MB-9cb6369175c9ed8da004395a54b93d98dd2f23333fd5641838b8850ecd1b8974
high
📛 Threat Title
Unknown: dck
Description
File type: sh. Size: 1837 bytes. Tags: sh. Reporter: abuse_ch. First seen: 2026-05-20 23:41:43.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
9cb6369175c9ed8da004395a54b93d98dd2f23333fd5641838b8850ecd1b8974
VT 28 / 75
IOC database
- Type
- hash_sha256
- Value
9cb6369175c9ed8da004395a54b93d98dd2f23333fd5641838b8850ecd1b8974- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- URLhaus payload hash
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 28 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| ALYac | malicious | Generic.Bash.MiraiA.EA2591E1 |
| Arcabit | malicious | Generic.Bash.MiraiA.EA2591E1 |
| Avast | malicious | BV:Downloader-AMZ [Drp] |
| AVG | malicious | BV:Downloader-AMZ [Drp] |
| Avira | malicious | HTML/ExpKit.Gen2 |
| BitDefender | malicious | Generic.Bash.MiraiA.EA2591E1 |
| CTX | malicious | shell.unknown.bash |
| Cynet | malicious | Malicious (score: 99) |
| DrWeb | malicious | Linux.DownLoader.37 |
| Emsisoft | malicious | Generic.Bash.MiraiA.EA2591E1 (B) |
| ESET-NOD32 | malicious | Linux/TrojanDownloader.SH.FFM trojan |
| F-Secure | malicious | Malware.HTML/ExpKit.Gen2 |
| Fortinet | malicious | BASH/Mirai.AEH!tr.dldr |
| GData | malicious | Generic.Bash.MiraiA.EA2591E1 |
| malicious | Detected |
|
| huorong | malicious | TrojanDownloader/Linux.Agent.ci |
| Kaspersky | malicious | HEUR:Trojan-Downloader.Shell.Agent.a |
| Microsoft | malicious | Trojan:SH/Geninst.JA |
| MicroWorld-eScan | malicious | Generic.Bash.MiraiA.EA2591E1 |
| Sangfor | malicious | Trojan.Generic-Script.Save.ba514 |
| Skyhigh | malicious | Linux/Downloader.w |
| Symantec | malicious | CL.Downloader!gen277 |
| Tencent | malicious | Html.Trojan.Expkit.Rnkl |
| TrellixENS | malicious | Linux/Downloader.w |
| TrendMicro | malicious | Possible_BASHDLOD.SMLBO1 |
| TrendMicro-HouseCall | malicious | Possible_BASHDLOD.SMLBO1 |
| Varist | malicious | SH/Mirai.D.gen!Camelot |
| VIPRE | malicious | Generic.Bash.MiraiA.EA2591E1 |
Details From VirusTotal
Basic Properties
| MD5 | 5202058cceb5de50ef30b8e992ba2fb7 |
| SHA-1 | caa419a844176c843258d04b7e0882f455e8d7cf |
| SHA-256 | 9cb6369175c9ed8da004395a54b93d98dd2f23333fd5641838b8850ecd1b8974 |
| SSDEEP | 24:05WXbe1A6PjpjNIh5jQbCKv5j7Mu6Z1kHTvzlplmF/EnwZf65Ge1mjbc2/oI63Bd:nbwRH0ZfeGg6O |
| TLSH | T18E317FCA3C12FDD6F457AE0BB2B0494AB03C94AF316FCFA6C9074A14C42C18E7116A18 |
| File type | Shell script |
| File type tag | shell |
| File extension | sh |
| Magic | Bourne-Again shell script, ASCII text executable |
| File size | 1.8 KB |
History
| First seen on VirusTotal | 2026-05-20 23:43 UTC |
| Last submission | 2026-05-20 23:43 UTC |
| Last analysis | 2026-05-21 00:03 UTC |
| Last modified on VirusTotal | 2026-05-22 20:56 UTC |
Known Names
9cb6369175c9ed8da004395a54b93d98dd2f23333fd5641838b8850ecd1b8974.sh_9cb6369175c9ed8da004395a54b93d98dd2f23333fd5641838b8850ecd1b8974.sh
hash_md5
5202058cceb5de50ef30b8e992ba2fb7
VT 28 / 75
IOC database
- Type
- hash_md5
- Value
5202058cceb5de50ef30b8e992ba2fb7- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- URLhaus payload hash
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 28 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| ALYac | malicious | Generic.Bash.MiraiA.EA2591E1 |
| Arcabit | malicious | Generic.Bash.MiraiA.EA2591E1 |
| Avast | malicious | BV:Downloader-AMZ [Drp] |
| AVG | malicious | BV:Downloader-AMZ [Drp] |
| Avira | malicious | HTML/ExpKit.Gen2 |
| BitDefender | malicious | Generic.Bash.MiraiA.EA2591E1 |
| CTX | malicious | shell.unknown.bash |
| Cynet | malicious | Malicious (score: 99) |
| DrWeb | malicious | Linux.DownLoader.37 |
| Emsisoft | malicious | Generic.Bash.MiraiA.EA2591E1 (B) |
| ESET-NOD32 | malicious | Linux/TrojanDownloader.SH.FFM trojan |
| F-Secure | malicious | Malware.HTML/ExpKit.Gen2 |
| Fortinet | malicious | BASH/Mirai.AEH!tr.dldr |
| GData | malicious | Generic.Bash.MiraiA.EA2591E1 |
| malicious | Detected |
|
| huorong | malicious | TrojanDownloader/Linux.Agent.ci |
| Kaspersky | malicious | HEUR:Trojan-Downloader.Shell.Agent.a |
| Microsoft | malicious | Trojan:SH/Geninst.JA |
| MicroWorld-eScan | malicious | Generic.Bash.MiraiA.EA2591E1 |
| Sangfor | malicious | Trojan.Generic-Script.Save.ba514 |
| Skyhigh | malicious | Linux/Downloader.w |
| Symantec | malicious | CL.Downloader!gen277 |
| Tencent | malicious | Html.Trojan.Expkit.Rnkl |
| TrellixENS | malicious | Linux/Downloader.w |
| TrendMicro | malicious | Possible_BASHDLOD.SMLBO1 |
| TrendMicro-HouseCall | malicious | Possible_BASHDLOD.SMLBO1 |
| Varist | malicious | SH/Mirai.D.gen!Camelot |
| VIPRE | malicious | Generic.Bash.MiraiA.EA2591E1 |
Details From VirusTotal
Basic Properties
| MD5 | 5202058cceb5de50ef30b8e992ba2fb7 |
| SHA-1 | caa419a844176c843258d04b7e0882f455e8d7cf |
| SHA-256 | 9cb6369175c9ed8da004395a54b93d98dd2f23333fd5641838b8850ecd1b8974 |
| SSDEEP | 24:05WXbe1A6PjpjNIh5jQbCKv5j7Mu6Z1kHTvzlplmF/EnwZf65Ge1mjbc2/oI63Bd:nbwRH0ZfeGg6O |
| TLSH | T18E317FCA3C12FDD6F457AE0BB2B0494AB03C94AF316FCFA6C9074A14C42C18E7116A18 |
| File type | Shell script |
| File type tag | shell |
| File extension | sh |
| Magic | Bourne-Again shell script, ASCII text executable |
| File size | 1.8 KB |
History
| First seen on VirusTotal | 2026-05-20 23:43 UTC |
| Last submission | 2026-05-20 23:43 UTC |
| Last analysis | 2026-05-21 00:03 UTC |
| Last modified on VirusTotal | 2026-05-21 02:23 UTC |
Known Names
_9cb6369175c9ed8da004395a54b93d98dd2f23333fd5641838b8850ecd1b8974.sh
hash_sha1
caa419a844176c843258d04b7e0882f455e8d7cf
VT 28 / 75
IOC database
- Type
- hash_sha1
- Value
caa419a844176c843258d04b7e0882f455e8d7cf- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 28 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| ALYac | malicious | Generic.Bash.MiraiA.EA2591E1 |
| Arcabit | malicious | Generic.Bash.MiraiA.EA2591E1 |
| Avast | malicious | BV:Downloader-AMZ [Drp] |
| AVG | malicious | BV:Downloader-AMZ [Drp] |
| Avira | malicious | HTML/ExpKit.Gen2 |
| BitDefender | malicious | Generic.Bash.MiraiA.EA2591E1 |
| CTX | malicious | shell.unknown.bash |
| Cynet | malicious | Malicious (score: 99) |
| DrWeb | malicious | Linux.DownLoader.37 |
| Emsisoft | malicious | Generic.Bash.MiraiA.EA2591E1 (B) |
| ESET-NOD32 | malicious | Linux/TrojanDownloader.SH.FFM trojan |
| F-Secure | malicious | Malware.HTML/ExpKit.Gen2 |
| Fortinet | malicious | BASH/Mirai.AEH!tr.dldr |
| GData | malicious | Generic.Bash.MiraiA.EA2591E1 |
| malicious | Detected |
|
| huorong | malicious | TrojanDownloader/Linux.Agent.ci |
| Kaspersky | malicious | HEUR:Trojan-Downloader.Shell.Agent.a |
| Microsoft | malicious | Trojan:SH/Geninst.JA |
| MicroWorld-eScan | malicious | Generic.Bash.MiraiA.EA2591E1 |
| Sangfor | malicious | Trojan.Generic-Script.Save.ba514 |
| Skyhigh | malicious | Linux/Downloader.w |
| Symantec | malicious | CL.Downloader!gen277 |
| Tencent | malicious | Html.Trojan.Expkit.Rnkl |
| TrellixENS | malicious | Linux/Downloader.w |
| TrendMicro | malicious | Possible_BASHDLOD.SMLBO1 |
| TrendMicro-HouseCall | malicious | Possible_BASHDLOD.SMLBO1 |
| Varist | malicious | SH/Mirai.D.gen!Camelot |
| VIPRE | malicious | Generic.Bash.MiraiA.EA2591E1 |
Details From VirusTotal
Basic Properties
| MD5 | 5202058cceb5de50ef30b8e992ba2fb7 |
| SHA-1 | caa419a844176c843258d04b7e0882f455e8d7cf |
| SHA-256 | 9cb6369175c9ed8da004395a54b93d98dd2f23333fd5641838b8850ecd1b8974 |
| SSDEEP | 24:05WXbe1A6PjpjNIh5jQbCKv5j7Mu6Z1kHTvzlplmF/EnwZf65Ge1mjbc2/oI63Bd:nbwRH0ZfeGg6O |
| TLSH | T18E317FCA3C12FDD6F457AE0BB2B0494AB03C94AF316FCFA6C9074A14C42C18E7116A18 |
| File type | Shell script |
| File type tag | shell |
| File extension | sh |
| Magic | Bourne-Again shell script, ASCII text executable |
| File size | 1.8 KB |
History
| First seen on VirusTotal | 2026-05-20 23:43 UTC |
| Last submission | 2026-05-20 23:43 UTC |
| Last analysis | 2026-05-21 00:03 UTC |
| Last modified on VirusTotal | 2026-05-21 02:23 UTC |
Known Names
_9cb6369175c9ed8da004395a54b93d98dd2f23333fd5641838b8850ecd1b8974.sh
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: sh. Size: 1837 bytes. Tags: sh. Reporter: abuse_ch. First seen: 2026-05-20 23:41:43.
Remediations (8)
-
web:panorays.com
Discover the difference between remediation and mitigation in risk management and how each strategy impacts security and resilience.
-
web:securityboulevard.com
Choosing between remediation and mitigation depends on several factors, including the severity of the vulnerability, available resources, and potential impact on business operations. Here are some considerations to help guide the decision: Urgency and Risk Level When a vulnerability poses a high risk and requires immediate attention, remediation is the preferred choice. By directly fixing the ...
-
web:virsec.com
Explore the nuances of vulnerability mitigation vs. remediation and see why a combined strategy is key for reducing security risks.
-
web:www.bugcrowd.com
Mitigation solutions include isolating a set of vulnerable resources from the rest of the network with segmentation, temporarily disabling an application, or blocking a port that could provide access to a vulnerable resource. Your choice usually isn't a straightforward either/or decision between vulnerability remediation and mitigation .
-
web:www.ionix.io
In this blog, we'll look at remediation vs. mitigation and how to handle vulnerabilities as they arise with your third parties.
-
web:www.rapid7.com
Automation can be a big help in effective vulnerability management, both when it comes to remediation and mitigation . For remediation , you'll want to adopt a vulnerability management solution, like Rapid7's InsightVM, that eliminates the need for manual reporting, complex spreadsheets, and confusing back-and-forth email tags.
-
web:www.secure.com
Learn the difference between vulnerability remediation and mitigation , and how a risk-based strategy can strengthen your security posture.
-
web:www.strongboxit.com
Learn the key differences between vulnerability remediation vs mitigation in cybersecurity. Discover which method is effective for protecting your data.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.