s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

MB-b6307cb3e0da1b5393cc002bdc02458d2a2604be5f12d184965f807e0d4415a8 high

📛 Threat Title

VShell: b6307cb3e0da1b5393cc002bdc02458d2a2604be5f12d184965f807e0d4415a8.exe

Category: VShell Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: exe. Size: 3584 bytes. Tags: exe, VShell. Reporter: Tuxxin. First seen: 2026-09-25 04:09:51.

Indicators of Compromise (4)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_imphash e82dd51b077167be63c004bed23d0c1e

IOC database

Type
hash_imphash
Value
e82dd51b077167be63c004bed23d0c1e
First seen
Last seen
Attached to this threat
Appears in
106 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha256 b6307cb3e0da1b5393cc002bdc02458d2a2604be5f12d184965f807e0d4415a8

IOC database

Type
hash_sha256
Value
b6307cb3e0da1b5393cc002bdc02458d2a2604be5f12d184965f807e0d4415a8
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
VShell

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 549f20805c66c717cc497fcf8c34a4c6a202a893

IOC database

Type
hash_sha1
Value
549f20805c66c717cc497fcf8c34a4c6a202a893
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_md5 6fd95cbbe8d961f26e89e870986f16ef

IOC database

Type
hash_md5
Value
6fd95cbbe8d961f26e89e870986f16ef
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: exe. Size: 3584 bytes. Tags: exe, VShell. Reporter: Tuxxin. First seen: 2026-09-25 04:09:51.

Remediations (10)

  • web:bazaar.abuse.ch

    VShell malware samples MalwareBazaar Database MalwareBazaar tries to identify the malware family (signature) of submitted malware samples. A malware sample can be associated with only one malware family. The page below gives you an overview on malware samples that MalwareBazaar has identified as VShell . Database Entry

  • web:boteraser.com

    VShell enables adversaries to exfiltrate sensitive intellectual property, source code, and employee credentials, leading to long-term espionage and supply-chain compromise.

  • web:github.com

    An incomplete reverse-engineered re-implementation of the in-the-wild exploited C2 framework " VShell " ⚠️ Disclaimer This repository is an incomplete reverse-engineering / re-implementation of the in-the-wild exploited C2 framework VShell (v3.0), for security research and learning purposes only. For authorized testing only. Any unlawful use is prohibited. Unofficial, unaffiliated with the ...

  • web:hunt.io

    VShell is an open-source, cross-platform malware designed to grant attackers remote access to compromised systems. It works on Windows, Linux, and macOS platforms, allowing attackers to execute commands, transfer files, and gather system information. VShell is highly customizable, which makes it a flexible and dangerous tool for cybercriminals.

  • web:malpedia.caad.fkie.fraunhofer.de

    VShell is an OST framework written in Go, enabling availability of implants for multiple platforms (Windows, Linux, macOS).

  • web:www.derp.ca

    VShell is a Go-based, cross-platform remote-access trojan and backdoor supporting Windows, Linux, and macOS/Darwin systems.

  • web:www.nviso.eu

    NVISO has actively tracked VShell for months, a Chinese-language intrusion tool used in espionage campaigns. NVISO has actively tracked VShell for months, a Chinese-language intrusion tool used in espionage campaigns. We share global infrastructure tracking techniques, tools to decrypt VShell communications, and insights into attacker behaviors.

  • web:www.secpod.com

    Weaponizing CVE-2026-1731: VShell and SparkRAT in Real-World BeyondTrust Breaches On February 6, 2026, BeyondTrust disclosed a critical pre-authentication remote code execution vulnerability, CVE-2026-1731, affecting its Remote Support and Privileged Remote Access products. The flaw, assigned a CVSS v4 score of 9.9, enables unauthenticated attackers to execute arbitrary operating...

  • web:www.vandyke.com

    VShell is a secure, multi-protocol file transfer server. Protect data in transit with SSH2, SFTP, FTPS, or HTTPS. Simple to install and configure, VShell offers security with convenience, flexibility, and quality technical support. VShell Enterprise Edition with HTTPS is an easy-to-use, browser-based file transfer solution.

  • web:www.vandyke.com

    The VShell Monitor is a real-time connection monitoring tool that displays the current connections to the VShell server. VanDyke Software Support provides comprehensive technical support, including pre-sales evaluation, consultation for installation and configuration issues, and support of maintenance and upgrade software.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.