MB-16db4b5aefca60a0f98d0aae888bdafd813a8a5f37fd2264b1667ec4f11b0698
high
📛 Threat Title
VShell: 16db4b5aefca60a0f98d0aae888bdafd813a8a5f37fd2264b1667ec4f11b0698.exe
Description
File type: exe. Size: 3584 bytes. Tags: exe, VShell. Reporter: Tuxxin. First seen: 2026-09-25 03:59:30.
Indicators of Compromise (4)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_imphash
e82dd51b077167be63c004bed23d0c1e
IOC database
- Type
- hash_imphash
- Value
e82dd51b077167be63c004bed23d0c1e- First seen
- Last seen
- Attached to this threat
- Appears in
- 106 threats
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha256
16db4b5aefca60a0f98d0aae888bdafd813a8a5f37fd2264b1667ec4f11b0698
IOC database
- Type
- hash_sha256
- Value
16db4b5aefca60a0f98d0aae888bdafd813a8a5f37fd2264b1667ec4f11b0698- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- VShell
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha1
a22c7ec9d8cbd7ee4edffd58c5bf69abe8afd020
IOC database
- Type
- hash_sha1
- Value
a22c7ec9d8cbd7ee4edffd58c5bf69abe8afd020- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_md5
12cf734117f67fcf1e0a852b84047cfd
IOC database
- Type
- hash_md5
- Value
12cf734117f67fcf1e0a852b84047cfd- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: exe. Size: 3584 bytes. Tags: exe, VShell. Reporter: Tuxxin. First seen: 2026-09-25 03:59:30.
Remediations (10)
-
web:bazaar.abuse.ch
VShell malware samples MalwareBazaar Database MalwareBazaar tries to identify the malware family (signature) of submitted malware samples. A malware sample can be associated with only one malware family. The page below gives you an overview on malware samples that MalwareBazaar has identified as VShell . Database Entry
-
web:boteraser.com
VShell enables adversaries to exfiltrate sensitive intellectual property, source code, and employee credentials, leading to long-term espionage and supply-chain compromise.
-
web:github.com
An incomplete reverse-engineered re-implementation of the in-the-wild exploited C2 framework " VShell " ⚠️ Disclaimer This repository is an incomplete reverse-engineering / re-implementation of the in-the-wild exploited C2 framework VShell (v3.0), for security research and learning purposes only. For authorized testing only. Any unlawful use is prohibited. Unofficial, unaffiliated with the ...
-
web:hunt.io
VShell is an open-source, cross-platform malware designed to grant attackers remote access to compromised systems. It works on Windows, Linux, and macOS platforms, allowing attackers to execute commands, transfer files, and gather system information. VShell is highly customizable, which makes it a flexible and dangerous tool for cybercriminals.
-
web:malpedia.caad.fkie.fraunhofer.de
VShell is an OST framework written in Go, enabling availability of implants for multiple platforms (Windows, Linux, macOS).
-
web:undercodetesting.com
SparkRAT and VShell Backdoor Deployment The attackers leveraged two distinct backdoors: SparkRAT, a cross-platform Go-based RAT first identified in 2023 DragonSpark campaigns, and VShell , a stealthy Linux backdoor capable of fileless memory execution .
-
web:www.microsoft.com
Understand how this virus or malware spreads and how its payloads affects your computer. Protect against this threat, identify symptoms, and clean up or remove infections.
-
web:www.nviso.eu
NVISO has actively tracked VShell for months, a Chinese-language intrusion tool used in espionage campaigns. NVISO has actively tracked VShell for months, a Chinese-language intrusion tool used in espionage campaigns. We share global infrastructure tracking techniques, tools to decrypt VShell communications, and insights into attacker behaviors.
-
web:www.vandyke.com
VShell is a secure, multi-protocol file transfer server. Protect data in transit with SSH2, SFTP, FTPS, or HTTPS. Simple to install and configure, VShell offers security with convenience, flexibility, and quality technical support. VShell Enterprise Edition with HTTPS is an easy-to-use, browser-based file transfer solution.
-
web:www.vandyke.com
The VShell Monitor is a real-time connection monitoring tool that displays the current connections to the VShell server. VanDyke Software Support provides comprehensive technical support, including pre-sales evaluation, consultation for installation and configuration issues, and support of maintenance and upgrade software.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.