ae37fcc493e562147f9b5afa92774a8a2 |
| VHash | 6f176afb59265d61c6131ca65ed70fde |
| SSDEEP | 49152:wYZ/SdCnVxNaPnN9a0dqNHWkyIQlTyUp5YIUiXK8PwyESHMEwOMHHUt5ER:NZnrgN9r8HWn+wTxK8PsSsEwOMnUjER |
| TLSH | T15D767C91FB48A136DA460A3248A70B30B3915D82C1F4C96F970AF72F59B26F7594FED0 |
| File type | ELF |
| File type tag | elf |
| Magic | ELF 64-bit MSB executable, 64-bit PowerPC or cisco 7500, Power ELF V1 ABI, version 1 (SYSV), statically linked, BuildID[sha1]=f968847d15756a9d8bdc8977d983fc69ca1c826f, stripped |
| File size | 7.0 MB |
History
| First seen on VirusTotal | 2026-05-14 17:00 UTC |
| Last submission | 2026-05-14 17:18 UTC |
| Last analysis | 2026-05-22 11:00 UTC |
| Last modified on VirusTotal | 2026-05-22 13:03 UTC |
Known Names
eeefa8281c00c2febd3d2ee552f2c36ae37fcc493e562147f9b5afa92774a8a2.elfppc6481.29.156.127_sample.bin57ojvm.exe_eeefa8281c00c2febd3d2ee552f2c36ae37fcc493e562147f9b5afa92774a8a2.elf
hash_sha1
698aa3dc75826d55f000d3dd25d49baa6864af40
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/698aa3dc75826d55f000d3dd25d49baa6864af40
1 feed
IOC database
- Type
- hash_sha1
- Value
698aa3dc75826d55f000d3dd25d49baa6864af40- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/698aa3dc75826d55f000d3dd25d49baa6864af40
hash_md5
9bcfc59510f4209dd6b93b25481b8889
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/9bcfc59510f4209dd6b93b25481b8889
2 feeds
IOC database
- Type
- hash_md5
- Value
9bcfc59510f4209dd6b93b25481b8889- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/9bcfc59510f4209dd6b93b25481b8889
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: elf. Size: 7340216 bytes. Tags: DDoSAgent. Reporter: BlinkzSec. First seen: 2026-05-14 17:00:10.
Remediations (10)
-
web:askubuntu.com
9 Update: Kernel 6.8.-117.117 is released now and features a kernel-level fix for CVE-2026-31431. While the website may be down, the security email list continues to work apparently and they have emailed about a mitigation there in an email from 30.04.2026 18:06 CET. The issue should be mitigated for now thanks to USN-8226-1 and USN-8226-2.
-
web:github.com
Contribute to SSGAalto/sgx-branch-shadowing- mitigation development by creating an account on GitHub.
-
web:microsoft.github.io
This capability supports the "Assume Breach" principle of Zero Trust by ensuring continuous detection and mitigation of weaknesses. Reference Remediate machine vulnerability findings - Microsoft Defender for Cloud Vulnerability scanning in Defender for Servers Remediate vulnerabilities with Microsoft Defender Vulnerability Management
-
web:panorays.com
Discover the difference between remediation and mitigation in risk management and how each strategy impacts security and resilience.
-
web:urlhaus.abuse.ch
Payload delivery The table below documents all payloads that URLhaus retrieved from this particular URL.
-
web:www.cisa.gov
This joint guide, Understanding and Responding to Distributed Denial-Of-Service Attacks, addresses the specific needs and challenges faced by organizations in defending against DDoS attacks. The guidance now includes detailed insight into three different types of DDoS techniques: Volumetric, attacks aiming to consume available bandwidth. Protocol, attacks which exploit vulnerabilities in ...
-
web:www.esd.whs.mil
Ensure configuration, asset, remediation , and mitigation management supports vulnerability management within the DODIN in accordance with DoD Instruction (DoDI) 8510.01. Support all systems, subsystems, and system components owned by or operated on behalf of DoD with efficient vulnerability assessment techniques, procedures, and capabilities.
-
web:www.joesandbox.com
General Information Sample name: ppc64 .elf Analysis ID: 1915051 Has dependencies: false MD5: bc811d11d9fa037ed1f05ba3b62f7e48 SHA1: e9770a98a2aa4d1956b949c0f7d4f5762d080f73 SHA256: 4bb2133f6943ade2dec29e265691e97a7742838331279da387c57727ee1045ad Tags: DDoSAgent , elf Infos:
-
web:www.microsoft.com
Understand how this virus or malware spreads and how its payloads affects your computer. Protect against this threat, identify symptoms, and clean up or remove infections.
-
web:www.sentinelone.com
A vulnerability remediation program helps you identify, analyze, prioritize, and eliminate security weaknesses before cyber attackers could exploit them.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.