IOC LOOKUP
// SEARCH IP, DOMAIN, HASH, OR URL AGAINST OTX THREAT INTELLIGENCE
Indicator of Compromise Search
✦ IPv4 Address
✦ Domain
✦ MD5/SHA1/SHA256 Hash
✦ URL
INDICATOR
414f2eb4522d0c85049ec0ad28c471304105643bcf6e61303955168390efba18
55
/100
HIGH
CONFIDENCE LEVEL
THREAT CONFIDENCE ANALYSIS
HIGH
55/100 confidence
Strong evidence of malicious activity across multiple sources. Prioritise investigation.
CLEAN
LOW
MED
HIGH
CRIT
0
25
50
75
100
OTX
10/30
1 pulses
VIRUSTOTAL
35/35
42/76 detected
ABUSEIPDB
—/25
IPv4 only
URLHAUS
10/10
LISTED
General Information
| Hash | 414f2eb4522d0c85049ec0ad28c471304105643bcf6e61303955168390efba18 |
| File Type | FileHash-SHA256 |
AlienVault OTX Analysis
↗ View on OTX
1
PULSE HITS
| Pulse Hits | 1 |
| Indicator Type | SHA256 |
| Threat Level |
ASSOCIATED PULSES
| PULSE NAME | DATE |
|---|---|
| 2023-10-15 |
VirusTotal Analysis
↗ View on VirusTotal
42/76
DETECTIONS
MALICIOUS
| Malicious | 42 |
| Suspicious | 0 |
| Harmless | 0 |
| Undetected | 19 |
| Reputation | -43 |
| File Name | XUM5UOZS.exe |
| File Type | ELF |
| File Size | 98.2 KB |
TOP DETECTIONS
| VENDOR | RESULT |
|---|---|
| ALYac | Gen:Variant.Trojan.Linux.Gafgyt.5 |
| AVG | ELF:DDoS-Y [Trj] |
| Ad-Aware | Gen:Variant.Trojan.Linux.Gafgyt.5 |
| AhnLab-V3 | Linux/Mirai.Gen6 |
| Antiy-AVL | Trojan[Backdoor]/Linux.Gafgyt.a |
| Arcabit | Trojan.Trojan.Linux.Gafgyt.5 |
| Avast | ELF:DDoS-Y [Trj] |
| Avast-Mobile | ELF:DDoS-S [Trj] |
| Avira | LINUX/Mirai.pzcqt |
| BitDefender | Gen:Variant.Trojan.Linux.Gafgyt.5 |
URLhaus (abuse.ch)
↗ View on URLhaus
⚠ LISTED
URLHAUS
| URLs Found | 1 |
| First Seen | 2019-04-30 |
| File Type | elf |
ASSOCIATED URLs
| URL | STATUS / TYPE | DATE |
|---|---|---|
| http://159.65.119.32/i586 | offline | — |