TF-1932562
high
📛 Threat Title
VShell: SHA256 hash of a malware sample (payload) 7a1af320c9474415699030039ebc7fac0e34ff66e4e10e55fcf30b211b7c94d4
Description
Indicator that identifies a malware sample (payload). IOC type: SHA256 hash of a malware sample (payload). Attributed malware: VShell. Confidence: 95. First seen: 2026-09-25 01:44:47 UTC. Reporter: whack_sh. Tags: exe, Vshell.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
7a1af320c9474415699030039ebc7fac0e34ff66e4e10e55fcf30b211b7c94d4
VT 43 / 74
IOC database
- Type
- hash_sha256
- Value
7a1af320c9474415699030039ebc7fac0e34ff66e4e10e55fcf30b211b7c94d4- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- VShell
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 43 of 74 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| AhnLab-V3 | malicious | Trojan/Win.Generic.C5508256 |
| alibabacloud | malicious | Backdoor:Win/shellcode.api(dyn) |
| ALYac | malicious | Gen:Variant.Application.Jaik.45622 |
| Antiy-AVL | malicious | Trojan/Win32.Mikey |
| APEX | malicious | Malicious |
| Arcabit | malicious | Trojan.Application.Jaik.DB236 |
| Avast | malicious | Win32:MalwareX-gen [Trj] |
| AVG | malicious | Win32:MalwareX-gen [Trj] |
| Avira | malicious | TR/W32.MalwareX |
| BitDefender | malicious | Gen:Variant.Application.Jaik.45622 |
| Bkav | malicious | W32.Malware.EFE5B203 |
| CrowdStrike | malicious | win/malicious_confidence_100% (W) |
| CTX | malicious | exe.unknown.jaik |
| Cylance | malicious | Unsafe |
| Cynet | malicious | Malicious (score: 100) |
| DeepInstinct | malicious | MALICIOUS |
| DrWeb | malicious | BackDoor.Siggen2.5324 |
| Elastic | malicious | malicious (high confidence) |
| Emsisoft | malicious | Gen:Variant.Application.Jaik.45622 (B) |
| ESET-NOD32 | malicious | Win64/Rozena.ZA trojan |
| F-Secure | malicious | Trojan.TR/W32.MalwareX |
| Fortinet | malicious | W32/Rozena.ZA!tr |
| GData | malicious | Gen:Variant.Application.Jaik.45622 |
| malicious | Detected |
|
| huorong | malicious | TrojanDownloader/Agent.bri |
| Ikarus | malicious | Trojan-Downloader.Win64.Small |
| Kaspersky | malicious | HEUR:Trojan.Win32.Generic |
| Kingsoft | malicious | malware.kb.a.935 |
| Malwarebytes | malicious | Malware.AI.1039774085 |
| McAfeeD | malicious | ti!7A1AF320C947 |
| Microsoft | malicious | Trojan:Win32/Mikey.HNC!MTB |
| MicroWorld-eScan | malicious | Gen:Variant.Application.Jaik.45622 |
| NANO-Antivirus | malicious | Virus.Win32.Gen.ccmw |
| Rising | malicious | Trojan.Mikey!8.1186D (TFE:3:Va1tsgOetEG) |
| Sophos | malicious | Troj/Loader-IY |
| SUPERAntiSpyware | malicious | Trojan.Agent/Gen-Mikey |
| Symantec | malicious | ML.Attribute.HighConfidence |
| Varist | malicious | W32/Rozena.JO.gen!Eldorado |
| VBA32 | malicious | BScope.Trojan.Wacatac |
| VIPRE | malicious | Gen:Variant.Application.Jaik.45622 |
| VirIT | malicious | Trojan.Win32.GenHeur.C |
| Webroot | malicious | Win.Trojan.Gen |
| ZoneAlarm | malicious | Troj/Loader-IY |
Details From VirusTotal
Basic Properties
| MD5 | 4e764918234c58a359dad275380c5ecd |
| SHA-1 | 09715c3421cf537aa29abb88883bdc0021b06fcb |
| SHA-256 | 7a1af320c9474415699030039ebc7fac0e34ff66e4e10e55fcf30b211b7c94d4 |
| VHash | 04303655151bz1!z |
| SSDEEP | 48:6I7lwe7Nih08SLJdSR1Ig9TPe1YpV1ZsSZIXxhxhwcRaK:Pl1pc091q1Ig9T2Enwp |
| TLSH | T12B91A5C5F757E6B2EC1C07F500A3B9A4C4682E14927C9B568FE16F0C3C111AA3D3DA52 |
| File type | Win32 EXE |
| File type tag | peexe |
| File extension | exe |
| Magic | PE32 executable (GUI) Intel 80386, for MS Windows |
| File size | 4.5 KB |
History
| Creation date | 2023-10-26 14:20 UTC |
| First seen on VirusTotal | 2026-09-16 22:14 UTC |
| Last submission | 2026-09-16 22:14 UTC |
| Last analysis | 2026-09-16 22:14 UTC |
| Last modified on VirusTotal | 2026-09-24 18:09 UTC |
Known Names
olfs5g4.exewindows_i386.exe
References (2)
- Malpedia profile ThreatFox IOCs
-
ThreatFox IOC page
ThreatFox IOCs
Indicator that identifies a malware sample (payload). IOC type: SHA256 hash of a malware sample (payload). Attributed malware: VShell. Confidence: 95. First seen: 2026-09-25 01:44:47 UTC. Reporter: whack_sh. Tags: exe, Vshell.
Remediations (10)
-
web:bazaar.abuse.ch
Information on VShell malware sample ( SHA256 07a7afd2a891cbd8b1600d0327a6832d596b655011b9fc79265c7e068bc8fc85) MalwareBazaar Database You are currently viewing the ...
-
web:bazaar.abuse.ch
Information on VShell malware sample ( SHA256 b98fc9f0dbc61810287e77ea978665a0b762dceea927bbffceb63fb7005149b3) YARA Signatures MalwareBazaar uses YARA rules from ...
-
web:bazaar.abuse.ch
Information on VShell malware sample ( SHA256 c18f7f43b71b39a46f888fab94408e07bba9ef75ab1de2146bef9231705318f0) YARA Signatures MalwareBazaar uses YARA rules from ...
-
web:bazaar.abuse.ch
Information on VShell malware sample ( SHA256 d4a1d31071219e052098223e88b0bc28bb78cc47fb0b6aa8cddf4ceff36ef556) YARA Signatures MalwareBazaar uses YARA rules from ...
-
web:boteraser.com
The malware uses a modular plugin architecture, allowing it to execute arbitrary commands, upload/download files, capture keystrokes, and enumerate network resources.
-
web:cipherssecurity.com
Check MD5, SHA-1, or SHA-256 file hashes against MalwareBazaar and VirusTotal feeds. Drop a file — hashing happens in your browser, never uploaded.
-
web:ismalicious.com
Database of known malware file hashes. MD5, SHA1, and SHA256 hashes with malware family classification. Updated daily from sandbox analysis and vendor feeds.
-
web:ismalicious.com
1,755 indicators of compromise attributed to the VShell malware family — domains, IPs, URLs and file hashes, from abuse.ch feeds.
-
web:www.sysdig.com
The SNOWLIGHT malware acts as a dropper for a fileless payload that resides solely in memory, called VShell . VShell is a Remote Access Trojan (RAT) popular among Chinese-speaking cybercriminals in several forums, and its main developer is also a Chinese speaker.
-
web:www.trellix.com
Final payload : VShell malware VShell malware is a Go-based backdoor used primarily by Chinese APT groups for remote access, file operations, and post-exploitation control on infected systems especially Linux servers.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.