🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 80f7d2d3de2cdfebab4c9d9b5de17efc7c08de900b12330c349beeaaf3eafedd. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



VShell


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments 1

SHA256 hash: 80f7d2d3de2cdfebab4c9d9b5de17efc7c08de900b12330c349beeaaf3eafedd
SHA3-384 hash: 64a1d4b0de618deb38960de9f6f741577cf95f1941778d86bbb3d917673af8b86874d9e95031e996b86d37c1f2d246a8
SHA1 hash: a585c051a53961017fe5fc779c7aadf7e94382d8
MD5 hash: d52aa0f6cf8620c50d8d7aea561b783a
humanhash: pizza-three-burger-speaker
File name:80f7d2d3de2cdfebab4c9d9b5de17efc7c08de900b12330c349beeaaf3eafedd
Download: download sample
Signature VShell
File size:1'872 bytes
First seen:2026-10-09 22:19:21 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 48:Y39LZ0Q3qp0r0vFCz7k/i76h7657RUa7QNZGyG:Y3F6OQ9Cz7kK76h7657ma7QNZi
TLSH T1E0310333E1C8FFBD7941EEAE4654D18818D310524DABF6D4A5D02523EC05AAB63C2D25
Magika shell
Reporter 0x3c7
Tags:sh vshell

Intelligence


File Origin
# of uploads :
1
# of downloads :
6
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Status:
terminated
Behavior Graph:
%3 guuid=91c798c0-1600-0000-1135-eba5d40d0000 pid=3540 /usr/bin/sudo guuid=d09c80c4-1600-0000-1135-eba5d50d0000 pid=3541 /tmp/sample.bin guuid=91c798c0-1600-0000-1135-eba5d40d0000 pid=3540->guuid=d09c80c4-1600-0000-1135-eba5d50d0000 pid=3541 execve guuid=9344d6c4-1600-0000-1135-eba5d60d0000 pid=3542 /usr/bin/mkdir guuid=d09c80c4-1600-0000-1135-eba5d50d0000 pid=3541->guuid=9344d6c4-1600-0000-1135-eba5d60d0000 pid=3542 execve guuid=457190c5-1600-0000-1135-eba5d70d0000 pid=3543 /usr/bin/touch guuid=d09c80c4-1600-0000-1135-eba5d50d0000 pid=3541->guuid=457190c5-1600-0000-1135-eba5d70d0000 pid=3543 execve guuid=61c3e7c5-1600-0000-1135-eba5d80d0000 pid=3544 /usr/bin/touch guuid=d09c80c4-1600-0000-1135-eba5d50d0000 pid=3541->guuid=61c3e7c5-1600-0000-1135-eba5d80d0000 pid=3544 execve guuid=a7483ec6-1600-0000-1135-eba5d90d0000 pid=3545 /usr/bin/touch guuid=d09c80c4-1600-0000-1135-eba5d50d0000 pid=3541->guuid=a7483ec6-1600-0000-1135-eba5d90d0000 pid=3545 execve guuid=346a92c6-1600-0000-1135-eba5da0d0000 pid=3546 /usr/bin/rm delete-file guuid=d09c80c4-1600-0000-1135-eba5d50d0000 pid=3541->guuid=346a92c6-1600-0000-1135-eba5da0d0000 pid=3546 execve guuid=678decc6-1600-0000-1135-eba5db0d0000 pid=3547 /usr/bin/dash guuid=d09c80c4-1600-0000-1135-eba5d50d0000 pid=3541->guuid=678decc6-1600-0000-1135-eba5db0d0000 pid=3547 clone guuid=f699ffc6-1600-0000-1135-eba5dc0d0000 pid=3548 /usr/bin/rm guuid=d09c80c4-1600-0000-1135-eba5d50d0000 pid=3541->guuid=f699ffc6-1600-0000-1135-eba5dc0d0000 pid=3548 execve guuid=8bb292c7-1600-0000-1135-eba5dd0d0000 pid=3549 /usr/bin/uname guuid=d09c80c4-1600-0000-1135-eba5d50d0000 pid=3541->guuid=8bb292c7-1600-0000-1135-eba5dd0d0000 pid=3549 execve guuid=955eedc7-1600-0000-1135-eba5de0d0000 pid=3550 /usr/bin/dash guuid=d09c80c4-1600-0000-1135-eba5d50d0000 pid=3541->guuid=955eedc7-1600-0000-1135-eba5de0d0000 pid=3550 clone guuid=9d83c254-2300-0000-1135-eba524140000 pid=5156 /usr/bin/chmod guuid=d09c80c4-1600-0000-1135-eba5d50d0000 pid=3541->guuid=9d83c254-2300-0000-1135-eba524140000 pid=5156 execve guuid=46801555-2300-0000-1135-eba525140000 pid=5157 /usr/bin/dash guuid=d09c80c4-1600-0000-1135-eba5d50d0000 pid=3541->guuid=46801555-2300-0000-1135-eba525140000 pid=5157 clone guuid=935ff9c7-1600-0000-1135-eba5df0d0000 pid=3551 /usr/bin/curl net send-data write-file guuid=955eedc7-1600-0000-1135-eba5de0d0000 pid=3550->guuid=935ff9c7-1600-0000-1135-eba5df0d0000 pid=3551 execve bafd85b0-590a-5974-ae21-da040cb85fcf 110.42.232.120:8897 guuid=935ff9c7-1600-0000-1135-eba5df0d0000 pid=3551->bafd85b0-590a-5974-ae21-da040cb85fcf send: 144B guuid=32302e55-2300-0000-1135-eba526140000 pid=5158 /usr/bin/b41bfef6tcp net send-data zombie guuid=46801555-2300-0000-1135-eba525140000 pid=5157->guuid=32302e55-2300-0000-1135-eba526140000 pid=5158 execve guuid=32302e55-2300-0000-1135-eba526140000 pid=5158->bafd85b0-590a-5974-ae21-da040cb85fcf send: 495B a88fe458-d88b-5b5b-b45f-c202dbded699 198.18.0.1:53 guuid=32302e55-2300-0000-1135-eba526140000 pid=5158->a88fe458-d88b-5b5b-b45f-c202dbded699 con guuid=24ac3a55-2300-0000-1135-eba527140000 pid=5159 /usr/bin/dash guuid=32302e55-2300-0000-1135-eba526140000 pid=5158->guuid=24ac3a55-2300-0000-1135-eba527140000 pid=5159 clone guuid=32302e55-2300-0000-1135-eba526140000 pid=5160 /usr/bin/b41bfef6tcp zombie guuid=32302e55-2300-0000-1135-eba526140000 pid=5158->guuid=32302e55-2300-0000-1135-eba526140000 pid=5160 clone guuid=32302e55-2300-0000-1135-eba526140000 pid=5161 /usr/bin/b41bfef6tcp zombie guuid=32302e55-2300-0000-1135-eba526140000 pid=5158->guuid=32302e55-2300-0000-1135-eba526140000 pid=5161 clone guuid=32302e55-2300-0000-1135-eba526140000 pid=5162 /usr/bin/b41bfef6tcp zombie guuid=32302e55-2300-0000-1135-eba526140000 pid=5158->guuid=32302e55-2300-0000-1135-eba526140000 pid=5162 clone guuid=32302e55-2300-0000-1135-eba526140000 pid=5163 /usr/bin/b41bfef6tcp net zombie guuid=32302e55-2300-0000-1135-eba526140000 pid=5158->guuid=32302e55-2300-0000-1135-eba526140000 pid=5163 clone guuid=32302e55-2300-0000-1135-eba526140000 pid=5164 /usr/bin/b41bfef6tcp guuid=32302e55-2300-0000-1135-eba526140000 pid=5158->guuid=32302e55-2300-0000-1135-eba526140000 pid=5164 clone guuid=32302e55-2300-0000-1135-eba526140000 pid=5165 /usr/bin/b41bfef6tcp guuid=32302e55-2300-0000-1135-eba526140000 pid=5158->guuid=32302e55-2300-0000-1135-eba526140000 pid=5165 clone guuid=32302e55-2300-0000-1135-eba526140000 pid=5166 /usr/bin/b41bfef6tcp guuid=32302e55-2300-0000-1135-eba526140000 pid=5158->guuid=32302e55-2300-0000-1135-eba526140000 pid=5166 clone guuid=32302e55-2300-0000-1135-eba526140000 pid=5167 /usr/bin/b41bfef6tcp guuid=32302e55-2300-0000-1135-eba526140000 pid=5158->guuid=32302e55-2300-0000-1135-eba526140000 pid=5167 clone guuid=32302e55-2300-0000-1135-eba526140000 pid=5163->bafd85b0-590a-5974-ae21-da040cb85fcf con
Gathering data
Threat name:
Linux.Downloader.VShell
Status:
Malicious
First seen:
2026-10-10 05:50:39 UTC
File Type:
Text (Shell)
AV detection:
10 of 36 (27.78%)
Threat level:
  3/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

VShell

sh 80f7d2d3de2cdfebab4c9d9b5de17efc7c08de900b12330c349beeaaf3eafedd

(this sample)

  
Delivery method
Distributed via web download

Comments



Avatar
commented on 2026-10-11 02:49:30 UTC

Shell dropper for VShell Linux implant bf8a8241e1d114be03550e909ddb8fb354d84b1e9c1b8a29c809de0160d74ee6. Picks a writable dir (/usr/local/bin, /usr/libexec, /usr/bin, else /tmp) using probe file 'writeablex', downloads 110.42.232.120:8897/?h=110.42.232.120&p=8897&t=tcp&a=<l64|l32|a64|a32>&stage=true&k=b41bfef6tcp via curl/wget/python, saves it as 'b41bfef6tcp' and starts it with nohup. No persistence in the script.