TF-1868509
high
📛 Threat Title
VShell: ip:port combination that is used for botnet Command&control (C&C) 38.55.105.238:8084
Description
Indicator that identifies a botnet command&control server (C&C). IOC type: ip:port combination that is used for botnet Command&control (C&C). Attributed malware: VShell. Confidence: 100. Observed port: 8084. First seen: 2026-08-04 20:05:07 UTC. Reporter: anonymous. Tags: Vshell.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
ipv4
38.55.105.238
IOC database
- Type
- ipv4
- Value
38.55.105.238- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- ip:port combination that is used for botnet Command&control (C&C) attributed to VShell
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (2)
- Malpedia profile ThreatFox IOCs
-
ThreatFox IOC page
ThreatFox IOCs
Indicator that identifies a botnet command&control server (C&C). IOC type: ip:port combination that is used for botnet Command&control (C&C). Attributed malware: VShell. Confidence: 100. Observed port: 8084. First seen: 2026-08-04 20:05:07 UTC. Reporter: anonymous. Tags: Vshell.
Remediations (9)
-
web:github.com
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode characters Show hidden characters Original file line number Diff line number Diff line change @@ -1,2 +1,4 @@ # Simple C HTTP Botnet
-
web:indiancyberclub.com
We would like to show you a description here but the site won't allow us.
-
web:www.cmu.edu
301 Moved Permanently Moved Permanently The document has moved here.
-
web:www.cnblogs.com
We would like to show you a description here but the site won't allow us.
-
web:www.kasada.io
The Anatomy of a Botnet Attack A botnet attack unfolds in three distinct phases. Infection: The attacker identifies methods of gaining control of a device, such as any susceptibilities that can be exploited to introduce malicious software. Command and control: The bot herder manages the infected devices through a C&C server.
-
web:www.rainforest.tech
Date: December 2025 Severity: CRITICAL Executive Summary This technical bulletin covers three critical attack vectors currently impacting organizations worldwide: the React2Shell vulnerability (CVE-2025-55182) actively exploited by Chinese APT groups, malicious extensions in the VSCode Marketplace compromising development environments, and the escalation of software supply chain attacks ...
-
web:www.redpacketsecurity.com
www.redpacketsecurity.com
-
web:www.techmonitor.ai
Tech Monitor - Navigating the horizon of business technology .
-
web:www.weforum.org
The World Economic Forum
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.