MB-1312c34b39dc8dcc8ab101a936f37e867492876a84f94ecfacf2df96c1e4db84
high
📛 Threat Title
Unknown: 1312c34b39dc8dcc8ab101a936f37e867492876a84f94ecfacf2df96c1e4db84.sh
Description
File type: sh. Size: 11053 bytes. Tags: sh. Reporter: abuse_ch. First seen: 2026-09-25 11:31:38.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
1312c34b39dc8dcc8ab101a936f37e867492876a84f94ecfacf2df96c1e4db84
VT 19 / 75
IOC database
- Type
- hash_sha256
- Value
1312c34b39dc8dcc8ab101a936f37e867492876a84f94ecfacf2df96c1e4db84- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Unknown
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 19 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| alibabacloud | malicious | Trojan[downloader]:Linux/Agent.a |
| Antiy-AVL | malicious | Trojan[Downloader]/Shell.Agent |
| Avast | malicious | BV:Downloader-BPG [Trj] |
| AVG | malicious | BV:Downloader-BPG [Trj] |
| Avira | malicious | TR/BAT.Downloader.BPG |
| Cynet | malicious | Malicious (score: 99) |
| ESET-NOD32 | malicious | Linux/TrojanDownloader.SH.FJS trojan |
| F-Secure | malicious | Trojan.TR/BAT.Downloader.BPG |
| GData | malicious | Script.Trojan.Agent.D7HLEW |
| malicious | Detected |
|
| huorong | malicious | TrojanDownloader/Linux.Shell.cr |
| Kaspersky | malicious | HEUR:Trojan-Downloader.Shell.Agent.a |
| Kingsoft | malicious | Win32.Troj.Undef.a |
| McAfeeD | malicious | ti!1312C34B39DC |
| Microsoft | malicious | Trojan:Win32/Egairtigado!rfn |
| Sangfor | malicious | Trojan.Generic-Bash.Save.cbad8f80 |
| Symantec | malicious | Trojan.Gen.MBT |
| Tencent | malicious | Win32.Trojan.Trojandownloader.Jjgl |
| Varist | malicious | Agent.VX |
Details From VirusTotal
Basic Properties
| MD5 | 66f0cdaabfe171ed2bd677437a16e9ad |
| SHA-1 | b74cd6fb8be77156cbe3f013f33dce84558116f8 |
| SHA-256 | 1312c34b39dc8dcc8ab101a936f37e867492876a84f94ecfacf2df96c1e4db84 |
| SSDEEP | 96:cCuosht+O+v1fsn+h4+tIiKqCTyOysYtujtuHKNpUj4waHv6y7LrJ1raqvlAAbKb:cCul4hvZ5m5FG4j4HKNphvfd1+qd0 |
| TLSH | T1AC32463B21F08B32D7C410C9A3B61A654E72A70B452614B5F4FE6736AF2D90371E7B61 |
| File type | XML |
| File type tag | xml |
| File extension | xml |
| Magic | ASCII text |
| File size | 10.8 KB |
History
| First seen on VirusTotal | 2026-09-25 11:34 UTC |
| Last submission | 2026-09-25 11:34 UTC |
| Last analysis | 2026-09-25 22:10 UTC |
| Last modified on VirusTotal | 2026-09-26 00:12 UTC |
Known Names
nq15g77s.exe1312c34b39dc8dcc8ab101a936f37e867492876a84f94ecfacf2df96c1e4db84.sh
hash_sha1
b74cd6fb8be77156cbe3f013f33dce84558116f8
VT 19 / 75
IOC database
- Type
- hash_sha1
- Value
b74cd6fb8be77156cbe3f013f33dce84558116f8- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 19 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| alibabacloud | malicious | Trojan[downloader]:Linux/Agent.a |
| Antiy-AVL | malicious | Trojan[Downloader]/Shell.Agent |
| Avast | malicious | BV:Downloader-BPG [Trj] |
| AVG | malicious | BV:Downloader-BPG [Trj] |
| Avira | malicious | TR/BAT.Downloader.BPG |
| Cynet | malicious | Malicious (score: 99) |
| ESET-NOD32 | malicious | Linux/TrojanDownloader.SH.FJS trojan |
| F-Secure | malicious | Trojan.TR/BAT.Downloader.BPG |
| GData | malicious | Script.Trojan.Agent.D7HLEW |
| malicious | Detected |
|
| huorong | malicious | TrojanDownloader/Linux.Shell.cr |
| Kaspersky | malicious | HEUR:Trojan-Downloader.Shell.Agent.a |
| Kingsoft | malicious | Win32.Troj.Undef.a |
| McAfeeD | malicious | ti!1312C34B39DC |
| Microsoft | malicious | Trojan:Win32/Egairtigado!rfn |
| Sangfor | malicious | Trojan.Generic-Bash.Save.cbad8f80 |
| Symantec | malicious | Trojan.Gen.MBT |
| Tencent | malicious | Win32.Trojan.Trojandownloader.Jjgl |
| Varist | malicious | Agent.VX |
Details From VirusTotal
Basic Properties
| MD5 | 66f0cdaabfe171ed2bd677437a16e9ad |
| SHA-1 | b74cd6fb8be77156cbe3f013f33dce84558116f8 |
| SHA-256 | 1312c34b39dc8dcc8ab101a936f37e867492876a84f94ecfacf2df96c1e4db84 |
| SSDEEP | 96:cCuosht+O+v1fsn+h4+tIiKqCTyOysYtujtuHKNpUj4waHv6y7LrJ1raqvlAAbKb:cCul4hvZ5m5FG4j4HKNphvfd1+qd0 |
| TLSH | T1AC32463B21F08B32D7C410C9A3B61A654E72A70B452614B5F4FE6736AF2D90371E7B61 |
| File type | XML |
| File type tag | xml |
| File extension | xml |
| Magic | ASCII text |
| File size | 10.8 KB |
History
| First seen on VirusTotal | 2026-09-25 11:34 UTC |
| Last submission | 2026-09-25 11:34 UTC |
| Last analysis | 2026-09-25 22:10 UTC |
| Last modified on VirusTotal | 2026-09-26 00:12 UTC |
Known Names
nq15g77s.exe1312c34b39dc8dcc8ab101a936f37e867492876a84f94ecfacf2df96c1e4db84.sh
hash_md5
66f0cdaabfe171ed2bd677437a16e9ad
VT 19 / 75
IOC database
- Type
- hash_md5
- Value
66f0cdaabfe171ed2bd677437a16e9ad- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 19 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| alibabacloud | malicious | Trojan[downloader]:Linux/Agent.a |
| Antiy-AVL | malicious | Trojan[Downloader]/Shell.Agent |
| Avast | malicious | BV:Downloader-BPG [Trj] |
| AVG | malicious | BV:Downloader-BPG [Trj] |
| Avira | malicious | TR/BAT.Downloader.BPG |
| Cynet | malicious | Malicious (score: 99) |
| ESET-NOD32 | malicious | Linux/TrojanDownloader.SH.FJS trojan |
| F-Secure | malicious | Trojan.TR/BAT.Downloader.BPG |
| GData | malicious | Script.Trojan.Agent.D7HLEW |
| malicious | Detected |
|
| huorong | malicious | TrojanDownloader/Linux.Shell.cr |
| Kaspersky | malicious | HEUR:Trojan-Downloader.Shell.Agent.a |
| Kingsoft | malicious | Win32.Troj.Undef.a |
| McAfeeD | malicious | ti!1312C34B39DC |
| Microsoft | malicious | Trojan:Win32/Egairtigado!rfn |
| Sangfor | malicious | Trojan.Generic-Bash.Save.cbad8f80 |
| Symantec | malicious | Trojan.Gen.MBT |
| Tencent | malicious | Win32.Trojan.Trojandownloader.Jjgl |
| Varist | malicious | Agent.VX |
Details From VirusTotal
Basic Properties
| MD5 | 66f0cdaabfe171ed2bd677437a16e9ad |
| SHA-1 | b74cd6fb8be77156cbe3f013f33dce84558116f8 |
| SHA-256 | 1312c34b39dc8dcc8ab101a936f37e867492876a84f94ecfacf2df96c1e4db84 |
| SSDEEP | 96:cCuosht+O+v1fsn+h4+tIiKqCTyOysYtujtuHKNpUj4waHv6y7LrJ1raqvlAAbKb:cCul4hvZ5m5FG4j4HKNphvfd1+qd0 |
| TLSH | T1AC32463B21F08B32D7C410C9A3B61A654E72A70B452614B5F4FE6736AF2D90371E7B61 |
| File type | XML |
| File type tag | xml |
| File extension | xml |
| Magic | ASCII text |
| File size | 10.8 KB |
History
| First seen on VirusTotal | 2026-09-25 11:34 UTC |
| Last submission | 2026-09-25 11:34 UTC |
| Last analysis | 2026-09-25 22:10 UTC |
| Last modified on VirusTotal | 2026-09-26 00:12 UTC |
Known Names
nq15g77s.exe1312c34b39dc8dcc8ab101a936f37e867492876a84f94ecfacf2df96c1e4db84.sh
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: sh. Size: 11053 bytes. Tags: sh. Reporter: abuse_ch. First seen: 2026-09-25 11:31:38.
Remediations (10)
-
web:blog.paessler.com
Learn how to identify and secure unknown devices on your network with detailed steps and advanced tools to protect your data and privacy.
-
web:github.com
CVE-2026-31431 Mitigation Script This repository provides a temporary mitigation and revert script for CVE-2026-31431, a Linux kernel local privilege escalation vulnerability.
-
web:ip-lookup.net
IP Address Lookup Look up IPv4 and IPv6 addresses to review map-based location, ISP, ASN, reverse DNS, WHOIS or RDAP ownership, and network risk signals. Compare current-address tools, IPv6 utilities, and privacy checks from one search surface.
-
web:maclookup.app
Check an OUIs or a MAC address and display details like vendor name, location, MAC details, and more… Search by Vendor Name?
-
web:maclookup.app
Use our MAC Address Search to find manufacturer details and vendor information in real-time. Enhance your network security with maclookup.app.
-
web:www.17track.net
Track your Unknown package instantly with 17TRACK. Get real-time updates, shipment status and delivery progress. Free tracking, no login required.
-
web:www.komodolabs.com
Komodo Labs' MAC address lookup tool provides vendor details and device age estimation, helping identify cybersecurity risks in older network devices.
-
web:www.macvendorlookup.com
MAC Address Lookup Enter any MAC address, OUI, or IAB below to lookup the manufacturer, location, and more
-
web:www.speedguide.net
SG MAC Address OUI Search About the SG MAC Address lookup tool The MAC Adderss OUI search helps identify unknown devices on your local network by simply typing their MAC address (or its OUI prefix), commonly listed by your NAT/Wireless router. It can be useful in identifying network adapter manufacturers, IoT devices, wireless clients, etc. MAC address (media access control address) is a ...
-
web:www.toolsley.com
Free browser tool to identify unknown files based on their contents. Recognizes over 2000 file formats using libmagic. No installation necessary. Just drag & drop!
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.