MB-68bcc19c29b0865ab6767a24e8b2d1e5a926666ae6b80c2382e0723c4a5d6874
high
📛 Threat Title
Unknown: d.sh
Description
File type: sh. Size: 583 bytes. Reporter: BlinkzSec. First seen: 2026-05-14 19:49:19.
Indicators of Compromise (4)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
d.sh
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/d.sh
UrlVoid 0 / 35
IOC database
- Type
- domain
- Value
d.sh- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat MB-68bcc19c29b0865ab6767a24e8b2d1e5a926666ae6b80c2382e0723c4a5d6874
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/d.sh
hash_sha256
68bcc19c29b0865ab6767a24e8b2d1e5a926666ae6b80c2382e0723c4a5d6874
1 feed
IOC database
- Type
- hash_sha256
- Value
68bcc19c29b0865ab6767a24e8b2d1e5a926666ae6b80c2382e0723c4a5d6874- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- Unknown
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha1
86a2f06a09a7f7d94a97f6b6a5373bd7e8ca2b4b
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/86a2f06a09a7f7d94a97f6b6a5373bd7e8ca2b4b
1 feed
IOC database
- Type
- hash_sha1
- Value
86a2f06a09a7f7d94a97f6b6a5373bd7e8ca2b4b- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/86a2f06a09a7f7d94a97f6b6a5373bd7e8ca2b4b
hash_md5
383ef4bb3b8a64a00eb87174826861d0
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/383ef4bb3b8a64a00eb87174826861d0
1 feed
IOC database
- Type
- hash_md5
- Value
383ef4bb3b8a64a00eb87174826861d0- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/383ef4bb3b8a64a00eb87174826861d0
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: sh. Size: 583 bytes. Reporter: BlinkzSec. First seen: 2026-05-14 19:49:19.
Remediations (10)
-
web:carthageelectronics.com
May 19, 2026 CVE bulletin: Microsoft Exchange CVE-2026-42897 zero-day (CVSS 8.1), Linux Fragnesia CVE-2026-46300 privilege escalation with public PoC, and 130+ May Patch Tuesday fixes. Full remediation steps included.
-
web:cyberpress.org
Fragnesia is a universal local privilege escalation (LPE) exploit targeting the Linux kernel's XFRM ESP-in-TCP subsystem.
-
web:github.com
# # The remediation is idempotent — running it repeatedly has no # additional effect once the blacklist file is in place and the # modules are unloaded. # # WARNING # This mitigation disables IPsec ESP (esp4 / esp6), IPsec # IP-Compression (ipcomp4 / ipcomp6), and RxRPC (rxrpc) kernel # modules.
-
web:virsec.com
Mitigation , on the other hand, provides critical protection, acting as a vital defense against known and unknown threats until the advent of that final fix (if it ever comes). So, use them both. Don't make yourself a hostage to patching and slow remediation cycles. Reduce exposure with immediate and automated mitigation .
-
web:www.bugcrowd.com
Mitigation solutions include isolating a set of vulnerable resources from the rest of the network with segmentation, temporarily disabling an application, or blocking a port that could provide access to a vulnerable resource. Your choice usually isn't a straightforward either/or decision between vulnerability remediation and mitigation .
-
web:www.cisa.gov
High Vulnerabilities PrimaryVendor -- Product Description Published CVSS Score Source Info
-
web:www.esd.whs.mil
Ensure configuration, asset, remediation , and mitigation management supports vulnerability management within the DODIN in accordance with DoD Instruction (DoDI) 8510.01. Support all systems, subsystems, and system components owned by or operated on behalf of DoD with efficient vulnerability assessment techniques, procedures, and capabilities.
-
web:www.indusface.com
Discover how to prioritize, mitigate, and remediate vulnerabilities after detection. Learn key steps in effective vulnerability remediation and risk mitigation .
-
web:www.secure.com
Learn the difference between vulnerability remediation and mitigation , and how a risk-based strategy can strengthen your security posture.
-
web:www.tenable.com
Dirty Frag (CVE-2026-43284, CVE-2026-43500) is a Linux kernel local privilege escalation exploit chain with a public PoC affecting major Linux distributions.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.