MB-8e786c3c15f527f5761dfb880179bb51dc0b6e2596700955ebca06597ad28d29
high
📛 Threat Title
Unknown: loader.sh
Description
File type: unknown. Size: 1305 bytes. Reporter: BlinkzSec. First seen: 2026-05-14 20:05:48.
Indicators of Compromise (4)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
loader.sh
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/loader.sh
UrlVoid 4 / 35
IOC database
- Type
- domain
- Value
loader.sh- First seen
- Last seen
- Attached to this threat
- Appears in
- 6 threats
- Description
- Extracted from Threat MB-ace5bd012ba9a7250286a9258aba3474c12f1ef5c50e98a388aec9e535e84e3b
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/loader.sh
hash_sha256
8e786c3c15f527f5761dfb880179bb51dc0b6e2596700955ebca06597ad28d29
1 feed
IOC database
- Type
- hash_sha256
- Value
8e786c3c15f527f5761dfb880179bb51dc0b6e2596700955ebca06597ad28d29- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- Unknown
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha1
276ad36a6d41ddc74249700484512ed5bc665f95
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/276ad36a6d41ddc74249700484512ed5bc665f95
1 feed
IOC database
- Type
- hash_sha1
- Value
276ad36a6d41ddc74249700484512ed5bc665f95- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/276ad36a6d41ddc74249700484512ed5bc665f95
hash_md5
9c66648c31cf4128992af86ba9219da0
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/9c66648c31cf4128992af86ba9219da0
1 feed
IOC database
- Type
- hash_md5
- Value
9c66648c31cf4128992af86ba9219da0- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/9c66648c31cf4128992af86ba9219da0
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: unknown. Size: 1305 bytes. Reporter: BlinkzSec. First seen: 2026-05-14 20:05:48.
Remediations (10)
-
web:askubuntu.com
9 Update: Kernel 6.8.-117.117 is released now and features a kernel-level fix for CVE-2026-31431. While the website may be down, the security email list continues to work apparently and they have emailed about a mitigation there in an email from 30.04.2026 18:06 CET. The issue should be mitigated for now thanks to USN-8226-1 and USN-8226-2.
-
web:github.com
Shares the affected xfrm # code path; called out by AWS Security Bulletin # 2026-027 as part of the mitigation set. # * rxrpc — RxRPC protocol stack (CVE-2026-43500). # # The remediation is idempotent — running it repeatedly has no # additional effect once the blacklist file is in place and the # modules are unloaded.
-
web:github.com
CVE-2026-31431 Mitigation Script This repository provides a temporary mitigation and revert script for CVE-2026-31431, a Linux kernel local privilege escalation vulnerability.
-
web:knowledge.broadcom.com
CVE-2026-22719 has direct impact to Aria Operations 8.18.x, and Aria Operations 9.0.x This vulnerability and its impact on the mentioned VMware products are documented in the following VMware Security Advisory (VMSA), please review this document before continuing: CVE-2026-22719 - VMSA-2026-0001 See the Change log at the end of this article for all changes and subscribe to the article for updates.
-
web:scloud.work
When a proactive remediation script fails to work as expected, it's much faster to test it locally than wait for the next sync from Intune. In this post, I'll show you how I troubleshoot Intune remediation scripts directly on a Windows device. This includes script locations, relevant logs, and registry entries that help verify what […]
-
web:windowsforum.com
A critical deserialization vulnerability in Fuji Electric's FRENIC-Loader 4 — tracked as CVE‑2025‑9365 and given a CVSS v4 base score of 8.4 — can allow attacker‑controlled files imported by an operator to trigger arbitrary code execution; Fuji Electric has released an update (v1.4.0.1 or later) and CISA has published an advisory urging rapid remediation and network hardening.
-
web:www.anonymoushackers.net
This article explores what PowerShell loader malware is, how it works, techniques for detection, real-world attack examples, and mitigation strategies.
-
web:www.reddit.com
If you don't have the in house staff to perform the threat analysis or threat hunting, you need a SOC. You could look at black point cyber since your are a PAX 8 customer. You currently have the detection portion of EDR, but not the analysis and remediation piece. You can't compare Symantec to Sentinel One, they aren't the same. Sentinel One IMO, is a far superior product, and in the years we ...
-
web:www.secwest.net
How to block CVE-2026-31431 (Copy Fail) — the Linux kernel algif_aead local privilege escalation that poisons setuid binaries via the shared page cache. Fleet-scale module disable, RHEL built-in workarounds, Docker/Kubernetes seccomp profiles to refuse AF_ALG, audit and Falco detection rules, and exploit portability notes for Alpine, doas, and aarch64.
-
web:www.unknowncheats.me
hello everyone, i was wondering what methods to protect the loader are available and which of them are more reliable. interested in both the client pa
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.