MB-17a364d3c81945062507876f302ba37b119c72f5603b8f6cac4de6a1009becbf
high
📛 Threat Title
Unknown: 17a364d3c81945062507876f302ba37b119c72f5603b8f6cac4de6a1009becbf.vbs
Description
File type: unknown. Size: 2791610 bytes. Tags: 45-133-174-90. Reporter: JAMESWT_WT. First seen: 2026-05-14 07:33:06.
Indicators of Compromise (2)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
17a364d3c81945062507876f302ba37b119c72f5603b8f6cac4de6a1009becbf
VT 14 / 75
1 feed
IOC database
- Type
- hash_sha256
- Value
17a364d3c81945062507876f302ba37b119c72f5603b8f6cac4de6a1009becbf- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- Unknown
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Flagged by 14 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| Antiy-AVL | malicious | Trojan/Script.Agent |
| Avira | malicious | TR/Malware |
| Cynet | malicious | Malicious (score: 99) |
| Fortinet | malicious | VBS/Agent.QCG!tr |
| Ikarus | malicious | Trojan-Downloader.JS.Func0 |
| Lionic | malicious | Trojan.CSV.Generic.4!c |
| McAfeeD | malicious | Trojan:Script/Remcos.AW!1 |
| Microsoft | malicious | Trojan:Win32/Ravartar!rfn |
| MicroWorld-eScan | malicious | Trojan.Generic.39954128 |
| Symantec | malicious | Trojan.Gen.NPE |
| Tencent | malicious | Win32.Trojan-Downloader.Downloader.Njgl |
| Varist | malicious | VBS/Agent.CRE |
| VirIT | malicious | Trojan.VBS.Agent.JQO |
| Xcitium | malicious | Malware@#198u7nfc7fle2 |
Details From VirusTotal
Basic Properties
| MD5 | 230febab9e7ac2c16a582bce626d1c54 |
| SHA-1 | 8c2d492e10f05d8c061cb5863f28559ac639dc80 |
| SHA-256 | 17a364d3c81945062507876f302ba37b119c72f5603b8f6cac4de6a1009becbf |
| SSDEEP | 96:pEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEL:C+/XS+ |
| TLSH | T111D5C5B7B214A3E85D44FB1AD44EFCC0CA14AB54F933642EE9FC0D546DC471E6CA18AA |
| File type | CSV |
| File type tag | csv |
| File extension | csv |
| Magic | CSV text |
| File size | 2.7 MB |
History
| First seen on VirusTotal | 2026-05-12 11:44 UTC |
| Last submission | 2026-05-12 11:44 UTC |
| Last analysis | 2026-05-20 09:01 UTC |
| Last modified on VirusTotal | 2026-05-20 11:09 UTC |
Known Names
17a364d3c81945062507876f302ba37b119c72f5603b8f6cac4de6a1009becbf.vbsbache.vbs
hash_md5
230febab9e7ac2c16a582bce626d1c54
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/230febab9e7ac2c16a582bce626d1c54
2 feeds
IOC database
- Type
- hash_md5
- Value
230febab9e7ac2c16a582bce626d1c54- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/230febab9e7ac2c16a582bce626d1c54
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: unknown. Size: 2791610 bytes. Tags: 45-133-174-90. Reporter: JAMESWT_WT. First seen: 2026-05-14 07:33:06.
Remediations (10)
-
web:forums.tomshardware.com
Question Sporadic BSOD screens appear shortly after "Virtualization-based security... is enabled due to VBS registry configuration" appears in Event Viewer ?
-
web:knowledge.broadcom.com
As a general best practice, we recommend you test the mitigation with your applications prior to deploying in production environments. Nested virtualization and Microsoft Virtualization-Based Security (VBS): Our testing showed a significant performance impact when applied to nested virtualized environments on ESXi.
-
web:learn.microsoft.com
If compatibility issues occur, see Troubleshooting for remediation steps. Memory integrity is a Virtualization-based security (VBS) feature available in Windows. Memory integrity and VBS improve the threat model of Windows and provide stronger protections against malware trying to exploit the Windows kernel.
-
web:superuser.com
Does the Microsoft update for BlackLotus mitigation SKUSiPolicy.p7b require Memory Integrity to be on and working in the Security Center?
-
web:support.microsoft.com
This mitigation is enabled by default. On these systems, the VBS-protected encryption keys are bound to the default-enabled boot session VBS CI policy and will only unseal if the matching CI policy version is being enforced.
-
web:windowsforum.com
In an important update released just recently, Microsoft has addressed the critical Virtualization-Based Security (VBS) vulnerability dubbed CVE-2024-21302, a flaw that could potentially allow attackers to downgrade modern Windows operating systems without user awareness. This significant security issue was publicly disclosed on August 14, 2024, coinciding with Microsoft's monthly Patch ...
-
web:www.17track.net
ALL IN ONE GLOBAL PACKAGE TRACKING Track global packages, eCommerce orders, and air cargo from 3300+ carriers and 190+ airlines, covering China and beyond. Start tracking USPS, DHL, FedEx, Canada Post, Deutsche Post, AliExpress, eBay, etc across web, mobile apps, and Shopify stores with 17TRACK!
-
web:www.elevenforum.com
Summary Microsoft was made aware of a vulnerability in Windows that allows an attacker with administrator privileges to replace updated Windows system files that have older versions, opening the door for an attacker to reintroduce vulnerabilities to Virtualization-based security (VBS). Rollback of these binaries might allow an attacker to circumvent VBS security features and exfiltrate data ...
-
web:www.forbes.com
WhatsApp users need to pay close attention following the latest attack warning from Microsoft. Here's what you need to know.
-
web:www.unknowncheats.me
I NEED HELP! PLEASE! Winver: WINDOWS 11 22H2 First time testing HVCI/VBS ON, all is ON, impost mode full. I'm using my own method, not a vulnerable dr
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.