public mosaic llc support@publicmosaic.com
malware sample

2bb373974f1488611ca19688ca053bb389884708826820eb58192c40a6e44890

A vShell sample, captured and analysed. Its family was read statically from the sample’s own bytes (an embedded ELF config). A network listener is never required for this record to exist.

2bb373974f1488611ca19688ca053bb389884708826820eb58192c40a6e44890

TLP:CLEAR

Sample

sha-2562bb373974f1488611ca19688ca053bb389884708826820eb58192c40a6e44890
familyvShell
provenancemined:elf_config
first seen2026-09-05 21:26 UTC
last seen2026-09-15 09:02 UTC

Observed served by 1 address

These addresses were seen DELIVERING this file. That is an observation of delivery, not an attribution — a widely distributed sample can reach unrelated hosts.