← Back to SOC feed Coverage →

ThreatFox: VShell IOCs

ioc-hunt HIGH ThreatFox
CommonSecurityLogDeviceNetworkEvents
iocthreatfoxwin-vshell
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at ThreatFox →
Retrieved: 2026-08-25T11:00:00Z · Confidence: high

Hunt Hypothesis

This detection rule identifies adversary activity involving known VShell indicators of compromise (IOCs) that signal potential command-and-control or lateral movement within the network. A proactive hunt is essential in Azure Sentinel to rapidly isolate and investigate these specific threats before they escalate into broader incidents, leveraging high-severity alerts to prioritize immediate response actions.

IOC Summary

Malware Family: VShell Total IOCs: 5 IOC Types: ip:port

TypeValueThreat TypeFirst SeenConfidence
ip:port180[.]76[.]135[.]85:8084botnet_cc2026-08-25100%
ip:port154[.]221[.]17[.]62:18080botnet_cc2026-08-25100%
ip:port150[.]129[.]80[.]247:8083botnet_cc2026-08-25100%
ip:port143[.]92[.]62[.]110:8083botnet_cc2026-08-25100%
ip:port114[.]132[.]178[.]92:8084botnet_cc2026-08-25100%

KQL: Ip Hunt

// Hunt for network connections to known malicious IPs
// Source: ThreatFox - VShell
let malicious_ips = dynamic(["154.221.17.62", "143.92.62.110", "114.132.178.92", "150.129.80.247", "180.76.135.85"]);
CommonSecurityLog
| where DestinationIP in (malicious_ips) or SourceIP in (malicious_ips)
| project TimeGenerated, SourceIP, DestinationIP, DestinationPort, DeviceAction, Activity
| order by TimeGenerated desc

KQL: Ip Hunt Device

// Hunt in Defender for Endpoint network events
let malicious_ips = dynamic(["154.221.17.62", "143.92.62.110", "114.132.178.92", "150.129.80.247", "180.76.135.85"]);
DeviceNetworkEvents
| where RemoteIP in (malicious_ips)
| project Timestamp, DeviceName, RemoteIP, RemotePort, InitiatingProcessFileName, ActionType
| order by Timestamp desc

Required Data Sources

Sentinel TableNotes
CommonSecurityLogEnsure this data connector is enabled
DeviceNetworkEventsEnsure this data connector is enabled

References

False Positive Guidance

Here are 3-5 specific false positive scenarios for the ThreatFox: VShell IOCs detection rule, including targeted filters and exclusions suitable for an enterprise environment:

Original source: https://threatfox.abuse.ch/browse/malware/win.vshell/